A team paid to break into top-secret bases
bbc.com
bbc.com
The MPs and US Mint Police were, of course, told we were doing this so they wouldn't shoot us. I do recall an incident from a bit more than a decade back, I think at Fort Bragg, where a soldier going through the special forces Q Course was shot by a police officer.
This is all anecdotal and will vary wildly by org and era. So if you were to compare, say, a NATO WSA during the Cold War against a modern colocation facility that occasionally trots out crew-served weapons for marketing photoshoots...while both are secure facilities featuring some degree of lethal response capability, these will have very different liability profiles and rules of engagement. But in both cases there will need to be procedures in place for evaluating on-duty armed guards in a manner that doesn't get anyone hurt.
For routine training during shifts, a training exercise is openly declared. This can be done ahead of time, or an evaluator may do so by surprise - it all depends on what procedures and scenarios are being evaluated. Once the evaluator/actor is detected or challenged by guards (or some other threshold is passed during a scenario), an exercise is declared out loud. Normally, this will happen before anyone in that scenario might reasonably need to use force.
Upon exercise declaration this is accompanied by a quick "safety briefing" over the radio to response forces with routine reminders on what to do if an unsafe act occurs, so guard forces know to appropriately pretend (shout "bang", blink flashlight, etc) instead of actually firing upon intruders. There's a degree of make-believe roleplay once the exercise is active, since discharging duty weapons in real life comes with mountains of paperwork that I don't want to think about even decades later. Of course, less harmful forms of force may still be permissible (and expected!), such as various restraint techniques or handcuffing/zip-tying resistant bad guys.
For any competent org, this sort of training happens constantly and with enough variation to keep everyone on their toes. The role of "bad guy" is rotated between different guards, so everyone has a chance to attempt breaking in to various restricted areas and enjoy tasting the various flavors of pavement around base as we tackle each other. An exercise of one type can snowball into another, if I manage to catch some unsuspecting lazy troop unawares and "kill" them (usually with a "Surprise! This is an exercise, you're dead, do not answer your radio."), then while they're tagged out (and chewed on by their sergeants about situational awareness), a quick response force is scrambled from available troops on shift to stop us. By this point everyone on shift will know the situation has escalated from a failed pentest into a nasty wargame and should act accordingly.
Bear in mind that these sorts of live exercises are meant to evaluate procedures and test readiness in situ - the forces involved may suddenly be interrupted by real-world duties and time constraints. Live force-on-force training conducted with blanks, MILES gear, airsoft or whatever less-lethal weapons they have these days would be during designated training time and not on shift.
Was this a mistaken transcription for Confluence, the Atlassian app?
edit: to those saying the word makes sense without referring to the Atlassian product, I'm not buying it. The journalist put it in quote marks, which to me suggests he thought it was a term of art — if he instead meant it metaphorically, I don't think he would have phrased it like that. It's also just an odd word to use to describe the idea.
I imagine the real human written sentence was "Trying to get admin access via a Confluence exploit," which there are many and an app that IT groups take their time updating.
We don't need AI for either interpretation, just familiarity with English.
In tech we usually assume "confluence" means the Atlassian product, not "a merging of several items".
These questions might have obvious answers. This isn't my line of work. I'm honestly interested in how they accommodate the need to (a) not kill the vendor and (b) still protect the facility.
One of my favourite episodes is the account of two people breaking into a US courthouse[1], it's both exhilarating and terrifying.
How I rob banks
https://www.amazon.com/How-Rob-Banks-Other-Places/dp/1119911...
Anyone have any movie recommendations for a more modern version of Sneakers (great movie)?
Physical pentesting or red teaming isn't anything new
Another very large tech company the security people DGAF about anything. You could forget your ID, tailgate someone, no problem. I started doing this to see how often I could do it, even when I had my ID. Security never stopped me, but when one of the C-suite folks did a badge scan, my manager got an earful wondering why I was never in the office. Which then resulted in a lengthy meeting with my manger, his director and another director. Imagine their surprise when they found out I was pseudo pen testing their security systems and pointed out that the security firm the company had hired was doing a horrible job. They obviously were not impressed and told me to stop doing it.
I also read a recent version where a team were doing this on purpose to get a person's ID scanned with some kind of a NFC scanner. Of course they would get kicked out for not having an ID or an appointment, but it didn't matter. They already had gotted several different employee ID's they could duplicate and use. They even managed to get some guy pretty high up who had an encrypted RFID ID card and managed to crack the encryption which allowed them to get into all kinds of restricted areas.
This sounds quite difficult, if not impossible :)
You're right that the existing fuel continues to decay (and this produces some heat, which is why you need an operational reactor cooling system even if you've shut it down, in order to prevent a meltdown), but it doesn't produce enough heat to meaningfully produce any power (via a steam turbine), and thus it could be argued that you have successfully stopped the core of the reactor from doing its job faster than you can pick a lock.
Off hand I imagine red-teaming a nuclear power station wouldn't actually go this far; victory would end at demonstrating merely that you could have (e.g. by being in a position and possessing the requisite equipment to compromise a temperature or flow sensor in the cooling system, leading the reactor controller to conclude that the cooling system has failed, triggering an emergency SCRAM).
Still it's interesting to think about.
At a European hacker con we had the custom of keeping crew badges in the first room to be occupied by us and our security. To get your crew badge, you had to get into that room without authorization.
Everyone worthy of being called "crew" did succeed.
Why is this relevant to Hacker News?