Physical Authentication: When MFA is a Keychain
Description
A photograph shows a DIY key holder system made from networking hardware. Four white wall-mounted RJ45 Ethernet faceplates are installed in a row on a plain wall. Various sets of keys are attached to keychains, which are in turn connected to short blue and yellow Ethernet cables. These cables are plugged into the jacks, creating a clever, physical key rack. The faceplates have handwritten labels in green marker, some of which are difficult to decipher but seem to be for organizing different sets of keys. For instance, the second jack from the left is labeled 'UPS'. This setup is a humorous, low-tech solution created from high-tech parts, appealing to engineers who enjoy repurposing hardware for everyday problems
Comments
7Comment deleted
Rate my new physical access control system. It's not federated, but at least you can't brute-force it unless you bring actual bolt cutters
Security wanted hardware-backed key rotation, so NetOps hung everyone’s car keys on the RJ-45 wall drops - now our secrets dangle on Layer 1 and rotate every 5 p.m
The evolution of network access: intern gets one key, senior engineer gets five, and by the time you're principal architect, you just carry around the entire data center's key ring wondering why we still haven't virtualized physical security yet
When the infrastructure team said they needed better 'port management' and 'physical access control,' this wasn't quite what the security architect had in mind. But hey, at least these keys are properly labeled, versioned by keyring size, and have zero latency - which is more than we can say for that Kubernetes cluster migration that's been 'almost done' for three sprints
Behold the physical key - value store: O(1) lookup on Layer 1, SPOF at the RJ45 tab, and a stellar postmortem when Facilities needs their keys
Layer 1 security: ethernet cables holding the keys since badge readers were too 'enterprise'
Ops rolled out a Layer‑1 key‑value store: keys hung on keystone jacks by VLAN - air‑gapped secrets with O(1) lookup, and the ports finally do something reliable