• e8d79@discuss.tchncs.de
    link
    fedilink
    arrow-up
    88
    ·
    2 days ago

    These Smart TVs are hanging in lots of meeting rooms at companies around the world. I wonder how many IT departments thought about checking for this.

    • calm.like.a.bomb@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      40
      ·
      2 days ago

      They don’t care… Most of the “IT departmens” at the companies I worked for were not interested in security stuff besides the employees’ endpoints.

      • med@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        17
        ·
        2 days ago

        I used to work for an MSP (Managed Service Provider), can confirm. Security is something I had to redirect attention to on a day-to-day basis. Even then, the company was more concerned with appearance and audit compliance than security.

        I have worked at IT companies that really did care about security, but those companies were driven by management and staff that personally cared about IT security. One of them was a certificate authority.

        Here’s a story about physical security from before that time.

        I once had equipment in a Data Center that was embedded in the 4th floor of an office building. There was a mantrap at the entrance, designed to prevent you from walking away with the main DC door open, or letting people tailgate in to it. One of the doors of the mantrap was a sliding door, disguised as a bit of the hallway.

        The sliding door was locked with a maglock on the thin end, so when it fully closed, it locked and you couldn’t slide it open without a key card, from inside or out.

        …unless you bumped in to it with your shoulder, which separated the lock and opened the door. Which, after it was figured out (about 1 month), happened all the time. People would get let in to the DC without a card that opened that specific door. (DC security control provisioned the main door was separate from building control, which managed the sliding door).

        When they tried to get out later, they’d get stuck in the mantrap, then they’d wait for someone to let them out (pre-cellphones). That person would then show them the trick. This was so common they turned off the forced-lock alarm. This lead to the mantrap being useless, and people propping the DC door open for ease of access when moving stuff in and out.

        This was put in place in 2001, and I visited the building last year in 2025, it’s still in place today.

        It’s worth noting that this DC was shared by multiple competitive reinsurers, ISPs and financial agencies. The were no cameras outside or inside, and you could poke most server reset buttons through the rack cages with the ink cartridge of a ball point pen. Not everyone was shown that trick.

    • ☂️-@lemmy.ml
      link
      fedilink
      arrow-up
      12
      ·
      2 days ago

      we are not paid to care about TVs. or privacy at all, too “paranoid”.

      so we don’t lmao.

    • Ildsaye [they/them]@hexbear.net
      link
      fedilink
      English
      arrow-up
      8
      ·
      edit-2
      2 days ago

      There are enterprise versions that cost a lot more, but come without the bloat or spyware, that are typically included in office installations at larger firms. Sometimes it is possible to obtain one for home use when an office is being renovated.

    • DannyMac@sh.itjust.works
      link
      fedilink
      arrow-up
      3
      ·
      2 days ago

      Usually those are commercial models. Those shouldn’t have mics, but are usually connected to Ethernet/Wi-Fi for remote control or signage applications.