Our depot wireless network had one key. It was set in 2017 when the scanners were rolled out, and it was the same at every site, so that a device could move between depots without being reconfigured. That was the reason, and it was a good one.
In March a supervisor mentioned, in passing, that the drivers' rest room had good signal now. The rest room is meant to be on the guest network, which barely reaches it. When we looked, nineteen personal phones and a games console were on the scanner network at that depot alone. Across the estate we counted a little over three hundred devices we had never issued. The key was written on the side of a cradle cabinet at two sites, printed on a laminated agency induction sheet at a third, and had been read out over the phone by our own service desk an unknown number of times.
The scanner network reaches the warehouse system, the label printers and the conveyor controllers. A phone joined to it was one hop from all three.
The obvious answer was to change the key, and that is where it became interesting. Changing it meant touching every scanner, printer and weighing scale that held it, roughly two thousand devices, about four hundred of which could only be changed by hand. Any device we missed would drop off the network at the start of a shift. So the key had never been changed, in nine years, through hundreds of leavers, and it could not have been changed in an emergency either. We did not control that secret. We only knew it.
The scanners now join with a certificate each, issued through our device management, so removing one device removes exactly one device. Printers and scales that cannot hold a certificate sit on their own network, with access only to the print and weighing servers, under a key that a script changes every quarter. Phones, drivers and visitors have a guest network that now actually reaches the rest room. The service desk no longer knows any wireless key, and so it cannot read one out.
The migration took five months, mostly at night, and nobody on the floor noticed it.
A credential that a thousand people know and nobody can change in an afternoon is not protecting anything. The question I ask about a shared secret now is how long it would take us to revoke it, not how strong it is.
– Serguey Shinder
Top comments (0)