frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

We installed a single turnstile to feel secure

https://idiallo.com/blog/installed-single-turnstile-for-security-theater
84•firefoxd•1d ago

Comments

CoffeeOnWrite•1h ago
Allegations of security theater should start with discussing the threat model. This is just somebody complaining about a crappy key card system.
ableal•1h ago
To be fair, he was pointing out that the invisible "credentials in cookies" issue was much harder to get fixed:

The turnstiles were visible. They were expensive. They disrupted everyone's day and made headlines in company-wide emails. Management could point to them and say that we're taking security seriously. Meanwhile, thousands of employees had their Jira credentials stored in cookies. A vulnerability that could expose our entire project management system. But that fix required documentation, vendor approval, a month of convincing people it mattered. A whole lot of begging.

CoffeeOnWrite•1h ago
Again, not security theater. Signs of general dysfunction yes. Embarrassing. Fun to tease about for sure.

Aside: the more times I re-read the article the more annoyed I am with the self-righteous tone. It feels like the author is mimicking the style of legendary Usenet posts, but the story just isn’t that interesting and the writing not that witty, it falls flat.

mcbits•50m ago
The writing is clearly AI-generated or at least AI-assisted, so I think it's safe to assume it's also a work of fiction.
leephillips•18m ago
I’ll take your word for that. I don’t know how to tell. But I did notice that the writing was conspicuously terrible throughout. Entire sentences make no sense, such as “I'd slip in suspiciously while they contemplated the email that clearly said not to let anyone in with your own card.”
summermusic•34m ago
If it isn't outright fake it's at least embellished. It even has the "and then everyone clapped" line!
Apreche•1h ago
I’ve been to many very large office buildings with turnstile systems, and I have never seen any kind of line, even during the busiest hours. Yes, they are security theater to a large extent, but they do legitimately help to make the elevators run a lot more efficiently.
Normal_gaussian•1h ago
There is nothing here that really tells us the turnstile was security theatre? Or the various key card swipes.

There are many ways to skin a cat; and there are many ways to ensure authenticated / trusted access. If you have site wide security gates, it means you know everyone on site / on a given floor conforms to a given minimal security or trust level, so now you can conduct operations in that area with more freedom. This makes the risk assessments for other actions so much simpler. e.g. Now when the apprentice IT tech leaves the SLT's laptop trolley in the corridor it doesn't trigger a reflash of all of the machines. Or when a key individual misplaces their keyfob (e.g. in the kitchen) it doesn't trigger a lockdown of core systems, because they had it on the way in and its reasonable to trust that nobody stole it.

Obviously the implementation was botched in this case - but "feel secure" and "security theatre" are right as often as they are wrong.

mikeryan•38m ago
It also doesn’t describe any of the why the additional security measures were put in place. It sounds arbitrary, but could be an insurance or regulatory requirement that the acquiring company needed to meet. Similar for the login issue, it’s suboptimal but what constraints caused that solution to be put in place? And why wasn’t it fixed?

Sans context there’s not a lot to complain about here.

heytakeiteasy•1h ago
Security theater, perhaps. Don't underestimate the degree to which those turnstiles were intended to serve the purpose of tracking employees' movements.
knallfrosch•1h ago
Those turnstiles were inefficient (slowed legitimate users down), but not security theater (they really blocked unauthorized access.)
hamdingers•1h ago
I worked at a company that had effectively no physical security during work hours until the second time someone came in during lunch and stole an armload of laptops.

Then we got card readers and a staffed front desk, and discovered our snack budget was too high because people from other companies on other floors were coming to ours for snacks too.

I never felt the office was insecure, except in retrospect once it was actually secure.

amluto•1h ago
Turnstiles have a genuine security benefit compared to door and elevator security: convincing people not to let their coworkers in the door or up the elevator is difficult because the actual request (“close the door behind you, this blocking the friendly person trying to go through, so their scan their card”) is genuinely obnoxious. But a turnstile really does fundamentally let one person through, even if it’s easy to bypass.
Liftyee•47m ago
Lift (elevator) sidenote: there are fancy well designed ones where the turnstile communicates what floor you need to go to to the lift, and a "destination dispatch" system assigns/batches groups of passengers with similar/same destinations to the same lift car to improve efficiency.
robomartin•46m ago
Interesting. I have worked in ITAR environments with serious security and have never experienced 30 minute lines at the door. In fact, I can't remember lines at all. Hard to understand what happened here.

Was it really a single turnstile for a building with over 10 floors? That's kind of silly, isn't it? Mass transit operations have this figured out. Most recently for me, taking the monorail in Las Vegas for the CES show. No problems for the most part. It would be interesting to know what this company actually installed.

wildzzz•17m ago
I don't see how any of this wasn't already a problem. In the story, everyone shows up to the office at the same time, how did they use to work out the elevator issue? This story has a bunch of AI telltales so I doubt it's real anyway.
jez•42m ago
As others have mentioned, it comes down to the threat model, but sometimes the threat model itself is uncomfortable to talk about.

It’s sad to think about, but in my recollection a lot of intra-building badge readers went up in response to the 2018 active shooter situation at the YouTube HQ[1]. In cases like this, the threat model is “confine a hostile person to a specific part of the building once they’ve gotten in while law enforcement arrives,” less than preventing someone from coat tailing their way into the building at all.

[1] https://news.ycombinator.com/item?id=16748529

nine_k•38m ago
This text is another reminder about the fact that as organizations grow, they become more and more dysfunctional. They function despite that, because the economies of scale are apparently still larger than the loss of functionality due to the increased size.

Humans' most important achievement is the ability to create structures larger than the Dunbar number. But this is not achieved for free.

(And this is another reason why I strive to work at startups more than at huge corporations.)

Scubabear68•28m ago
Many years ago I was doing due diligence on a point of sale hardware company, I had to head up to an acquisition they had done. People bitched and moaned about the level of physical security added, and when I asked them why they were so upset, they told me to go to the loading dock in the back.

The loading dock was kept completely open "because it's hot and we don't have A/C back here!".

chihuahua•27m ago
Amazon is pretty serious about physical access security. Even back in 2002, you had to scan your badge while a security guard watches, to check if you are the same person as the badge picture.

The same guard also checked if your dog was registered (I think my dog got a badge with his picture, although I think that was just for fun, and not functional)

And no easy ability to enter through side doors - you couldn't open a side door with your badge. At the time, you could still lurk outside a side door until someone else opens the door to exit. Eventually (11 years later) they locked all the side doors because they noticed people doing this sort of thing.

More recently, I think you have to scan your badge to leave so they can even track how long you're in the building, and know when you're supposed to work on site but you were there only long enough to have a coffee and then went home to continue working from home. This last part is second-hand knowledge since I haven't work there in a long time.

xvedejas•23m ago
> they locked all the side doors

And this didn't get them in trouble with the fire marshal?

malfist•18m ago
Amazon employees can just use all the ...water... bottles they keep around their workstation to put out the fires.
class3shock•21m ago
This is the opposite of security theater. It was an apparently an implementation of security with issues but restricting physical access, both for people and vehicles, is absolutely a real improvement to security.
jacquesm•13m ago
Funny. We had a security guard that had memorized all the faces of the employees. If he knew you he'd buzz you through. If he didn't know you you'd have to be vouched for by someone that he did know or by showing your credentials. By day #3 he'd know you, and he also somehow knew when you were no longer with the company.

There never was a line and there were 1400 people in those buildings.

I never realized how incredibly that guy's contribution was but this story made it perfectly clear.

Also, I don't actually buy the story as related here. It would seem to me that within minutes of that queue building up the turnstiles + card system would be disabled because something clearly was not working.

CydeWeys•10m ago
I'm not really sure what the point of this article is. Yes, obviously, you need to implement systems that are secure and performant so that you don't get a backed-up line of people waiting an hour just to get into the office in the morning. But that's a notably rollout; millions of employees go into badge-in-required offices every day without issue. And it's kind of hard to imagine running a large office while lacking such basic physical security as "keep unauthorized people out of the building". Having electronic badges and readers is table stakes.
SiempreViernes•6m ago
Yeah, it got very strong "hello, I'm from the internet and this meatspace thing you are doing is wrong" vibes.

I Pitched a Roller Coaster to Disneyland at Age 10 in 1978

https://wordglyph.xyz/one-piece-at-a-time
223•wordglyph•4h ago•81 comments

Samsung Upcycle Promise

https://www.xda-developers.com/samsung-promised-make-old-phones-useful-galaxy-upcycle/
76•1970-01-01•1d ago•34 comments

Kansai Airport has never lost a baggage in the 30 years since it opened (2024)

https://japannews.yomiuri.co.jp/features/japan-focus/20241228-229891/
68•thunderbong•51m ago•11 comments

Extending C with Prolog (1994)

https://www.amzi.com/articles/irq_expert_system.htm
24•Antibabelic•2d ago•5 comments

Diode – Build, program, and simulate hardware

https://www.withdiode.com/
358•rossant•3d ago•78 comments

Stripe valued at $159B, 2025 annual letter

https://stripe.com/newsroom/news/stripe-2025-update
84•jez•2h ago•74 comments

Verge (YC S15) Is Hiring a Director of Computational Biology and AI Scientists/Eng

https://jobs.ashbyhq.com/verge-genomics
1•alicexzhang•31m ago

We installed a single turnstile to feel secure

https://idiallo.com/blog/installed-single-turnstile-for-security-theater
89•firefoxd•1d ago•27 comments

Goodbye InnerHTML, Hello SetHTML: Stronger XSS Protection in Firefox 148

https://hacks.mozilla.org/2026/02/goodbye-innerhtml-hello-sethtml-stronger-xss-protection-in-fire...
229•todsacerdoti•4h ago•99 comments

λProlog: Logic programming in higher-order logic

https://www.lix.polytechnique.fr/Labo/Dale.Miller/lProlog/
110•ux266478•3d ago•25 comments

Terence Tao, at 8 years old (1984) [pdf]

https://gwern.net/doc/iq/high/smpy/1984-clements.pdf
419•gurjeet•1d ago•246 comments

A distributed queue in a single JSON file on object storage

https://turbopuffer.com/blog/object-storage-queue
120•Sirupsen•3d ago•36 comments

Tiny QR code achieved using electron microscope technology

https://newatlas.com/technology/smallest-qr-code-bacteria-tu-wien/
26•jonbaer•3d ago•18 comments

The Missing Semester of Your CS Education – Revised for 2026

https://missing.csail.mit.edu/
262•anishathalye•1d ago•78 comments

Open Letter to Google on Mandatory Developer Registration for App Distribution

https://keepandroidopen.org/open-letter/
7•kaplun•11m ago•0 comments

IRS Tactics Against Meta Open a New Front in the Corporate Tax Fight

https://www.nytimes.com/2026/02/24/business/irs-meta-corporate-taxes.html
96•mitchbob•4h ago•111 comments

Cardiorespiratory fitness is associated with lower anger and anxiety

https://linkinghub.elsevier.com/retrieve/pii/S000169182600171X
11•PaulHoule•28m ago•3 comments

I Ported Coreboot to the ThinkPad X270

https://dork.dev/posts/2026-02-20-ported-coreboot/
264•todsacerdoti•17h ago•56 comments

Show HN: enveil – hide your .env secrets from prAIng eyes

https://github.com/GreatScott/enveil
175•parkaboy•12h ago•108 comments

Show HN: X86CSS – An x86 CPU emulator written in CSS

https://lyra.horse/x86css/
230•rebane2001•15h ago•71 comments

Unsung heroes: Flickr's URLs scheme

https://unsung.aresluna.org/unsung-heroes-flickrs-urls-scheme/
217•onli•3d ago•79 comments

The Age Verification Trap: Verifying age undermines everyone's data protection

https://spectrum.ieee.org/age-verification
1616•oldnetguy•1d ago•1223 comments

Catherine of Braganza, the Queen Who Brought Tea to England

https://www.thecollector.com/catherine-braganza-queen-tea-england/
8•Tomte•3d ago•1 comments

Show HN: Steerling-8B, a language model that can explain any token it generates

https://www.guidelabs.ai/post/steerling-8b-base-model-release/
279•adebayoj•16h ago•82 comments

Making Wolfram tech available as a foundation tool for LLM systems

https://writings.stephenwolfram.com/2026/02/making-wolfram-tech-available-as-a-foundation-tool-fo...
270•surprisetalk•19h ago•148 comments

Blood test boosts Alzheimer's diagnosis accuracy to 94.5%, clinical study shows

https://medicalxpress.com/news/2026-02-blood-boosts-alzheimer-diagnosis-accuracy.html
386•wglb•14h ago•151 comments

Discord cuts ties with Peter Thiel-backed verification software

https://fortune.com/2026/02/24/discord-peter-thiel-backed-persona-identity-verification-breach/
256•robtherobber•5h ago•169 comments

“Car Wash” test with 53 models

https://opper.ai/blog/car-wash-test
340•felix089•21h ago•405 comments

ATAboy is a USB adapter for legacy CHS only style IDE (PATA) drives

https://github.com/redruM0381/ATAboy
51•zdw•3d ago•31 comments

Firefox 148 Launches with AI Kill Switch Feature and More Enhancements

https://serverhost.com/blog/firefox-148-launches-with-exciting-ai-kill-switch-feature-and-more-en...
425•shaunpud•11h ago•344 comments