back
5 comments
We can draw some interesting parallels to information security from this. Both thieves snuck in through unused passageways, just like some interesting attacks use legacy functionality that is still carried in software: Heartbleed exploited a flaw in DTLS heartbeat code that practically no-one was using; SMACK actually formalised the concept of using unforeseen code paths to navigate TLS state machines.

Which leads to the question: What to do with unused pathways through buildings or software? In any case, we probably have to account for them in security considerations. Beyond that, what's the best way to go about it? Documentation (publish plans with secret passageways included / open source), instrumentation (tell the cramming student to check the dumbwaiters / IDS/IPS), remediation (fill them in with concrete / clean up the code base)?

Interesting cases. Stories of thieves crawling through hidden passages in ancient buildings are always exciting. But the writing in the last couple paragraphs was way too flowery for me.
So good. If you actually wrote a fictional account of this, your editor would turn you away for not being realistic enough.

"Are you kidding me? The guy just coincidentally found a map in the public archives? It happened to have been forgotten by them? And it was a secret passage? And now you claim part of the monastery was a hotel? I suggest you read up on some real life cases before you attempt fiction."

Cabinet seems to specialize in insane true stories.
So did they get the books back?