Slashdot Mirror


Sys-Admins Reading the Bosses Mail?

PetManimal writes "Computerworld has an article about IT staff who have access to corner-office email. Systems administrators, database administrators, storage administrators and higher level IT super users are the types who may access sensitive executive information; one source quoted in the article says that in a company with 1,500 employees, there might typically be five to 10 administrators who have this access. As for how many abuse these priviledges, it's hard to tell, but rogue admins out for workplace revenge or personal gain can wreak havoc: '... Experts agree that the severity of these occurrences generally makes them more harmful than external attacks. One of the biggest obstacles to eliminating unauthorized access is determining how many people have it. Access lists are particularly difficult to formulate in both mature companies, where the number and power of administrators have expanded over periods of years, and small companies, where rapid growth leads to undocumented tangles of administrators who are able to maintain their access because nobody has time to assess their status.'"

90 of 398 comments (clear)

  1. apparently they never read BOFH! by ezh · · Score: 5, Funny
  2. Clearance Control by Shadow+Wrought · · Score: 4, Insightful

    A friend in the Government once told me that after the Pollard spy scandal the Government rethought the way it handled clearances. So now there is a discreet pool of clearances. There's no reason why a company, new, mature, huge, or small shouldn't be able to institute a similar policy in terms of access.

    --
    If brevity is the soul of wit, then how does one explain Twitter?
    1. Re:Clearance Control by qwijibo · · Score: 4, Insightful

      Policies are the problem, not the solution. The policies grant access only to those who have a legitimate business need. The practical problem occurs when you consider system administration to be an annoying fact of life to be relegated to the lowest bidder. The administrator has a legitimate business need to have priviledged access to the system. That same access means the administrator can do whatever they want. You can implement more policies to make it harder for someone to abuse their position without collusion, but the reality is that all systems have one or more people that you trust implicitly. The problem is that very few people think of making that trust explicit and well known to everyone who relies on it.

    2. Re:Clearance Control by Coffee+Warlord · · Score: 5, Interesting
      There's no reason why a company, new, mature, huge, or small shouldn't be able to institute a similar policy in terms of access.


      Frankly, I say it's a nightmare for a small company when a big boss reads shit like this, freaks out, and all of a sudden you have to spend the next week trying to implement some goofy policy that will either be totally ignored, or tossed aside when it becomes a hassle. For larger companies, yes, internal security is no laughing matter. For small companies, when there's one, maybe 2 admins running the show, it's a wasted expense. They don't need intricate security policies. They need nothing more than, "Okay, I can access everything, everyone else can access their own shit. Done."
    3. Re:Clearance Control by paranode · · Score: 2, Interesting

      Clearances are expensive and time-consuming, many companies cannot afford to do it unless it is a stipulation of their contract (eg defense contractors). And you can also bet that it will cut your available workforce significantly.

    4. Re:Clearance Control by Anonymous Coward · · Score: 2, Funny
      So now there is a discreet pool of clearances.

      Well there was, until you went and told everyone!

    5. Re:Clearance Control by petes_PoV · · Score: 5, Insightful
      The biggest problem with this is the way lazy exec's just reply to all for every comment they make. If a request for info is sent out to (say) 20 people, it's very possible that all 20 recipients will get all the traffic on this subject - whether it's "sorry I don't know" or "don't bother, we're closing that location" or anything in between.

      You can't back security into an organisation. Either the individuals are prepared to put up with the extra work it needs, or they aren't. Without some effort from everyone, your level of security drops to that of the weakest link (usually the boss)

      --
      politicians are like babies' nappies: they should both be changed regularly and for the same reasons
    6. Re:Clearance Control by pilgrim23 · · Score: 2, Insightful

      Or, they could act like government's true approach to security: everything is so sensitive, nothing can be read by anyone on any level, thereby removing all information from the decision making process. In the case of every corner office I have ever associated with, no change in practice would be observed at all.

      --
      - Minutus cantorum, minutus balorum, minutus carborata descendum pantorum.
    7. Re:Clearance Control by griffjon · · Score: 2, Funny

      And the reality, a week later, when the boss has problems/forgot his super-cool passphrase and you're now locked out of his information, too.

      --
      Returned Peace Corps IT Volunteer
    8. Re:Clearance Control by Captain+Splendid · · Score: 2, Funny

      Okay, I can access everything, everyone else can access their own shit. Done.

      It's like you read my mind. Freaky.

      --
      Linux, you magnificent bastard, I read the fucking manual!
    9. Re:Clearance Control by kabocox · · Score: 4, Insightful

      Frankly, I say it's a nightmare for a small company when a big boss reads shit like this, freaks out, and all of a sudden you have to spend the next week trying to implement some goofy policy that will either be totally ignored, or tossed aside when it becomes a hassle. For larger companies, yes, internal security is no laughing matter. For small companies, when there's one, maybe 2 admins running the show, it's a wasted expense. They don't need intricate security policies. They need nothing more than, "Okay, I can access everything, everyone else can access their own shit. Done."

      And this is what is really wrong with IT now. In 100-200 years maybe when the industry starts to get alittle mature things will change, but currently the one or two computer guys have access to everything school of thought is really what's wrong with the entire industry. I'll consider this industry to be growing up when any small business could hire/fire/transfer admins with complete confidence that the new guy has complete access and the old guy has zero access without carrying home backups or enough info to successfully compete with the company. We just aren't there, yet. I know that I'm trust worthy, but I wouldn't trust any other IT person. I wouldn't trust Bill Gates or Linus to be left with ulitmate unchecked power over all my machines. Why would I want a setup where just 1 guy may or may not have complete control/access to the small network? Of course you need to define "small business." If you are talking about 10 networked computers and one temp. computer contracter guy that comes in to set things up or do windows up dates every 3 months or so, then your reasoning makes sense, but is still off. That computer guy no matter how trusted shouldn't have complete control over the network. What happens when that trusted computer guy is killed by a drunk driver, and then you have to hire a new guy?

    10. Re:Clearance Control by Maximum+Prophet · · Score: 5, Interesting

      Welcome to small business. Most usually have one or two key players that, if they die, the business dies with them. Usually, this is the founder, but not always. Sometimes, the president/founder/Grand Poobah doesn't realize who this key player is, and he fires that key player only to see his business fail, because he was too egotistical and arogant to notice that the company revolved around someone else.

      Many small businesses have several key player that would severly hurt the company if they left. I was working at a small database company many moons ago, and was offers a consulting gig in a far off state at twice my current salary and I jumped at the chance. I had no clue that there was a million dollar contract riding on the project I was working on. Once the customer heard I was leaving, the contract evaporated. If they had only let me know that what I was doing really mattered, I might have stayed. (at a higher rate)

      --
      All ideas^H^H^H^H^Hprocesses in this post are Patent Pending. (as well as the process of patenting all postings)
    11. Re:Clearance Control by Dun+Malg · · Score: 5, Interesting
      A friend in the Government once told me that after the Pollard spy scandal the Government rethought the way it handled clearances. So now there is a discreet pool of clearances. There's no reason why a company, new, mature, huge, or small shouldn't be able to institute a similar policy in terms of access.
      As a holder of a TS clearance and former military intelligence goon, I can tell you that there are PLENTY of reasons why a private company shouldn't implement a similar policy. The primary problem is that it introduces a huge amount of bureaucratic "friction" to anything you do. By my estimate, I spent about 20% of my time as an analyst dealing with the various forms of "hoop jumping" required to get anything done with heavily classified and compartmentalized information. For example, I might want to ask a guy specializing in "compartment A" stuff about something, but if the material I'm working with contains "compartment B" intel, I have to try to either a) try to recompile the material to omit "B" intel while still making sense (tedious, takes time, might not even be possible); or b) get him signed off with "B" clearance (takes even longer, might not even be possible). Since the government is already produces nothing tangible and operates as a net drain on the economy anyway, this massive waste is just more of the same. In a corporate environment, though, a government-style security policy would be a monstrous drain on productivity and, in turn, profitability.
      --
      If a job's not worth doing, it's not worth doing right.
    12. Re:Clearance Control by 1stpreacher · · Score: 5, Interesting

      I equate many of these positions to the janitor (and sometimes I've felt like a janitor) while he may not get paid much, and may not get much respect ... He's one of the few guys that has keys to the WHOLE building... You just have to trust some people. Or don't hire them...

    13. Re:Clearance Control by Anonymous Coward · · Score: 3, Insightful

      re trusted guy getting hit by a car.

      Here, there's also an "if sysadmins get run over" domain admin account detailed in an envelope in the company safe (with appropriate precautions to make tampering evident).

      Use of that password and account will light up every sysadmins pager / mobile and is logged as critical in all monitoring kit. So there's the means to ensure business continuity, but a massive lart ready for anyone who abuses their access to that envelope.

      You still need to read the network docs and know wtf you're doing, but the solution works for us.

    14. Re:Clearance Control by DDLKermit007 · · Score: 2, Insightful

      Honestly you were better off leaving. Once you make your goals known to an employer that it's "higher paycheck or I'm leaving" your going to be leaving. They would have kept you around for a couple months till the contract was signed and the other party couldn't get out of it/they didn't care and you would have been canned once they could find someone to replace you. If a company isn't transparent with it's lifeblood (ie it's workers/key players) your best off getting the hell out while the getting is good. Sad thing is the only workers that usualy get any level of transparency is contract workers (or clout for that matter). Fine by me given I switched to that a couple years ago. Old clients at over double the regular rate. A good deal to me.

    15. Re:Clearance Control by chris_mahan · · Score: 5, Insightful

      Who keeps the systems where your private key is stored?
      On your desktop machine? Who keeps your desktop machine?
      On your USB? a) Are you violating a policy for using a USB device? and b) When then USB is plugged-in, it's part of the machine (see above)

      If it's passphrase encrypted, are you 100% sure that there isn't a software keylogger on your machine?

      Trust me, you can't hide anything from competent sysadmins.

      The only way to make sure you control your machine is to install it, secure it, and manage it yourself, but then you've become the sysadmin.

      And it may very well be that the company won't allow anyone but an experienced and trusted sysadmin to plug such a machine into the corporate network (for good reason I might add).

      So you might as well get used to the idea that sysadmins have access to everything on the network.

      [puts on sysadmin hat]
      Ad that is how it should be anyway if you want the network to even start down the path of better security.

      --

      "Piter, too, is dead."

    16. Re:Clearance Control by Total_Wimp · · Score: 4, Insightful

      Insightful indead. Companies choose to trust CxOs, accountants, bookeepers and physical security personnel. These people can cause a tremendous amout of damage to a company, up to, and including, the complete collapse of the company (Enron, Worldcom, etc).

      The question isn't whether to trust, but under what conditions? Accountants and bookeepers often have checks, balances, licenses and bonding. CxOs have major positions of repsonsibilty with the salaries to match, and now they have Sarbanes-Oxley too. Physical security folks are often bonded, polygraphed, drug tested, etc.

      So which of these are most applicable to IT? Do we have checks, balances, licensing, bonding, major positions of responsibility with the salaries to match? Do we have polygraphs or drug tests? Do we have laws like SOX that put us in the hot seat if things go wrong?

      I'm not sugesting we should do any particular one of these things, but as IT continues to mature, and IT is seen, as it should be, as a single point of failure that could cause damage up to, and including, the complete collapse of the company, we're going to need to proffesionalize our practices to the point much greater than the blind faith that often exists today.

      TW

      (note: I know IT has a major role in SOX compliance, but we're not held responsible unless the company in question builds that into the system. Many companies aren't, at least not to the extent they should. If SOX causes more shops to know exactly who has access to email, and exactly how to go about making sure they're responsible and holding them accountable then, well, problem solved. I personally don't think SOX alone is enough.)

    17. Re:Clearance Control by h4rm0ny · · Score: 4, Funny


      That's one good example. Another is secretaries. Everything confidential seems to go through them in a small business and they always seem to need access to all the sensitive areas of the network.

      Incidentally, I run the network at my current employers. Shortly after starting, I restructured all the groups to make it more secure. I then matter of factly told them that I'd removed my access to certain areas that I didn't have the right to access. On occasion, I've added myself back on to accomplish certain things for them. They always find that hugely amusing.

      --

      Aide-toi, le Ciel t'aidera - Jeanne D'Arc.
    18. Re:Clearance Control by timeOday · · Score: 2, Interesting
      You have to turst people somewhat, but you can encrypt your stuff.
      But to be adopted, any such solution would have to protect the bosses' email from peons while still allowing convenient access to the peons' email by the bosses. Companies don't want email to be private, what they want is to control who can read whose mail. And of course the government is above all of them, making requirements that even the bosses' emails are archived and subject to subponea later on. In fact, President Bush stated in an interview just yesterday that he never uses email, because it leaves a permanent record:
      "In a CNBC interview with Maria Bartiromo, Bush was asked a question on many of our minds: 'I'm curious, have you ever Googled anybody? Do you use Google?'

      "According to CNBC's unofficial transcript, he replied: 'Occasionally... 'I tend not to email or -- not only tend not to email, I don't email, because of the different record requests that can happen to a president. I don't want to receive emails because, you know, there's no telling what somebody's email may -- it would show up as, you know, a part of some kind of a story, and I wouldn't be able to say, `Well, I didn't read the email.' `But I sent it to your address, how can you say you didn't?' So, in other words, I'm very cautious about emailing.'"

    19. Re:Clearance Control by gwayne · · Score: 5, Interesting

      Haha...that reminds me of a print shop I used to run. I was a part-time employee and college student, but I did all the quoting, typesetting, pre-press and some of the press work. The owner sold out to some guy who decided he needed a full-time office manager, and since I was only part-time, he hired some bimbo who didn't know dick about printing to run the place. I put up with her trying to tell me how to do my job for a few weeks. Then one day I needed $10 out of petty cash for supplies to finish a printing job. She refused to let me have it, so I quit right there on the spot. The next day the pressman quit. Less than a month later the business closed.

      BWAHAHAHAHAHAHAH! F*CKERZ!

    20. Re:Clearance Control by thethibs · · Score: 3, Interesting

      Janitors have the keys to the whole building, but none of the file cabinets.

      And, yes, the analogy is a good one. Read the rest of this thread; do the Dilbertian attitudes presented make you feel warm and fuzzy about the loyalty and trustworthiness of the avarage sysadmin? Sysadmins should have enough access to maintain the systems, but not enough to modify their own personnel files or read their boss' mail (at least not without leaving a trail).

      Achieving this is not rocket science with a modern system. Hell, it's never been rocket science; Banyan Vines had the required features fifteen years ago. Compartmentalization is baseline security.

      --
      I'm a Programmer. That's one level above Software Engineer and one level below Engineer.
    21. Re:Clearance Control by rilian4 · · Score: 3, Insightful

      When it comes down to it, there has to be a sysadmin at some level who is trusted to have complete access to the network. My mentor in college taught me and my classmates that a good sysadmin should always have a VERY trusted person who has access to a copy of the main password(s) to the network in case of physical injury or incapacitation. This trusted person has to know and be held accountable that they cannot use this information other than in an emergency.

      You simply cannot run a network effectively if you do not have full access to it. Somebody at some level has to be entrusted with this. The check/balance on this has to come from some kind of background check that would leave a resonable amount of certainty in the trustworthiness of the potential sysadmin.

      As Peter Parker's Uncle told him: "With great power comes great responsibility". A sysadmin should be trusted with that power in order to be as effective as possible but should also have to live up to the responsibility as well.

      --

      ...quicker, easier, more seductive the darkside is...but more powerful, it is not.
    22. Re:Clearance Control by SharpFang · · Score: 2, Insightful

      Who polices the police?

      If the company is huge, it's hard to audit all the systems to ensure no backdoors - especially that local admins have years of experience with said systems, often with custom modifications auditors will have no idea about. If the company is small, it's very expensive to employ a reliable external contractor who will implement security properly (and won't side with the admin instead of the boss, "overlooking" some backdoor). It may be easier in a new company where a system is created from scratch and a different crew is in charge of creating it, than the crew that will maintain it, but still there's nothing that stops an admin from installing an exploit instead of a patch on the mailserver and only regular, unexpected (and very expensive) audits can detect it.

      About the best way I know how such situation can be handled is to have dedicated, loyal employees and care for them.
      I didn't read my boss' mail. He was a nice guy and it would be rude, and I wouldn't do rude things to a nice guy.

      --
      45 5F E1 04 22 CA 29 C4 93 3F 95 05 2B 79 2A B2
    23. Re:Clearance Control by jesterzog · · Score: 2, Insightful

      We do this in a lot of places too, and I think there are perfectly good reasons for it, including security. (eg. If my account ever gets hacked, someone probably still needs to know a much more secure password if they want to give the account more access.) Another is just plain robustness. It's harder for me to accidentally break things when I don't have access to them.

      At least as importantly, though, I think it helps the users actually trust us more easily. Most of our users realise that we don't automatically have access to their documents, for instance. They also know from experience that we'll tend to ask them if we ever need to give ourselves access. Another example is with watching (and controlling) their desktops, usually for tech support. We could quite easily configure things to be able to connect at any time, but instead we make sure that whenever we do it, they first get a prompt which asks them if they'll give permission. Obviously it doesn't mean we can't do things without them knowing, but having policies about that sort of thing which people understand really makes it easier to work with the other people in the organisation.

  3. Passing on encryption by Anonymous Coward · · Score: 2, Insightful

    The article mentions the lack of encryption and I suspect if it ever starts being used the same IT folks who have admin access will end up with the encryption keys, so the added admin and overhead won't buy you more security from prying eyes.

  4. Bah old news... by Lumpy · · Score: 5, Funny

    I read this last week when my boss submitted the article to that magazine in his outgoing email.

    Gotta go, he's sending an email now about outsourcing the IT department!

    --
    Do not look at laser with remaining good eye.
  5. Definition of a hacker by Silver+Sloth · · Score: 2, Insightful

    Knows how to break IT security, but no longer needs to.

    --
    init 11 - for when you need that edge.
  6. there is no procedural or techical solution by maynard · · Score: 2, Interesting

    Whoever has access to sensitive company information is a threat to the company. It doesn't matter if they are a sysadmin or an executive. Limiting access may help, but at a certain point someone must know these details within a firm. And sysadmins cannot do their jobs without full access to the systems they support.

    The solution is regularly teaching business ethics to students. Perhaps even make it mandatory to earn a degree. Certainly mandatory for a graduate degree.

    1. Re:there is no procedural or techical solution by overshoot · · Score: 4, Insightful
      sysadmins cannot do their jobs without full access to the systems they support.
      Which isn't the same thing as having full access to the data on them.

      There are, after all, fairly straightforward ways to secure data against the admins (assuming they don't actually install spyware, which is a separate subject.) There are also ways to arrange secure key recovery so that the records can be recovered if Something Happens to the exec, but no one person can do it (say, three board members and an outside law firm.)

      --
      Lacking <sarcasm> tags, /. substitutes moderation as "Troll."
    2. Re:there is no procedural or techical solution by Anonymous Coward · · Score: 5, Insightful

      If you do not trust your staff, you have other problems.

      In my consulting work I have worked with systems containing sensitive information. Outside the workplace and outside the context of my particular role the information was of no interest to me.

    3. Re:there is no procedural or techical solution by jafiwam · · Score: 4, Insightful

      Also, maybe access but _logged_ access. And then a process where someone views the logs to look for unauthorized browsing.

      The DMV does it (every once in a while some bozo is fired from the state DMV for looking up minor celebrities information), I am sure many other less involved database systems can too.

    4. Re:there is no procedural or techical solution by dc.wander · · Score: 2, Insightful

      The solution is regularly teaching business ethics to students. Perhaps even make it mandatory to earn a degree. Certainly mandatory for a graduate degree.

      The suggestion that a mandatory degree and ethics classes will solve the problem is laughable. Many examples of why this is so exist: Citigroup, Enron, Worldcom... to name a few. Do they teach business ethics in MBA or CPA programs? Of course they do. Did it help? No.

    5. Re:there is no procedural or techical solution by peragrin · · Score: 2, Interesting

      Funny I have just that setup at home. I have an encrypted disk image(Yes I run OSX that's why this works and is easy for any idiot to implement)

      as I was saying, I have an ecrypted disk image, which stores my sensitive files. Tax file documents, and other such documents. Also on that image are the data files, and configuration files for an application. The data files are encrypted by the application, so that I can have my passwords secured(twice).

      When i double click on the app it tries to load it's configuration but the files aren't on the volume as it's not mounted. OS X tries to auto mount the encrypted disk image only to stop to require a password. The image decrypts and mounts allowing the App to finish loading. Another password in the app and I can access my password. Total access time 20 seconds. Knowing my passwords are protected by two different passwords with two different types of encryption. Priceless.

      --
      i thought once I was found, but it was only a dream.
    6. Re:there is no procedural or techical solution by nine-times · · Score: 2, Insightful

      And what do you do about the IT personnel who have rights sufficient to circumvent logging or alter the logs? The difference from you DMV situation is that you're talking about logging random DMV workers, and not the person who set up the system and maintains it, therefore having read/write access to everything.

    7. Re:there is no procedural or techical solution by SirKron · · Score: 2, Informative

      On MS Exchange this is easy.

      1. Enable mailbox login auditing
      2. Report on audit log entries with MOM

      Auditing is only the first step. It does not stop the person from taking a backup copy of the Exchange databases home and export the mail with Quest Recovery Manager for Exchange.

      So, even if you lock down your company like a government secure networks it all comes back to trust. They run background checks and grant security clearances for a reason. I have mine.

  7. Clueless in the corner office by overshoot · · Score: 4, Interesting
    The same executives wouldn't keep sensitive paper documents in an unlocked drawer, though.

    I realize it's a business problem when the CxO doesn't have a clue about encryption, but who's going to demand he get some education?

    FWIW, the legal profession actually has directives from the Bar Associations on when it's even permitted to use e-mail, and if so when encryption is required. Sometimes it's nice to actually have authority over you.

    --
    Lacking <sarcasm> tags, /. substitutes moderation as "Troll."
    1. Re:Clueless in the corner office by MrZaius · · Score: 2, Insightful

      http://www.lacba.org/Files/Main%20Folder/Documents /%20Ethics%20%20%20Opinions/Files/Eth514.pdf
      Los Angeles Bar Association: "Lawyers are not required to encrypt e-mail containing confidential client communications because e-mail poses no greater risk of interception and disclosure than regular mail, phones or faxes."

      http://www.netlawtools.com/security/emailsecurity1 .html
      The American National Bar Association takes a similar stance, but the above link does warn that if an unencrypted email is intercepted, the lawyer may be held legally liable.

      While it certainly should be necessary for important legal, medical, and other confidential information to be encrypted, it doesn't appear that the Bar association is quite as far ahead of the game as one would hope.

  8. It is all part of the job by cyanics · · Score: 5, Insightful

    Would you be upset if your alergist (doctor) had access to your blood work? No. It is his job. Trust is a huge component of system administration, and any company, or corporation, who doesn't understand that the administrator has the keys to the system, needs to take a better look at their corporate layout.

    Admins have access to everything. Or at least they should have access to virtually everything. Because who would you call if it was broken? certainly not the corner office.

    Trust is necessary. You have to trust your admins. And if you have an admin that leaves under suspicious or grievious circumstances, you protect your corporations ass with a dismissal agreement.

    1. Re:It is all part of the job by Shivetya · · Score: 2, Insightful

      The still do not need access to the text of the email.

      Sorry, but here are quite a number of methods by which the admin could track down an errant email or such without knowing its contents.

      Its like passwords, your argument has been used before by people who defend systems in which the password is retrievable. The only way for me to know a user's password in my systems is if I set it myself or they tell me. There is not a method to recover them. The same can be done for the text and such of the mail.

      --
      * Winners compare their achievements to their goals, losers compare theirs to that of others.
    2. Re:It is all part of the job by cyanics · · Score: 2, Insightful

      Good response. However, why on earth would a corner office think that the contents of ANY email were secure. email is basically just plain text. it sits in the spool as basically plain text. it prints on your screen as plain text. there is typically no encoding, no decoding, and anyone who has an email client can read it.

      I guess it is a problem with assumption. Corners assume communication is privileged, and private. Well, it isn't. It's like using a megaphone to talk through the wall to the office next door. Yeah, no one outside your office might hear you, but you don't know how many people are in the next office listening.

      Corners can't assume that email is private. It doesn't work that way.

    3. Re:It is all part of the job by eodmightier · · Score: 3, Interesting

      Our HR person has access to my SSN and all sorts of private information. OH NOES!!

      Our accounting person has handled personal bank information for my direct deposit information. OH NOES!!

      Lets make everyone who does anything get licensed by the state. That is what we need. More state licensing.

      --
      -Eod
    4. Re:It is all part of the job by NMerriam · · Score: 3, Insightful
      Its like passwords, your argument has been used before by people who defend systems in which the password is retrievable. The only way for me to know a user's password in my systems is if I set it myself or they tell me. There is not a method to recover them. The same can be done for the text and such of the mail.


      Except that assigning a new password and "destroying" the old one is a perfectly acceptable solution. So there is no need for anyone to be able to recover the old one. Destroying a document is not an acceptable solution -- if my boss needs me to recover a document, I need to be able to do it, whether it is by interacting with the application, searching through cache data, or scouring the individual hard disk sectors.

      Ultimately it does come down to trust (or greater monitoring), but you can't remove the fundamental ability of IT to be able to access all corporate data in some manner if you expect them to provide comprehensive support to the organization.
      --
      Recursive: Adj. See Recursive.
    5. Re:It is all part of the job by Orange+Crush · · Score: 5, Insightful
      The still do not need access to the text of the email. Sorry, but here are quite a number of methods by which the admin could track down an errant email or such without knowing its contents.

      That depends on who you work for/with. My boss likes to ask for things like:

      "Can you print me a copy of that e-mail I sent about our new sales strategy a few months ago? I think I deleted it."

      "Do you remember who you sent it to?

      "No."

      "Do you remember the date you sent it?"

      "Oh, a while ago."

      "What was it about?"

      "Sales."

      So anyway, when you work for people who routinely ask you questions that are about as specific as: "Hey, can you find me the thing I wrote about something just the other day?" it's helpful to be able to do fulltext searches and keep blunt throwable objects out of arm's reach.

    6. Re:It is all part of the job by nine-times · · Score: 3, Insightful

      Yeah, people don't get what's going. In the first place, e-mail isn't a secure form of communication. It's usually transmitted unencrypted, and often your authentication to your e-mail server isn't encrypted. Whoever is running your e-mail server, whether it's your ISP or Google, can read your e-mail if they really want, and mostly you're relying on them to be disinterested in the matters you're sending back and forth. People should understand this.

      However, the second component here is that, if you can't trust your IT staff, you are in big trouble. The reason is this: even if you put security measures in place to restrict IT access to e-mail messages, your IT staff is going to have to put that in place. If you can't trust the person who institutes your security, you won't know for sure whether they left themselves a back-door in. Basically, you're trying to lock people out of a system that they've set up themselves, and they know the system better than you do (or you probably wouldn't have hired them).

      So the best solution-- the only solution-- is to hire IT people you can trust. When you hand over control of your network to someone, imagine it being like handing over keys to a storage room with all your information in it, with only their integrity to keep them from browsing through it.

      As an aside: you should also be careful about the communications you have through your office e-mail. Even well-intentioned trustworthy support personnel might stumble across it while fixing problems or troubleshooting. Take it from a guy who's accidentally stumbled across e-mail from an executive's mistress before. I was just browsing trough our spam filter to look for false positives, and there it was. I wasn't looking for it, wish I hadn't seen it, and didn't want to know, but there it was. So as a rule, if you have personal information you wouldn't feel comfortable telling your IT people (like that you're having an affair and doing coke on weekends), don't talk about it in your work e-mail account.

    7. Re:It is all part of the job by 14CharUsername · · Score: 2, Informative

      Nope. You just encrypt everything. Everyone gets a USB keychain (or something similar). You keep a backup copy of all the keys on discs which you store in a safe. The admin can still manage stuff, but can't actually read, only the owner of the key can. If a user requires assistance in finding a file in an encrypted filesystem, then the admin might have to use remote desktop (or visit in person) and find the file under the supervision of the user. If a user loses their key, the admin has to go to the vault, sign out the disc with the user's key and decrypt everything and reencrypt with a new key in the presence of his supervisor (and maybe the owner of the key too).

      Yeah its a real pain in the ass to do this, and it will require a lot of extra training for the users, but it is possible.

    8. Re:It is all part of the job by metamatic · · Score: 2, Insightful
      Nope. You just encrypt everything. [...] If a user requires assistance in finding a file in an encrypted filesystem, then the admin might have to use remote desktop (or visit in person) and find the file under the supervision of the user.

      But in that scenario, IT can still get access to the encrypted data if they really want to. They can install a key logger and a tool that records your screen contents at intervals. Face it, you have to trust everyone who's able to install software on your computer.

      So while encryption may be able to reduce the number of IT staff who can read your e-mail--maybe the server admins can't read it now, only malicious desktop admins--you won't ever reduce the number to 0.

      Yeah its a real pain in the ass to do this, and it will require a lot of extra training for the users, but it is possible.

      It's a real pain in the ass, it requires lots of training, increases the risk of data loss, and it still doesn't actually prevent IT from being able to read your data. That's why nobody does it.

      --
      GCHQ Quantum Insert installed. If only our tongues were made of glass, how much more careful we would be when we speak
    9. Re:It is all part of the job by NMerriam · · Score: 2, Insightful

      Yes, it's possible. And even in your scenario, the admin ultimately has the ability to get at the data (albeit with a supervisor). You simply cannot remove that requirement the way you can with passwords, because you cannot destroy the data.

      Ultimately you do have to trust the IT department not to go to the vault together and decrypt everything over the weekend. They have to be able to decrypt things without the user, that's just a fundamental requirement for data preservation. You can put all the auditing and supervision on the process you like, but you can never escape the requirement unless you're willing to lose all data when an employee is killed in a car accident.

      --
      Recursive: Adj. See Recursive.
  9. Dog bites man. I by wwest4 · · Score: 5, Insightful

    If you don't have a chain of trust in your IT department you're fucked... even if you do spend bank on "secure internal IT infrastructure."

    The rest of the article is all over the place. There's some mention of rogue admins reading executive e-mail rolled into boilerplate security talk about how X% of security risks are insider threats, and then it finishes up with a vaguely related sales pitch for RSA products, owned by... yep, EMC. The guys providing ComputerWorld with ad revenue on that sidebar.

    Hopefully those scared VPs will hire consultants and purchase EMC products to "secure" their infrastructure from "rogue admins" who are probably reading their e-mail RIGHT NOW.

    1. Re:Dog bites man. I by Lumpy · · Score: 2, Insightful

      here's a few facts for you.

      Computrerworld is nota very highly regarded magazine. It's a freebie they shove down your throat. only middled managers actually put ant value into that rag's words. All this article does is fester distrust of the IT department from managers that have not a clue.

      your IT admins can bury your company and wield far more power than the executive staff combined does. Yet compared to all other departments IT get's the lowest pay.

      One admin with all they keys can easily take down anyone in the company in scandal, legal, whatever. When I worked corperate I had the keys to send emails as any of the executives, Presidents and VP's. I could have placed "evidence" on any of their laptops and done them in.

      IT people typically have the "hero" attitude and do not do such things even in the face of being screwed. WE like to help and do good things for the network and PC's so the risk is low... but I know o some ticking time bombs that will go off eventually if those companies management does no tpull their heads out of their rear.

      --
      Do not look at laser with remaining good eye.
  10. Re:And slashdot comments? by 99BottlesOfBeerInMyF · · Score: 5, Funny

    What about the /. admins who can read our highly sensitive comments?

    Comments? I'm not even sure they read the article summaries.

  11. Re:PGP mainstream? by wwest4 · · Score: 2, Insightful

    The problem is: how will PGP stop an admin? Clickity-click, I just logged keystrokes and got Mr. Fancy Pants' private key password. You have to trust your admins to some degree.

  12. Re:Anonymous by Anonymous Coward · · Score: 3, Funny

    Yesterday my boss got an email saying I was to be fired. I changed it so I got promoted instead.

  13. a pragmatic solution by pkbarbiedoll · · Score: 2, Insightful

    Maybe if companies paid their workers fairly and instilled loyalty things like this wouldn't be such a worry. Instead we're asked to do the jobs of several people for fraction of payroll - and not complain about it. What do CEO's think is going to happen?

  14. big deal by dlc3007 · · Score: 2, Insightful

    I've got read access to the entire financial database. I can find out how much they spent for dinner on their last trip and their salary as well. Luckily for them, I just don't care.

    1. Re:big deal by MrNougat · · Score: 2, Insightful
      Luckily for them, I just don't care.


      You just haven't found anything worth caring about yet. Wait till you find out that all of the people who are at the same level in the org chart as you are make $20K more a year than you, and they all come to you all the time to get things done because none of them know what they're doing. Or that the person reporting to you makes $30K more. Or that the company subsidizes the CEO's political fundraisers (worse if it's for a political party you strongly oppose).

      Keep looking, you'll find something.
      --
      Web 2.0 == Giant Blogspam Circle Jerk
  15. If you don't trust your Sysadmin(s)... by drsmithy · · Score: 2, Insightful

    ...Then the battle is already lost. You may as well close up shop and go home.

    Which is not to say there aren't unscrupulous people out there who will abuse positions of trust, but this is a HR issue, not a technical/security one (and is most certainly not one limited to the IT department).

  16. I have access.. by Anonymous Coward · · Score: 2, Insightful

    I work for a relatively small company with approximately 100 employees, and being one of the two sysadmins, I could easily go in and look at anyone's email. One of the many reasons I have for not doing so is because I have dignity and want to respect peoples privacy, no matter who they are. Also I could probably find some "dirt" about someone, but in the end it does no good, and in some cases would probably piss me off. If there really is dirt going around the office, I would rather hear about it by traditional means, just like everyone else. I also think that knowing about certain situations that might be going on, which have no effect on my day-to-day duties, affects my ability to treat all employees with the same respect that they deserve.

  17. This is normal and necessary by compunut · · Score: 5, Insightful

    At least in small business, and probably in all business, it is completely necessary for upper IT staff to have complete access to everything. I've lost count of how many times upper level management has come to me with the 'I forgot my password, can you get my stuff back?' request. This is a normal occurrence. If we take away the privileges of IT to access upper management data, then upper management is very likely to lose that data.

    As an anecdote, one of my customers (I am an IT consultant) lost the password to the video surveillance system. They immediately came to me, and were shocked and annoyed when I said 'Sorry, I wasn't involved in the installation of that system and was never informed of the passwords.' In the end, we found that a user had written down the password at one point and were able to get back in that way!

    The point really should be that companies better find upper IT staff that they can TRUST! If they can't trust their IT staff, they have big problems.

    1. Re:This is normal and necessary by snarlydwarf · · Score: 5, Interesting

      I have complete access to read (and even modify! w00t! that could be fun!) email for some 15,000 people.

      Unlogged.

      Do I?

      Hell, no.

      It would be nice to pretend it is all about ethics, but let's be realistic: it is really about "why would I -care- what they are jabbering about?" These are people who complain about getting "unbearable amounts of spam" when they get a total of a half dozen emails a day...

      Sorry: nethack, dinking around on forums and mailing lists, listening to music... all of them are much more important than the sort of nonsense people send in mail. I really don't care what people mail each other, how many porn sites they visit or whatever it is they actually do online as long as they leave me alone.

      It isnt ethics: it is pure and simple apathy about them.

  18. Secretaries are a bigger issue by Salo2112 · · Score: 4, Informative

    Odd people are concerned that IT types *might* be reading email when so many of the C*Os give their secretaries their passwords and other sensitive information. I am convinced that my Big Boss's secretary actually runs the place.

    1. Re:Secretaries are a bigger issue by SpecBear · · Score: 5, Funny

      I was once trying to explain to an exec why his account would never be absolutely secure.

      Me: "If somebody wants your account information badly enough, he's going to get it. He doesn't have to hack the system, he can just get it from you."
      Exec: "That's crazy, I'd never give anyone my password."
      Me: "Imagine you come home and find someone's broken in. He's got a gun to your daughter's head, and he tells you he's going to shoot in ten seconds if you don't give him your password. What would you do?"
      Exec: [long pause] ... Which daughter?

      To this day I still don't know if he was joking. But I no longer use that example.

  19. TRUST. by DRAGONWEEZEL · · Score: 2, Interesting

    How very true. I have to say that if you don't trust your employees, they can't do their job. If they can't do their job, how are their supervisors going to do supervisory work? etc etc.

    From a CEO's perspective you trust that your subordinates do their job, so that their subordinates are able to do their job all the way down to janitorial staff. Granted your level of trust declines proportionally to the level of visibility, but if the janitorial staff fails to take out the garbage for a week...

    --
    How much is your data worth? Back it up now.
  20. This is old news. by generic · · Score: 4, Funny

    I already read it in cmdrtaco's inbox. Seriously I bet a good number of IT people own the T-Shirt, "I read your email". We aren't kidding.

    --
    Microsoft aggravates my tourettes syndrome.
  21. And then of course... by skids · · Score: 4, Insightful


    There are ways to run a business that limit the amount of information that has to be classified so that it can be relayed verbally or by sneakernet. Like not defrauding your workers or business associates is a good start, followed by not raking in huge undeserved stock options and bonuses, not downsizing and outsourcing just because it is the latest fad, and in general being competent to the point that the only people who care what's in your email are the rarer criminal element and not every damn single employee.

    Ahh, driftnet on the switch monitor port. Never has there been such an artistically odd juxtaposition of shoes, porn, corporate logos, and vacation photos.

  22. Re:And slashdot comments? by Lehk228 · · Score: 4, Funny

    i assure you the vast majority of slashdot comments are in fact, insensitive

    --
    Snowden and Manning are heroes.
  23. One thing that would solve this... by spottedkangaroo · · Score: 3, Insightful

    Public key encryption, duh. Then, even if your admins had this access, which they must in some cases, they couldn't read the message anyway. The sooner CEOs catch on, the sooner everyone else will also.

    --
    Imagine if you weren't allowed to use roads because a bus company complained about your driving 3 times. --skunkpussy
  24. Fucking Computerworld fear-mongering! by Robber+Baron · · Score: 4, Interesting

    No shit Sherlock! Did you figure that out all by yourself?!? Of course I can read their e-mail! I'm a sysadmin and I set up the frigging mail system in the first place! Duh!
    What they fail to grasp is I don't have time to be going through their shit!
    Conversely PHBs don't have time to learn how to admin mail systems, which is what they'd have to do in order to keep me out.

    Here's a novel concept: Why don't you simply try hiring people who are trustworthy?

    --

    You're using her as bait, Master!

    1. Re:Fucking Computerworld fear-mongering! by dmihalko · · Score: 3, Funny

      But you do have time to read slashdot?

  25. Trust me by Anonymous Coward · · Score: 2, Funny

    It would never occur to me to take advantage of my responsibilities as a sys admin to use private information for personal gain.

    John Smith
    CIO, CFO, CEO
    MegaCorp, Inc.
    Employee of the Month
    Employee of the Year
    Grand Exalted Poohbah
    Keeper of Keys
    Omniscient All-Seeing Eye

  26. I am a Sysadmin by darth300z · · Score: 2, Insightful

    I am a Sysadmin. I built the network, I built the mail server, I built the VOIP system, and I built the DVR security system. I have control over all of these things. I know what happens here before anyone else does. I see your every move, can listen to your every phone call, and yes, I can read your email.

    We are not regular employees. We aren't the boss. We occupy a grey area, because we control everything.

    My system has millions of dollars flowing through it. You trust me with that, but have a problem with reading an email?

    I am a Sysadmin. Trust me or not. Me reading your email is the least of your problems should you choose not to trust me.

    --
    By law, anyone who has been drinking is "sober" until he or she "cannot hold onto the ground." Actual lexington, KY law
  27. bounces are better by Bigbutt · · Score: 5, Funny

    As the e-mail admin receiving the bounces are even more enlightening. There was a torrid love exchange in e-mail going on but they'd put an extra, invalid e-mail address in so the thread kept bouncing down to us. We tried to let them know about the problem but they were ignoring our messages.

    I created a t-shirt for work a couple of years back when I heard someone saying that we were reading their e-mails.

    "I Read Your E-mail"
    " It's Boring " :D

    [John]

    --
    Shit better not happen!
  28. Re:And slashdot comments? by cp.tar · · Score: 4, Funny

    ... and probably written by clods.

    --
    Ignore this signature. By order.
  29. Re:And slashdot comments? by Frank+T.+Lofaro+Jr. · · Score: 2, Informative

    They don't even read the title!

    It is grammatically wrong. The apostrophe is missing from "bosses" even though it is being used as a possessive.

    --
    Just because it CAN be done, doesn't mean it should!
  30. Another reminder about email insecurity by volsung · · Score: 3, Informative

    The root problem here is that standard email is intrinsically insecure. Most people imagine it as a digital letter, but it is more of a digital postcard. Anyone can read the message contents on any mail server queue it sits in. To solve this problem properly, you really need to start using encrypted email. Then you don't have to worry about the IT people (unless they installed a keyboard sniffer while you were on vacation) reading your mail, or anyone for that matter even if there is a server break in.

  31. Malicious... or just plain crazy? by fractalus · · Score: 4, Interesting

    At one small company I once worked at, my Windows box popped up a strange notice one day that someone else was using my IP. Since my IP was fixed (so that I could access various IP-restricted network devices) this immediately raised some red flags. We began looking for the culprit; something must've tipped off the hacker because we found ourselves locked out of our mail server. Since access to the mail server was only permitted from inside our network, we shut off our net access, hoping to block the hacker while we got back into our server.

    We tracked the hacker down. It turned out it was another admin, who had gone some kind of crazy. He had three NICs in his desktop box all configured to impersonate different machines, he had re-routed the boss's email through his mailbox (and some clients' mail too), and had all kinds of other things going on. And he had sat there the whole time we were trying to ID the hacker, pretending nothing was going on, all the while trying to stay ahead of us. Strangest thing I ever saw.

    Yes, he was fired. He really didn't seem to know why he'd done it (none of it made rational sense) and he'd really put his family in a bind. I think he was sick, but I'm not a psychiatrist.

    --
    People are never as simple as their stereotypes. This applies equally to Christians, Muslims, and Emacs-lovers.
  32. two man rule by thanasakis · · Score: 2, Interesting

    There are methodologies that can ensure that certain types of actions cannot be done without two admins working together. Can this be done for the action of reading someone elses email? If it was possible, they would have to conspire to read the bosses email. Anyone has any good links?

  33. Bullshit by Overzeetop · · Score: 2, Interesting

    In small business, there is (noramlly) no need for high security beacuse you can't Really Fuck Things Up (TM) like you can in big business where there are billions at stake.

    In big business, the data should be secure. Period. You lose your password, you lose your information - it's that simple. Oh, sure, you can^Wmust have a contingency plan (the three board members and an outside law firm) if somebody gets hit by a bus, but it really should be a hard process to implement retrieval. Would that embarrass the forgetee? Hell yes; that's the point.

    If you're in charge of IT you should _want_ there to be no way for you (or any single individual other than the owner) to retrieve that data. And you should have that policy in writing, with buy in from the top.

    The key here is that losing data is not an excuse for lax scurity. All data in business can be reproduced, at the cost of time and effort (=$$). It's a simple cost of doing secure business, and an incentive for executives to be midful of their responsibilties. Don't worry, they get paid enough to figure out how to commit a password to memory. If your executives don't believe that such security is necessary, then they either really don't need security (cough*bullshit*cough) or they shouldn't be making these kinds of decisions (cough*McDonaldsManager*cough).

    --
    Is it just my observation, or are there way too many stupid people in the world?
    1. Re:Bullshit by pmc · · Score: 2, Insightful

      There are three parts to IT security - confidentiality, integrity, and availability. An IT security policy must balance these. Your solution sacrifices availability. Maybe in some situations it is worth it, but in others it won't be. You say data should be secure - what do you mean? If data is on a public web server you know it isn't confidential, but you definitely want the webserver to be up, and you certainly don't want anyone unauthorised to change it.

      In your example (which boils down to two man working, essentially) you have increased the cost of support - is it worth paying? That depends - what are you relying on to enforce it (procedural or technical measures, a combination of these)? What are you protecting?

      There is also the rather tricky problem of defining who the owner is. If you have a data area with multiple people accessing it how do you put in sensible processes to manage this, and to recover the data when Fred fubars the spreadsheet. How do you audit use of the data (and do you even bother)?

      There are ways to cope with all of this, but a blanket "you lose your password, you lose your information (unless you put into action this very expensive process)" isn't a panacea.

      Finally - you say "all data in business can be reproduced, at the cost of time and effort". The first part, generally, isn't true. The "cost time and effort" also is misleading - sure, there will be problems where pouring money at them will get you better answers, but the business can't afford it (and it wouldn't be the first business that went down because they had an inappropriate security policy). It's a paradox, I suppose - important data is the only sort you can't afford to recover, because if it wasn't important you wouldn't need to.

    2. Re:Bullshit by The+One+and+Only · · Score: 2, Insightful
      In big business, the data should be secure. Period. You lose your password, you lose your information - it's that simple.

      That's a perfect strategy for security if you completely disregard human behavior. If you set the stakes so high for forgetting your password, you end up with people either using ridiculously simple passwords (so they remember) or writing their passwords on post-it notes underneath their keyboard. Congratulations, now your system is less secure.

      --
      In Repressive Burma, it's not just your connection that dies. slashdot.org/comments.pl?sid=314547&cid=20819199
  34. Funny but... by Anonymous Coward · · Score: 3, Insightful

    but the title is still insightful. This is old news. At work, I'm a domain admin. I have unrestricted access to all the files on tends of thousands of workstations. And to countless shares on hundreds of servers, with lots of infos and documents. And several Exchange servers. And many large databases. Webservers too. You name it, I can access it, totally unrestricted. I have access to tape backup libs. I can read the CEO's mail and documents no problem. I could install keyloggers or anywhere or do packet sniffing or such.

    But, well paid employees in a job that doesn't suck aren't typically motivated to do immoral stuff. I get paid well, I'm respected, my hours are decent, etc. I have no reason to be disgruntled and do bad stuff. On the other hand, I can say I'm a fairly ethical person (saying otherwise would be false modesty). The idea is to have good employees, and keep them happy.

    Now, if I was some guy paid below what I deserve, in a high stress job that sucks, risking to be outsourced and all, with management making every second of your life miserable and such, poor workplace politics and the old backstabbing between co-workers, then yeah, I wouldn't be surprised when something bad happens... It's old news, disgruntled ppl will sometimes do that kind of stuff.

    1. Re:Funny but... by Kelbear · · Score: 4, Interesting

      http://en.wikipedia.org/wiki/Efficiency_wage_hypot hesis

      Reading the parent's post made me recall this footnote from my economics classes. It's a theory that when you pay your employees well(i.e, better than the average competitor), you'll find advantages in that employee's performance. If you're in a good job and know you're being treated like you're a good employee, the theory is that this serves to discourage you from being a bad employee since you're risking the loss of a good thing.

      There's other reasons involved in this theory too though. If your compensation is that of a good employee, you're expected to be worthy of it, and your conscience may urge you to live up to such expectations.

      Of course, there's diminishing returns from doing this, but the point is...

      If an employee is important enough to possibly damage a company with negligence or malice, maybe that employee should be treated a little better to encourage them to put more effort in to avoid such things from happening. Economically, the additional compensation should reflect the chance of the damage times the cost of the damage if it were to occur, but it's not something easily measured.

  35. postcard by martin · · Score: 4, Insightful

    Let me think, when all this email started getting popular in the mid 1990's wasn't the advice to treat it as postcard....

    ie it could be read during transmission buy the post-office worker (sys-admin)....

    just a gentle reminder.

  36. EU member states called on to encrypt e-mail by SgtChaireBourne · · Score: 2, Interesting
    e-Mail per se has the same level of security as a postcard. Any company rellying on the mail being kept secret are just complete idiots.
    As you point out, the only solution is to keep the data safe. In case of e-Mail, any critically confident information should be PGP/GPG crypted,

    That makes it safe not only on the server, but in transit as well which may be more of a benefit.

    Interestingly, this very topic came up recently and you might find the following interesting:

    " 29. Urges the Commission and Member States to devise appropriate measures to promote, develop and manufacture European encryption technology and software and above all to support projects aimed at developing user-friendly open-source encryption software;

    30. Calls on the Commission and Member States to promote software projects whose source text is made public (open-source software), as this is the only way of guaranteeing that no backdoors are built into programmes;

    31. Calls on the Commission to lay down a standard for the level of security of e-mail software packages, placing those packages whose source code has not been made public in the "least reliable" category;

    32. Calls on the European institutions and the public administrations of the Member States systematically to encrypt e-mails, so that ultimately encryption becomes the norm; ..."

    European Parliament resolution on the existence of a global system for the interception of private and commercial communications (ECHELON interception system) (2001/2098(INI))

    (my emphasis above)
    That's an EC resolution - a finished decision. We've known about the problem for years and years, we've had the solution at hand since PGP/GPG, and even the politicians have caught on: EU member states are called on to use encryption for e-mail, not only use software which can be independently code audited. Now, why aren't we following it yet?

    --
    Beta is broken and the link to classic doesn't work. Stop wasting our time or there won't be anybody left here.
  37. Re:Trained Professionals by rs79 · · Score: 3, Informative

    " willing to live up to that level of professionalism"

    Funny. The day after email was invented the snooping began. I've seen it since the 70s. I knew a sysadmin of a well known california site that read EVERYTHING; absolutely nothing is safe.

    If you don't want somebody else to see it, never type it.

    I use the phone a lot.

    --
    Need Mercedes parts ?
  38. Re:Trained Professionals by Wanker · · Score: 2, Insightful
    If you don't want somebody else to see it, never type it.

    I use the phone a lot.


    I don't suppose you use voice-over-IP phones? I bet it would be trivial to set up auto-transcript on our CEO's phone IP...
  39. Duh, Breaking news at 11! by Dark_MadMax666 · · Score: 2, Insightful

    Seriously why it is such an issue? Yes - admins have access to most everything. So what? - its one of the upsides of being a sysadmin. you have to run backups , configure systems and such- your CIO will not do that (and most probably does not have skills for this either) . Now there is logging tools /products for auditing all secure object level access, but who is gonna implement them and put it in place? -That right exact same people .

      You don't bitch about plumber having access your basement ,or auto mechanic driving your car in repair bay , so don't bitch about people carrying weight of systems support of having necessary privileges.

      I can bitch about HR too - they have the most private information about employees (I saw HR files /data - in no way I would want them have that if I could) -but corporate culture justifies that .At least with sysadmins its a pretty good technical justification.

  40. Flavor of the week. by Anonymous Coward · · Score: 3, Insightful

    I too have seen many knee-jerk reactions by management to any number of real or perceived problems.

    Think about it. A group of highly paid MBAs sit in a room and come up with an IT solution you are supposed to implement.

    It really doesn't matter whether or not their solution is workable. You MUST embrace it.

    If you do not embrace it, you will always be remembered as the "difficult one".

    And really, the stupider the idea is, the faster it will go away and be forgotten. It is kind of like evolution, good ideas live and bad ideas die.

    In the end, the managers will not remember the solution, or the problem. All they will remember is whether or not you were a "team player" or the "difficult one". Just always agree and do your best to implement. When it dies, let it die quietly. No funeral. No wake. Just let it go.

  41. Options and bonuses for boss are sometimes good by AHumbleOpinion · · Score: 3, Insightful

    ... followed by not raking in huge undeserved stock options and bonuses ...

    While I agree that there have been terrible abuses here, I also recognize that sometimes these options and bonuses are appropriate but that is not always readily apparent. First there is the agent problem. The boss is sometimes merely an agent of the owner(s), how do you make sure he acts in a manner that improves the owners situation rather than his own? Options are one way. This also works up and down the ranks, for bosses and workers. The other area where a big seemingly undeserved bonus is appropriate is for the founder(s) who lost interest/investment income by spending his/her saving to start a business, lost salary income as he/she worked for no salary or a partial salary in the early days of the business, who risked their financially security and reputation to pursing a dream, etc. If they get a couple of big bonuses to repay and compensate for the preceding once the company becomes established, IMHO that is fair. I've seen small companies get bought out, and I've seen employees complain that they got a far smaller bonus than the founder they worked side by side with. What these employees failed to realize is that they took little risk, and that their boss made personal sacrifices so that their payroll checks were there on schedule.

    Is the above a typical scenario? I have no idea, but I have seen it a couple of times. I believe it happens often enough to warrant mentioning among the stream of expected "bosses are evil and all profit should go to those doing the work" follow ups. Like many topics, things are far more complicated than they seem.

  42. Re:And slashdot comments? by Anonymous Coward · · Score: 5, Funny

    Yes, the title for an article about an admin reading the e-mail of a single boss would be:

    English: "Sys-Admins Reading the Boss' Mail?"
    Slashdot: "Sys-Admins Reading the Bosses Mail?"

    For an admin reading the e-mail of more than one boss, the title would be:

    English: "Sys-Admins Reading the Bosses' Mail?"
    Slashdot: "Sys-Admins Reading the Bosseses Mail?"