Slashdot Mirror


Randal Schwartz's Charges Expunged

After 13 years, Randal Schwartz has had his conviction expunged. In effect, legally it never happened. If you haven't heard about this one before, my take is that as a contractor at Intel, Randal did some over-zealous white-hat cracking free-of-charge; this embarrassed some people in management (he pointed out that their passwords were terrible) and management then chose to embarrass themselves further by having him convicted of a felony under an 'anti-hacking' law. More info can be had from the Friends of Randal Schwartz.

35 of 219 comments (clear)

  1. Congratulations by Ron+Harwood · · Score: 5, Insightful

    Congratulations to Randal - it's nice to actually read a good news story with regards to the legal system.

    1. Re:Congratulations by A+beautiful+mind · · Score: 4, Insightful

      13 years of fighting doesn't sound especially pleasant. I can't imagine what Randall had to go through to get his name cleared.

      --
      It takes a man to suffer ignorance and smile
      Be yourself no matter what they say
    2. Re:Congratulations by jc42 · · Score: 4, Interesting

      ... if you keep fighting, eventually justice can work for "the little guy."

      Well, maybe, but what I always find interesting in cases like this is: How much money did it cost?

      All too often, when the "little guy" wins, he's also bankrupt.

      Anyone know what the bill was for all this legal action?

      --
      Those who do study history are doomed to stand helplessly by while everyone else repeats it.
    3. Re:Congratulations by merlyn · · Score: 5, Informative
      "He installed backdoors at 3 companies"

      Objection! Assumes facts not in evidence, your honor!

      Sustained.

    4. Re:Congratulations by merlyn · · Score: 5, Interesting

      I'll never claim that I wasn't stupid. It's not my job to get you to like me. The point of my case is to pay attention to the mistakes I made, because a lot of people have told me that they either have or could have made similar mistakes. Maybe some of you are so perfect that you wouldn't. Good for you. But don't be so quick to judge that nobody would be that stupid then. Please.

    5. Re:Congratulations by Bretai · · Score: 3, Insightful

      I agree that his actions are not anywhere close to "perfect", but the punishment given under this ridiculous law, is not in the neighborhood of justice either. I can only assume that the government thought it would be too hard to prove damages once someone hacked into computer systems, so they simply criminalized the attempt. I don't think a felony conviction, 5 years of probation, 60 days of full-time community service, 90 days in jail, $68K in restitution, and more than $100K in legal bills fits this crime in the absence of any damages, or even malice. At least one more of those is removed now, so he's a little closer to justice than before.

      Try to understand that when you know that you intend no harm, it's easy to see your actions as harmless. I think those were different times, when companies were still trying to understand and come to grips with the threat of hackers - and Intel was a soulless mega-corporation. They still are, but I doubt they would take the same action today. They'd just terminate his contract with prejudice and move on.

      After what he's been through, I'd say he deserves to put this behind him and have a beer with his friends. Cheers.

      --
      Controlling complexity is the essence of computer programming. -Brian Kernigan
    6. Re:Congratulations by Mikkeles · · Score: 4, Insightful

      Justice delayed is justice denied. This is not a feather in the cap for the justice system.

      --
      Great minds think alike; fools seldom differ.
  2. Its about damned time this was cleared. by Almost-Retired · · Score: 4, Insightful

    Congratulations Randall, its great news to hear that the legal system actually works once in a while.

    --
    Cheers Gene

    1. Re:Its about damned time this was cleared. by 1010110010 · · Score: 5, Insightful

      Are you fucking serious? After 13 years? You call that working?

  3. the terrible thing about character assassination by twitter · · Score: 3, Interesting

    The terrible thing about character assassination is that the event never had to happen. All you have to do is start a rumor about travel expenses and the victim is as good as blacklisted at big dumb companies where lip service is given to leadership but obedience and conformity are valued above all else.

    --

    Friends don't help friends install M$ junk.

  4. Legally Never Happened by vux984 · · Score: 5, Insightful

    Except that it did.

    And all the effects can never be erased.

    For example any "lists" he's been added to over the last 13 years will not be updated to reflect his new 'never was a criminal' status. Be it terrorist watch lists, no fly lists, FBI persons of interest list, or whatever else, not to mention his prints will remain in the system, etc, etc.

    1. Re:Legally Never Happened by hansamurai · · Score: 5, Funny

      perl will take care of this...

      @files = ("terrorist_watch_list.txt", "no_fly.doc", "fbi_persons_of_interest_list.ppt");
      foreach $file (@files) {
              unlink($file);
      }

    2. Re:Legally Never Happened by belmolis · · Score: 4, Insightful

      Uh, actually, this program doesn't do the right thing. Surely the right thing to do is not to delete the files but to remove Randall's name from them. Some people deserve to be on those lists.

    3. Re:Legally Never Happened by merlyn · · Score: 4, Informative

      I never lost my right to vote. Only four states do that, not Oregon.

      I can probably still get out of jury duty, since I now have a bias about criminal convictions. {grin}

      I can't possess firearms yet. I have to apply to the BATF separately. I plan on doing that, but it's not yet in progress.

    4. Re:Legally Never Happened by ObsessiveMathsFreak · · Score: 3, Insightful

      I can probably still get out of jury duty, since I now have a bias about criminal convictions. {grin}

      Having personally sufferred through a miscarraige of justice, you still don't don't see the point of the jury.

      And people wonder what's wrong with the legal system these days.
      --
      May the Maths Be with you!
  5. If you're going to blow the whistle by Profane+MuthaFucka · · Score: 4, Funny

    The best way to pass out embarassing information is anonymously. Burn some CD's with the info and leave them around randomly, in places untraceable to you.

    Don't touch the CD's with your fingers.
    Destroy the CD burner when you're done.
    Buy the CD burner secondhand at a garage sale. Pay cash.
    Steal the CDs from a college student.
    Don't leave the CD in a place where there's a camera.

    What else. Help me out here.

    Rely on someone else to find the data and spread it around. No need to get yourself into trouble. Have some Common Sense. Do you know what I am speaking of?

    --
    Fascism trolls keeping me up every night. When I starts a preachin', he HITS ME WITH HIS REICH!
    1. Re:If you're going to blow the whistle by Matt+Perry · · Score: 4, Informative

      I didn't realise this was blowing the whistle; I thought it was part of any good IT department employees job. That is to ensure all passwords, more so management passwords, are as secure as possible.
      He wasn't an employee of Intel. He was a contractor hired to do a specific job which wasn't checking for password security.
      --
      Slashdot: Failed Car Analogies. Amateur Lawyering. Anecdote Battles.
  6. In other news... by FlyByPC · · Score: 3, Funny
    Breaking news:White-hat hacker's conviction "never happened."

    In other news:
    • Hell freezes over; Devil announces installation of HVAC units.
    • Islam and Judaism to merge; Pope named as new high official.
    • Coca-Cola to license soda formula as GPL; KFC to follow suit
    • George W. Bush awarded Nobel Peace Prize
    • Bill Clinton and Gary Hart take vow of chastity
    --
    Paleotechnologist and connoisseur of pretty shiny things.
  7. Ditto; FBI can still see it by mekkab · · Score: 4, Interesting

    and Randall still can't get a clearance without being upfront about it.
    Basically it means he can tell a police officer he's never been arrested and doesn't need to disclose it on a non-clearance employment application or any "low grade" background check like rentin an apartment.

    With that out of the way, Randal has helped me out on comp.lang.perl (right before it went moderated) so ... Good on ya, Randall!

    --
    In the future, I would want to not be isolated from my friends in the Space Station.
  8. Expungement is the sealing of a criminal record by viking80 · · Score: 4, Informative

    Expungement is the sealing of a criminal record so it is not publicly available. The consequence might be that you can deny you have a criminal record, but it is quite different from a pardon, which is forgiveness of a crime and the penalty associated with it.

    --
    don't cut it off www.mgmbill.org
    1. Re:Expungement is the sealing of a criminal record by humphrm · · Score: 3, Informative

      but it is quite different from a pardon, which is forgiveness of a crime and the penalty associated with it.

      Indeed, a pardon cannot become effective unless you admit to wrongdoing - then you are "forgiven" and the penalty is dropped.

      In this case, he could argue that he never broke the law to begin with, because he was (albeit overzealeously) exposing security issues to his own employer. So accepting a pardon would be saying, "Yeah, I did break the law, sorry." In this case, he does not have to admit wrongdoing. In this case, Randall is instead being told, "Yeah, you didn't break the law, sorry."

      Honestly every one who knows Randall probably knows about this legal blemish, and probably don't care about it.

      --
      -- "In order to have power, I must be taken seriously." -Mojo Jojo
  9. Moral Of Story: CYA by cmholm · · Score: 3, Insightful
    It shouldn't have been necessary, but it was Randal's misfortune to show us the way to live with catch-all computer crime laws. To wit:

    The independent contractor shall...
    • Put all proposed activities in the contract/statement of work in as great a detail as possible, then...
    • Get written approval from the customer (your immediate POC and their boss) for any additional activities that occur to you after work commences.

    The in-house employee shall...
    • Review company computer use policies yearly, if not already required to do so.
    • Before attempting activities that may even conceivably be considered against company policy, get approval from lead in writing, hard copy signature if possible.

    May not seem a good use of time, unless you consider the value of staying out of the criminal legal system.
    --
    Luke, help me take this mask off ... Just for once, let me butterfly kiss you with my own eyes.
    1. Re:Moral Of Story: CYA by kcbrown · · Score: 4, Insightful

      No, the real moral of this story, and others like it, is simple:

      • Don't bother testing the security of a system unless you're forced to use that system to store, in unencrypted form, information you care about.
      • If you are forced to use such a system (and thus to test its security), perform all your tests in such a way that there's no way they can be traced back to you.
      • If you find security holes, the only action you should take is to minimize your use of the system. Under no circumstances should you actually tell management about the security holes unless you have, signed and in writing, authorization to perform the security testing. If you have such authorization, make sure you store copies of it in safe places. Even so, with today's fucked up legal environment, it's entirely possible that their lawyers would be able to get said document stricken from the evidence record on some sort of legal technicality, which means that even if you have ironclad proof that you were authorized to perform the security testing in question, you might not be able to use it.
      • If you absolutely must tell someone, make sure it's someone you can absolutely, positively trust with your life. Because that may be what's on the line (well, at least part of it, because we're talking about jail time here, and inmates love fresh nerd meat).

      The bottom line is that corporate management doesn't give a shit about the actual security of their system. They only care about the illusion of security, and they'll bring their full wrath against anyone who dares shatter that illusion.

      Let them have their illusion. If they ever get seriously 0wn3d, as is likely (it's only a matter of time), you can laugh your ass off at them, because it'll be evil people getting the shaft from other evil people. But today there is nothing but a whole lot of pain for the good guys in the world. Welcome to the real world, where evil usually wins in the end thanks to the world's inherent tendency towards chaos. You can try to fight it if you want, but you'll probably lose, so why bother? You're probably better off just keeping your own affairs in order and letting the others get fucked up the ass for their stupidity.

      --
      Use 'slashdot stuff' in the subject line in any email you send me if you want to get past the spam filter.
  10. Re:Ditto; FBI can still see it by Anonymous Coward · · Score: 5, Informative
    There was a PDF file linked on the http://www.lightlink.com/spacenka/fors/Friends of Randal Schwartz site states:

    IT IS FURTHER ORDERED that the clerk of the Court shall forward a certified copy of this Order to all law enforcement agencies mentioned in the Court's file, including the following:
    A. The Federal Bureau of Investigation, and
    B. The Oregon State Police, and
    C. The Oregon State Corrections Division, and
    D. The Arresting Agency, Portland Police Bureau. So the FBI can't use it against him. The PDF file is a copy of the expungement order from the court.
  11. Re:Whither $68k? by krbvroc1 · · Score: 4, Insightful

    At the federal level, it depends on the president. Clinton was fairly liberal with his pardons. Bush is tight with his. Whoop dee do.

    Most of the 'controversial' pardons are granted the last day of office, so there is not enough data to compare the current president and former. Report back in 2008 when there is more data.

  12. What about Chip? by nuzak · · Score: 3, Informative

    Whatever happened to Chip Salzenberg? He seems to have pretty much vanished since mid-2006.

    --
    Done with slashdot, done with nerds, getting a life.
  13. How's that for revisionist history? by tji · · Score: 5, Insightful

    The slashdot crowd has a short memory.. This is not a simple issue of "embarassing the management", as the summary states. In fact, in all the original writeups, I don't remember ever hearing executive passwords being an issue. The issues were egregious violations of corporate security policy, and basic logic:

    - His position at Intel was not involved in security, intrusion detection, or other areas that might actually call for "white hat hacking" as part of the job function. He was a contractor, not an Intel employee, which I'm sure made Intel even more concerned about his security violations.

    - He had installed backdoors on Intel machines, which allowed him to access the Intel network from outside the company.

    - He took passwd files and ran cracking tools against them to break other users passwords.

    - Not only was he cracking password files from Intel organizations, he was using Intel systems to crack password files from other companies, including O'Reilly and Associates.

    See this writeup for information from the person involved in shutting him down.

    Whether this was "white hat" hacking could be debated. In any case, it was fucking stupid. Bypassing network security for an inbound back door?!? Cracking password files from other companies on Intel computers?!? These are just stupid moves, which anyone should expect to get fired for doing.

    1. Re:How's that for revisionist history? by merlyn · · Score: 5, Informative
      "His position at Intel was not involved in security, intrusion detection, or other areas that might actually call for "white hat hacking" as part of the job function.".

      Wrong, I was a systems and network administrator. According to job description, that's part of the job.

    2. Re:How's that for revisionist history? by merlyn · · Score: 4, Informative

      The password was "pre$ident". Yes, president, with the s changed to a dollar sign. Which "crack" found.

    3. Re:How's that for revisionist history? by TheLink · · Score: 3, Insightful

      What I'm curious about is why does Sony get away so easily with installing backdoors and you don't?

      I mean just look at the fine to revenue ratios. And who got a criminal record because they were involved in the sony rootkit thing?

      --
  14. Re:Whither $68k? by merlyn · · Score: 4, Informative

    First, the amount in dispute was less than $5K. Second, the lower court just reaffirmed what they said before. In other words, no net change. So yes, I still paid roughly $68K in restitution, at the end of the day.

  15. Similar to SCO vs IBM by Anonymous Coward · · Score: 3, Funny

    SCO is being drained to death by the unfair legal assault by IBM. I hope that SCO wins $2-3 billions in the end. They certainly deserve it.

  16. Re:Ditto; FBI can still see it by Wavicle · · Score: 5, Insightful

    and Randall still can't get a clearance without being upfront about it.

    As someone who has gone through a security background check, worked at Intel and read the decision of the appeals court: I would be fairly surprised if Randal was able to get a security clearance even even if no conviction had occurred. The undisputed portions of the case suggest that Randal lacked an ethical barrier between him and either his curiosity about things for which he did not have access or his desire to gain respect by demonstrating his skill. This was 13 years ago maybe he has changed, I don't know.

    Whether his intentions at the time were noble or not: he logged onto a system for which he knew his account should have been deleted; he ran a gate program on the system (after previously being told to stop running a gate on other systems); he cracked one of the passwords to someone with higher access on the system; he then logged on to the system using the cracked user's account; he transferred the password file to another machine; he ran crack on this other machine; he turned up 35 weak passwords; he said nothing; he left for a while to teach a class; he came back; he still said nothing; he re-ran crack on another faster machine (this is apparently what eventually got him caught).

    Randal claims he did all this to re-gain respect at Intel's supercomputer division. I have no reason to doubt this is honest. The fact that he so freely gave so much information to the police suggests to me that he was trying to convey that he had no intention of harming Intel's business. However it is very, very bad judgment. Now if you were the agent assigned to his security background check, looking to see if his character demonstrates a likelihood of compromising sensitive information, even unintentionally, what would you think?

    --
    Education is a better safeguard of liberty than a standing army.
    Edward Everett (1794 - 1865)
  17. Re:Ditto; FBI can still see it by doom · · Score: 4, Insightful

    I would be fairly surprised if Randal was able to get a security clearance

    I was once working as an engineer at a secure facility, where one of my friends explained to me that he had never actually planned on working there. He figured he'd let them pay them while the background check was in progress, but never expected to actually be cleared (the interview with the Feds went something like Q: "So what about all these hits of acid they found in your refrigerator?", A: "Well, they were there.")

    But they did indeed give him a clearence, I would infer because they concluded he wasn't vulnerable to blackmail on the point, and so on.

    And I have to say that the opinion of "someone who has gone through a security check" isn't terribly authoritative, unless you were turned down for having a similar background to Randal's.

  18. Depends on the check - and why they need you by cheros · · Score: 4, Insightful

    At a sufficiently high level, a security check is not something you 'fail' or 'pass' - it's simply a risk assessment that clarifies to those that are planning to use your services which areas of risk they need to manage. It's not a tick box process that HR does over lunch - it takes months of investigative work. There is a simple way to get through that: do. not. lie.

    --
    Insert .sig here. Send no money now. Owner may sue, contents will settle. Batteries not included.