Slashdot Mirror


The IT Department as Corporate Snoop?

coondoggie writes with a link to a NetworkWorld article about the dangers of IT department snoops. A study released today is likely to exacerbate the trend of failing trust in employees; it shows that one in three IT employees poke through systems and prod at confidential information while on the job. The survey was done by a firm specializing in password security, so some salt might be required for this particular article. "The survey found that more than one-third of IT professionals admit they could still access their company's network once they'd left their current job, with no one to stop them. More than 200 IT professionals participated in the survey with many revealing that although it wasn't corporate policy to allow IT workers to access systems after termination, still almost 25% of respondents knew of another IT staff member who still had access to sensitive networks even though they'd left the company long ago."

35 of 116 comments (clear)

  1. Only 1/3rd? by Skyshadow · · Score: 3, Funny

    1/3rd of IT professionals poke through other employee's files? What are the other 2/3rds up to all day long?

    Never hire an IT guy who couldn't pass the BOFH test.

    --
    Every year during my review, I just pray the words "slashdot.org" aren't mentioned.
    1. Re:Only 1/3rd? by ajanp · · Score: 2, Funny
      1/3 of them are simply too busy reading /. to trouble themselves with old files.

      The other 1/3... well... when I read their thoughts all that was coming through was "deny, deny, deny."

      --
      File Deletion is Murder.
    2. Re:Only 1/3rd? by YrWrstNtmr · · Score: 2, Insightful

      It seems like there'd be more important security implications with disgruntled fired IT guys still having unbridled access to the company network.

      Not all are fired/disgruntled. Some leave on good terms.

  2. Hmmm by Anon-Admin · · Score: 2, Interesting

    "The survey found that more than one-third of IT professionals admit they could still access their company's network once they'd left their current job,"

    This is kind of funny, When the layoffs hit back in 2001 I know of lots of instances where this happened. They lay off the IT staff and expect the systems to magically run them selfs, or expect the janitor to be able to run it all.

    But to see that today is a little of a surprise. Maybe they have not hired new IT staff and the equipment is just running on autopilot.

  3. All the more reason.... by Chabo · · Score: 3, Funny

    All the more reason to put make sure nobody else is snooping on you before you install your backdoor program!

    --
    Convert FLACs to a portable format with FlacSquisher
  4. Re:me! by Anon-Admin · · Score: 3, Funny

    The company I work for has a firewall is your site is blocked. It tells me "This site belongs to the XXXXXXXXXXXX defined Internet category "Tasteless" which has restrictions."

    I guess Ill have to look at it when I get home. :)

  5. Seperation of powers by tubapro12 · · Score: 3, Informative

    Like in government (cough cough cough), powers should be divided amongst a number of people i.e. hardware admins, web server admins, database admins, 'maintenance admins', et cetera. But for the majority of places this could easily be too many people. Of course, this is pretty impractical too, and I for one know most admins don't like having obstacles; but after all that's the root of the problem at hand.

  6. default passwords by grassy_knoll · · Score: 4, Funny
    From TFA:

    Eight percent of respondents noted that they still use the manufacturer's default admin password on critical systems.


    Some people are blockheads.
    News at 11.
  7. Why? by Hoi+Polloi · · Score: 3, Funny

    The last thing I want to do after spending 8 hours on my company's network is spend my personal time trying to get back onto my company's network.

    --
    It is by the juice of the coffee bean that thoughts acquire speed, the teeth acquire stains. The stains become a warning
  8. Thinkgeek knows it too by Weaselmancer · · Score: 4, Funny
    --
    Weaselmancer
    rediculous.
  9. Bad security, even without snooping by L.+VeGas · · Score: 4, Interesting

    In the mid 90's, I switched employers. My former employer was a fairly large medical / toxicology (drug testing) laboratory, and the records were fully searchable by name, SS#, and so on. Around this time, I got a new PC, and left the old one pretty much untouched for several years. About five years later, I fired it up out of curiosity. The terminal emulator shortcut was still there, so I plugged in the modem and was on the laboratory's network within minutes. Full access.

    The company has since been bought out and shut down, but that incident has always bugged me.

  10. old work still accessable by timmarhy · · Score: 2, Interesting
    the private files thing is total bullshit - we don't CARE abotu your dirty emails to your wife.

    accessing old work system is true i think... i know i still have access to places i setup 7 years ago, i login once a year to look at the up time on the system. it's nothing more then me checking on how my creation is going, if i saw a problem i'd probably report it to my old boss with a suggested fix.

    by the way, it's linux 2.4... 7 years up time on old salvaged hardware.

    --
    If you mod me down, I will become more powerful than you can imagine....
    1. Re:old work still accessable by Compholio · · Score: 3, Interesting

      it's nothing more then me checking on how my creation is going, if i saw a problem i'd probably report it to my old boss with a suggested fix.
      I would imagine that a lot of employers have actually made the conscious choice to keep people like you online after "termination". After all, who knows when they may need you to fix your creation?
    2. Re:old work still accessable by akeyes · · Score: 2

      er, it was lastest 2.4 version when i left. can't vouch for it right now though

      I'll tell you what... we will wait while you check. (You did say that you still have access.)

    3. Re:old work still accessable by jimicus · · Score: 2, Insightful

      if i saw a problem i'd probably report it to my old boss with a suggested fix.

      As one IT pro to another... if your former boss doesn't know this, don't do it. There's a strong chance you'll cause far more trouble for yourself than you ever dreamed possible.

  11. Shenanigans! by laron · · Score: 3, Insightful

    "The survey found that more than one-third of IT professionals admit..."

    I find that hard to believe.

    --
    "Beware of he who would deny you access to information, for in his heart he dreams himself your master."
  12. Can't be called professional without ethics by erroneus · · Score: 4, Interesting

    It's just my opinion but I'm sure many will agree with me on that. In every case where a person has privileged access to information as part of their job, there is usually some sort of ethical standard of non-disclosure in place. As an IT manager, I thrust my ethics upon people on a regular basis citing that I do not EVER want to know anything I don't need to know. Usually, it's passwords, but wouldn't that just be the start?

    I can't imagine how anyone could consider themselves "professional" without professional standards of behavior to go along with it. Do professionals in all fields get tempted "by the dark side?" Oh yeah... we see it on the news every day.

    But at a rate of 33% of IT professionals breeching company trust? That's pretty frightening... it's probably untrue.

  13. This seems to keep coming up lately... by Yobgod+Ababua · · Score: 3, Insightful

    Your company should have a published policy regarding user privacy and IT, and all members of IT should abide by that policy at all times. (In our case, for files or email, we require the approval of the user themselves or of a department manager and human resources before we go off reading your stuff. We do reserve the right to monitor network traffic at any time, for any reason, but we also make sure your email access runs encrypted over the network...)

    In any case, please encourage your local IT Professionals to behave like Professionals. How should they behave, you ask?

    Like THIS.

    Anyone who doesn't lock the accounts of ex-root-access employees and change the shared passwords that they had access to is lazy and negligent, bordering on criminally negligent. That's just inexcuseable...

  14. True enough by grasshoppa · · Score: 2, Insightful

    From my perspective, this is true enough. There are places that I still have access to that, by all rights, I shouldn't. I log in about once a year to see if I still have access, and if I do, I email the owner/manager of the place to that effect. Last thing I want is for something to go legal and me have a finger in the pie.

    Of course, for a few places around here, me still having access is a good thing. Seeing how they call me about once a week because they couldn't follow well laid out documentation on managing the system...but I digress.

    --
    Mod me down with all of your hatred and your journey towards the dark side will be complete!
  15. Wot no exit procedures? by Colin+Smith · · Score: 2, Interesting

    It's almost impossible not to occasionally catch sight of something sensitive when you work in IT; Employee databases, email folders/logs, web browser histories, chat logs etc etc.

    More than any other reason, this is why your IT team should be well paid and why duties should be segregated.

    Course there should be documented exit procedures for HR and IT when people leave.

    --
    Deleted
    1. Re:Wot no exit procedures? by nine-times · · Score: 5, Informative

      More than any other reason, this is why your IT team should be well paid and why duties should be segregated.

      And also "trustworthiness" really has to be high on your priority list of job-qualifications for IT people. I always tell people, if you can't trust your IT people, you're in trouble.

      You might ask why. "Why can't you put security in place that prevents your IT people from accessing the information you don't want them to see?" Well, I'll answer that with another question: who will put that security in place? Inevitably, there will have to be people who put security in place, and whoever that is could leave back-doors for themselves. There will be people who maintain the systems and security, people with powerful logins and passwords, and those people can override your security.

      And ultimately, there are accidents. At one company, we can a common spam database for the whole company (years ago). Every piece of spam went into the same place. While looking for false positives in order to see whether the filter needed adjusting, you'd see every e-mail that had a swear word in it. If someone wrote about "f*%king", it was in the spam filter. Every mention of "penis" went in the spam filter. A lot of it was spam, but there was plenty of employee e-mail going around, talking about things they probably didn't want anyone to see.

      Also, there were plenty of times where someone invited me to look at their desktop or e-mail in order to help them with something. Like, "hey, can you help me find this e-mail I'm looking for?" I say "yeah," and the e-mail up on the screen is an e-mail about having an affair and an Excel file containing everyone's salaries. It happens!

      My point is, even if your IT personnel are honest, they'll probably see sensitive information somehow, even if by accident. Trustworthiness is an important trait. My advice: If you're hiring IT people, it might be good to hire the person you'd feel most comfortable telling all your dirty secrets. If you're just another employee, keep any information on your work computer or pass information through your work systems unless you'd be comfortable with your IT people seeing it. If you must send information from work that you don't want your IT people to see, use a Gmail account, and don't leave your browser open while you're away from your computer.

    2. Re:Wot no exit procedures? by turbidostato · · Score: 2, Funny

      "who will put that security in place?"

      Why, indian engineers we get on green cards, of course. After the job is done, we bury them alive within the datacenter.

      We already used that trick on our pyramids.

  16. IT people could go to jail by Anonymous Coward · · Score: 2, Interesting

    The Air Canada vs. Westjet case involved computer espionage and a former employee who kept access to Air Canada's computer system. The result cost Westjet millions. The settlement left no doubt that what Westjet and its employees did was illegal. Illegal, as in someone could end up in jail, that kind of illegal. http://www.lockergnome.com/nexus/news/2006/05/29/w estjet-accepts-blame-settles-with-air-canada-in-es pionage-case/

  17. Passwords by Otter · · Score: 2, Interesting
    The study also showed that over 50% of workers still keep their passwords on a Post-It note, in spite of all the education the IT security industry to do it differently. And in the don't do-as-I do-dept., more than 50% of respondents admitted to using Post-It notes to store passwords to administrator accounts. One-fifth of all organizations admitted that they rarely changed their administrative passwords with seven percent saying they never change administrative passwords.

    I'm skeptical about the snooping (much as I bitch about admins, they're actually remarkably ethical about privacy given the access they have, IME) but that password thing sounds dead on. Whenever they give us the lecture about how keeping track of the login/password combos for 25 different accounts, each rotated every 60-90 days, with mandatory mixed case, numbers and punctuation is easy -- why all you do is make up a little story -- "Mary went to the store to buy milk" becomes h7^Y8U0bs# -- I always ask them for the story to their previous password to the office furniture request page. They splutter about how no, that's a security risk to part with one of their expired stories but I can see the Post-It with the root password in their minds, like I'm Professor Snape.

    1. Re:Passwords by drinkypoo · · Score: 2, Interesting

      They splutter about how no, that's a security risk to part with one of their expired stories but I can see the Post-It with the root password in their minds, like I'm Professor Snape.

      I've always written down my new passwords until I memorize them. Then I burn the paper.

      If you lose it while you're still memorizing it, you change it quickly :)

      But you don't write down what it's for, either...

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
  18. Telegraph Operators by Frogbert · · Score: 4, Insightful

    I like to think of myself as a Telegraph Operator. Sure I know peoples secrets, but it would be unprofessional for me to tell them to anyone.

  19. It's a problem by Phil+Wherry · · Score: 4, Interesting

    In the security business, a lot of the danger from IT employees comes from a class of attack known as "abuse of authority." It's near-impossible to prevent through technical measures, since the people in question need the elevated privileges in order to do their jobs. A careful program of auditing can often detect these abuses after they've occurred, however.

    I had a situation occur a few years ago in which I had to fire a trusted and valuable staff member for snooping through a senior manager's email. Another staff member actually detected this when he printed a copy of the email, and it came out of the printer in his home office even though he was on travel. This came to my attention very quickly, and we reviewed audit logs that we'd put in place earlier and found plenty of evidence of his snooping. It pained me to fire the guy--he was smart, ambitious, and held up really well under pressure. But in the end, I concluded that a slap on the wrist would just send the message to other team members that it was OK to cheat until caught for the first time. I suspect that it was the right move for him, too; our sudden, decisive response to his lapse in judgment doubtless made an impression.

    So, some advice to IT managers: ensure that there's an audit trail for all privileged activity. You'll detect and stop abuse if it's going in, and will deter staffers from being tempted to misuse their rights.

    Phil

  20. Salt for passwords too by omnirealm · · Score: 2, Funny

    Not only should the article written by the firm specializing in password security be taken with some salt, but it is also a good idea to add salt to passwords.

    Okay, that was a stretch.

    --
    An unjust law is no law at all. - St. Augustine
  21. Re:Who writes this stuff? by Nonesuch · · Score: 2, Informative
    One nice thing about physical access tokens is you can add them to the security guard's checklist for terminations, just like a laptop, badge/keycard, and company car. You don't turn it in, you don't get your final paycheck.

    The same IT department that doesn't turn off a terminated employee's access would be the same one who doesn't turn off access for the employee's token. These tokens don't magically fix broken IT security policies.
    But these tokens do have a built-in expiration date, the server doesn't fix policies, but it will enforce policies. When the end-of-life arrives, the token becomes a useless fifty buck hunk of plastic. And unlike passwords, lazy admins cannot trivially override the expiration date, like they do for VIPs in the "user must change password every X days" GPO on every Microsoft AD deployment I've ever seen.
  22. Curiousity herded the cat by Nonesuch · · Score: 2, Insightful
    I've found as I've gotten older and now have more to lose, I go out of my way to not acquire keys, to not know users passwords, to not have accounts on systems where I don't need them -- I'm just as curious, yet more risk-adverse.

    Average wrote: I always found that sysadmins (myself included) tend to acquire keys whenever possible. I don't care if it's just a broom closet, I want to know what's in there. There's a mix of paranoia, extreme curiosity, and helpfulness that come with the profile.
    When I want to see what's in a broom closet, I have security send up a guard with a key and have him open the door and show me around. My curiousity is satisified, and no worries about being liable if later a broom turns up missing :)
  23. Why...? by Telephone+Sanitizer · · Score: 3, Insightful

    > The survey found that more than one-third of IT professionals
    > admit they could still access their company's network once
    > they'd left their current job, with no one to stop them.

    Does it seem that people are villainizing the IT guys that left?

    Shouldn't the criticism be levied upon the IT guys who REMAIN?

    And as for snooping, it's not the snooping that bugs me, but the disclosures that sometimes follow. I was really pissed off when my boss started publicly ripping on me for the quality of some code scraps he found in my documents folder.

    I didn't mind that he looked -- I don't expect privacy on a corporate computer. But he used what he found in an attempt to humiliate me (which failed since the rest of the department knew that the code was something that I was reviewing from a new intern).

  24. Re:Who writes this stuff? by OnlineAlias · · Score: 2, Informative


    Curiously, Microsoft AD has no such ability. Password policies are set domain wide and there are no exceptions for anyone even with a GPO, a well known limitation of AD.

    Let me correct your statement. You have "never seen an AD deployment where a GPO's were making exceptions..."

  25. This has happened too many times... by SirKron · · Score: 2

    I agree with many of the people before me. I do not accept keys to client locations unless I am onsite more than a month. I do not accept domain administrator passwords, I ask for a unique admin account with delegated rights. And I do not snoop into files.

    Just recently I went to my boss and told him that our ex-HR person's home directory was wide open. I pointed out to him his hire letter and more from my other collegues. I almost did not approach him about it for fear of repricussions. However, I did not have any more than domain user rights and found it using Vista's new desktop search.

  26. Re:Who writes this stuff? by jombeewoof · · Score: 2, Interesting

    easy enough to set that token to "lost" with a passcode that doesn't expire.
    If you're an admin you would certainly have access to the RSA ACE server that allows this.

    --
    Linux Zealots: Smarter than Mac Zealots, but still zealots.
  27. Corporate Snoop? Wearing a tie with cornrows? by jsolan · · Score: 2, Funny

    fo shizzle