Man Fired When Laptop Malware Downloaded Porn
Geoffrey.landis writes "The Massachusetts Department of Industrial Accidents fired worker Michael Fiola and initiated procedures to prosecute him for child pornography when they determined that internet temporary files on his laptop computer contained child porn. According to Fiola, 'My boss called me into his office at 9 a.m. The director of the Department of Industrial Accidents, my immediate supervisor, and the personnel director were there. They handed me a letter and said, "You are being fired for a violation of the computer usage policy. You have pornography on your computer. You're fired. Clean out your desk. Let's go."' Fiola said, 'They wouldn't talk to me. They said, "We've been advised by our attorney not to talk to you."' However, prosecutors dropped the case when a state investigation of his computer determined there was insufficient evidence to prove he had downloaded the files. Computer forensic analyst Tami Loehrs, who spent a month dissecting the computer for the defense, explained in a 30-page report that the laptop was running corrupted virus-protection software, and Fiola was hit by spammers and crackers bombarding its memory with images of incest and pre-teen porn not visible to the naked eye. The virus protection and software update functions on the laptop had been disabled, and apparently the laptop was 'crippled' by malware. According to Loehrs, 'When they gave him this laptop, it had belonged to another user, and they changed the user name for him, but forgot to change the SMS user name, so SMS was trying to connect to a user that no longer existed ... It was set up to do all of its security updates via the server, and none of that was happening because he was out in the field.' A malware script on the machine surfed foreign sites at a rate of up to 40 per minute whenever the machine was within range of a wireless site."
Good to know they researched heavily before firing him. At my company when re-deploying hardware like a laptop it is standard to wipe it completely and load a ghosted image. Who WOULDN'T do at least as much?
case where you can't help but think "this can't be right".. making certain types of information illegal to possess just doesn't make practical sense in the context of the Internet, no matter how morally objectionable we find it.
If people hadn't jumped to conclusions and had done a more thorough investigation, this man would not have lost his job and reputation.
I've heard of people getting screwed by their bosses before but this is ridiculous.
If he hadn't had the resources to hire his own expert, he would be in prison and branded a sex offender for life, all because his boss didn't practice safe hex.
Knowledge is how to play a game, intelligence is how to win, wisdom is knowing what game to play.
This is a tough lesson learned for Mr. Fiola, but the lesson is, always request a clean build when receiving new equipment in the workplace. That would have eliminated the malware and given him a clean system to work on.
--I like turtles...
Not that Linux (or OSX, or any of 'em for that matter) are 100% crack-proof, but putting one's career at the mercy of common malware and the only safety net is a sharp eye at the IT department?
OTOH, I suspect this guy (if he plays his cards right and has a sharp lawyer on retainer) may never have to work another day in his life.
Quo usque tandem abutere, Nimbus, patientia nostra?
Julie Amero and the Porn Pop-Ups all over again?
The real crime here is that the charges were dropped thru "insufficient evidence".... Why is this loophole allowed to prosecutors? How about. "We are sorry we should never have arrested you, fired you and will will formally erradicate all your arrest process so it never happened and give you backed dated pay and legal expenses".
"As soon as you mention child pornography, everybody's senses go out the window, she [the computer forensics expert] said."
Sounds too familiar. What's really fucked up is that his former employers "stand by their decision", namely to fire the guy. The bare minimum would be a public excuse, an offer to let him work there again, and probably a hefty compensation if he refused. But that's not likely to happen since by definition, the government knows best.
The grass is always greener on the other side of the light cone.
DIA spokeswoman Linnea Walsh confirmed Fiola "was terminated," but declined to say if any internal discipline has been meted out as a result of his name being cleared in court.
"We stand by our decision," she said. So now the DIA is trying cover it's own ass for giving him "a ticking time bomb" and then firing him for it and ruining any social life he had.
The worst part is that the assholes at DIA responsible for the horrible "roll-out" of a replacement laptop, and the PHB's responsible for firing him w/o doing proper research into the issue will not be punished in any way. THEIR lives won't be ruined. Even if he wins a lawsuit. It'll be money from the DIA, but no real punishment to the people involved.
Somebody find all their names and contact info (I'm too lazy) and post it. Let's send the info to Russia with requests for Viagra and child porn.
Seriously though, The Office is funny on TV, but tragic in real life. These people should be arrested for harassment and criminal negligence at the least.
What kind of laws can we enforce (and/or pass) to truly punish the individuals responsible for shit like this? Lawsuit money from the organization isn't even close to justice.
Operator, give me the number for 911!
Hey, this trick worked on my mother when she busted me with (regular) porn on the family computer back in the day. I just showed her some flashy sensationalist article from the newspaper about 'malware' and 'popups' and told her the internet must have done it. Obviously it was that evil internet that had filled her computer with pornography, and not her pure-minded, cherub-like son. Curse that evil internet.
I wonder if she ever noticed that 'the internet' preferred brunettes?
Dealing with lawyers would be a lot less tedious if they all looked like Casey Novak.
* to disrupt society
* to provide a plausible alibi for any of his perverted friends
* to drive up the cost of prosecuting this type of crime so prosecutors will have less money to prosecute his brother-in-law who runs an organized crime family
* kicks/jollies/juvenile reasons
* someone paid him to do it
* Why ask why
* He wanted his work to get on CowboyNealBoard, er, I mean Slashdot
Knowledge is how to play a game, intelligence is how to win, wisdom is knowing what game to play.
Because the sites the malware connects through pay via click through.
What that bit of malware probably did was go around to a bunch of sites that the author gets fees from and makes it look like someone is browsing them.
Get a botnet of 1,000 computers going and it looks like hacker X convinced 1,000 people to view the site over and over.
It's better to be the foot on the boot than the face on the pavement. ~~ tkx Kadin2048
The fact the he was charged with child porn. I've been following this case in the news because it is such an odd case. As TFA says, they eventually figured out it was viruses and malware doing the downloading of images (over the web, BTW). Ok, fair enough.
...or did they find real kiddie porn on there?
However, another article (can't find the link, sorry) was interviewing one of the detectives involved with the case. What he said was something along the lines of "there was a LOT of porn on the computer. 99% of it was just gross stuff, not illegal. But we did find a few pics of young girls.". Which makes me wonder --- how, exactly, do they define child porn?
Are they just arresting people because pictures look young?
It just seems odd that all of a sudden there is all this kiddie porn out on the publicly available internet and it does not draw attention. I would presume, with Tor, Freenet, etc all of that activity would be driven underground (ie: encrypted). Is there really "spam" and popup based kiddie porn still going on in the WWW?
I ask because I have...err...my friend has not seen it since the early early days of the internet. Back then, you truly could stumble across it accidentally. It hasn't been that way for a long long time though, in my experience.
Personally, I'm skeptical about the idea of malware that secretly downloads and hides kiddie porn--why would the malware developer do that?
I've actually seen this sort of thing a couple times... not for kiddie porn luckily. Just movies (hollywood) and warez back before p2p.
As you can imagine finding servers to host and distribute this sort of stuff can be difficult. So why not compromise some random persons laptop, setup an ftp server, irc, dynamic dns, and whatever else... and then use it as a free and 'anonymous' remote host and storage.
It wouldn't surprise me in the least that this could be in use for kiddie porn distribution.
I really can't fault the emploeyr for not considering such an idea and investigating it.
When dealing with any case of child abuse including kiddie porn, one should ALWAYS be extremely cautious. Because whether he is innocent or not, people will never look at him the same way again.
Let me guess: Your mom is a brunette...
Any sufficiently well-organized community is indistinguishable from Government.
* To create mirrored websites to ensure availability of the material.
It happens with malware spreading sites, why not illegal porn?
If the malware can run a distributed dynamic dns based site, it will achieve a highly distributed network that would be hard to shut down easily.
No sig
She is. I know this because I also prefer brunettes.
Probably, the malware itself is a temporary webserver to help distribute the load of an illegal kiddie porn pay site. Look up Fast Flux (http://en.wikipedia.org/wiki/Fast_flux) spammers use it all the time and it is very simple to set up.
Personally, I'm skeptical about the idea of malware that secretly downloads and hides kiddie porn--why would the malware developer do that? The malware wasn't downloading and hiding kiddie porn From the article: "Loehrs found a script file that was set to go out and run its own searches on foreign Web sites, she said. "And once you get into some of these foreign sites, you'll get all kinds of stuff you don't want to see. "Actually, the child pornography was just a very small portion of it. The majority was just bizarre porn. He was being hit with everything," she added." The malware author was probably running a pay per click scam by using his malware to visit a bunch of sites and making it seem a bunch of visitors were browsing the site.
zero tolerance laws produce an extreme disincentive to properly and discretely investigate such things before slinging around an accusation which will ruin somebody's life.
"Megan's law"s punish people after the official debt to society has been paid. If you are so sure pedophilia is an incurable, life-long disease, than imprison them for life or develop a house arrest program, but you can't simply toss these sex offenders out, put a big neon "child molester" sign over their head, and pretend they have the same rights, or are not in danger of vigilantism.
VLC FOR MAC IS DYING! IF YOU DEVELOP, PLEASE SAVE IT!!
I'm involved in investigating things like this in my line of work. The argument I've worked on the most was that X worker was on eBay at 6am, and then there is a record of X on at 12pm, so we fired X for waisting time spending 6 hours of their day on eBay. Everyone of the cases I've helped investigate the employee was a few months from reaching a big pay increase or increase in retirement benefits.
Their team also loves to hand us data that their forensic person has pulled from Windows without giving us access to the original drive. When questioned on how he obtained the data it was clear that their certified forensic expert didn't make a locked copy of the drive but logged in and poked around. The certification their contractor has is from IACIS http://www.cops.org/certifications
None of them so far has gone to a judge AFAIK but I know my PHB has testified for an arbitrator and the arbitrator ruled there was insufficient evidence for a dismissal.
Amendment 8 - Cruel and Unusual Punishment. Ratified 12/15/1791.
Excessive bail shall not be required, nor excessive fines imposed, nor cruel and unusual punishments inflicted.
Frankly, zero-tolerance doesn't seem like what the Founders had in mind, nor does torturing people you don't like for the rest of their natural (and now probably shortened) lives. Granted, I suppose this depends upon your interpretation of "cruel and unusual", but if this can be applied to sex offenders it can be applied to any group of people if you can manage to vilify them sufficiently.
The higher the technology, the sharper that two-edged sword.
As a sys-admin, I was given a laptop to use that was my predecessor's. While doing a search of the laptop, I found A LOT of porn in the internet cache. My predecessor had used the firewall/lan bypass device we reserve for site visitors to surf for porn on company time. I did not report him, I simply contacted him and said "I seem to have found some adult material on your laptop, all time and user stamped for you. I think I will re-image this machine, do you have any objections?" He seemed pretty thankful that I was doing so and has been very helpful towards me ever since (8+ months).
I would like to think that as a sysadmin, I have the duty to protect both the company and the users under my watch. I was not harming the company by giving this guy an out(especially since he had just got a big promotion and an expensive move to corporate HQ).
Do you think I did wrong in not reporting the guy? (It was obviously deliberate browsing, but no kiddie stuffs)
How amazed would you be to suddenly find that you just forgot what I wrote and you needed to reread my post.... again.
Not having a skill you might happen (I assume) to have shouldn't be cause for derision or ridicule. As for the "nerve", you've obviously never had a job at a company of any significant size. And we'll leave it at that.
Web2.0: I love when people Flickr my cuil and digg my boingboing until my google is reddit and I start to yahoo
I've noticed from having kids that when kids think they're getting away with something, it's just that the whole thing sucks (embarrassing for both or just annoying) so you let the kid think he got away with it. One day, if you have any kids, you'll figure this out.
Yes, Megan's law is obviously intended to incite mob 'justice'. Executions are expensive and socially messy. It is much simpler to 'think of the children', publish the addresses of sex offenders, and hope that some other sicko takes care of the problem for you.
Firing people based on things that happened on an infected PC is the modern equivalent of shouting burn the witch!
The truth is that this can happen. The truth is that so many corporate desktop and laptop systems are p0wn3d by th3m that it isn't even funny.
The truth is that event logging on these networks and systems are insufficiently detailed as to demonstrate conclusively which actually happened. Any logging that does take place on a system probably can't show you wether the user was responsible, or if an automated program pretending to be the user was responsible. Any corporation that gives a users a typical Windows system and then holds that user responsible when something untoward happens on that system ought to be opening themselves up to a lawsuit.
The truth is that even the the lawyers who advised not to talk about the reasons for dismissal don't recognize this. They prohibit discussion of the details regarding the dismissal of the employee for reasons entirely unrelated to the issue of being entirely unable to conclusively substantiate any accusations which would be made. (It's standard dismissal policy at all of the Fortune 500 to not give any reason). In general, employees, managers, lawyers and judges are completely unprepared to assess the details which would expose the fact that nobody can actually prove that this unfortunate person was probably the victim of some botmaster's prank. People should be surprised that this doesn't happen more often.
That said, there are things one can look at to determine what was *likely* to have happened on that box, and one can assess to some degree what things were relatively more likely than others. If the box was running malware, though, the most likely outcome is that one cannot demonstrate beyond a reasonable doubt that the user was guilty. However, one can, in some cases, demonstrate innocence, by showing, for example, that a given download occurred when the user was away from the keyboard.
It's important to note that the converse is not true. The malware can easily mimic user behavior by performing user style tasks only when the user is logged in. Malware may, for example, have incentive to operate only when a real user is logged in, because certain operations in certain environments are unlikely to succeed if the user is not logged in (being stopped, and identified as likely malware behavior by a 3rd party heuristic detection system, for example.) Malware often does change its behavior based on instructions from the outside, based on the day or the time, based on all sorts of things, and may not behave the same in an isolated test lab as it does "in the wild" so it can be difficult or impossible to demonstrate the full capability of a given strain, even if you have a copy of it.
If you mod me down, I shall become more powerful than you could possibly imagine.
4) You own him until he leaves the company.
"He'd have 40 Web sites hitting his computer in a minute -- who's the IT guy who looked at this and said, "Wow, this guy is pretty active on the Internet?'" Loehrs said. "It's physically impossible!"
Loehrs found a script file that was set to go out and run its own searches on foreign Web sites, she said. "And once you get into some of these foreign sites, you'll get all kinds of stuff you don't want to see.
"Actually, the child pornography was just a very small portion of it. The majority was just bizarre porn. He was being hit with everything," she added. Are you still so certain of your position?
512 MB RAM, 20 GB disk, 200 GB transfer, five datacenters. $19.95/month.
And let us not forget even trusted websites can get compromised,so for all we know this guy was surfing a legitimate website and got hit by a driveby or one of the many exploits that had been released since his machine no longer was updating. I personally hope he gets enough out of them in a lawsuit that he never has to work again. It is obvious to me they never bothered to look at the laptop except to look for porn,and the fact that it was THEIR OWN SCREWUP that caused this in the first place should make it a slam dunk for any decent lawyer. But as always that is my 02c from many years of fixing Windows boxes,YMMV
ACs don't waste your time replying, your posts are never seen by me.
How about stop going around being so trigger happy about sacking and prosecuting people for such "crimes"?
How about actually following the money trail? Are the malware authors and people putting those images up really doing such stuff for free? Someone must be paying for those ads, the creation of child porn sites etc.
There are more serious crimes than possession of some image file, especially an image file that is likely to be downloaded by malware.
Lastly, Linux isn't going to help. The real problem is mass hysteria - lots of people suddenly turning their brains off when they hear a trigger phrase. Sure child porn is bad, but if you really want to fix it, follow the money to the bitter end. Not go around starting stupid witch hunts. The way they do things, I figure it's just a tool for cynical manipulation of a mindless populace.
You can't imagine the world of crap awaiting that guy had you reported him. It would have been a problem that would probably haunt him for the rest of his life. My spouse recently almost lost her job after a 40 year old arrest for dope surfaced in the FCIC database after a background check. Nevermind that she has a clean record since 1968, and has tirelessly worked with youth groups, sunday school, Boy/Girl scouts and extremely active both at church and the community. In fact, the official arrest /court records don't even exist after a 1997 fire at the courthouse destroyed everything.
As a computer professional, I'm shocked that Georgia went back so far in time to key that data into the database.
You definitely did the right thing. Definitely.