Slashdot Mirror


SF Not an Exception In Giving IT Too Much Control

CWmike writes "The city of San Francisco's IT department is certainly not the exception when it comes to allowing just one person to have unfettered rights to make password and configuration changes to networks and enterprise systems. In fact, it's a situation fairly common in many organizations — especially small to medium-size ones, IT managers and others cautioned in the wake of the recent Terry Childs incident."

21 of 245 comments (clear)

  1. God complex by daveywest · · Score: 4, Funny

    What was it they said in the 80's about the most common admin passwords?

    1. Re:God complex by pwnies · · Score: 4, Funny

      "1, 2, 3, 4, 5...the kind of thing an idiot would have on his luggage"
      -Spaceballs, 1987.

    2. Re:God complex by oodaloop · · Score: 4, Funny

      That is the combination to my luggage, you insensitive clod!

      --
      Tic-Tac-Toe, Global Thermonuclear War, and relationships all have the same winning move.
    3. Re:God complex by ShieldW0lf · · Score: 4, Insightful

      The subject of the article is about one central admin having too much control over too many machines, and the risks that entails when they go bad.

      Which makes a person wonder... how much worse when billions of consumers are giving total control over all their machines to a centralized authority through Trusted Computing and Vista?

      I mean, what happens when Microsoft goes bad?

      --
      -1 Uncomfortable Truth
    4. Re:God complex by smooth+wombat · · Score: 5, Insightful

      and the risks that entails when they go bad.

      It's not just when they go bad. What happens if they get run over by a bus or a stampede of wildebeests? If they are the only person to know the admin passwords, commands, etc, they are the single point of failure, regardless if they go bad or not.

      Just as we harp on backing up our files (um, yeah), we also need to harp on a backup for the admin. There should always be someone else, even if it's the mayor, who also has the list of admin passwords.

      --
      We will bankrupt ourselves in the vain search for absolute security. -- Dwight D. Eisenhower
    5. Re:God complex by JCSoRocks · · Score: 4, Insightful

      I use the bus example pretty regularly. It's the same reason that I expect documentation for everything. Is writing documentation fun? no. Is it necessary? Perhaps not... but does it save days, or possibly weeks from being wasted? Yes.

      As far as I'm concerned... passwords are just the beginning. Configurations and such can also be a nightmare to replicate when they're undocumented. Ever stepped into a project where they only guy working on it is gone and you have to figure out how to setup your machine / development environment just to get it to run? It's awful. All of the "don't install that patch, it ruins everything" or "you have to install these components in this order so that they don't interfere with one another" is gone and you have a horrific puzzle before you.

      --
      You are using English. Please learn the difference between loose and lose; they're, there, and their; your and you're.
  2. It will happen again, and continue to happen. by pwnies · · Score: 4, Insightful

    I really think this type of thing is inevitable with this high level of a network admin. There comes a point where the complexity of the network you manage means that you simply can't report all the inner details and workings to a manager or overseer. Not only that, but with the speed that computers advance, hardware becomes obsolete within a decade, and new talent often times wont have knowledge/capabilities/will to deal with the older hardware that builds up in operations such as these.

    Sadly I think the only thing one can do with things this size, is appoint someone and pray he isn't chaotic evil.

    1. Re:It will happen again, and continue to happen. by The+Warlock · · Score: 4, Insightful

      No, that doesn't work. What if, instead of just refusing to divulge the password, Childs had shot himself in the head or gotten hit by a bus or something. He locked down his network so well that only through a password that was only in his head could anyone have admin access.

      --
      I've upped my standards, so up yours.
  3. Here come the elephants. by Harmonious+Botch · · Score: 5, Insightful

    I forget who said that "an elephant is a mouse designed by a committee." Sure, you can get paranoid about network design and control, and give the job to a committee. But that is going to be really clumsy.

    The issue here really is not about size of the design team, it is about vetting the guy who does it. ( The guy who is in charge of the network for my business is someone who I really know and trust. He was best man at my wedding. )

    1. Re:Here come the elephants. by Spad · · Score: 4, Funny

      So he's going to change all your passwords *and* run off with your wife?

  4. Not news to nerds by iamhigh · · Score: 4, Informative

    They claim that you should have more than one person that knows the password and configuation of the network. I work mainly in small-mid sized business; I have never heard of only one person knowing the password. In fact, the smaller the business, the more the owner wants to know the password (IME). Generally IT doesn't want $random_user to have the admin passwords. Also, everyone that has them is another person that can potentially "lock down" the system (see third para).

    The configuration? Well I am not real sure what they mean? Basic configs such as IP addreses and such have been documented at even the shoddiest implementations I have seen. Plus, if you know how to run that server, you probably know or can find and make changes to the "configuration". But if there is only one person at that company that knows that server/technology, well then there is probably only one person that knows the configuation! What should the accounting manager know how to run our servers?

    But the bigger issue is that in a SMB, and in my current positions, I could CHANGE THE PASSWORD!!! Doh, they forgot that you can do that!

    TFA goes on to say things about hiring an administrator and then an auditor for the admin. WTF? Never heard of this happening in my career. I do know the military uses these methods, but that makes sense for them. The average sign printing company (even a 200 employee company) can't do that.

    TFA highlights a situation that we all knew existed... and didn't even give a (reasonable) proposed solution.

    --
    No comprende? Let me type that a little slower for you...
  5. You asked for it, you got it. by mrroot · · Score: 4, Insightful

    When you have already laid off everyone and downsized your IT department to so few employees, its kind of hard to avoid having a single person with so much power.

    --
    I Heart Sorting Networks
  6. This is silly by peipas · · Score: 4, Insightful

    Of course there will be people in IT who have power, and of course that power can be abused.

    Somebody at a television network has the power to broadcast rocking horse porn if they want to as well and there is no time machine to unrock that horse.

    The articles hypes up one person being able to abuse power as if it were unique to IT and suggests a remedy that more than one person should have this power, as if this had any bearing on anything, e.g. the ability for the abuser to simply revoke access to others. What, somebody else should be assigned the exclusive ability to revoke? Then that person is the potential abuser. This is silly.

  7. What "incident"?? by Jane+Q.+Public · · Score: 4, Insightful

    Apparently, a bunch of idiot managers realized all of a sudden that they had GIVEN one person control over a major network, and tried to seize back control. Also apparently, he did not trust them to keep it running properly. (And also apparently, rightly so.)

    So where is the "incident"?? What did he do wrong?

    By law he might have done "wrong" by not relinquishing the passwords immediately. But by the people of San Francisco, he may have saved them a lot of trouble and headaches. So, he was faced with a dilemma: obey the law, or do the right thing.

    Sad.

  8. Not qualified to comment. by Shaitan+Apistos · · Score: 5, Funny

    Whenever I register for a site where my email address is my username, the password I use happens to be the same password that I use for my email account.

    With that in mind, I'm going to go ahead and not express any opinions on security.

  9. HA! by Splab · · Score: 4, Interesting

    As if it's ITs fault. Most companies I've worked at I have pointed this very situation out and usually get overruled based on the cost of doing it "right".

    (It isn't enough to have several people with the password, you need to know how to recover if you lose total communication with the guy responsible - ig. died.)

    Also it isn't just IT. Last months pay got delayed at my company, which really shouldn't happen since KPMG is responsible for taking care of payments for our company. The reason? The lady responsible for authorizing the transfer was the only one with the passwords to do so, and she was in labor.

  10. A Lesson from Star Wars by jackspenn · · Score: 5, Insightful

    Some people on /. think it is best to have one knowledgeable person with all the information so that confidential information is not leaked or changes made without the lead guy being aware.

    Others think of the bus rule, what happens if the guy who knows everything about mission critical infrastructure components gets hit by a bus?

    That is why I have taken a page from the Sith Lord Darth Bane and apply the rule of two. When I build a network I teach and train one apprentice. Then if they suck I fire them and hire a replacement, but if they are good, when I get bored and decided to move on, I feel confident they can take on a apprentice themselves.

    It is neat, clean and simple, better still it doesn't have the rules and complexity of Jedi type systems requiring me to check in docs to a source control system, report changes to managers what don't understand, have managers that don't understand sign-off on things they don't understand and avoid dumb rules like not being able to train techs that appear to old, etc.

    Yeh, if you ask me the Republic, I mean Network as a whole is best off with Sith types in charge versus bureaucratic Jedi types.

    --
    Respect the Constitution
  11. The Childs story stinks like five day old fish by 99luftballon · · Score: 4, Insightful

    The more I see on this case the more I think Childs is being set up as a scapegoat. The guy built the networking side from scratch and it seems management were happy with him running it with sole admin rights. Then a new admin comes in and he freaks out and gets overprotective. And a $5 million bail? Murderers don't get that much.

  12. That's not all they're asking for by Nymz · · Score: 4, Insightful

    Everyone knows the name of Terry Childs, but how many people know the name of the manager(s) in charge, the ones responsible (or negligent) for letting this situation continue until it got to this point.

    "You asked for it, you got it." and you are spot on because if they don't correctly assess this current situation, and assign blame to the deserving names, then they are only 'asking for it' to happen again and again.

  13. Less control... how about more staff? by phorm · · Score: 4, Insightful

    Seems to me that in many cases, the IT department may be rather grossly understaffed (either in terms of # of staff, or # of experienced staff).

    Many places I've worked end up with a Lord-of-all-IT situation simply because they haven't got anyone who can replace him* or back him up, or weren't willing to pay for backup/additional/experienced staff.

    * male gender used for convenience purposes.

  14. Banks deal with this by mlwmohawk · · Score: 5, Insightful

    One of my first jobs was a bank teller. Our passwords were sealed in an envelop, which we initialed, and locked in a vault which needed two keys to open.

    If the two officers needed my password, they'd open the vault, open the envelope, breaking my seal (letting me off the hook of responsibility).

    IT has to learn from banks.