Slashdot Mirror


San Francisco DA Discloses City's Passwords

snydeq writes "The office of San Francisco District Attorney Kamala Harris has made public close to 150 usernames and passwords used by various departments to connect to the city's VPN. The passwords were filed this week as Exhibit A in a court document arguing against a reduction in $5 million bail in the case against Terry Childs. Though they placed the passwords in the public record, city prosecutors do seem to think that they are sensitive. InfoWorld's Paul Venezia, who has been following the case closely, provides further analysis of the technical details in the city's case. 'By themselves, [the passwords] would not be enough to allow anyone to access the network via VPN,' Venezia writes, 'but the fact that the city entered them into evidence is quite shocking. At the very least, they'll have to shut down their VPN access for awhile until they've changed them all and modified the configurations of some large number of VPN clients.'"

15 of 333 comments (clear)

  1. Ah HA! by clang_jangle · · Score: 5, Insightful

    AH HA! See, Childs was right , he is the only competent one!

    --
    Caveat Utilitor
    1. Re:Ah HA! by Volante3192 · · Score: 4, Insightful

      Bad IT policy, or bad users? IT is sadly not as much a dictatorship as we'd like. If enough users whine, it ends up being policy that passwords get lax. These users "are too important to have to come up with complex passwords incorporating at least 3 different character types in 8 or more characters"

      Make password policies too complex, users just write them down. Frying pan, fire...welcome to IT.

    2. Re:Ah HA! by _Sprocket_ · · Score: 5, Insightful

      Childs' defense attorney has got to be happy about this.

      "Your Honor.. I would like to direct the Court's attention to Exhibit A; the mere existence of which proves our case..."

    3. Re:Ah HA! by GameboyRMH · · Score: 4, Insightful

      My first thought. Whenever a password is stored in a form that it could be retrieved (rather than only reset), the users should be notified beforehand, otherwise it's just unethical IMO...not to mention the security issues.

      --
      "When information is power, privacy is freedom" - Jah-Wren Ryel
    4. Re:Ah HA! by crath · · Score: 5, Insightful

      Therefore, it should be his job to keep this document so that he can provide the users(of the proper departments) with their proper access credentials.

      There are NO circumstances under which one user should possess another user's password; not even an Administrator. The only exception to this rule ever allowed is when the account is first created: when a one-time use password is assigned by the Administrator; however, in a world-class IT infrastructure (such as an enterprise like the city of SF can afford to implement) an application creates and assigns a random password and then communicates it to the user via secure means (with no person seeing or having access to that password).

  2. Dang! by Ungrounded+Lightning · · Score: 5, Insightful

    AH HA! See, Childs was right , he is the only competent one!

    Dang! You beat me to posting about it.

    Wasn't part of Childs' point that password security in the S.F. government was lax and that divulging the big one in a way that would spread it around was dangerous to the network?

    Given that the configurations on the routers weren't saved, the first guy to use that password on them had better be DARNED careful to get them recorded before changing anything or he's likely to break the network big time. So handing it to an administrator, who will hand it to several people, any of whom might leak it, could cause the net to come crashing down.

    If all they'll let him do for a handoff is hand off the passwords, I can see how a prima donna BOFH would want to hand the big one directly to his successor, who would then spend the next week carefully recording the configs as-running before making changes or sharing the password with less-skilled delegates.

    Not that it's right. But looks to me like the city is making his point for him - which his lawyer should use in a counter-argument at the bail hearing. B-)

    --
    Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
  3. Being paranoid doesn't mean you're wrong by pembo13 · · Score: 4, Insightful

    Even if the sysadmin referred to as 'Childs' was a paranoid schizophrenic, does not mean he wasn't right.

    --
    "Thanks for all the money you paid to us. We've used it to buy off ISO among other things" -Microsoft
  4. Another interesting thing came out in the filing. by Ungrounded+Lightning · · Score: 4, Insightful

    According TFA, the thing about his not saving the configs to flash is a CLAIM by the city, not something confirmed by Childs.

    So how do they KNOW that, if they don't have the passwords? Did they try rebooting some network boxes and have them not come up? (If so, how is it that the net is still running...)

    This is looking more and more like a pointy-haired-boss SNAFU than logic-bomb job-insurance/revenge sabotage.

    --
    Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
  5. Re:Suddenly Childs seems quite normal by John+Hasler · · Score: 4, Insightful

    > ...he didn't really have the authority to do that...

    You don't know what he did. You only know what the aforementioned "fuckwits" allege that he did.

    --
    Warning: this article may contain humor, sarcasm, parody, and perhaps even irony. Read at your own risk.
  6. Re:Suddenly Childs seems quite normal by actionbastard · · Score: 5, Insightful

    "...because he didn't really have the authority to do that..."
    But his supervisors and everyone in his department knew he was the only one -the 'go to' guy- that really had the in-depth knowledge to figure out problems and make stuff work. If they let him do that without objection or questioning his reasons, they gave their tacit approval to allow him to operate in the fashion that he did.

    --
    Sig this!
  7. Re:RTFA by Anonymous+Psychopath · · Score: 4, Insightful

    They aren't worried about releasing him on bail with what they know Child's knows. They are worried about what they don't know that he knows. Perhaps the copy of the password file found on his office PC is not the only copy? How could you know that he doesn't have it on a USB key in a safe deposit box or something along those lines. I wouldn't want him where I couldn't keep an eye on him until everything he had access to (and probably everything I didn't think he had access to) had undergone a complete audit.

    --

    Eagles may soar, but weasels don't get sucked into jet engines.

  8. Re:The reason for password disclosure by Anonymous+Psychopath · · Score: 4, Insightful

    from TFA --

    The username/password combos were apparently functioning sets. The DA is saying they found them on Child's own computer. The DA is all in a tizzy because Child's could then use these accounts to sneak into the system and cause mischief without getting tracked back.

    Right. The only guy in the world with God level access to this network needs fake usernames/passwords so he can 'cause mischief'?

    Give me a fucking break. I can think of many reasons for him to have those combos on his personal system.

    1. He's checking to see what naughtiness has already happened with those accounts

    They should have (but maybe do not) procedures for suspicious accounts. If they don't Childs should have created and documented one.

    He's got accounts so he can log in with a lower level of access and see what's accessible

    More reasonable, but 150 of them? That doesn't seem plausible.

    These are usernames/password combos that he sniffed off the network, during routine security testing.

    Possibly, but why did he need to keep a copy of the password file? If his goal was to uncover security vulnerabilities, it isn't necessary to keep the credentials uncovered.

    These are people with accounts that have had some kind of trouble, and he's got them so he can attempt to diagnose problems linked to user level access.

    It is not standard nor best practice to ask a user for their password, ever. If you need to access their account, you use admin privs to change their password, do whatever needs to be done, then ask the user to change it themselves when you no longer need access to their account.

    It's a list of post-it pad's he's seen while walking around at work, and he'd been planning to inform the users to change their passwords.

    You need the user's name for that. Not their login ID and password. Also, the number of passwords in the file makes this implausible.

    They're the output list of a password security checker.

    I think this one is redundant. While it is best practice to examine the security of your own network, it is not common nor reasonable to keep an archive of usernames/passwords uncovered.

    Apparently the less than brilliant DA's office is unaware that the GOD level admin has the ability to do anything at all on the network and REMOVE ALL TRACES IN THE LOGS afterwards. It's trivial, when you're the one who runs the tattletales.

    Dear DA office: IF YOU LOOK HARD YOU'LL UNDOUBTEDLY FIND EVIDENCE TRACY EAVESDROPPING ON THE NETWORK SNIFFING AND ATTEMPTING TO ILLEGALLY PENETRATE THE SYSTEM. IT'S PART OF HIS JOB, MORONS. IF YOU KEEP BRINGING THIS CRAP UP, YOU'LL ONLY LOOK STUPIDER.

    Keep this up, and Nifong will have company in the 'worlds dumbest DA's club'

    I think you should examine the well-documented, published, and logical security & administration best practices. Keeping a password list on a PC is a great way to compromise your network. If it turns out that these are, indeed, valid user security credentials, Childs doesn't appear to know the first thing about information security.

    --

    Eagles may soar, but weasels don't get sucked into jet engines.

  9. Re:The reason for password disclosure by dreamchaser · · Score: 4, Insightful

    It is not standard nor best practice to ask a user for their password, ever. If you need to access their account, you use admin privs to change their password, do whatever needs to be done, then ask the user to change it themselves when you no longer need access to their account.

    Actually that IS standard practice...but for desktop techs, not admins. I often have to admonish people for this, but it's quite a common practice to get the user's password so as to facilitate service. It certainly isn't a best practice, but it's a common one and in most cases it inconveniences the user far less.

  10. DA is retarded by jackspenn · · Score: 4, Insightful

    Well since the Constitution grants him the right of discovery, if that was the only copy, all Childs has to do is file a motion to see the evidence against him to obtain those usernames and passwords, plus because they were entered into a court record, if he or a friend were to launch an attack or whatever, he would have reasonable doubt given that any court clerk, judge, DA, case officer, police officer, citizen/group/reporter filing open record request, etc. can now see it. Better still if the system were hacked while he was in jail he could use it as defense saying "Hey, when I was running things the network remained secure, but as soon as I was removed it was compromised so how can the DA suggest to the jury that I was somehow putting the network at undo risk? The facts suggest otherwise. Just imagine how cool it would be to read on /. that this happened? Hum?

    Honestly the more I read about this the worse SF managers and the DA look. How dumb are they, I mean they are disproving their own case, if I were Childs' lawyer, I would ask this question to the DA in front of the jury "Just so I get this straight, because I am a simple man, you are telling us that this information was so confidential and put the city at so much risk that you publicized it yourself the same day that you made a statement about the dangers of Childs potentially releasing the information? Did you make sure the passwords and usernames were changed before doing so? Isn't it possible that the usernames alone being published could create a target point for hackers to work from? Allowing them to launch either DOS attacks if lockouts are set on thes accounts or to continually work on cracking passwords if no lockout is set? Do you even have the technical knowledge to understand the details of this case without you yourself putting the city at risk like you 'allege' my client has? If Childs put the city at risk by having it on his computer and deserves jail time, what punishment should you get for filing it into the court records? Didn't security concerns worry you? Where is the confirmation the passwords were updated or the account deactivated before you entered sensitive information with the court?"

    This is out of a comic stripe, SF is run by idiots. Childs is not the problem it is those that let him control everything so long as he did their work for them. Those are the people who should be on trial. It is a retarded DA that is 1). Putting city systems are risk for a prosecution and 2). Given the defense more ammunition.

    --
    Respect the Constitution
  11. Re:The reason for password disclosure by remmelt · · Score: 4, Insightful

    Please, no biometrics. I can change my password/smart card/whatever else quite easily, but I can never change my iris or fingerprints or what have you.