Slashdot Mirror


3 of 4 Charges Against Terry Childs Dropped

phantomfive writes "Terry Childs, who was arrested nearly a year ago for refusing to turn over the passwords to San Francisco's FiberWAN network, has been cleared of three of the four charges against him. The dropped charges referred to the attachment of modems to the network; the remaining charge is for refusing to turn over the password. The prosecutor has vowed to appeal, to have the charges reinstated. We have the original story, and the story where Childs tells his side, for those who want a refresher."

38 of 189 comments (clear)

  1. Witch hunt by joaommp · · Score: 5, Insightful

    Always seemed to me this was not much more than a witch hunt. Why else would them set a bail higher than for killers and rapists?

    1. Re:Witch hunt by Anonymous Coward · · Score: 5, Insightful

      politics 101. pissing of the ones in power is the worst crime you can commit.

  2. 1M bail and 1yr in jail...? by Manip · · Score: 4, Insightful

    I'm sorry but this guy has already had time served. Even if they do find him guilty one year in jail for what he did is far more than enough. Plus 1M bail? Is he a violent criminal? ...

    This sounds like a classic story if ignorant people making decisions about technical crime and getting scared. I aim that both at the city and at the judge who set the original bail.

    We need special technical trials for things like this within which both the defence and prosecution are allowed to bring in technical witnesses to put the case into perspective for non-technical people (as opposed to "HACKER! Get the pitch forks!").

    1. Re:1M bail and 1yr in jail...? by Seumas · · Score: 5, Insightful

      Ignorant people are afraid of the technologically savvy the same way they are afraid of science. They don't understand it, so rather than bettering their knowledge and informing themselves, they'd rather fear the worst and attack those who represent a threat (that is, those who know something they don't).

      Also, why didn't the guy just say "dude, it was a complex random password and I've completely forgotten it"? They can't force you to give them a password that you've forgotten, surely? Also, is a partial "moral victory" really worth an entire year of your short life span?

    2. Re:1M bail and 1yr in jail...? by LordKronos · · Score: 4, Insightful

      We need special technical trials for things like this within which both the defence and prosecution are allowed to bring in technical witnesses to put the case into perspective for non-technical people

      Huh? Special technical trials? Why? The current system already allows lawyers to bring in expert witnesses to explain stuff. And lawyers are allowed to do a bit of story telling during their opening and closing arguments, and they can use that opportunity to explain thing in other terms (including car analogies, if they choose).

      A lot of us around here always complain about legislature creating special laws to make illegal things that are already illegal under an existing law. Let's not turn it around and start asking for special trials when the cases can already be accommodated by the existing court system.

    3. Re:1M bail and 1yr in jail...? by MrKaos · · Score: 4, Insightful

      This sounds like a classic story if ignorant people making decisions about technical crime and getting scared. I aim that both at the city and at the judge who set the original bail.

      There is a saying, There is no such thing as a bad student only a bad teacher. If the legal system is ignorant about how 'technical crime' should be addressed it's because we, as technology professionals, have failed to lobby for the appropriate changes to be made to law to handle these cases properly.

      We need special technical trials for things like this within which both the defence and prosecution are allowed to bring in technical witnesses to put the case into perspective for non-technical people (as opposed to "HACKER! Get the pitch forks!").

      Why? The framework for all of these things already exist in the legal system. All this world changing technology has been unleashed over the last decade or two and Information Technology is maturing as a profession. It's a bit unrealistic to expect the legal system to make quality decisions about how the law should be adapted to handle those changes while the people responsible for delivering the technology do not get involved in educating those who can codify the law to behave reasonably.

      It ridicules us to point the finger and say 'look at how ignorant they are' when in reality we should be more self critical and understand that this is the treatment we should expect if we are too apathetic to influence the legal system appropriately.

      --
      My ism, it's full of beliefs.
    4. Re:1M bail and 1yr in jail...? by Jah-Wren+Ryel · · Score: 4, Insightful

      Huh? Special technical trials? Why? The current system already allows lawyers to bring in expert witnesses to explain stuff. And lawyers are allowed to do a bit of story telling during their opening and closing arguments, and they can use that opportunity to explain thing in other terms (including car analogies, if they choose).

      Once upon a time a "jury of your peers" really meant peers, and not just the most easily swayed people in the jury pool. I'm not saying every single person on the jury needs to be a network engineer, but you can pretty much count on the prosecutor objecting to anyone in the pool with any technical expertise relevant to the case.

      So, not special trials per se, but a process that rules out anyone with domain knowledge relevant to the trial is fundamentally broken. The number of really bad car analogies that get made here everyday among the relatively technically astute should be proof enough that requiring the issues to be dumbed down for an uneducated jury is not a very good way to run the system.

      --
      When information is power, privacy is freedom.
    5. Re:1M bail and 1yr in jail...? by Hurricane78 · · Score: 4, Funny

      Well, they should be afraid. Because I'm going to kick their asses for their ignorance!

      (*blend to underwater lair under a volcano*)
      Release the sha... what?... OK, the sea bass...

      MUHAHAHAAAA

      --
      Any sufficiently advanced intelligence is indistinguishable from stupidity.
    6. Re:1M bail and 1yr in jail...? by Yetihehe · · Score: 4, Insightful

      There is a saying, There is no such thing as a bad student only a bad teacher.

      You haven't seen some people who don't want and/or are incapable of learning the most basic scientific facts. Yes, you could spend with them 5x the normal time for normal student, but is it really worth it? We need someone to clean the streets, and really intelligent ambitious people don't really want to do it. Typical street cleaner doesn't need to know what an Ohm's law is.

      --
      Extreme Programming - Redundant Array of Inexpensive Developers
    7. Re:1M bail and 1yr in jail...? by Zombywuf · · Score: 5, Informative

      He didn't say he'd forgotten it because he was simply doing what his job description told him to do. He was called into a room with a dozen people he didn't know, he refused to hand over the password to these people. When a single person (the mayor) who was authorized to know the password asked for it, he handed it over without hesitation.

      --
      If you can read this you've gone too far.
    8. Re:1M bail and 1yr in jail...? by ScrewMaster · · Score: 5, Insightful

      With respect, none of this is as complex as DNA and other forensic evidence which is handled quite well in criminal trials every day.

      With equal respect, have you ever been through jury selection? I have (a number of times unfortunately: every time I move they waste a day of my time not selecting me) and the GP is correct. The system selects for the most ignorant of any issues relevant to the proceedings, and anyone who could be presumed to have knowledge of mathematics or statistics suffer the first peremptory challenges issued. Don't want someone who can see through the numbers the trial lawyers and their expert witnesses pull out of their nether regions. I'm just a software engineer, and every god damn time I was asked what I do for a living I was promptly removed from the jury. The people that were left were often very nice people (you get to know some of your potential fellow jurors in the jury pool beforehand) but not people that I would want on my jury, if I were accused of a computer crime ... especially if I were innocent. The naked fear so many individuals have of computers, and especially those who are accused of computer crimes is unnerving. Fear of the unknown is not intrinsically irrational: but fear of gaining understanding is.

      All the juries I've (almost) been on are filled with people to whom a trial about computer systems is, in fact, just as unfamiliar and frightening as a trial involving DNA or other complex evidence, and might just as well be about DNA so far as their level of understanding is concerned. The idea of a technical court is not a bad one at all, particularly given the importance of sophisticated science and technology to all of us, not just those with technical backgrounds. Imagine judges with engineering or science degrees running the show in such trials. Honestly, if we had such courts the patent system probably wouldn't be broken and the RIAA would have been laughed out of court from day one. I can just see a judge who just incidentally happened to have a degree in computer science asking an RIAA attorney: "So, you're claiming that a logged IP address infallibly identifies an individual copyright infringer? Hm. Not on this planet, bucko."

      Truly, in these times ignorance is not bliss, and we as a society are paying the price for allowing our adversarial system to dumb down those who judge us. Remember, our justice system was developed in much simpler times. The pace of change being what it is, it's too much to expect the law itself to always be on top of things, but it shouldn't be too much to expect our juries to really be composed of our peers.

      --
      The higher the technology, the sharper that two-edged sword.
    9. Re:1M bail and 1yr in jail...? by sumdumass · · Score: 4, Interesting

      Speaking of incompetent but well meaning people on the jury, I used to work with a girl who sat on a jury trial over a murder where two boys (14 and 16) shot and killed some girl who was obsessed with one of them, enlisted the help of his mom and another friend (a 19 year old woman) who took the body to a barn across the county and caught it on fire.

      This girl on the jury came into work after the first day of trial and told us they were going to fry if she had anything to do with it. I wrote a letter to the judge and defense attorney about this. She was left on the jury and the death penalty was taken off the table. I was also arrested and brought before the judge and told that if I threaten a juror it was a felony and so on before being release 5 miles away from my car with no way to get home but walking with no charges ever being filed. I was totally flabbergasted and had no idea what was going on. The jury was then sequestered.

      Years later, someone else that used to work there told me she had told the judge that she only said those things because I kept telling her to convict the people. I never spoke to her directly, I was just there when she was bragging about how much power the jury had (and hence, how much power she had because of it) I guess I had the same last name (no relation) as one of the defendants and throwing me under the bus was her way of making sure they paid while she stayed out of trouble.

    10. Re:1M bail and 1yr in jail...? by Anonymous Coward · · Score: 4, Interesting

      I have to disagree with your entire statement. Lawyers are busy people, a lot the local ones are my clients.

      They don't have time to learn more about anything other than law.
      There is no way to educate someone who doesn't have a desire to learn, or who has themselves convinced that they don't have time to learn.

      Some of my clients ask for my opinion on cases, and I've been an expert witness on 2.

      One good example is this one. A local kid "cracked" into his schools (completely unprotected) "teacher only" network share and looked at his grades, then told the "network administrator" (read:80year old librarian) about the security issue.

      A month later, some grades were changed in this system (still unprotected to this day btw) and they threw the book at this kid.

      I can access this system from the parking lot, with my cell phone.

      After explaining this to the court, the prosecutor still insisted that the kid must have hacked into the system because of half of an answer to a single question,

      Lawyer : "Are you suggesting that any one member of the jury could have done this easily?"
      Me: "Probably not, but" >> "Thank you, no further questions."

      When the expert witnesses get cut off in the middle of their explanations, how in the hell are we supposed to educate anyone?

      Fyi, the kid was released because someone else went in and deleted the entire network share while he was still in jail.

    11. Re:1M bail and 1yr in jail...? by sumdumass · · Score: 3, Interesting

      I was young, about 19 at the time. I could have handled it different and trust me, with hindsight, I would have. I thought I was doing the right thing and it left me very scared to do anything else at the time. I'm not that way any more and I'm willing to stand up to them if nothing else but to get my chastising them onto the public record.

      The country I live is is really corrupt (well it appears that way). When I was a kid, the sheriff had his house blown up by some Mob associates because he decided to close down a gambling hall and run it himself. He quit and his replacement has lost an election some 10 years later because drug dealers were complaining that they didn't touch drugs until the sheriff recruited them to do sting operations in which all traces of the drugs except those used to convict them disappeared. Evidently the sheriff was framing people in order to show results at a time people were demanding others to be tough on crime. The sheriff after that is currently serving time in federal prison for embezzlement and something else. The then 30 year tenure chief of police of the nearest town and county seat resigned without pension to avoid charges of embezzlement, improper allocations of public resources and systematic mistreatment of prisoners along with a few allegations of planting evidence made on a couple officers who resigned also.

      It appears to have taken about a 8 year lapse in corruption but I was recently (2 years ago) threatened by a police officer in the lobby of the police station over wanting to file a complain for misconduct against another officer. I handled that entirely different and went to the mayor, the state and federal attorney generals office, and even called the FBI who was investigating another corrupt sheriff a county or two away. I can't really do anything to him for it because he didn't act on the threats which he kept vague and the audio to the surveillance system was somehow turned off ten minutes before I got there and turned back on a half hour after I left. The video shows anger on both out faces but he kept his back to the cameras when speaking. But I am privy to an internal disciplinary action on the officer who was order to take an anger management class on his own time and a refresher course on dealing with the public on the department's dime. I also got an apology from the deputy director of the police force and the mayor went to bat with me to make sure that no threats would be followed through with.

    12. Re:1M bail and 1yr in jail...? by i.r.id10t · · Score: 3, Funny

      So... if Childs floats, the must be guilty right?

      --
      Don't blame me, I voted for Kodos
    13. Re:1M bail and 1yr in jail...? by budgenator · · Score: 3, Insightful

      You do realize that there is a truck driver that knows so much about the nuclear weapons built in the 1940s and '50s that he has been invited to give presentations at Los Almos. Some people like menial labor because it give them the opportunity to think about things they are more passionate about.

      --
      Apocalypse Cancelled, Sorry, No Ticket Refunds
  3. But Why Go to the Trouble? by mpapet · · Score: 3, Interesting

    I opined on the last story that he was playing the 'power game' from the bottom of the political strata. By most accounts he was at the top of the network knowledge, so a technically important guy. 'Network God' doesn't translate into political power and he got burned.

    But what else is in the plea deal? I can't help but think there's waaaay more to the story given the political heat this guy brought on himself. Maybe the plea deal keeps him quiet?

    --
    http://www.maxineudall.com/2010/02/should-economists-be-sued-for-malpractice.html
  4. Excelent way to link to that interview. by MartinSchou · · Score: 4, Informative

    Link to an old Slashdot story that then links to an archive page that doesn't even have the word Childs on it.

    You have to go to page three of the archive to find the bloody interview!

    Why the hell is it so difficult to provide direct links to the actual articles?

    1. Re:Excelent way to link to that interview. by MartinSchou · · Score: 3, Interesting

      *sigh*

      Apparently that wasn't the interview either. Where the hell is that interview?

      It's like watching cable news doing a circle jerk talking about how a twitter post talks about a blog post that mentions an article that refers to an interview where the reporter asks a question about something, but no one even cares about showing the relevant clip!

    2. Re:Excelent way to link to that interview. by Zak3056 · · Score: 4, Interesting

      I dont see that happening on NPR or other reputable new sources.

      NPR doesn't show video clips at all. :)

      All kidding aside, I think you have your blinders on. I listen to NPR for, on average, an hour a day (most of my morning and evening commutes) and while I find them to be superior to most other news outlets other than the BBC, there have been plenty of times that I've noticed them talking about something at length, before playing the source material (and sometimes they don't play the source material at all), which is the exact behavior that the GP described. I also listen to right wing talk radio, and while the entire reason that they seem to exist is to program responses into people, their methods of doing so are a bit different. Someone like Limbaugh or Hannity absolutely loves playing soundbites (original source material in this case) over, and over, and over, but they're often taken out of context or referencing a slightly (in some cases completely) different subject.

      --
      What part of "shall not be infringed" is so hard to understand?
  5. Re:Actual crime by GaryOlson · · Score: 4, Insightful

    ...sufficient to keep him from being hired...

    After this thorough exposure and experience with the legal profession, law firms should be recruiting him. Not to mention his arrogance and narrow focus on a crucial point of fact indicates he would fit well in with lawyers of the same personality traits.

    --
    Every mans' island needs an ocean; choose your ocean carefully.
  6. Charges were not dropped... by Anita+Coney · · Score: 5, Informative

    I don't have to read the article to know that. If the charges were dropped, the prosecutor would not be vowing to appeal. When a judge gets rid of charges, they're dismissed. When a prosecutor voluntarily gets rid of charges, then they're dropped.

    --
    If someone says he and his monkey have nothing to hide, they almost certainly do.
  7. Re:Actual crime by dbIII · · Score: 3, Insightful

    And the details of the offense (hostage-taking to avoid a pink slip)

    I'm not really sure that makes sense either but we should know soon. It really just looks like management that was so spectacularly bad that they called in the police to handle a simple workplace dispute. It should have been escalated up the chain away from these clowns to some form of adult supervision before calling in the police.
    Just a bit of wild speculation here, but it will be very interesting to find out if the inexperienced "IT security" person that sparked all this off is a relative or lover of the new management that handled this all so badly. If I found a complete stranger wandering about removing hard drives containing sensitive information I would be asking rude questions, taking photos and making threats about calling the police as well. The only way you tell a surprise security audit from a robbery is by having someone known within the company follow them around to avoid STUPID situations like this. If a manager can't get anyone or do it themselves they really have to put in their notice and get a job with less responsibility.
    Very wild speculation here, but wouldn't it be funny if the entire thing was revenge for making the new manager's mistress cry?

  8. Overzealous prosecutors by MikeRT · · Score: 4, Informative

    It's a little known fact that prosecutors cannot be sued for anything they do in court to a defendant. Prosecutors are truly the worst part of the system since they are unaccountable to the public and are rewarded for getting convictions, not enforcing the law wisely. As a profession, they are so corrupt that they make civil lawyers look sympathetic since civil lawyers are at least limiting themselves to cases where you can kinda sorta see how their client was genuinely harmed.

    1. Re:Overzealous prosecutors by Attila+Dimedici · · Score: 4, Interesting

      It's a little known fact that prosecutors cannot be sued for anything they do in court to a defendant. Prosecutors are truly the worst part of the system since they are unaccountable to the public and are rewarded for getting convictions, not enforcing the law wisely. As a profession, they are so corrupt that they make civil lawyers look sympathetic since civil lawyers are at least limiting themselves to cases where you can kinda sorta see how their client was genuinely harmed.

      Most prosecutors answer to the District Attorney, and can be fired by the DA almost at will. The District Attorney is an elected official. In those cases where the prosecutor doesn't answer to the elected District Attorney (or essentially the same office with a different title), they answer to the elected head of the of the executive branch of whatever level of government they represent (Mayor, Governor, President, etc). If your local prosecutors are loose cannons, campaign against their boss.
      The only reason that prosecutors appear to be unaccountable to the public is because the public doesn't pay enough attention to local politics/civics

      --
      The truth is that all men having power ought to be mistrusted. James Madison
  9. Re:Great! by drinkypoo · · Score: 4, Insightful

    As an ex-employee, it's no longer his call as to "who gets the keys"

    Wrong! The SOP was that he was only to turn the passwords over to the Mayor. This has been covered extensively. This requirement DOES go away if you're fired... you don't [by default] have to turn over ANY passwords! Just say "I don't work here any more, and I don't have your passwords." Meanwhile, if you do still work there, then you're still bound by the agreement you already made to follow the policies and procedures, which means he was bound to turn the passwords only over to the mayor.

    In other words, the only charge not dismissed by the judge is the only one which he ever should have been accused of (if any) and he has a solid defense against it. We shall see how it plays out, but it is not nearly as cut and dried as you imagine or pretend.

    --
    "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
  10. Re:Pathetic accusations by walmass · · Score: 4, Informative

    IIRC, he allegedly changed the Cisco configs but never saved them on NVRAM. You can power-cycle Cisco devices and have a 60-second window to get in without knowing the password That was the big problem.. had he saved the configs to NVRAM, the City could have just power-cycled the devices during a maintenance window, gone in and reset the passwords. But the configs being only in volatile memory meant that if they tried that, the boxes would have lost the config, resulting in the "full system failure"--they City network would have gone down.

  11. He did everything by the book by dbIII · · Score: 4, Informative
    Here's a chunk of the SF password policy, shamelessly taken from a post by Jeana Pieralde at http://www.burbed.com/2008/07/15/terry-childs-and-the-san-francisco-fiberwan-computer-network/

    "Password Policy"
    As such, all County employees (including contractors, vendors, and temporary staff with access to County systems) are responsible for taking the appropriate steps, as outlined below, to select and secure their passwords.
    All system-level passwords (e.g., root, enable, NT admin, application administration accounts, etc.) must be changed on at least a monthly basis"
    "Do not share County passwords with anyone, including administrative assistants or secretaries.

    All passwords are to be treated as sensitive, confidential County information.

    Here is a list of things to avoid
    -Telling your boss your password.
    -Talking about a password in front of others.
    -Telling your co-workers your passwordwhile on vacation."

    http://www.sfgov.org/site/uploadedfiles/dtis/coit/Policies_Forms/CCISDA_security.pdf

    So announcing it at a meeting was right out.
    The person that should have taken this all into hand and resulted in a normal dismissal instead of an arrest is Chris Vein. He was originally an accountant but many CIOs are and some manage to pick up management skills and familiarity with technology along the way.
    Here is what http://blogs.zdnet.com/BTL/?p=4692 says about him:

    San Francisco's CIO Chris Vein calls himself an "accidental CIO." His background includes working in and around the White House during Reagan, Bush and Clinton administrations. For the city of San Francisco, Vein's political background has turned out to be an important asset.

    It's still possible he got there by merit, but it starting to look like a political appointment. On his linkedin page he describes himself as "Delivering strong and effective leadership", which often means someone that fires people for no good reason to show they are "strong" but maybe I've just seen too many bastards in action that like that word. These things may give an insight or maybe not, but the end result of getting the police involved in a workplace dispute demonstrates to me that he is not paticularly effective, let alone the situation where there was only one person that could do the job. BTW San Francisco, do you have your free WiFi from 2006 yet? If not you now know the name of the guy that was in charge of delivering it.

  12. One more bit by dbIII · · Score: 5, Interesting

    From http://www.linkedin.com/pub/chris-vein/7/110/71b you can see that Chris Vein was a senior advisor at the White House after only three years in the workforce! I do not think such a rise is possible by merit or desirable in an honest government.
    I hope this case looks deeply at the motivations behind getting the police involved. I'm also extremely curious as to what the $1million that has to be spent to repair the "damage" is required for and hope the defence and judge push hard for an explanation of this unusual claim

  13. Plea? What plea? by Bacon+Bits · · Score: 5, Insightful

    The defense made a motion challenging the evidence and the judge agreed that there was not sufficient evidence to support 3 of the 4 charges. There was no plea here. The court threw out the state's allegations for lack of evidence. There was no evidence because what he did was probably not sufficient as a matter of law (a matter of fact would probably have been decided by a jury). The charges were merely trumped up. Fabricated. Lies.

    And yet they still kept this man in jail for a year awaiting trial for a ridiculous amount of bail money for a non-violent crime.

    --
    The road to tyranny has always been paved with claims of necessity.
  14. some of the routers where in a place with little s by Joe+The+Dragon · · Score: 3, Insightful

    some of the routers where in a place with little security and that is where you may want to use that config.

  15. Re:Actual crime by dbIII · · Score: 4, Informative

    I withdraw my wild accusation. The security officer was promoted internally to the post and when she rang the CIO to complain about being caught doing what she was previously not authorised to do it doesn't mean she knew him personally. It's looking like office politics that has been mismanaged so badly that it has been allowed to escape into the legal system with some incredibly wild claims to stop it looking like an over-reaction, just triggered by an employee that wouldn't do what he was told without a reason. The secret promotion thing was just too weird, I would expect at least an email saying "your new computer security officer appointed today is X, please assist her in her work" instead of secret security audits by someone secretly assigned to the position. That shows a both a spectacular level of distrust of employees and poor management.
    It really looks like he made someone angry and they decided to put him in jail in revenge.

  16. Re:Why isn't he turning over the passwords? by dbIII · · Score: 3, Informative

    He gave them to the Mayor in person not long after imprisonment. That would be approximately a year ago.

  17. Re:Actual crime by Sun.Jedi · · Score: 4, Insightful
    First, switch CISSP with DBA.

    Lets not forget...
    1. 1. The network he was unable to attend to (because of being jailed inappropriately) ran FINE in his absence. He has skills, and previous descriptions indicate this is not a simple network.
    2. 2. He stuck to his beliefs. I think this is a good quality, especially considering it cost him his freedom for a period of time.
    3. 3. In spite of the negative connotations of imprisonment, I'm sure there is educational value from his situation.
    4. 4. In my personal opinion, from whats been published, management screwed the pooch on this one, he did the right thing, in several situations.

    I would hire him.

  18. Re:He should have offered his resignation ... by ka8zrt · · Score: 3, Insightful

    Ya know... that is not always the case. Or to use your vernacular, with emphasis... BULLSHIT! I have administered systems which were secure enough that they would not boot up into single user mode and grant access without the root password, and the drives were secured in such a way that not even pulling the drive and putting it in another system would help... the boot loader required a password to decrypt the filesystem. Given that this machine was up for like 10 years last I knew, when it was finally taken out of commission... reboots were rare. As for exploiting holes in remote access routes, such as through sendmail, http, etc... the only active routes into the system were for Kerberos (e.g. ports like kerberos, kpasswd, and klogin) and considered at the time to be secure short of the resources of the likes of NSA, CIA or DOD.

    Now in the particulars of this case, Child's practice of not committing configurations to NVRAM complicates the problem, and makes it even more impossible for the passwords to be recovered. Ever spent some time configuring a router, holding off on the saving to NVRAM to test the configuration, and then lost power? If the scripts to configure the routers were some place only he knew (such as on a USB key, or hidden away some place on a 300GB drive, perhaps in an encrypted file), it was no problem for him if a unit rebooted. But try to reboot to gain access... guess what, you just lost what you were looking to find. And since we are talking about a router, even if he had committed the configuration (and associated password) to NVRAM, how would having physical access help you? Most routers I have seen, the best you can do is to reset to factory defaults with a little magic button, and provide no way to boot off of other media and still access the configuration on the switch. Nor can you pull the drive and put it in another PC and go that route. As someone who helped write the firmware for networking gear, I know. Only those of us who did that work even had a clue on how to get at a shell like environment to get at the stored configuration. But again, we are bitten by the lack of writing to non-volatile storage in this case. And if you are going to try to brute force a password... it would not help if the password for the console access is "KGToNBhChA2ayofcVL1voA". Granted, using such a password on quite a few switches/routers would be stupid, unless you scripted that access (something I have done). But then there are the countermeasures against such brute force attacks, such as delaying login re-attempts for 5-15 seconds, locking accounts after so many failed logins, etc.

    So, with all this said, someone needing to try to gain access to some machines had better either hope they have the configurations stored someplace off the switch to enable restoration, or hope that they only have to assume a position of humility (e.g. the mayor asking Childs) in having to ask for the administrator password which has hopefully not been locked down. Because, if that is not the case, they are going to soon be assuming the same position a ex-LEO or child rapist is said to be forced to assume in prison...

    Oh... and as for resigning (can one say he was really given a chance to do so properly) and giving the passwords to someone who was not supposed to get them, he could quite possibly be held responsible for the resulting damages if it was contrary to procedures. And given that this has all the appearances of being one pissing match of a turf war... I would be very afraid that that would be the case were I in his position, and as such, the case is IMO totally absurd, and perhaps just has some folks wanting to make a name for themselves...

    --
    Helping build UN*X and the Internet since 1981. :)
  19. It's been a year already? by synthesizerpatel · · Score: 3, Informative

    Really the classic bit of this story is how the prosecutors included a list of usernames and passwords in their court filing which couldn't have been a better home-run for the defense in terms of 'See what happens when you give the passwords out to these idiots?'.

    A year of his life gone though.. This should be a cautionary tale for any IT person.. When things get so bad that you're angry and not making good decisions.. just quit. Find somewhere else, relax. A job at burger king is better than going to prison.

  20. misleading title and tags don't work by MoFoQ · · Score: 3, Insightful

    misleading title...as the charges weren't "dropped," they were dismissed by the Judge (yes...I rtfa).

    "Dropped" implies that the prosecutor did the "dropping," either due to a plea bargain or because the lack of evidence.

    plus I don't like how the Examiner "labels" Childs as a hacker....he was the f*cking sysadmin and essentially the father/protector of the city's fiberWAN.
    Especially considering the incompetence with computers and network security policies and practices by other city workers, he was considered the messiah/scapegoat.
    (definitely, among those of us who have had to deal with the city govt)

    there are plenty of other fish that the prosecutor(s) can fry that are worth the frying.

    oh, btw, I can't get the triangle button to add a tag to work anymore.

  21. Re:Great! by sjames · · Score: 3, Insightful

    Well, you don't have to turn the equipment over because of employment, you have to turn it over because your (now former) employer is the rightful owner.

    Before they fired him, he was bound by policy NOT to give the password to his boss or co-workers. After he was fired, he wasn't even bound to remember the password at all much less tell someone what it was.

    Personally when I leave an engagement where I had passwords, I delete personal accounts and if I was the only person with a role account password, change it to unmemorable junk, write it down, and seal it in an envelope (then forget it). That goes to whoever the policy says should have it ONLY. If others already legitimately have the role passwords I tell them to change it IN WRITING.

    If they choose not to have an appropriate transitional arrangement for that to happen, that's it, I'm gone, good luck to ya! I don't remember a thing!

    He indicated willingness to give the password to the mayor. Once the mayor could be bothered to get said password from him, he did just that. Too bad they made a big stink of it such that that step took place while he was in jail. As for the claims of millions in damage to "repair" the network, that seems rather unlikely unless they really were the bumbling id10ts Childs makes them out to be. Even then, that's not HIS doing.