Judge Won't Lower $5M Bail For Jailed SF IT Admin
snydeq writes "San Francisco County Judge Charles Haines has denied Terry Childs' motion to reduce his $5 million bail, alluding to 'public security concerns,' according to Richard Shikman, who is representing Childs in court. The ruling comes in the wake of a recent decision to drop three of the four changes that have been levied against Childs, who has spent the past 14 months in jail. The fourth charge — that Childs violated a California statute regarding illegal denial of service for the San Francisco FiberWAN — has been called into question by those closely monitoring the case. As a point of comparison, the San Francisco Felony Bail Schedule lists a $1 million bail for the most serious crimes, such as sexual assault of a child, aggravated arson, or kidnapping for ransom. Prosecutors have argued that the bail is appropriate because, if released, Childs could cause damage to San Francisco's network."
Childs could cause damage to San Francisco's network.
But, but... think of the children
He's a danger to their network only if no one has yet changed the passwords on the routers and other equipment.
Truth, Justice. Or the American Way.
Anybody who knows about computers has to be kept away from them, else they might cast spells on the rest of us.
maybe he should get his money's worth and go sexually assault five children then...
> Prosecutors have argued that the bail is appropriate because, if released, Childs could cause damage to San Francisco's network.
It sounds like they have zero confidence in whoever is now in charge of securing their network.
1 in 4 Maine children in struggle with hunger.
The incompetence of the legal system has no lower bound.
Since I can't mod you down, I'll just note that they've now had over a year to change the passwords and otherwise secure the allegedly compromised LAN.
I don't think the judge understands the nature of network security, which is understandable since he isn't an IT guy......but no doubt the prosecuting attorney was pushing to distort the issue to make him look as dangerous as possible. What if he is not guilty, are they still going to keep him in jail because he might be dangerous? Furthermore, if he DOES damage the network, can't they just charge him for that crime at that time? It's not like he can cause irreparable damage, as murdering someone might.
One thing I don't understand is why this guy doesn't exercise his right to a speedy trial. He's already been punished enough considering all the evidence I've seen suggests he is innocent. Maybe he is getting some kind of zen experience living in jail and he actually likes it or something. From what I've heard from some sysadmins, living in jail can't be much worse than that job.
Qxe4
You are right, any nutso can get a sniper rifle, case full of ammo, and take out half a campus from the church tower. It's the really dangerous folk, like the ones who haven't had access to your network in the past year (which you somehow haven't secured on your own because you are too fucking stupid) that are the real danger to society at large.
Here's a tip for the Judge, if there is still something out there on SF's network that Childs actually could manipulate with greater access or affect than a normal citizen, then the folk who should be in jail are the ones who cleaned up the mess.
Prosecutors have argued that the bail is appropriate because, if released, Childs could cause damage to San Francisco's network.
So if the 4th charge is dropped and he is freed, can they keep him jailed? He could, at that point, still cause the same damage that he can now.
But then I realized the cable was blue, so I only gave it one star. I hate blue.
I think the problem is they know he's not going to be convicted of anything in the end. So the judge is trying to send a message to people who might be inclined to do the same thing.
"We can get you. We don't need to actually convict you, either. We can get you anyway."
Doesn't this guy have a sixth amendment right to a speedy trial?
Besides (and Google may have led me the wrong CA statute) but it look like the penalty for the remaining charge could be as little as a $5,000 fine. It also seems to have an out:
"Subdivision (c) does not apply to punish any acts which are committed by a person within the scope of his or her lawful employment. For purposes of this section, a person acts within the scope of his or her employment when he or she performs acts which are reasonably necessary to the performance of his or her work assignment."
When I was a corporate IT guy (about 3 years in the middle of about 16 years as a consultant), I took responsibility over a large part of the network in a multi facility health care business. This wasn't life or death stuff, but network outages did cause problems with appointments and general "face" of the corporation. When I came on board, the network was down a lot. No change control, no "chief" in charge of the network, and about 9 people mucking with stuff constantly.
I put my job on the line, in exchange for FULL control of that system (It was a 85 server Netware + Groupwise environment). The first thing I did was take *everyone's* admin away, removed "admin" from supervisory rights to the tree. I then doled out the appropriate levels of access to the security team (read new users, password resetters), put in a hidden OU with a tree supervisor in it and then wrote the "master" admin/login information down. Lightly, in pencil. Folded it up, put it in an envelope with a tamper seal, that went into another tamper evident envelope and that went into the safe. Every month or two I changed the password and replaced the envelope.
That was in case I died, they could easily get in. That is what Terry should have done. Then it wouldn't have come to this - he might have gotten sacked, and/or lost control over what he considered to be his "creation" -- but he wouldn't be rotting in jail....
= Grow a brain...
While it seems the prosecutors in this case are overreacting (why's this even a criminal case?), what I find curious is that there was no scheme to retrieve the passwords if Childs were to pass away accidentally (no HBB protection). Passwords written on paper in a safe, safety deposit box or similar, or the passphrase to Password Safe written down somewhere secure.
It's pretty stupid to have to physically access all the routers to reset passwords in the event that the network admin dies or quits in fury. Just write the procedure into the admin's job description.
testing 1 2 3
Maybe I don't remember HS Civic's very well but I thought the point of bail was ONLY to prevent flight, not that it had been redefined to be large as a result of danger the innocent (until proved otherwise) person poses. He's being jailed not because he's a flight risk but because of political posturing by the DA, that is a serious miscarriage of justice. I don't have a lot of sympathy for the guy but bail is clearly being misused here.
it's not at all inconceivable that Childs could cause damage to that network if he chose to do so.
You are correct, of course. Childs should be immediately lobotomized, or if the procedure appears to be unreliable then he should be just killed. He knows too much and can never be released. His possible future crime must be prevented at any cost. Same applies to all future sysadmins of SF - once they learn the network (a few weeks on the job, perhaps) they will have to be destroyed.
Excessive bail shall not be required, nor excessive fines imposed, nor cruel and unusual punishments inflicted.
Judge needs to be removed and disbarred.
The pervert/sickos they just caught in SF had their bail set at $500,000 each
for imprisoning and raping kids for 20 years
10% of what this admins bail is set at
good to see the USA court has its priorities set
raping kids is only 10% of the risk to society than this guy?
it's not at all inconceivable that Childs could cause damage to that network if he chose to do so.
It's not at all inconceivable that the average slashdot reader could damage the network if he chose to do so (with some basic research + social engineering, to gather some general info).
Phillip Garrido is only being held on $1 million bail. Which one do you think can do more damage if released, Childs or Garrido? If you answered "Childs", I would insist your priorities are seriously fucked up.
I've abandoned my search for truth; now I'm just looking for some useful delusions.
... when he has to register as a Childs offender.
Anybody want a peanut?
Someone send over 63 pirated songs then.
Is there anything that can be done for him?
As a SysAd and citizen I find this case to be disturbing. I don't know if visiting him in jail would be helpful.
Do they even let one have cookies in there? Cookies may not help him or his case, but cookies can taste good.
20 characters max for the password? How will I use my favorite poems as passwords?
Which requires them to know what all of the equipment is, and potentially all of the software installed in all of it. Information for which Childs was supposed to be the source.
I'm not saying that the $5 million bail is right, but it's not at all inconceivable that Childs could cause damage to that network if he chose to do so.
Childs should not be the "source" of knowledge on their equipment. Their internal inventory and documentation policies are the source for that information. Childs designed and maintained the network, he did document it, even going so far as to Copyright the network design. Childs even followed policy when he refused to disclose his password to members of the San Francisco Police Department, representatives from HR, and an unknown group of people on the phone.
San Francisco government policy, from http://www.sfgov.org/site/uploadedfiles/dtis/coit/Policies_Forms/CCISDA_security.pdf
"Password Policy"
As such, all County employees (including contractors, vendors, and temporary staff with access to County systems) are responsible for taking the appropriate steps, as outlined below, to select and secure their passwords.
All system-level passwords (e.g., root, enable, NT admin, application administration accounts, etc.) must be changed on at least a monthly basis"
"Do not share County passwords with anyone, including administrative assistants or secretaries.
All passwords are to be treated as sensitive, confidential County information.
Here is a list of things to avoid
-Telling your boss your password.
-Talking about a password in front of others.
-Telling your co-workers your password while on vacation."
This is a corrupt government using its influence over the DA and judicial appointees to persecute Mr. Childs. After this last charge is throw out, Mr. Childs will undoubtedly counter-sue in a different jurisdiction to stay clear of the corruption in the SF government.
An idiot with a backhoe could damage the network. Justice is neither being done nor being seen to be done.
When ordinary citizens break the law, they get punished, often going to jail. When officers of the state violate citizen's constitutional rights, violations that have a much more resounding effect on society, the violations go largely ignored, rarely resulting in penalties, and even rarer that those officers will see any jail time. It is unfair and fucked up, the kind of system the founders wanted to prevent. IMO, if a civil servant (from the bottom to the top) blatantly violates the constitutional rights of a citizen, it should be prosecuted. Of course that will never happen, but one can dream.
On one charge? This looks _very_ fishy. Conditions on bail would certainly include no computer use. I suspect the real motive for the DA is to use incarceration as pressure for some sort of plea bargain. Any bargain, because their case is weak / non-existant. Highly corrupt.
The DA has to pressure, because if he does NOT cave, they're facing a multi-million $ lawsuit for wrongful (or even malicious where less would be protected by privilige) prosecution. This will ruin careers. As it should.
What skilled, knowledgable, trained network administrator would work for them at this point?
Some may be willing to take a crappy job to put food on their kids table... but one that's likely to put you in jail for following their own proceedures?... I wouldn't do that to my kids.