The Trial of Terry Childs Begins
snydeq writes "Opening arguments were heard today in the trial against IT admin Terry Childs, who was arrested 18 months ago for refusing to hand over passwords to the San Francisco city network. InfoWorld's Paul Venezia, who has been following the case from the start, speculates that the 18-month wait is due to the fact that 'the DA has done no homework on the technical issues in play here and is instead more than willing to use the Frankenstein offense: It's different, so it must be killed.' On the other hand, the city — which has held Childs on $5 million bail despite having already dropped three of the four charges against him — may have finally figured out 'just how ridiculous the whole scenario is but is too far down the line to pull back the reins and is continuing with the prosecution just to save face,' Venezia writes. The trial is expected to last until mid-March. San Francisco Mayor Gavin Newsom, to whom Childs eventually gave the city's network passwords, will be included in the roster of those who will testify in the case — one that could put all admins in danger should Childs be found guilty of tampering."
Surely you mean all admins who refuse to provide passwords when asked by an authorised official at the company they set the passwords for?
This guy denied access to the owners of that network. Just because there isn't a law to fit the crime doesn't mean he is innocent of wrong doing. Hell, it's not a stretch to say that for a time, before they recovered it, he had stolen the entire network from them.
Take your word smithing and semantics and stick 'em where the sun don't shine. What he did was wrong for it, and he needs to be punished.
What do you mean "Just because there isn't a law to fit the crime doesn't mean he is innocent of wrong doing." That's exactly what it means. If there's no law to fit his "crime," then by definition there is no crime committed. Perhaps he's guilty of being an asshat, but doesn't mean he's criminally liable according to your definition.
It's quite a stretch to say he had stolen the entire network. In fact, it's absolutely false. They could have done a hard admin reset on the routers and affected systems and been back in complete control of them. They chose not to, for various legitimate reasons, but the network remained in the possession of the legitimate owners.
You complain about word smithing and semantics yet that's exactly what you are doing. What he did may be wrong, but the question as to whether any laws were broken is far from a given. To punish him for breaking no laws would be absurd and your assertion that he should is equally absurd.
I was initially very skeptical of Childs until additional information came out about the case that changed the story notably.
Their policy prohibited Childs from simply handing passwords over to his boss, when asked by the mayor he handed them over as requested. I think the bigger issue is one of policy on security and a lack of industry best practices by the city. What holds the greater weight, policy or your bosses request? Depending on where you work, handing over your passwords to anyone can readily be a criminal infraction. At a minimum they could have asked Childs to create an additional account with full administrative access and that account could then have been used to disable Childs account.
I know at my employer I am not allowed to share my passwords with anyone, including my supervisor. I have an official backup with equivalent access to myself and my refusal to hand over passwords would not prevent anyone else from taking over for me. If my employer wanted they could simply reset my password and gain access to my account. The issue in San Francisco is there wasn't anyone else who had equivalent access to begin with. Their network was complex and the city had cut to the bone on staffing ahead of time.
Lessons can be learned from this from a management standpoint, the city took an antagonistic approach and did not update their policy and instead asked Childs to break it. Their security personal should have known industry best practices and instead asked Childs to violate them and hand over his password. Ultimately the case showed incompetence in city management and embarrassed them, and that's the only reason I can think of the city pressed the case.
> the people this guy works for asked for the passwords
My impression was, that in a nice show of cluelessness, they decided to fire this guy first, and then ask him for the passwords which they didn't have (i.e., they didn't have any plan of action if he got run over by a bus or otherwise dropped dead).
Sorting out fact from fiction in the Terry Childs case (InfoWorld)
so you would rather that he broke the policy that was given to him with regard to passwords and let unauthorized people have access? The city policy only allowed him to give passwords to the Mayor, which he did as soon as he was allowed to. If you are fired, and some random people ask you to give up the password, would you? If you say yes, then you will end up at the wrong end of a lawsuit, as that would make you criminally culpable in whatever havoc those people caused on the network.
APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
Will people please stop posting that Terry Childs was "being an ass about it"?! He didn't give up the passwords to his supervisor because policy prevented it. It would be a breach of contract (potentially criminally negligent) for him to divulge the passwords requested to anybody but the Mayor.
Guess who got the passwords as soon as they asked? That's right!
THE MAYOR.
End of subject, folks. Stop posting about him "being an ass" or "getting what he deserves" or "setting a bad example." He set the best example by not caving in and handing the "keys to the realm" to some new face he didn't know the technical knowledge of, and was specifically prevented from releasing by the very policy which kept him employed.
This is a PR campaign to save face and nothing else. Someone high up the food chain did something idiotic (calling the police instead of HR / legal dept) and blew things out of proportion. Now they have to see it through, or they'll look like fools and lose their jobs. CYA territory.
I hope the lot of them are fired, and Terry gets to sue every last one.
Finally had enough. Come see us over at https://soylentnews.org/
I worked for a company that performed services for companies that had a lot of personal information. Our systems were kept pretty tight.
For a while, I was the only IT person in the company. I had the primary passwords for much of the company's infrastructure, and the policy manual that was worked up allowed me to give those passwords to two other people on request - the President and my departmental Vice President of the company. The VP was three rungs up the ladder from me.
Neither had the chops to do anything with the passwords, but of course they could easily have hired someone who did. I also had to keep the current passwords in an offsite lockbox at a local bank and only the three of us had access to that box. That way, if I got hit by a bus (or terminated for cause, quit under suspicious circumstances, or whatever) the company could continue operations smoothly.
My boss's boss walked in my office one day and asked for a password for one of the main systems. After a long, involved, and rather unpleasant conversation, I was threatened with termination if the passwords were not handed over. As I started to pack my crap up, the President walked in the room and thanked me for my diligence in following security protocol. It was a surprise audit. I don't think I would have been terminated if I had handed over the passwords, but I'm sure my clearance to possess them would have been revoked in a very large hurry. And that would have been the correct action to take.
There are circumstances where you DO NOT have the authority to give information to your boss. If there is a policy against it, the policy trumps your boss's ability to ask you for the information.
I don't know for sure the policies in place at this particular department, but it is very possible that the boss was not authorized for that information. Passwords and security information do not necessarily follow the chain of command - they follow a chain of responsibility and/or trust, and that isn't always perfectly aligned with the chain of command. If Childs' boss was not authorized for the information, he did the right thing in insisting that the information be turned over to the people his security protocol manual specified.
If Childs' boss WAS authorized for the information by policy, and Childs honestly felt the boss would misuse the information for something illegal and/or was gunning for Childs, then his actions may or may not be justifiable in this case - he's going to have to produce some proof that his boss had an illegitimate purpose. That could be tough.
"This post contains words, known to the State of California to cause thought. Wash brain thoroughly after reading."