Slashdot Mirror


10% of IT Pros Can Access Previous Jobs' Accounts

dinscott writes "According to a survey that examines how IT professionals and employees view the use of policies and technologies to manage and protect users' electronic identities, the sharing of work log-ins and passwords between co-workers is a regular occurrence. It's no wonder then that half of them are concerned about insider threats to network security in their company's current infrastructure! But one of the most surprising results shows that one in 10 IT professionals admit they have accounts from previous jobs, from which they can still access systems even though they've left the organization."

50 of 218 comments (clear)

  1. well, i can by gblfxt · · Score: 4, Interesting

    but is it my responsibility to suggest they change the password? especially since a 'professional' it outsourcing company took it over?

    1. Re:well, i can by Stenchwarrior · · Score: 2

      Fuck no its not. And I'd have a hard time not getting behind some proxy and doing something bad, in your case. Unless I'm reading you wrong and it wasn't a sour situation for you.

      --
      Loading...
    2. Re:well, i can by John+Hasler · · Score: 5, Insightful

      > but is it my responsibility to suggest they change the password?

      You should do so for your own protection. Do it in writing. Don't check to see if the password has been changed, however: you could be accused of "breaking in". Just send them a letter reminding them to make the change.

      > especially since a 'professional' it outsourcing company took it over?

      Which may look around for a scapegoat after they screw up. You really don't want them to discover that a break-in occured via an account for which you, a "disgruntled former employee", had a password.

      --
      Warning: this article may contain humor, sarcasm, parody, and perhaps even irony. Read at your own risk.
    3. Re:well, i can by gblfxt · · Score: 2

      i am a professional, and i understood that they thought i was overpaid (especially since after i was there for 2 years, there were hardly any network issues). i don't wish them harm, but i would like to at least hire a competent IT outsourcing company to replace me, so I know my 2 years of work ended up in good hands... :)

    4. Re:well, i can by mysidia · · Score: 3, Insightful

      Sure I do. I didn't do it, so they can't prove I did. And I get to rub it in their faces- "You fired me, a competent employee, and hired some losers who can't even change a password. What idiots!!".

      The best thing to do in such circumstances is probably to just let yourself forget what your old password is. Providing you were smart, it is a strong password, and difficult to remember, it will be forgotten eventually.

      Just don't try to remember it or use any new password similar to it.

    5. Re:well, i can by Toe,+The · · Score: 2

      No, no, no. It's like paying for insurance...

      I only buy insurance policies the day before I intend to get in an accident, decide to get robbed, elect to have my house destroyed by a tornado, etc.

      It is much more cost-effective that way.

    6. Re:well, i can by fuzzyfuzzyfungus · · Score: 2

      (especially since after i was there for 2 years, there were hardly any network issues)

      Surely that can only mean you were doing your job well.

      Unfortunately, this is not the way of user psychology...

      By default, all complex network setups work perfectly(It said "enterprise" right on the box, dinn'it?). If yours does not work perfectly, that is because your IT department is incompetent. If yours does work perfectly, this implies that your IT department is slacking off and playing video games, and should probably be fired and replaced by something cheaper.

    7. Re:well, i can by bzipitidoo · · Score: 3, Insightful

      Seriously. Unless you are rehired, never touch your old accounts again, no matter how well intentioned. The law is over the top on punishing evil hackers. Even if the risks seem low, the law makes it so not worth helping out should things turn sour. The least you should have is decent compensation for the risks you're taking, and to help allay suspicions of whether you could have ulterior motives.

      My last employer wanted me to continue to help out after the money ran out. So I was to keep right on doing what I had been doing, with no contract, and no pay? No way!

      --
      Intellectual Property is a monopolistic, selfish, and defective concept. It is "tyranny over the mind of man"
    8. Re:well, i can by hawguy · · Score: 3, Informative

      Sure I do. I didn't do it, so they can't prove I did. And I get to rub it in their faces- "You fired me, a competent employee, and hired some losers who can't even change a password. What idiots!!".

      What makes you think they can't prove you did it just because you didn't do it? Do you really think no innocent man has ever been convicted of a crime they did not commit? Even if you can ultimately prove it in court, it could cause you quite a bit of inconvenience in the meantime -- the company just needs their forensics "expert" to convince the cops and a judge that you did it and they'll come take all of your computing equipment from your house.

      Wouldn't you want to be able to give your defense attorney the letter you sent to your former boss that gives step by step instructions for making sure all of your points of entry into their network have been closed. If the company is as incompentent as you suspect, you should do everything you can to protect yourself in case they get breached.

      Even when my company was bought by idiots (who ran it into the ground within months), on my last day I sat down with the new Network Admin and my former boss and we went through the letter to make sure all of the network/admin passwords were changed and the firewall "backdoor" into the DMZ from my home IP address was removed.

    9. Re:well, i can by mlts · · Score: 3, Insightful

      This. If you are good at the IT job, your work is invisible. However, one needs to make sure they are not invisible, mainly by proactively checking with other cow-orkers and departments to see how things are running, anything possible they can get, etc. This way, you have a presence.

      I have seen companies fire their IT guys who have extreme clues because they thought that they could get someone cheaper to run things, then their whole infrastructure collapses with the guys they hired on to replace the veteran IT people barely able to do firefighting duties. Said companies end up with two choices, either finding another veteran IT person that they likely will end up paying far more, re-hiring the guy they fired (assuming he or she would ever bother to come back), or re-hiring the fired person as a consultant for a lot of cash.

      Here is the ironic thing: The PHB who has the MBA goes through courses like ITIL/ITSM concepts where they have to pass concepts like this. So, the concept assuming that the IT infrastructure would work perfectly by jettisoning veterans was taught to them that it won't work.

    10. Re:well, i can by rayd75 · · Score: 3, Interesting

      It's certainly your responsibility to never try that password. I left an IT job at a financial institution rather abruptly a couple of years ago after a blow-up with my boss over whether I was responsible for failures in a process that she'd explicitly delegated to another group. (Just the last in a long line of ex post facto policy and procedure changes) Anyway, I never had reason to try (nor would I, given the legal and moral aspects), but for a while I suspected they'd probably disabled my accounts but missed things like router passwords, voicemail passwords, etc. that were either too obscure or too difficult to change. Later, I spoke to a former coworker and found out that they spent untold sums of money on security audits and consulting after I left. Turns out, the best way to secure an organization is to talk doom and gloom, "nothing can save us" security for a while and then leave pissed-off and shouting.
      As you might expect, once all those unfamiliar hands got into the shop, uptime went to crap. (Not good when you're dealing with other people's money) So, while I did nothing and probably didn't have any access anyway, the results for them were much the same - large cleanup bill and lost customer confidence. A moral of the story might be that while documentation, procedure, and security are all vital parts of IT, they can't substitute for a good management relationship with a competent, loyal staff. This is particularly true for organizations with IT shops on the smaller side of the staffing scale.

    11. Re:well, i can by mlts · · Score: 4, Interesting

      With clued people, there may not be convincing evidence.

      However, in a jury trial with the DA throwing the book at you for a lot of computer trespass charges, convincing a jury of that is a lot harder.

      We all have dealt with the Joe Sixpack archetype. He calls you on the phone demanding you "fix" his computer. Because he is either a friend of someone you care about, or otherwise can't tell him where to stick it, you go over. You make it past the baying mangy hound menagerie, avoid the cans of Bud Light on the front porch, hold your breath as you round the TV area that is permanently turned onto Fox News, and narrowly dodge the gun cleaner oil perched precariously on a table.

      Finally you get to his computer. The copy of AV software has expired (or never been activated.) You see the hard disk light constantly on even though the box is idle. Further prodding finds that a reinstall is a must because iexplorer.exe and explorer.exe got corrupted and replaced by something. The recovery partition? Completely corrupted.

      You ask Joe for the install media. He never made the install CDs (if he bought the box from most PC companies), or he lost the media (if he bought a Dell). You ask him about backups. He tells you that if he backs his pickup up any more, it will smash into the wall. You ask him about saved images of Windows. He wonders why you want pictures of stuff found in a Pella or Andersen catalog.

      End result is that you tell him to buy some install media. He ends up stopping by Best Buy and just buying another computer. You help him get the new machine set up and browsing the NSFW stuff (the computer's primary use), and almost certainly, the cycle will begin again in a few months.

      Now picture twelve of these types of people who have zero clue about computers. They are deciding your fate, and they have possibly the rest of your life in their pork-rind stained hands. The DA will tell them in the opening/closing statement that you trespassed electronically, and the jury will just rubber stamp that verdict and the sentence time asked, because they don't know better. They will dismiss the defense as greasy nerds with "ass-burgers syndrome" who are trying to spout meaningless technobabble in order to get a disgruntled employee off the hook.

      It just pays not to log in at all, whatsoever to an ex-employer without permission. It also pays to use a strong password, so you are not kept up at night wondering if a cracker would get in and get you blamed for it.

    12. Re:well, i can by Deekin_Scalesinger · · Score: 2

      I was wondering the same thing, and I'm about as savvy as the next guy here on /. I've practiced all of those in the workplace, just never heard that acronym...

      On another note, I used to work for a hosting company, and they gave us an employee account. My login still works for it, seven long years after I left there. Seven. I don't host anything out of it - I just use it for testing purposes from a remote location not associated with my local ISP.

      I haven't logged into it in about a year, for fears arising what TFA alludes to, but the DNS still resolves, so it is still an active account. It's a bit scary that they haven't done an audit of employee accounts in nearly a decade...makes me wonder what other internal balls are being dropped.

      --
      "As the intrepid kobold companion continues his journey, he begins to wonder... if priests raises dead, why anybody die?
    13. Re:well, i can by gknoy · · Score: 3, Interesting

      It's all in how you phrase it.

      "Please change the bob.admin account's password, as it appears to not have been changed" : BAD.

      "Hey Cyril, I just wanted to follow up and make sure that the new IT guys at XYZ.inc got all of my old accounts locked down. I expect they already changed the password on my old bob.admin account and disabled its permissions, but I want to make sure they also locked down the bob.vpn account and removed the firewall exceptions that we'd installed when I needed to fix the webserver that one time on my vacation." : LESS BAD.

      The latter doesn't imply that you tried to access it, but rather that you're trying to make sure that the new IT people know about all of your accounts, not just the obvious one. The IT guys will say, "Oh yeah of course we did that ... " and then go fix it quietly if they didn't.

  2. I'd better not be able to... by HappyHead · · Score: 4, Interesting

    My last action in my previous sysadmin job was to disable my own old accounts. If I find that they're accessible to me again, it means that:

    • They somehow guessed my line-noise password, and put it back on the account, or
    • They broke the servers badly, and had to restore everything from the backup I made before I left, and then were too stupid to re-do the list of admin tasks afterwards, which included disabling the accounts of three other former employees, one of which was fired for dirty dealings.
    1. Re:I'd better not be able to... by kwenf · · Score: 2

      They broke the servers badly, and had to restore everything from the backup I made before I left, and then were too stupid to re-do the list of admin tasks afterwards, which included disabling the accounts of three other former employees, one of which was fired for dirty dealings.

      I find this scenario plausible. You should check if you can access the accounts.

    2. Re:I'd better not be able to... by Stenchwarrior · · Score: 4, Insightful

      They made you disable the access?! That's either very lazy or...well, I don't know what else. Relying on the person leaving to kill their own access is a bit like leaving the wolf to tend the chickens, no? I'm sure there are audit trails that show that if certain places in the network are accessed it can be traced back to your username, but who's to say that your particular account didn't get hacked? This only creates headaches for the IT manager later down the road. This reminds me of my brother who is very good at not working, but at a cost where he actually works harder to not work, more so than he would if he actually just fucking worked.

      --
      Loading...
    3. Re:I'd better not be able to... by L4t3r4lu5 · · Score: 2

      I disabled my own account too. Locked my own mailbox, logged on as Domain Admin, moved any documents or files which may be required by a successor out of my user area, disabled my user account, and handed the "key to the city" to the next guy, who promptly changed the Domain Admin credentials.

      It enabled a clean break, and ensured I'd be disturbed as little as possible by the next guy asking what's what.

      --
      Finally had enough. Come see us over at https://soylentnews.org/
    4. Re:I'd better not be able to... by somersault · · Score: 4, Insightful

      I hate when people don't actually tell me that an employee has left. Last week someone was like "did you know that Elaine is back already?" and I was suprised to hear that she'd even left. Sure, come to me when you need a new account, but if someone leaves nobody says a thing. In fact I'm going to email our new HR dept right now, it should be part of the procedure when people leave..

      --
      which is totally what she said
    5. Re:I'd better not be able to... by PitaBred · · Score: 2

      Trust has everything to do with it. Why would you give anyone root access if you didn't trust them?

      All human relationships come down to trust at some point or another. If you don't recognized that, you're in for a world of hurt in the business world.

    6. Re:I'd better not be able to... by gknoy · · Score: 2

      Dont bother, unless of course they call you up for 5x the money, to fix things... then your a 'consultant'

      I disagree. When you leave, harp and leave a paper trail asking for them to lock your account (if you didn't have access to do so). When you come back, tell them "Please give me a login and credentials to access this." You're not even asking for your old account, in that case.

    7. Re:I'd better not be able to... by Stenchwarrior · · Score: 2

      I agree to a certain point, but you'd still better be able to provide an audit trail of every system accessed by any given user at any given time. I'm sure there's a statistic out there of companies who are ripped off by supposedly trust-worthy employees. It happens every day and the competent IT manager has to make sure measures are in place to keep it from happening, or at least reduce the risk to a low factor.

      I think it's great that you are able to trust people not to rip you off and I agree, most of them wont. Even if it's 99.9999% of the people that won't you'd be a fool to not protect yourself against the other .0001% because it's that one person that can make or break your business. Humans are falable and subject to emotions and generally bad things. If you don't recognize that you're in for a world of hurt in any world.

      --
      Loading...
  3. Not surprised by dwarfsoft · · Score: 2

    I have a memory that absorbs passwords. I know that two years down the track after I left one company they called me asking for the Directory Services Restore Mode password. This was all well documented when I left. From this same incident I also know that the Admin passwords and the remote connection were all still using the same settings as when I worked there.

    Not surprised in the slightest.

    --
    Cheers, Chris
  4. Re:Only 1 in 10? by characterZer0 · · Score: 4, Insightful

    People often leave on good terms and the accounts are kept so the ex-employees can help out later here and there if asked.

    --
    Go green: turn off your refrigerator.
  5. This is telling by elrous0 · · Score: 2

    Even though that's the case (and I'm actually surprised the number isn't higher, considering my own experiences), the real revealing thing about this is that the VAST majority of IT professionals are professional enough not to take advantage of this or to retaliate against former employers. With the exception of a few high profile cases, almost all IT workers do not use these backdoors for sabotage, theft, etc.

    --
    SJW: Someone who has run out of real oppression, and has to fake it.
    1. Re:This is telling by Galestar · · Score: 2

      With the exception of a few high profile cases [infoworld.com], almost all IT workers do not use these backdoors for sabotage, theft, etc.

      I think you don't quite have all of your facts straight about Terry Childs. He didn't use it for sabotage/theft nor did he use a backdoor.
      Please, go inform yourself before posting again.

      --
      AccountKiller
  6. Re:Only 1 in 10? by ryanov · · Score: 2

    This was one of our IT assistant director's ideas. I was uncomfortable about it from moment 1, but I did as asked. Someone about a year later looked at me like I was crazy when I said that that's what happened and told me to disable the account immediately.

    I don't know why I'd want a former employee logging in, ever.

  7. Re:Only 1 in 10? by DrgnDancer · · Score: 3, Insightful

    Lat place I worked (may it rot in Hell) I hired a junior admin (whom I like, and now feel really bad for accidentally screwing that way) whose previous company did that. It was a small organization and they'd only had him and another guy in IT. Every so often they'd pass him a few bills to login and fix something. Worked out well all around, he made a few extra bucks and they didn't have to do a panicked job search to replace him instantly. Definitely a terrible idea from a strict IA perspective, but it was a family owned company and they liked and trusted him (with good reason, he was a likable, trust-able guy).

    --
    I don't need a million points of light, just two points of multi-mode fiber and a 10 Gig-E router.
  8. Re:Audits needed by Shadow99_1 · · Score: 4, Insightful

    I'm with you right up til you start talking about mandatory password changes. Research has pretty well proved by now that making people change their passwords regularly means they write them down. A written down password provides a worthless level of protection from from almost every attempt to get into a system. Statistically a person with a secure password they can remember is far more secure then any number of new passwords they cannot.

    --
    we are all invisible unless we choose otherwise
  9. So easy to retaliate, but didn't by toygeek · · Score: 3, Funny

    I have a customer who stiffed me a few hundred bucks for sysadmin work, and he has yet to change his passwords. I doubt he even knows how. I ran across one of them a while ago and sure enough it logged me right in to the account for his colo provider. I did nothing. In fact I even notified him that he should change his password and "oh you still owe me" and never heard a word.

    "Hello, my name is Inigo Montoya. You stiffed me money. Prepare to be Pwned!"

  10. Re:wtf? by Eivind · · Score: 3, Insightful

    social engineering is so very simple, and so very effective, true.

    Google a mid-sized company enough to know the name, position and email-adress of an employee, and the name of one of his/her supervisors.

    "Hi, it's from [network-provider] - I got a report that you where having some trouble accessing your email, [name-of-supervisor] couldn't get at his at all today - do you have a minute to perform some tests on your account ?"

    People will gladly tell you their passwords, if it appears you know what you're doing and you know even a *tiny* bit about their environment, enough to make you seem legit.

    It's not hard.

  11. Client resistance to security efforts by grapeape · · Score: 3, Interesting

    Last year I actually lost a client for being too security conscious. They were a part-time client and only usually called me when it was an absolute emergency...most of the time when a problem happened they would try and fix it themselves, make it worse then call me. I tried to talk them into letting me come in once a month to patch and update on a scheduled basis. I was told I was trying to fleece them and pad my hours and that they felt they needed to take IT in another direction.

    Nearly a year later I am still receiving backup notices, a few ,months back I found out accidentally that the root password hadn't changed when I ran a maintenance script that I used to do a resources audit, forgot to change the account info to a different client. I called them right away and instead of "thanks we will take care of it" I was told that I was hacking and that if I didn't stop they would report it to the police. I even tried talking to their new IT guy (one of the owners nephews) but he told me he was not allowed to speak to me and hung up.

    I'm actually worried about the former client but am completely at my wits end about what I can do about it and frankly i'm worried that when the inevitable happens the first person they will attempt to blame for any disaster is going to be me. For now all I have been able to do is document my efforts to get them to fix the issue.

  12. Make sure to document account removal request by bl8n8r · · Score: 4, Insightful

    When I leave a place, or a contract is over, I usually work it into an email to request my credentials be removed, or account disabled.  When something goes wrong, the first thing everyone does is point a finger at the last person that left.  If my account has been disabled, it's pretty easy for me to prove my innocence and not waste time trying to convince anyone.  Also puts a little more weight into your argument when you produce an account revocation document which a company was negligent in following through with.  Doesn't sound like much, but makes a *huge* difference when the witch hunt starts.

    --
    boycott slashdot February 10th - 17th check out: altSlashdot.org
  13. Re:wtf? by arth1 · · Score: 2

    A key is a password too.

    Just because the machine types in "ssh-dss AAAAB3N...uxIOH1" for you doesn't make it inherently more secure. If not properly managed, it's less secure, because it goes from "something you know" to "something anyone who gained access knows".

  14. 6 out of 10..... by Lumpy · · Score: 3, Interesting

    Have copies of companies assets in their possession. OR physical assets of the company still in their possession.

    I was cleaning out some junk data the past weekend, went through my archive of 900+ CD-R's of the past 14 years and found several discs that I shredded as they contained company data from old employers. I also found a binder with a printout of some sourcecode that was for a old job from before 1995.

    I dont worry about the guy that can access a server at work, I worry about the guy that leaves the job with a 64gb thumb drive that has the entire customer database on it.

    --
    Do not look at laser with remaining good eye.
    1. Re:6 out of 10..... by anotheryak · · Score: 2

      I dont worry about the guy that can access a server at work, I worry about the guy that leaves the job with a 64gb thumb drive that has the entire customer database on it.

      You hit the nail square on the head there. I have access to several former employers; I even have access to one site where I shut off my own access before I walked out the door. But then my replacement did not work out and they begged me to help them find out what was going on...I had to come back into the building and hack into my old servers with a boot disk to restore my access and undo the work of my "successor".

      Generally, a true IT professional can be trusted after they leave, because if they wanted to get confidential information, they had plenty of chances while they worked there. Most of us don't even care what the data is, we just don't want to lose it. for the company.

      As a company, you generally have no risk from a true professional IT person. Not a lot of risk from engineers, either...some are crooks, but most are ready when they leave to work on something new anyway. Your highest risk staff are folks like sales, who already work on commission and are likely to be doing the same thing with a similar customer list at their next employer. They are also likely to have poor security practices among their group and therefore know the passwords of a half-dozen coworkers.

      .

  15. Re:Does a real "Pro" even know? by Lumpy · · Score: 3, Funny

    Yes a real PRO knows.

    My desk at comcast, one I have not sat at for 7 years now is STILL empty and has my PC on it's desk logged in and running as me. I know this as friends in the department tell me that they still have not moved from my test server on my local machine to a production server so they simply still log in as me with the same password. That will teach them for hiring only MCSE's, one linux box confuses them.

    They do use my cube as storage though.

    --
    Do not look at laser with remaining good eye.
  16. Re:Only 1 in 10? by Ephemeriis · · Score: 4, Insightful

    People often leave on good terms and the accounts are kept so the ex-employees can help out later here and there if asked.

    At my current job, I've replaced a guy who accomplished a hell of a lot in the two years that he was here. There's a good chunk of stuff here that my boss doesn't really feel comfortable with. So he disabled my predecessor's account, instead of straight-up deleting it, in case we had to call him in for help (at which point he would have been paid as an independent contractor).

    But that account is disabled. Even though it's still got the same credentials on it, and could be re-activated and used in an emergency, it doesn't currently work. My predecessor could not log in right now if he wanted to.

    You'd have to be crazy to intentionally leave an account active and functioning after someone leaves the company.

    --
    "Work is the curse of the drinking classes." -Oscar Wilde
  17. It's quite common by ledow · · Score: 5, Interesting

    Most places will happily give you every password in the world when you start a job there. And sometimes the "intermediate" stage between you leaving and someone else doing your job is filled with outside contractors and random people who "need" your passwords.

    Whenever I leave an employer, I make a BIG list of everything I know in terms of passwords, passcodes, keys, etc. and compile it on paper or a CD. I put literally everything in there, even down to little foibles of the system and the reasoning for strange configurations. I then furnish the boss with one copy of that CD, hand him another copy to "put in a safe place" (usually a safe) and then leave.

    I did this at my last workplace. They were getting increasingly silly and employing people with zero expertise, and I already had another job already lined up so my entire notice period was spent house-cleaning and compiling lists while taking care of the mundane jobs.

    Technically I reported only to the headteacher of the school in question, having been employed by him without any formal assignment in a staffing structure (to the point where the local borough phoned up to complain that I was earning too much for any of their pay-scales and had to be put on my own unique one).

    When I left, there was no replacement for me (because they weren't interested in employing the only guy out of all the candidates that *could* do my job because he had formerly worked in Tesco's supermarket rather than sit on his arse in the middle of a recession) so I handed off to the headteacher. This immediately caused an argument because one of the new staff who was the new "second-in-command" there (and that decision was partly responsible for me wanting to leave in the first place!) DEMANDED the "admin password for the network".

    He wasn't an IT guy. He knew nothing about computers at all. He just wanted it because he was sure that the dozens of digital voice recorders that he'd bought on a whim (without IT authorisation) could be made compatible with the non-networkable, kiddified, decades-old audio editing software he'd bought on a whim (without IT authorisation) on the network he didn't know how to manage, no matter how many times I told him they were incompatible. He was convinced that if he somehow got the "magic" administrator's password and then let 1000 kids loose with it so they could listen to themselves talking, it would solve his problems with not teaching part of the IT curriculum.

    Obviously I must have been deliberately lying when his DRM'd-AAC-only recorders couldn't be opened in a program that only took WAV's (not even MP3's!) and that an intermediate conversion step (which he DEMANDED shouldn't be necessary and refused to use) was required.

    Apart from the fact there were three networks, there were dozens of different passwords, and he wasn't getting *ANY* of their passwords until I was way outside the building and long gone, I had a duty to protect the information secured by those passwords (information on kids, people's salaries etc.). If you read the rules precisely, that means that I had to hand off ONLY to the headteacher, who could then hand off passwords to others as they saw fit.

    So I did just that, in the process making my own day by telling the guy "No." even if he WAS second-in-command there (he didn't seem to understand that I didn't report to him, no matter what he thought of that idea). He was rather miffed. I also, with the head's permission, gave a copy of the CD to the lead governor of the school who was a big-iron IT guy for his day-job, that we both knew we could trust - he would be fixing any major issues that occurred in the school until they could find a replacement and he was there to sign-off on my hand-over.

    A week later, a phone call from the second-in-command. He'd got the administrator password, tried it out on several PC's and couldn't do what he wanted (ignoring the fact that he wasn't using ANY of the network software management that we had in place). So he demanded that I give

  18. Quest. by saintlupus · · Score: 4, Insightful

    If only the company who commissioned this survey happened to sell a bunch of account and identity management tools.... Oh, they do? What luck!

  19. Re:Audits needed by fuzzyfuzzyfungus · · Score: 2

    In an institutional setting(where a good slice of any individual's coworkers can probably obtain physical access for 10 minutes without drawing suspicion, and whatever contract cleaning service was cheapest gets absolutely insane levels of physical access, granted to the high-turnover pool of whatever poor bastards they can find to do night-shift cleaning for $not much/hour, written passwords are, indeed, just asking for it.

    In a physically secure environment, though, if you are concerned primarily with internet threats(as with, say, home banking) an excellent written password can be a perfectly decent strategy(particularly if you do something like remember an ok password, then append the written-down 20-character-line-noise one... Even a breakin won't get somebody what they need...).

    Ultimately, though, if it is really that important, you should probably suck it up and go with some flavor of cryptographic token + password. They aren't terribly inexpensive, and everybody hates them; but they are better.

  20. Re:Audits needed by Lord+Ender · · Score: 2

    A written down password provides a worthless level of protection from from almost every attempt to get into a system.

    Wrong. 99% of attacks will come from out on the internet somewhere. Having your password written down does not make these any more dangerous. Having a good password written down is far more secure than having a memorable password that you never change.

    --
    A slashdotter who didn't build his own computer is like a Jedi who didn't build his own lightsaber.
  21. I do NOT have a hard time by SmallFurryCreature · · Score: 4, Insightful

    I know I still got access because they called me from a previous job if I could help them out and I just tried my login during the call to see what was going on and it was still there. I just thought "oh", fixed the issue and mailed that I still had access and left it at that.

    I am a pro but not a sys admin. If I do not work for them, I do not have a need to access their servers and so I don't. Not very hard. Disgruntled? Even then I wouldn't because it would be against the law and could seriously hurt future employment.

    The trick therefor for companies is to both have good account management AND hire professionals who care about not becoming a criminal.

    Seriously kid, to anyone who read this, you just gave a massive reason NOT to hire you.

    Do I as an employer constantly have to worry if it is that time of month for you?

    --

    MMO Quests are like orgasms:

    You may solo them, I prefer them in a group.

    1. Re:I do NOT have a hard time by BattleApple · · Score: 2

      I can see how that could turn into a mess.. If I was in that situation, I'd probably want to help, but imagine if something went wrong - even something unrelated to what you did to fix the problem. Some clueless manager could flip out and make life really hard for you.

      Years ago, I repaired photocopiers. Once I just stopped at an account for periodic maintenance because I had nothing else to do. First thing I did was hit the copy button for a test copy, and the scanner lamp blew. I didn't have any lamps for that model on me and had to order one, so the customer wasn't too happy. And of course they wouldn't believe it wasn't my fault.

      And I agree.. anyone who would go back and intentionally fuck things up has some growing up to do.

    2. Re:I do NOT have a hard time by flimflammer · · Score: 2, Insightful

      Do I as an employer constantly have to worry if it is that time of month for you?

      If you as an employer had the forethought (they rarely do) to worry about that, then they would have changed the login credentials already.

      I don't feel the need to baby my ex-employers through their incompetence. I'm not going to do anything with the information, but when you let me go, my obligation to the company ends there. It should be standard operating procedure when you let someone in IT go who has privileged login credentials, that you revoke those credentials.

    3. Re:I do NOT have a hard time by candl · · Score: 2

      >The trick therefor for companies is to both have good account management AND hire professionals who care about not becoming a criminal.

      I found myself on the receiving end of the recession a year ago, having to suddenly tune my interviewing skills again. I still think one of my best selling points was being able to answer the "Why should we hire you?" question with this:

      "My position was eliminated and I was given a 90 day notice by my previous employer. At which point I was allowed to work through the full contract and not immediately escorted out. As an IT professional working under IT Managers who understood the security risk I posed, this was not an oversight, but the result of 8 years of working for this employer with integrity."

      I think if I had been removed from the premises, as policy normally dictates, I wouldn't have even brought it up. But since it played out this way, it gave me an angle to show loyalty and some dignity. And yes, my accounts were set to expire at 5pm the day I left.

  22. Re:Audits needed by _Sprocket_ · · Score: 2

    A post-it note kept in ones wallet? Secure

    When I need to do something like this, I use a several character cookie that resides in different positions of the passwords. The cookie is a placeholder for an additional sequence of characters - remove cookie and insert sequence (character count of cookie and sequence should not match). I never write the cookie down. When I need to use the password, I look it up on the slip in my wallet and then mentally replace the cookie with the actual sequence of characters. This allows for strong passwords unique to each system / environment that can be changed on a regular basis. I only have to remember a smaller sequence that is commonly used - less to remember and a better chance of repetition to help enforce / refresh that memory.

    Granted - an observant attacker who got possession of my password list might notice the cookie repeated in each password listed. But it does present an additional hurdle.

  23. Re:Audits needed by SvnLyrBrto · · Score: 2

    Sometimes the goal is not actually security. The goal is to comply with some regulation (PCI, HIPAA, etc.) whose authors did not understand security, but thought that monthly password changes, a 12-character minimum length, and no reuse for the last seven passwords in the history; makes for some fine theatre. Also, substitute "regulation" with "C-level exec" and you get a similar situation.

    Yes, I actually worked at a company once that had that password policy.

    --
    Imagine all the people...
  24. Don't know; don't wanna find out. by Beorytis · · Score: 2

    If I had to guess, I'd bet there was an account left over at a former employer, but there's no way I would check, even for curiosity. Seems like they might be dumb enough to leave a hole, lucky enough to notice the access, and vicious enough to make a legal issue of it. I know they were too dumb to disable the notices to my mobile phone when a NAS went into panic 2 months after they laid me off. I called to tell them about the problem before their contract "IT guy" arrived for the day.

  25. Re:wtf? by Frosty+Piss · · Score: 2

    Or exactly the same security as a password that is stored in Desktop/passwords.txt, anyway.

    That's why I stor my passwords in a text file named PamAnderson.mpeg.

    NO ONE ever even askes about it.

    --
    If you want news from today, you have to come back tomorrow.