Judge Orders Former San Francisco Admin Terry Childs To Pay $1.5M
0WaitState writes "A judge Tuesday ordered a former city worker who locked San Francisco out of its main computer network for 12 days in 2008 to pay nearly $1.5 million in restitution, prosecutors said.' Keep in mind the network never went down and no user services were denied, and given that Terry Childs was the only one who had admin access (for years prior) it is difficult to understand how they came up in $1.5 million in costs, unless they're billing Terry Childs for the City's own failure to set up division of responsibility and standby emergency access procedures?"
We will make an example out of you, who cares about justice?
That explains why American culture is so obsessed with vigilante justice - the actual judicial system is fucking retarded .
Terry Childs did some mistakes. I think the restitution for damages is more justified than the criminal punishment he got.
CU, Martin
I forget a lot of what he said, but one of the points which stuck out for me was that Terry kept the keys / passwords out of the key management system, which was against policy. He kept the Keys to the Kingdom in his head, which is just bad IT policy. He also cleaned the backup configs on switches so that any reboots would essentially wipe them clean.
/. poster was on the jury. He'll chip in with better information than anyone else. As for the fine... Well, if he doesn't have that money, he'll default like everyone else would and live off welfare. Shows the system works, eh?
Like I said, a
Finally had enough. Come see us over at https://soylentnews.org/
At first I thought the citizens were going to have to pay for the cleanup and fixing of all the problems, along with the trial and all that. Now that I know this criminal with no job prospects will be paying the $1.5M I can sleep better at night.
My personal ideas about job integrity end at or a little before the threat of getting arrested so I could argue I don't think what he did was wise (I would've made the guy wanting the passwords put it in writing and then quietly laughed when they broke things), but I don't think the punishment fits the crime at all. Why is there never a middle ground in the justice system between ruining someones life and letting them go free?
And why can't the city just let this one go? They won a long time ago.. back when he was fired, jailed, etc and he surrendered the passwords without the network ever going down.
He did not care about security other than his own job security. He was one of 'those' types of IT people. You know the ones I mean -- they think "job security" means keeping all the secrets locked away so that only he can fix things when they are broken. Furthermore, they tend to behave as if they own the networks and servers they maintain and they tend to hide their limitations of knowledge and experience from others as well as being unwilling to share what little knowledge they actually have. There might have been a time when that was common enough to be acceptable, but today's business and government leaders see through this.
Good riddance to bad rubbish. "Vendor lock-in" is evil regardless of who practices it.
The problem isn't that we're defending him. Most people on Slashdot think he's an idiot and a criminal. The problem is the $1.5 million fine. That's around 20 years of his salary (at a comfortable $75k/yr). It's not a matter of whether or not he's guilty or deserves punishment, it's a matter of letting the punishment fit the crime. That pesky eighth amendment that mentions no excessive fines.
"...unless they're billing Terry Childs for the City's own failure to set up division of responsibility and standby emergency access procedures?"
What exactly is being insinuated here? That it's the City's fault that Childs decided to commit a crime?
Sorry, pal, it doesn't work that way. Yes, the city has a lot of work to do to clean up its IT policies, but that has no bearing whatsoever on Childs' decision to commit a criminal act.
"Ask not what your country can do for you." --John F. Kennedy
Terry Childs was clearly on an excessive one-man power trip. I don't think too many on /. think that deserves jail time though.
A firing for unprofessional conduct: sure.
A $1.5M fine? This just adds to the farce.
I'm sure the head of the IMF will get a fair trial.
He has already been convicted (by the media) and is in jail. ... now all we need to do is to get most of Wall Street in jail.
They have been tried in the media but not put in jail.
Mr. Childs clashed with the new Security Manager on the subject of authentication and control, which led to poor formal review.
Sorting out fact from fiction in the Terry Childs case
he's paying it to the department of technology, not justice
Just because it's not a court-ordered bribe doesn't mean it's definitely not a punishment verdict.
yes, withhold passwords on a network resulting in no measurable loss, get 20yrs of income as fine. Damage and destroy an ecosystem causing loss of animal life and depressing an entire area economically; get fines that amount to about 7~mos of income. That's called justice.
If you think imaginary property and real property are the same, when does your house become public domain?
Oh bullshit. He was part of the incompetence . At what point do we admit that Mr. Childs was just as irresponsible for neglecting to create an appropriate backup and contingency plan for outages, disaster recovery, etc. that allowed for someone else to get access to the passwords?
Where I'm sitting, any sysadmin with half a brain knows that a single point of failure is a no-no. Let's not pretend he was some white knight, if there were no adequate plans for password access in place, then he's just as incompetent as his managers were. Only difference is, he was incompetent, and broke the law in the process, by refusing to turn over the password to his management chain when he was reassigned and holding the network he was "protecting" hostage.