TechRepublic : A ZDNet Tech Community

IT Leadership

Host: Toni Bowers
Contact

The situation has finally happened. A network admin has brought a city to its knees by changing the master system password. What IT leadership needs to learn from this situation. And what they need to do to cope.

______________________________________________________________________________

Hollywood, the nice people who taught us that if you blindly pound the keys on your keyboard actual commands will magically appear on the screen, never saw this coming. Or maybe they did and didn’t want to scare us with actual fact. Now it has happened.

Terry Childs, a 43 year old network administrator for San Francisco’s Department of Telecommunications and Information Services is currently in jail and being held on $5 Million bail. He is accused of altering the city’s FiberWAN network system to deny service to authorized users and setting up devices that would allow unauthorized service to the system.

I hope that our Security blogger, Chad Perrin will speak to the security issues in this case. My focus is on the leadership issues that arise from this situation.

What we currently know is that Childs has been employed by the city for five years. When he was hired he disclosed that he is a convicted felon- aggravated robbery and aggravated burglary in 1982. He was on probation or parole until 1987. According to a city official, Childs had recently been disciplined on the job for poor performance and was potentially to be fired.

It is believed that Childs began tampering with the system around June 20. He set a master password that cannot be overridden and does not allow for sufficient access to upgrade or maintain the system. Further, it appears that he may have enabled a third party to access data from the system that houses the 311 system, the city e-mail system, and the city servers, including confidential information. It also appears that he was reading his bosses e-mail.

I am so glad to not be this guy’s manager today. Even happier that I am not the manager’s manager or the person who hired this guy.

The city has brought in Cisco Systems to help them to get back in control of their brand new $3M system. They think that the bill to hack back the system may run into the millions. And Childs is being held on four felony charges. But how did it get this far?

Apparently the city hired a new head of security some months ago. She began auditing who had password access to the system. Childs seemed to not handle this well and began photographing her. His behavior became increasingly possessive of the system but he continued to have access to it. In addition, he had access to his bosses emails regarding his conduct. At least until he was taken into custody on July 13. But why did it take so long?

It is difficult to see the whole picture as events are unfolding. In hindsight, I am sure that we all agree that this guy should have been assigned to work with another system or simply put on administrative leave until the mess was sorted out. That never happened.

As the leader in this IT group, how do you go about insuring that the problem cannot happen again? How do you keep it from happening in the first place?

Childs’ behavior had been increasingly odd since June 20. To the city’s credit, an investigation of Childs had been undertaken but it appears that no one thought to limit his access to the system. I would have thought that would be the first step.

In the same situation, I would have taken the time to pull the employee off the system and at the least, had a chat about what was bothering him to the point that he felt it necessary to photograph his seniors and monitor their email. But there must have been earlier warning signs that were overlooked.

Regardless of what was missed and what should have been done differently, leadership has a difficult task in front of it. Beyond all the additional workload that is being shunted to Cisco, leadership needs to consider the other admins who are doing the same or similar job and consider how they can avoid a repeat of the situation. That will mean some discussion with the employees but in a manner that is not threatening to them. Certainly it will mean new oversight and new processes.

Normally, I would work with the Administrator team to define what the new processes should look like and incorporate the ideas into a new plan that we can all feel comfortable with. But given the situation, I should reconsider how much input I should take from the team. After all, a member of the team caused this problem. On the other hand, I can’t blame the whole team for the actions of a rogue employee.

What would you do as the manager of this department, given this situation? Is there any “right” answer? Or is this situation truly breaking new ground?

More information:

SF Officials Locked out of computer network (San Francisco Chronicle)

Computer Engineer keeping quiet on lockout (San Francisco Chronicle)

SF city worker charged with computer tampering (CBS5)

Print/View all Posts Comments on this blog

When your network admin hijacks your system TiggerTwo | 07/16/08
Single point of failure Iam_Mordac | 07/16/08
I get it TiggerTwo | 07/16/08
A good way to minimize this: BETTER SALARIES! bruno_n1 | 07/21/08
Poor Fellow, only made $150,000 per year! Dr Dij | 07/21/08
It's all relative, my friend bruno_n1 | 07/22/08
Not Very Much... Brett.Blatchley@... | 07/23/08
Salary not enough for San Fran. john.wang@... | 07/22/08
a rogue employee paulob@... | 07/21/08
$5 Million Deposit required to work here trrrr@... | 07/16/08
The Reset Button jacl@... | 07/16/08
As I understand it TiggerTwo | 07/17/08
Back-up copy of the config geonetworks@... | 07/17/08
not so quick, ROMMON disabled, not so simple to recover bakerga@... | 07/18/08
If I could raise that sort fo deposit alex.kashko@... | 07/18/08
Management must accept blame Steve Romero | 07/16/08
Another reason to agree with Evangelist patmurray12@... | 07/17/08
Well said! ws3d | 07/17/08
WHO IS GOING TO GUARD THE GUARDS? geonetworks@... | 07/17/08
PS: geonetworks@... | 07/17/08
Reading emails and taking photos? john.morrison@... | 07/22/08
who is going to snoop on the snoopers? geonetworks@... | 07/22/08
Well yes but alex.kashko@... | 07/18/08
Rotation of personnel? bruno_n1 | 07/21/08
IT Governance in limelight... mncube@... | 07/28/08
Hijack Ed Woychowsky | 07/17/08
Biggest problem I see bkinsey@... | 07/17/08
AMEN brother! TiggerTwo | 07/17/08
No Tig the problem started long before this happened HAL 9000 | 07/17/08
Documentation garye@... | 07/17/08
yes sir, say it again bakerga@... | 07/18/08
Brilliant point jredmon@... | 07/17/08
Cutting a deal is sensible alex.kashko@... | 07/18/08
Send him to Jail. Fire the people that hired him. tnstomtns | 07/17/08
"awesome responsibility".... agree, but.... bruno_n1 | 07/21/08
Security bill@... | 07/17/08
you will not be able to stop the havoc bakerga@... | 07/18/08
Well for starters HAL 9000 | 07/19/08
This should never had happened Gastón Nusimovich | 07/17/08
Wake up people chezis34@... | 07/17/08
What to do?? hus34tb@... | 07/17/08
No, if your network and security zlitocook@... | 07/17/08
Cisco, not MS Zontago | 07/21/08
As long as you have physical access to the box jdclyde | 07/21/08
If they guy was there for FIVE YEARS jdclyde | 07/21/08
This is merely an extreme case alex.kashko@... | 07/18/08
Cisco IOS rootkit for Management backdoor???? bakerga@... | 07/18/08
So funny... daveb@... | 07/22/08
several things could do... tomofumi | 07/22/08
This is management failure martinsepion@... | 08/01/08
They should try this little Nazi, BernieLyons | 12/24/08
Waaaay late off the mark seanferd | 12/25/08
ah.. you named that old political party Neon Samurai | 12/25/08
RE: When your network admin hijacks your system shasca | 07/16/08
Was he a rouge employee? NickNielsen | 07/16/08
I fixed the spelling boo boo TiggerTwo | 07/16/08
Send him to GitMo jacl@... | 07/16/08
Of course they will neilb@... | 07/17/08
why rob mekel | 07/17/08
Last I heard jdclyde | 07/17/08
Damn those liberals!!!! maecuff | 07/17/08
You're right Mae jdclyde | 07/17/08
The entire problem here is the Bureaucracy OH Smeg | 07/16/08
No offense but... shodges119@... | 07/17/08
Oh, boy ... OH smeg ... you can't realy mean that. rob mekel | 07/17/08
Rob I've just had a couple of days of dealing with Bureaucrats again. :( HAL 9000 | 07/17/08
I agree william.burgesen@... | 07/17/08
Here is what I don't understand HAL 9000 | 07/17/08
You're an idiot jredmon@... | 07/17/08
:D :D :D :D :D :D HAL 9000 | 07/17/08
holy goldfish Col! Shellbot | 07/17/08
Holy Goldfish???? The Scummy One | 07/17/08
Holy Goldfish Steffi28 | 07/17/08
its comlpicated Shellbot | 07/18/08
I am just totally, totally w2ktechman | 07/18/08
shucks.. Shellbot | 07/22/08
:) -- Its been so long The Scummy One | 07/22/08
No Shelly HAL 9000 | 07/19/08
Oi! CuteElf | 07/20/08
As is yours JR The 'G-Man.' | 07/18/08
And who is the bigger idiot jredmom OH Smeg | 07/19/08
HAL I am concerned TiggerTwo | 07/20/08
~sigh~ -- Tigs, it is not w2ktechman | 07/20/08
No Tig, Boxy Introduced me to Vista. :D HAL 9000 | 07/21/08
Thanks for proving my point jredmon@... | 07/21/08
Here is a piece of paper go file it HAL 9000 | 07/21/08
Don't even know where to start... bernalillo | 07/21/08
That is why cutbacks are a bad idea jdclyde | 07/17/08
hey jd jck | 07/17/08
There is a backup for every position jdclyde | 07/17/08
incompetence?? jck | 07/17/08
Not everything is a "them and us" jdclyde | 07/17/08
actually... jck | 07/17/08
in conjunction.... jdclyde | 07/17/08
nope...it doesn't... jck | 07/17/08
The big 3's problems RFink | 07/17/08
Too Much Pain? Brett.Blatchley@... | 07/23/08
Rubbish it will make no difference to anyone but the unknowing HAL 9000 | 07/24/08
How exactly would bernalillo | 10/07/08
There are signs to look for in a weasle jdclyde | 10/08/08
Re Hijacking your system rob mekel | 07/17/08
Thanks Rob! TiggerTwo | 07/17/08
They'll import one NickNielsen | 07/17/08
Yes, the Joker... seanferd | 07/17/08
Poor internal controls angry_white_male | 07/17/08
Is it just me .... Slartibartfast | 07/17/08
It would be my guess jdclyde | 07/17/08
Thanks for that seanferd | 07/17/08
Glad to serve jdclyde | 07/18/08
add in more backdoors egpor95@... | 07/21/08
Just like any compromised system jdclyde | 07/21/08
Get NSA Involved... Brett.Blatchley@... | 07/23/08
RE: When your network admin hijacks your system thepaulmorris@... | 07/17/08
What? You can't trust a convicted FELON with your system? kstarks@... | 07/17/08
But thanks to these same people jdclyde | 07/17/08
Hey? This is San Francisco. He had only committed... JohnMcGrew@... | 07/17/08
What? You can't trust a convicted FELON with your system? UKBasedITAnalyst | 07/17/08
Yeah, how dare someone jdclyde | 07/17/08
No the problem here isn't the fact that this guy is guilty of a HAL 9000 | 07/17/08
Ka-Ching! seanferd | 07/17/08
That's what judgement is for.. Brett.Blatchley@... | 07/23/08
ANYONE is capable of this; not just an Ex-Con.. delpurg | 08/01/08
A more intesting debate might be... JohnMcGrew@... | 07/17/08
John, I agree completely TiggerTwo | 07/17/08
Disappear? Brett.Blatchley@... | 07/23/08
Not these days, and not in San Francisco JohnMcGrew@... | 07/24/08
A deal is in the works Ragged_Scooper | 07/17/08
Have we learned nothing? jredmon@... | 07/17/08
Black Mail Money & Freedom jacl@... | 07/17/08
It Should Not Though The Scummy One | 07/17/08
Can he profit? seanferd | 07/17/08
I don't think so TiggerTwo | 07/18/08
With Publicity & Notoriety Comes $$$$$$ jacl@... | 07/18/08
You're right Jaci TiggerTwo | 07/18/08
another aproach to add Neon Samurai | 07/18/08
Hmmm. Notoriety. seanferd | 07/19/08
If this clown thinks that he's gonna profit from his "notoriety"... JohnMcGrew@... | 07/20/08
Of course it doesn't work... JohnMcGrew@... | 07/20/08
Is this all he was up to? BillT174 | 07/17/08
RE: When your network admin hijacks your system john.wang@... | 07/17/08
Ya gotta love this bit. (?!) seanferd | 07/18/08
That Explains It All w2ktechman | 07/18/08
And it's all "just a misunderstanding". seanferd | 07/19/08
And exactly what it sounds like too HAL 9000 | 07/19/08
What are the Chances that This Could be the Next Terrorist Attack? cactii1@... | 07/18/08
Hmmm, did you perhaps watch w2ktechman | 07/18/08
Done and done seanferd | 07/19/08
Yep totally correct HAL 9000 | 07/19/08
More information NickNielsen | 07/19/08
And Nick this shows HAL 9000 | 07/19/08
And Hal this also shows NickNielsen | 07/20/08
Yes Nick I was suspicious when I read that they "Thought" HAL 9000 | 07/20/08
Fawlty Networks? NickNielsen | 07/20/08
Basil! seanferd | 07/20/08
Every Bit is Sacred CuteElf | 07/20/08
:D NickNielsen | 07/21/08
Brava! Brava! Encore! neilb@... | 07/21/08
But Nick, I never said it was TiggerTwo | 07/21/08
Sorry, Tig NickNielsen | 07/21/08
Tig the Important word here is Speculation HAL 9000 | 07/21/08
RE: When your network admin hijacks your system michael@... | 07/21/08
It is easy to provide that level of critique TiggerTwo | 07/21/08
While I do agree with you Tig HAL 9000 | 07/21/08
The basic computer security model just really sucks. doug@... | 07/21/08
Peter Principle at Work cduncan@... | 07/21/08
Peter Principle, Yes, but not in Childs' case tfloyd@... | 07/21/08
RE: Peter Principle, Yes, but not in Childs' case cduncan@... | 07/22/08
RE: When your network admin hijacks your system waltrutka@... | 07/21/08
What! again, oh, it was a government, never mind... mikifinaz1@... | 07/21/08
I use Linux to side step this issue... mikifinaz1@... | 07/21/08
So perhaps you care to explain how to achieve this with HAL 9000 | 07/21/08
When people are not paying attention jdclyde | 07/22/08
Well JD I thought I was missing something here HAL 9000 | 07/23/08
Indeed it does Col jdclyde | 07/23/08
It wouldn't surprise me one little bit either HAL 9000 | 07/23/08
RE: When your network admin hijacks your system meollex@... | 07/22/08
Updates ayotunde | 07/23/08
Yep, there's backdoors into everything. doug@... | 07/24/08
Re: When your network Admin hijacks your system sarthurk@... | 02/27/09
NT Admins! The 'G-Man.' | 02/27/09
RE: That applies to any worker in any fold! HAL 9000 | 02/27/09
Guess so The 'G-Man.' | 02/27/09

What do you think?

White Papers, Webcasts, and Downloads

Recent Entries

TR on Twitter

Archives

TechRepublic Blogs



Quick Reference: Linux Commands
Reduce stress and speed up resolutions with the easiest command references right at your fingertips. You'll receive a PDF file covering Linux, packed with the most common commands you'll need and use daily.
Buy Now
Administrator's Guide to TCP/IP, Second Edition
Maintain your critical TCP/IP system and ensure reliable, safe remote access. Get the expert advice and solutions to handle Windows networking, Cisco routing, documentation, and troubleshooting.
Buy Now

Popular Sanity Saver Videos