Welcome | Sign In
TechNewsWorld.com
Cyberattacks

Renegade Sysadmin Gives Up Secret Passwords to SF Mayor

Print Version
E-Mail Article
Reprints
Renegade Sysadmin Gives Up Secret Passwords to SF Mayor

San Francisco's highly publicized case of a teed off sysadmin freezing the city's computer network should not be viewed as an isolated incident. Unless proper background checks are conducted -- and backup systems put in place -- any network could be vulnerable to the same type of mischief.


eMarketer Whitepaper: Optimizing the E-Commerce Experience
From the Web to the Contact Center, are you prepared to proactively engage and keep your savvy customers? Read how e-commerce leaders are optimizing their sites with ratings, reviews, live help, Web analytics, mobile and more.

Usually, it's a mayor who hands out the key to his or her city to residents deserving special recognition. In San Francisco's case, it was Mayor Gavin Newsom who took back the key to his city's computer network from the man who held it hostage for more than a week.

The only positive recognition system administrator Terry Childs is likely to get from his escapade is credit for alerting other cities to take a second look at their information technology security practices.

Childs was jailed July 13 after he changed crucial passwords to the city's wide area network. He was held on US$5 million dollars bond while experts from Cisco Systems (Nasdaq: CSCO) attempted to restore access without disabling the entire system.

On Monday, July 21, Childs said through his attorney that he would give up the new passwords, but only to Mayor Newsom. By Tuesday evening, the city was back in control of its own computer network.

How Could This Happen?

Childs may have been driven to enact his cyber-sabotage plan because of what he called "incompetence" at the Department of Telecommunications and Information Services, where he worked for five years, Childs' attorney, Erin Crane, has told reporters. The department had recently seen cutbacks and layoffs, and Childs apparently was worried about potential damage to city networks.

Lean budgets are indeed an issue in the IT world, but cutbacks can also make someone like Childs more valuable.

"The problem with city and state governments is that a lot of times, they don't have a lot in their IT budgets," Paul Ferguson, advanced threat researcher at Trend Micro (Nasdaq: TMIC), told TechNewsWorld.

"We see the same problem all the time -- they hire some third party to set up Web sites or networks, and the consultant collects the money and goes on their way. We have a real hard time finding the right person to clean up the problem," Ferguson said, "because there's no expertise there. It's usually a smalll number of people who have high-level access to the network infrastructure and have the ability to wreak havoc should the opportunity arise."

What Other Cities Should Do

San Francisco's embarrassing IT debacle is a lesson for other municipalities and those who are in charge of their networks.

"They should review their processes," Jamz Yaneza, threat research manager at Trend Micro, told TechNewsWorld.

"It's basically Network 101 to make backups and audit trails of everything," he noted. "Also, you need [to conduct] due diligence of the process and find out who's in charge of what, do background checks. It depends on how much trust you put on the person doing the [system] configuring. Have you done your background checks on this guy? But, on the other hand, have you done your own homework to make sure there are backup processes in place?"

Other cities are likely vulnerable to their own insider threats, according to Ferguson.

"It will happen again," he predicted. "It's happened in the past where some disgruntled employee has planted logic bombs."


Print Version E-Mail Article Reprints More by Renay San Miguel


Talkback: Join the Discussion.
DTIS Disaster Recovery website
Permission
Posted 2008-08-16
DTIS Disaster Recovery website, created by the City's "Enterprise Engineer" William ...
Misleading
Permission
Posted 2008-08-07
..."Childs may have been driven to enact his cyber-sabotage plan "... ...
Misleading
Permission
Posted 2008-08-07
..."Childs was jailed July 13 after he changed crucial passwords to the city's wide area ...
Not frozen.
Permission
Posted 2008-08-07
..."freezing the city's computer network"... ...
Misleading
Permission
Posted 2008-08-07
..."it was Mayor Gavin Newsom who took back the key to his city's computer network from the ...

More by Renay San Miguel

Sony Talks Up Plans for Digital Media Superstore
November 20, 2009
Sony is one of the few companies in the world with an ecosystem of hardware and services that could match Apple's. It just doesn't mesh together nearly as smoothly as Cupertino's. Sony executives want to change that. They've announced plans to build an online network that ties in many of the company's products and allows users to download a wide variety of content.
Playboy's Bunny Couldn't Make the Hop to the Web
November 20, 2009
The party may be winding down for Playboy. Buyers may be attempting to wheel a deal for Playboy Enterprises, which could in turn bring an end to a publication long past its heyday. It seems that a magazine that was one of the first to storm the barricades of censorship couldn't conquer 21st-century cyberspace.
AOL Spinoff May Send Third of Workforce Reeling
November 19, 2009
When it parts ways with Time Warner next month, AOL will likely begin laying off as many as 2,500 workers, about a third of its staff, the company said. The once-mighty portal and Internet service provider faces the task of redefining itself and deciding which of its assets to keep and which to let go. There's still some hope for the company that gave millions their first glimpse of the Internet.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network