<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: Lock the Network Doors and Swallow the Key</title>
	<atom:link href="http://www.geeksaresexy.net/2008/07/15/lock-the-network-doors-and-swallow-the-key/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.geeksaresexy.net/2008/07/15/lock-the-network-doors-and-swallow-the-key/</link>
	<description>tech, science, news and social issues for geeks</description>
	<pubDate>Wed, 07 Jan 2009 23:26:51 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Binary Assassin</title>
		<link>http://www.geeksaresexy.net/2008/07/15/lock-the-network-doors-and-swallow-the-key/comment-page-1/#comment-93570</link>
		<dc:creator>Binary Assassin</dc:creator>
		<pubDate>Thu, 24 Jul 2008 18:07:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.geeksaresexy.net/?p=3246#comment-93570</guid>
		<description>Jesus H! I think an execution just &lt;i&gt;might&lt;/i&gt; be going &lt;strong&gt;OVERBOARD&lt;/strong&gt; here! ouch.</description>
		<content:encoded><![CDATA[<p>Jesus H! I think an execution just <i>might</i> be going <strong>OVERBOARD</strong> here! ouch.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Claudel</title>
		<link>http://www.geeksaresexy.net/2008/07/15/lock-the-network-doors-and-swallow-the-key/comment-page-1/#comment-92445</link>
		<dc:creator>Claudel</dc:creator>
		<pubDate>Sat, 19 Jul 2008 20:05:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.geeksaresexy.net/?p=3246#comment-92445</guid>
		<description>Just another show for dummies, the media has no idea wtf they talking about nor wtf is going, nor that hole town knows how to regain access from local what a silly storry, infact hillariously retarded. Oh, i forgot its USA! nothing new, moving on.

I should put this along the other stupid things of the day, much more like a joke then a real story but heh was funny for like 5 seconds.

thanx for sharing anyway.</description>
		<content:encoded><![CDATA[<p>Just another show for dummies, the media has no idea wtf they talking about nor wtf is going, nor that hole town knows how to regain access from local what a silly storry, infact hillariously retarded. Oh, i forgot its USA! nothing new, moving on.</p>
<p>I should put this along the other stupid things of the day, much more like a joke then a real story but heh was funny for like 5 seconds.</p>
<p>thanx for sharing anyway.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Preston L. Bannister</title>
		<link>http://www.geeksaresexy.net/2008/07/15/lock-the-network-doors-and-swallow-the-key/comment-page-1/#comment-92035</link>
		<dc:creator>Preston L. Bannister</dc:creator>
		<pubDate>Fri, 18 Jul 2008 08:01:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.geeksaresexy.net/?p=3246#comment-92035</guid>
		<description>To "Marine", there is more than one possibility. Whether the guy accused is a "traitor" or a patriot is still not clear.

If you have worked with government agencies - some are excellent, and some are astounding in their lack of competence. The excellent organizations often depend on a very small number of skilled individuals.

It is possible that Childs is that single skilled individual working within the City of San Francisco government. 

The obvious possibility is that this Childs has gone weird for entirely personal reasons. On a national scale this sort of stuff happens regularly, and could well explain this particular case.

On the other hand, it is also possible that the "treason" is not Childs, but the folk in City government whose actions with which he did not agree. It is possible that he was asked to do something morally wrong, and he refused. 

Ask system administrators for cases where their bosses asked them to do something morally dubious. You will get a rather a lot of stories.

This entire story smells funny. Even if Childs went nuts, if the city employed someone competent, the entire problem should have been corrected in a small number of days, That this appears not to be true suggests that Childs was the only halfway-able guy employed by the city. Why did Childs refuse to help the city regain control? One possibility is that Childs went odd. 

This sort of stuff does happen.

Another possibility is that Childs was told to give administrative access to some political hack's idiot nephew. Ask around - this sort of nonsense occurs far too often. 

As to whether Childs is a traitor, a patriot, or a simple nutter - we do not as yet have anyway to judge.

... unless you think obeying "authority" is more important than defending the principles on which this country was founded. If blind obedience to authority is your belief, you have more in common with the Nazis than the Founding Fathers.</description>
		<content:encoded><![CDATA[<p>To &#8220;Marine&#8221;, there is more than one possibility. Whether the guy accused is a &#8220;traitor&#8221; or a patriot is still not clear.</p>
<p>If you have worked with government agencies - some are excellent, and some are astounding in their lack of competence. The excellent organizations often depend on a very small number of skilled individuals.</p>
<p>It is possible that Childs is that single skilled individual working within the City of San Francisco government. </p>
<p>The obvious possibility is that this Childs has gone weird for entirely personal reasons. On a national scale this sort of stuff happens regularly, and could well explain this particular case.</p>
<p>On the other hand, it is also possible that the &#8220;treason&#8221; is not Childs, but the folk in City government whose actions with which he did not agree. It is possible that he was asked to do something morally wrong, and he refused. </p>
<p>Ask system administrators for cases where their bosses asked them to do something morally dubious. You will get a rather a lot of stories.</p>
<p>This entire story smells funny. Even if Childs went nuts, if the city employed someone competent, the entire problem should have been corrected in a small number of days, That this appears not to be true suggests that Childs was the only halfway-able guy employed by the city. Why did Childs refuse to help the city regain control? One possibility is that Childs went odd. </p>
<p>This sort of stuff does happen.</p>
<p>Another possibility is that Childs was told to give administrative access to some political hack&#8217;s idiot nephew. Ask around - this sort of nonsense occurs far too often. </p>
<p>As to whether Childs is a traitor, a patriot, or a simple nutter - we do not as yet have anyway to judge.</p>
<p>&#8230; unless you think obeying &#8220;authority&#8221; is more important than defending the principles on which this country was founded. If blind obedience to authority is your belief, you have more in common with the Nazis than the Founding Fathers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marine</title>
		<link>http://www.geeksaresexy.net/2008/07/15/lock-the-network-doors-and-swallow-the-key/comment-page-1/#comment-91994</link>
		<dc:creator>Marine</dc:creator>
		<pubDate>Fri, 18 Jul 2008 05:09:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.geeksaresexy.net/?p=3246#comment-91994</guid>
		<description>I am a U.S ex Serviceman, Defending my nation is an oath I have taken. This man/systems administrator, has in my view, committed an act of treason against the government and the authorities. 

Acts of treason are punishable by death. This scum of a traitor should get the death penalty. Cyber terrorist.</description>
		<content:encoded><![CDATA[<p>I am a U.S ex Serviceman, Defending my nation is an oath I have taken. This man/systems administrator, has in my view, committed an act of treason against the government and the authorities. </p>
<p>Acts of treason are punishable by death. This scum of a traitor should get the death penalty. Cyber terrorist.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PatB</title>
		<link>http://www.geeksaresexy.net/2008/07/15/lock-the-network-doors-and-swallow-the-key/comment-page-1/#comment-91865</link>
		<dc:creator>PatB</dc:creator>
		<pubDate>Thu, 17 Jul 2008 16:57:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.geeksaresexy.net/?p=3246#comment-91865</guid>
		<description>Yeah, that thought crossed my mind too.  The story says he gave the password to the cops but it didn't work.  What if the cops fatfingered the password or couldn't find a special character on the keyboard-  and the result is that the sysadmin goes to jail?</description>
		<content:encoded><![CDATA[<p>Yeah, that thought crossed my mind too.  The story says he gave the password to the cops but it didn&#8217;t work.  What if the cops fatfingered the password or couldn&#8217;t find a special character on the keyboard-  and the result is that the sysadmin goes to jail?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave L</title>
		<link>http://www.geeksaresexy.net/2008/07/15/lock-the-network-doors-and-swallow-the-key/comment-page-1/#comment-91863</link>
		<dc:creator>Dave L</dc:creator>
		<pubDate>Thu, 17 Jul 2008 16:51:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.geeksaresexy.net/?p=3246#comment-91863</guid>
		<description>He probably forgot what the password is and is too embarrased to admit it.</description>
		<content:encoded><![CDATA[<p>He probably forgot what the password is and is too embarrased to admit it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John R</title>
		<link>http://www.geeksaresexy.net/2008/07/15/lock-the-network-doors-and-swallow-the-key/comment-page-1/#comment-91416</link>
		<dc:creator>John R</dc:creator>
		<pubDate>Wed, 16 Jul 2008 13:28:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.geeksaresexy.net/?p=3246#comment-91416</guid>
		<description>Very fishy. The more I think about it, the more it doesn't stack up. The statement &lt;i&gt;Multi-million dollar&lt;/i&gt; implies vendor involvement.

Network consolidation for the City of San Francisco is not something that a couple of enthusiasts tinkered with over the weekend, and would have had a number of project teams, even if the core IT Department only had a handful of staff.

Many IT Departments these days are just vendor managers. This story sounds like media sensationalism at its best, fanning the flames of distrust for IT staff who handle sensitive information.

The first question I ask is where are the policies, controls, and checks to prevent exactly this sort of thing happening? Someone should slap the city officials with a copy of ISO 27001. http://en.wikipedia.org/wiki/ISO/IEC_27001

This is the point where someone has an epiphany at City Hall and wonders whether or not they should have paid those consultants for a security review.</description>
		<content:encoded><![CDATA[<p>Very fishy. The more I think about it, the more it doesn&#8217;t stack up. The statement <i>Multi-million dollar</i> implies vendor involvement.</p>
<p>Network consolidation for the City of San Francisco is not something that a couple of enthusiasts tinkered with over the weekend, and would have had a number of project teams, even if the core IT Department only had a handful of staff.</p>
<p>Many IT Departments these days are just vendor managers. This story sounds like media sensationalism at its best, fanning the flames of distrust for IT staff who handle sensitive information.</p>
<p>The first question I ask is where are the policies, controls, and checks to prevent exactly this sort of thing happening? Someone should slap the city officials with a copy of ISO 27001. <a href="http://en.wikipedia.org/wiki/ISO/IEC_27001" rel="nofollow">http://en.wikipedia.org/wiki/ISO/IEC_27001</a></p>
<p>This is the point where someone has an epiphany at City Hall and wonders whether or not they should have paid those consultants for a security review.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PatB</title>
		<link>http://www.geeksaresexy.net/2008/07/15/lock-the-network-doors-and-swallow-the-key/comment-page-1/#comment-91233</link>
		<dc:creator>PatB</dc:creator>
		<pubDate>Wed, 16 Jul 2008 00:39:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.geeksaresexy.net/?p=3246#comment-91233</guid>
		<description>Preston and John,

Thanks for the feedback.  So its not just me that thinks some of this sounds fishy?

Preston, you may be quite right about the competence of the one guy in the Tech department.  And the article suggests massive consolidation of the infrastructure, which was likely due to budget constraints.  And a tighter budget would likely suggest a small staff.</description>
		<content:encoded><![CDATA[<p>Preston and John,</p>
<p>Thanks for the feedback.  So its not just me that thinks some of this sounds fishy?</p>
<p>Preston, you may be quite right about the competence of the one guy in the Tech department.  And the article suggests massive consolidation of the infrastructure, which was likely due to budget constraints.  And a tighter budget would likely suggest a small staff.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John R</title>
		<link>http://www.geeksaresexy.net/2008/07/15/lock-the-network-doors-and-swallow-the-key/comment-page-1/#comment-91209</link>
		<dc:creator>John R</dc:creator>
		<pubDate>Tue, 15 Jul 2008 23:09:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.geeksaresexy.net/?p=3246#comment-91209</guid>
		<description>I agree with the comments about fearmongering. Presumably "city officials" can provide physical access to servers and routers to other equally intelligent non-criminal masterminds. So the router passwords can be reset in, oh, about 35 secs via the serial port, and the servers can be booted into various recovery modes depending on what sort of operating systems they are running. It's the application level passwords that are likely the difficult ones.</description>
		<content:encoded><![CDATA[<p>I agree with the comments about fearmongering. Presumably &#8220;city officials&#8221; can provide physical access to servers and routers to other equally intelligent non-criminal masterminds. So the router passwords can be reset in, oh, about 35 secs via the serial port, and the servers can be booted into various recovery modes depending on what sort of operating systems they are running. It&#8217;s the application level passwords that are likely the difficult ones.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Preston L. Bannister</title>
		<link>http://www.geeksaresexy.net/2008/07/15/lock-the-network-doors-and-swallow-the-key/comment-page-1/#comment-91192</link>
		<dc:creator>Preston L. Bannister</dc:creator>
		<pubDate>Tue, 15 Jul 2008 21:38:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.geeksaresexy.net/?p=3246#comment-91192</guid>
		<description>That no one seems(?) to know how to re-gain access suggests that Childs may be the only semi-competent guy there. This is very odd.

One of the first rules of security is that if you have physical access to the hardware, you can almost certainly subvert any software security. Unless he encrypted the contents of every hard disk (unlikely - especially if the system is running and functional), there is always a secondary path for resetting security when you have physical access.</description>
		<content:encoded><![CDATA[<p>That no one seems(?) to know how to re-gain access suggests that Childs may be the only semi-competent guy there. This is very odd.</p>
<p>One of the first rules of security is that if you have physical access to the hardware, you can almost certainly subvert any software security. Unless he encrypted the contents of every hard disk (unlikely - especially if the system is running and functional), there is always a secondary path for resetting security when you have physical access.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Binary Assassin</title>
		<link>http://www.geeksaresexy.net/2008/07/15/lock-the-network-doors-and-swallow-the-key/comment-page-1/#comment-91165</link>
		<dc:creator>Binary Assassin</dc:creator>
		<pubDate>Tue, 15 Jul 2008 19:04:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.geeksaresexy.net/?p=3246#comment-91165</guid>
		<description>I like stories like this, especially seeing as I am a network administrator. 
Thanks, and keep 'em coming!</description>
		<content:encoded><![CDATA[<p>I like stories like this, especially seeing as I am a network administrator.<br />
Thanks, and keep &#8216;em coming!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
