News: 1657269010

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

This is the military – you can't just delete your history like you're 15

(2022/07/08)


On Call Welcome to an [1]On Call where on-site misdeeds resulted in the most dishonorable of discharges.

Our story, from a reader we have Regomized as "Jones", takes place in the early years of this century and concerns some military gear supplied by his company.

While the computers (which ran Windows) were not connected to the internet for obvious reasons, they were powerful beasts and used for processing images and operating equipment. During training, the operators were told that while the kit was capable of playing music or movies, it was strictly forbidden to go sticking DVDs or external storage devices into them. Nothing was to be inserted into the various ports or slots without express permission from the designated person on site.

[2]

Sadly, simply disabling the USB sockets (or filling them with glue) was not an option since data occasionally had to be downloaded from the hardware. The same applied to the DVD drive.

[3]

[4]

Time passed, and one particular site developed the annoying habit of frequently going down, sometimes several times a week.

"Part of our job," said Jones, "was if there was a problem with a site, we dropped whatever we were doing and by any means necessary got a tech to the site.

[5]

"Now I can tell you that getting to some sites took a bit of creativity and trust. You call, we haul."

And haul he did. With some of the military sites lurking deep in the desert, being On Call was a particular challenge.

The computer itself had a very large (for the time) hard disk, divided into four partitions with two used for image storage. Part of the operator training was to take current images, once a certain size had been reached, and shunt them into another partition for archiving, and then delete the original.

[6]

"In those partitions were some hidden folders that kept data about operating parameters and resource usage along with thumbnails," explained Jones.

On this one desert site, the computer kept falling over, or running painfully slowly. After a few call-outs, Jones decided to dig a bit deeper and find out what was going wrong. The computers weren't on the internet, did not take updates, and every couple of months a full reinstall would happen ("you know how Windows always works better on a fresh install," commented Jones).

So why was this one failing?

[7]NOBODY PRINT! Selfless hero saves typing pool from carbon catastrophe

[8]The perfect crime – undone by the perfect email backups

[9]Password recovery from beyond the grave

[10]How one techie ended up paying the tab on an Apple Macintosh Plus

There was a small leftover bit of the partition, intended for swap files. It was also where hidden files lurked, created when, say, looking at images and viewing videos.

Armed with an account of suitable privilege, our hero opened up the hidden folder and archive. And probably wished he hadn't.

"I found a ton of thumbnails with timestamps and source data for each…"

It appeared that the personnel assigned to the post were a bit bored, and so would occasionally pop in an external storage device in order to watch videos of a NSFW nature. The timestamps made identification of the culprits easy. The limited space meant that there was less capacity for swapping, hence the sluggish performance and occasional lock-ups.

"Unfortunately for them," said Jones, "even though they were very diligent in covering their tracks, they missed that hidden archive file."

What to do? Since the poor performance and crashes were nothing to do with what the computer was designed for, Jones opted to download the evidence and present it to the powers that be. He also tweaked the configuration so the USB ports could only be used to download data.

And the pair with the mucky military habits? Stripped of their respective ranks, they spent the rest of their tour doing hard labor before being shipped back for a dishonorable discharge and a stint behind bars, according to Jones.

Ever been called out to deal with a performance problem and seen something you couldn't unsee? Or told users to never, ever do something you knew they would do the moment the door closed behind you? Share the call-out you'd rather forget with an email to [11]On Call . ®

Get our [12]Tech Resources



[1] https://www.theregister.com/Tag/on-call

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YsgAQibysiyEgnd6mvH1TQAAAIc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YsgAQibysiyEgnd6mvH1TQAAAIc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YsgAQibysiyEgnd6mvH1TQAAAIc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YsgAQibysiyEgnd6mvH1TQAAAIc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YsgAQibysiyEgnd6mvH1TQAAAIc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2022/07/01/on_call/

[8] https://www.theregister.com/2022/06/24/on_call/

[9] https://www.theregister.com/2022/06/17/on_call/

[10] https://www.theregister.com/2022/06/10/on_call/

[11] mailto:oncall@theregister.com

[12] https://whitepapers.theregister.com/



We've Probably All Come Across This

Wally Dug

The (rather annoying and arrogant) sales manager who kept complaining about the speed of his laptop eventually sent it to us to have a look. As part of the troubleshooting, I looked at his Internet browsing history. Completely empty. Curiosity piqued now, I looked at the Internet cache - full of pr0n, so a word to my boss who said that we had no option but to report him to HR. Who made him an ex-sales manager. And, yes, he had signed an Internet usage form and he also denied looking at the pr0n.

P.S. we have Regomized as "Jones" Don't panic, I see what you did there, well done.

Anonymous Coward

Many years ago, I worked in the computing department of a university. A chunk of the estate was Solaris, with automounted shares from various servers to the desktops that some of the researchers used. Shares included a central /usr/local/bin for distributing software, home directories, web server content, etc.

At some point I became aware that the web server share was rather more full than I'd been expecting, this being the days when web pages and images were generally fairly small. After digging through with "du", I found a folder owned by one of the researchers containing many pictures of women without much in the way of clothing... Nuked the folder and left a README.TXT file which said something like "who's been a naughty boy?" and chown'd it to his ID.

The folder and README were gone 2 days later...

What got me about this was that he had a workstation on his desk which had a decent sized home directory for his own use; a directory I'd almost certainly never have found anything in without specifically needing to check. If he'd kept his porn stash there, it would likely never have been found...

Killfalcon

So often, it's the overly-complex hiding the tracks that gets people caught.

There was a manager at a big insurer (er, let's call them Celtic Bereaved) back in the 90s who was just writing himself cheques from the company, and approving them. Due to the volume of cheques moving around and the trusted (at the time) position he was in, this wasn't caught, and the final investigation confirmed that if he'd just kept doing that he'd never have been caught! If nothing else, these payments were so regular that anyone who might process them would just see them as "another one of those" - completely routine, and not suspicious.

What got him caught was he started moving money around between other accounts to 'disguise' the payments, and one day one of these cover payments attracted a desk jockey's attention as being a bit odd, asked a few questions and before you knew it, manager's in handcuffs and the board are setting up a team specifically to audit managers who have the authority to both raise and approve payments.

Written reports on pron.

DrBobK

As a junior academic, but with some IT skills, I was once given the task of determining whether our senior IT technician, who had been caught 'red-handed' watching porn, had downloaded or viewed any illegal material. This was a very strange task, but the strangest, and hardest (not intended as ooh-err-missus) part was that I was expected to write a report for the Head of Department describing exactly what sort of things he had been watching even if they were not illegal. A rather tricky assignment, and I was never quite clear why the non-illegal material had to be desired in detail!

Re: Written reports on pron.

veti

So... For a brief time, it was actually your job to watch somebody else's playlist of porn?

Sounds horrible.

what rules?

Mike 137

An associate once set up a small 'red & black' computer unit in a war zone. The red and black machines were of course electronically and electrically isolated and the statutory distance apart. He returned a couple months later to find a USB stick suspended from the ceiling between the two machines on a length of elastic.

Only Once...

GlenP

I've only found dodgy material once on a work machine, but then I don't normally go looking for it. As the person had already left the company there wasn't much I could do except report it to HR and delete it.

I did hear a story, which may or may not be true, from the early days of CD writers. The evening shift lab tech at one of the UK's nuclear establishments was spending most of his time duplicating dodgy material for sale.

You need to know how to clear a paper jam if you are going to print dodgy material

ColinPa

At work, one of the printers had a paper jam. I cleared it, and it started printing its backlog. One of the documents looked like a list of porn sites. I took it to my manager who dealt with it. The offender was called in, and denied all knowledge of the document. The manager said he would call the IT department to scan the computer for this document, or any other suspicious documents. Suddenly the offender decided it might be better if he took early retirement.

It's happened to me a few times...

DailyLlama

I was in my office one day circa 2001, and "someone" came in and put a Zip disk (remember them?) into the drive of a computer used by someone who wasn't in that day. Then went back to their own desk.

Then I noticed the activity light flashing a lot, and being a nosy bugger (and not trusting this person a jot), I opened Windows Explorer and went to the Zip drive, and found that the disk was filling up with images of women who had clearly gotten too warm, and decided to remove all their clothing.

Screenshots were duly taken (of filenames, not the images), and information sent to HR & Management, whereupon the user in question claimed that he was "copying it for a friend who didn't have internet access). Management then decided that even though there was a precedent of sacking people caught doing this kind of thing, that he merely merited a warning.

Every single time

elsergiovolador

[1]Every single time when someone told me their computer is slow

[1] https://i.kym-cdn.com/photos/images/newsfeed/000/605/041/dd7.jpg

Let me ask the board

Admiral Grace Hopper

If you're really lucky, [1]there's a member of the board handy when you find something interesting .

I always enjoyed explaining access and audit logs to people hitherto unaware of their role or indeed their existence.

[1] https://forums.theregister.com/forum/all/2020/04/03/on_call/#c_4007629

I believe the story

Anonymous Coward

But not the punishment

Never eat more than you can lift.
-- Miss Piggy