News: 1705048270

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

While we fire the boss, can you lock him out of the network?

(2024/01/12)


On Call Welcome once more, dear reader, to On Call, The Register 's weekly reader-contributed column detailing the delights and dangers of working in tech support.

This week, meet a reader we'll Regomize as "Alvin" who regaled us with the tale of the time one of his clients told him their chief network engineer was suspected of having improperly accessed HR files.

Their evidence for the allegation was temp files that showed the engineer's account had been used to open certain documents he had no business seeing – never mind reading as thoroughly as the metadata trail indicated.

[1]

Alvin was asked to sit in on a disciplinary meeting, in which he would share his opinion that the temp files were damning evidence.

[2]

[3]

"The engineer was very skilled at gaslighting the management regarding such things, and without me present they feared he would just flim-flam his way out of trouble – and not for the first time," Alvin told On Call. The intended outcome was a severe wrist-slap that left the engineer chastened, but happy to continue his important contribution.

Alvin's advice was that this approach was not sufficient. The org had lost confidence in a critical employee and would never be able to trust him again. Only a dismissal would do.

[4]

The biz countered that the engineer had done good work for years, and had built the network from scratch. Dismissal would mean losing important corporate memory.

Alvin responded that an untrustworthy employee should not be retained, and won the day. So a plan was hatched: while HR fired the engineer, Alvin would revoke his network access to ensure no revenge could be wreaked.

[5]People power made payroll support in putrid places prodigiously perilous

[6]CEO arranged his own cybersecurity, with predictable results

[7]‘I needed antihistamine tablets every time I opened the computers’

[8]Superuser mostly helped IT, until a BSOD saw him invent a farcical fix

To make that possible, Alvin was provided with network credentials that let him plan the deed. As he rummaged around the network, he found a VPN connecting to what looked like a residential address. And at that address he found half a dozen servers laden with company files.

"The chief engineer had built a hot backup site for the company in his apartment," Alvin told On Call. "When they asked him about it during the HR meeting, he claimed that he'd told the company they needed a hot backup site, and when they balked at the cost he had decided out of the goodness of his heart to build one for them in his home and just not tell them about it."

The engineer was duly let go, under an agreement that ensured the backup servers were handed over. All passwords were then changed and the business carried on – just without its network engineer.

[9]

For several months, all was well.

But after a time Alvin was asked why the org's network was running so slowly.

"It turned out I had overlooked an important change on the engineer's last day: I had not thought to contact the ISP and remove the engineer's name from the list of people authorized to make changes."

And changes had been made. The former engineer had throttled the bandwidth on the company's account. Which explained why the network was so slow.

Not to mention confirming that firing the engineer was the right course of action.

"The company took no disciplinary action against me for my oversight, nor their former network engineer for his sabotage, but chalked it up to a lesson learned for everybody," Alvin told On Call.

Have you been asked to help fire a colleague? Or encountered extensive undocumented tech? If so, [10]click here to send On Call an email and we may feature it in a future column. ®

Get our [11]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZaEb1S7vvyePyvsHIMXlzwAAAcQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZaEb1S7vvyePyvsHIMXlzwAAAcQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZaEb1S7vvyePyvsHIMXlzwAAAcQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZaEb1S7vvyePyvsHIMXlzwAAAcQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2024/01/01/on_call/

[6] https://www.theregister.com/2023/12/29/on_call/

[7] https://www.theregister.com/2023/12/28/on_call/

[8] https://www.theregister.com/2023/12/22/on_call/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZaEb1S7vvyePyvsHIMXlzwAAAcQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[10] mailto:oncall@theregister.com

[11] https://whitepapers.theregister.com/



A Non e-mouse

Never, ever, keep an employee you can't trust. No matter how clever, knowledgeable or productive they are, your inability to trust them will hurt you far, far more than any temporary loss.

Likewise ...

jake

Never, ever, keep a customer you can't trust.

Contrary to popular belief, the customer is not always automatically right, and you can fire them.

Re: Likewise ...

Catkin

I prefer "the customer is always the customer".

Re: Likewise ...

Andy Non

I had a client like that once, a multi-million pound manufacturing company I had a good working relationship with. Did loads of software for them and they always paid on time. After a number of years they got taken over by an American firm and it became a nightmare getting paid, so many delays, hoops and hurdles to get past, imposed on them from across the pond. The next time they wanted work doing I said "No, I'm not prepared to deal with you any more."

wolfetone

I work for a company who has an employee like this. Everyone is wary of him, he's a massive c**t. But he's still here, still stealing a living.

Anonymous Coward

And never let that employee suspect that you're planning to let them go until you are absolutely certain that you can revoke ALL their access the second they get called into the manager's office. As proven by this story.

Prst. V.Jeltz

Sounds like they were lucky to get away this just that bandwidth throttle , given the picture painted of the culprit and the knowledge / access he would have had.

Dead mans shoes career progression

Prst. V.Jeltz

Alvin: " We definately have to fire the boss - he's not trustworthy . I'll be at my desk polishing the CV "

A BOFH is born.

Re: Dead mans shoes career progression

Peter Gathercole

A true BOFH never want's to be the boss, at least not in title. Manipulating the person in that post, well, that's just the game!

Re: Dead mans shoes career progression

Anonymous Anti-ANC South African Coward

A true BOFH never want's to be the boss, at least not in title. Manipulating the person in that post, well, that's just the game!

'strue dat. Being a mangler means you are more visible.

Being a normal worker means you are less visible, and have more time for shenanigans.

Sounds like the network engineer ...

Michael H.F. Wilkinson

wasn't called Simon. No problems with Windows installs or database normalization warnings

wyatt

Clearly they need an open window, saves identifying all the credentials that need changing.

"Clearly they need an open window, "

rafff

Maybe it was a Linux shop: no WIndows

Re: "Clearly they need an open window, "

Zippy´s Sausage Factory

Linux shops. As soon as anyone mentions Windows they start wine-ing.

Anonymous Coward

I remember a few jobs ago I was brought in as a senior engineer looking after exchange and generally helping run the windows and linux environments.

My senior manager was totally incompetent who hadn't updated his skills and knowledge for years (the reason i was brought in was because he switched the email gateways to open relays and the firm was blacklisted) He was genuinely the most incompetent people I've ever worked with and had an excuse for everything (we once had an issue with a server that was built over a year before, no blame was being raised but when we had a meeting about fixing it his first comment was I was on holiday when that server was built!)

Anyway, I was in charge of our outdated email archiving server and started doing regular access audits as I knew a few people had access. The system was terrible and had no auditing so I whipped up some SQL to run reports. It turned out mr slopey shoulders had been running searches on the HR director, FCO and CEOs emails. I reported this to our head of security who then took it to the director and he was called in for a disciplinary. I'm pretty sure he must have had leverage on the director as he kept his job and wasn't punished at all! He left a year later and last I heard he'd been hired for a hosting company as their senior engineer which was a total joke as the guy knew nothing!

Anonymous Anti-ANC South African Coward

hired for a hosting company as their senior engineer

Tsohost?

Hot backup servers?

Wellyboot

A guy who has access to all the files... Does anyone think he 'actually' paid for those servers?

...Unix, MS-DOS, and Windows NT (also known as the Good, the Bad, and
the Ugly).
-- Matt Welsh