Read up on the latest ideas and technologies from companies that sell hardware, software and services. Improving Sales Productivity: An Opportunity for Sales and IT Leadership
Why Security SaaS Makes Sense Today
Solve Exchange Storage Problems Once and For All: A New Approach without Stubs or Links
Radicati Market Quadrant 2008 on Corporate Web Security
Strategies for Eliminating .PST Files
CRM your salespeople will love
How to Beef Up Your Sales Pipeline
Mimosa™ NearPoint™ for Microsoft® Exchange Server: Email Archiving 101
Zones provide focussed content from Computerworld and leading technology partners.Newsletter Subscription
A network administrator has allegedly locked up a multimillion-dollar computer system for the city of San Francisco that handles sensitive data, and he is refusing to give police the password
Terry Childs, 43, was arrested Sunday and has been charged with four counts of tampering with a computer network. According to the office of San Francisco District Attorney Kamala Harris, Childs made changes to the city's Fibre WAN (wide area network), allegedly rendering it inaccessible to administrators. He also "set up devices to gain unauthorized access to the system," the DA's office said in a statement.
The Fibre WAN is used to connect computers in buildings throughout the city and carries about 60 percent of the networking traffic for the city government. On Tuesday it was functioning normally, but the city no longer has administrative access to the switches and routers on the network, according to Ron Vinson, chief administrative officer with the city's Department of Telecommunication Information Services. "It was a little unnerving to discover that this person had created this fiefdom of access to our network," he said.
"We continue to monitor the system to make sure that we do maintain the integrity of the network," he added. "The issue at hand is the access codes that we are trying to get our hands around."
Childs was arrested on Sunday at his home in Pittsburg, California, the DA's office said.
In the days leading up to his arrest, his behavior had become erratic and he had become hostile toward his colleagues, according to a source familiar with the situation. After his arrest, he first gave some bogus passwords to police and then refused to reveal the real passwords, the source said.
Childs is a network administrator with the city's Department of Telecommunication Information Services, which runs the city's critical IT operations, including the e-mail system, Web site, 311 call center and telecommunications infrastructure.
Childs remains in custody, Harris said in a Monday afternoon news conference. "The bail has been set at [US]$5 million, and the exposure in this case if he were convicted on all counts would be seven years in prison," she said. He is set to be arraigned on Thursday.
Harris said it's unknown why Childs allegedly tampered with the system.
Vinson said his department recently hired a new security chief who oversaw an assessment of the group's security. Over the past few weeks that assessment discovered evidence of tampering. "It was escalated to the police department, who brought their own forensics team that came in to do their own investigation of our network," he said.
That investigation led to Childs' arrest, he said.
The city is now working with Cisco Systems to repair the problem, but if it has to replace the routers and switches that have been tampered with, it could easily face a $250,000 bill for the incident.
The situation doesn't reflect well on San Francisco's IT staff, said Andrew Storms, director of security operations with security vendor nCircle. "His managers should have known better," he said via instant message. "Some safety nets and best practices were probably overlooked if one person could have caused this much damage."
San Francisco began rolling out the Fibre WAN about four years ago as a less-costly alternative to leased data lines, Vinson said. To date the city has spent more than $3 million on the project.
With administrative access to switches and routers, could Childs now seize control of the city's network? "Not where he's sitting now," Vinson said.
Computerworld Member Login
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
VeCommerce Launches Top Ten List of Personal Security Breaches In Lead Up to National ID Fraud Awareness Week 2008-10-07 15:10:00+10
Multimedia Technology signs exclusive National distribution agreement with Freecom 2008-10-07 14:30:00+10
Open Text: Upheaval in the Financial Markets Sharpens the Focus on Information Governance and Enterprise 2008-10-07 13:19:00+10
Symantec State of Spam Report - October 2008 2008-10-07 11:58:00+10
AIIA to Reward Sustainability and Green IT Champions at the 2009 iAwards 2008-10-07 11:56:00+10
Optimized Back-up and Recovery for VMWare for VMWare Infrastructure with EMC Avamar
Virtual machines deployed in the data centre must be protected against failure. Read on to find out how to extend data protection to your virtual machines.











