Live data from Hacker News

Fannie Mae Unix Engineer Gets 41 Months for Planting Logic Bomb

thenewnewinternet.com

21–30 of 54 posts

Re: Fannie Mae Unix Engineer Gets 41 Months for Planting Logic Bomb

#22
post #14

41 months seems exceptionally high given that it was discovered before execution. It would take me an hour to dig it all up, but there are federal sentencing guidelines based on the dollar amount of damages. I don't think they take potential damages into account.

Funny, I came here looking for the exact opposite post to upvote. Seems exceptionally low to me, given the obvious malicious intent and potential damages. But I'm mostly ignorant about the relevant law.

Re: Fannie Mae Unix Engineer Gets 41 Months for Planting Logic Bomb

#23

Earlier quoted context omitted.

More info here - http://news.softpedia.com/news/Rogue-IT-admin-Close-to-Shutt...

During this time Makwana had root access to all of the main systems This quote above, and the entire article boggles the mind. I've worked with big and small organizations that protected root on <10 machines like it was the key to preventing aging.

Not sure this matters much. Most places I've worked have considered local root exploits not worth patching. So if you have a user account, you have root.

Re: Fannie Mae Unix Engineer Gets 41 Months for Planting Logic Bomb

#24
post #2

While it will probably always be hard to stop inside-man attacks, it will probably always be easy to do backups :)

And as Fannie Mae provided the inside-man with root access to all the main systems, it was apparently just as easy to destroy the backups.

Edit: also in reference to this comment: http://news.ycombinator.com/item?id=2054679

Re: Fannie Mae Unix Engineer Gets 41 Months for Planting Logic Bomb

#25
post #8

Does anyone know what the actual "logic bomb" consisted of? My money is on a crontab that executed a simple set of ssh command attacks on the specified date. As per the article, to destroy "all data, including financial, securities and mortgage information," it would be as simple as an "rm -rf" across multiple servers. Except for one critical item, he would have to have root access on all those servers. Either the sc…

If he was part of the SA team for their production systems, it's likely he DID have root access to all of them, and that it was legitimate and had business justification. Even if he didn't have explicit root access, it's even more likely he had direct physical access, which is generally less carefully protected by IT policies and is usually all or nothing.

Granted, this isn't just run of the mill data, and Fannie Mae could have certainly had significantly better security policies in force, but I don't think they were below average for a corporation in their security policies.

Re: Fannie Mae Unix Engineer Gets 41 Months for Planting Logic Bomb

#26
post #2

While it will probably always be hard to stop inside-man attacks, it will probably always be easy to do backups :)

And as Fannie Mae provided the inside-man with root access to all the main systems, it was apparently just as easy to destroy the backups. Edit: also in reference to this comment: http://news.ycombinator.com/item?id=2054679

If root access to systems lets you destroy backups then they cannot rightly be considered backups.

Re: Fannie Mae Unix Engineer Gets 41 Months for Planting Logic Bomb

#27
post #14

41 months seems exceptionally high given that it was discovered before execution. It would take me an hour to dig it all up, but there are federal sentencing guidelines based on the dollar amount of damages. I don't think they take potential damages into account.

If you'd be willing to take the time to dig something up on that I'd love to read it.

It seems surprising to me that potential damages would not be taken into account. By doing so, the accussed would essentially be rewarded based on chance - at least in this case.

Re: Fannie Mae Unix Engineer Gets 41 Months for Planting Logic Bomb

#28
post #2

While it will probably always be hard to stop inside-man attacks, it will probably always be easy to do backups :)

Just imagine if that guy had been successful. Americans would have been debt free!!

Nope. There are plenty of backup records for all of the debts. Physical records of deeds, contracts, etc. And it's possible much of the data could have been restored through backups and data retrieval methods. What this would have caused would be delays and difficulties in handling existing mortgages but the biggest impact would have likely been an inability of people to apply for new mortgages using fanny mae, which is hardly a win for anybody.
Post reply on HN