Live data from Hacker News

Contractor admits planting logic bombs in his software

arstechnica.com

1–10 of 156 posts

Re: Contractor admits planting logic bombs in his software

#3
post #2

Apparently it was a password protected spreadsheet. Which seems like incredible incompetence of the company to accept code in that format in the first place and to not have demanded the password when the first issue arose.

Yep. If it was me I would hold the supervisors responsible.

Re: Contractor admits planting logic bombs in his software

#5
In 2011 Tinley had refused to hand over the password to unlock the spreadsheet for editing when asked, claiming he was protecting his work product.

> For years, the spreadsheet would glitch, Tinley would be hired to come in, would "fix" it, invoice Siemens, and head out again. But that all changed in May 2016 when Tinley was out of state, and Siemens called again about the spreadsheet. The company had an urgent order it had to put through, it told Tinley, and it wasn't working properly again. Pushed, Tinley relented and handed over the password.

https://www.theregister.co.uk/2019/06/25/siemens_logic_bomb/

Re: Contractor admits planting logic bombs in his software

#6
post #2

Apparently it was a password protected spreadsheet. Which seems like incredible incompetence of the company to accept code in that format in the first place and to not have demanded the password when the first issue arose.

If you dump the XML and remove the line you don't even need to ask for the password.

Re: Contractor admits planting logic bombs in his software

#7
post #6
post #2

Apparently it was a password protected spreadsheet. Which seems like incredible incompetence of the company to accept code in that format in the first place and to not have demanded the password when the first issue arose.

If you dump the XML and remove the line you don't even need to ask for the password.

Haha really? That is hilariously insecure.

Re: Contractor admits planting logic bombs in his software

#8
post #4

I would be curious how they came to realise what was happening. Also, how were the contractors changes not reviewed? If the same engineers work keeps throwing unknown problems down the line, the LAST thing I am doing is contacting them again.

Can you even "review" changes to spreadsheet code? I know that Office apps have some support for change management, but is it even up to this task?

Re: Contractor admits planting logic bombs in his software

#9
post #6
post #2

Apparently it was a password protected spreadsheet. Which seems like incredible incompetence of the company to accept code in that format in the first place and to not have demanded the password when the first issue arose.

If you dump the XML and remove the line you don't even need to ask for the password.

Warning: This being true, it can still be construed as "hacking" no matter how simple it is. Just because the barrier is easy to get over, it doesn't mean you're legally allowed to enter.

This person asserted the spreadsheet was his "work product". Presumably Siemens's lawyers found this convincing enough to be wary of hacking around the password.

Re: Contractor admits planting logic bombs in his software

#10
post #2

Apparently it was a password protected spreadsheet. Which seems like incredible incompetence of the company to accept code in that format in the first place and to not have demanded the password when the first issue arose.

On the one hand, yes, that's crazy. On the other hand, an argument can be made that company accept proprietary software in binary form all the time, and this is no different !

Still a good laugh from the sidelines...

Post reply on HN