Contractor admits planting logic bombs in his software
arstechnica.com
Contractor admits planting logic bombs in his software
1–10 of 156 posts
Re: Contractor admits planting logic bombs in his software
#2Which seems like incredible incompetence of the company to accept code in that format in the first place and to not have demanded the password when the first issue arose.
Re: Contractor admits planting logic bombs in his software
#3Apparently it was a password protected spreadsheet. Which seems like incredible incompetence of the company to accept code in that format in the first place and to not have demanded the password when the first issue arose.
Re: Contractor admits planting logic bombs in his software
#4Also, how were the contractors changes not reviewed?
If the same engineers work keeps throwing unknown problems down the line, the LAST thing I am doing is contacting them again.
Re: Contractor admits planting logic bombs in his software
#5> For years, the spreadsheet would glitch, Tinley would be hired to come in, would "fix" it, invoice Siemens, and head out again. But that all changed in May 2016 when Tinley was out of state, and Siemens called again about the spreadsheet. The company had an urgent order it had to put through, it told Tinley, and it wasn't working properly again. Pushed, Tinley relented and handed over the password.
https://www.theregister.co.uk/2019/06/25/siemens_logic_bomb/
Re: Contractor admits planting logic bombs in his software
#6Apparently it was a password protected spreadsheet. Which seems like incredible incompetence of the company to accept code in that format in the first place and to not have demanded the password when the first issue arose.
Re: Contractor admits planting logic bombs in his software
#7Apparently it was a password protected spreadsheet. Which seems like incredible incompetence of the company to accept code in that format in the first place and to not have demanded the password when the first issue arose.
If you dump the XML and remove the line you don't even need to ask for the password.
Re: Contractor admits planting logic bombs in his software
#8I would be curious how they came to realise what was happening. Also, how were the contractors changes not reviewed? If the same engineers work keeps throwing unknown problems down the line, the LAST thing I am doing is contacting them again.
Re: Contractor admits planting logic bombs in his software
#9Apparently it was a password protected spreadsheet. Which seems like incredible incompetence of the company to accept code in that format in the first place and to not have demanded the password when the first issue arose.
If you dump the XML and remove the line you don't even need to ask for the password.
This person asserted the spreadsheet was his "work product". Presumably Siemens's lawyers found this convincing enough to be wary of hacking around the password.
Re: Contractor admits planting logic bombs in his software
#10Apparently it was a password protected spreadsheet. Which seems like incredible incompetence of the company to accept code in that format in the first place and to not have demanded the password when the first issue arose.
Still a good laugh from the sidelines...