Live data from Hacker News

Disney worker who hacked menus gets 3 years in prison

nytimes.com

11–14 of 14 posts

Re: Disney worker who hacked menus gets 3 years in prison

#11

What credentials / access did he use to get into Disney's system after he was terminated?

Scheuer allegedly went into action quickly following his termination, and by early July was said to have used his work credentials, which still functioned after his termination, to access the menu creation system Disney contracted another company to create and change all the fonts in the system to wingdings symbols.

https://www.theregister.com/2024/10/30/fired_disney_employee...

Re: Disney worker who hacked menus gets 3 years in prison

#12

What credentials / access did he use to get into Disney's system after he was terminated?

Scheuer allegedly went into action quickly following his termination, and by early July was said to have used his work credentials, which still functioned after his termination, to access the menu creation system Disney contracted another company to create and change all the fonts in the system to wingdings symbols. https://www.theregister.com/2024/10/30/fired_disney_employee...

Okay. So while jail is probably appropriate given the potential threat of harm if nobody had reviewed the menus prior to their publication with the allergens stripped...

The tech community should not let Disney off the hook for failing to scrub the access credentials of a terminated employee. Because the law can punish one actor, but if the attack vector is still open, the public isn't safe from future more subtle incidents of menu manipulation (or other similar attacks by other disgruntled employees).

Is there any information on what Disney did after this incident to prevent another Scheuer in the future? The root of the attack is that the sFTP system was accessible via "credentials [that] were non-individualized, not specific to a particular user, and available for use by multiple employees with administrative access."

(I'm also a little unclear on whether this was all owned by Disney proper or they were farming this out to a third-party service provider company and that company screwed up. With so many entertainment venues in such a small area, Orlando is positively shot through with high-volume, hyper-focused service provider companies that do stuff like this).

Re: Disney worker who hacked menus gets 3 years in prison

#13
post #7

The restitution seems too high. He probably was fired for going on mat leave as other companies have shown to do and wanted payback. The "unspecified misconduct" firing reason seems weird and they won't expand on it.

"Probably".

Internet Experts(tm) are also telepaths.

We have no idea, and since his retaliation involved vandalism that could potentially harm bystanders, I'm going to go out on a limb and say... I have no idea why he was fired.

Re: Disney worker who hacked menus gets 3 years in prison

#14

Earlier quoted context omitted.

Scheuer allegedly went into action quickly following his termination, and by early July was said to have used his work credentials, which still functioned after his termination, to access the menu creation system Disney contracted another company to create and change all the fonts in the system to wingdings symbols. https://www.theregister.com/2024/10/30/fired_disney_employee...

Okay. So while jail is probably appropriate given the potential threat of harm if nobody had reviewed the menus prior to their publication with the allergens stripped... The tech community should not let Disney off the hook for failing to scrub the access credentials of a terminated employee. Because the law can punish one actor, but if the attack vector is still open, the public isn't safe from future more subtle in…

Yes! Disney should be more worried about their HR/IT practices, than one lone angry ex-employee.

And by worried, I mean: correcting lax or missing practices, not punishing scapegoats.

Post reply on HN