Live data from Hacker News

Fannie Mae Unix Engineer Gets 41 Months for Planting Logic Bomb

thenewnewinternet.com

41–50 of 54 posts

Re: Fannie Mae Unix Engineer Gets 41 Months for Planting Logic Bomb

#41
post #20

Earlier quoted context omitted.

Just imagine if that guy had been successful. Americans would have been debt free!!

You think that debt wasn't leveraged? You think people can just not pay back loans and no one gets hurt?

The way the US economic/legal system works is that banks can just not pay their debts and the banks' owners don't get hurt.

If debts owed by banks aren't legally enforceable, debts owed to banks shouldn't be either. To put it another way, limited liability, if it exists, should go both ways.

Re: Fannie Mae Unix Engineer Gets 41 Months for Planting Logic Bomb

#42
post #22

Earlier quoted context omitted.

Funny, I came here looking for the exact opposite post to upvote. Seems exceptionally low to me, given the obvious malicious intent and potential damages. But I'm mostly ignorant about the relevant law.

I assume you mean relative to other sentences/crimes you're aware of? It may be low compared to those, but in general, American sentences seem exceptionally high to me, and this is a good example. I don't think a stronger sentence would have deterred him. I doubt he sat down and thought "If I get caught, I'll only get 3 1/2 years, which isn't too bad. Now, if I would get 10 years, that's another story..." I doubt he…

What annoys me about this is not the sentence, it's the way that corporations can get away with doing the same thing.

If malicious software is a bad thing -- and it is -- then let's punish everyone who does it. Starting with Sony when they put a rootkit in CDs. But of course, Sony are a big corporation, so that makes it OK.

Re: Fannie Mae Unix Engineer Gets 41 Months for Planting Logic Bomb

#43
post #19

5000 Servers. A "Senior Engineer" discovered this script. Probably it was a cron job or something which they review regularly? Would be useful to know how exactly they got to that one script. Must have real good review practices , audits and logging in place if they were able to find it before it did the damage and then collect evidence to trace it back to the perpetrator.

According to an article about the indictment, it was discovered by chance: "It was only by chance that [the Fannie Mae engineer] scrolled down to the bottom of the legitimate script to discover the malicious script" http://www.computerworld.com/s/article/9127040/Fannie_Mae_en...

More detail from the above article:

[quote] If the malicious script had gone undiscovered, it would have disabled monitoring alerts and all log-ins, deleted the root passwords to the approximately 4,000 Fannie Mae servers, then erased all data and backup data on those servers by overwriting with zeros.

"Finally, this script would power off all servers, disabling the ability to remotely turn on a server," said the government's complaint. "Subsequently, the only way to turn the servers back on was physically getting to a data center." [/quote]

Re: Fannie Mae Unix Engineer Gets 41 Months for Planting Logic Bomb

#46

Earlier quoted context omitted.

Just imagine if that guy had been successful. Americans would have been debt free!!

Nope. There are plenty of backup records for all of the debts. Physical records of deeds, contracts, etc. And it's possible much of the data could have been restored through backups and data retrieval methods. What this would have caused would be delays and difficulties in handling existing mortgages but the biggest impact would have likely been an inability of people to apply for new mortgages using fanny mae, which…

In retrospect, it probably would have been a good thing.

Re: Fannie Mae Unix Engineer Gets 41 Months for Planting Logic Bomb

#47
post #14

41 months seems exceptionally high given that it was discovered before execution. It would take me an hour to dig it all up, but there are federal sentencing guidelines based on the dollar amount of damages. I don't think they take potential damages into account.

If you'd be willing to take the time to dig something up on that I'd love to read it. It seems surprising to me that potential damages would not be taken into account. By doing so, the accussed would essentially be rewarded based on chance - at least in this case.

Ok, let me dig. It's been a while and I'm not a lawyer.

Looking at the actual indictment, I think he was charged with just violating Section 1030 (a)(5)(A)(i) of the U.S. Code. I don't think the other two sections mentioned are separate charges.

http://www.law.cornell.edu/uscode/html/uscode18/usc_sec_18_0...

If you've never read section 1030, it's surprisingly clumsy and vague to us non-lawyers. Two important things for most cases are that generally any computer that is (or even 'can be') connected to the internet is considered to be 'protected' as it may potentially be involved in interstate commerce. The second this is that for this section to apply, there must be at least $5000 in damages involved.

Then you can go look up sentencing guidelines. It's important to realize that these 'guidelines' are a lot more than just suggestions for federal judges. They can go outside of these guidelines but rarely do. http://www.sentencing.us has a great calculator. That quickly tells us to use section 2B1.1(a)(2) of the guidelines.

http://www.ussc.gov/Guidelines/2010_guidelines/Manual_HTML/2...

If you go look at those guidelines, there's a chart in (b)(1) that shows how much his base offense level would be increased depending on the damages. From the descriptions I've read, I would think the damage amount would be less than $120,000 (lost time, hours it took to clean up) so that's a +8 level increase.

Then there are a number of special modifiers that can increase the 'level' of the sentence guideline. It looks like (b)(14)(B) might apply due to the financial institution aspect, so that would be a +4, except if I read the awkward combination of (C) and (D) correctly, this automatically pushes him to a level 24.

So then you need to look at the sentencing table: http://www.ussc.gov/Guidelines/2010_guidelines/Manual_HTML/5...

The table takes his criminal history into account, which was likely none. Then we need to look at his level, which we still don't know.

If he caused under $120,000 in damages, his level should be a base of 6 plus 8 for the dollar amount. He could reduce this by 1 or 2 levels by accepting responsibility or other things. But if he was at a level 14, his sentence guideline should be 15-21 months. I would think that the damage amount could be even lower than that, especially if it had to be proved in trial. This is why I made my original statement that I thought it sounded quite high.

So they must have applied the (b)(14)(B) part to push him to level 24 for a range of 51-63. In which case his sentence of 41 months is then too low. So if he "accepted responsibility" he could reduce his 24 to a 22, getting him right at the 41-51 month range. Judges would almost always apply the lowest end of the range to a first time offender.

I think his 41 months can be split into two phases so he could spend half of it in an actual prison and then the rest on 'supervised release' - either monitored home detention or in a halfway house. He might even be able to spend the entire time on 'supervised release'. I couldn't find it but section 1030 offenses used to have a clause about mandatory 6 months 'imprisonment'.

Due to his offense level, he could have gotten 5 years probation, but 3 is typical. He will be required to make restitution to the victim for the damage amount. There's also a fine table that shows him with a $7,500 to $75,000 fine range. He'll have to make his best effort to pay those.

So that's the mechanics of federal sentencing.

This is something I wish they covered in every school program. It's amazing to realize that one angry act by a programmer or IT person could result in very severe consequences. So few people in our field realize how stiff the penalties can be, so this law isn't much of a deterrent.

Re: Fannie Mae Unix Engineer Gets 41 Months for Planting Logic Bomb

#48

Earlier quoted context omitted.

And as Fannie Mae provided the inside-man with root access to all the main systems, it was apparently just as easy to destroy the backups. Edit: also in reference to this comment: http://news.ycombinator.com/item?id=2054679

If root access to systems lets you destroy backups then they cannot rightly be considered backups.

The Tao of Backup: http://www.taobackup.com/

Re: Fannie Mae Unix Engineer Gets 41 Months for Planting Logic Bomb

#49
post #21

Most of my student loans were issued by them, if only the logic bomb had executed and destroyed my loan data...

sallie mae = student loans. fannie mae and freddie mac are home mortgage only.

Did all the financial institutions in the States get together to come up with the most ridiculous sounding names?

Re: Fannie Mae Unix Engineer Gets 41 Months for Planting Logic Bomb

#50
post #2

While it will probably always be hard to stop inside-man attacks, it will probably always be easy to do backups :)

Also, while it will probably always be easy to accomplish inside-man attacks, it will also be generally harder to get away with them than you might think. (Especially if real money is involved!)
Post reply on HN