Usernames and passwords to San Francisco network exposed in court docs

By Michael Hatamoto | Published July 28, 2008, 3:13 PM

San Francisco again has control of its own FiberWAN network, but as it compiles evidence to keep distraught network administrator Terry Childs in jail, the city could have opened itself up to a slew of new security problems.

The San Francisco District Attorney's office entered up to 150 usernames and passwords into Exhibit A of the ongoing legal case against Childs. Each account is said to be sensitive and private, and the city has gone through a lot of work to get the accounts back, only to enter them into the public domain through the courtroom filings.

The passwords entered into Exhibit A happen to be just one set of at least two sets of passwords necessary to access the network, but security experts again were left shaking their heads. Access into the city's VPN network would still be required to make use of the exposed login information.

All of the usernames are linked to the mayor's office and district attorney's office, multiple city agencies and departments, and the city's police department. Security experts already pointed out the city should change all of the passwords, especially since a number of them are identical to their usernames or would otherwise be easy to guess.

Specifically, Exhibit A was used against Childs when he requested his bail be lowered from an unusually high $5 million. Childs will have to remain in jail until Sept. 24, the date of his next hearing. The high bail was set because of fears that Childs would leave prison and use the passwords to permanently lock the city out of its own network.

Childs, a San Francisco Department of Technology (DOT) senior network administrator who had control of the city's FiberWAN network, changed passwords and effectively locked everyone out of the network. He stopped users from accessing parts of the network they were authorized to use, and also enabled his own access to sections of the network to which he should have been restricted while he worked for the city, San Francisco district attorney spokespeople said.

Childs finally disclosed passwords for city administrators only after meeting San Francisco Mayor Gavin Newsom in person, who then delivered them to Cisco Systems engineers brought in to help unlock the network.

The FiberWAN network is responsible for controlling the city's e-mails, law enforcement records, payroll, and personal records. It controls 60 percent of the city's municipal data that also includes lawyer information and 311 information system.

After being arrested, Childs was charged with four felony counts of tampering with computer networks and has a fifth pending misdemeanor for criminal damages. He has pleaded not guilty to all five charges.

Comments

View comments by with a score of at least

Wow, just wow...

The Prosecution is really showing that Terry is in the right. They, the Prosecution, do not understand network principals and that what Terry was doing is normal for someone that has enterprise level administration over large networks.

From reading through this article, I can already see where Terry was using the principles of least access, making sure that there were alternate ways to administer equipment that could not be contacted through normal means (modems attached to networking equipment if the network is not functioning properly), and making sure that passwords for accounts with high level access were kept securely. Terry's lawyer is going to have a field day with the Prosecution's court filings and I can see that Terry will likely be found not guilty in the end and the City of San Fransisco is going to have a huge civil case brought against it.

Score: 0

|

Don't be pathetic. Nobody gives a damn in court how he set up the network. He abused his privileges and locked down a network he was entrusted to support. He is one sorry ass.

Score: 0

|

What you missed in cdigan's words is that he could argue now that the Prosecutors' knowledge about security is lower than it should be, so he did what he could to keep that information secret.

Of course this is a twist of events, but what we know so far is what the media has told us, so we know nothing actually.

Score: 0

|

Let me ask you a serious question preinterpost, do you work in IT as a network admin? If you did, you would realize that some of the things the prosecution is accusing Terry of are standard procedures so you can maintain the integrity of your network. Likewise, superusers (enterprise admins) have to have full access to the network in order to perform a number of duties. Superusers have to have access to data in order to back it up, decrypt it if someone loses their decryption keys, and be able to get to any location on the network to tell if the network is functioning properly. What superusers also have to have is the ethics to realize what data they *should* actually look at vs. what they *shouldn't* look at.

If Terry's lawyer plays her cards right, she's going to show that Terry was doing everything right and that the management of San Fransisco's IT deparement is incompetient and negligent. Doing that and Terry will get off and Terry will then be able to turn around and sue the City of San Fransisco for wrongful jail time, ruining his reputation, and a few other things, and he'll win that as well if his lawyers play things right.

Score: 0

|

Amazing.

At least we can be encouraged that the the more things change there, the more they will stay the same.

The Chamber of Commerce is definitely building brand equity: "The Land of Fruits and Nuts" Indeed!

Score: 0

|

Well, it looks like Terry was right; no one in the IT dept in SF is qualified to have control of network security in the county. BTW, access to the county domain is so hard, try parking near one of their buildings with a Pringles can and log into their wireless.

If the accounts they published are now locked, lookup the names of other employees and use their names as the password.

Do they know they can set rules to prevent users from using easy passwords?

Score: 0

|

NEWSFLASH: supposedly when Gavin asked Childs what the password was, he replied "byte me" and sure enough, it worked!

there is now somee speculation that Gavin will meet with Childs again to comply...

Score: 0

|

This article is written with great irresponsibility. I can assure all those accounts had access turned off immd. and the users have to appear in person to submit a new form for a VPN account, same as usual. The old and previous names and passwords are useless to any criminal, the accounts were turned off, and only moved to new accounts after in-person creation of a new account, this is standard practice, remember, the users may only be floor away from the IT department that performs these functions.

Score: 0

|

How do you know this for sure? Seriously I think you're just trying to think positive. People screw up all the time and sticking your head in the sand ignoring it isn't going to help.

Score: 0

|

Even if the accounts were turned off, this still gives crackers reconnaissance information. Basically, a cracker would know the style of user names, for example, TChilds could be Terry Childs user name. If all the names are set up this way, it's easy to guess what someone else's user name will be. Also, if the list shows a commonality among initial passwords, then you might as well open up your network.

Basically, just because those accounts are disabled, there are probably other accounts with similar style initial passwords. Also, are they changing the user names?

Score: 0

|

I'm gonna have a beer tonight for you Terry. Good work. If those in charge were dumb enough to allow this to happen, they deserve every bit of embarrassment they got and then some.

Once again bravo to you.

Score: 0

|

So.... you are saying that he shouldn't be charged with the four felonies for obviously and blatantly breaking the law? You would actually not mind working with/for him? What he did was not only illegal but was very piss-poor judgment on his part. This was not the way to get a point across, just like people who post security exploits simply because Company X wouldn't listen. If I were hiring IT people, I sure as hell would not hire this guy. He gets angry or disgruntled and then blows up your entire infrastructure LOL.

Score: 0

|

It's my 'be nice' week but this is the best I can do... Since the majority of the people affected by this incident (such as getting their pay check) have nothing to do with the IT department except using a computer I hope irresponsible kids like you will never have meaningful a career in IT. Good luck with your fake ID tonight.

Score: 0

|

LOL

Score: 0

|

As a secrity centric IT person I was laghing so hard I was crying reading this. From what Ive seen of others networks this is standard practice in the industry, and people still wonder out loud how there credit card, medical and other personal information could get comprimised on corporate networks.

Score: 0

|

Security firm: Windows patches not responsible for 'Black Screen of Death'

On second thought, maybe that access control list thingie with the lockdown something-or-rather didn't trigger an alleged, perhaps non-existent, pandemic.

My Windows 7 confession (and why you should confess, too)

I've held back the real reason for sticking with Windows 7, even as, gulp, iLife calls me to go back to the Mac.

Apple settles with Psystar except for 'circumvention devices'

The fracas with the Florida clone computer maker might have ended today had Apple not have muddled the issue over a cheap piece of Psystar software.

Where did Apple's Black Friday sales go?

According to one analyst, Apple sold nearly four fewer Macs per hour on Black Friday than same day a year ago. Now why is that?

Google begrudgingly adjusts news crawling for paid publishers

If publishers want to make readers pay for news content, and thereby drive down its popularity and Google ranking, the company says, they can just go right on ahead.

Fee or free? Murdoch, Huffington square off over the cost of Internet news

Participants in an FTC workshop yesterday witnessed the two extremes of the Web news publishing debate, still centered on the issue of long-term profitability.

Microsoft denies latest 'Black Screen of Death' claims

After an anti-malware producer announced a fix to what it says is a swarm of recent KSoD problems, evidence of the swarm itself has yet to turn up.

Latest Firefox 3.6 beta fixes 133 bugs, promises faster page load times

A once-sluggish beta testing process has kicked into overdrive, with astonishing success at finding serious bugs. Will Mozilla be able to fix all the others in time?

Confirmed: Office 2010 to ship in June

Two weeks after Microsoft had been expected to draw a clearer roadmap for its principal applications suite, it's finally ready to commit to the end of H1.

New EU antitrust commissioner will oversee Microsoft, Oracle+Sun, Intel issues

As one of Europe's most prominent politicians shifts positions in January, her replacement remains a question mark over technology's biggest issues.

Without its own 'iTablet' yet, is Apple missing the boat?

Steve Jobs is on record as dissing "single-purpose" devices like e-readers. But given their recent popularity, was that a mistake?