8 ms·
Fired employee deleted servers, causing it to lose S$918,000
- not_your_vase 2y ago[flagged]
- constantcrying 2y ago>I would also imprison (or at least fine) the company's security chief. This is just incompetency. It is ridiculous to think that this should rise to the level of criminal negligence. Of course there are good reasons to fire him.
- not_your_vase 2y agoThe occupation "engineer" does come with liability, and such incompetence can (and does) result in prison sentence. Of course not "CS engineers". (Would you call it ridiculous also, if it was an article about architect, who designed a house that just razed itself to ground after a someone shut the door too hard?)
- paulpauper 2y agoKandula's laptop was seized by the police and the script used to carry out the deletions was found on it. full disk encryption is a thing. it's amazing how people who are otherwise technically competent leave such obvious incrementing evidence on computer
- Rinzler89 2y agoI assume he had to give up the decryption credentials when he handed the laptop for the investigation. Not complying with the investigation can make it worse for you in some places.
- patrulek 2y agoCant you just forget decryption credentials during the investigation?
- ceejayoz 2y agoSure. They may not believe you, though. Related example: https://en.wikipedia.org/wiki/H._Beatty_Chadwick https://en.wikipedia.org/wiki/H._Beatty_Chadwick
- meepmorp 2y agoI'd rather have the 14 years of my life than $2.5 million I can't even use. People are weird.
- Rinzler89 2y agoYou can, but depending on the justice system in your area, you might not want to.
- eddd-ddde 2y agoThere are double encryption systems. You give your "password" and they access a volume, where another encrypted volume isn't even apparent.
- Rygian 2y agoThat's why you have two decryption keys. One for the real stuff, one that decrypts to a decoy. https://veracrypt.eu/en/VeraCrypt%20Hidden%20Operating%20System.html https://veracrypt.eu/en/VeraCrypt%20Hidden%20Operating%20Sys...
- akira2501 2y agoYep. All very good advice on how to better conceal your crimes.
- averageRoyalty 2y ago
- aswanson 2y agoProbably thought he was safe in his country. You can be tech literate and international criminal law illiterate.
- dookahku 2y agoi dunno what privacy/civil laws are like there, but couldn't the police or courts compel Kandula to surrender the password?
- ceejayoz 2y agoI suspect so. https://en.wikipedia.org/wiki/Caning_in_Singapore https://en.wikipedia.org/wiki/Caning_in_Singapore https://en.wikipedia.org/wiki/Human_rights_in_Singapore#Privacy_under_mass_surveillance https://en.wikipedia.org/wiki/Human_rights_in_Singapore#Priv...
- constantcrying 2y ago>full disk encryption is a thing. Just actually get rid of the evidence. Throw your laptop into a shredder and buy a new one. At least get a new hard drive.
- ceejayoz 2y agoI can't speak for Singapore's specifics, but outright destroying evidence is often its own crime.
- Spooky23 2y agoFor this individual, it's a little late to close the barn door.
- freeone3000 2y agoGood luck proving it!
- ceejayoz 2y agoIn a country where possession of chewing gum is illegal and 14 grams of heroin geets you a death sentence, I'm not sure I'd want to test the practical limitations of the burden of proof on that sort of thing.
- exe34 2y agoprobably easiest to buy a second hand laptop, do the thing and then low level format the disk with a hammer.
- constantcrying 2y agoBut you already committed the crime, surely that alone will be much worse than a completely unprovable charge of destruction of evidence.
- ceejayoz 2y ago
- StarterPro 2y agoRun a VM on a portable linux distro, delete the VM, easy days.
- technick 2y agoEasier to run tails or other live distros that don't store anything on disk and then run memtest afterwards.
- averageRoyalty 2y agoHe was googling for "how to delete VMs script" to do the initial attack, I think you overestimate his opsec capability.
- ocodo 2y agoHe had an opsec capability? I assumed he'd never heard of opsec.
- jihadjihad 2y ago> incrementing evidence It just keeps piling up!
- technick 2y agoI assume Kandula was a microsoft user and it's widely suspected there's a backdoor for law enforcement.
- averageRoyalty 2y agoOn built in disk encryption? I'd be surprised if security researchers hadn't found that target. Got a source? Who credible suspects this?
- technick 2y agoNSA and FBI both approached previous bitlocker devs to insert backdoors in the early days. It's no secret Microsoft cooperates with federal government branches to ensure the government keeps using their products. Further because bitlocker is closed source, there hasn't been any outside research done on the code. https://boingboing.net/2013/09/11/how-the-feds-asked-microsoft-t.html https://boingboing.net/2013/09/11/how-the-feds-asked-microso... Some good comments here: https://old.reddit.com/r/sysadmin/comments/26vm25/why_is_there_no_trust_in_the_security_of_bitlocker/ https://old.reddit.com/r/sysadmin/comments/26vm25/why_is_the... There's more resources on google and I remember attending a talk at either blackhat or defcon on why you shouldn't be using bitlocker.
- tmtvl 2y agoRemember: sometimes a simple 'rm' may not be good enough, that's why the gods of GNU gave us 'shred': https://linux.die.net/man/1/shred https://linux.die.net/man/1/shred
- craftkiller 2y agoWell, the file was found on his laptop and laptops are pretty much exclusively using SSDs. On SSDs a simple `rm` is enough. On an SSD: 1. You run rm 2. Your filesystem uses trim to mark the pages as invalid 3. The drive's garbage collector finds blocks containing invalid pages and consolidates valid pages into new blocks and marks the old blocks as invalid. 4. Then the drive resets the block to empty and marks it as available. This improves write performance because SSDs can only write to empty pages (they cannot overwrite pages that have already been written, instead they'd have to first reset the page and then write a new page) so by proactively resetting pages, they have pages ready to be immediately written. But this also means that the blocks containing your deleted file will be proactively reset/emptied which means it will uncharge the cells which is equivalent to all the bits being `1`, thereby destroying the file. Source: https://kcall.co.uk/ssd/index.html https://kcall.co.uk/ssd/index.html
- tmtvl 2y agoCool, I learned something interesting today, thanks!
- paulpauper 2y agolol 34 people replied to this. I think this ranks in the top 10 of my most replied to posts ever. But no change in votes.
- TacticalCoder 2y agoThere's a reason why some companies are using measures that feel very inhuman when they fire someone: it's because of people like the one from TFA.
- kstrauser 2y agoI told my colleagues to do me a favor: if I'm ever let go for any reason, please terminate all my access immediately and diligently. It's for my protection just as much as theirs. If I can't get in, they can't blame me if something goes wrong down the road.
- candiddevmike 2y agoThat is very threatening, why would you share this? If you truly think this way, you may want to consider a different career or look internally to figure out what makes you think this way. EDIT: I thought the "If I can't" portion read "If I can" in parent's comment. Disregard, sorry parent.
- r2_pilot 2y agoSome people work in regulated environments with audit requirements.
- ilikecakeandpie 2y agoRight? Just take the L and look for a new job
- stetrain 2y agoI don't see how that's incompatible with wanting your access revoked on termination to avoid accusations of wrongdoing.
- landryraccoon 2y agoEmotions aside, isn’t it just sensible security policy to delete all permissions and invalidate all credentials of a terminated employee as soon as possible? Any other approach would be exceptional.
- glonq 2y ago> His contract with NCS was terminated in October 2022 due to poor work performance and his official last date of employment was Nov 16, 2022 This is why you don't force employees or contractors to work through their final two weeks. Too little benefit, too much risk. > After Kandula's contract was terminated and he arrived back in India, he used his laptop to gain unauthorised access to the system using the administrator login credentials. He did so on six occasions between Jan 6 and Jan 17, 2023. Oh nevermind, it's far worse than just that!
- moshun 2y agoThe real question is why he had active admin credentials months after termination.
- deleted 2y ago[deleted]
- mysterydip 2y agomy anecdotal guess: there was a single admin account rather than a group, and they didnt want to risk changing the password because of an unknown number of scripts/services using it.
- r00fus 2y agoIs this even remotely justifiable in a well run organization? Speaks more to the management than this fired employee.
- mysterydip 2y agoI don't think anyone sets out to have this policy. What seems to happen, especially with organizations that existed pre-computing, is these things evolved gradually along with computing and best practices. You picked the person with the most computing prowess, sat them down and said "make this work". And they got it working. And then it was too important to stop working. It takes an IT team with skill and a management team that trusts them and their decision making to turn that kind of thing around. It's a similar story of a company that fails to have a working backup or disaster recovery: "everything has been fine and we can't justify the expense", when in reality it's a time bomb.
- InfiniteVortex 2y agoI wonder how much he was fine (if he was - they also have caning as a penalty). Singapore is known to be incredibly strict with criminal punishments. There was a recent $8 billion money laundering case that garnered international headlines because SG is known to be corruption-free for the most part. I'm sure you can find the reasons for verdict (SG has no jury trials) and reasons for sentence. Generally, an incredibly well run state IMHO. (Yes, it has its downsides, criticisms and controversies). It'll be interesting to see how PM Wong will govern compared to LKY & LHL.
- deleted 2y ago[deleted]
- xyst 2y agoOnly $678K worth of damage? Rookie numbers. Worked with a number of folks that caused much more than that just by mere accident. Not disgruntled or anything. Just “fat fingered” a command or had a momentary brain fart (deleted prod db instead of backup!). Guy truly was incompetent and deserves everything coming to him.
- averageRoyalty 2y agoIncompetent is an understatement. According to the article (which by the wording is not written by someone technical, so take with a grain of salt I guess), the accused: - accessed the servers tens of times post employment from India - returned to Singapore - lived with another active employee of the company he was planning to attack - had a script kiddie Google history - made no efforts to cover his access It's hard to read in any way but him wanting to be caught, although I'd love a more detailed article to clear up some confusion. It was cold blooded months after, and he moved back to the country where he could be convicted. Wild.
- barfbagginus 2y agoReads like arrogance and poor trade craft, not a desire to get caught. He could have thought that the organization was too corrupt and incompetent to track the attack. He might have been unaware of law enforcement investigation procedures, or jurisdiction risks. It would be common for script kids to lack sophistication in forensics, legal risk analysis, and not really understand the magnitude of their crime. Assuming there is no evidence that he was getting paid by a third party to do this, I think his defense could have argued he was a naive and immature prankster that didn't think they were doing real damage, not a hardened criminal intentionally causing damage for profit. He only got 2 years. Seems light, for nearly a million dollars in damages, right? A 2-year vacation with free food and housing and criminal advocacy, and then try again maybe with more professional approaches? The birth of a real pro! Doesn't sound so bad honestly. He'll be 41 when he gets out, and ready to strike again! Maybe he'll get a big brain, and go straight into security consultancy, a la Mitnick! Either way, the kid just made his boldest career move! Wishing him all the best of luck!
- banku_brougham 2y agoWhat about leaving an ssh key on there with a port open?
- technick 2y agoThe level of incompetence on NCS's part is criminal, they absolutely deserved what they got. It could have been much worst, as in the malicious actor finding a way to insert code that makes it into production and then exfiltrating sensitive data to be sold on the dark web. Luckily Kandula wasn't smart enough to think like one of us. NCS sounds like a clown show based on this article. The administrator credentials should have been changed as soon as Kandula was let go. Ideally, these credentials shouldn't have ever been used and everyone should be acting as themselves with a elevated privilege step. As for the $678k in damages, why didn't NCS have snapshots that they could have quickly restored? Sounds like their BCDR plans need to be reviewed and updated. Moral of the story is don't do business with NCS.
- rkwz 2y ago> On Mar 18 and 19, he ran a programmed script to delete 180 virtual servers in the system. > The system that Kandula’s former team was managing was used to test new software and programs before launch. In a statement to CNA on Wednesday, NCS said it was a "standalone test system". > As a result of his actions, NCS suffered a loss of S$917,832. Wondering if these are CI/CD pipelines, and how the loss amount was calculated since these can be spun up again.
- geodel 2y agoI guess it is mostly the billable hours of testing and other teams waiting for few days without work (but paid) before new VMs come online
- frank_bb 2y ago[dead]
- rekabis 2y agoI’m sorry but based on this, > NCS is a company that offers information communication and technology services. And more importantly, this: > After Kandula's contract was terminated and he arrived back in India, he used his laptop to gain unauthorised access to the system using the administrator login credentials. He did so on six occasions between Jan 6 and Jan 17, 2023. The company is not just ignorant, but massively incompetent. You don’t fire someone without totally withdrawing every last shred of access they have. The fact that he was able to use a common, generic administrative credential shows that NCS fails epically at even the simplest of security.
- ssahoo 2y ago180vms and 678k loss. So 3.5k a pop.