PDA

View Full Version : Security audit finds dev OUTSOURCED his JOB to China to goof off at work



Serpo
16th January 2013, 02:33 PM
Security audit finds dev OUTSOURCED his JOB to China to goof off at work








Cunning scheme netted him 'best in company' awards
By Iain Thomson in San Francisco (http://forms.theregister.co.uk/mail_author/?story_url=/2013/01/16/developer_oursources_job_china/) • Get more from this author (http://search.theregister.co.uk/?author=Iain%20Thomson)
Posted in Business (http://www.theregister.co.uk/business/), 16th January 2013 01:29 GMT (http://www.theregister.co.uk/2013/01/16/)
Free whitepaper – A Vision for the Data Centre (http://go.theregister.com/tl/728/-2674/a-vision-for-the-data-centre.pdf?td=wptl728)
A security audit of a US critical infrastructure company last year revealed that its star developer had outsourced his own job to a Chinese subcontractor and was spending all his work time playing around on the internet.
The firm's telecommunications supplier Verizon was called in after the company set up a basic VPN system with two-factor authentication so staff could work at home. The VPN traffic logs showed a regular series of logins to the company's main server from Shenyang, China, using the credentials of the firm's top programmer, "Bob".


"The company's IT personnel were sure that the issue had to do with some kind of zero day malware that was able to initiate VPN connections from Bob's desktop workstation via external proxy and then route that VPN traffic to China, only to be routed back to their concentrator," said (http://securityblog.verizonbusiness.com/2013/01/14/case-study-pro-active-log-review-might-be-a-good-idea/) Verizon. "Yes, it is a bit of a convoluted theory, and like most convoluted theories, an incorrect one."

After getting permission to study Bob's computer habits, Verizon investigators found that he had hired a software consultancy in Shenyang to do his programming work for him, and had FedExed them his two-factor authentication token so they could log into his account. He was paying them a fifth of his six-figure salary to do the work and spent the rest of his time on other activities.
The analysis of his workstation found hundreds of PDF invoices from the Chinese contractors and determined that Bob's typical work day consisted of:
9:00 a.m. – Arrive and surf Reddit for a couple of hours. Watch cat videos
11:30 a.m. – Take lunch
1:00 p.m. – Ebay time
2:00-ish p.m – Facebook updates, LinkedIn
4:30 p.m. – End-of-day update e-mail to management
5:00 p.m. – Go home
The scheme worked very well for Bob. In his performance assessments by the firm's human resources department, he was the firm's top coder for many quarters and was considered expert in C, C++, Perl, Java, Ruby, PHP, and Python.
Further investigation found that the enterprising Bob had actually taken jobs with other firms and had outsourced that work too, netting him hundreds of thousands of dollars in profit as well as lots of time to hang around on internet messaging boards and checking for a new Detective Mittens video (http://www.youtube.com/watch?v=tVx2uCcDXX0).
Bob is no longer employed by the firm. ®



http://www.theregister.co.uk/2013/01/16/developer_oursources_job_china/

Glass
16th January 2013, 03:38 PM
I've been following the NBN debacle on and off. It hasn't gone supernova debacle yet but it will. I always have a chuckle when the name Huawei crops up. They have been banned by the Govt from participating in the contracts associated with this.

NBN is the National Broadband Network in Australia. 1 internet provider, fibre to every home, for the whole country with multiple billing agents who were formerly independent ISP's.

I get a chuckle because Huawei want to sue the government and the Government won't explain (in public) why they blocked them. They were blocked because of all the back doors they put in their Cisco rip offs which ended up in US Government installations.

chad
16th January 2013, 03:52 PM
i'm self employed, but i do this kind of thing. i meet with a client, he lays out what he wants, i charge him say 5k for it. then i go on rent a coder, pay some guy from belarus $100 to do it, keep $4,900 for myself and spend the rest of the day f-ing off on gs-us, fishing, and shooting guns.

gunny highway
16th January 2013, 04:28 PM
genius, pure genius.

chad
16th January 2013, 04:31 PM
my best run ever was a full blown content management system with an ebay type interface for dealers run on a company intranet. i charged them $26k and change for it. i paid some guy $2,000 to make it and he thought he HIT THE LOTTERY. i fucked around for the whole summer and didn't work at all after that one. :D

rent a coder is your good, good, friend.