Software Developer Outsources His Own Job, Gets Busted During Security Audit
January 16, 2013 10:00 AM
comment(s) - last by
Bob gets busted bypassing business security
It comes as no surprise to anyone that it is typically much cheaper to have programming performed in China rather than in the U.S., as the work can typically done for a fraction of the cost. A security case involving this interesting dynamic between the U.S. and China has surfaced that's both funny and disturbing at the same time.
A developer for a U.S.-based critical infrastructure company simply called "Bob" was busted for outsourcing his programming job to China. Obviously, his employer had no idea what Bob was doing despite the fact that he had been receiving glowing performance reviews.
Bob was caught during a company security review of VPN logs. Security personnel at the company discovered that there was an unauthorized VPN connection coming into their system from China. Since they are a U.S. critical infrastructure company, having an
unauthorized VPN access from China was a big deal
Making the problem even scarier for the security personnel was that the company had implemented two-factor authentication for the VPN using a rotating token RSA key fob. An unauthorized Chinese connection to the VPN meant that whoever was accessing the system from China had also been able to bypass a security token, or at least they thought this was the case.
Making things even more puzzling for the investigators was that the developer whose credentials were being used was sitting at his desk in the office when the live VPN connection from China was discovered. On further investigation, it was discovered that Bob had physically mailed his RSA key fob to China and had hired developers to do his work.
Bob was reportedly making several hundred thousand dollars per year while paying roughly $50,000 per year to the Chinese developers who were doing his work for him. Bob was spending his day watching cat videos, surfing Facebook, and messing around on eBay according to evidence the security researchers later found on his computer. Bob was also storing invoices from his Chinese developer on his work computer.
Bob had a good thing going, but unsurprisingly, his company wasn’t too fond of his antics and fired him.
Verizon Business Security Blog (cached)
This article is over a month old, voting and posting comments is disabled
RE: Not bad
1/16/2013 1:16:06 PM
There are a lot of people who are willing to take chances. Take a look at Kevin Mitnick.
Actually I think he would be best off starting his own business, outsourced software development. You talk to him and he outsources to China. They said the results were good, why not continue? If it's not defense work it's not a serious issue.
RE: Not bad
1/16/2013 1:16:35 PM
I'm actually tempted to try a legal version of this myself.
"If a man really wants to make a million dollars, the best way would be to start his own religion." -- Scientology founder L. Ron. Hubbard
Lockheed Warns Foreign Cyberattackers are Targeting Its Contractors
November 13, 2012, 6:33 PM
Report: AT&T Eyeing $40B DirecTV Purchase
May 1, 2014, 8:00 AM
WebOS Class Action Settlement Costs HP $57 Million
April 1, 2014, 10:22 AM
IBM Workers Strike Over Terms of Deal That Will Have Them Working for Lenovo
March 6, 2014, 9:29 AM
Google Picking Up Artificial Intelligence Company "DeepMind" for $400 Million
January 27, 2014, 9:25 AM
Quick Note: Qualcomm Grabs up Palm, IPAQ, and Bitfone Patent Portfolio from HP
January 24, 2014, 9:18 AM
Verizon Buys Intel Media OnCue Cloud TV assets
January 21, 2014, 10:26 AM
Most Popular Articles
Cool Science Video of the Day: Carnivorous Leech Eats Giant Jungle Worm
October 16, 2014, 6:44 PM
Chinese Government Declares Digital War Against America's Top Tech Firms
October 20, 2014, 12:07 PM
PS4 "Masamune" Update 2.0 Will Bring New Music and Customization Features
October 17, 2014, 1:05 PM
HBO, CBS Lead Charge to Ditch Cable
October 16, 2014, 4:40 PM
Update: Motorola Droid Turbo Coming Oct 28, 48-hour Battery Life Confirmed
October 19, 2014, 9:19 PM
Latest Blog Posts
The Surface Mini That Was Never Released Gets "Hands On" Treatment
Sep 26, 2014, 8:22 AM
ISIS Imposes Ban on Teaching Evolution in Iraq
Sep 17, 2014, 5:22 PM
Space Terrorism is a Looming Threat For the United States
Apr 23, 2014, 7:47 PM
Facebook Aims to Provide Internet to "Every Person in the World" with Drones, Satellites
Apr 1, 2014, 10:20 AM
Retail Mobile Sites Experience Outages in Light of Simplexity's Bankruptcy
Mar 14, 2014, 8:48 AM
More Blog Posts
Copyright 2014 DailyTech LLC. -
Terms, Conditions & Privacy Information