|
Over the weekend a former employee of ours got into
our servers, copied files and made some small modifications, nothing major just
nuisance stuff - but enough to piss me off.
Today after gathering all the log file data i
decided to ring the police.
What the Computer Crimes Section told me was a bit
of an eye opener;
Former staff members are allowed back inside your
servers and are able to copy and modify information at will - because they were
once allowed to.
The only way they can be charged criminally is if
they gain access to your system via another means other than a known username
and password (it doesnt even matter if it wasnt their username and password -
any will do).
The only way other than changing every password on
your system is to have a watertight employment contract, advising them that
they have no access rights to your system after their period of employment ends,
this contract must also outline the ownership of the intellectual property they
create whilst employed - this must be signed by both parties. If they gain
access to the system outside of their employment then its a criminal
act.
We didnt have this in place, and our contract was
full of wholes when dealing with the ownership of the code he created for
us.
We can of course go after him via civil action -
but he hasnt got anything, so it would be a waste of time - i would have much
preffered a criminal conviction.
A bitter lesson learned
Does anyone have a contract of this nature that
they would like to share?
Steve Soars Interactive Redlands [p] 07 3821-5800 "what we do in
life You are currently subscribed to cfaussie as: [EMAIL PROTECTED] To unsubscribe send a blank email to [EMAIL PROTECTED] MX Downunder AsiaPac DevCon - http://mxdu.com/ |
