Hi Scott, good points but a couple of rebuttals ;)
SB> Can you lock someone into a contract stating they cannot work for a SB> competitor for X months? I thought you can't do this. I had a situation with SB> a company i worked for, who basically put in the contract the very same SB> thing you described "Cannot divulge company secrets, cannot work for my SB> competitor etc" you can lock someone into anything you like that isn't illegal if they're willing to sign the contract. I've seen contracts like that before "you cannot work for or with anyone we've ever heard of for a year after you leave us" which I've 'politely declined'. Nobody can legally force you to sign something like that, but a lot of people get suckered into it if they won't get the job otherwise. SB> In this case, frankly the problem lied with someone knowing way to much SB> information about a companies infrastructure. I've heard stories of where in SB> a "professional" environment, the IT guys knew a person was fired before SB> they did, in that they'd come in that morning to find that they can't login SB> and with a yellow post-it note saying "See HR".. that's the big problem - what if the employee in question IS one of the IT guys? More specifically, in the case that started this thread, the guy wasn't fired. He left in an amicable way, and was busy taking these files before he left. At the time he took them, he had legal access to copy them. Whether it's legal for him to take them with him and show other people is debatable, but by other people than I. Their unfortunate situation was that they trusted this guy, he was leaving and using his existing permissions he did something bad. Backups wouldn't help because he didn't destroy it - he just took a copy for himself. This is the inherant flaw in any security. If you work for a secured agency like MOD or NSA or something like that, to get into your building you'll find yourself interrogated by full-auto wielding unfriendly fellows who don't care whether they've known you all your life, you still have to prove you are who you are and what your reason is for being there. The single easiest, safest and most fruitful avenue of invasion is social engineering (allegedly ;) ). If in any way you can gain a position of trust with your target, or an employee of your target, you're in. Whether that be by pretending to be someone you're not, by conning someone out of a password or even being employed by them for a length of time, there is very very little that can be done to completely prevent it. When somebody operates from a positions of trust, security is already irrelevant. There was no way these guys could have forseen this happening, and the only way to get any redress currently is to follow it up in civil court and take your chances (assuming you can get a case heard). The general consensus is that we don't necessarily have an answer yet, but we'd all be better served by laws and lawmakers who understood the unique problems faced by people in our industries. Toby SB> You need to have a monitoring situation on your sysadmins and have someone SB> check their work etc, play big brother if you have such sensitive SB> information. Also backups anyone? SB> --- SB> You are currently subscribed to cfaussie as: [EMAIL PROTECTED] SB> To unsubscribe send a blank email to [EMAIL PROTECTED] SB> MX Downunder AsiaPac DevCon - http://mxdu.com/ --------------------------------------- Life is poetry - write it in your own words. --------------------------------------- Toby Tremayne Technical Team Lead Code Poet and Zen Master of the Heavy Sleep Toll Solutions 154 Moray St Sth Melbourne VIC 3205 +61 3 9697 2317 0416 048 090 ICQ: 13107913 --- You are currently subscribed to cfaussie as: [EMAIL PROTECTED] To unsubscribe send a blank email to [EMAIL PROTECTED] MX Downunder AsiaPac DevCon - http://mxdu.com/
