Hi Scott,

good points but a couple of rebuttals ;)

SB> Can you lock someone into a contract stating they cannot work for a
SB> competitor for X months? I thought you can't do this. I had a situation with
SB> a company i worked for, who basically put in the contract the very same
SB> thing you described "Cannot divulge company secrets, cannot work for my
SB> competitor etc"

you can lock someone into anything you like that isn't illegal if
they're willing to sign the contract.  I've seen contracts like that
before "you cannot work for or with anyone we've ever heard of for a
year after you leave us" which I've 'politely declined'.  Nobody can
legally force you to sign something like that, but a lot of people get
suckered into it if they won't get the job otherwise.

SB> In this case, frankly the problem lied with someone knowing way to much
SB> information about a companies infrastructure. I've heard stories of where in
SB> a "professional" environment, the IT guys knew a person was fired before
SB> they did, in that they'd come in that morning to find that they can't login
SB> and with a yellow post-it note saying "See HR"..

that's the big problem - what if the employee in question IS one of
the IT guys?  More specifically, in the case that started this thread,
the guy wasn't fired.  He left in an amicable way, and was busy taking
these files before he left.  At the time he took them, he had legal
access to copy them.  Whether it's legal for him to take them with him
and show other people is debatable, but by other people than I.  Their
unfortunate situation was that they trusted this guy, he was leaving
and using his existing permissions he did something bad.  Backups
wouldn't help because he didn't destroy it - he just took a copy for
himself.

This is the inherant flaw in any security.  If you work for a secured
agency like MOD or NSA or something like that, to get into your
building you'll find yourself interrogated by full-auto wielding
unfriendly fellows who don't care whether they've known you all your
life, you still have to prove you are who you are and what your reason
is for being there.  The single easiest, safest and most fruitful avenue
of invasion is social engineering (allegedly ;) ).
If in any way you can gain a position of trust with your
target, or an employee of your target, you're in.  Whether that be by
pretending to be someone you're not, by conning someone out of a
password or even being employed by them for a length of time, there is
very very little that can  be done to completely prevent it.

When somebody operates from a positions of trust, security is already
irrelevant.  There was no way these guys could have forseen this
happening, and the only way to get any redress currently is to follow
it up in civil court and take your chances (assuming you can get a
case heard).  The general consensus is that we don't necessarily have
an answer yet, but we'd all be better served by laws and lawmakers who
understood the unique problems faced by people in our industries.

Toby

SB> You need to have a monitoring situation on your sysadmins and have someone
SB> check their work etc, play big brother if you have such sensitive
SB> information. Also backups anyone?



SB> ---
SB> You are currently subscribed to cfaussie as: [EMAIL PROTECTED]
SB> To unsubscribe send a blank email to [EMAIL PROTECTED]

SB> MX Downunder AsiaPac DevCon - http://mxdu.com/







 ---------------------------------------

             Life is poetry - 
               write it in your own words.

 ---------------------------------------

Toby Tremayne 
Technical Team Lead
Code Poet and Zen Master of the Heavy Sleep
Toll Solutions
154 Moray St
Sth Melbourne
VIC 3205
+61 3 9697 2317
0416 048 090
ICQ:  13107913


---
You are currently subscribed to cfaussie as: [EMAIL PROTECTED]
To unsubscribe send a blank email to [EMAIL PROTECTED]

MX Downunder AsiaPac DevCon - http://mxdu.com/

Reply via email to