Parts of San Francisco network still locked out

By Robert McMillan, IDG News Service |  Security, cybercrime, Network access control 1 comment

The high-profile troubles on the city of San Francisco's computer network continue, despite a dramatic jailhouse intervention by the city's mayor this week.

While the city has regained control of the five devices at the heart of its FiberWAN network, which carries data between city government buildings, administrators are still locked out of the city's voice over Internet Protocol system and local area networks within the Sheriff's Department and the Recreation & Park Department. Assistant District Attorney Conrad Del Rosario revealed the ongoing problems Wednesday at a bail hearing for Terry Childs, the former network administrator with the city's Department of Telecommunications and Information Services (DTIS) who is accused of holding the city's networks hostage for the past 10 days.

[ Related reading: San Francisco's mayor gets back keys to the network ]

During that time, the networks have functioned normally, but IT staffers have been unable to make administrative changes to some of the city's critical routers and switches.

Childs' attorney, Erin Crane, had moved for a reduction in the US$5 million bail set in the case. San Francisco Superior Court Judge Lucy McCabe denied that motion Wednesday.

[ Related reading: IT admin locks up San Francisco's network ]

Childs' defense has portrayed him as a capable engineer, surrounded by incompetent management, who simply didn't trust anyone with the administrative passwords to the five network devices at the heart of the FiberWAN. On Monday, Childs had a secret meeting with San Francisco Mayor Gavin Newsom where Childs turned over the passwords.

Del Rosario argued against any reduction of bail, noting that Childs handed over the passwords only after a scheduled July 19 power outage at the city's One Market Street data center failed to take down the FiberWAN. Because Childs did not store network configuration files on the routers' hard drives, a power outage would wipe this information out of memory, disabling the network until it was reconfigured, he said.

[Related reading: IT administrator pleads not guilty to network tampering ]

The assistant DA said it was "extremely suspicious" that Childs only communicated with the mayor after the network did not go out of service.

In court filings, prosecutors say they do not know where these critical router configuration files are located.

As the city's principal network engineer, Childs worked on about 1,100 networking devices throughout the city, Del Rosario said. Even with the FiberWAN passwords, there are still questions about the rest of these systems. "We do not know whether we have control of these devices," he said.

Crane said that her client was the victim of jealous co-workers who were upset because his good work made them look bad. "I think the entire thing is specious," she told the judge. "This is a DTIS management problem."

This is not Childs' first time in criminal court. He also served four years in Kansas prison on aggravated robbery and aggravated burglary charges, prosecutors said. Those charges stem from an incident that occurred when Childs was 16 years old, Crane said.

The court also ordered Childs to stay away from several of his former co-workers, including Jeana Pieralde, the DTIS director of security who was allegedly so afraid of Childs that she locked herself in a room in the data center, and his former supervisor Herb Tong, whom Childs felt was undermining his work at the department.

Prosecutors say that police found bullets when they searched his Pittsburg, California, home on July 13.

In a brief appearance before reporters after the hearing, Crane said that she and Childs were "deeply disappointed that bail had not been reduced."

Childs' next scheduled court date is a Sept. 24 pretrial hearing.

1 comment

    mburton325
    mburton325 3 years ago
    "Del Rosario argued against any reduction of bail, noting that Childs handed over the passwords only after a scheduled July 19 power outage at the city's One Market Street data center failed to take down the FiberWAN." Good administrators always put uninteruptable power supplies on the critical parts of a network. This again proves that the people investigating have no clue as to what it takes to administer a network like this. "Because Childs did not store network configuration files on the routers' hard drives, a power outage would wipe this information out of memory, disabling the network until it was reconfigured, he said."The backup files for the configuration should not be stored on the router's hard drive that defeats the purpose of the back up.Computer illiterate people scare me.

      Add a comment

      Post a comment using one of these accounts
      Or join now
      At least 6 characters

      Note: Comment will appear soon after you have activated your account.
      Obscene/spam comments will be removed and accounts suspended.
      The information you submit is subject to our Privacy Policy and Terms of Service.

      ITworld LIVE

      SecurityWhite Papers & Webcasts

      White Paper

      Overcome Top 7 Admin Challenges of Active Directory

      As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable, enforceable processes that reduces administrative overhead and enables robust, customizable reporting and auditing capabilities. Brought to you by NetIQ.

      White Paper

      Insiders Can Ruin Your Company. Take Action.

      Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.

      White Paper

      Top Solutions and Tools to Prevent Devastating Malware

      Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring (FIM) tools that provide immediate alerts. This white paper has been brought to you by NetIQ, the leader in solving complex IT challenges.

      White Paper

      Streamline Compliance and Increase ROI

      Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will help your business gain the maximum return on investment possible while aligning your compliance programs.

      White Paper

      X-Ray of the PCI Process-4 Proactive Steps

      This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into creating a compliant and secure IT environment. Follow these four proactive steps now before your next audit. Brought to you by NetIQ.

      See more White Papers | Webcasts

      Ask a question

      Ask a Question