Siemens contractor pleads guilty to planting logic bomb in company spreadsheets
zdnet.com
zdnet.com
We're talking about the choice of an algorithm in a spreadsheet delivered by a contractor being a criminal offense. It's not like that's impossible but it seems a lot more like a contractual issue at first glance. I mean fundamentally it's a string of ones and zeros, it's a piece of software.
What if he says that it was his policy to put an expiration into all his software deliverables? How is this, as a criminal legal matter different from a company that disables a piece of software without a support contract in place, or similar?
It seems a lot like a contractual issue, a discrepancy between what he delivered and what they expected, with monetary damages as the legal remedy. What am I missing here?
EDIT: Upon reading a little more about it it's a Federal charge, which seems even more insane. I can't find the actual complaint to see if it's a CFAA charge but it looks that way.
This looks a lot like yet another case of "person vs. giant multinational billion plus dollar company" on a computer issue, which means massive Federal charges for some reason, along the lines of Sergey Aleynikov, Aaron Schwartz, or Weev.
If he says that in his contract, and the expiration process is written to do something honest like pop up a dialog saying "you need to renew your license" then I can't see there being a problem with that.
It sounds like there was malicious intent, however, if the contract didn't specify expiration and the expiration is intentionally designed to look like a fault rather than an expiration.
Of course multi-million dollar companies do at times get away with built-in obsolescence... be great if this set a precedent regarding all the smartphones that mysteriously become unusable after 2 years...
It looks like he was hired as a contractor to work on their internal systems (i.e. the spreadsheet) rather than licensing a product to them. If as is likely the bank owned the spreadsheet, he's purposefully modified it without permission to malfunction after a certain date - that's why it would be a criminal matter, he's been told "you can access these internal systems to incorporate functionality x", and has additionally gone in and planted malicious functionality.
When you license software that disables functionality without a current license, it's legal because you have no right to use that software without the license. If you own the copyright to some software and someone you'd hired to work on it goes and sneaks in a logic bomb to make themselves indispensable, I think you have every right to be pretty peeved.
Indeed. That's an excellent point, if true.
It is more than that. He purposefully modified it to expire in a time frame and in a method other developers would fine unreasonable and did so for personal profits. Then he took advantage of that modification.
Most the software I make has a problem in it when we reach the year 10,000AD. But we would all agree that is a reasonable issue that I shouldn't be found liable (it would be a massive achievement to even be remembered as a footnote come 10,000AD).
In fact it was CFAA: 18 USC § 1030.
> The case is U.S. v. Tinley, case number 2:19-cr-00156, in the U.S. District Court for the Western District of Pennsylvania.
[1] https://www.law360.com/commercialcontracts/articles/1180318/...
You can reduce anything like that. Shooting a person? How can that be a crime? Fundamentally, it's just atoms. How can atoms be illegal? All they've done is move them from one place to another.
Outcomes are what matter.
More specifically, intent.
https://regmedia.co.uk/2019/06/25/tinley-siemens-logic-bomb....
Have federal prosecutors filed any CFAA complaints on behalf of individual consumers. For example someone who has lost over $5K in one year as a result of planned obsolescence.
He's not the last person who will realize that the market can be manipulated by sabotage. It seems important that the penalties for trying that outweigh the potential benefits.
Do you apply that same logic to other software, such as Malware?
That's not what we're really talking about. He intentionally added in a failure to the software he delivered and then charged them to 'fix' the issue i.e. reset the trigger to happen at a later date and charged them for the 'fix'. Seems like a pretty straight forward fraud charge.
I don't know if the courts will see it the same way, but to me it seems that Tinley's crime is a lot less severe. That other case was stock manipulation, which has the potential to cause much larger losses for other uninvolved parties. The only effects of Tinley's action is stealing his fee directly from Siemens plus whatever loss results from the spreadsheets briefly not working (which couldn't have been that great if they didn't just get them rewritten).
> Every time the scripts would crash, Siemens would call Tinley, who'd fix the files for a fee.
I wonder what the code looked like. Is it obviously nefarious, like
if (date() > '2018-01-01') { exit(); }
or can it be chalked up to laziness, like for(date in range('2000-01-01', '2018-12-31')) { process(date); // TODO, this should be moved out of this spreadsheetThis article speaks volumes about their internal IT Governance and process.
You'd be surprised.
Excel files are used to handle trillions (not billions) of dollars in businesses, even for the most critical processes...
https://baselinescenario.com/2013/02/09/the-importance-of-ex...
> JPMorgan’s Chief Investment Office needed a new value-at-risk (VaR) model for the synthetic credit portfolio (the one that blew up) and assigned a quantitative whiz (“a London-based quantitative expert, mathematician and model developer” who previously worked at a company that built analytical models) to create it. The new model “operated through a series of Excel spreadsheets, which had to be completed manually, by a process of copying and pasting data from one spreadsheet to another.” The internal Model Review Group identified this problem as well as a few others, but approved the model, while saying that it should be automated and another significant flaw should be fixed.* After the London Whale trade blew up, the Model Review Group discovered that the model had not been automated and found several other errors...
It creates the mindset of, let me do a little everyday to make this a more automated process.
That turned ~4 hrs/day of reports into an automated system, gave me a good understanding of how the various systems and reports work together, and helped me get my first promotion.
I've moved on to a new role where I'm doing the same thing on a process which has been void of substantial improvements for 3+ years. There's always something, and I can remove a bit more time with every automation iteration.
The csvkit toolset – particularly `in2csv` [0] and `csvsql`, which, respectively, can be used to extract CSV from Excel sheets and import/insert directly into sqlite – make frequent appearances in my daily work these days.
Though admittedly, I don't know what options there are to distangle spreadsheets that aren't just data (e.g. intertwined formulas).
[0] https://csvkit.readthedocs.io/en/1.0.3/scripts/in2csv.html
[1] https://csvkit.readthedocs.io/en/1.0.3/scripts/csvsql.html
It is very easy to train people on how to use excel if they are willing to invest the time to learn formulas, and once you learn VB, you will be tempted to do most data presentation in Excel.
That said, just because most people know how to use Excel does not mean they are technically capable of setting up things like version control, backups, validation or security. A lot of users I have worked with in addition get their files from someone else, who may not even work at the company anymore and they have no idea what is or could be running in the background or how exactly the calculation in certain cells is done. Further, it is very common that one technically capable person creates an excel that becomes a crux of an internal process simply because it is the easiest thing to use, once IT governence policies are put in place, it doesn't help because they damage lies in the fundamental data they started with.
Tl;dr it is more common and innocent than it seems.
This is like the story of the accountant who never goes on vacation, but when she finally does it turns out she had been skimming money.
I’m not familiar with how to deploy Excel macros, could this code be checked into a source repo and then somehow automatically deployed? If not I can see how he can sneak this by IT by saving it was hard to deploy and that’s why I’m giving you a binary and tell all your users to hit this URL to install.
Unfortunately, regardless of save format, the VBA portion is saved in a binary format.
There are some source control systems out there for the embedded VBA code, but I haven't tried any out.
Probably 90% of my day is jumping between spreadsheets and queries building tools and updating reports. Spreadsheets are a "universal language" that most people understand, and allow the technically inclined business user to investigate problems without having to submit a help desk ticket and wait 4-48 hours for an answer.
Of course if I'm away and there's an emergency they have everything they need to modify it themselves, including the in-house skills. I wouldn't do anything nefarious like this, but I can relate to the situation of them not wanting/needing day-to-day access to the code.
It's analogous to being able to hire a full-time personal physician, and then self-diagnosing all your medical problems with quartz crystals and pendulums, and not even the free and reputable medical information sources.
We routinely give out free advice, such as:
- Make backups.
- ...including an off-site backup.
- Use source control.
- Don't trust inputs.
- Run tests.
Maybe we can add to this, "if your company has permanent in-house developers, use them" and "synchronize your personal calendar with your logic bomb schedule".I guess the main difference is that corporations have the leverage to force consumers (or employees) to accept their license terms no matter how lopsided they are, whereas the opposite is never true and so this surreptitious method was required.
This, in my opinion, is a real problem. There's too much patch work trying to generate spreadsheets from other documents through macros and it's most likely a security risk.
I worked for a company that was moving away from using Office products for report management for this very reason. We have databases and it's 2019.
In fact, there's entire services that track assets already built that are infinitely better than spreadsheet generation.
I think ten years is way too much. Maybe like 3-5 if he had malicious intent. (not a lawyer)
I think that the persons who need attention are the managers who let things like this to happen, not the contractors who they hire as scapegoats.
Managers might be negligent, but he is still responsible for his illegal actions.
If he had done this to 100 companies, then he would be considered an enterprise, not a criminal.
How is this not simply ad-hoc DRM by another name?
What's the difference between an expiring file format and Microsoft's operating system being shipped with vulnerabilities that require automatic update patches and refusing support for old versions of XP?
In my experience pretty much every company on the planet would be deemed "pretty pathetic" by your lofty standards.