Contractor admits planting logic bombs in his software
arstechnica.com
arstechnica.com
> For years, the spreadsheet would glitch, Tinley would be hired to come in, would "fix" it, invoice Siemens, and head out again. But that all changed in May 2016 when Tinley was out of state, and Siemens called again about the spreadsheet. The company had an urgent order it had to put through, it told Tinley, and it wasn't working properly again. Pushed, Tinley relented and handed over the password.
https://www.theregister.co.uk/2019/06/25/siemens_logic_bomb/
We hired a licensed plumber on 2 occasions - to install a sink and later a shower.
We just had a different plumber out because the sink was plugged up. He pointed out that the prior plumber had installed the sanitary-t upside down basically guarantying it would eventually become clogged.
We also had him look at the shower because we couldn’t figure out how to get the screen out to clear the hair. Turns out the grate was also installed upside-down and the screws holding the screen in are in-accessible. So, there is no way to get it out without demoing the shower.
Should this plumber be sentenced to 6-months in jail?
I personally do not think that 6 months' jail for stealing $42k from somebody is so severe, to be honest, it's a lot of money.
If you stole a car (often valued at less than $40k), you could have gotten 1-9 years in the USA (depending on the value of the car).
On the other hand, it's entirely possible the plumber made an honest mistake.
Is your argument that the programmer in the FA was tired after a long day and accidentally concocted a scheme to defraud his client of $40,000?
Edit: After some thought, I feel a precedent. My car has parts that don't become obsolete, they flat break requiring never ending service. Surely I can sue for fraud as the auto company has the ability to use another means. (Devils advocate)
For example, Apple noticed that most customers replaced their phones within 2-3 years. A lithium ion battery's lifetime is determined by its charging and discharge characteristics. Its life is extended if it is charged more slowly and neither charged or discharged fully. But this increases charge time and reduced usable battery capacity - both of which are key selling features for smartphones. So Apple optimized the iPhone's battery management to deliver good charging and usable capacity, with the tradeoff that it would degrade significantly beyond 2-3 years of use.
This contractor's activities would have been analogous to Apple introducing code that checks the current timestamp with the timestamp from when the phone was sold and degrading performance when that difference exceeded a threshold.
Perhaps, but it's two points on the same continuum.
Is it particularly that you think that there isn't a continuum from legal actions to illegal actions? Isn't it possible and common that two instances of similar actions can be on the right and wrong sides of the law?
Planned obsolescence and what this contractor did are not on any sort of continuum. This contractor was not making a trade-off, he deliberately sabotaged his work. This is not on any sort of continuum with optimizing phone's battery life for a certain number of years, or making similar tradeoffs.
Planned obsolescence could in the abstract be just about making a trade-off between price and durability, but in all real instances it leverages the fact that the consumer can't reliably assess the ratio of cost to lifespan of a product. If the trade-off was transparent to the buyer, then competition would produce much more durable products, even if not infinitely durable.
No, your assertion is quite wrong. All engineered products have service lives, because they all have failure modes that are taken into account in the design process. If a phone's failure mode consists of the battery dying the the battery will be designed to ensure it will likely work well for a minimum of x time following a typical usage pattern. Likewise an airplane failure mode is the fuseage breaking off due to fatigue, thus it is designed to be flown X times (takeoff/landing counts, number of hours in flight) taking onto account the likelihood of cracks forming and propagating. Targeting a certain service life in a design does not mean there is mischief in play. It only means engineering.
Thus obviously planting time bombs has absolutely nothing to do with engineering a product.
You're missing the whole point. Everything fails after a while. Everything. It's the engineer's job to ensure that it fails only after X amount of use, which can be expressed in time of normal usage. There are no time bombs, only the fact that designers picked a small service life.
They really aren't. All engineered products are designed to meet a target service life. Even today's houses are designed with a design lifespan of 50 years. A consumer product is not different.
Surely you understand the difference between a part that naturally wears out over time due to friction and wear and tear, versus a part that's delibrately installed incorrectly to cause a malfunction?
However, I tend to disagree with this approach when the final result is that the "incompetent" one stands to profitably gain from their alleged incompetence or ignorance.
It's like if the plumber designed, built, and installed a device specifically to make your plumbing leak or clog or something at a specific point in the future, instead of just installing a normal and expected device incorrectly.
The law does tend to take intentions into account for crimes and punishment. Killing somebody by a freak accident is different from making a plan in advance to kill somebody and executing it.
This does make it feel rather odd that it's legal to DRM things though.
Intent is what matters. The distinction you're describing just affects whether it's deniable.
1. Ignorance/Incompetence -- wasn't paying attention?
2. Gross negligence -- doing it wrong was somehow quicker and cheaper.
3. Fraud -- calculated to fail.
p.s. Dealing with similar case of malfeasance myself just now (electrical). Looks to be about #1 20%, #2 80%.
I wonder why this is illegal but it's legal for hardware to deny service or even break stuff when they detect you're using something they don't like (I'm referring to printers, but I also remember a case where a microcontroller would try to brick something when it detected a counterfeit cable).
It was not that uncommon if you bought a cheap USB to serial or USB to TTL dongle online.
APC devices are generally pretty good, except for this infuriating and dangerous “feature”.
It’s almost 2020, and vendors still have this ridiculous idea that they can lock you into their proprietary ecosystem by doing stuff like this.
That said, there's absolutely zero reason to keep maintaining this ancient and dangerous option.
Probably the timed aspect of it is the issue. Selling something that purposefully breaks in that way is malicious. Unless he comes up with a truly fantastic excuse but it doesn't sound like he did.
Overflow of like milliseconds counter would be just the thing. After all a lot of software did this trick with the 2 digit year counter in the 20th century guaranteeing that massive upgrade and contractor y2k call. And the UNIX 32 bit seconds counter comes to mind too - the guys i guess were planning long-term for a very plush retirement.
You might be thinking of the big FTDI scandal where they published a driver update for their chips that would attempt to detect a counterfeit FTDI chip and if it found one it would reconfigure the counterfeit chip with a bogus VID and PID thus rendering it essentially bricked. Bricking the cables using counterfeit chips wasn't the worst of it though, some of the chips in question were integrated into expensive equipment and rather than the manufacturer trying to use counterfeit FTDI chips they very well might be the victim being unwittingly sold counterfeits while paying the fraudster full price.
Which seems like incredible incompetence of the company to accept code in that format in the first place and to not have demanded the password when the first issue arose.
This person asserted the spreadsheet was his "work product". Presumably Siemens's lawyers found this convincing enough to be wary of hacking around the password.
No, he's a contractor. So what they own precisely should have been defined in the consulting contract.
It may have been perfectly legal for him to password protect the output, much like using an obsfucator - but the time-bomb stuff is fraud any way you cut it.
I found the following screenshots/guide that shows "sheetProtection" includes "algorithmName" and "hashValue" but not "password" variable... https://www.excelsupersite.com/how-to-remove-an-excel-spread...
At that time, Windows 3.1 was the latest and greatest and is what was running on all of the "display" PCs. Unfortunately, the password-protected screensaver was almost always activated -- meaning you couldn't actually do anything on the PCs.
Luckily, those passwords were easily bypassed! All you needed to do was simply power cycle / reboot the machine. Once it started booting up, you would just hit CTRL-C to interrupt and terminate the "autoexec.bat" file. Next, change into the "\WINDOWS\" directory, and open up some .INI file [0], find the line where the password was set, and delete everything after the "=" sign. Finally, save your changes, exit the editor, and hit CTRL-ALT-DEL to reboot.
The PC would start up and launch into Windows as usual, but without any password protection for the screensaver.
(A slightly older version of myself may have, allegedly, then set his own passwords on occasion.)
[0]: "sys.ini", "windows.ini", something like that.
Still a good laugh from the sidelines...
It's a little different if only from a professional dignity perspective, lol. Also, every senior programmer I've ever worked with who makes use of third-party binaries will find a moment to say, "I'll just decompile it if it ever gives us any real trouble!"
Without the source, the customer loses the ability to switch software contractors, which is against their procurement rules. Even if you don't have the clout of being huge, not controlling the source for business-critical software is basically putting the supplier's gun up to your own head.
Companies that take binary-only delivery have obviously never hired anyone who could tell them they shouldn't do that.
Always get the source, or write it in-house.
If he had accidentally written sloppy code that happened to break periodically would that have been illegal? I don’t fully understand what law he broke and how such a law would not also apply to the seemingly infinite cases of built in obsolescence.
The damage was intentional (i.e., not an accident).
If he had intentionally created a spaghetti code mess that just happened to break from time to time would that be different? I assume intention is difficult to prove in court but I am not an attorney.
Clearly, yes. Here Siemens decided to go to court because it was obviously malicious code. With a spaghetti mess they would just have hired someone else to clean it.
18 USC 1030, or:
> > intentional damage to a protected computer
I think this might explain a few things I have seen or heard about in my life.
I knew I’d have the upper hand if the site suddenly stopped working. But I was afraid of some kind of “hacking laws” being “exceeding access” or whatever (probably stupid given what was realistic) and never did it. My only acceptable option was to do a DMCA takedown at AWS because they had never signed a copyright assignment.
Anyway long story short I never got paid. Been too nice / scared. And the startup went out of business. Many of its investors were pissed. The usual.
Also, how were the contractors changes not reviewed?
If the same engineers work keeps throwing unknown problems down the line, the LAST thing I am doing is contacting them again.
That was my release workflow. Worked for the +30k line application I built in VBA.
Screenshot: https://support.content.office.net/en-us/media/9149c7e8-6f0c...
In the Excel Options dialog box, select All Commands under Choose commands from.
In the list of commands, scroll down to Compare and Merge Workbooks, select it and click the Add button to move it to the right-hand section.
I could say the same about some of the... less talented developers I've worked with in the past. Hanlon's razor might not apply in this case, but that's a scary thought given how the US justice system seems so inept at handling cyber crime.
It makes it sound more sophisticated than it is. What’s wrong with calling it malware? Or even better, simply criminal behaviour that happens to involve a computer.
It seemed unlikely to be an April Fool's Day joke, but I knew the code hadn't changed so I couldn't understand why it would quit working. Root cause? The fiscal year in the spreadsheet started in April, which made it the "zeroth" month, which triggered a logic failure due to this being a false value.
It would have made a great hard-to-spot logic bomb... if I had planted it intentionally!
The prosecutors and industries that coined these terms are very clever. For the petty crimes that they describe, they can turn the outrage up to eleven by comparing the most minor transgression to murder. In the case of DRM, the industry managed to convince people to buy new TVs, monitors, video cards, and cables... to protect their rights? Their right to be turned upside down and have the coins and bills shaken out of their pants, I guess.
The FSF seems to like calling it "digital restrictions management". I can get on board with that. (Every few years I edit the Wikipedia article to try and make that name stick, but it gets reverted immediately.)
It immediately suggests that it has a delayed action that creates a disruption after some time (and not right away); that it is hidden (as opposed to e.g. ransomware), that it's intentionally deployed there (as opposed to someone accidentally getting infected), that it's most likely not spreading itself automatically like a virus and that the damage isn't controlled in realtime like in a botnet, etc.
Simply saying 'malware' would not tell us this information, so it would be vague and inaccurate instead of using the appropriate terminology.
As PeterisP mentioned, the delayed action is integral to the concept of a logic bomb, as opposed to just invoking a piece of malware that immediately starts breaking things. Delaying the "attack" helps to hide its origin, making it harder to discover the cause of the problems.
Anyway plasmids have these things called addiction molecules to prevent the bacteria from eliminating them. They create a long lived poison, and a short lived anti-poison. If the plasmid is no longer around, then the anti-poison degrades and the cell dies.
"It wasn't an armed robbery, it was just unsophisticated criminal behavior that happened to involve a gun."
Doesn't seem like he was a very good scam artist... That's not a lot of money to risk jail over.
That's an oddly specific loss amount, especially the 50c
* Contractor's time multiplied by their hourly rate
* Whoever was overseeing the contractor for some percentage of their time
multiplied by their fully loaded hourly rate
* Processing and payment of contractor's invoices
* Discounts or coupons given out as a result of late orders due to this problem
* Anything in any contract relating to late orders that was caused by this problem, even in part
You start multiplying fully loaded employee costs (including 401(k) matches, healthcare, etc) by fractions of a percentage for how often they deal with this person and it's not at all hard to end up with fractions of a penny at the end of it all.Maybe he was only used for some older niche stuff that was going out of style and he was trying to cling to the past.