Sister CISA CISSP

Oct 9 2008   2:00PM GMT

Hardware? What Hardware?



Posted by: Arian Eigen Heald
Security, Hardware & InfoSec

I came across a recent post from the Breach Blog reporting that a U.S. Naval Laboratory employee - the computer administrator - had stolen 19,709 pieces of computer equipment, worth up to $1.6 million.

Did no one see this guy carting hardware out the door? I’m not talking about the small stuff, I’m talking about the more than 100 personal computers. Doesn’t a Naval laboratory have cameras on the exits, and guards? I know it’s easy to have hindsight vision, but this seems like it should have tripped somebody’s awareness alarm.

We can also extrapolate that there was no inventory control of hardware, AND no financial oversight of hardware costs. This happened over the course of ten years, so maybe he was able to slide it in under the radar.

What about the information ON the hardware? The Navy says only 14 people were affected. Given the evidence of their controls so far, I’m not sure I have a high level of confidence. They had to go through hard drives, CDs, Zip drives and all those computers. I hope they did.

How was this discovered? He and his wife are divorcing, she filed a protection request, and told his bosses she wanted his “work stuff” out of the house. He had so much stuff, he was storing some of the equipment at a neighbor’s house.

Comment on this Post


You must be logged-in to post a comment. Log-in/Register

Suzmonster  |   Oct 9 2008   8:28PM GMT

I can’t believe he’s only facing 12-18 months in prison for this! That’s a slap on the wrist. I should have started carrying hardware home from employers ages ago. Think of the value on eBay! (Oh yeah, that’s why I didn’t do it. Too traceable.) Storing it at a neighbor’s? I’d never be allowed to accumulate that much stuff! His wife was far too lenient.