Accused Network Administrator Still In Jail

slfisher 0 Tallied Votes 363 Views Share

Remember Terry Childs? He was the network administrator for the city of San Francisco who -- claiming he was protecting the city government's computer system from incompetent coworkers -- changed the system's passwords and then for more than a week refused to give them to anyone, even after being arrested.

Childs eventually did give the passwords to San Francisco Mayor Gavin Newsom, and was charged with four felony counts, basically of variations on hacking.

Well, it's more than a year later, and Childs is still in jail, without yet having been convicted of anything.

In August, San Francisco Superior Court judge Kevin McCarthy dropped three of the four charges, related to his attaching three modems to the network. The charge associated with his refusing to reveal the passwords stayed.

However, later in the month, Judge Charles Haines to lower Childs' $5 million bail, calling him a flight risk (when arrested, he'd been found with a large amount of cash) and a security risk to the San Francisco network.

In comparison, , which provides bail guidelines for a variety of offenses, lists a $1 million bail for the most serious crimes, such as sexual assault of a child, aggravated arson, or kidnapping for ransom, according to the IDG News Service.

Meanwhile, in January, Childs filed a $3 million against the city, including $1 million in compensation for lost wages and benefits, $1 million for emotional stress, $500,000 in attorney fees, and $500,000 in unspecified "special damages."

If convicted, Childs faces up to five years in prison -- assuming, of course, they manage to go to trial and convict him by then.

Dani AI

Generated

This thread — and ’s link — is a useful reminder that operational risk isn’t only about outside attackers. Concentrating emergency credentials, emergency procedures, and change authority in one person creates a single point of failure that can quickly become a security, legal, and continuity problem. Fixing that requires both technical controls and simple, enforced governance.

Technically, reduce single‑person control by adopting privileged access management: vault all high‑impact credentials, require just‑in‑time (JIT) role activation with approval and MFA, give admins dedicated non‑browsing accounts, enable session recording and immutable audit logs, and make emergency “break‑glass” access time‑bound, alerting, and subject to immediate rotation after use. These are standard safeguards in modern control frameworks and vendor guidance. (cisecurity.org)
CIS Control 4 — Controlled Use of Administrative Privileges (CIS) · Microsoft Entra PIM (just‑in‑time admin) · NIST SP 800-53 Rev. 5 (access/control guidance)

Organizationally, require documented change‑management, a published “emergency access” playbook, and routine cross‑training so no one person holds all knowledge or keys. Preserve forensic evidence and follow an incident‑response playbook that documents who authorized access, why, and what actions were taken — escalate to legal/HR when appropriate and preserve chain‑of‑custody for logs and images. Industry incident‑handling guidance covers these practices. ()

Quick operational checklist (doable now)

  • Preserve logs and take forensically sound copies before changing anything.
  • Open a documented ticket and escalate to CISO/GC/HR — follow the playbook.
  • Use your PAM/break‑glass workflow (approval, MFA, time‑limit); record the session.
  • Rotate and resecure any emergency credentials immediately after use.
  • Run a post‑incident access review and remove single‑person dependencies.

Putting these basics in place prevents most “admin lockout” scenarios and gives organizations an auditable, defensible response that protects operations and people.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.