Skip to content

Comment on Engineer admits he wiped 456 Cisco WebEx VMs from AWS after leaving

Comments

This paragraph is baffling:

According to a court document, Ramesh is in the US on an H-1B visa and has a green card application pending. "Although he and his employer recognize that his guilty plea in this case may have immigration consequences, up to and including deportation, his employer … is willing to work with him regarding the possibility of his remaining in the country and continuing to work for the company," the document [PDF] says.

Why would you re-hire someone who quit and wiped your servers?

It doesn’t sound like this is what happened though.

During his unauthorized access, Ramesh admitted that he deployed a code from his Google Cloud Project account that resulted in the deletion of 456 virtual machines for Cisco’s WebEx Teams application

It sounds like this may have been more accidental than malicious.

Pure speculation, but I wonder if he had gcp service account credentials sitting around his laptop which applied terraform to the wrong project. terraform apply -auto-approve can wipe out a lot of infrastructure in a few seconds.

Most crimes require mens rea for conviction. That is, the prosecution has to prove beyond a reasonable doubt that you intended to do it. If it's really the case that he accidentally ran terraform with the wrong project/credentials, I doubt he'd accept the plea agreement.

HN has previously discussed the egregious power imbalance at play in plea agreements.

That would be amazing. And I could believe it.

Not properly setting up and configuring auth could result in long duration of auth tokens, which could be sitting around unknowingly.

Just a few lines above what you wrote:

Sudhish Kasaba Ramesh, who worked at Cisco from July 2016 to April 2018, admitted in a plea agreement with prosecutors that he had deliberately connected to Cisco's AWS-hosted systems without authorization in September 2018

How does that sound accidental to you?

It's a plea agreement. It's quite common in the US to admit to crimes you didn't do to secure a plea bargain.

Could just be very risk-averse plea-bargaining on Ramesh's part.

Yep. It may just be a fact that he ran terraform and it said to delete all VM instances, only he forgot he had his old credentials in the environment variables, and who would have ever expected them to work.

That said, the lack of details on this do leave a lot to be imagined - it’s just as easy to read this as revenge, and that large companies don’t bother to publicly shame people most of the time.

I believe his current employer (Stitch Fix) is willing to keep him employed, not his ex-employer (Cisco).

I can’t recall the deal with h1bs, but green card applications require that you haven’t committed any acts of moral turpitude, which would easily include this.

All work visas have a no criminal charges rule, so if this is a criminal case I believe being found guilty puts him in the area of instant visa revocation

Criminal vs. civil, afaik the former is gov. vs. ____. Moral terpiude, deployed a project to GCP and it deleted VMs—not my idea of a moral failure. Generally I’d not fire people for honest mistakes no matter the cost. You have to pay it anyway, and now the person has hopefully learned and probably feels honored to work hard to be better.

It’s not a matter of firing - it’s the us gov terminating the visa, which honestly in this case seems reasonable

His current employer is actually stitchfix (not Cisco)

Because his skills are valued higher than his cost.

Well he’s good at saving money on VM’s

"Responsible for capex savings of over $1.4MM by implementing cloud computing cost savings tasks that reduced cloud computing resource usage by 20%"

one weird trick to save millions on your AWS bill.

cloud providers hate him

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.