It doesn’t sound like this is what happened though.
During his unauthorized access, Ramesh admitted that he deployed a code from his Google Cloud Project account that resulted in the deletion of 456 virtual machines for Cisco’s WebEx Teams application
It sounds like this may have been more accidental than malicious.
Pure speculation, but I wonder if he had gcp service account credentials sitting around his laptop which applied terraform to the wrong project. terraform apply -auto-approve can wipe out a lot of infrastructure in a few seconds.
Most crimes require mens rea for conviction. That is, the prosecution has to prove beyond a reasonable doubt that you intended to do it. If it's really the case that he accidentally ran terraform with the wrong project/credentials, I doubt he'd accept the plea agreement.
Sudhish Kasaba Ramesh, who worked at Cisco from July 2016 to April 2018, admitted in a plea agreement with prosecutors that he had deliberately connected to Cisco's AWS-hosted systems without authorization in September 2018
Yep. It may just be a fact that he ran terraform and it said to delete all VM instances, only he forgot he had his old credentials in the environment variables, and who would have ever expected them to work.
That said, the lack of details on this do leave a lot to be imagined - it’s just as easy to read this as revenge, and that large companies don’t bother to publicly shame people most of the time.
Comments
It doesn’t sound like this is what happened though.
It sounds like this may have been more accidental than malicious.
Pure speculation, but I wonder if he had gcp service account credentials sitting around his laptop which applied terraform to the wrong project. terraform apply -auto-approve can wipe out a lot of infrastructure in a few seconds.
Most crimes require mens rea for conviction. That is, the prosecution has to prove beyond a reasonable doubt that you intended to do it. If it's really the case that he accidentally ran terraform with the wrong project/credentials, I doubt he'd accept the plea agreement.
HN has previously discussed the egregious power imbalance at play in plea agreements.
That would be amazing. And I could believe it.
Not properly setting up and configuring auth could result in long duration of auth tokens, which could be sitting around unknowingly.
Just a few lines above what you wrote:
How does that sound accidental to you?
It's a plea agreement. It's quite common in the US to admit to crimes you didn't do to secure a plea bargain.
Could just be very risk-averse plea-bargaining on Ramesh's part.
Yep. It may just be a fact that he ran terraform and it said to delete all VM instances, only he forgot he had his old credentials in the environment variables, and who would have ever expected them to work.
That said, the lack of details on this do leave a lot to be imagined - it’s just as easy to read this as revenge, and that large companies don’t bother to publicly shame people most of the time.