Skip to content

Comment on Engineer admits he wiped 456 Cisco WebEx VMs from AWS after leavingparent

Comments

I think they meant ‘don’t log in, discover you have access, then browse and take no further action’. You can try to log in, you just need to inform someone immediately if you have access when you shouldn’t. That’s my take anyway.

That's what to do when it happens accidentally. It would also make sense to do so immediately after you left. They already made sure that you left behind all relevant keys, documents, and your work computer. It would be natural and in both parties' interest to ensure that all other credentials have been revoked as well in time.

Successfully trying to log in can already be a crime depending on your jurisdiction in my opinion.

You're right - I guess in that case it would be wise to ask your previous employer to provide proof that you're no longer able to access anything, and no longer liable. Many wouldn't offer that, but I'm not sure how else you could navigate that.

I think the common sense approach would dictate that a persons motive would need to have been shown to be nefarious for criminal proceedings to have any chance. Ie. Intent. Without intent, I struggle to see any court move with this, but I'm no lawyer - just an engineer!

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.