There was that guy that outsourced his own job to a developer in China so he could surf Reddit and HN all day at work. If I recall he even FedEx'ed his two-factor auth to the guy in China so he could VPN in and complete his work.
I remember that guy getting caught from some OPSEC weaknesses though. He would have been better off if the Chinese replacement was logging in though a machine at the guy's house, so the IP address didn't give it away. You could also use a webcam to share the RSA token, without having to physically send it, and lose control of it.
Comments
There was that guy that outsourced his own job to a developer in China so he could surf Reddit and HN all day at work. If I recall he even FedEx'ed his two-factor auth to the guy in China so he could VPN in and complete his work.
I remember that guy getting caught from some OPSEC weaknesses though. He would have been better off if the Chinese replacement was logging in though a machine at the guy's house, so the IP address didn't give it away. You could also use a webcam to share the RSA token, without having to physically send it, and lose control of it.