The Register Home Page

back to article Law firm insisted on one password to rule them all

PWNED Welcome back to PWNED, the weekly column where we gather lessons from organizations that didn’t take security seriously enough. This week’s tale of woe comes from a company that left a door wide open for miscreants, but was lucky it didn't have to pay the price. Have a story about someone leaving a gaping hole in their …

  1. Pascal Monett Silver badge
    Windows

    "In the end, the boss will have the final word"

    Yup. It's the golden rule : he who has the gold makes the rules, even when they are abysmally stupid.

    1. KittenHuffer Silver badge

      Re: "In the end, the boss will have the final word"

      Just make sure that you've documented their choice, your objections to their choice, and their override of your objections. And then make sure you have a copy of this documentation on hard copy and/or on a your own system.

      When they are stupid ... CYA!

      1. Phil O'Sophical Silver badge

        Re: "In the end, the boss will have the final word"

        Not necessarily enough. If what you're asked to do contravenes some legislation, Sarbanes–Oxley for example, no amount of ass-covering will help.

        1. Ignazio

          Re: "In the end, the boss will have the final word"

          It's pretty good when it comes to breaking laws - might not keep you out of jail but will ensure there's company from the company

        2. cmdrklarg

          Re: "In the end, the boss will have the final word"

          Unfortunately that is when you hand in your resignation. I will not commit a crime even if my bosses insist upon it. I would sooner be a whistleblower.

          1. ecofeco Silver badge

            Re: "In the end, the boss will have the final word"

            This.

            I've had leave two job because they wanted me to break laws. It sucked. It ruined me. I lost a lot.

            What I did not do was go to jail for making someone else rich.

            1. MachDiamond Silver badge

              Re: "In the end, the boss will have the final word"

              "I've had leave two job because they wanted me to break laws. It sucked. It ruined me. I lost a lot."

              I've had a similar experience but it was physical safety rather than something more "white collar". I'm glad to be gone from that company.

              When required to do something stupid, run. In this case as a sole IT department, the law firm should be concerned that the person leaving on short notice will be a big problem. If there is an employee contract that sets a minimum notice time for leaving, write in an exception that lets you leave immediately if required to do something illegal or potentially harmful or there are those issues elsewhere in the company that are not remedied when pointed out. If you find fire doors welded shut "for security reasons", run.

      2. Cliffwilliams44 Silver badge

        Re: "In the end, the boss will have the final word"

        Won't work. No matter what they tell you, if something goes wrong and they get infiltrated, they will blame you! The Boox is never going to blame themselves, not matter how much documentation you have.

    2. GlenP Silver badge

      Re: "In the end, the boss will have the final word"

      Not necessarily!

      I will require justification for system access for Directors and Execs and will refuse it, with a full explanation, if it's not justified. It rarely happens of course, ultimately the C-Suite could overrule me but that's not happened at the current company. I do have the advantage of being a grey beard who's close to retirement and has been with the company a long time, it's a lot harder for someone younger who's early in their career.

      1. Pascal Monett Silver badge

        Re: "In the end, the boss will have the final word"

        You're lucky you don't get fired.

        Because the C-Suits have a tendency to get rid of anything that gets in their way.

        1. Anonymous Coward Silver badge
          Meh

          Re: "In the end, the boss will have the final word"

          If you're experienced and the upper echelons are treating you like that, I'd recommend moving to a firm that actually respects your knowledge and experience. Remind them that they're only at the top because of people like you, but if they don't want you supporting them, you'd be prepared to see them fall.

          (my experience is UK based. USA "employment at will" laws probably make it a more tenuous scenario)

        2. Bebu sa Ware Silver badge
          Windows

          Re: "In the end, the boss will have the final word"

          > the C-Suits have a tendency to get rid of anything that gets in their way.

          From what I have seen the C-suite while unbelievably stupid, they invariably do have the low cunning of the proverbial shit·house rat. So their ratty whiskers normally detect an imminent fecal shampoo and usually cry off.

          Of course there are those that whose faculties don't rise even to the level of low cunning but then you are best advised to lead the rats abandoning the inevitably sinking ship.

        3. AtomicDog

          Re: "In the end, the boss will have the final word"

          If you're experienced enough, and they have any brain left at all, they would realise that pissing you off would likely trigger whistleblowing to ALL of the relevant authorities, which would likely result in severe financial loss to them, and possibly the end of their careers...

      2. ElCondor
        Happy

        Re: "In the end, the boss will have the final word"

        If you have a grey beard and lot of years in company, your word has some authority, even if you are not CEO but CIO or whichever equivalent role.

        IMNSHO idea here should not be to disable/disallow users to change data, but to log in DB table and in log file (if possible/needed) WHO does it.

        And that table should be INSERT and READ only, no UPDATE allowed.

        System where you can impersonate other users doing important things is bad, system where log of actions (in DB table or elsewhere) is not to be trusted, is faulty.

        Ideally, not everybody should be allowed to change all the data, but that is company policy. And grey beard means nothing if CEO says otherwise and will not listen.

        It is a nice world where you as expert in your field is listened, but it is not always so. Sometimes you are listened, but not paid enough, sometimes neither.

        In perfect world, company like Microsoft would vanish long ago, but this is not perfect world.

        Dummies use imperfect OS's because they are dummies, and some evidently clever enough people realized that perfect OS is nice thing to have, but dummies need dumb OS, not perfect one.

        Dummies are creatures of habit, they always resist change, even when change is for the better.

        And in this world there are a LOT of dummies. :)

        1. Anonymous Coward
          Anonymous Coward

          Re: "In the end, the boss will have the final word"

          Also,

          Don't let anyone know about this log, keep it and any daily journal files backed up in multiple locations and I'd seriously consider one regular copy to go into a personal off-site write-only location.

          You can never have enough evidence when dealing with lawyers.

          Finally, find another job then blow a whistle! the companies clients have a right to data security.

      3. MachDiamond Silver badge

        Re: "In the end, the boss will have the final word"

        "it's a lot harder for someone younger who's early in their career."

        It's a lesson that has to be learned and the sooner the better. Your career will be in even worse shape if you wind up being known for blowing up the VVLHC regardless of whether it was your fault or not vs. bailing on short notice.

    3. Philo T Farnsworth Silver badge

      Re: "In the end, the boss will have the final word"

      To paraphrase John Gilmore, "Getting work done interprets security as damage and works around it."

      I'm not an expert in the field, even though at one time or another in my career I've had to play one, but perhaps it might be useful to ask ourselves if a "one size fits all" authoritarian security model is the best of all possible worlds.

      While I clearly understand the necessity of keeping confidential information confidential, impeding workers from getting their work done seems to me as much of a risk to security as a simple shared admin password.

      If the workers need to resort of bad security as a part of their jobs, perhaps it's the design or implementation of the application that is at fault, not the workers.

      1. doublelayer Silver badge

        Re: "In the end, the boss will have the final word"

        A good design process takes that into account and figures out a way to make things possible and secure. In such a process, security takes precedence over process. That means if people routinely impersonate each other and we don't accept it, we make people change how they work rather than abandon security so they don't have to learn new buttons, but we find a way that they can accomplish what they needed impersonation for rather than just blocking it.

        Unfortunately, there are people who use the same argument you have whenever they want to ignore security because doing stuff properly is hard. It sometimes is hard, but it's your customers' data you're playing with, not yours. Sometimes, security is necessary even if it reduces speed, and there is a correct response to people who route around that: fire them and expose what they're doing to their customers.

        1. Philo T Farnsworth Silver badge

          Re: "In the end, the boss will have the final word"

          There's truth there, to a point and in certain circumstances.

          If you're designing a system for an enterprise with which hundreds or even thousands of employees need to interact or deals with ultrasensitive classified information like for the Colonel's 11 Secret Herbs and Spices or the formula for New Coke, sure, security is going to be paramount.

          If you're dealing with a law office that has two partners, five paralegals, and a couple of secretaries, you might consider not making security so onerous that nobody can get their work done without explicit blessing from the BOFH.

          Good security should be transparent or, at the very least, translucent, and not promulgate workarounds and hacks. If you create such a strict regime that no one can get their job done, I submit you have failed because those workarounds and hacks are going to proliferate, subverting the very goal which you're trying to accomplish.

          Contrary to the somewhat patronizing mindset that seems to prevail, people, for the most part, aren't stupid or lazy and actually want to accomplish the tasks for which they are hired.

          It's our job to help them.

          1. Ian Johnston Silver badge

            Re: "In the end, the boss will have the final word"

            Good security should be transparent or, at the very least, translucent, and not promulgate workarounds and hacks. If you create such a strict regime that no one can get their job done, I submit you have failed because those workarounds and hacks are going to proliferate, subverting the very goal which you're trying to accomplish.

            In much the same way that draconian password regimes inevitably result in passwords on post-it notes on monitors.

            1. Excused Boots Silver badge

              Re: "In the end, the boss will have the final word"

              "In much the same way that draconian password regimes inevitably result in passwords on post-it notes on monitors."

              Not sure why someone downvoted this, as it is absolutely true.

          2. doublelayer Silver badge

            Re: "In the end, the boss will have the final word"

            "Good security should be transparent or, at the very least, translucent,"

            I think I said that: "we find a way that they can accomplish what they needed impersonation for rather than just blocking it". However, a small law firm is no excuse for not doing it properly. The clients of those lawyers deserve security. If they store evidence in a system that's easily tampered with, that could invalidate that evidence in court, losing the clients their cases. Once again, it's the clients that are being harmed and the lawyers do not have the right to neglect that because they want ease or they're not that big really. If the clients' data is stolen, regulators can apply very harsh penalties and the lawyers can lose large negligence suits, and they would deserve both.

            1. Philo T Farnsworth Silver badge

              Re: "In the end, the boss will have the final word"

              Agreed. Mostly.

              I'm not saying not [do] it properly. I'm saying do it better.

              Let me make a very rough analogy.

              Perhaps you've had the experience of being in a supermarket check out line and the checker inadvertently makes an overring. In a lot of stores, especially the larger ones that have accreted layers of "policy," the checker has to call a supervisor to come, log in, and validate the reversal.

              It's bad enough when it's you getting checked out but if you're backed up five deep in shopping carts, it's downright annoying.

              To some extent I understand the reasoning -- there's a need to prevent theft -- but if you treat your end user, the customer, as if their time is valueless, the person who wants to pay you money, you've failed.

              We're clever people. Let's use that cleverness to make the work lives (and just plain lives) of people whom we ultimately serve easier not more difficult.

              Now I'll shut up.

          3. MazeFrame

            Re: "In the end, the boss will have the final word"

            No matter how much of a frictionless vaccuum you as the IT-guy wants to provide your users, they will complain.

            Information Security is a lot like fire protection, except everyone understands the need to prevent the roof being on fire.

            Regular folk working with a computer will with few exceptions strive for a frictionless vaccum, meaning they will work around any restrictions of organizational or technical kind if it saves them ten seconds or even saves them from having to click "that other program".

    4. DS999 Silver badge
      Holmes

      Normally

      You could tell the head guy "among other issues, having health information available to anyone without any audit trail sure sounds to me like a violation of HIPAA (or your country's equivalent)" but one can only imagine the reaction a statement like that providing amateur advice on the law would get from the LAWYER running the law firm.

      So all you can do is make sure you have a printed copy of the email you sent to follow up with the conversation saying something like "just to be clear you have instructed me to make everyone an Administrator, giving them access to all records and data and ability to send emails as others as needed, to replicate this desired behavior from the previous system". Being a lawyer, he may twig onto the fact you are covering your ass and depending on his attitude may chuckle or may fire you in a fit of rage, but either way your ass is covered.

      And if you were fired I imagine you could contact a lawyer from another firm, show them the email you sent, the background information as to why you felt it was necessary, and how that led directly to your firing, and be told you have a GREAT case. Because your former employer will almost certainly want to settle rather than going to court and testifying under oath and having it put on the record how shoddy their information security has been for 15 years and still is.

      In his shoes I'd honestly make that email as specific as possible HOPING to be fired because I think it would be a slam dunk to get a huge settlement (like year's salary or more) out of that.

  2. Zaphodikus

    Not just law firms, auditors and accountants too

    I suspect that a failure in the education system to predict the needs of future workforces in the 90's got us here. The number of computer users who do not know what or why 2fa is is shocking. It's arguably more valuable skill than algebra, is computer security. And yes your auditors may well be Prince2 and SOC compliant, but they still have all emails going into one multiple different inboxes and the passwords are all the same password for obvious reasons.

    1. Bebu sa Ware Silver badge
      Windows

      Re: Not just law firms, auditors and accountants too

      > … users who do not know what or why 2fa is is shocking.

      That sentence sort of got away from itself. :) Or 2fa is shocking.

      I don't really imagine too many computer users are the full bottle on algebra (linear or otherwise.) I suspect most of Academia couldn't solve a quadratic equation unaided.

      The polloi are conventionally said to lack the arithmetic to be able to balance their cheque books but fortunately for them cheques have largely disappeared.

      1. Elongated Muskrat Silver badge

        Re: Not just law firms, auditors and accountants too

        I never understood the concept of balancing one's cheque-book. You write a cheque, including the amount on the stub, and some indeterminate time later it appears on your bank statement. What's to balance? Most people aren't keeping a ledger with double-entry bookkeeping for their personal finances.

        1. MarkTriumphant

          Re: Not just law firms, auditors and accountants too

          When I used cheques, I would have the balance of my account written in the chequebook, and keep it updated. It meant I always knew how much I had available. There are much easier ways now, but back then it was the simplest way.

          1. Elongated Muskrat Silver badge

            Re: Not just law firms, auditors and accountants too

            That assumes the cheques have their own account. I've never had a chequebook that paid out of anything other than my current account, and there's no way I'd be keeping a ledger of all of its transactions in my cheque book.

            I guess these things work differently in the US, where cheques are probably still a thing. I think the last time I had to write one for something was well over a decade ago, and that was for an organisation whose options were to pay them with a cheque or postal order, or phone them up and give them your bank details over the phone to take a payment, which is even less secure than writing a cheque.

            1. doublelayer Silver badge

              Re: Not just law firms, auditors and accountants too

              I think people were keeping a log of all transactions, regardless of how they were withdrawn from the account, to be aware of their balance and liabilities, then checking it against statements to confirm whether any unexpected charges had gone in. That's still a good idea today except that you don't have to wait for a statement or go to the bank to see the history, so you don't have to be as meticulous. Both then and now, paying more than you have in the account comes with unpleasant consequences, and there are only a few ways to avoid the risk of that.

              It doesn't really matter how you make the payments. Cheques aren't as heavily used as they once were, but people who use a debit card have the same experience. Payment cards are not that old in the scheme of things, though, and before them, you had far fewer options for large payments or ones you weren't making in person.

        2. cmdrklarg

          Re: Not just law firms, auditors and accountants too

          It's for finding any discrepancies between your records and the bank's, which can be due to error or malfeasance. Gotta keep 'em honest.

          A while back I found an entry referring to an online pr0n site, which I had not subscribed to (why would I when I can find that stuff for free). Called the bank's fraud department and got that sorted. The wife at the time was not amused but was OK once I explained that much to her.

        3. Anonymous Coward
          Anonymous Coward

          Re: I never understood the concept of balancing one's cheque-book.

          The thing is that cheques can hang around for months before they get paid in. So the debit might appear at an unexpected time; perhaps sometime after you had written it, and maybe after you had forgotten about it. And with bank statements (historically) only appearing by post once a month or whatever, if you didn't (or couldn't) keep a large enough float in the account, you might easily get caught out when a cheque gets unexpectedly banked.

    2. DS999 Silver badge

      There are much bigger issues with education than teaching people 2FA

      People graduate high school without knowing anything about the real world - how to handle stuff like banking, taxes, insurance, leases, loans, credit records and so forth. I suppose nowadays you have the internet available as a resource if you care to learn (but that requires knowing WHY you need to learn) but those of us who came of age pre internet really had to depend on family, or I suppose close friends/mentors. I learned about that stuff from my dad - not explicitly taught but just hearing him talk about it and probably asking a few questions here and there when something happened like a hail storm meaning we got a new roof or whatever.

      Schools need to have a sort of "real world 101" course that's mandatory for graduation that teaches you the basics of living independently without putting yourself in financial peril. Keeping your important information secure from fraudsters would be part of it, and that's where they could teach 2FA. This is probably one of the big reasons that people from poor backgrounds make bad financial decisions and become poor themselves. If you aren't exposed to this stuff done right as a kid, and you aren't taught it, how are you going to know if you are making a bad decision on that payday loan or what happens when you fail to file a tax return or if you get lucky on your sports bets and make a bundle how to keep fraudsters from stealing your winnings (before you can squander them taking your friends to Vegas because you never learned the importance of a rainy day fund)

  3. Anonymous Coward
    Anonymous Coward

    Retailer no longer trading

    Their servers had no Administrator password i was staggered. I used to get the remote techys to down the servers to facilitate hardware repairs such as DLT Drive swaps. So Rang them and they said i can do it, ok user name Administrator no Password

  4. Doctor Syntax Silver badge

    In this case it's a law firm. That might present a different approach - a sufficiently frightened partner. Get one of the partners to review whether the arrangement is compatible with various bits of legislation.

  5. Doctor Syntax Silver badge

    I notice in TFA that the correspondence address for new articles is @sitpub.com. Was this doamin set up by the BOFH?

    1. RT Harrison

      Situation Publishing (a media firm) is the parent company of The Register amongst other publications.

      It's at the bottom of all webpages.

      1. Excused Boots Silver badge

        Yes but maybe the domain name was originally setup by a BOFH.

  6. Elongated Muskrat Silver badge

    Our story comes courtesy of a reader we’ll Regomize as Manny.

    Is this because of the heat, and Dave's syndrome?

  7. Kimo

    Law Firm Logic

    It's a Plausible Deniability Password. If everyone can use it to log in, you can't connect any specific action to a specific person. It unlocks the Blame the Intern defense in court.

    1. Ken Hagan Gold badge

      Re: Law Firm Logic

      Not if I'm on the jury, it doesn't!

    2. MachDiamond Silver badge

      Re: Law Firm Logic

      "It unlocks the Blame the Intern defense in court."

      .... or the sole IT person in this case. "We didn't tell them to do that".

  8. BPontius

    Hope he resigned and the firm got hacked and went insolvent soon afterwards!!!

  9. trevorde Silver badge

    Early security

    Worked on a project which used Oracle as its data store. Oracle has very fine grained and sophisticated table level security. During development, everyone had admin access. When they started to enforce security, *everything* broke, such that everyone was restored to admins. The lesson was to enforce security from the start, which I promptly took to my next job.

    1. Excused Boots Silver badge

      Re: Early security

      Yes exactly, security needs ti be factored in right from the very start, trying to show-horn it in afterwards always causes problems.

  10. Terry 6 Silver badge

    Data = money

    Even in 2026 this seems to be a fact that too many managements haven't really understood. Even if they say it themselves,they don't really think it; deep down in their guts the stuff on the computers is just the admin, not something of value.

    I have literally come across managers ( of small organisations) that are more worried about the security of the stationery* cupboard ,and have it carefully locked and guarded (by a fierce admin), than of the data on their computers.Because envelopes have a visible price tag.

    * (if I got the spelling wrong, sorry )

    1. Excused Boots Silver badge

      Re: Data = money

      No that's right, stationery v stationary - I always think 'e' for envelope, something you might well find in a stationEry cupboard.

  11. MachDiamond Silver badge

    Shoulda known

    Confidentiality is very important in a legal practice and can sometimes be more important that health records. I would expect that many jurors would be happy to see a load of blood sucking lawyers burn white hot in a data breach case. It's not a good thing to present a case to a jury who really want to find you guilty as hell rather than act as an impartial panel.

  12. Northern Lad

    Management Are Stupid (Usually)

    If I've learnt one thing after being in IT 30 years is that management are usually mostly stupid people gifted with a golden mouth.

    I recently worked for a company which when dealing with customers would say 'if its not written down its not happened' and I fully agreed with that, but would then tell you to do something and not follow it up with an email, then say they never said anything to you if it went pear shaped. I've even seen when you do get an email (or teams chat) telling you to do something that goes wrong then totally refuse to admit it was their decision/order/command even when presented with the evidence.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon