A story about a laptop

πŸ“… Which is functioning as a paperweight since 6/10/2020

πŸ„πŸ½ Issued for my personal use

🏑 Connected to my personal network

πŸš™ Powered by my electricity

Where I'm coming from

πŸ€“ Previously, I installed software division wide

🚌 Peers have admin access already

πŸ•΄ Told by ADS staff member I should have admin rights to machine.

πŸ§‘β€πŸ’Ό Informed manager that I could work around current missing admin rights easily. ADS staff also heard this.

Unauthorized

not having official permission or approval.

"unauthorized access to the computer system"

Access

the action or process of obtaining or retrieving information stored in a computer's memory.

"this prevents unauthorized access or inadvertent deletion of the file"

Policy

ELECTRONIC COMMUNICATIONS AND INTERNET USE Number 11.7

RULES FOR USE OF SYSTEMS OR INTERNET SERVICES #5:

"State employees must conform to reasonable professional standards for use of Internet services as detailed in this guideline. This includes a prohibition against any activity that impairs operation of any state computer resource

...

This also includes hacking, which means gaining or attempting to gain unauthorized access to any computers, computer networks, databases, data, or electronically stored information, unless acting within the proper scope of official duties."

My Actions Were..

βœ… Authorized - I was told I should have admin rights.

βœ… Proffesional - Leveraged my expertise to help solve a problem

βœ… An Official Duty - Tasked with setting up my laptop for work

My Actions Did Not...

❌ Impair the operation of any computer system

❌ Crack, break, hack, or misuse any state resourse

❌ Cause risk, harm or cost to the state

My Intent

πŸ’» Tasked with installing software on a newly issued laptop

πŸ•§ I am a Former partner/contractor for ADS

πŸ¦‰ Previously advised on software to use Division wide

πŸ‡ΊπŸ‡Έ I'm working here to have easy access tools/data to help the state

πŸ˜• I have never been issued a laptop without admin access

πŸ—£ I have been open about actions and intent from the start

What's my official duty?

Install Software I need to do my job, Visual Studio, Python, etc

Use a computer system which I exclusively have been issued for my own work purposes

My efforts only affected my machine & only the exact permission I needed

System was brand new and contains no private information other than my own.

I was hired because of my technical expertise with software systems.

Actions I performed

Copied a file(NTUSER.DAT to NTUSER.MAN)

.MAN stands for mandatory settings

"NTuser.man is the same thing as NTuser.dat, but it has been manually renamed to .man in order to change the profile"

Altered the file:

  • Using a supported Windows program for editing settings
  • Turned off only what was blocking me from installing software (UAC)

File is supported by Windows, meant for mandatory settings for a local machine.

Also ran a security Scan to test if laptop was secured properly

The Equivalent Story

A mover is asked to head to an address and move some furniture inside a house.

The key to get in is not where they were told it would be.

Owner was consulted and confirms they can go inside

Looking at the building, the front window is wide open and they can easily get in.

Suddenly the mover notices an alarm going off. Owner calls and asked what happened?

Wait for Security to come and explain what happened.

What?

What party has been damaged or penelized by my actions?

What is the cost benefit analysis of ADS's actions to date?

Why?

Why didn't ADS talk to me about intent?

Why didn't they ask if I should have these permissions?

Why has no information been sent to me with updates on this situation?

Why am I assumed guilty?

My only interaction with ADS about this:

I'm afraid I can't do that, David

Request 3rd Party Review

All of my actions used supported features of the operating system.

I request that a knowledgable 3rd party review the technical facts at hand and determine if my actions were a hack or attempt to break into an unauthorized system.

ADS's actions feel retalitory.

What message does it send to others who find a problem?πŸ“