This is messed up. Messing with allergen info can kill people.
But using your credentials is not hacking. Disney should have revoke the access and it probably would have prevented it. But I suppose we can’t expect a billion dollar company to have good process and procedures.
“The complaint alleges he did this soon after being fired by Disney using passwords that he still had access to on several different systems.“
Using your credentials is not hacking, but once he was canned he no longer had authorization to access those systems. Legally, there is probably no distinction between gaining access by actual hacking vs. using credentials that are no longer authorized.
So yes, their IT processes are deficient, but that doesn’t let the guy off the hook or mitigate his punishment.
Yeah, the proper time to revoke credentials is before they even know they’re getting fired. At all the places I worked, the first sign that someone was getting fired would be that they’re suddenly unable to access anything.
IT systems need a way to pre-enter an account deactivation, and when HR sends a text to the system it makes it live, or something. I’ve been the IT guy who was told to disable an account, and the user found out before the news was broken so they asked me what was going on. No bueno.
This is messed up. Messing with allergen info can kill people.
But using your credentials is not hacking. Disney should have revoke the access and it probably would have prevented it. But I suppose we can’t expect a billion dollar company to have good process and procedures.
“The complaint alleges he did this soon after being fired by Disney using passwords that he still had access to on several different systems.“
Using your credentials is not hacking, but once he was canned he no longer had authorization to access those systems. Legally, there is probably no distinction between gaining access by actual hacking vs. using credentials that are no longer authorized.
So yes, their IT processes are deficient, but that doesn’t let the guy off the hook or mitigate his punishment.
Unauthorized access is what the US government calls it. https://www.law.cornell.edu/uscode/text/18/1030
Does the government define “hacking”? I’d imagine not that specific word.
Yeah, the proper time to revoke credentials is before they even know they’re getting fired. At all the places I worked, the first sign that someone was getting fired would be that they’re suddenly unable to access anything.
IT systems need a way to pre-enter an account deactivation, and when HR sends a text to the system it makes it live, or something. I’ve been the IT guy who was told to disable an account, and the user found out before the news was broken so they asked me what was going on. No bueno.
https://www.cnn.com/2024/02/26/business/new-york-doctor-dies-at-disney-world-restaurant-after-staff-confirmed-food-was-allergen-free-lawsuit-alleges/index.html