Culture, Odds And Ends

Outsource Yourself For Fun And Profit

What began as an attempt to improve security by reviewing VPN connection logs yielded quite unexpected results last year for a U.S.-based firm. Verizon’s Business Security Blog tells the story of an unnamed “critical infrastructure company” surprised to find a live VPN connection into its network originating from Shenyang, China.

Like many businesses, this company was slowly increasing its employees’ ability to work from home. The company installed a VPN concentrator to make this possible, securing the logins with two-factor authentication using a rotating token RSA keyfob as the second factor. The fact that an unauthorized connection was successfully established from a foreign country was alarming enough. Even more so when the connection requires physical possession of the security keyfob issued to an employee — an employee supposed to be working from the PC on his office desk.

The employee in question worked for the company for a fairly long time as a software developer fluent in most of the popular programming languages (C++, Perl, Python, Ruby, Java, etc.). As a middle-aged family man, he was described as quiet and not one to stand our or make a scene. The IT staff who spotted the odd VPN intrusion was certain some type of malware had infected his PC. Perhaps this malware was intercepting his network traffic, rerouting it via an external proxy server to a host in China which in turn routed traffic back to the VPN concentrator? Nope. In fact, the truth turns out to be much simpler and devious than that.

Investigators examined an image of the employee’s hard drive. No malware was found, but they did find hundreds of PDF invoices from a Chinese developer. This employee had successfully outsourced his own job to the Chinese. After mailing his RSA token to the developers, this one-man outsourcer paid them to connect to the corporate network throughout his eight-hour workday, doing his software coding for him. While receiving a six-figure salary for his work, this creative and conniving individual only paid a fraction of his paychecks back to the developer. Apparently, this employee even managed to get hired on at several other firms in the area, running the same scam with them too.

A closer look at his web browsing history revealed that beyond emailing his boss a daily work progress update in the morning and again in the late afternoon, he spent the rest of his time reading Reddit, shopping on eBay, and using Facebook. Which, admittedly, is pretty much what the majority of other Americans do too, but they also have to do their jobs too.

According to performance reviews, this outsourcer’s code was always submitted on time and it was clean and efficient. For several years in a row, this employee was noted as the best developer in the building. It sounds like he was a top-notch project manager, even if only a fraudulent developer.




Tags: , , , , , , , ,


Tom Wyrick

About Tom Wyrick

Tom Wyrick is a computer support analyst in Bethesda, Maryland and part of a family of five who all share an interest in computers, the internet and gaming. Mac or PC? Yes, please.

  • http://www.facebook.com/generalram Norman G. King

    Many companies do this, that is true. But they get mad when an employee outsourced their work to a foreign nation. This is the “Tom Swayer” method of getting others to do the work for you, like whitewashing a fence. Something we all know about in Missouri. http://www.pbs.org/marktwain/learnmore/writings_tom.html

    Makes me want to start up another small business, get into software development again and offshore all the work to India and China, and then debug the code to make sure it is quality and then sell it. Why do this at a job, you are thinking small, go into business for yourself and then outsource/offshore the work and then sell it and market and promote it and make more than the average salary of a developer.