** sigh **

What do you do when you detect hacker-ish activity on your system at work, the system you are unofficially responsible for maintaining, since you are the only person able to figure out how to log in to the server?

According to company protocol, you report such activity to the security people.

You must be sure to include the information that the unfamiliar user ID logged in for a minute, then three minutes, then one minute, then five minutes, then half an hour.

Remember to pass on the information that this is two days after a complete system crash.

The security people will assure you that everything is fine.

In fact, they will send you ten different e-mails assuring you that everything is fine, and they are on top of things.

Then you will receive a phone call revealing that the strange user ID behaving hacker-ey was some idiot doing system maintenence who forgot to notify anyone.

The security people will ask that you make sure that a strange user ID is a strange user ID in the future before you notify them.

How do you verify that?

By notifying the security people.

Whom you are not permitted to notify until you have verified, which you have to notify them to do.


