Film-Tech Cinema Systems
Film-Tech Forum ARCHIVE


  
my profile | my password | search | faq & rules | forum home
  next oldest topic   next newest topic
» Film-Tech Forum ARCHIVE   » Operations   » Digital Cinema Forum   » How much access should the end user have??? (Page 2)

 
This topic comprises 3 pages: 1  2  3 
 
Author Topic: How much access should the end user have???
Tony Bandiera Jr
Film God

Posts: 3067
From: Moreland Idaho
Registered: Apr 2004


 - posted 12-29-2018 11:21 AM      Profile for Tony Bandiera Jr   Email Tony Bandiera Jr   Send New Private Message       Edit/Delete Post 
When I ended a situation similar to this, I took the middle ground. (Pretty much same reason, cost cutting.)

I OFFERED limited operator training with first hour of my fee waived, (which never happened) and referred them to a service company. That was it. Only the service company got access passwords and other tech information.

I would say it all depends on the circumstances. In Dan's case, I would do the absolute minimum possible.

Basically, surrender projectionist ONLY passwords and very basic instruction, leave all the tech passwords (even if changed from default) as confidential. If the situation arises where they are needed, release them ONLY to a service company he has a good working relationship with, or release them only if charging a fee for himself, AND with a signed agreement that he is not responsible in any way for any problems or damage they cause by using them.

quote: Dave Macaulay
"As far as passwords go, we changed ALL default passwords on all equipment here" There is ample case law to establish that you will be held liable for the costs of repairing this sabotage, lost income caused by it, and also subject to punitive damages. Bad idea.
Really? Maybe in Canada, but it would be very hard to PROVE that the changing of default passwords (which is an industry standard practice) qualifies as sabotage. The ONLY way it could be proven as malicious is IF AND ONLY IF it could be proven that the passwords were changed just prior to someone's departure. Otherwise any competent judge would dismiss the case or refuse to hear it solely on the basis of a changed password. And most manufacturers' equipment has a back door password to defeat that anyway.

If they want detailed training, charge them for it. My minimum would be $65 per hour with a four hour minimum.

Dan plans on offering a Service Agreement..if they decline to accept, I would definitely walk away without disclosing ANYTHING.

One concept sadly lost is loyalty....too many organizations and companies demand loyalty out of their employees/contractors, but when it is time to return that loyalty, the company attitude becomes one of "screw you, we don't owe you anything". In that case, let them suffer. Which in Dan's case, seems to have happened based on the new director's actions.

 |  IP: Logged

Jack Ondracek
Film God

Posts: 2348
From: Port Orchard, WA, USA
Registered: Oct 2002


 - posted 12-29-2018 11:56 AM      Profile for Jack Ondracek   Author's Homepage   Email Jack Ondracek   Send New Private Message       Edit/Delete Post 
Changing default passwords isn't exactly 'sabotage', but it does put you in the pipeline. Did you make that change on your customer's dime? Did the customer ask you to do it? Apparently, you did so for your convenience so as not to be bothered by nuisance calls. IMO, you should put the defaults back in or give them the new access codes.

Beyond that, I tend to agree with the notion of exiting as gracefully as possible. You can opt to pass along basics... ingesting and the like. Also, let them know where in the manual they can also find that info. As for passing along knowledge, based on the skills you've accumulated by experience; that is a benefit to them that should be paid for. Offer them a reasonable rate (not @2,500/day), and even give them a short list of others they can call if they don't initially care for your rates. That way, you've given them a choice and not painted them into a corner that only you can get them out of... it looks better that way.

Last year, I had to file a collections suit against my largest radio client. It was a 6-figure problem which, I was sure, would permanently blow up our relationship. In the midst of negotiations between the attorneys, they noted they could go elsewhere for services. I agreed and gave them a list of 5 other engineers they could call. In the end, we made a deal on payments, they kept it and, surprisingly, asked me to resume services, once the balance was paid. I did so, albeit with new conditions, and we've gotten along well since.

Your customer may not come back to you, but they can do damage, if they acquire a perception you played dirty tricks on them. Others can not be saved, and you need to be able to walk away from those clients with a clear conscience. Some day, they may be back.

 |  IP: Logged

Stephan Shelley
Jedi Master Film Handler

Posts: 854
From: castro valley, CA, usa
Registered: Nov 2014


 - posted 12-29-2018 12:54 PM      Profile for Stephan Shelley   Email Stephan Shelley   Send New Private Message       Edit/Delete Post 
On the changing default passwords, as an independent service tech I have gone to theatres where this has happened and no one there knows what the passwords are. Hard to do ones job when that happens. And what happens when the say one person that knows them moves on and no longer works there. It can lead to a bad situation.

 |  IP: Logged

Steve Guttag
We forgot the crackers Gromit!!!

Posts: 12814
From: Annapolis, MD
Registered: Dec 1999


 - posted 12-29-2018 01:26 PM      Profile for Steve Guttag   Email Steve Guttag   Send New Private Message       Edit/Delete Post 
Every once in a while, we don't have a good "fit" with a customer and our support services. Honestly, people should use support agencies that they feel provide the service they want. It doesn't hurt my feelings any.

There are aspects of our services that we consider proprietary. They include the manner in which we access the site (beyond the customer providing the internet access) and often passwords (we no longer "sell" our Cardinal Care box either. This precludes any "IT ownership" and at the conclusion of our relationship, it stays with us).

If a customer decides to go a "different direction," we revert passwords that were changed to their factory defaults so the customer or any new entity can pick up right where we left off. Rarely do we change passwords on things like DCP servers or projectors. As Stephen points out, there can often be events were a technician, besides us, has legitimate need to make changes. Furthermore, anytime WE make a change, it is backed up so we can always get a projector, server...or whatever back to the last time we made a change.

Since part of what we provide is how the equipment functions with each other, all they have to do is request the feature/format so they really don't have to play with things so much. That said, all customers are different and we vary our/customer interaction on a customer-by-customer basis. However, if we had a customer where they wanted to do everything, why are they paying us? So again, it wouldn't be a good fit for what we provide versus what they want.

As for training, we never train people how to service the equipment beyond user maintenance (filter cleaning/changing and such) nor am I going to tell a customer how to reconfigure a sound processor (and how often should that need to be fiddled with). This will get to be even more so with drag and drop DSP based sound processors like QSYS.

Sabotaging equipment (locking the equipment with non-standard passwords) is stupid that will, at best, get you a bad reputation. On your departure, restore that stuff back to defaults and move on with life. Who knows, maybe once they try the others, they'll realize what they lost and want you back. A scorched-earth policy will not result in that outcome and likely get one a bad reputation.

 |  IP: Logged

Leo Enticknap
Film God

Posts: 7474
From: Loma Linda, CA
Registered: Jul 2000


 - posted 12-29-2018 02:50 PM      Profile for Leo Enticknap   Author's Homepage   Email Leo Enticknap   Send New Private Message       Edit/Delete Post 
Agreed with Steve that the handing off being offered should be restricted to offering training to the end user in the operations that the equipment manufacturer recommends can be done by the end user.

For example, I recently installed a DP4K-32B, and will be going back to train the customer's staff just after the new year. I intend to walk them through maintenance schedules A and B in as much detail as they need (e.g. show them where the air filters are, and how to pull them out and clean them per Barco's instructions). I will also tell them that C and D exist, and if they ask, will give them a rough description of what they involve, but with the health warning that they are only supposed to be done by a Barco schooled tech, and that they could have warranty problems if they try to do this maintenance themselves.

I've had to deal with short-sighted venue managers such as the one Dan encountered before. Often, one lost show or serious maintenance problem that is beyond the ability of the venue's staff to fix will be enough to persuade them to renew the service contract. So try to part company on good terms, stressing that you'd be happy to offer one-time service calls to address any problems they may have in the future, but, if pressed, telling them that high level training for service tech operations is not a service that you offer, and here's a link to the schedule of Barco classes in Rancho Cordova if he's serious about taking that work in-house.

The best case scenario for you is that he'll quickly realize that ending the service contract is a false economy, and renew it. The worst is that he'll follow through and go do the class (and then spend a week in bed with the stomach bug that anyone who goes to Rancho Cordova is guaranteed to come away with!), but you will have parted on good terms, and he may still recommend you to other potential customers.

 |  IP: Logged

Carsten Kurz
Film God

Posts: 4340
From: Cologne, NRW, Germany
Registered: Aug 2009


 - posted 12-29-2018 02:59 PM      Profile for Carsten Kurz   Email Carsten Kurz   Send New Private Message       Edit/Delete Post 
There are many (if not most) cinema operations based on just the basic knowledge on ingest/playlist building, deleting content, etc. Many operations do not even change bulbs on their own. Give them all the changed passwords, train them for daily operations, and then wait what happens.

- Carsten

 |  IP: Logged

Marcel Birgelen
Film God

Posts: 3357
From: Maastricht, Limburg, Netherlands
Registered: Feb 2012


 - posted 12-29-2018 03:31 PM      Profile for Marcel Birgelen   Email Marcel Birgelen   Send New Private Message       Edit/Delete Post 
What your responsibilities are, is primarily dependent on the type of contract you have.

If you're working there as an employee and while they're paying you the salary agreed upon, they can demand pretty far reaching stuff like you training any new incoming replacement. There have been cases were employers coupled bonuses to "successful" transitions, which is obviously a pretty perverse incentive to get what they want.

If you work as an external service tech, then the contract between the service company and the customer is leading. You usually don't stipulate in such a contract that in case of a termination of that contract, the service company needs to train new incoming replacements.

In any case, it's never a good idea to entirely burn your bridges. Obviously, you should draw lines, where lines are due. They cannot demand much more from you than the basics. If the incoming replacement isn't up to the job, then it's best to make that abundantly clear.

Many of us can tell you anecdotal stories were a contract got terminated and replaced by one from a competitor, only to receive a call from them a few weeks down the road, after it all crashed and burned with the supposedly superior (usually just cheaper) replacements.

As Dave already pointed out, regarding passwords: You're pretty much required to provide those to your employer once the contract has been terminated. There is case law in many jurisdictions were the IT guy thought he could take his former employer hostage and drew the shorter straw. In the end it's his equipment and you cannot simply take it hostage.

And like Steve pointed out, this kind of behavior will at best give you a bad reputation.

 |  IP: Logged

Justin Hamaker
Film God

Posts: 2253
From: Lakeport, CA USA
Registered: Jan 2004


 - posted 12-29-2018 04:42 PM      Profile for Justin Hamaker   Author's Homepage   Email Justin Hamaker   Send New Private Message       Edit/Delete Post 
quote: Richard May
I, personally, would not train ANYONE that would be coming in to take my job. I doubt any contract would say that you have to. If they want to bring someone new in, they should train them themselves.
If this is part of the normal job during the contract, then you have an obligation to continue doing so until the day the contract expires. I also think there is an ethical obligation to ensure you have done as much to pass off the operation to the next person, especially any non-standard changes or procedures which have been implemented.

 |  IP: Logged

Dan Williams
Film Handler

Posts: 11
From: Southampton, NY United States
Registered: Feb 2018


 - posted 12-29-2018 07:26 PM      Profile for Dan Williams   Email Dan Williams   Send New Private Message       Edit/Delete Post 
You guys are the best... This was all great advice. What I’ve decided to do as of now at least:

1. Default all passwords and provide them user/projectionist passwords with a signed release for basic operation. I will not release service passwords.

2. Provide them a service contract for 2019 with fees stipulated for required maintenance, service calls, emergency service, as well as a fee to go through the basic system layout and “hand-off”... Because I was the integrator we originally waived all fees for staff training because we were the sole operators.

3. Give them a list of alternates... Allbeit more expensive options.

At this point I’m just disappointed they would make such a short sighted decision with a true belief that they’d yield a savings. Because I’ve been involved since their inception I’ve continued giving them a slamming deal. I have a feeling in the end the net result will simply be getting my rates current.

 |  IP: Logged

Scott Norwood
Film God

Posts: 8146
From: Boston, MA. USA (1774.21 miles northeast of Dallas)
Registered: Jun 99


 - posted 12-29-2018 07:36 PM      Profile for Scott Norwood   Author's Homepage   Email Scott Norwood   Send New Private Message       Edit/Delete Post 
Agreed with the other comments about not holding the customer hostage. He owns the equipment and should have all of the standard user login and password information. "Service" logins and passwords should be set (or returned) to their defaults so that the next technician can work on the equipment.

My full-time job is in the IT industry; default passwords are (almost) never acceptable there, but D-cinema is a special case, where physical and network access are tightly controlled. In the IT industry, it would be common to have root-level account information written down and stored in a safe somewhere with important company papers.

The above assumes that the customer has kept up his side of the contract. I could see refusing to hand over login information until all bills are paid.

Unless it is part of an existing service contract, I would think that training would be an extra service that could be provided on a time-and-materials basis. An experienced technician wouldn't need it, but an inexperienced one might.

An interesting customer-held-hostage situation arises if source code is involved. I saw this happen with a Crestron automation system once--the customer hired a company to install and program the system. A year or two later, the installation/programming company went out of business and effectively disappeared. At that point, any changes to the automation would require a completely new program to be written (the Crestron box in question only stored the "compiled" program--not the editable code). I don't know how to solve this, but it seems to be that the original programming company should have made some provision for providing the customer with the source code or at least providing it to another programmer who could make changes in the future without re-writing everything.

Agreed with the don't-burn-bridges argument that many have made. Cinema exhibition is a small industry, and word travels. I could see withholding service until bills are paid, but sabotage just hurts everyone.

 |  IP: Logged

Steve Guttag
We forgot the crackers Gromit!!!

Posts: 12814
From: Annapolis, MD
Registered: Dec 1999


 - posted 12-29-2018 07:40 PM      Profile for Steve Guttag   Email Steve Guttag   Send New Private Message       Edit/Delete Post 
I would suggest to not take it personal. If you provided value, they'll see it soon enough. If they really just want to go another way, that is their prerogative. Sometimes it is just a matter of being penny wise and dollar foolish but they can't see that, at this point.

As for passwords, I've signed enough NDAs to legally tell people, I'm not permitted, legally, to give out non-published passwords. "You should seek those out from the various manufacturers." Again, putting things back to the default password for that device removes any obligation by you to reveal any other company's secrets.

I repeat, try not to take it personal.

 |  IP: Logged

Leo Enticknap
Film God

Posts: 7474
From: Loma Linda, CA
Registered: Jul 2000


 - posted 12-30-2018 03:01 PM      Profile for Leo Enticknap   Author's Homepage   Email Leo Enticknap   Send New Private Message       Edit/Delete Post 
Also on the subject of passwords, changing them from factory defaults can be risky even if you do hand over the information in an orderly fashion when you leave.

I once had a call from the owner of a Series 2 NEC. The former chief projectionist had changed the factory default passwords on everything in the booth, because of another staff member who was inclined to tinker. When he left, he provided his boss with a list of all the passwords. The boss subsequently lost it. Fast forward several months, and they're trying to clear a tamper alarm. The guy who left did not keep a copy of the list: when asked, he explained that he didn't want anything left on his personal devices that could compromise security at a former workplace.

Most of the devices could be reset either by a clean reinstall of the software (e.g. the DSS200), or by poking a pin into the reset button, but the projector stores the codes on an internal board (the CPU/backplane, I suspect). So for that one, they were buggered. I explained that they would need to contact NEC, and that it might be an expensive repair. I didn't hear from them again, so am not sure how they eventually resolved it.

For this reason, if I was an employee of a theater, had changed access codes from their factory defaults and was leaving, I'd give my boss the option of resetting them to factory defaults, or having a list of the changed info, but would warn him or her in writing that I would not be responsible for the consequences if (s)he chose to take the list, and later lost the information.

 |  IP: Logged

Rick Raskin
Phenomenal Film Handler

Posts: 1100
From: Manassas Virginia
Registered: Jan 2003


 - posted 12-30-2018 04:33 PM      Profile for Rick Raskin   Email Rick Raskin   Send New Private Message       Edit/Delete Post 
I agree with Steve, especially about not taking it personally. Reset user passwords to their published defaults and walk away. You have no further obligation.

 |  IP: Logged

Steve Guttag
We forgot the crackers Gromit!!!

Posts: 12814
From: Annapolis, MD
Registered: Dec 1999


 - posted 12-30-2018 05:15 PM      Profile for Steve Guttag   Email Steve Guttag   Send New Private Message       Edit/Delete Post 
I'm of the opinion, on projection/sound equipment IN CINEMA, that the passwords should not be changable for the service level. The restriction should be on the service person having physical access and that is it. Barco has sort of taken this approach to their projectors (and consequently, their servers).

At the very least, there should be a means to reset them to factory defaults by the right entities (even if that is the manufacturer because, again, they would only have access if the company gave it to them).

On projectors like Christie, we create our own user/password so the logs show if it was us or some other person at a service level logged in but again, I don't lock out legitimate service entities.

 |  IP: Logged

Leo Enticknap
Film God

Posts: 7474
From: Loma Linda, CA
Registered: Jul 2000


 - posted 12-31-2018 01:08 AM      Profile for Leo Enticknap   Author's Homepage   Email Leo Enticknap   Send New Private Message       Edit/Delete Post 
I'm not sure that I agree that service level passwords should not be changeable from factory defaults. The truth of the matter is that many of these factory default credentials are widely known within the biz, including among end users who have not had any training in service or maintenance, and could easily cause damage and/or change settings that stop the equipment from working. It's not ideal that these people know these passwords, but they do. In such a situation, their bosses need the ability to lock them out of service functions. I've no problem with manufacturers building in a backdoor that can only be used in the event of sabotage, a genuinely lost password, etc., but there are legitimate reasons why equipment owners might need the ability to prevent their staff from being able to change settings when working with the equipment unsupervised.

 |  IP: Logged



All times are Central (GMT -6:00)
This topic comprises 3 pages: 1  2  3 
 
   Close Topic    Move Topic    Delete Topic    next oldest topic   next newest topic
 - Printer-friendly view of this topic
Hop To:



Powered by Infopop Corporation
UBB.classicTM 6.3.1.2

The Film-Tech Forums are designed for various members related to the cinema industry to express their opinions, viewpoints and testimonials on various products, services and events based upon speculation, personal knowledge and factual information through use, therefore all views represented here allow no liability upon the publishers of this web site and the owners of said views assume no liability for any ill will resulting from these postings. The posts made here are for educational as well as entertainment purposes and as such anyone viewing this portion of the website must accept these views as statements of the author of that opinion and agrees to release the authors from any and all liability.

© 1999-2020 Film-Tech Cinema Systems, LLC. All rights reserved.