This is topic How much access should the end user have??? in forum Digital Cinema Forum at Film-Tech Forum ARCHIVE.


To visit this topic, use this URL:
https://ft-forum.com/ft/cgi-bin/ubb/ultimatebb.cgi?ubb=get_topic;f=16;t=003533

Posted by Dan Williams (Member # 10367) on 12-28-2018, 09:23 PM:
 
Long story as short as possible... I have been involved in the day to day technical operation with an art house for the last 5 years. A year ago I handled the installation of a Barco 10s running a Doremi IMS. About 6 months ago said art house brought in a new Director who implemented a bunch of decisions to cut costs and as a part of those cuts I was just l told that our yearly contract would not be renewed in the new year. They have brought someone in who has almost no technical knowledge because well, “it’s just pressing a few buttons”... Cureently there’s basic access to run BluRay content via the SDI input via the default startup state and basic projector control via iPad and the cinemate app. Anytime we run DCP content it’s done by a qualified tech via web interface... So, the question is whether I leave it as simply the basic access and tell them that “any actual projectionist” will be able to handle the rest or do I actually walk them through access to the IMB and the Barco Communicator? What’s the right thing here? Thanks!
 
Posted by Justin Hamaker (Member # 2165) on 12-28-2018, 09:32 PM:
 
I would be reluctant to teach anyone unless it is someone with at least some technical knowledge of the systems. I don't see why a "button pusher" should be taught anything more than how to change the format. Teach them too much and there is a risk they start poking around where they don't belong.
 
Posted by Dan Williams (Member # 10367) on 12-28-2018, 09:45 PM:
 
Agreed, it’s also about protecting their original investment. I guess the meat of this question is whether or not to go into the media block, loading and playing content or just leave it as “a qualified tech will know how that works”? Or is that a bad practice because after all... it is a system they own.
 
Posted by Stephan Shelley (Member # 8587) on 12-28-2018, 09:56 PM:
 
Yes one of the common misconception all is need it to push a few buttons. The other one is once it is installed you can lock it up and never have to touch it again.

I say you have no obligation to train anyone. But as you say the do own the equipment so you should give them a list of all relevant logins and passwords. Tell them to call if they need help but it will be at the no contract hourly rate.
 
Posted by Martin Brooks (Member # 1269) on 12-28-2018, 09:59 PM:
 
Assuming your contract is up 12/31, it's a moot point. Else, tell them you can't train anyone unless your contract is renewed (for another year) and that you work on a long-term contract basis, not a per diem basis. If they insist, charge them $2500 per day.
 
Posted by Randy Stankey (Member # 64) on 12-28-2018, 10:51 PM:
 
Walk away the day your contract is up.

Your responsibility only goes as far as you are being paid to go.
 
Posted by Dan Williams (Member # 10367) on 12-28-2018, 10:54 PM:
 
I’ll definitely present them with a service agreement for next year they can choose to accept or not... With that said if I do a proper hand off of the system... Where do you draw the line on handing off vs teaching? Do we do passwords and basic operation, do I go through all the operations of the server with them or do I leave that open ended and simply say that those functions are only available to a qualified or certified tech? What do you all do?
 
Posted by Justin Hamaker (Member # 2165) on 12-28-2018, 11:08 PM:
 
I wouldn't go any further than basic operations. Ingesting and loading content, building play lists, and playback operations. I would not get into any maintenance or repair functions, including things like changing bulbs. I would definitely make sure they have all necessary passwords for operation purposes, but I would be reluctant to hand off any tech passwords.

If you do give them any tech passwords, I would make sure to be clear about how those passwords would allow someone access which could result in them screwing up settings and impacting their presentation.
 
Posted by Dave Macaulay (Member # 813) on 12-28-2018, 11:09 PM:
 
Leave the default passwords in place and walk away. You don't, IMO, have an onligation to train anyone. But changing passwords so they can't access the system if they just call Barco and ask, that could lead to trouble for you.
They own the equipment and can do as they wish with it.
 
Posted by Randy Stankey (Member # 64) on 12-28-2018, 11:17 PM:
 
quote: Dave Macaulay
Leave the default passwords in place and walk away. You don't, IMO, have an onligation to train anyone.
And if (when) people say, "But...but...but...who is going to teach people to run the booth?" your answer should be, "You should have thought of that before you terminated my contract."
 
Posted by Marcel Birgelen (Member # 6801) on 12-29-2018, 07:54 AM:
 
It obviously depends on the particular contract you have, but usually you can't simply refuse training your "replacement", no matter how demoralizing it might be.

That said, it doesn't mean you have to be great at it either. And never spend any second longer than that you're contractually obliged to spend on it.

And sure, every time you're doing something more than just pushing two buttons, like changing a lamp, tell them the potential implications of letting an untrained tech doing this.
 
Posted by Randy Stankey (Member # 64) on 12-29-2018, 09:29 AM:
 
quote: Marcel Birgelen
It obviously depends on the particular contract you have, but usually you can't simply refuse training your "replacement", no matter how demoralizing it might be.
If your contract or job description say that you must train others then, yes, that's true. But, if not, you can simply walk out the door.

Practical reality dictates a solution somewhere in the middle. I think you should give somebody some basic instruction on how to operate the system but you should NOT have to teach somebody else to do your job.

If they want somebody to run the system properly they must PAY somebody to do it.
 
Posted by Richard May (Member # 2627) on 12-29-2018, 09:40 AM:
 
I, personally, would not train ANYONE that would be coming in to take my job. I doubt any contract would say that you have to. If they want to bring someone new in, they should train them themselves.

As far as passwords go, we changed ALL default passwords on all equipment here. That's the whole point of changing them. You don't want just anyone accessing things. Also, maybe I'm being a dick here but if we were ever replaced, why would I give them the passwords? You want someone else to run the booth, let them figure things out.

Owners and management love to cut costs because, in the end, we're only "pushing buttons" anyway. [fu]
 
Posted by Martin McCaffery (Member # 37) on 12-29-2018, 10:25 AM:
 
Why burn your bridges? Make a graceful exit and let them know you are available for renewing the contract at any time. There's a good chance things will get screwed up enough often enough they will realize they are wasting more money than saving.
 
Posted by Dave Macaulay (Member # 813) on 12-29-2018, 11:16 AM:
 
"As far as passwords go, we changed ALL default passwords on all equipment here"
There is ample case law to establish that you will be held liable for the costs of repairing this sabotage, lost income caused by it, and also subject to punitive damages. Bad idea.
 
Posted by Tony Bandiera Jr (Member # 2365) on 12-29-2018, 11:21 AM:
 
When I ended a situation similar to this, I took the middle ground. (Pretty much same reason, cost cutting.)

I OFFERED limited operator training with first hour of my fee waived, (which never happened) and referred them to a service company. That was it. Only the service company got access passwords and other tech information.

I would say it all depends on the circumstances. In Dan's case, I would do the absolute minimum possible.

Basically, surrender projectionist ONLY passwords and very basic instruction, leave all the tech passwords (even if changed from default) as confidential. If the situation arises where they are needed, release them ONLY to a service company he has a good working relationship with, or release them only if charging a fee for himself, AND with a signed agreement that he is not responsible in any way for any problems or damage they cause by using them.

quote: Dave Macaulay
"As far as passwords go, we changed ALL default passwords on all equipment here" There is ample case law to establish that you will be held liable for the costs of repairing this sabotage, lost income caused by it, and also subject to punitive damages. Bad idea.
Really? Maybe in Canada, but it would be very hard to PROVE that the changing of default passwords (which is an industry standard practice) qualifies as sabotage. The ONLY way it could be proven as malicious is IF AND ONLY IF it could be proven that the passwords were changed just prior to someone's departure. Otherwise any competent judge would dismiss the case or refuse to hear it solely on the basis of a changed password. And most manufacturers' equipment has a back door password to defeat that anyway.

If they want detailed training, charge them for it. My minimum would be $65 per hour with a four hour minimum.

Dan plans on offering a Service Agreement..if they decline to accept, I would definitely walk away without disclosing ANYTHING.

One concept sadly lost is loyalty....too many organizations and companies demand loyalty out of their employees/contractors, but when it is time to return that loyalty, the company attitude becomes one of "screw you, we don't owe you anything". In that case, let them suffer. Which in Dan's case, seems to have happened based on the new director's actions.
 
Posted by Jack Ondracek (Member # 1466) on 12-29-2018, 11:56 AM:
 
Changing default passwords isn't exactly 'sabotage', but it does put you in the pipeline. Did you make that change on your customer's dime? Did the customer ask you to do it? Apparently, you did so for your convenience so as not to be bothered by nuisance calls. IMO, you should put the defaults back in or give them the new access codes.

Beyond that, I tend to agree with the notion of exiting as gracefully as possible. You can opt to pass along basics... ingesting and the like. Also, let them know where in the manual they can also find that info. As for passing along knowledge, based on the skills you've accumulated by experience; that is a benefit to them that should be paid for. Offer them a reasonable rate (not @2,500/day), and even give them a short list of others they can call if they don't initially care for your rates. That way, you've given them a choice and not painted them into a corner that only you can get them out of... it looks better that way.

Last year, I had to file a collections suit against my largest radio client. It was a 6-figure problem which, I was sure, would permanently blow up our relationship. In the midst of negotiations between the attorneys, they noted they could go elsewhere for services. I agreed and gave them a list of 5 other engineers they could call. In the end, we made a deal on payments, they kept it and, surprisingly, asked me to resume services, once the balance was paid. I did so, albeit with new conditions, and we've gotten along well since.

Your customer may not come back to you, but they can do damage, if they acquire a perception you played dirty tricks on them. Others can not be saved, and you need to be able to walk away from those clients with a clear conscience. Some day, they may be back.
 
Posted by Stephan Shelley (Member # 8587) on 12-29-2018, 12:54 PM:
 
On the changing default passwords, as an independent service tech I have gone to theatres where this has happened and no one there knows what the passwords are. Hard to do ones job when that happens. And what happens when the say one person that knows them moves on and no longer works there. It can lead to a bad situation.
 
Posted by Steve Guttag (Member # 268) on 12-29-2018, 01:26 PM:
 
Every once in a while, we don't have a good "fit" with a customer and our support services. Honestly, people should use support agencies that they feel provide the service they want. It doesn't hurt my feelings any.

There are aspects of our services that we consider proprietary. They include the manner in which we access the site (beyond the customer providing the internet access) and often passwords (we no longer "sell" our Cardinal Care box either. This precludes any "IT ownership" and at the conclusion of our relationship, it stays with us).

If a customer decides to go a "different direction," we revert passwords that were changed to their factory defaults so the customer or any new entity can pick up right where we left off. Rarely do we change passwords on things like DCP servers or projectors. As Stephen points out, there can often be events were a technician, besides us, has legitimate need to make changes. Furthermore, anytime WE make a change, it is backed up so we can always get a projector, server...or whatever back to the last time we made a change.

Since part of what we provide is how the equipment functions with each other, all they have to do is request the feature/format so they really don't have to play with things so much. That said, all customers are different and we vary our/customer interaction on a customer-by-customer basis. However, if we had a customer where they wanted to do everything, why are they paying us? So again, it wouldn't be a good fit for what we provide versus what they want.

As for training, we never train people how to service the equipment beyond user maintenance (filter cleaning/changing and such) nor am I going to tell a customer how to reconfigure a sound processor (and how often should that need to be fiddled with). This will get to be even more so with drag and drop DSP based sound processors like QSYS.

Sabotaging equipment (locking the equipment with non-standard passwords) is stupid that will, at best, get you a bad reputation. On your departure, restore that stuff back to defaults and move on with life. Who knows, maybe once they try the others, they'll realize what they lost and want you back. A scorched-earth policy will not result in that outcome and likely get one a bad reputation.
 
Posted by Leo Enticknap (Member # 534) on 12-29-2018, 02:50 PM:
 
Agreed with Steve that the handing off being offered should be restricted to offering training to the end user in the operations that the equipment manufacturer recommends can be done by the end user.

For example, I recently installed a DP4K-32B, and will be going back to train the customer's staff just after the new year. I intend to walk them through maintenance schedules A and B in as much detail as they need (e.g. show them where the air filters are, and how to pull them out and clean them per Barco's instructions). I will also tell them that C and D exist, and if they ask, will give them a rough description of what they involve, but with the health warning that they are only supposed to be done by a Barco schooled tech, and that they could have warranty problems if they try to do this maintenance themselves.

I've had to deal with short-sighted venue managers such as the one Dan encountered before. Often, one lost show or serious maintenance problem that is beyond the ability of the venue's staff to fix will be enough to persuade them to renew the service contract. So try to part company on good terms, stressing that you'd be happy to offer one-time service calls to address any problems they may have in the future, but, if pressed, telling them that high level training for service tech operations is not a service that you offer, and here's a link to the schedule of Barco classes in Rancho Cordova if he's serious about taking that work in-house.

The best case scenario for you is that he'll quickly realize that ending the service contract is a false economy, and renew it. The worst is that he'll follow through and go do the class (and then spend a week in bed with the stomach bug that anyone who goes to Rancho Cordova is guaranteed to come away with!), but you will have parted on good terms, and he may still recommend you to other potential customers.
 
Posted by Carsten Kurz (Member # 5396) on 12-29-2018, 02:59 PM:
 
There are many (if not most) cinema operations based on just the basic knowledge on ingest/playlist building, deleting content, etc. Many operations do not even change bulbs on their own. Give them all the changed passwords, train them for daily operations, and then wait what happens.

- Carsten
 
Posted by Marcel Birgelen (Member # 6801) on 12-29-2018, 03:31 PM:
 
What your responsibilities are, is primarily dependent on the type of contract you have.

If you're working there as an employee and while they're paying you the salary agreed upon, they can demand pretty far reaching stuff like you training any new incoming replacement. There have been cases were employers coupled bonuses to "successful" transitions, which is obviously a pretty perverse incentive to get what they want.

If you work as an external service tech, then the contract between the service company and the customer is leading. You usually don't stipulate in such a contract that in case of a termination of that contract, the service company needs to train new incoming replacements.

In any case, it's never a good idea to entirely burn your bridges. Obviously, you should draw lines, where lines are due. They cannot demand much more from you than the basics. If the incoming replacement isn't up to the job, then it's best to make that abundantly clear.

Many of us can tell you anecdotal stories were a contract got terminated and replaced by one from a competitor, only to receive a call from them a few weeks down the road, after it all crashed and burned with the supposedly superior (usually just cheaper) replacements.

As Dave already pointed out, regarding passwords: You're pretty much required to provide those to your employer once the contract has been terminated. There is case law in many jurisdictions were the IT guy thought he could take his former employer hostage and drew the shorter straw. In the end it's his equipment and you cannot simply take it hostage.

And like Steve pointed out, this kind of behavior will at best give you a bad reputation.
 
Posted by Justin Hamaker (Member # 2165) on 12-29-2018, 04:42 PM:
 
quote: Richard May
I, personally, would not train ANYONE that would be coming in to take my job. I doubt any contract would say that you have to. If they want to bring someone new in, they should train them themselves.
If this is part of the normal job during the contract, then you have an obligation to continue doing so until the day the contract expires. I also think there is an ethical obligation to ensure you have done as much to pass off the operation to the next person, especially any non-standard changes or procedures which have been implemented.
 
Posted by Dan Williams (Member # 10367) on 12-29-2018, 07:26 PM:
 
You guys are the best... This was all great advice. What I’ve decided to do as of now at least:

1. Default all passwords and provide them user/projectionist passwords with a signed release for basic operation. I will not release service passwords.

2. Provide them a service contract for 2019 with fees stipulated for required maintenance, service calls, emergency service, as well as a fee to go through the basic system layout and “hand-off”... Because I was the integrator we originally waived all fees for staff training because we were the sole operators.

3. Give them a list of alternates... Allbeit more expensive options.

At this point I’m just disappointed they would make such a short sighted decision with a true belief that they’d yield a savings. Because I’ve been involved since their inception I’ve continued giving them a slamming deal. I have a feeling in the end the net result will simply be getting my rates current.
 
Posted by Scott Norwood (Member # 30) on 12-29-2018, 07:36 PM:
 
Agreed with the other comments about not holding the customer hostage. He owns the equipment and should have all of the standard user login and password information. "Service" logins and passwords should be set (or returned) to their defaults so that the next technician can work on the equipment.

My full-time job is in the IT industry; default passwords are (almost) never acceptable there, but D-cinema is a special case, where physical and network access are tightly controlled. In the IT industry, it would be common to have root-level account information written down and stored in a safe somewhere with important company papers.

The above assumes that the customer has kept up his side of the contract. I could see refusing to hand over login information until all bills are paid.

Unless it is part of an existing service contract, I would think that training would be an extra service that could be provided on a time-and-materials basis. An experienced technician wouldn't need it, but an inexperienced one might.

An interesting customer-held-hostage situation arises if source code is involved. I saw this happen with a Crestron automation system once--the customer hired a company to install and program the system. A year or two later, the installation/programming company went out of business and effectively disappeared. At that point, any changes to the automation would require a completely new program to be written (the Crestron box in question only stored the "compiled" program--not the editable code). I don't know how to solve this, but it seems to be that the original programming company should have made some provision for providing the customer with the source code or at least providing it to another programmer who could make changes in the future without re-writing everything.

Agreed with the don't-burn-bridges argument that many have made. Cinema exhibition is a small industry, and word travels. I could see withholding service until bills are paid, but sabotage just hurts everyone.
 
Posted by Steve Guttag (Member # 268) on 12-29-2018, 07:40 PM:
 
I would suggest to not take it personal. If you provided value, they'll see it soon enough. If they really just want to go another way, that is their prerogative. Sometimes it is just a matter of being penny wise and dollar foolish but they can't see that, at this point.

As for passwords, I've signed enough NDAs to legally tell people, I'm not permitted, legally, to give out non-published passwords. "You should seek those out from the various manufacturers." Again, putting things back to the default password for that device removes any obligation by you to reveal any other company's secrets.

I repeat, try not to take it personal.
 
Posted by Leo Enticknap (Member # 534) on 12-30-2018, 03:01 PM:
 
Also on the subject of passwords, changing them from factory defaults can be risky even if you do hand over the information in an orderly fashion when you leave.

I once had a call from the owner of a Series 2 NEC. The former chief projectionist had changed the factory default passwords on everything in the booth, because of another staff member who was inclined to tinker. When he left, he provided his boss with a list of all the passwords. The boss subsequently lost it. Fast forward several months, and they're trying to clear a tamper alarm. The guy who left did not keep a copy of the list: when asked, he explained that he didn't want anything left on his personal devices that could compromise security at a former workplace.

Most of the devices could be reset either by a clean reinstall of the software (e.g. the DSS200), or by poking a pin into the reset button, but the projector stores the codes on an internal board (the CPU/backplane, I suspect). So for that one, they were buggered. I explained that they would need to contact NEC, and that it might be an expensive repair. I didn't hear from them again, so am not sure how they eventually resolved it.

For this reason, if I was an employee of a theater, had changed access codes from their factory defaults and was leaving, I'd give my boss the option of resetting them to factory defaults, or having a list of the changed info, but would warn him or her in writing that I would not be responsible for the consequences if (s)he chose to take the list, and later lost the information.
 
Posted by Rick Raskin (Member # 1561) on 12-30-2018, 04:33 PM:
 
I agree with Steve, especially about not taking it personally. Reset user passwords to their published defaults and walk away. You have no further obligation.
 
Posted by Steve Guttag (Member # 268) on 12-30-2018, 05:15 PM:
 
I'm of the opinion, on projection/sound equipment IN CINEMA, that the passwords should not be changable for the service level. The restriction should be on the service person having physical access and that is it. Barco has sort of taken this approach to their projectors (and consequently, their servers).

At the very least, there should be a means to reset them to factory defaults by the right entities (even if that is the manufacturer because, again, they would only have access if the company gave it to them).

On projectors like Christie, we create our own user/password so the logs show if it was us or some other person at a service level logged in but again, I don't lock out legitimate service entities.
 
Posted by Leo Enticknap (Member # 534) on 12-31-2018, 01:08 AM:
 
I'm not sure that I agree that service level passwords should not be changeable from factory defaults. The truth of the matter is that many of these factory default credentials are widely known within the biz, including among end users who have not had any training in service or maintenance, and could easily cause damage and/or change settings that stop the equipment from working. It's not ideal that these people know these passwords, but they do. In such a situation, their bosses need the ability to lock them out of service functions. I've no problem with manufacturers building in a backdoor that can only be used in the event of sabotage, a genuinely lost password, etc., but there are legitimate reasons why equipment owners might need the ability to prevent their staff from being able to change settings when working with the equipment unsupervised.
 
Posted by Marcel Birgelen (Member # 6801) on 12-31-2018, 02:21 AM:
 
My opinion might, again, be a little bit different...

I think it's fine that factory default service accounts are changeable, but there should be documented reset procedures for those passwords.

In my opinion, once you have physical access to the equipment, you already have the proverbial super-power to screw things up.

I think this should not only be true for DCI equipment, but for practically all "IT equipment", maybe with the sole exception for devices that really store sensitive data and your average DCI setup stores none of such data.

I've been in too many situations, where the previous guy who ran the technical show left and nobody knows anything about "passwords" or "access credentials". Restoring access to all the gizmos in a modern production environment can be quite a challenge, including lots of wasted hours on trying to password reset thingy X or gadget Y.

For starters, try to get any Android device running that was registered to an unknown Google account, but somebody decided to factory reset...
 
Posted by Dave Macaulay (Member # 813) on 12-31-2018, 09:55 AM:
 
Linux is fairly secure. If someone changes the root password, you are not going to easily recover control of the system. For Doremi where the root password is relatively public, that means replacing the flash drive. Barco does not give away their root passwords and they should be able to recover a projector with the admin password changed but I have never askex for that.
The Christie TPC runs on Windows, much easier to crack.
 
Posted by Scott Norwood (Member # 30) on 12-31-2018, 11:27 AM:
 
Actually, it should be fairly easy to re-set the root password on a Doremi if it can boot from an external device (or the internal CD drive). It should be a five-minute (more-or-less) process.
 
Posted by Mark Gulbrandsen (Member # 72) on 12-31-2018, 11:31 AM:
 
You would need to see whats in your contract. It may well just say leave the booth in the condition you found it, or it may say train the next guy taking the position. Of course once you leave I'd block their number so they can't call you with questions. If you are Barco trained and the new guy is not then don't hand out any passwords! Let them send him to Barco school.

Mark
 
Posted by Steve Guttag (Member # 268) on 12-31-2018, 12:55 PM:
 
With Barco, oddly enough, passwords are tied to the software program on YOUR computer, not the projector so if you have physical connection and you have a service level password, you can get into any projector.

The only time one needs a root password is to clear out a service user from one of their touchpanels. The root password is a temporary item to allow this and does not require Barco involvement, if you know what you are doing and are trained in the procedure.
 
Posted by Mark Gulbrandsen (Member # 72) on 12-31-2018, 01:58 PM:
 
Irregardless of that he still needs to know exactly whats in his contract and not provide any more or any less than what it says.

Mark
 
Posted by Carsten Kurz (Member # 5396) on 12-31-2018, 10:06 PM:
 
Most support contracts do not contains such details, because those who work out the contracts do not know anything about work details.

- Carsten
 
Posted by Mark Gulbrandsen (Member # 72) on 01-01-2019, 11:26 AM:
 
quote: Carsten Kurz
Most support contracts do not contains such details, because those who work out the contracts do not know anything about work details.

Yes, fortunately, sometimes. The incoming director obviously hasn't a clue either.
 
Posted by Rick Raskin (Member # 1561) on 01-01-2019, 04:25 PM:
 
quote: Steve Guttag
At the very least, there should be a means to reset them to factory defaults by the right entities (even if that is the manufacturer because, again, they would only have access if the company gave it to them).
Agree -- In my TELCO experience that was often by means of a serial port on the affected hardware. We did often set them up so we could telnet in remotely.
 




Powered by Infopop Corporation
UBB.classicTM 6.3.1.2