Why the Astros Didn’t Catch Chris Correa

The St. Louis Cardinals’ former director of amateur scouting, Chris Correa, is serving 46 months in jail for gaining unauthorized access to the Astros’ player information/evaluation database, codenamed Ground Control. A few days ago, MLB announced St. Louis’s penalty: they’d have to send $2 million and their top two draft picks to Houston.

From a network-security perspective, the case is interesting. It illustrates how difficult true network security really is, which raises the strong possibility that another team will attempt this in the future (if indeed one isn’t doing it right now).

Here’s a timeline of the incident up until it was made public:

  • March 2013 – April 2014: Correa accesses Ground Control using passwords of various Astros staff. (Source: David Barron and Jake Kaplan of the Houston Chronicle.)
  • June 2014: Deadspin posts leaked documents that were retrieved from Ground Control, mostly regarding trades or potential trades during the 2013 season. This action causes the Astros to contact MLB, who contacts the FBI to begin an investigation into the breach. (Source: Derrick Goold and Robert Partrick of the St. Louis Post-Dispatch.)
  • June 2015: Michael S. Schmidt of the New York Times reports that the Cardinals are the prime suspects in this investigation.

Why didn’t the Astros detect the unauthorized access themselves? I don’t know anything about how they ran their security team, so I can only speculate. But I do have several years of experience in the network-security industry. I’ll use those to provide a perspective.

First, Correa masqueraded as Astros personnel. According to the article by Barron and Kaplan cited above, Correa was able to guess or otherwise obtain the password of accounts belonging to general manager Jeff Luhnow, analyst Colin Wyers, and three minor-league players. The article contains details on what Correa did while logged in as these people, implying Ground Control keeps a record of user actions while they’re logged in.

Impersonating three different people was smart. If anyone looked at Ground Control’s logs, they wouldn’t see Correa snooping around. They’d see Luhnow, Wyers, or a player accessing information. In this case the threshold for “something fishy is going on here, I’d better report it” is very, very high. These people are all expected to access Ground Control as part of their jobs. If Correa had gained access another way, perhaps via an account he was able to create for himself or by exploiting a security vulnerability in a web page, that might’ve set off more (figurative) alarms.

You Aren't a FanGraphs Member
It looks like you aren't yet a FanGraphs Member (or aren't logged in). We aren't mad, just disappointed.
We get it. You want to read this article. But before we let you get back to it, we'd like to point out a few of the good reasons why you should become a Member.
1. Ad Free viewing! We won't bug you with this ad, or any other.
2. Unlimited articles! Non-Members only get to read 10 free articles a month. Members never get cut off.
3. Dark mode and Classic mode!
4. Custom player page dashboards! Choose the player cards you want, in the order you want them.
5. One-click data exports! Export our projections and leaderboards for your personal projects.
6. Remove the photos on the home page! (Honestly, this doesn't sound so great to us, but some people wanted it, and we like to give our Members what they want.)
7. Even more Steamer projections! We have handedness, percentile, and context neutral projections available for Members only.
8. Get FanGraphs Walk-Off, a customized year end review! Find out exactly how you used FanGraphs this year, and how that compares to other Members. Don't be a victim of FOMO.
9. A weekly mailbag column, exclusively for Members.
10. Help support FanGraphs and our entire staff! Our Members provide us with critical resources to improve the site and deliver new features!
We hope you'll consider a Membership today, for yourself or as a gift! And we realize this has been an awfully long sales pitch, so we've also removed all the other ads in this article. We didn't want to overdo it.

In addition to Ground Control logs, there are logs from network devices that I’m betting Correa had to use in order to get to Ground Control. These device logs provided another way for the Astros to detect Correa. They didn’t, though, probably because network security is hard. Really hard.

Some Obstacles to Effective Network Security

The following problems are just a few I’ve noticed among customers in my own experience.

Misconfigured Devices
If you’re not collecting a log, you can’t analyze it for evidence of malfeasance. IT staff, often overworked to begin with, may install a device like a router, change the default password, make sure it works, and leave it be. These devices collect logs by default, but many have optional and even custom fields on which they can report. The trade-off is in disk space and storage: the more logs you collect, the more you have to store. IT is a cost center for many companies, so the focus is on minimizing money spent, not on creating a rich data source for security analysis.

Products like Splunk and LogRhythm exist to centralize, and provide reports on, logs from all manner of devices, including network devices but also applications like Ground Control itself. You can search for anything you want and call up trend reports and pie charts at will. But these products are only as good as the people who use them, which leads to the next problem…

Lack of Staff
Maintaining a Security Operations Center (SOC) is expensive. If you want your network monitored 24 hours a day, seven days a week, and 365 days a year, you need to hire nine people to cover shift changes, sick time, vacations, and so on. Then you have to train them and retain them just like any other employee. If you don’t have a 24 x 7 x 365 SOC, you risk getting breached when no one’s monitoring the network. You may never find out about it.

Employees are often the most expensive part of any organization, but proving a return on this particular investment is difficult. If the SOC team catches something, there’s no way to quantify the value of their work. Who can say where the attackers would’ve gone and what they would’ve gotten? But the longer this team goes without catching anything, the more management looks at the team’s budget and starts wondering what value those nerds in the SOC are really providing.

For these reasons I’ve seen many companies with a “Security Director” who is simply the IT person. This person may not have any network-security training whatsoever. They’re told they have to handle network security because they handle all the other computer stuff. CEO can’t log into her email? Printer’s acting up? Phone system’s down? Got hacked? These tasks often fall on the same person.

False Positives
A false positive is a security incident on which you raise an alarm but is actually expected behavior. Tackling this problem is difficult because each network has its own layout, its own set of users, and its own set of shared assumptions about how and when it’ll be used. The same is true of each application, especially custom-built ones like Ground Control.

Here’s an oversimplified but illustrative example. Let’s say the Astros do have people monitoring not only their Ground Control logs, but also their network logs, and a security analyst notices Luhnow logging in from the Dominican Republic at 3:51 AM on a Sunday. The analyst thinks “That’s a weird time for Jeff to be logging in, and I don’t think he’s in the DR.” They tell their boss, who tells their boss, and pretty soon Luhnow gets a phone call: “Did you log in from the DR at 3:51 AM?”

He replies yes, he took an unannounced scouting trip. This fact gets back to the analyst, who then removes “Jeff logging in from the Dominican Republic” from his mental checklist of “suspicious things I should report.” After all, no one wants to look incompetent in front of the guy who runs the team.

Correa is now free to log in from the Dominican Republic, or pretend he’s in the Dominican Republic, with Luhnow’s account whenever he wants. After enough of these false positives, Correa has a lot of latitude for when he can log in as Luhnow, Wyers, or any staffer.

Rise of the Analytics

The trend in the network-security industry that attempts to overcome these problems is the same one that’s been roiling the baseball world for the past decade: analytics. Specifically: algorithms that run in real-time or on a schedule, monitor log files and other data sources on the network, apply statistical techniques, and alert humans when the “probability that something bad happened” exceeds a confidence threshold.

The newest class of analytics would be perfect for the situation the Astros faced. User and Entity Behavioral Analytics (UEBA) claim to use machine-learning techniques along with network logs and other contextual data to establish behavioral patterns of all users on your network. When someone deviates from the pattern, an alert fires.

Theoretically, UEBA would’ve caught Correa earlier. But they didn’t exist in 2013, and we don’t know how closely Correa’s activity matched Luhnow’s. Additionally, security analytics aren’t a panacea. Many analytics systems suffer from the same problems as manual log analysis.

Consider:

False Positives
How do you write an algorithm that catches Chris Correa masquerading as Jeff Luhnow but lets the real Luhnow do his job without interruption? Over time, humans can learn the idiosyncrasies of the network or application they’re analyzing and adjust. In the example above, our human analyst did this. But teaching a computer is more difficult, and machine-learning techniques are in their infancy.

In the security industry we talk about needing to “tune” security analytics systems. By tuning, we mean giving feedback to the detection algorithms (or whoever writes them) to suppress alerts about which we don’t care, reserving our inboxes for the ones that are relevant. The easier a system is to tune, and the more feedback an analyst can give it directly — instead of having to file a bug, send an email, or some other long-running activity — the more useful it is.

Still, tuning can take weeks to months — and that’s if there’s a team dedicated to it, which brings us back to the problem of…

Lack of Staff
Analytics reduce, but don’t obviate, the need to retain staff. Someone must receive the alert, prioritize it along with the other things to which they must respond (the CEO still can’t log into her email, remember?), find the issue, remediate it, and (maybe) provide feedback to the system.

A human being can fail at any one of these phases. Consider the hack of Target stores in 2013: analysts saw alerts but decided they “did not warrant immediate follow up.” The analytics did their job; the humans, as they do from time to time, erred in theirs.

Additionally, if you depend on security analytics, you’re depending on a company’s ability to hire people to create useful ones. The intersection between “people who know network security well enough to create useful algorithms for detecting threats” and “people who know how to express these algorithms in production-ready code” is smaller than you might think. Several tools exist that purport to make writing analytics easier, but so far none have risen to the top.

It’s similar to baseball operations. You have people who know baseball well enough to come up with useful ways of analyzing data, and you have people who can write releasable code. There’s a Venn Diagram here. The folks on the outside can provide value, but the people in the center are in the highest demand.

Running Algorithms on Big Data
Large computer networks truly are big data. For large companies, analytics may need to process and store millions of log messages per day, everything from “Fred logged in to gc-db-03 at 12:35:34 GMT” to “Mary transferred 545667 bytes of data to the IP address 1.2.3.4 at 14:01:22 GMT.” These analytics may also need access to historical datasets going back a year or more. Advanced systems store not only the log, but the actual packets that crossed the wire. All of this data has to be available to multiple security analysts at once, as quickly as possible.

This Will Happen Again

I’ve left out a lot about running an effective network-security operation here, because there isn’t room. Network security is a complex problem that exists at the very boundary between human-computer interaction. It’s a discipline unto itself replete with dense textbooks, advanced degrees, and industry certifications. Despite being 15-plus years into the internet-connected age, no one has quite solved these problems yet.

The following is pure speculation: I suspect that, prior to 2014, the Astros had a typical network setup that probably included some log-management devices. I suspect that very competent people installed and maintained this equipment and set up the network so that (a) staffers could to their jobs but (b) the millions of people who visit Minute Maid Park every summer couldn’t access areas of the network they shouldn’t.

But I suspect the team didn’t prioritize log reviews/monitoring as highly as they could have. In 2013, very few companies were doing security analytics, but many were doing log management. Splunk and LogRhythm both existed. Regular, deep audits of network access or flow logs could have helped the team catch Correa before the leaked documents hit the web. Regular audits of Ground Control logs would also have helped.

I’m not knocking the Astros. The above two paragraphs are true of many companies — far more than you’d guess.

Like a homeowner who installs a burglar alarm after getting robbed, I bet the Astros and other MLB teams doubled down on network security after Deadspin posted the leak. The fallout within MLB circles was apparently huge. According to Dave Cameron:

The Astros didn’t benefit [from this situation]; they get a couple of lower-value picks and some mostly meaningless cash in exchange for some pretty seriously negative PR. Given the amount teams spend on their image, Houston came out in the red here. They got crushed when the trade transcripts were leaked to Deadspin. Crushed.

I’m sure the Astros pay much more attention to their network and application security now. But this kind of thing will happen again — if not to the Astros, then some other team. Millions of dollars are at stake, not to mention the bright sheen of a World Series championship. The only question is: who is the next Chris Correa?





Ryan enjoys characterizing that elusive line between luck and skill in baseball. For more, subscribe to his articles and follow him on Twitter.

69 Comments
Oldest
Newest Most Voted
lesmashMember since 2017
9 years ago

Fantastic article, Ryan. I learned a great deal from reading your piece.

Question about your claim that ‘this kind of thing will happen again’:

Do you suspect that Correa’s lengthy jail sentence, coupled with his complete blackballing from the sport, is not a significant disincentive for someone contemplating this behavior? Given how little money these guys make, isn’t the risk vs reward balance heavily skewed on the risk side?

cmarts cups
9 years ago
Reply to  lesmash

Yeah, this some some great insight into security, but I just don’t get the premise that MLB team employees are chomping at the bit to hack into another team’s system and face serious prison time.

I am the Rockies fan
9 years ago
Reply to  cmarts cups

I wouldn’t say chomping at the bit, but with that logic there would be very few people in prison, and no thrill junkies or thieves who steal though they need nothing.

People often commit crimes knowing full well potential consequences, it’s not like Correa or any other serious hacker/criminal had no idea of what would happen if he was caught. Criminals are very often opportunists, so if you give them an opening (like say the password to another teams database), and a half decent motive, whether a personal grudge or something else, this could easily happen again.

Rollie's MustacheMember since 2017
9 years ago

I agree. Punishment is rarely a deterrent for breaking a set of rules. Look at Jenrry Mejia. He knew he’d be kicked out of MLB forever if he got caught a 3rd time for PEDs and he did it anyway.

jdbolickMember since 2016
9 years ago

There was a massive incentive for Mejia to take that risk in the form of a major league baseball salary. Lower level team employees aren’t getting paid anywhere near what the players do, and there wouldn’t appear to be any opportunity for them to turn performance into a massive raise. Basically, while there may be significant benefits to an organization hacking another if they remain undetected, there wouldn’t appear to be much benefit for any particular employee of that organization to do so. That means they’re exposing themselves to extremely serious risk for a minimal personal gain. Maybe someone desperate to remain in baseball would try it, but I have to think that anyone who would have the tools to make a reasonable attempt wouldn’t be in a position of such desperation.

victorvran
9 years ago
Reply to  cmarts cups

Wasn’t a lot of the prison time for violating HIPPA? If someone was to access data that wasn’t medical records, they’d like see a far shorter prison sentence to (from my understanding of what happened)

Johnny Dickshot
9 years ago

It wouldn’t surprise me at all that if Correa contemplated getting caught, he did not think 46 months of federal prison time under the CFAA was the likely result of his actions for looking at scouting reports, etc.

Likewise, every girlfriend/boyfriend who snoops into his/her partner’s email account and goes through the emails without permission isn’t contemplating jail time for unauthorized access either.

OkraMember since 2016
9 years ago

I totally agree with this. No way Correa expected 4yrs in jail if caught. Now that everyone in the industry knows how serious the penalty is I really doubt anyone is very anxious try it again. I say this because I’m also not totally convinced that the reward for successfully hacking into another team’s database is all that great. Want to look at their draft board? Who’s to say their scouts are better than yours. Find out they value (insert skill here) 10% more than you? Not very ground breaking. Perhaps you do get lucky and find their new whizzbang algorithm that nicely quantifies player defense with statcast data. Is marginally improving your defensive valuations/player shifts really worth the potential penalties? With the $2M fine the Cardinals paid you could hire lots of really smart people to do this work yourself. And not risk 4yrs in jail.

Paul G.Member since 2016
9 years ago
Reply to  lesmash

Punishments are a disincentive to performing certain behaviors. However, its one factor in many. There are people who would never have done this even if guaranteed they would not get caught. There are people who desperately want to be successful as a baseball executive, do not have the requisite skills, and are willing to do pretty much anything. There are people who are quite willing to hack but are not willing to risk 4 years in jail for it. And there are people who don’t need to hack but will do it anyway because they are ruthless and arrogant.

If the punishment was the death penalty, there would still be people willing to do it. It would be a lot less people than with a 4 year penalty which is still a lot smaller than if there was no punishment at all.

jianadaren
9 years ago
Reply to  lesmash

It’s exactly zero disincentive for a team to hire somebody confident in their ability to cover their tracks.

forum199Member since 2017
9 years ago

In other news, the Cards were hacked by a rogue Astros employee named Sam Piscotty.

jcutigerMember since 2020
9 years ago

Why didn’t the DNC catch the “Russians”?

cmarts cups
9 years ago

“But this kind of thing will happen again — if not to the Astros, then some other team. Millions of dollars are at stake, not to mention the bright sheen of a World Series championship. The only question is: who is the next Chris Correa?”

4 years in prison. 4 years in prison. Who in their right mind is going to risk multiple years in prison to try to gain some competitive advantage for the baseball team they work for? I guess I don’t understand. Even if you want to say a team itself will order someone to hack into another teams system because maybe they really want that team’s intel or scouting reports, what employee at any level is going to risk serious prison time to to this?

cmarts cups
9 years ago

My thinking is more along the lines of, what is the payoff versus the risk? For example, guys like Bernie Madoff made insane amounts of money running Ponzi Schemes, and insider trading often nets people millions of dollars. But I just don’t see what the payoff is for a team employee, high or low level, to do this. Teams throw millions into their own scouting and data resources. Why risk jail time and org punishment to hack into another system and obtain… other scouting reports and data that another team created? This info could be beneficial, or it could be totally useless. For instance, if I’m running a draft room, and I am able to acquire scouting reports and draft strategy from the Astros, how much is that likely to help me or change my decision based on my own intel or reports? It could help a bit, or it couldn’t help at at. Regardless, I don’t see how one could think it would possibly provide enough benefit to risk jail time and professional ruin.

It’s not that there isn’t any benefit to be gained from hacking, but I just don’t see the payoff being worth the risk to any sane person, unless you’re just a hardcore adrenaline junkie who gets off on hacking. If that’s the case, why are you working for an MLB team and not Wikileaks?

fjtorres
9 years ago
Reply to  cmarts cups

It doesn’t have to be a team employee. It could be an agent employee or a player associate, somebody willing to risk jail for a bonus or a payoff.

There was a personal trainer who risked a federal perjury sentence to protect his superstar employer, remember? There’s big money in baseball and people will risk a lot for a big payout. Even go to jail, so long as their families are taken are of. A million bucks is chump change in baseball but to most people it is a lifetime of earnings. Some might even take a fall for something they didn’t do.

It will happen again.

ashlandateam
9 years ago

This really is a great look into both how simple and complicated this is. Hopefully some of the ‘the Astros deserved it/asked for it’ crowd will settle down after reading this. Thanks!!

mike sixelMember since 2016
9 years ago

People keep typing that the jail term is a good enough deterrent….by that logic, no one would hack again. And, we know that’s not true….

Bexevar
9 years ago
Reply to  mike sixel

Huh? I think the point is the risk-reward profile (jail vs. an ambiguous potential increase in perception of job ability in a low-paying, narrow pyramid job) is not remotely close to the risk reward profile of more traditional commercial forms of hacking.

mike sixelMember since 2016
9 years ago
Reply to  Bexevar

Well, I don’t think the risk of jail time is worth any crime…(nor do I think crime is right), but clearly others do. That’s why we still have laws, and jails, because different people do that calculation differently than you and I do.

LHPSU
9 years ago

What this really shows isn’t how hard network security is – it’s how much easier it gets if you can take away the social engineering angle. Passwords, passwords.

BirdStackMember since 2020
9 years ago
Reply to  LHPSU

I was thinking the same thing. Great Article, really, but it operates under the assumption that the passwords were already compromised, (which they were). I understand the necessity for netsec to operate under this assumption, but it still does not shift responsibility from the fact that at the very least passwords were not required to be changed in an acceptable amount of time, not to mention the many other ways to make login protection more secure. But, I am not well read in the case and could be missing something too.

Garyth
9 years ago
Reply to  LHPSU

Passwords are dead. Any enterprise that vitally needs to protect its information should be using two-step verification. The most convenient and least disruptive form of this currently is using a modern identity back-end like Microsoft Azure Active Directory and forcing your users to use Authenticator. This is an app that runs only on your registered smartphone. Whenever you enter your password anywhere, you additionally have to also enter a pin on the Authenticator app to verify that it is you.

You’ll notice and report your phone is stolen or missing long before anything else. Your IT security also then knows exactly to look for authentication attempts during the period in which your phone was lost, which hugely narrows the load on active monitoring and removes completely any false positives.

mike sixelMember since 2016
9 years ago
Reply to  Garyth

There are still companies using Lotus Notes and Windows XP…..expecting that companies or individuals will be up to date on technology is probably a losing bet.

Hemo_jr
9 years ago

One thing you failed to note was how Correa got the passwords he did. When Luhnow & Mejdal were hired away from the Cards by the Astros, they were asked to turn their laptops in. In addition, they were asked by Correa for their laptop passwords. As an IT person, you don’t ask users for their passwords and as a user, you don’t give your password to anyone.

The laptops should have been setup by the Cardinal’s IT department to begin with. And they should have been set up with an administrator ID/PW combo by the IT department that can be used to access the laptop without knowing the user’s password. And rather than give your memorable password to the guy who you turn over your laptop to (if the IT dept didn’t have any foresight), a user should change or delete his or her password and/or ID.

And while Luhnow/Mejdal did use different passwords with the Astros, they weren’t different enough. Apparently the kept the same password stem & simply changed a number they appended to that stem. This was enough to allow Correa to guess the new passwords once he found out the URL to the Ground Control database conveniently photographed in an article about it.

EasyenoughMember since 2016
9 years ago

Or luhnow could just have changed his password once in a blue moon. Literally.

JUICEMANE
9 years ago

For a guy that “acted alone” he sure did some damage. I thought only Jason Bourne would be able to pull something like this off “alone” lol. Since when do amateur player scouts learn to hack into systems like that? Lets me guess YouTube? I mean seriously he would have to be one of the V for Vendetta hackers or near that level. A lot of people seem to believe he “acted alone”…I don’t believe that.

Johnny Dickshot
9 years ago
Reply to  JUICEMANE

I mean, Mejdal literally gave Correa his old password when he left the Cards, and then Mejdal used almost exactly the same one with the Astros. Michael Bourne could have done it…

cmarts cups
9 years ago
Reply to  JUICEMANE

Here’s how he did it… wait for this huge hacking secret… he figured out their passwords and logged in.

JUICEMANE
9 years ago
Reply to  cmarts cups

If you guys believe that whats really happened then you’re incredibly naive sorry to say.

cmarts cups
9 years ago
Reply to  JUICEMANE

Ok, hold on… let me put my tinfoil hat on. Please, tell me what really happened?

JUICEMANE
9 years ago
Reply to  cmarts cups

I’m saying the simple answer they are giving you isn’t what really happened. It obvious to me there is A LOT more that went on, but IDK exactly. You sound extremely gullible. Are you involved in a lot of pyramid schemes?

JUICEMANE
9 years ago
Reply to  JUICEMANE

And also if y’all have any kids I pray for y’all when they become teenagers LOL

Ryan DCMember since 2016
9 years ago
Reply to  JUICEMANE

You don’t know much about hacking, do you?

alpha309
9 years ago
Reply to  JUICEMANE

The guy literally had the password, guessed the right change they made to it, and got in. That isn’t difficult hacking. That is about as easy as it possibly gets.

If I know your email address, and I know your password, I can get in and access and mess around with whatever I want. That is all he did.

JUICEMANE
9 years ago
Reply to  alpha309

Thats what they told you he did…so after being caught hacking he suddenly came clean and was 100% truthful and forthcoming with information. Ok yeah thats much more beliveable

blurrrr427
9 years ago
Reply to  JUICEMANE

JUICEMANE – post another comment so I can Down-Vote it. This is fun.

citizen
9 years ago

Would Correa’s particular method have been stopped simply by dual factor authentication?

alpha309
9 years ago
Reply to  citizen

You would have to assume so. If he didn’t have the authorization number that the system would have sent to the backup source, he couldn’t have input it.

AndrewMember since 2016
9 years ago

Ryan–you are a professional in this area, so I am going to ask you a question that has been bothering me about this scandal: is the whole “cyber-security” frame making us take this behavior too seriously or is there something uniquely bad about computer hacking that justifies the long prison term and serious sanctions. Baseball is a business, but it is also a game. And a game with a long history of people trying to take every advantage even when against the rules and the law. If similar information had been gathered through a non-electronic mechanism, we would have laughed it off and let it become part of the lore of the game. (Let’s say that a player who was traded a few months ago is back as a visiting player, figures out that a security guard didn’t know he had been traded, talks his way into the room where scouting reports are kept, and helps himself to them.) Shouldn’t the fact that it is a game and a game with a long history of spit-balling, amphetamine-popping, sign-stealing, etc. have kept this out of the courts?

mike sixelMember since 2016
9 years ago
Reply to  Andrew

It’s not a game, it’s a multi billion dollar industry. Heck, it might be trillions if you count stadiums as assets…..Stealing the secrets of a competing company has been against the law for a long time. This isn’t about computers, it is about corporate espionage.

JUICEMANE
9 years ago
Reply to  mike sixel

Finally someone who understands!

sopcod
9 years ago
Reply to  mike sixel

Someone else mentioned that these databases contained medical records, which was a major factor in the sentencing.

LHPSU
9 years ago
Reply to  Andrew

Er, no, that player would be legally liable for trespassing and theft, and that’s before we even talk about corporate espionage.

wily moMember since 2020
9 years ago

for about three seconds i thought this was going to be an article about why carlos correa isn’t a catcher

JUICEMANE
9 years ago

If we believe the answer they are giving us, then in turn, we must also believe that no team EVER thought to worry about being hacked EVER until now…not in the 90’s not in the 2000’s not until 2017! not until Chris Correa an amateur scouting director…and to believe that is incredibly naive.

paulsorrentosbat
9 years ago

“This action causes the Astros to contact the MLB, who contacts the FBI to conduct an investigation into the breach”

“Network security is a complex problem that exists at the very boundary between human-computer interaction.”

Definitely sounds like an X-File.

Abstract; Mulder pursues lead pertaining to murderous bat-wielding massive throbbing heaving roided monster who he believes also once played first base at Busch Stadium. Scully uncovers plot by Cards’ analytics department to genetically modify Astros’ minor league depth in order for them to earn call-ups and ultimately defame organization through off-field savagery.

Kristopher
9 years ago

Ryan, I think you’re going far too high level on this. There’s a simple solution, and it’s two factor authentication. There’s plenty of third party apps that can be integrated without too much trouble.

That takes it from an “it” issue to a “physically having to steal your phone” issue.

Obviously there’s a million different ways to get into a system, but doing that one simple thing eliminates 99% of them.

You can get into the nitty gritty of having only specific subnets allowed to VPN in. And having pre-shared keys, yadda yadda. But it’s safe to assume people share absolutely everything.

So build in two factor into your stupid apps, astros.

Richie
9 years ago
Reply to  Kristopher

Having formerly been a techie, yes Ryan is going too high on this, because it is his profession. We all tend to.

Adam absolutely nailed, slam dunked, put this puppy to bed some posts upward. If getting someone else’s scouting reports were that valuable, teams would simply high more of their own scouts. The Cardinals gained pretty much squat, the Astros suffered nothing other than embarrassment. If team scouting reports differed much, you’d see much more volatile draft boards. Like, ‘they drafted WHO Where??’ You keep your scouting reports to yourself just on principle, but there’s not much else to it.

The Astros got “crushed”?? Ridiculous, I see no long-term effects here on Jeff Luhnow.

Richie
9 years ago
Reply to  Richie

Simply “hire” more, of course.

Richie
9 years ago
Reply to  Richie

The only useful inside info teams have is on their own players. The White Sox would love to have the inteam reports on the various prospects they could trade Quintana for. Anything else? Ehhh. Never mind jail, nothing even worth getting a no-jail plea bargain onto your legal record for.

Jetsy Extrano
9 years ago
Reply to  Kristopher

Yeah. Network logs analysis and 24/7 security center are the icing you put on after you cover the basics. Or you don’t, and the basics block this type of amateur hack.

Kristopher
9 years ago
Reply to  Jetsy Extrano

This is my exact point, and I missed the other comment that addressed two-factor.

Anyone building this out, is almost certainly building it without a public facing front-end. The Database would only be directly accessible on the host where the App resides. So to get in, you’d have to VPN into the Cloud or the Astros LAN and from there, you’d visit the DB front-end app. At that point, you’d rely on Google Authenticator or something (https://tools.ietf.org/html/rfc6238). You wouldn’t have access to the DB, only to the app that has access to the DB.

If all this is done, the hack never happens. Even if the Astros had a public facing front-end without the VPN, two factor eliminates most of the risk.

With all that said, sure, if someone wanted to “hack” and they had VPN access, I’m sure they could find a rogue /tmp folder where pdfs go to get printed or pull some magic voodoo SQL Injection.

But again, that initial VPN access should have some pretty portable rules that’ll defeat most basic attempts to gain access. Whether it’s MAC filtering, IP subnet filtering, location filtering, whatever.

You’re trying to get the Astros to prevent against a hack, when all indications seem like this was just illegal access.

kevinthecomic
9 years ago

What 15 years in the risk management profession taught me is that people only require two things in order to commit a crime: motive and opportunity. Correa clearly had opportunity in that he either knew or was able to easily guess the Astro’s passwords. As to motive, only Correa can truly answer that, but it shouldn’t be too hard for us to make some educated guesses. Baseball FOs are hyper competitive and anyone aspiring to break away from low-paying serfdom to the GM’s chair would be, conceivably, looking for any advantage. This is a similar thought process used by the perennial AAAA player who takes PEDs because if he can manage to break into MLB as opposed to toiling in the minors, his pay increases by decimal places (Chris Colabello anyone?) as opposed to percentage points. To the extent that you could hack the Astro’s system, learn their way of thinking, gain insights into the way of other team’s thinking (there was info about other teams, too), you would have a clear edge in dealing with them (and others). There are probably even more concrete benefits to hacking, in the perp’s mind, and probably even in reality: if I know what someone else is offering in a trade, I can create a counter offer that is 1% better in order to close the deal as opposed to guessing what the required next best offer is and inadvertently overbidding by, say, 25%. If you can pull this off consistently and not have anyone know you are doing it illegally, you’re going to look like a genius and get promoted. Couple this with a low expectation of getting caught (and someone will develop a more clever way to hack and convince themselves that they won’t get caught), and you have yourself both motive and opportunity.

paulsorrentosbat
9 years ago
Reply to  kevinthecomic

Correa actually claims that the motive was retaliatory (to Luhnow and co. stealing Cards data), which any respectable adult knows is never a fair motive.

paperlions
9 years ago

I only skimmed through the comments, sorry if someone else brought this up.

It seems to me that it is FAR more likely that fans of one team that have hacking skills would try to hack into a rival teams systems to leak information than it is that a team employee will do this again.

It is probably even more likely that a team would hire a hacker to do the work rather than do it themselves.

scooter262
9 years ago

Ryan brings up a lot of good points about the cost and learning curve to get to a good state of Network Security. As we’ve seen in the past several years, it’s not only baseball teams that have this problem. As the stakes become higher, organizations need to make the investment, both in time and money, necessary to better lock down their networks and protect their data.

Mike Fetters's Topless CarwashMember since 2025
9 years ago

Very informative to me. Thank you. I do agree with those in the thread who think that the 46 month prison sentence Correa received will be an effective deterrent to the vast majority of baseball personnel.

The Other DougMember since 2016
9 years ago

To the vast majority, yes…. but it only takes one.

Baltar
9 years ago

My first thought when I read the headline was, “Wow! Carlos Correa at catcher! That would be some player!”

The Other DougMember since 2016
9 years ago
Reply to  Baltar

Carlos Correa at shortstop is already some player!

redbirdsFanatic
9 years ago

Travis, care to any more information about your experience in the InfoSec realm? It seems like a very unique career path, moving from there into sports journalism.

Psychic... Powerless...
9 years ago

Travis’ output continues to astound, but he didn’t write this one.

Baltar
9 years ago

Absolutely great article! One of the best ever!