tfh
Volume 18, Number 7 -- February 16, 2009

The AS/400 Made Off with the Money

Published: February 16, 2009

by Alex Woodie

The IBM AS/400 is good at a lot of things, including tracking inventory, processing claims, and tallying sales. And now you can add one more accomplishment to the legendary box's resume: Running Ponzi schemes. In recent weeks, evidence points to the fact that Bernie Madoff used an AS/400 server to help perpetrate his alleged $50 billion fraud. Data contained on the server, recently confiscated by the Justice Department, will likely play a crucial role in helping to unravel the crime of the century.

Fox Business broke the story about Madoff's use of the AS/400 to run his alleged Ponzi scheme less than two weeks ago. Reporter Adam Shapiro interviewed a former employee of Bernard Madoff Investment Securities, Nader Ibrahim, about the alleged scheme. In particular, Shapiro focused on the activities of a key former Madoff employee, Frank DiPascali, who is thought to have run the fraudulent activities on the 17th floor of the so-called "Lipstick Building" in New York City where Madoff was based.

"His role was to input data into the computer, which was spitting out what we now know were fraudulent statements," Shapiro said of DiPascali in his broadcast, which can be viewed here. "One thing that you can be sure, the investigators are zeroing in on that computer . . . .an AS/400, it's called. An old IBM computer."

The Fox report came a week after The Wall Street Journal (like Fox, a News Corp holding) published a story on the layout and inner-workings of the 17th floor, based on interviews with Ibrahim and others. "Across the hall was another room, where an old International Business Machines computer generated client statements, former employees say," the WSJ reported on January 29. "The IBM server operated independently from Madoff’s other computer systems but was supported by tech staffers who also did work for the stock-trading group, according to former employees."

That Madoff used an IBM server to perpetrate his alleged fraud is no knock against IBM or its products. It seems logical that the same elements that make the AS/400 such a popular platform for business computing--rock-solid stability and nearly impenetrable security--would also be in high demand among white collar criminals, as Madoff is alleged to be. In any event, IBM refused to comment to IT Jungle for this story.

However, for members of the AS/400 community and the enterprise IT community at large, the Madoff affair raises interesting questions about security, ethics, and the transparency of business processes. For starters, how did Madoff generate so much false data without raising any red flags? The answer to this question may lie with the outside accounting firm that audited Madoff's books, and the federal laws that exempt private brokerages such as Madoff's from greater scrutiny.

Madoff's accountant was Friehling & Horowitz, a three-person accounting firm based in the same office building as Madoff. Industry experts are aghast that such a tiny accounting firm was allowed to vouch for accuracy of the books for such a large, multi-billion dollar investment house. Such a small firm lacked the manpower and expertise to accurately assess the books of such a large operation, they say.

However, Madoff was entirely within the law in hiring Friehling & Horowitz. Because it did not audit public companies, Friehling & Horowitz was not required to register with the Public Company Accounting Oversight Board (PCAOB), according to Reuters. The PCAOB was created under the Sarbanes-Oxley Act in 2002 to help prevent the type of fraud we saw with Enron and its accountant, Arthur Anderson. While the Securities and Exchange Commission has mandated that privately held brokerages such as Madoff's be audited by PCAOB-registered accounting firms, it has delayed implementing that rule several times over the years, providing more cover for Madoff to perpetrate his (alleged) Ponzi scheme.

Even if Madoff's auditor was investment grade, they may have had a hard time spotting the fraud because it was so pervasive. Auditors typically will look at a wide range of data, and then analyze it for items that look out of place. "If everything appeared to look like a genuine transaction, then I guess you'd only spot it at an accounting level," says Terry Heath, chief operating officer of Safestone, a System i security software developer based in the United Kingdom. "Unfortunately, if your baseline for normal is corrupt in the first place, it's obviously hard to spot those events that are out of the ordinary."

It can't be known what motives Madoff had for choosing the AS/400 to perpetrate his fraud (if it was even him that selected it for this task), and it may be irrelevant in the end analysis. But it's interesting when you consider the fact that the AS/400 is a notoriously difficult platform for auditors to crack.

Many regulations that affect IT are commonly written from the point of view of more prevalent Unix and Windows operating systems, the Payment Cardholder's Industry (PCI) Data Security Standard (DSS) being the most recent example. So even if Madoff's accounting firm had experience auditing large investment houses, they may have not had much experience dealing with the AS/400. This lack of oversight could have provided more shadowy areas for Madoff and his crew to execute their scheme.

Despite some of the red flags that, in hindsight, should have invited more scrutiny, Madoff and his crew appeared to operate in an above board fashion. Madoff's business even appeared in several AS/400 marketing databases commonly distributed among ISVs. One company that found Madoff associates in its database is Kisco Information Systems, a developer of System i security software in upstate New York. But many more AS/400 ISVs undoubtedly have Madoff in their marketing databases, and some of them likely sold them software to help them run their AS/400.

When a crime the magnitude of Madoff's alleged crime surfaces, it takes everybody by surprise. Madoff is alleged to have bilked $50 billion from trusting individuals and institutions, and that's nothing to take lightly. The fact that he used a powerful business machine to perpetrate the crime is interesting, but the human toll is much more important. And this isn't the first time an organizations use of AS/400 technology has received guffaws. There's the urban legend about the Columbian drug cartel that used an AS/400 to run its business. And how can you forget the struggles that Microsoft had getting off the box.

New laws will undoubtedly be passed to try and prevent the next Ponzi scheme (start by closing the PCAOB loopholes). And auditors may bone up on the AS/400 so they're not startled by the "strangeness" of the platform. While it would be nice if AS/400s weren't used for illegitimate purposes, that's ultimately impossible.

Kisco president Rich Loeber, who's also an amateur theologian, has struggled with the moral question of the responsible use of technology. "I don't see how anyone can control how the hardware is used," Loeber says. "Over the years, I've given this much thought and my final conclusion is that computers are morally neutral. How they are used is where the morals come in, and that is all controlled by people. I would not be surprised that AS/400s are used in all sorts of immoral ways, Madoff's company just being one such example."

What is true of AS/400s and their progeny is, of course, also true of IBM mainframes, Hewlett-Packard and Sun Microsystems Unix boxes, clusters of Linux-X64 servers or Windows tower servers from myriad vendors. That assessment also applies to the systems and application software that rides atop all of this iron. A computer is just a tool, and any morality associated with it comes from the user, not the machine.




                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
MKS

Are you using WDSC today? Moving to RDi tomorrow?

Would you like a more efficient way to work - a way to see all development tasks and change requests directly within your Eclipse-based development environment?

With MKS Integrity for IBM i, MKS offers the most advanced plug-in for WDSC and RDi available today. The plug-in brings requirements management, task management, software change and configuration management and the ability to deploy, directly to WDSC and RDi, helping developers be more productive and giving managers the process control and audit trail they are seeking to meet compliance and governance demands.

Developers can see tasks, update issues, run queries, check out code and deploy directly from within their IDE. All users get complete visibility of project requirements and changes as they occur. Stakeholders stay informed of project status throughout the software lifecycle ... and all of this from directly within WDSC and RDi!

If you are using WDSC or moving to RDi, let MKS demonstrate a superior way to do development - one that promotes productivity, efficiency and control.

Contact MKS today at 1-800-365-4406 or email info@mks.com.

Download a FREE White Paper:
From WDSC to RDi - Making Software Change Easier with MKS Integrity for IBM i


Editor: Timothy Prickett Morgan
Contributing Editors: Dan Burger, Joe Hertvik, Brian Kelly, Shannon O'Donnell,
Mary Lou Roberts, Victor Rozek, Kevin Vandever, Hesh Wiener, Alex Woodie
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

Vision Solutions:  Learn About Data Integration for Business Intelligence
COMMON:  Join us at the 2009 annual meeting and expo, April 26-30, Reno, Nevada
WMCPA:  24rd Annual Spring Technical Conference, April 1 & 2, 2009, Delavan, WI

 

 

IT Jungle Store Top Book Picks

Easy Steps to Internet Programming for AS/400, iSeries, and System i: List Price, $49.95
Getting Started with PHP for i5/OS: List Price, $59.95
The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
The System i Pocket RPG & RPG IV Guide: List Price, $69.95
The iSeries Pocket Database Guide: List Price, $59.00
The iSeries Pocket Developers' Guide: List Price, $59.00
The iSeries Pocket SQL Guide: List Price, $59.00
The iSeries Pocket Query Guide: List Price, $49.00
The iSeries Pocket WebFacing Primer: List Price, $39.00
Migrating to WebSphere Express for iSeries: List Price, $49.00
iSeries Express Web Implementer's Guide: List Price, $59.00
Getting Started with WebSphere Development Studio for iSeries: List Price, $79.95
Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
Getting Started with WebSphere Express for iSeries: List Price, $49.00
WebFacing Application Design and Development Guide: List Price, $55.00
Can the AS/400 Survive IBM?: List Price, $49.00
The All-Everything Machine: List Price, $29.95
Chip Wars: List Price, $29.95


 
Four Hundred Stuff
Linoma Refines Data Distribution Tasks with GoAnywhere 2.0

DB2 Web Query Goes Multiplatform

GroundWork Revs Performance of Monitoring Tool

InstallAnywhere 2009 Looks to Smooth Java App Installs

New Address Correction Software from WorksRight is Suite

Four Hundred Guru
A Bevy of BIFs: Look Up to %LookUp

Treasury Of New DB2 6.1 Features, Part 1: Query Enhancements

Admin Alert: Time Gobbling Tasks for a System Upgrade

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

System i PTF Guide
February 7, 2009: Volume 11, Number 6

January 31, 2009: Volume 11, Number 5

January 24, 2009: Volume 11, Number 4

January 17, 2009: Volume 11, Number 3

January 10, 2009: Volume 11, Number 2

January 3, 2009: Volume 11, Number 1

TPM at The Register
Intel's future Xeons to share sockets

Rackable stomached $31.3m loss in 2008

VIA spins mini-mobo disk array

Cray thanks Uncle Sam for juiced revenues

Cuba crafts extra-communist Linux distro

IBM lobs biz software at Amazon cloud

Dell punts green gear with 0% interest

Unisys tastes recession red ink

Intel confirms Nehalem Xeons imminent

Intel to spend $7bn to upgrade US factories

Europe gets first petaflops super

Red Hat updates real-time Linux

Deconstructing and rebuilding IBM's server sales

Tough times mean channel love for Novell

THIS ISSUE SPONSORED BY:

MKS
looksoftware
Bsafe Information Systems
HiT Software
Bug Busters Software Engineering


Printer Friendly Version


TABLE OF CONTENTS
The AS/400 Made Off with the Money

IBM's Dynamic Infrastructure Announcement Blitz

Sugar in the YiPs Sandbox

Mad Dog 21/21: Biting The Handout

Soltis Tapped for Vision Solutions Advisory Group and Road Shows

But Wait, There's More:

Reader Feedback on The X Factor: Head in the Clouds . . . Arrow Hit by X64 Downturn, Proprietary Servers Do OK . . . IBS Sales Decline in Q4, Windows ERP Suite Ramps Up . . . IBM Creates a Cloud Computing Division . . . SaaS to Get a Bump Up from the Down Economy? . . .

The Four Hundred

BACK ISSUES




 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2009 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement