Monday, April 23, 2007

When It rains It Pours... And It Leaks All Over

U.S. Exposed Personal Data: Census Bureau Posted 63,000 Social Security Numbers Online

In the continuing saga of mismanagement of data, computers and networks within the governmental infrastructure, we now learn that the Census Bureau--which practically guarantees confidentiality on the surveys it sends out every 10 years--has been releasing identity data of those that have sought financial aid in the past.

For those of us that have taken out student loans and were forced to finance our way through college, this is worrisome, even though this particular instance doesn't involve student loans. But since the federal government has outsourced much of the dealings and processes having to deal with student loans, and there has been a lot of news regarding the recent scandals involving student loan lenders, and anyone that has ever fell into arrears can testify how unethical the collectors hired by the Department of Education can be... well, I'll just let you come to the point I am trying to make.

However, given my recent posts on our government not being able to protect, use and guarantee our data systems, computers and networks used in all aspects of the federal government, this series of articles gives us more cause to pause and ponder how unsafe we really are... and how our own government is probably a bigger threat to our identity, privacy, security and civil liberties than even the Al-Qaeda criminals.
For more than a decade, the Census Bureau posted on a public Web site the Social Security numbers of 63,000 people who received financial aid, officials said yesterday. The apparent violation of federal privacy law prompted concerns about identity theft.

Government officials removed the data from the Web site on April 13, the day they were alerted to the breach by an Illinois farmer who discovered the numbers while surfing the Internet. They did not publicize the matter until yesterday, saying they needed the delay to enable information-security officials to contact those whose numbers were revealed and to contact "at least a half-dozen" mirror sites.

"We take full responsibility for this and offer no excuses for it," said Terri Teuber, a spokeswoman for the U.S. Department of Agriculture. "We absolutely do not think it was appropriate."

A watchdog group countered that officials tried to suppress the news.

"The bottom line is the government screwed up," said Gary Bass, executive director of OMB Watch. "What's really important is that they now try to rectify the problem. Thousands of research groups have copies of this site."

Government officials said they knew of no misuse of the personal data, but the breach underscores the ease with which such data can be exposed in the digital age.

Last month, Los Alamos National Laboratory discovered that a subcontractor working on a security system in 1998 had posted the names and Social Security numbers of 550 lab workers on the subcontractor's Web site. The site was removed that day, a spokesman said.

In the current incident, Marsha Bergmeier said she was bored April 12, so she did an Internet search for her farm's name. It brought up a link to FedSpending.org, a site created by OMB Watch to allow monitoring of federal spending.

The site includes a searchable database of federal contract information, and her farm loan amount, under an Agriculture Department program, was listed. Also listed, Bergmeier discovered, were the Social Security numbers of 28,000 farmers.

"I was in disbelief," she said.

Teuber said the USDA had been using Social Security numbers as part of a 15-digit federal contract identifier number. The practice dates back more than 25 years, she said, to when Social Security numbers were printed on checks. She said the USDA's information-security division was not aware of this continuing practice until last week.

The loans database was part of a larger public Web site run by the Census Bureau, which collects all federal loan and grant data. The site has been up since 1996.


Cyberspies exploit Microsoft Office

Given that almost every corporation, federal and state agency, and most of our personal data is stored somewhere on a computer that either uses Microsoft Windows, or allows computers operating with Windows to access this stored data, the vulnerabilities that this article exposes is quite significant and presents an overwhelming threat to our national security. Even military operations on the ground in Iraq and Afghanistan employ Windows-based software and operating systems. The NSA, NSC, White House, Pentagon and Treasury Department use Windows-based software, operating systems and networks.

Personally, I have always questioned these common practices that Microsoft has epitomized:

1. Using beta releases to test the reliability and validity of its software; releasing these beta versions to any number of vendors, third-party software creators, educators and corporations developing software training programs, etc.;

2. Revealing internal security settings to other corporations doing high volume business for computer users relying upon Microsoft operating and network systems;

3. Releasing some of the buggiest software, operating systems, network management systems and having to release numerous patches, many of which create as many bugs as they fix;

4. Forcing end-users (regardless of the size/type of consumer) to visit the Microsoft web site to download updates and bug fixes;

5. Allowing Windows-based computers to send background information to Microsoft engineers and software experts regarding system crashes, authenticity verification, and automatic updates (newer computers operating under XP, .NET and VISTA platforms);

6. Dominating the marketplace with tactics that squeeze out the competition and getting involved in hundreds of law suits over patents, exposure, cybersecurity flaws, anti-trust activities, etc.

But since Microsoft is what it is--the most dominant software company in the world--we do not have many alternatives to substitute for its operating systems, office suites and utilities.

Cyberspies have a new secret weapon: tainted Microsoft Office files.

A rising number of cyberattacks are taking aim at specific individuals at critical government agencies and corporations — enticing them to unwittingly open a corrupted Word, Excel or PowerPoint file sent as an e-mail attachment.

Clicking on the file relinquishes control of the PC without the user's knowledge. The attacker then uses the compromised PC as a base from which to roam the organization's internal network.

Federal agencies and defense and nuclear contractors are under assault. Security firm MessageLabs says it has been intercepting a series of attacks from PCs in Taiwan and China since November.

"The bad guys know which organizations have data worth stealing and are picking them out one by one," says Alex Shipp, senior technologist at MessageLabs.

In early 2006, security experts detected one or two such attacks a week. Last month, MessageLabs intercepted 716 e-mails carrying corrupted Office files aimed at 216 different agencies and companies.

Assaults are coming from China and perhaps other countries in the hunt for military, trade and infrastructure intelligence, says Alan Paller, research director at The SANS Institute, a security think tank. The goal: strategic advantage over the USA. "The attacks are working," says Paller. "Penetrations are deep and broad."

Some attacks could be "on-demand," at the behest of companies that hire cybergangs to pilfer data from rivals, says Righard Zwienenberg, chief researcher at Norman Data Defense Systems.

At a congressional hearing last week on cybersecurity, Donald Reid, a senior State Department official, described how an employee in May clicked on a Word document corrupted via a security hole for which Microsoft had no patch. A fix wasn't available until eight weeks later. Microsoft has issued 10 patches for security holes in Office programs since January 2006, including a handful delivered only after crooks began using newly discovered flaws in their attacks. The best protection: keeping Office security patches updated.

The Office file attacks are "very targeted and very limited," says Mark Miller, Microsoft's director of security response, who called on workers "to absolutely extend extreme caution" when opening Office files in e-mail.

Microsoft has been slow to patch security holes in Office programs, says Zwienenberg. "But the cybercriminals are getting smarter and smarter."


Lest we think that I have a bias against Microsoft, or that other platforms are not involved in similar risks, the news regarding Apple software and operating systems isn't without bad news: Mac platforms are at risk almost as much as Windows-based PCs and networks. However, hackers have is less interest in hacking Macs and Mac networks because there are so few of them used for exploitable databases, accounts and identity information.

Myth Crushed As Hacker Shows Mac Break-In: Dino Di Zovie Illustrates Security Flaws in OS X
A hacker managed to break into a Mac and win a $10,000 prize as part of a contest started at the CanSecWest security conference in Vancouver.

In winning the contest, he exposed a hole in Safari, Apple's browser. "Currently, every copy of OS X out there now is vulnerable to this," said Sean Comeau, one of the organizers of CanSecWest.

The conference organizers decided to offer the contest in part to draw attention to possible security shortcomings in Macs. "You see a lot of people running OS X saying it's so secure, and frankly, Microsoft is putting more work into security than Apple has," said Dragos Ruiu, the principal organizer of security conferences including CanSecWest

Initially, contestants were invited to try to access one of two Macs through a wireless access point while the Macs had no programs running. No attackers managed to do so, and so conference organizers allowed participants to try to get in through the browser by sending URLs via e-mail.

Dino Dai Zovi, who lives in New York, sent along a URL that exposed the hole. Because the contest was only open to attendees in Vancouver, he sent it to a friend who was at the conference and forwarded it on.

The URL opened a blank page but exposed a vulnerability in input handling in Safari, Comeau said. An attacker could use the vulnerability in a number of ways, but Dai Zovi used it to open a back door that gave him access to anything on the computer, Comeau said.

The vulnerability won't be published. 3Com's TippingPoint division, which put up the cash prize, will handle disclosing it to Apple.

The prize for the contest was originally one of the Macs. But on Thursday evening, TippingPoint put up the cash award, which may have spurred a wider interest in the contest.

One reason Macs haven't been much of a target for hackers is that there are fewer to attack, said Terri Forslof, manager of security response for TippingPoint. "It's an incentive issue. The Mac is not as widely deployed of a platform as, say, Windows," she said. In this case, the cash may have provided motivation.

The contest was a chance for hackers to demonstrate techniques they may have boasted about. "I hear a lot of people bragging about how easy it is to break into Macs," Ruiu said.

Some attendees didn't think it was a coincidence that on late Thursday Apple released a patch for 25 vulnerabilities in OS X.


But here is the really bad news:

Most Computer Attacks Originate in U.S.

For all the bruhaha about external security threats, the reality is that our biggest cybersecurity threats originate within our own borders, generated by the corporations that develop and maintain our networking backbone, the corporations that maintain millions of terabytes of data on our credit and business transactions, and our own government that is collecting data in an exponentially expanding manner.
The United States generates more malicious computer activity than any other country, and sophisticated hackers worldwide are banding together in highly efficient crime rings, according to a new report.

Researchers at Cupertino-based Symantec also found that fierce competition in the criminal underworld is driving down prices for stolen financial information.

Criminals may purchase verified credit card numbers for as little as $1, and they can buy a complete identity — a date of birth and U.S. bank account, credit card and government-issued identification numbers — for $14, according to Symantec's twice-yearly Internet Security Threat Report released Monday.

Researchers at the security software company found that about a third of all computer attacks worldwide in the second half of 2006 originated from machines in the United States. That makes the United States the most fertile breeding ground for threats such as spam, phishing and malicious code — easily surpassing runners-up China, which generates 10% of attacks, and Germany, which generates 7%.

The United States also leads in "bot network activity." Bots are compromised computers controlled remotely and operating in concert to pump out spam or perform other nefarious acts.

The legitimate owner of the computer typically doesn't know the machine has been taken over — and the phenomenon is largely responsible for the palpable increase in junk e-mail in the past half year.

Spam made up 59% of all e-mail traffic Symantec monitored. That's up 5 percentage points from the previous period. Much of the spam was related to stock picks and other financial scams.

The United States is also home to more than half of the world's "underground economy servers" — typically corporate computers that have been commandeered to facilitate clandestine transactions involving stolen data and may be compromised for as little as two hours or as long as two weeks, according to the report.


There are a lot of unanswered questions and un-addressed issues in terms of cybersecurity, especially within our corporations (many of which are vendors for our government) and our governmental agencies... including those that claim they are protecting us and our civil rights.


REFERENCES:

Flaw Count Hits A High
Last year (2006), researchers at Internet Security Systems identified 5,195 vulnerabilities in software. On Monday (October 2006), the count for 2006 stood at 5,450, according to the Atlanta-based company's survey, and the projected total for the whole of the year is almost 7,500 bugs.



U.S. Agencies Fail Cybersecurity Tests
Overall government grades improve slightly, but Homeland Security, Defense, and State departments still need work.



Lawmakers Grill US Agencies on Cyberattacks
Lawmakers expressed concern Thursday that multiple U.S. agencies whose networks were hacked recently can't be sure they've fixed their vulnerabilities because of poor cybersecurity practices.

Several agencies haven't completed inventories of their IT equipment, and can't know how badly they've been compromised, said Representative James Langevin, a Rhode Island Democrat, during a hearing of the House of Representatives Subcommittee on Emerging Threats, Cybersecurity, and Science and Technology.



Wellesley College: CyberSecurity Guidelines
As computer systems get more complex, the need to keep them up to date is crucial for preventing data loss and maintaining the security and privacy of your information. Some of the computing problems that have been seen on campus (anywhere) recently were (are) caused by viruses, security holes, mis-configured computers, and the illegal sharing and downloading of copyrighted material.

A compromised computer affects all the other computers on campus (anywhere) because we are connected to the same network. The speed of and reliability of our network can be affected because compromised computers may cause large amounts of network traffic and often attack computers on and off the campus network.



Threats And Vulnerabilities To Our Global Computer Networks And Systems Are Growing Faster Than We Can Address Them
Malicious code--viruses and worms--is being created to exploit software flaws within days, when only a year ago it would have taken months for such code to appear. Our water supply, electric grid, nuclear energy system and other critical infrastructures are interconnected and interdependent, increasing the likelihood that a cyberattack could disrupt major services and cripple economic activity.

Indeed, if a cyberattack occurred at the same time as a physical attack, critical emergency response systems and communications operations could be taken out, increasing the confusion of an attack, and the number of casualties.

When the Department of Homeland Security was created, the president eliminated the position of senior advisor to the president on cybersecurity and delegated its responsibilities to the new department. For months, the department failed to assume this responsibility and did little on cybersecurity.

The government cannot be naive in its approach and must recognize the unique and cross-cutting nature of the cyberworld.



U.S. Cybersecurity Czar Has His Marching Orders

Labels: , ,

More Information Security Woes... Can We Ever Be Safe From Our Own Government?

Agency Officials Say Info Security Law Falls Short

The federal law governing agency information security practices took a beating Thursday in congressional testimony from government cybersecurity officials.

Donald Reid, senior coordinator for security infrastructure at the State Department's Bureau of Diplomatic Security, told a congressional subcommittee that the 2002 Federal Information Security Management Act (FISMA) does not "tell the whole story" when it comes to agencies' information security practices.

Earlier this month, State received a failing grade on the fiscal 2006 cybersecurity report card for the third time in the four years the grades have been handed out. But Reid said that even if the department had received an A+ on the report card, it would not have been able to prevent a June 2006 cyber attack on the department's networks.

"Our ability to detect and respond to intrusions ... nowhere is that measured in FISMA," Reid said. "It's a great baseline log, but we clearly have more work to do."


So let's see if we have this correct:

1. Our government, specifically the State Department in this article, has received failing grades for cybersecurity throughout several agencies, including the IRS, the Department of Agriculture, three branches of the military, the White House, the VA and elsewhere;

2. The DHS/NSA combined project of developing an information and intelligence sharing center has encountered so many problems trying to get all the information to share across database platforms and network topographies;

3. The VA, IRS, the high security/top secret defense labs in New Mexico and elsewhere throughout our government there have been numerous (hundreds) laptop computers stolen or lost with confidential and secret data on the hard drives.

4. Experts regarding the use and structure of databases have made the case that the data mining conducted by the NSA, DHS, airport security, etc., is not only ineffective, but a major waste of taxpayer dollars.

Is anyone seeing the pattern here?
The June 2006 attack was initiated when an employee of the department opened a Microsoft Word e-mail attachment that contained an exploit code, which is a piece of software or data often used to gain control of a computer.

How is it that millions of home computer users can protect their computers from such attacks (albeit millions often do not), but our government--with all its resources, expertise and money--cannot protect its computer systems?
Doubts have been raised about the effectiveness of FISMA for more than a year, with critics stating that it is little more than a paperwork exercise. But OMB officials have said the law needs more time before it can be judged.

The problem is that the people passing the laws do not understand the threats, the technology, the limits and the possibilities involved in not only providing cybersecurity, but even how (and what) to protect governmental computer networks. Given that our lawmakers have relied on the expertise provided to them by government employees, what does this say about who we are hiring and depending on for security.

Let's face facts. Anyone with real cybersecurity credentials is not going to work for our government because the salary is significantly lower than what can be obtained in the private sector, there are better opportunities as a consultant or contractor to the government, and there is just too many damn political issues when working for Uncle Sam. But if we rely on contractors and consultants we run into several conflicts of interest, not the least of which is the fact that it pays for the contractor or consultant to stretch the process out for as long as possible. The other problem is that, given the recent history of scandals, waste and fraud, we have not been able to rely upon the ethics and integrity of governmental contractors and consultants.
Rep. James Langevin, D-R.I., chairman of the House Homeland Security Subcommittee on Emerging Threats, Cybersecurity and Science and Technology, which held the hearing, said incidents at State are just the tip of the iceberg.

"These are not the only agencies experiencing problems," Langevin said. "They are simply the only attacks that have been made public."

According to information provided by Langevin, hackers using Chinese Internet servers launched an attack on the computer systems at the Commerce Department's Bureau of Industry and Security in October 2006. The hackers used a "rootkit" program that allowed them to mask their presence to gain access to the system.

"I think these incidents have opened a lot of eyes in the halls of Congress," Langevin said. "We don't know the scope of our networks. We don't know who's inside our networks. We don't know what information has been stolen. We need to get serious about this threat to our national security."

These statements really instill our confidence in the way our government conducts its business, don't they? The litany of what these folks do not know is longer than a Catholic novena.
Dave Jarrell, manager of the Commerce Department's critical infrastructure protection program, said the department focuses a significant amount of attention on FISMA, which primarily centers on certifying and accrediting an agency's information technology systems.

We have to wonder what the Commerce Department focused on before the passing of FISMA. Why is the effort to secure our computers and networks requiring so much focus? Was the security of our computers and networks ignored before FISMA came along? Was the neglect so significant that there is now a need for a complete overhaul? And, if Congressman Langevin's statements are true, how will they know if they get it right?
Any rating of an agency's systems under FISMA is merely a snapshot in time, Jarrell said. A change to a system, such as an introduction of new technology or a new user, changes the security variables that an agency looks at, Jarrell said. While FISMA is a good tool, an agency also has to look at other capabilities and vulnerabilities.

"Having the ability to put more technology in place so that we can secure that system is also a great issue," Jarrell said. "It seems that there needs to be more of a balance of FISMA and the introduction of new technology."

Of course, anyone that has worked for the federal government knows that the government is almost always five to ten months out of date with its technology implementation. In the world of information technology, that length of time is equivalent to three to five years in most other industries and technologies.

Consider the differences between television technologies and computer technologies as an example of what being out of date means. Recent innovations in televisions include High Definition and digital signals. It has taken almost 15 years to implement both innovations. However, while most computer users are just grasping the possibilities with CD-ROM, CD-R, CD-RW, DVD, DVD-R and DVD-RW storage technologies, the computer industry has already introduced Blu-Disc technology that is slated to replace all the previously listed storage devices. The storage capabilities of home computers have experience innovations and new devices about every 2-4 months, including the elimination of floppy disks; the obsolescence of ZIP, Jazz and other larger external storage devices; the introduction of flash drive technologies; the introduction of micro-drive readers; etc. By the time our government figures it all out, the technology has changed.

On top of all these issues is the fact that the government has so many workers using computers and the amount of training received regarding computer, network and technology security is at best a one-day session and at worst a warning from a supervisor to read the manuals. Even with the best technology experts operating the behind-the-scenes security, the configuration of our governmental networks and the number of people on these systems changes rapidly, creating an unstable networking environment where the level of protection at the end-user level is always in question.

I am not saying that our systems cannot be secured. I am saying that we do not have managers, leaders and lawmakers that understand how to implement security measures well, and we do not train end-users to assist in making our computers, storage devices and networks secure. In other words, we have ignored these issues for so long that we will never be able to catch up without doing a complete analysis and overhaul of the way we have structured our networks and the way we assign access to computers, networks and other technologies.

Given all these issues, I am even more concerned regarding the way the NSA, DOJ, DHS, TSA, IRS, VA, USDA, CDC, CCMS, NSC, DOT and other governmental agencies collect, handle, analyze and use the data they collect. My concerns are especially focused on the issues of national security, law enforcement and civil liberties.
Greg Wilshusen, director of the Government Accountability Office's information security issues division, said if the performance measures established by the Office of Management and Budget do not spotlight the effectiveness of security activities, FISMA cannot be not fully effective.

"Just performing certain activities doesn't mean they are being performed effectively," Wilshusen said. "Just because a system is certified and accredited does not make it necessarily secure."

He said receiving a higher grade on the FISMA score card is more an indication of the measures used to assess security implementation rather than of the actual state of government information security.

In other words, A FISMA report card is all but meaningless. Given that any efforts to assess FISMA compliance are admittedly focused on a "snapshot in time," and the world of hacking and breaking security is fluid and dynamic, we do not have the ability to secure our networks.
Rep. Tom Davis, R-Va., who issues an annual report card on FISMA compliance, said last week that while the law could be improved, criticism of it has come "mainly from failing agencies." He also said he wants "to take FISMA to the next level."

Davis introduced legislation in the last session of Congress that would have amended FISMA to require all government chief information offices to enforce rules accounting for and securing IT equipment containing sensitive information.

The legislation, which would have required agencies to inform the public when data breaches involving sensitive information occur, passed the House but never made it out of the Senate.

The Senate must have realized what a political football such reporting requirements would be. Imagine what would happen if every federal agency actually reported the failing status of our cybersecurity. What would be the reaction from their constituents? Would there be pressure to retract the requirements from the IRS to use the computer to file taxes? What would the media say? How would the realization that we are not only vulnerable, but also that what we have in place is inaccurate and abused, affect the mood of our nation? Would that change apathy many Americans have regarding the collection of all sorts of data by the government? Would it undermine our confidence (even further than it is now) in our government and its officials?

To Find the Danger, This Software Poses as the Bad Guys

Do not fret too much about the status of our governmental computers and networks, because there is every indication that our corporate computers and networks are not all that secure either.
FOR all our dependence on computer software, the truth is, it isn’t very safe. Recent data breaches involving tens of millions of confidential company files have made this all too clear.

Why is software potentially so dangerous to the health of a business? There are scores of reasons. The big one is that software systems are so complex that it is next to impossible to find all the holes.

That can lead to trouble: hackers stealing trade secrets, for example, or customer information. Company servers can also be infiltrated and used to send spam, or data can inadvertently be exposed to anyone with access to a search engine.

The rise of the Web, which encourages companies to connect their programs to those of other companies, creates the potential for even more software problems — most code wasn’t written with sharing in mind.

Then there is the growing practice of releasing unfinished “beta” code to the Web to keep ahead of competitors, which can make it seem as if the software industry prefers to fix products after the fact. Indeed, at times, the software industry appears to be racing downhill while still trying to build its car.

A new company, Veracode, of Burlington, Mass., gives companies a way to help keep the wheels on. In February, Veracode introduced SecurityReview, a service that lets companies automatically test their code, either alone or with other businesses. The goal is to find vulnerabilities that could leave data exposed or that hackers could exploit.

Some of these vulnerabilities are as old as software itself — like the buffer overflow, in which hackers hijack computer systems by interrupting program commands and inserting new ones. Veracode’s tool finds these and other common problems with software by acting as an automatic hacker.


New Hacker Techniques Threaten Agencies
As if I needed confirmation and affirmation of statements made above, the following article points to new methods hackers are using to exploit computer and network vulnerabilities.

With hackers constantly concocting new types of malicious software, government agencies are struggling to stay abreast of the latest threats, according to testimony released Thursday by federal auditors.

One new trick that intruders are trying involves a covert form of "malware" called a rootkit. A rootkit remains dormant, invisible to the user and even the computer's operating system, while gaining access to information in the computer and any network connected to the computer.

"[T]he purpose of the rootkit is to jimmy the door or make a key to the house that no one else knows that you have, so you can gain entry," said Jim Butterworth, the director of incident response at Guidance Software, a computer investigation firm. "It's a significant threat to all government agencies."

While rootkits can be outwitted by users and sophisticated technical protections, including a tool offered by Guidance, agencies are not fully executing their defense strategies, according to the Government Accountability Office (GAO-07-751T).

User training is critical to combating threats, Butterworth said. "A lot of times it is human error that results in an intrusion. It is accidental. ... It is unintentional."

He added that checking Web-based mail or surfing the Internet could open a computer to a rootkit. Thumb drives, too, can become conduits for malware. Butterworth urged agencies to mitigate the danger posed by removable devices by disabling USB ports on all employee computers, except ports used for required work-related purposes.

Labels: , , ,