Subscribe Sign in

Government contractor reported path to immigration records

3 min read Rewritten in plain language

Security

Show what we removed Rules applied: A3×3 C2×2 D2×5 D3×10 D4×2 E3×6 F2×7 all 30 rules
  • Today’s scary story involves government contractors who just had to make their lives easier at the expense of locking down sensitive information.
  • Our tale of bureaucratic hell comes courtesy of security researcher Joe Brinkley, who previously worked for a government contractor as an information system security officer responsible for firewall rule changes, plus network intrusion detection and prevention.
  • The datacenter itself provided the VPN, not the government.
  • When the developers said they make this change for ease of deploying code, Brinkley told the Change Review Board that it was a bad idea.
  • After Brinkley showed supervisors what was going on, they immediately changed the rule back to the way it was before.

5 sentences from our version of the report, chosen to cover it. Nothing here is written; every line is in the article below. How

During a week when Brinkley was on vacation, the developers who wanted this firewall change talked directly to the Change Acceptance Board and got the rule changed. This was a server that had 50 million records about immigration: who was coming to the country and so on.

Headline check

Headline as published: Government contractor exposed path to immigration records

The headline claims nothing the report does not, but it puts it more firmly than the report does.

  • The headline states “exposed” outright. In the report the claim is attributed to somebody, or hedged.

Figures, names and quoted words in the headline, looked for in the report itself — not in the summary above. How this is checked

Read the full reportHide the full report3 min

IT took a shortcut when the boss was away, and it led to danger!

Welcome back to PWNED, the column where we look at all the ways your security can become self-owned. Today’s scary story involves government contractors who just had to make their lives easier at the expense of locking down sensitive information.

Have a story about someone leaving a gaping hole in their network? Share it with us at pwned@sitpub.com. Anonymity is available upon request.

Our tale of bureaucratic hell comes courtesy of security researcher Joe Brinkley, who previously worked for a government contractor as an information system security officer responsible for firewall rule changes, plus network intrusion detection and prevention.

To improve the contractor's ability to deploy program changes, some of the org's developers wanted to change the firewall rules so it would be easier to move data from a low-security datacenter where they tested new code to the classified datacenter that housed the production server and data. They wanted to be able to VPN into a low-security commercial datacenter, where other non-governmental tenants, such as Microsoft and Oracle, had servers accessible through the same VPN connection. The datacenter itself provided the VPN, not the government.

Back then, in the early 2010s, developers would use a provisioning server to help deploy code from dev to production. But there was always a hard firewall between the classified datacenter and the non-classified datacenter. The developers wanted this provisioning server to be able to access all of the production servers that sat in the classified datacenter so they could more push the code around.

When the developers said they make this change for ease of deploying code, Brinkley told the Change Review Board that it was a bad idea.

“It creates a very glaring issue that we are going from a low-level secured datacenter all the way up to a high-level, top secret secured datacenter for production, and you guys are opening up a firewall rule that would allow anybody from that low level datacenter to have access into, at a minimum, into the high level datacenter,” Brinkley said.

However, during a week when Brinkley was on vacation, the developers who wanted this firewall change talked directly to the Change Acceptance Board and got the rule changed.

When he got back, Brinkley got a member of his company and a government representative to sit down for a demonstration. Tethering his laptop to his cell phone, he logged into the dev server over the VPN — then turned the box on and off. Then he showed how, with the same VPN connection, he could get into the prod server and control it. This was a server that had 50 million records about immigration: who was coming to the country, who those people stayed with, and so on.

According to Brinkley, thousands of people had access to the commercial datacenter’s VPN, but only dozens were supposed to have access to the classified government datacenter. The change potentially made the production servers reachable from a network accessible to thousands of VPN users.

Yes, the servers still required a username and password for access, but an enterprising hacker could have tried guessing the correct combos or attempting a brute-force attack. There was no multi-factor authentication and password standards were low at the time.

After Brinkley showed supervisors what was going on, they immediately changed the rule back to the way it was before.

What we can take away from this lesson is that, even when you have security measures like a VPN and password protection, sensitive data requires additional safeguards. It’s not enough to do the minimum. ®

You are reading our version, not theirs. This is The Register's report with its verdicts and loaded words taken out. Plain description stays, and so do adjectives that carry a fact, such as "former" or "federal". The reporting, the facts and the quotations are theirs — quotations are never edited — and the indicators beside it measure this version. Hover or tap Adjectives to see every one left in the text.

How this outlet filed it, and how we rewrote it

No other newsroom we read has filed on this event, so there is nothing to compare it with yet.

Outlet Niral ScoreAdjectivesSourcingSentimentHappiness
The Registeras they published this story 18.3 8 12 -0.1 38.4
Mundane Readneutralized from The Register 15.5 8 12 -0.1 38.4

Sign in to react.

Comments

Nothing here yet.

Sign in to comment.

Questions

Readers can ask a question about this story here. Questions and answers are for subscribers. Sign in to read them.

Comments are read before they appear where anything in them needs a person to look. Nothing posted here is ever deleted; a comment taken down keeps its text and the reason, so the decision can be looked at again. How this works