Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

5/8/2009
11:16 PM
George V. Hulme
George V. Hulme
Commentary
50%
50%

Maybe Government Should Give Up On Computers, Revert To Paper

Governments and their agencies are clearly over their head when it comes to IT security and governance. In fact, a number of recent reports highlight just how poor a job governments perform when it comes to securing our data.

Governments and their agencies are clearly over their head when it comes to IT security and governance. In fact, a number of recent reports highlight just how poor a job governments perform when it comes to securing our data.Consider this finding, reported in the Daily Mail, where details on a sensitive US air defense system, among other tidbits, were found on a hard-drive bought on eBay:

The test launch procedures were found on a hard disk for the THAAD (Terminal High Altitude Area Defense) ground to air missile defense system, used to shoot down Scud missiles in Iraq.

The disk also contained security policies, blueprints of facilities and personal information on employees including social security numbers, belonging to technology company Lockheed Martin - who designed and built the system.

If anyone, you'd think rocket scientists (okay, these were missiles, but close enough) would be smart enough to wipe hard drives used to manage sensitive data. After all, the debate as to whether hard-disk wipe routines are effective has been essentially settled.

It is not just the US government, and its contractors, who can't keep data under control. It seems the Britain's are having enough trouble of their own. From VNUNET.com on the incompetent tale of MI6 and a lost USB drive:

The data was lost in 2006 by a female agent, known only as 'T', but was only confirmed by the Serious Organised Crime Agency (Soca) on Saturday. MI6 claims that its data handling procedures have been updated and improved since the loss.

'T' had been carrying the storage device in her handbag, which she left on a transit coach in Columbia. The loss put dozens of agents' and informants' lives at risk, and Soca had to relocate the individuals in case the device fell into the wrong hands.

Nice. Can I interest you in some encryption? Securing a USB drive, like running a software-wiping program, isn't rocket science, either.

Next up: the Federal Aviation Administration. According to this AFP story, the US air traffic control system has become easy prey:

WASHINGTON (AFP) - Hackers broke into US air traffic control computers on several occasions over the past few years and increased reliance on Web applications and commercial software has made networks more vulnerable, according to a government audit.

Among the breaches was an attack on a Federal Aviation Administration (FAA) computer in February 2009 in which hackers gained access to personal information on 48,000 current and former FAA employees, the report said.

That's not all. The report highlighted a 2006 virus attack -- emanating from the Internet -- that forced air traffic control systems to be shut down in Alaska. The report also found more than 700 high-risk vulnerabilities in Web and commercial applications -- apparently connected to the Internet that could provide attackers access to applications and data.

I know I'm just a journalist and IT security commentator. I'm not cursed with the job of having to actually secure the applications that many software vendors shovel out into the marketplace, nor try to convince users that security polices exist for a reason. But I have to wonder: why are systems used to govern air traffic connected to the Internet at all? And if they must be connected to the public Internet -- can someone from the FAA introduce those systems to a Web and network vulnerability scanner?

For my mobile security and tech observations, follow my Twitter account.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Overcoming the Challenge of Shorter Certificate Lifespans
Mike Cooper, Founder & CEO of Revocent,  10/15/2020
7 Tips for Choosing Security Metrics That Matter
Ericka Chickowski, Contributing Writer,  10/19/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-27621
PUBLISHED: 2020-10-22
The FileImporter extension in MediaWiki through 1.35.0 was not properly attributing various user actions to a specific user's IP address. Instead, for various actions, it would report the IP address of an internal Wikimedia Foundation server by omitting X-Forwarded-For data. This resulted in an inab...
CVE-2020-27620
PUBLISHED: 2020-10-22
The Cosmos Skin for MediaWiki through 1.35.0 has stored XSS because MediaWiki messages were not being properly escaped. This is related to wfMessage and Html::rawElement, as demonstrated by CosmosSocialProfile::getUserGroups.
CVE-2020-27619
PUBLISHED: 2020-10-22
In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.
CVE-2020-17454
PUBLISHED: 2020-10-21
WSO2 API Manager 3.1.0 and earlier has reflected XSS on the "publisher" component's admin interface. More precisely, it is possible to inject an XSS payload into the owner POST parameter, which does not filter user inputs. By putting an XSS payload in place of a valid Owner Name, a modal b...
CVE-2020-24421
PUBLISHED: 2020-10-21
Adobe InDesign version 15.1.2 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious .indd file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.