Friday, July 31, 2015

Former National Security Officials Now See the Peril of Weakening Encryption

Former National Security Officials Now See the Peril of Weakening Encryption
FBI Director James Comey, Director of National Intelligence James Clapper, and NSA Director Mike Rogers continue to lament the ability of people to secure the privacy of their communications with end-to-end encryption that even governments cannot break. But the push for laws mandating “backdoor access,” or built-in security flaws for the state to exploit, has run into some unexpected opponents: former national security officials on the other side of the revolving door.
“My position is probably going to be a little surprising to people here,” Michael Chertoff, the former secretary of homeland security, told an audience last week at the Aspen Security Forum. “I think that it’s a mistake to require companies that are making hardware and software to build a duplicate key or a back door even if you hedge it with the notion that there’s going to be a court order.”
That’s long been the position of most technologists and many tech companies in the communications business. As founder of The Chertoff Group, where former national security officials draw on the knowledge and relationships they acquired as public servants to service the needs of corporations that pay them as consultants, Chertoff is “working with some companies in this area,” he disclosed.
Michael Hayden has served as director of national intelligence as well as head of the NSA and CIA. He is now a principal at the Chertoff Group. And according to The Daily Beast’s Noah Shachtman, who moderated a panel at the Aspen Security Forum, Hayden declared in an interview, “I think I come down on the side of industry. The downsides of a front or back door outweigh the very real public safety concerns.”
Michael Leiter has doubts about mandatory “backdoors” too. A former director of the United States National Counterterrorism Center, he presently works for Leidos, a defense and homeland security contractor. Appearing on the same panel as Chertoff, he declared that “we are clearly going to a world where end-to-end encryption with temporary keys that disappear immediately after any communication occurs, that is the future. There is no way around that; we are not going to stop that. And because of that, for the technology issues, I don't think there is a long term way to preserve the US government's ability to intercept or get access to those.”
“We have to accept that the degree to which we undermine our national security by having that back door or front door, depending upon how you define it, is very real,” he added. “We have seen that because of the cyberthreat.” Policymakers can try to design backdoor access to communications, he said, “but reality is going to overtake you and it's a funny thing that when technology and law conflict, law's not going to change that technology for long, it's going to overtake it. And you have to have a law which addresses reality, and not what you hope reality will be."
Journalist Marcy Wheeler, one of the first members of the press to take note of the panel, observed that Chertoff’s answer is notable because of who he is. Through much of his career, “Chertoff has been the close colleague of FBI Director Jim Comey, the guy pushing back doors now,” she wrote. “It’s possible he’s saying this now because as a contractor he’s being paid to voice the opinions of the tech industry; as he noted, he’s working with some companies on this issue. Nevertheless, it’s not just hippies and hackers making these arguments. It’s also someone who, for most of his career, pursued and prosecuted the same kinds of people that Jim Comey is today.”
Chertoff’s paymaster isn’t the only thing that has changed.
Being in private industry exposes him to people with different values, incentives, institutional imperatives, and responsibilities than he met when he traveled in national security circles. And the rest of Chertoff’s remarks, whatever motivated them, included cogent, hard-to-refute arguments against requiring “backdoors” and weakening encryption.
First of all, he said, “you’re basically making things less secure for ordinary people.”
Second, he said, “the really bad people are going to find apps and tools that are going to allow them to encrypt everything without a back door. These apps are multiplying all the time. The idea that you’re going to be able to stop this, particularly given the global environment, I think is a pipe dream. So what would wind up happening is people who are legitimate actors will be taking somewhat less secure communications and the bad guys will still not be able to be decrypted.”
Third, he explained, looking abroad, “what are we going to tell other countries? When other countries say great, we want to have a duplicate key too, with Beijing or in Moscow or someplace else? The companies are not going to have a principled basis to refuse to do that. So that’s going to be a strategic problem for us.”
He concluded by observing that “we do not historically organize our society to make it maximally easy for law enforcement, even with court orders, to get information”––and that past experience suggests “we’re not quite as dark, sometimes, as we fear. In the ‘90s –– when encryption first became a big deal –– there was a debate about a Clipper Chip that would be embedded in devices or whatever your communications equipment was to allow court ordered interception. Ultimately, Congress and the president did not agree to that. And talking to people in the community afterwards ... we collected more than ever. We found ways to deal with that issue. So it’s a little bit of a long-winded answer. But I think on this one, strategically, requiring people to build a vulnerability may be a strategic mistake.”
Again, none of these points is new. Opponents of “backdoors” have made them many times. It is nevertheless striking that even Chertoff, Hayden, and Leiter, alums of the national security state who are sympathetic to its needs, cannot be convinced that “backdoors” are a prudent solution to the problem of bad guys “going dark.”
See original article on The Atlantic

It’s actually not that difficult to protect your digital identity like an expert

No Experience Required

It’s actually not that difficult to protect your digital identity like an expert.


Cybersecurity.
Update your software, and your conceptions about what it takes to protect yourself online.
Photo by wavebreakmedia/Shutterstock
You, too, can protect your computers and online accounts like an expert! But you probably don’t, according to a study from researchers at Google presented at the Symposium on Usable Privacy and Security last week. The researchers conducted online surveys of 231 security “experts” (defined as people with at least five years of experience working in the field) and 294 non-experts, recruited through Amazon Mechanical Turk, to find out how the two groups’ security practices differed. The results showed several discrepancies in how the expert and non-expert groups protected themselves online. More strikingly, the study also suggested that protecting yourself like an expert actually requires very little expertise at all.
In an attempt to winnow down the massive amount of computer security advice out there, the survey asked respondents the open-ended question “What are the 3 most important things you do to protect your security online?” The top five responses in the expert group were: installing software updates (35 percent), using unique passwords (25 percent), using two-factor authentication (20 percent), using strong passwords (19 percent), and using a password manager (12 percent). For non-experts, the top five responses were: using anti-virus software (42 percent), using strong passwords (31 percent), changing passwords frequently (21 percent), visiting only known websites (21 percent), and not sharing personal information (17 percent). (Strong passwords are those that are difficult to guess because of their length or complexity; unique passwords are those that are used for only one account and not repeated across multiple sites.)
Advertisement
Let’s set aside the question of how it’s possible that one-fifth of the non-expert computer-using population is visiting only known websites. One of the most interesting things about these findings is the implication that expert-level protection requires very little technical know-how. The practices that experts are most likely to endorse—and implement themselves—do not require an intimate knowledge of computer networking, or traffic monitoring, or malicious code. You don’t need any training in computer science or security to figure out how to install software updates or choose unique passwords. Even the slightly more sophisticated practices—two-factor authentication (i.e., using a one-time code texted to your cellphone or other credential in addition to a password to login to an account) and password managers—are fairly straightforward and easily available even to users with relatively little tech savvy.
To protect yourself online like an expert, in other words, you don’t need to understand the Internet’s architecture or inner workings—you just need to branch out from anti-virus software. The survey suggests non-expert users are wary about programs like password managers or new software updates. But they lean heavily on anti-virus software, which 85 percent of non-experts said they used on their personal computers, compared with only 63 percent of expert respondents. Only 7 percent of experts said they considered anti-virus to be one of the top three things they do to stay safe online, compared with 42 percent of non-experts.
But when it came to installing software updates and using password managers, non-experts were much more hesitant than experts. For instance, 73 percent of experts said they used a password manager program to store their credentials for at least some of their accounts, compared with 24 percent of non-experts. And some of the non-experts said in the survey that they did not think password managers were safe and might result in their passwords being leaked. “I wouldn’t use a password manager even if it helps because I don’t trust it,” one wrote. Those fears aren’t entirely unfounded—password manager LastPass announced it had been hacked earlier this summer—but dedicated password managers are still probably more trustworthy and reliable than the alternatives (or so many of the surveyed experts seemed to feel).
Other non-experts expressed concern about downloading software updates, with one writing, “I don’t know if updating software is always safe. What if you download malicious software?” Another noted that “there are often bugs in these updates initially, that must be worked out by the software vendor.” This suspicion of new updates may be part of the reason that 25 percent of experts said they installed updates “immediately,” compared with 9 percent of non-expert respondents.
People who work in computer security (and security more generally) tend to have a reputation for being paranoid about every possible risk, so it’s striking that the non-expert population actually seems to exhibit greater paranoia around some issues—being more suspicious about the trustworthiness of a password manager, or the reliability or a new update, or the threats presented by an unknown website.
It’s possible, of course, that the expert population is less fearful of new programs and updates and websites because they have greater faith in their own ability to identify threats. For instance, though the researchers found that the advice experts offered to less tech-savvy users mostly mirrored their own practices, there were some exceptions. For instance, many experts considered it to be good security advice to not click on links or open emails from unknown people. Yet 38 percent of expert respondents said they often clicked on links from unknown senders, compared with only 12 percent of non-experts. (One expert admitted: “I do all the time … but I tell my mother not to.”)
Paranoid or not, the computer security experts seem, in some ways, to live in less fear of the dangers of the Internet than the non-expert population. In some cases this may just be an indication of how experts and non-experts fear different threats—perhaps the group of non-experts is more concerned about their old passwords being guessed or stolen and therefore change their passwords regularly, while the experts are worrying about having their passwords phished, and therefore are more likely to activate two-factor authentication.
Of course, non-expert opinions about security are probably shaped to a large extent by expert ones—someone probably told them that anti-virus software and regularly changing passwords and staying away from unknown websites are important safety measures. If anything, the most popular non-expert safety measures seem to reflect the messages that the security community has most effectively communicated (whether intentionally or otherwise) to the rest of the world. That may be partly a function of how long those messages have been around—after all, we’ve been hearing about anti-virus for much longer than we have two-factor authentication—as well as the inundation of security advice in recent years, as a growing number of breaches have made headlines, which has made it harder to know which measures to adopt.
Actually, it’s still hard to know which measures to adopt. The Google study largely sidesteps the question of which of these myriad suggestions actually lead to the best outcomes, or correlate with fewer malware infections or account compromises.
That doesn’t mean the expert suggestions from the survey aren’t good advice. Indeed, non-experts might do well to shift some of their practices to emulate those recommendations (especially if you’re one of the users out there studiously avoiding all unknown websites—as my favorite survey respondent said of this recommendation, “Why not hide under the bed too?”) It does mean, though, that protecting yourself online like an expert is, at least for now, more about doing things that the experts do—and less about doing things that are proven to work.
This article is part of Future Tense, a collaboration among Arizona State University, New America, and Slate. Future Tense explores the ways emerging technologies affect society, policy, and culture. To read more, visit the Future Tense blog and the Future Tense home page. You can also follow us on Twitter.

Thursday, July 2, 2015

Facebook Messenger now lets users send money to friends


Facebook Messenger now lets users send money to friends

Filed Under: Android, Facebook, Featured, iOS, Mobile
Facebook Messenger now lets US users send money to friendsAs of Tuesday, Facebook has switched on person-to-person (P2P) payments for users in the US to instantly message money to friends.
David Marcus, former president of PayPal and currently Facebook's Vice President of Messaging Products, said on his Facebook page that it's easy and safe:
We're happy to announce that Messenger person-to-person payments are now available to everyone in the U.S.! Add your Debit Card and pay anyone on Messenger in a few taps. Money goes straight from your checking account to the recipient's checking account. Easy and safe. As always, give it a try and let us know how we can make even better for you!
Here's how it works:
  1. Start a message with a friend
  2. Tap the $ icon and enter the amount you want to send
  3. Tap Pay in the top right and add your debit card to send money
To receive money:
  1. Open the conversation from your friend
  2. Tap Add Card in the message and add your debit card to accept money for the first time
As Facebook said when it first announced the service in March, using the service requires adding a Visa or MasterCard debit card issued by a US bank to your Messenger account when you first send or receive money.
Facebook has reportedly said that it's opted to avoid making the new service compatible with credit cards, so as to reduce fraud and avoid the exorbitant fees that might turn off users from using the service.
P2P payment service Venmo, for example, charges a 3% fee per payment for credit cards and non-major debit cards, to cover processing costs.
After you've added a debit card to your Messenger account, you can also create a PIN for additional security the next time you send money.
Touch ID can also be enabled on iOS devices.
Facebook says that "as always," you can also add another layer of authentication to your account at any time with login approvals.
That's a setting which prompts you for a special security code each time you try to access your Facebook account from a new computer or mobile phone.
Funds may take one to three business days to become available after they're sent, depending on the bank involved, just as it does with other deposits.
Messenger P2P payments are available on Android, iOS, and desktop operating systems.
Facebook promises that it's lovingly swaddled our payments and card details in secure systems with encrypted connections between users and itself with "layers of software and hardware protection that meet the highest industry standards."
The company says that its payment systems are kept in a secure environment, separate from other parts of the Facebook network, and monitored by a team of anti-fraud specialists keeping an eye out for suspicious purchase activity.
"Trust us!" Facebook says, pointing out that it's been processing transactions for game players and advertisers since 2007 and at this point is processing over 1 million transactions daily.
Convinced? Tell us why or why not in the comments section below!

Image of Facebook payments courtesy of Shutterstock.

Directie moet grotere rol spelen in IT-beveiliging

Nieuws van AG Partnerblog

Directie moet grotere rol spelen in IT-beveiliging

De negatieve effecten van een IT-beveiligingslek, dringen langzaam door in de boardroom. Waren in het verleden raden van bestuur en senior executives nog enigszins zelfgenoegzaam over de risico’s van datalekken en cyberaanvallen, tegenwoordig is er een groeiende bezorgdheid over reputatieschade, groepsvorderingen en kostbare downtime. Security heeft eindelijk de aandacht van de boardroom. En terecht.
Uit onderzoek van Ponemon Institute in opdracht van HP (oktober 2014) blijkt dat senior executives steeds meer betrokken zijn bij de voorkoming van en het nemen van de juiste acties na een digitale inbraak. Het beperken van de financiële impact van mogelijke incidenten en het beschermen van de bedrijfsreputatie en merknaam zijn belangrijke drijfveren. 79 Procent van de ondervraagden geeft aan dat de bemoeienis van een executive bij een beveiligingslek noodzakelijk is voor effectieve actie.
Forse financiële schade
De financiële consequenties van een digitale inbraak kunnen fors zijn. Uit de ‘Cost of Cyber Crime Study 2014’ blijkt dat de gemiddelde jaarlijkse schade voor de 59 onderzochte Amerikaanse bedrijven uitkomt op 12,7 miljoen dollar, variërend van 1,6 miljoen tot 61 miljoen per bedrijf. De 38 Britse bedrijven die meewerkten aan het onderzoek gaven aan gemiddeld 3,56 miljoen pond per jaar kwijt te zijn aan de gevolgen van datalekken, variërend van ruim 544.000 Britse pond tot 14 miljoen pond per bedrijf.  
Risico’s security onduidelijk
De belangrijkste belemmeringen voor effectieve actie na een beveiligingslek zijn de slechte communicatie, het gebrek aan leiderschap en het gebrek aan toezicht vanuit de board. Vooral de communicatie is een groot punt van zorg onder de respondenten. Nog niet de helft gaf aan dat ze worden geïnformeerd over het te volgen actieplan na een datalek. Uit ander onderzoek blijkt dat beveiligingsexperts bij een organisatie het lastig vinden om met senior executives te praten over security, zeker als het gaat om het uitleggen van de risico’s en gevolgen. Bijna twee derde (65 procent) van de ondervraagden gaf aan dat als ze gevraagd wordt om een rapport van een beveiligingsincident met grote gevolgen voor de organisatie, ze rapporten wijzigen, filteren of afzwakken. De kans is dan ook groot dat de meeste CEO’s, raden van bestuur en andere managers in het duister tasten over de daadwerkelijke gereedheid van de organisatie om te reageren op beveiligingslekken en digitale inbraken.
Wat te doen?
De uitkomsten van het onderzoek van Ponemon Institute zijn, samen met een aantal aanbevelingen, gebundeld in het whitepaper ‘Het belang van de betrokkenheid van het senior management'.

Tuesday, June 30, 2015

Is your CEO ignoring their cyber security responsibilities?

Is your CEO ignoring their cyber security responsibilities?

CEOs and boards are responsible for the overall direction and governance of an organisation. This covers every aspect of the organisation, from the business model to the marketing plan, to brand awareness and conformity with law and regulations.
Somehow, it seems, cyber security – now an issue of critical importance to all organisations – is being overlooked.
PwC’s Global State of Information Security Survey 2015 found that 58% of boards were uninvolved in the overall security strategy, with 75% playing no part in reviewing security and privacy risks.
The below graph from PwC shows the level of involvement – or lack thereof – with security issues throughout the organisation:

Cyber security is no longer the preserve of just the IT department. Everyone in the organisation has a role to play and it is the board and its director’s responsibility to drive security throughout the organisation.
Get cyber secure now
The government’s Cyber Essentials scheme has been developed to help all UK businesses create a base level of cyber security. It advocates implementing five controls that will help mitigate up to 80% of the most common cyber attacks.
IT Governance can help you achieve certification to Cyber Essentials for as little as £270 with our Do It Yourself Solution.
Find out how Cyber Essentials can help you get cyber secure now.

Sunday, June 28, 2015

Meer gemeenten borgen informatieveiligheid met ISMS Control Framework


Algemeen Directeur key2control | Risicomanagement | Informatieveiligheid | Gemeenten | ISMS
In januari 2015 heeft de Informatiebeveiligingsdienst voor gemeenten (IBD) een uitgebreide brochure uitgegeven over de wenselijkheid van het implementeren van een Informatiebeveiliging Management Systeem (ISMS).
In navolging van gemeenten als Den Haag, Velsen, Helmond, Edam-Volendam, hebben nu ook de gemeenten Almere, Landgraaf en Waalwijk gekozen voor het implementeren van een ISMS. Om deze implementaties structureel te borgen in hun organisaties, hebben deze gemeenten gekozen voor het ISMS Control Framework van key2control.
Jeroen Blok, Concern Information Security Officer van de gemeente Almere: “Met een ISMS ben ik continu aantoonbaar in control op het proces van informatieveiligheid. Daarmee borgen we niet alleen de processen maar met name ook bewustwording en commitment bij het management en onze medewerkers.”
Arie Hartog, algemeen directeur van key2control is zeer verheugd met het besluit van de gemeenten Almere, Landgraaf en Waalwijk. “Het is nadrukkelijk ons doel om gemeenten te ondersteunen in het verhogen van de kwaliteit van hun informatiebeveiligings- en privacy processen. Het is dan ook goed om te zien dat steeds meer gemeenten besluiten een ISMS in te zetten en daarbij gebruik maken van het ISMS Control Framework van key2control.”
Voor meer informatie over het ISMS Control Framework kunt u contact met mij opnemen via LinkedIn of telefonisch: 06 - 575 99 235.

Monday, June 22, 2015

Risk Assessment / Security & Hacktivism


Risk Assessment / Security & Hacktivism

“EPIC” fail—how OPM hackers tapped the mother lode of espionage data

Two separate "penetrations" exposed 14 million people's personal info.

Government officials have been vague in their testimony about the data breaches—there was apparently more than one—at the Office of Personnel Management. But on Thursday, officials from OPM, the Department of Homeland Security, and the Department of the Interior revealed new information that indicates at least two separate systems were compromised by attackers within OPM's and Interior's networks. The first was the Electronic Official Personnel Folder (eOPF) system, an entity hosted for OPM at the Department of the Interior's shared service data center. The second was the central database behind EPIC, the suite of software used by OPM's Federal Investigative Service in order to collect data for government employee and contractor background investigations.
OPM has not yet revealed the full extent of the data exposed by the attack, but initial actions by the agency in response to the breaches indicate information of as many as 3.2 million federal employees (both current federal employees and retirees) was exposed. However, new estimates in light of this week's revelations have soared, estimating as many as 14 million people in and outside government will be affected by the breach—including uniformed military and intelligence personnel. It is, essentially, the biggest potential "doxing" in history. And if true, personal details from nearly everyone who works for the government in some capacity may now be in the hands of a foreign government. This fallout is the culmination of years of issues such as reliance on outdated software and contracting large swaths of security work elsewhere (including China).
The OPM breaches themselves are cause for major concerns, but there are signs that these are not isolated incidents. "We see supporting evidence that these attacks are related to the group that launched the attack on Anthem [the large health insurer breached earlier this year]," said Tom Parker, chief technology officer of the information security company FusionX. "And there was a breach at United Airlines that's potentially correlated as well." When pulled together into an analytical database, the information could essentially become a LinkedIn for spies, providing a foreign intelligence organization with a way to find individuals with the right job titles, the right connections, and traits that might make them more susceptible to recruitment or compromise.
Preliminary evidence points to a group dubbed by Crowdstrike as "Deep Panda," a Chinese cyber-espionage group. In the past, the group has used Windows PowerShell attacks to implant remote access tools (RATs) on Windows desktops and servers. It is this malware that investigators are believed to have discovered on OPM's network and in the Department of the Interior's data center.

Handing out bandages

The two systems breached were the Electronic Official Personnel Folder (eOPF) system, an entity hosted for OPM at the Department of the Interior's shared service data center, and the central database behind "EPIC," the suite of software used by OPM's Federal Investigative Service in order to collect data for government employee and contractor background investigations.
Ars contacted both OPM and DHS while researching this story, but officials at both agencies refused to confirm or deny that these systems were part of the breach due to the ongoing investigation. However, sources familiar with OPM projects identified these systems as the ones most likely to be at the heart of the breaches.
In the weeks following the breach discovery, OPM officials scrambled to find a contractor to handle the "Privacy Act event." The organization issued a call in late May and awarded a contract five days later (on June 2) to Winvale Group, a Washington, DC-based technology services company that also helps businesses sell services to the government. OPM classified the transaction as a blanket purchase agreement to allow for multiple additional purchases. The $20.8 million "first call" was for 3.2 million "units" of credit monitoring and identity theft recovery services, indicating the agency's early assessment of how many individuals might have been affected by the breach.
The Winvale Group may get a lot more business based on OPM Director Katherine Archuleta's statement to the House Government Oversight Committee this week. "In early May, the interagency incident response team shared with relevant agencies that the exposure of personnel records had occurred," Archuleta said. "During the course of the ongoing investigation, the interagency incident response team concluded—later in May—that additional systems were likely compromised, also at an earlier date. This separate incident—which also predated deployment of our new security tools and capabilities—remains under investigation by OPM and our interagency partners. In early June, the interagency response team shared with relevant agencies that there was a high degree of confidence that OPM systems related to background investigations of current, former, and prospective Federal government employees, and those for whom a federal background investigation was conducted, may have been compromised."
To date, OPM has no idea how many individuals' background investigations were exposed. All Archuleta said was that the agency was "committed to notifying those individuals whose information may have been compromised as soon as practicable."
In the meantime, the Obama administration has ordered a “30-day Cybersecurity Sprint." Agencies must perform vulnerability testing and patch existing holes in security. They must prune the number of privileged user accounts and expand adoption of multifactor authentication for all systems. The Department of Defense and intelligence community have led the way on that last requirement, but many civilian agencies (such as OPM) have been slow to put it in place.
Just how much this "sprint" will improve government security remains to be seen, especially since agencies such as OPM have been repeatedly warned in the past about minimum "security hygiene." Thirty days is not likely enough time to correct a decade-plus of neglect of antiquated systems, poor leadership, and spotty attempts at modernization.

Employees must wash hands

Enlarge / The OPM Federal Investigative Service secure Web portal, powered by the no-longer-supported Adobe JRun.
OPM is not alone in neglecting basic security guidelines spelled out for them by both federal regulations and executive orders for much of the past decade. Even those agencies that have implemented systems to comply with the letter of FISMA (Federal Information and Security Management Act) and other regulations have had problems keeping on point because of the constantly changing nature of information security threats. And the complex plaque of information systems that agencies have built up often defies any sort of security management because the vendors who built many of the systems have long since disappeared.
By and large, government agencies in the last 20 years have become increasingly dependent on outside contractors to provide the most basic of information technology services—especially smaller agencies like OPM. The result has been a patchwork IT systems and security, and the Office of the CIO at OPM has a direct hand in fewer and fewer projects. Of the 47 major IT systems at OPM, 22 of them are currently run by contractors. OPM's security team has limited visibility into these outside projects, but even the internally operated systems were found to be lacking in terms of basic security measures.
While OPM instituted continuous monitoring of some systems using security information and event management (SIEM) tools, those tools covered only 80 percent of OPM's systems according to a fiscal year 2014 audit by OPM's Internal Office of the Inspector General (OIG) audit team. And as of October 2014, monitoring didn't yet include contractor-operated systems, according to the same organizational oversight.
"The OCIO (Office of Chief Information Officer) achieved the FY 2014 milestones outlined in the roadmap which included quarterly reporting for high impact systems," the OPM OIG reported in its audit. "The next stage in the OCIO’s plan involves requiring continuous monitoring by contractor-operated systems and implementation of the DHS Continuous Diagnostic and Mitigation program." In other words, OPM had no idea what was going on inside contractor-provided networks and only a limited grasp on what was going on within its own network.
There were significant gaps in OPM's security testing as well. Seven major systems out of 25 had inadequate documentation of security testing—four of which were systems directly maintained by the OPM's internal IT department. Three out of the 22 contractor-operated systems had not been tested in the last year; the remainder had only been tested once a year.
The greatest lapse within OPM's security, perhaps, is the way that it has handled user authentication. The OPM IG report has found progress on access controls, including the use of multi-factor authentication to access OPM's virtual private networks and even to log into workstations using Personal Identity Verification (PIV) card readers—essentially guarding the entry points into the OPM network. But "none of the agency's 47 major applications require PIV authentication," the Office of the Inspector General reported, a violation of an Office of Management and Budget mandate for federal systems.
OPM's Office of the CIO responded that "in [fiscal year] 15 we will continue to implement PIV authentication for major systems."
Ironically, federal officials have been blaming the messenger to some degree through anonymous statements to the press. NPR reported that investigators were looking into whether the IG report "tipped off hackers to some of the agency's vulnerabilities," and reporter Dina Temple-Raston found that investigators believed the attack came "about a month" after the IG report was published. "Among the things the inspector general found that could have helped hackers was that nearly a quarter of the agency's systems did not have valid authorization procedures," she said. "The reason that's important is because one of the departments that didn't have the correct procedures was the Federal Investigative Services. That's the group responsible for background investigations of federal employees. So that data's very sensitive, and as we know now, this is one of the databases that was hacked."
But those problems had been well-documented prior to the 2014 IG report. Attacks on two OPM investigative contractors—USIS and KeyPoint—could have provided plenty of intelligence on just how bad OPM's systems were. Even a quick Web search would have given attackers plenty of ideas about how to get into OPM's sensitive systems. For example, the "secure" Web gateway to OPM's background investigation systems is a contractor-hosted website at an application service provider. That Web gateway is reached through a Windows Web server running JRun 4.0, Adobe's Java application server, as well as ColdFusion, a platform that has been used for a number of breached government servers in the past few years.
In 2013, someone hacked into Adobe and stole the ColdFusion source code. And Adobe dropped the JRun product line entirely in 2013—with extended "core" support ending in December of 2014. There is no evidence that OPM or its application provider had purchased expensive extended, dedicated support, but JRun would hardly be the only unsupported platform still used by OPM. The agency still has systems based on Windows XP (supported under a custom support agreement with Microsoft), and many of the core systems run by the agency are based on mainframe applications that haven't been updated since their COBOL code was fixed for the Y2K bug in the late 1990s.
It would be incorrect to say that these older systems (especially the COBOL code) couldn't be updated to support encryption, however. There are numerous software libraries that can be used to integrate encryption schemes into older applications, including libraries from PKWare. Other government agencies and financial institutions already utilize such software, according to Matt Little, VP of Product Development at PKWare. The problem is that, as DHS Assistant Secretary for Cybersecurity Andy Ozment noted during his testimony, OPM didn't have the kind of authentication infrastructure in place for its major applications to take advantage of encryption in the first place. Encryption, he said, would "not have helped in this case."
Since multi-factor authentication and encryption were not integrated into any of OPM's 47 major applications, all an attacker had to do was to gain access to a system on the network—nearly any system. Based on the testimony before Congress and other publicly available data, we know that hackers found at least two systems and were able to easily expand their access laterally within OPM and then contractor and service provider networks afterward.
"There's a process failure in every spot there," said PKWare's Little. "It's just bad security controls. It looks ridiculous—they didn't even have basic IP (network) access controls. This is not something we typically see in a serious security customer."
As Ars has reported, those problems were not just found at OPM itself. Contractors working for the agency may have introduced some unique security issues of their own, including employing Chinese nationals—some working from overseas—as part of subcontracting teams. Allegedly, that project was an implementation of SAP's SuccessFactors software, undertaken by a systems integrator for OPM and affiliated agencies, and included access to employee personnel data for the Department of Energy, the Transportation Security Agency, and others. SuccessFactors is used as part of a human resources system called the Talent Management System (TMS), "an integrated learning management and performance management system based on the industry leading SAP/Plateau/Success Factors software" hosted for multiple agencies by a data center at the Department of the Interior. SAP could not provide information about the program, the integrator, or even confirm that Interior or OPM were a customer without OPM authorization.


The wrong kind of file sharing

The login page for the Web gateway to the Electronic Official Personnel File (eOPM) hosted at the Interior Business Center may have had some security weaknesses, as shown by Chrome.

Initially, the investigation into the OPM breach uncovered an infiltration into personnel file databases, which may have included the Central Personnel Data File. That database includes the personnel records of a majority of federal employees. The data breach, based on testimony provided by federal officials, included an intrusion into an OPM system hosted by an outside service provider: the Department of the Interior.

The Interior Business Center, formerly known as the Department of Interior National Business Center, is what's known as a shared services center. That means it gets its funding by bidding for work from other government agencies, occasionally competing against outside contractors. So the IBC has been a relatively active center of innovation in the US government as a result. The center has been in the government cloud business since before the Obama administration, providing infrastructure and software as a service. The IBC uses its IBM mainframes, database instances, and mainframe Linux instances (along with other servers) to do everything from serving up webpages to running payroll for dozens of agencies. IBM even profiled IBC (then NBC) for a case study on using System z mainframes as an enterprise cloud platform.
Starting in 2011, OPM pushed agencies to adopt approved Human Resources Line of Business (HR LOB) applications running at federal and commercial shared service centers, hoping to save a billion or more over four years by using more generic federal human resources applications hosted at both federal and commercial shared services centers. But even before the Obama administration had begun its big push to consolidate federal data centers under Chief Information Officer Vivek Kundra, NBC was providing IT services for more than 150 government agencies (often as Web-based software-as-a-service offerings).
IBC also offered mainframe capacity through "infrastructure-as-a-service" packages to other agencies. And as OPM was seeking to consolidate its own data center operations, it turned to IBC to host the eOPF system—the electronic version of government employees' personnel files. The eOPF system's data includes the electronic version of the SF-50 (Notification of Personnel Action), which a State Department human resources document referred to as "Your Federal Employment Birth Certificate." It documents a federal employee's career—promotions, demotions, other administrative actions, retirement plan, and work schedule, as well as personal identifying data. OPM maintains eOPF records for millions of current and former government employees, including Congressional staffers.
At some agencies, eOPF is only accessible from within departmental networks. But some agencies, including OPM, have Internet-accessible portals into the eOPF system. Apparently, eOPF's servers are accessible over the same Internet gateway that other agency Web servers running in IBC used. It's also behind the same firewall. So exploiting one of the Web servers operated by IBC would have given attackers access from within the firewall to eOPF and, in turn, to the OPM databases and services connected to it.
That much was confirmed by Interior's CIO Sylvia Burns, who said in her statement to the House Government Oversight Committee that there was evidence "the adversary had access to the DOI data center’s overall environment." As a result, DOI is "accelerating" a number of fixes. "As part of DHS’s Binding Operational Directive (BOD) we are identifying and mitigating critical Information Technology (IT) security vulnerabilities for all Internet facing systems... We are fully enabling two factor authentication for privileged users (e.g., system administrators, etc.), as well as regular end-users."
In other words, once the attackers had gained access to login credentials of a "privileged user" in IBC's data center, they had the keys to the kingdom. Burns also said that improvements were being made to the way networks within the IBC data center were isolated from each other, an attempt to prevent attackers from exploiting systems connected to the Internet in order to access the rest of its infrastructure.
And the eOPM Web interface itself may have been susceptible to breach. A check of the site's Internet-facing login by Ars found "obsolete" crypto—the site still uses TLS 1.0. There were also insecure elements on the page which might have been modified by a man-in-the-middle attack to fool users into giving up credentials.
In a notice to federal employees about the breach, OPM obliquely confirmed that eOPF had been breached:
The kind of data that may have been compromised in this incident could include name, Social Security Number, date and place of birth, and current and former addresses. It is the type of information you would typically find in a personnel file, such as job assignments, training records, and benefit selection decisions, but not the names of family members or beneficiaries and not information contained in actual policies.
While the attackers had full access to IBC's data center, it so far appears that they didn't pull data from the HR LOB applications run there. Data available there would have been more interesting to thieves interested in financial gain, but the eOPF data is more interesting from an intelligence perspective because it profiles government employees. Such information might indicate things like whether they had problems in the workplace and might be susceptible to recruiting efforts.
Even so, eOPF isn't nearly as dangerous to both federal employees and the government at large as the other system at OPM that got hacked: EPIC.

Tell us a little about yourself

The header to SF-86, the questionnaire filled out by all candidates for security clearance background investigations. All that data goes into OPM's CVS.
The background investigation toolset is called EPIC, which is an acronym based on its major components:
  • E, for the Electronic Questionnaires for Investigations Processing (e-QIP) system, a "Web-based automated system...designed to facilitate the processing of standard investigative forms used when conducting background investigations for Federal security, suitability, fitness and credentialing purposes." The e-QIP system provides a "secure Internet connection"—a Web-based HTTPS portal, based on Adobe ColdFusion—to "electronically enter, update and transmit their personal investigative data over a secure Internet connection to a requesting agency."
  • P, for the Personnel Investigations Processing System (PIPS), a background investigation case management system that handles individual investigation requests from agencies. In addition to handling the scheduling and processing of background investigations, PIPS contains the Security/Suitability Investigations Index (SII), a master record of background investigations conducted on government employees. This is consulted whenever a "National Agency Check" is run against a person as part of a background investigation.
  • I, for Imaging—as in the PIPS Imaging System—a viewer for digitized paper case files. Paper surveys, questionnaires, written reports, and other images are stored here in a system based on IBM's Deaja ViewOne.
  • C, for the Central Verification System (CVS), the mother lode of background investigation data. According to OPM, it contains "information on security clearances, investigations, suitability, fitness determinations, Homeland Security Presidential Directive 12 (HSPD-12) decisions the background checks required for employees and government contractors to gain access to federal facilities, Personal Identification Verification (PIV) credentials [the government ID cards used for facility access and as a second factor in authentication systems], and polygraph data." In 2014, OPM increased the scope of CVS to accept security clearances granted to state, local, tribal and certain corporate employees to meet the needs of the Department of Homeland Security. CVS is also "bridged" to the military's Joint Personnel Adjudication System (JPAS), the Department of Defense's own clearance system for uniformed and civilian employees, so that contractors performing background checks can reach into DOD data when performing background investigations.
Some pieces of EPIC are so sensitive that they are housed at Fort Meade—the home of the Defense Information Systems Agency and the National Security Agency. Contractors who support them require Top Secret clearances.
In a fiscal year 2014 annual report, officials at OPM's Federal Investigative Service wrote, "At OPM, the security of our network and the data entrusted to us remains our top priority. OPM FIS took steps to strengthen security protocols imposed on its own information technology systems and those of its contractors in an effort to preempt any malicious incident that could cause harm to the privacy of individuals or our national interests."
Despite those steps, two OPM investigative contractors—USIS and KeyPoint Solutions—discovered data breaches in 2014. And while some of the elements of EPIC may have been protected from external attack by being located in federally owned secure data centers, it was the breach of OPM's own departmental network that led to the exposure of the contents of the CVS system. While users of OPM FIS' "secure Web portal" are prompted for two-factor authentication (or at least, that's what the code on the site's ColdFusion-powered login page suggests), only a single set of credentials was required from inside OPM's network to gain access to data.
The malware behind the attack, which could have resided on a FIS workstation or nearly any other system within OPM, could then use those credentials to issue queries against CVS and sneak the data back out of the network over the Internet, hiding its activity internally among normal CVS traffic. It was only when OPM was assessing systems to actually implement the sort of continuous monitoring tools that the Federal Information Systems Management Act dictates that OPM security officers discovered traffic outbound from the network that indicated something was very, very wrong.
The damage done to national security by this breach far exceeds anything that could be claimed in relationship to the documents leaked by former NSA contractor Edward Snowden. In total, more than 10 million people have active background investigation files in the CVS—either because they have been investigated for a security clearance, or just to obtain permission to work inside federal facilities. Those include all the data from the SF-85 and SF-86 personal survey forms they have filled out detailing much of their personal lives. They include police, fire, and other emergency personnel at state and local levels who have contact with federal anti-terror "fusion" centers, DOD investigators and intelligence analysts. The only agency that may not have been affected is the CIA, which maintains its own background investigation and clearance system.

A lack of imagination

The weaknesses that were exploited at OPM were ones that weren't just discovered overnight—they were problems that had existed in some form for over eight years and possibly longer, exacerbated by outsourcing and poor leadership and planning. These problems are all too common among government agencies because of the "checkbox" approach that agencies have taken to information security.
With the "checkbox," agencies measure their security based on whether they have done something that matches against a particular FISMA regulation or used a technology that meets the National Institute of Standards and Technology's (NIST's) Federal Information Processing Standards (FIPS), allowing agencies to achieve security "compliance" without really being secure, according to security experts who spoke with Ars. And while the Defense Department and intelligence agencies have taken a more aggressive stance on security measures, few agencies have ever taken the decades-old approach to security that the military pioneered for classified systems: having someone "red-team" them with penetration tests that resemble actual attacks.
"One of the things they struggle with is a failure of imagination," said FusionX's Parker. "The 9/11 attacks happened because we had a failure of imagination in terms of what hijacking was. It's the same with cyber. People aren't gaming things enough—not doing it in tabletop exercises, but doing it for real." While the government holds security exercises like "Cyber Storm", DHS' biennial effort, these are still essentially the paper-based roleplaying game version of security.
While the White House pushed forward with executive orders calling for penetration testing as part of the "30 Day Sprint" launched by President Obama last week, Parker said that he's still "seeing decades of box checking and a lack of realistic threat simulation." These sorts of tests are useless if the goal is understanding how attackers might exploit systems in unexpected ways, he said. "Like Mike Tyson said, 'Everyone has a plan, and then they get punched in the face.' Where these adversaries are catching people with their pants down is the unknown unknowns."
Bringing an approach from military training, where "train like you fight" has long been a mantra, would certainly help. But that's unlikely to happen without major changes to government security policy and culture. "Everything is focused on box checking," Parker noted. He added that his company doesn't do work in the federal market "because there's still a lowest bidder mentality there. If you're a CISO in a private company and you get hacked, and you get called into the boardroom and they ask you what is your procurement philosophy, and you say you went with the lowest bidder, you're going to get hung out to dry."
Instead of addressing some of the underlying problems, government agencies' approach has largely been to throw more people at the problem—Information Systems Security Officers (ISSOs). As of last October, OPM had hired seven ISSOs to take over management of systems security and had another four in the hiring pipeline. Parker said this is akin to "putting as many people around a bad fort instead of rebuilding a better fort." And while great heaps of money are being spent on cybersecurity systems, agencies could likely get a better result spending that money on "fixing systems that are 10 to 20 years old that have never been upgraded."
But these efforts won't happen without a sea change in culture, procurement approaches, and Congressional funding. Until then, expect to hear about more breaches—likely at an increasing rate.