Government contractor exposed path to immigration records
IT took a shortcut when the boss was away, and it led to danger!
The story explores the serious security breach at a government contractor that allowed potentially sensitive immigration records to be accessed. The contractor's firewall rules were changed by developers who wanted to make it easier to move code from a low-security datacenter to a classified datacenter housing production servers.
The developers bypassed security protocols by having the provisioning server in the low-security datacenter VPN into the high-security classified datacenter. This change could potentially allow unauthorized access from thousands of VPN users to the classified datacenter. Even though the servers still required usernames and passwords, the weak password standards at the time made it vulnerable to guessing attacks or brute force.
Brinkley demonstrated this security flaw during a demonstration after returning from vacation, and the change was promptly reverted by supervisors. The takeaway is that while VPN access and passwords are important security measures, additional safeguards are necessary to protect sensitive data. Just relying on the minimum security measures is not enough.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
Also reported by 1 other outlet
- Government contractor exposed path to immigration records theregister.com