Government contractor exposed path to immigration records
IT took a shortcut when the boss was away, and it led to danger!
A government contractor recently exposed a security flaw that allowed unauthorized access to immigration records. The issue arose when developers at the contractor wanted to change firewall rules to make it easier to move data between a low-security datacenter and a classified one. The developers believed this change would simplify the deployment of code for new software programs.
However, information system security officer Joe Brinkley warned against the change, stating it would create a significant security risk by allowing access from a low-security datacenter to a high-security, top-secret datacenter. Brinkley demonstrated how an attacker could exploit the weakened firewall to gain access to the classified servers, revealing 50 million immigration records that included sensitive information about individuals seeking entry into the country.
Despite Brinkley's demonstration and warning, the firewall rule change was implemented without additional security measures. The lesson learned is that even with VPNs and password protection in place, sensitive data requires more robust safeguards.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- Government contractor exposed path to immigration records theregister.com