FACEbook

Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Saturday, January 17, 2015

Feds Buy 'Cossack' Armored Border Guard Truck … For Ukraine

    In April, the Obama administration announced plans for financial aid, advisers, and 'non-lethal' security assistance for Ukraine in its struggle against Russian encroachment on its territory. Eight months later, citing the "urgent and compelling need to establish security and stability," the White
House National Security Council staff approved the purchase of an armored “Cossack” truck, a rapid-reaction military vehicle, for use by the border guard service of Ukraine.



    The $189,000 vehicle was purchased from the Practika PJSC company, in Ukraine, and is being handled by the state department's procurement office in Germany.
    Despite the lapse of eight months since the assistance was announced by President Obama, the Justification and Approval document cited "unusual and compelling urgency" as the reason that full and open competition was precluded for the contract. When asked about the timing of the vehicle purchase, a state department official replied, "The United States has committed over $118 million to Ukrainian forces since the start of the crisis, including over $47 million in equipment to border guards.  The urgent and compelling requirements are derived from Ukraine’s ongoing operations to protect its sovereignty and territorial integrity." The official also said that the vehicle is scheduled to be delivered to Ukraine’s State Border Guard Service on January 19th: "The “Cossack” armored truck, designed and manufactured by the Ukrainian company 'Practika,' is one of a variety of armored vehicles that we are providing to Ukraine’s State Border Guard Service to help it better monitor and secure its borders and operate more safely and effectively."
    A June 4, 2014, "fact sheet" issued by the White House said that as of that date, "President Obama has approved more than $23 million in additional defensive security assistance since early March," and went on to detail the assistance already provided to the Ukrainian border service:
Embassy Kyiv has purchased and delivered 20-person shelters, sleeping bags, fuel filter adapters, barbed wire, patrol flashlights, perimeter alarm systems, fuel pumps, concertina wire, vehicle batteries, spare tires, binoculars, excavators, trucks, generators, food storage freezers, field stoves, and communications gear to the Ukrainian State Border Guard Service, for use in monitoring and securing their borders.
    THE WEEKLY STANDARD reported in August that the state department spent $435,000 on security fencing for the Ukrainian border.



Note: A version of this post first appeared at The Weekly Standard.

Saturday, January 3, 2015

Feds Looking for Company to Run 'National Data Warehouse' for Obamacare, Medicare

    The Department of Health and Human Services (HHS) is looking for vendors to run its "National Data Warehouse", a database for "capturing, aggregating, and analyzing information" related to beneficiary and customer experiences with Medicare and the federal health insurance Marketplaces. Although the database primarily consists of quality control metrics related to individuals' interactions with customer service, potential contractors are to "[d]emonstrate ... experience with scalability and security in protecting data and information with customer, person-sensitive information including Personal Health Information and Personally Identifiable information (personal health records, etc.)." Vendors are also instructed that one of the requirements of a possible future contract would be "[e]nsuring that all products developed and delivered adhere to Health Insurance Portability and Accountability Act (HIPAA) compliance standards[.]"
    For a number of years, the Centers for Medicare and Medicaid Services (CMS), the division of HHS responsible for Medicare and now Obamacare also, has maintained a "national data warehouse" (NDW) related to the 1-800-MEDICARE helpline. The passage of the Affordable Care Act and subsequent establishment of the Marketplaces has expanded the scope of the NDW. The CMS notice explains the NDW as follows:
The NDW performs a significant role with oversight and monitoring functions under the Virtual Call Center Strategy (VCS) initiative and Medicare Reform legislation. The NDW acts as the central repository for capturing, aggregating, and analyzing information related to the beneficiary experience with Medicare and the consumer experience with Marketplaces. The NDW also serves as a foundation for operational and management reporting to support improved decision-making, business practices, and services to callers. 
    The type of data included in the NDW "includes information for CMS’ Virtual Contact Center operations including, but not necessarily limited to" items such as "Workforce management data", "Quality monitoring", "Medicare disenrollments", "Beneficiary satisfaction surveys", and "Web Chat metrics." The NDW is part of CMS's larger $15 billion "Virtual Data Center" program awarded to multiple vendors in 2012. The eventual vendor for the NDW must be able to integrate and share data with the other Virtual Data Center vendors.
    The description for the "NDW Functional Requirements" included thirty-six items, several with multiple subpoints, and even this list is not meant to be "all inclusive" according to CMS. In addition to these functions, the "contractor shall implement a security program that adheres to CMS security standards." Interested vendors have until January 19, 2015, to respond.


Note: A version of this post first appeared at The Weekly Standard.

Thursday, October 30, 2014

Customs and Border Protection Halts Background Checks Over Security Concerns

    The Department of Homeland Security (DHS) recently suspended all background investigations on current and prospective Customs and Border Protection (CBP) employees due to security concerns over Personally Identifiable Information (PII). At least five sole-source, no-bid contracts of "unusual and compelling urgency" totaling almost a half million dollars were awarded to various information technology vendors at the end of September.
    Although the justification documents for the contracts state that the awards were "not the result of a lack of planning," the contracts' sole-source, no-bid nature was justified because "[t]ime and urgency did not allow for soliciting multiple sources." CBP halted all background investigations until security upgrades are completed:

        The five upgrade contracts were awarded in ColoradoVirginiaIndianaMaryland, and New Mexico. According to the documents, the need for the upgrade is the result of "a requirement for increased security standards for background investigation contractors accessing Personally Identifiable Information." No source is cited for the "requirement for increased security standards":


    The BPA referenced in the document covers at least 47 transactions stretching back to 2009 totaling $53 million for background investigations for the CBP. Market research, usually a requirement for government contracts, was not done in the case of the security enhancements because, per the government documents, only the selected vendors can conduct the upgrades due to the systems' proprietary nature. Without the upgrades, use of the systems would have to be discontinued.
    It is not clear if the CBP has resumed background checks yet. An email to the CBP requesting an answer to that question and clarification on other issues has been acknowledged by a CBP media representative but a response to the inquiries has not yet been forthcoming.

UPDATE: Although KeyPoint Government Solutions is the vendor shown in the screenshots above, KeyPoint is only one of five vendors involved in the upgrades. The other four are Omniplex World Services Corp., CSC Systems & Solutions LLC, MSM Security Services LLC, and ADC LTD NM.


Note: A version of this post first appeared at The Weekly Standard.

Wednesday, April 16, 2014

Under Obamacare, HHS Begins Fingerprinting "High Risk" Medicare Providers and Suppliers

    Four years after Obamacare became law, the Department of Health and Human Services (HHS) is notifying Medicare providers and suppliers of new fingerprint-based background checks.  Eventually, all individuals who hold a five percent or greater stake in a Medicare supplier or provider that is categorized as "high risk" will be subject to the requirement.  The provision is part of the Medicare, Medicaid, and CHIP Program Integrity Provisions (Title E) of the Affordable Care Act, and gives the HHS secretary broad discretion in applying the background check requirements depending on the potential for abuse, fraud and/or waste.
    The new requirements are spelled out in a document posted online on the website of the Centers for Medicare and Medicaid Services (CMS) last Friday.  The new rules will apply to both current and future enrollees who are classified as "high risk," the stated purpose being to weed out "bad actors" in the Medicare program and prevent any more from enrolling.
    This particular document is a "News Flash" from CMS's Medicare Learning Network and is addressed to suppliers and providers who submit claims for "Durable Medical Equipment Medicare Administrative Contractors (DME MACs) and Home Health and Hospice (HH&H) MACs for services provided to Medicare beneficiaries."  There is no effective date or implementation date listed on the document; rather, the document states that "fingerprint-based background check implementation will be phased in beginning in 2014," and that those affected will receive letters after which the individuals will have thirty days to comply with the finger-printing requirement.  The fingerprints will be submitted to the FBI for a background check and will be stored by the government in accordance with federal requirements and FBI guidelines.
    Although initially the new regulations will only be applied to providers and suppliers of "Durable Medicare Equipment, Prosthetics, Orthotics, and Supplies (DMEPOS) suppliers or Home Health Agencies (HHA)," the "high risk" category is defined at the discretion of the HHS secretary and may be expanded in the future.


Note: A version of this post first appeared at The Weekly Standard.

Thursday, April 3, 2014

Inspector General Uncovers 'High-Risk Security Vulnerabilities' in State Medicaid Systems

     The Office of the Inspector General (OIG) for the Department of Health and Human Services (HHS) has uncovered seventy-nine "high-risk security vulnerabilities" in the information processing systems of ten state Medicaid agencies that "raise concerns about the integrity of the systems used to process Medicaid claims."  While the ten states are not identified by name, the OIG said that the investigation "suggests that other State Medicaid information systems may be similarly vulnerable," though the results could not be conclusively applied to all fifty states.  Now that the expansion of Medicaid under the Affordable Care Act has taken effect in 2014, millions of new enrollees will be added to these same state systems, ready or not.
    While the number of findings range from a low of three in one state to a high of seventeen in another, a chart accompanying the report illustrates the pervasiveness of the problems throughout the states, as well as the widespread nature of the vulnerabilities:

    The OIG provided specific examples of the vulnerabilities exposed by the investigation:
  • one State agency had not encrypted the hard drives of 14 portable laptop computers, leaving them susceptible to unauthorized access.
  • one State agency had not established any type of formal agency-wide inventory mechanism to account for all information system components and devices and was unable to identify all workstations and servers that were authorized to access the secure network and so needed to be properly secured.
  • one State agency had not enabled the network user account lockout function after unsuccessful login attempts, an error that could have allowed intruders to successfully run automated login attack tools without detection. 
  • one State agency was using an insecure remote access method, which sent unencrypted data (including passwords) across the Internet, to perform system administration functions within its MMIS [Medicaid Management Information Systems].
  • one State agency’s physical access control policies and procedures did not address the review of electronic badge access rights; consequently, some terminated employees still had access to the datacenter housing the State agency’s MMIS.
  • one State agency had not established formal policies and procedures to address the antivirus software deployment and update requirements. In the absence of formal antivirus deployment policies and procedures, more than 1,000 workstations and 200 servers from the State agency’s network were not reporting to the antivirus software control console, which was used to track the antivirus deployment and update status. Without updated antivirus deployment, State agencies expose their networks to known vulnerabilities, which could leave sensitive systems and data susceptible to unauthorized access and exploitation. 
    In the report's conclusion, the OIG repeated the warning of the "serious vulnerabilities" found in the ten states studied.  The state Medicaid agencies told the OIG that the vulnerabilities were being addressed.  The OIG said that "management should make information system security a higher priority," and that the inspector general was continuing to investigate in this area.
    With full implementation of the Affordable Care Act (ACA) in 2014, Medicaid will see a massive increase in enrollment even with only about half of states participating in the ACA-related expansion. As many as 8.9 million low-income Americans will meet the revised income threshold for eligibility.  With the personal information of nearly 9 million more Americans running through state Medicaid systems, the increased strain on the system and workload of state personnel serve to increase the urgency of addressing these serious security shortcomings.


Note: A version of this post first appeared at The Weekly Standard.

Security Breaches of Personal Information at Federal Agencies More Than Double Since 2009

    Millions of individuals who recently entrusted personal, medical, and financial information to the federal government while enrolling in Obamacare via Healthcare.gov may find a recent trend reported by the Government Accountability Office (GAO) rather unsettling.  The number of security breaches involving Personally Identifiable Information (PII) at federal agencies more than doubled in recent years, increasing from 10,481 in 2009 to 25,566 in 2013.  Perhaps even more disturbing, the GOA found that "none of the seven agencies [in a related study] consistently documented lessons learned from PII breaches."
    A graph accompanying the GAO report illustrates the dramatic and consistent upward trend in PII-related breaches over the last several years:


    A data breach may consist of something as simple as mailing documents containing PII to the wrong recipient, but also includes incidents involving massive loss of sensitive data as illustrated by these examples in the report:
  • [I]n May 2006, the Department of Veterans Affairs (VA) reported that computer equipment containing PII on about 26.5 million veterans and active duty members of the military was stolen from the home of a VA employee. 
  • In July 2013, hackers stole a variety of PII on more than 104,000 individuals from a Department of Energy system. Types of data stolen included Social Security numbers, birth dates and locations, bank account numbers and security questions and answers...
  • In May 2012, the Federal Retirement Thrift Investment Board (FRTIB) reported a sophisticated cyber attack on the computer of a contractor that provided services to the Thrift Savings Plan. As a result of the attack, PII associated with approximately 123,000 plan participants was accessed. According to FRTIB, the information included 43,587 individuals' names, addresses, and Social Security numbers, and 79,614 individuals' Social Security numbers and other PII-related information. 
    While the increasing number of incidents is concerning, the GAO also found that "agencies have had mixed results in addressing" information security "and most agencies had weaknesses in implementing specific security controls."  An earlier GAO report in December 2013 covered the responses to PII data breaches of seven federal agencies, including the IRS; the Centers for Medicare and Medicaid Services (CMS), the agency charged with implementing and running Obamacare; and the Veterans Administration (VA).  That report found agency responses broadly inconsistent.  For example:
  • only one of seven agencies reviewed had documented both an assigned risk level and how that level was determined for PII data breaches
  • only two agencies documented the number of affected individuals for each incident 
  • only two agencies notified affected individuals for all high-risk breaches
  • the seven agencies did not consistently offer credit monitoring to affected individuals
  • none of the seven agencies consistently documented lessons learned from their breach responses
    The GAO report also gives a preview of an upcoming report specifically on cybersecurity at federal agencies, and preliminary results are not encouraging.  The GAO has found effective and consistent response to cyber incidents in only about 35% of cases:
While these results are still subject to revision, we estimate, based on a statistical sample of cyber incidents reported in fiscal year 2012, that the 24 major federal agencies did not effectively or consistently demonstrate actions taken in response to a detected cyber incident in about 65 percent of reported incidents.
    The full GAO report on cybersecurity will be completed and issued later this spring.


Note: A version of this post first appeared at The Weekly Standard.

Monday, March 10, 2014

Senate, EPA, Treasury Websites Vulnerable to Phishing Scams [Updated]

UPDATE: The exit message on the Senate website has changed since this post ran at The Weekly Standard.  It's not perfect because it just lumps potential scamming sites in with the ones that Senators actually want to link to, but it is still an improvement.

--------------------

    Less than a month after the exposure of a widespread vulnerability on government "open data" websites, another perhaps even more insidious opening for abuse of government websites has come to light.  The problem is known as an "unvalidated redirect," and has been found on the websites of the Environmental Protection Agency, the Treasury Department, and even the Senate, among others. The vulnerability is not a new one and could extend back months if not years, and is not an uncommon problem on commercial websites either.
    A "redirect" is a web address that automatically opens a webpage or, in many cases, even a completely different website that the original address, or URL, indicated.  Generally when a government website directs a user to an external site, a warning or disclaimer appears alerting the user. For instance, the Centers for Medicare and Medicaid Services website places a small "world" icon next to external links, and the site has a page explaining the disclaimer:

 
     Other government sites follow a different protocol where a special disclaimer page is displayed for several seconds after the external link is clicked before the users is automatically taken to the new page or site.  While this protocol is not a problem in and of itself, if the website code does not restrict the ability to redirect only to sites approved by host sites, any web address can be substituted.  This can allow unscrupulous website operators to provide a link in a website or an email that begins with a legitimate government address, such as senate.gov or epa.gov, but then quickly and automatically transport users to any website they choose.
    The website for the Senate is an especially serious example of this vulnerability because of the complete lack of a disclaimer on the "exit" page before the redirect takes place.  Senators often will direct website users to pertinent news articles, stories concerning constituent issues, or government services on other federal websites.  However, the following screen is all that users see before they are bounced to the new page or site:

    Since the script for the exit page is not restricted, anyone can establish a link by entering a [web address] after this prefix: http://www.senate.gov/cgi-bin/exitmsg?url=[web address]  For example, this link directs users to Google.com after bouncing off of Senate.gov:  <http://www.senate.gov/cgi-bin/exitmsg?url=http://www.google.com>  But replacing "www.google.com" with any website works just the same way to direct users to that site.  This opening could easily be exploited by inserting this type of link in a phishing email or a website and inviting users to simply click on what appears to be a Senate website address but in reality is a redirect to a phishing site.  At that point, personal information could be solicited with the apparent endorsement of the Senate.
    A bold scammer could even explicitly tell users, for example, that "you will see a message that you are exiting the Senate web server system and being transferred to our secure data collection site."  Without a restriction on redirect links or even a disclaimer, there is nothing to warn an unsuspecting user that the Senate is in no way connected with the linked site.
    The Senate's site is not the only government website vulnerable to this kind of exploitation.  A subdomain of the Treasury Department's website, publicdebt.treas.gov, has a similar problem.  While there is a more complete exit page provided, with a disclaimer ("You're going to a website that is not managed or controlled by the Bureau of the Public Debt. Its privacy policies may differ from ours."), the user is still bounced to the new site (again, using google.com as an example) with the apparent blessing of the Treasury:



    A Google search suggests that this vulnerability does not exist simply in theory, but has been used either innocuously or maliciously already.  Here is a screenshot of a Google search as it existed on March 9:

    Clicking on each of these links automatically transfers users, after eight seconds of the exit page, to a website not connected to or endorsed by the Bureau of the Public Debt of the Treasury Department, yet without a clear warning to indicate such.
    Other vulnerable websites include biometrics.gov, fmcsa.dot.gov, and epa.gov.  Unvalidated redirects linked from these government websites include sites for pornography, weight-loss site, and even a Bible study.  Despite the obvious opening provided for phishing, no actual examples of linked phishing sites were found during the investigation for this story, although phishing attempts are often made via unsolicited mass emails.  In any case, David Kennedy of the information security company TrustedSec,asked to comment for this story, said that these unvalidated redirects are "definitely an exposure."
    The House of Representatives is a good example of a government site that not only has a stronger disclaimer on its exit page, but disallows users from substituting a different web address in its exit URL.  For instance, Rep. Paul Ryan recently linked to a John McCormack piece at THE WEEKLY STANDARD.  The exit page informs users that they are leaving the House website, and users must manually click on the link before being redirected instead of the redirect happening automatically. Additionally, users are told that "Neither the House office whose site contains the above link, nor the U.S. House of Representatives is responsible for the content of the non-House site you are about to access."  Furthermore, an attempt to change the redirect address to a different site or page is met with a "File Not Found" error.
    The unvalidated redirect exposure is an unsophisticated yet effective tool for scammers.  No hacking is required as the referring websites do not actually host any unauthorized pages, but the simplicity actually works to the advantage of potential scammers or those simply seeking to direct additional traffic to their websites.  On the upside, the simplicity also means a relatively simple fix at the affected websites.  But until more government websites follow the example of the House or the Centers for Medicare and Medicaid Services, the unvalidated redirect will remain a prime opportunity for marketers or scammers looking to trade on the authority and sense of security conferred by a connection to the federal government.


Note: A version of this post first appeared at The Weekly Standard.

Friday, February 21, 2014

Widespread Vulnerability Found in Dozens of Government 'Open Data' Websites [Updated]

    At first glance, a page on the Health and Human Services (HHS) website seems to be giving that agency's official advice on the "The Health Benefits of Nootropics," a classification of purportedly memory-enhancing drugs.  The page is found on the website's subdomain of the Assistant Secretary for Planning and Evaluation (ASPE) as part of the Health System Measurement Project.  The page contains the official logo of HHS, the domain in the URL ends with the legitimate HHS address containing "hhs.gov", and the "https://" indicates the connection is even a secure one.  Further down the page, there is even a link to a website selling related products.  A partial screenshot of the profile page at HHS.gov appears as follows:



    Similar pages on the site offer information and counsel on shampoo, surgery, and health issues suffered by computer users.  However, in spite of all the apparently reassuring elements and features of these pages, Health and Human Services had nothing to do with their creation or content, and does not recommend or endorse either the information or the linked products.
    Nevertheless, while the pages are not official HHS information, neither are they technically cases of hacking.  Rather, the creators have exploited a weakness in the "open data" system used by dozens of government websites.  The platform was developed by a company called Socrata.  The system allows users to create profiles and then manipulate data tables that various governments (federal, state, local) host on their websites.  The results can be shared with others for statistical analysis, research, and other purposes, as some users have done. However, in cases like the ones above, a profile page itself can be used to promote a product or information in a way that gives viewers the impression that the host government entity approves or even endorses.  A legitimate looking link could even be included in an email to direct recipients to what they may easily perceive as government-provided information.
    THE WEEKLY STANDARD first reported this opening in January when some internet marketers had created profiles at data.healthcare.gov, the federal government's Obamacare website.  Within a day  after the story ran, Healthcare.gov disabled public access to profiles created for its data site.  At the time, David Kennedy, the CEO of TrustedSec, an information security firm, remarked that the opening could allow scammers to fool users with a "website that’s legitimate to make them believe its something else," and that "an attacker can basically create a functioning website and host any content they want there and under the umbrella of healthcare.gov."
    Use of the profiles can be especially effective since the profiles contain no disclaimers that the government entity does not endorse the content, and there are no warnings when clicking on links that "you are now leaving the website for an external site", a common warning on government sites.
    Health and Human Services is not the only government agency at risk.  The White House announced "Project Open Data" in May 2013 with dozens of federal agencies and sub-agencies taking part.  As recently as January 14, the White House released a Fact Sheet on the White House Safety Datapalooza,  an initiative to safeguard government data that is "part of the Administration’s larger commitment to unleash the power of open data."
    Other examples of profiles such as the one above are numerous, including other federal agencies, plus state, county and local governments.  The products and information being pushed range from private loans to debt consolidation to even "artificial turf":











    Each of the pages above (and dozens of others discovered in the preparation of this story) contains a link to an external website that is obviously not an officially sanctioned site by the government host, but neither are there any disclaimers to warn potential viewers.  The pages appear to violate the Terms of Service of the Socrata platform since "[u]nsolicited promotions, political campaigning, advertising or solicitations" are prohibited.
    More malicious sites could be used for data harvesting or even identity theft since scammers are able to trade on the credibility conferred by the official government websites that host these profile pages.  THE WEEKLY STANDARD has no direct evidence that such activity has yet taken place via an "open data" website, but at this point, clearly the door is wide open to such abuse.  
   An email to an official at Data.gov seeking comment was referred to another official who has not yet responded.  An emailed request to Socrata for comment was initially returned Tuesday evening with a promise of a response, but so far, no additional response has been received.

UPDATE: By the end of the day on Thursday, public access to Socrata profiles had been disabled.  Clicking on links to the profiles now redirect users to a login page.  Neither the government nor Socrata ever acknowledged the vulnerability nor issued any statement regarding the issue despite earlier promises to respond.  Tim Cashman, a Senior Content Strategist at Socrata, initially responded to an email Tuesday night with a promise to "be in touch with a response shortly", and Steven Gottlieb, a Socrata PR contact, and Bill Glenn, VP of Marketing, were both cc'd on his reply.  Several followup emails to all three Socrata representatives, however, were ignored.


Note: A version of this post, before the update, first appeared at The Weekly Standard.

Wednesday, February 12, 2014

Feds' Climate Change Website Hacked By Online Drug Seller

    The website of the U.S. Global Change Research Program (USGCRP) was repeatedly hacked on Monday and Tuesday this week by an online drug retailer.  A Tuesday Google search of the site, www.globalchange.gov, revealed dozens of pages hawking everything from Xanax to Levitra to Ambien. A partial list is shown in the screen grab below:


    Clicking on the links immediately redirected users to a website called "HealthLife", which bills itself as "the leader in delivering medications throughout the world".  The site appears to be registered in the United States:



    While the links were redirects, a cached page (no longer available) revealed that the Global Change site itself contained unauthorized pages as well, such as this one:


    By Tuesday afternoon, the hacking had apparently been discovered and the unauthorized pages were deleted.
    The U.S. Global Change Research Program identifies itself as dealing not only with climate change, but "land productivity, oceans or other water resources, atmospheric chemistry, [and] ecological systems":
The U.S. Global Change Research Program (USGCRP) is a Federal program that coordinates and integrates global change research across 13 government agencies to ensure that it most effectively and efficiently serves the Nation and the world. USGCRP was mandated by Congress in the Global Change Research Act of 1990, and has since made the world’s largest scientific investment in the areas of climate science and global change research.
    An email to the USGCRP requesting comment has not yet been returned.


Note: A version of this post first appeared at The Weekly Standard.

Friday, January 24, 2014

Security Expert: Attacker Can Host Any Content Under Healthcare.gov Umbrella

    A security expert who has testified before Congress and spoken in the media about vulnerabilities in the Healthcare.gov website has weighed in on the website's latest security issue, which was first reported Thursday by THE WEEKLY STANDARD.  David Kennedy, the CEO of TrustedSec, an information security firm, said that the unintended opening at Healthcare.gov detailed in Thursday's story would allow malicious scammers to fool users with a "website that’s legitimate to make them believe its something else."  He said the existence of this potential pitfall on the site is "absolutely amazing," and added that "an attacker can basically create a functioning website and host any content they want there and under the umbrella of healthcare.gov."
    At issue is the profile feature of the data.healthcare.gov section of the website that allows anyone to set up a custom made page intended to host "data-sets" based on the insurance plan information database on the website.  Users can sort, group and otherwise manipulate the data to create unique presentations based on various criteria.  However, the lack of disclaimers and other safeguards allow marketers, or worse, scammers and identity thieves, to establish what appears to be legitimate Healthcare.gov webpages which can be used to redirect users to other sites.
    A fuller explanation of the problem, complete with examples of offending profiles, can be found in Thursday's story; but an example of how the profile feature can be misused was set up for this story and can be seen here:


    The feature even made it possible to upload a clipping of an actual Healthcare.gov graphic to give the page an even more genuine look.  Experienced users of the data-set feature would not be fooled, but unsuspecting users directed to the page by a link beginning with "https://data.healthcare.gov" contained in an email or another website could easily be duped into believing they had accessed a government sanctioned webpage.  Links contained in the profiles contain no disclaimers or warnings and could be used to redirect users to sites where personal and financial information could be harvested.
    TrustedSec's Kennedy noted that by Friday morning, the ability to create a data-set profile via the Healthcare.gov website had been removed since the original story ran on Thursday. However, he pointed out that this may not solve the problem.  Profiles can still be set up at opendata.socrata.com, the website that facilitates the data-set function for Healthcare.gov.  It is not clear at this time, however, if those new profiles can be accessed publicly with a data.healthcare.gov address.  Accounts set up before Friday are still accessible at Healthcare.gov.
    Kennedy also pointed out that other profiles have been set up for simply comic purposes at the site.  One is titled The Bieb, complete with Justin Bieber's recent mug shot.  Another is called William "I love bacon" Shakespeare with a picture of the bard looking quite shocked.  However, the real possibility of innocent users of Healthcare.gov having their personal information or identities stolen is no laughing matter.  The longer the profile feature remains inadequately safeguarded and monitored, the more likely that someone simply looking for health insurance will get far more, or rather lose far more, than he bargained for.


UPDATE: Shortly after this story posted Friday morning, Healthcare.gov disabled access to all data-set profiles.  Attempts to view a profile are redirected back to data.healthcare.gov.  However, cached pages of the profiles are still available at archive.org, such as here and here.


Note: A version of this post first appeared at The Weekly Standard.

Thursday, January 23, 2014

Opportunistic Marketers Exploit Opening at Healthcare.gov

    At least three marketers of health-related or insurance products and services have taken advantage of the "data-set" feature at Healthcare.gov to give themselves a virtual presence on the federal government's Obamacare site.  The ability to use a web address containing "healthcare.gov" may lend credibility and even imply endorsement by the government.  An informational website about schizophrenia called Schiz Life and a company hawking an anti-wrinkle skin product called Vivexin have both used the "profile" feature of data.healthcare.gov to introduce users to their services and products, as well as direct users to their respective websites.  A third profile even offers "universal life insurance" from No Exam Insurers.
    Here is an example of one of the profiles in question:


    The information is presented in a rather clinical fashion, but all the profiles contain links further down on the pages that direct users to websites where more information is given and, in some cases, products can be ordered.  There is no disclaimer anywhere on the profile pages that the information presented is not endorsed by Healthcare.gov, nor is there the customary warning found on many government websites that the pages contain "an external link that is not the responsibility of, or under the control of" the federal government.  
    The addresses of all three profile pages begin with "https://", which indicates a secure browser connection, providing further reassurance that the pages are a legitimate offering of the Obamacare site.  The "https://" is followed by "data.healthcare.gov", which is the domain also used for legitimate and intended purposes by the site's administrator and other registered users.  Thus, anyone could set up a similar profile (conceivably with more malicious purposes than these three sites appear to have) and proceed to advertise their data.healthcare.gov link on another website or in an email.  The Healthcare.gov address could easily influence the uninformed to believe that they are accessing government-sponsored webpages, leaving them wide open to "phishing" attacks where identity thieves extract personal and financial information from the unsuspecting.
    The three profiles described above appear to violate the terms of service of data.healthcare.gov which prohibits "Unsolicited promotions, political campaigning, advertising or solicitations."  However, at least one of the profiles has been around for weeks, possibly longer.  Also, there is evidence that a fourth profile promoting an anxiety-reducing and/or weight-loss product has been directly linked to by external websites.
    The "data-set" feature of Healthcare.gov was established to allow users to sort and present the health insurance plans and data used by the site in various ways that might be helpful to those looking for a plan or those researching trends and patterns in the health insurance marketplace.  The site provides details of the different ways the data can be manipulated and even published.  There are a number of apparently legitimate users who have established profiles and created their own data sets.  The profiles even include social-media-type features such as photos and "followers."  But as is the case everywhere on the internet, without adequate safeguards and monitoring, there are always those who will subvert the intended purpose of a given website if given an opening.  As the cost of Healthcare.gov approaches half a billion dollars, it is clear more money is not always the answer.  When it comes to earning the trust of the public, Healthcare.gov obviously has more work to do.


Note: A version of this post first appeared at The Weekly Standard.

Tuesday, December 10, 2013

HHS Document: Cyber Threat Monitoring Increased 500% in Eight Months

    Concerns have increased over the security of personal information collected by the Department of Health and Human Services (HHS) as the volume of personal data has multiplied dramatically with the implementation of the Affordable Care Act, or Obamacare.  Security experts have testified before Congress about flaws they have uncovered at Healthcare.gov, and various press reports have related other potential problems with the website or with information flowing to the Federal Services Data Hub that could be exploited by hackers and identify thieves.  An HHS document dated December 5 describing a more than 500% increase in the monitoring of cyber threat indicators since April 2013 may only increase those concerns.
    The document states that the agency's Computer Security Incidents Response Center (CSIRC) has experienced more than a five-fold increase in the number of "indicators" monitored by the center in just the last eight months alone.  To cope with the potential threats from this vast increase in data, HHS intends to negotiate a sole-source contract to Cyber Squared, an Arlington, VA, cyber security firm after allowing less than four days (including a weekend) for responses from other interested firms, and even explicitly states that HHS is not soliciting competitive quotations.  HHS describes the apparently urgent need for upgraded threat monitoring as follows:
In the past eight months the number of indicators monitored by the CSIRC has grown well over 500 percent. With the inclusion of the federal Healthcare Threat Operations Center (HTOC) information sharing data from HHS CSO, VA-Network Security Operations Center (VA-NSOC), and the Space and Naval Warfare NSOC for Medical Health Systems (SPAWAR NSOC (MHS), the ability to analyze and correlate this much data requires the use of Threat Connect to be effective and efficient in combating cyber threats. This capability will allow for the joint collection and tracking of internally and externally derived indicators more efficiently as well as facilitate the analysis and correlation of a threat.
    Some of the terminology used in this document raises questions about the scope of the monitoring. For instance, although the document references the "Healthcare Threat Operations Center (HTOC)", the federal government's 2013 Information Sharing Services annual report to Congress makes no mention of the HTOC among the five Federal Cybersecurity Centers, nor is there any other reference to a "Healthcare Threat Operations Center" on the HHS website or any other government website.  References to each of the other potential data sources can be found on various government websites and documents.
     The notice regarding ThreatConnect was posted by HHS at 3:42 PM on Thursday, December 5, and stated that responses would be needed by 8:00 AM, Monday, December 9.  The documentation accompanying the notice does not explicitly mention the Affordable Care Act or Healthcare.gov, but emails sent Thursday to the listed contracting officer and the HHS press office requesting clarification have not been returned.


Note: A version of this article appeared first at The Weekly Standard.

Saturday, November 30, 2013

Report: Security Concerns at U.S. Embassy in Belarus

    The terrorist attack against the U.S. diplomatic post in Benghazi, Libya on September 11, 2012, awakened renewed interest in the security of overseas consulates and embassy facilities.  A recent report by the State Department's Office of the Inspector General spotlights some major concerns regarding the safety of American diplomats and staff in Minsk, Belarus, as well as the security of communications.  The report notes that some progress has been made during the last year, but more remains to be done.
    The report lays out the difficult conditions for the diplomatic mission in Belarus, noting that to visit the "Embassy Minsk is to step back in time to an era when American diplomats in Eastern Europe operated in inhospitable environments."  The government of Belarus is often hostile and imposes severe restrictions, including a five-person limit on American staff.  This has produced a ratio of five Americans to 119 locals staff members, too high by normal standards, and has also resulted in the five Americans (down from 35 in 2008) serving long hours and often double duty.  The limit remains despite assurance from the Belarus government that it was only temporary, and is largely responsible for the staff's inability "to comply with numerous security, consular, information technology, reporting, and management requirements..."
    The American staff is generally praised by the Inspector General for excellent work and ingenuity under difficult conditions.  For instance, the report relates an incident where consul foiled "the kidnapping of an American citizen by repeatedly calling his cell phone until the kidnappers, alarmed by the U.S. Government label appearing on his phone’s screen, released him unharmed." Additionally, the chargé d’affaires is credited with improving security since arriving in 2012:
The chargé has also reinforced embassy security measures. When he arrived at post in 2012, access control was haphazard. Badges were not issued to visitors, and the local guard force used familiarity as a criterion for granting personnel access to the compound. The chargé and management officer/post security officer moved quickly to implement the required access control policy and procedures. The chargé has also worked with the Kyiv-based RSO to enhance mission security.
   Security concerns, however, remain as noted elsewhere in the report:
The 2012 chief of mission controls statement of assurance noted that a physical security survey has not been performed within the past 3 years. As discussed earlier in the report, there are serious facilities, [portion redacted] deficiencies that did not appear in the 2012 statement. The OIG team stressed that, in preparation for the 2013 statement, it is important that the mission review, document, and establish an improvement plan to resolve current deficiencies. 
    Because the main facility (the "chancery") is in a state of disrepair and a $34 million planned renovation is on hold, all embassy business must be conducted from an annex.  This as well as the intrusiveness of the government of Belarus makes conducting private communication virtually impossible.  The report notes that communications security is non-existent:
Embassy Minsk staff members, both American and local, are subject to regular harassment by the Belarusian security services. American staff residences have been entered surreptitiously. The embassy and all U.S. and Belarusian staff are under constant physical surveillance...
The embassy does not have classified communications. Staff members operate on the assumption that everything sent on unclassified systems or spoken on the telephone is monitored by Belarusian security services and other local security agencies.
    Restrictions and sanctions against Belarus by the U.S. and other countries make it important for diplomatic staff to keep a close eye on visas granted by the embassy:
The United States has also imposed sanctions on Belarus under several additional laws and executive orders, These sanctions include travel and financial sanctions and asset freezes against officials who have undermined democratic processes and against state-owned and other companies that have supported proliferation of weapons of mass destruction or money laundering. The European Union also maintains a broad range of sanctions against individuals and firms. 
    However, the same five-person staff limitation imposed by the host country has caused concerns about visa referrals issued by the embassy:
Senior embassy officials have made inappropriate visa referrals. Host government limitations on American staff numbers in Minsk have forced most Belarusians to apply for visas outside Belarus. With referrals affording the only access to a Minsk interview for many visa applicants, the referral program is unusually vulnerable to misuse.
    Other concerns are raised in the report as well, including one redacted in its entirety, as shown here:


    The State Department, first under Hillary Clinton and now John Kerry, instituted worldwide security reviews of diplomatic facilities after the Benghazi attack and in response to the subsequent report from the Accountability Review Board.  Although some advances have apparently taken place, this report on the Minsk embassy shows that security at foreign facilities is far from ideal.


Note: A version of this article first appeared at The Weekly Standard.

IRS Program Allows Employees to Access IRS Data on Personal Smartphones

    The Internal Revenue Service is conducting a pilot program allowing IRS employees to use personal smart phones to access government email accounts and other work related information.  The program is known as Bring Your Own Device (BYOD), and the Treasury Inspector General for Tax Administration (TIGTA) has raised concerns about the security and cost-effectiveness of the program in a recent report:
TIGTA expressed concern that the IRS allows BYOD devices access to resources on the IRS network in addition to e-mail access. This increases the risk that privacy and taxpayer data could be compromised. TIGTA also raised concerns about allowing devices based on the Android operating system to participate in the BYOD pilot, because these devices are more subject to malware than the Apple devices tested in earlier phases. 
“A Bring Your Own Device program could provide significant benefits and even potential cost savings,” said J. Russell George, Treasury Inspector General for Tax Administration. “However, the IRS must conduct a thorough, realistic cost-benefit analysis before such a program’s benefit can be appropriately ascertained.”
Among the recommendations made by TIGTA are restricting the program to email access only, and delaying Android-device access completely until a risk assessment addressing security concerns is conducted.  The IRS agreed with all of TIGTA's recommendations except the Android device delay.  TIGTA remains unsatisfied with the IRS's response to the findings in the report:
TIGTA believes that some of the corrective actions proposed by the IRS are inadequate because they are contingent on BYOD expansion or additional funding. The relevant controls should be put in place for the existing BYOD effort, which does not have a clear end date and which is being used by hundreds of employees and devices within the production environment.

Note: A version of this article first appeared at The Weekly Standard

Friday, October 4, 2013

HHS-Run Website Hacked; Now Selling NFL Jerseys, Ugg Boots, Armani Fragrances [UPDATED]

    A portion of the website of the Substance Abuse and Mental Health Services Administration (SAMHSA) was apparently hacked as long as two months ago.  SAMHSA is an agency of the Department of Health and Human Services (HHS).  HHS also runs the new Obamacare insurance marketplace, Healthcare.gov.
    Dozens of pages hawking retail merchandise have been uploaded to the SAMHSA site, ranging from NFL jerseys to Uggs shoes to Armani fragrances.  Screen captures of the various pages are shown here:






     Clicking on the pages in some cases takes users directly to an external website; other times, certain functions seem to operate within the samhsa.gov site.  Of the websites investigated, two domains are registered in the United States and one in China.
    All of the instances uncovered by this investigation are under the sub domain nace.samhsa.gov, which is the Native American Center for Excellence.  The first breach discovered dates back to July 29 of this year, and the unauthorized pages are still on the site.
    In September, a portion of NASA's website was hacked by a Brazilian group protesting reports of spying in that country by the National Security Agency.



UPDATE:  Shortly after this story was posted, the site (nace.samhsa.gov) returned an error message saying that the site could not be found.  Later, the following message appeared on the site (misspelling included, [since corrected]): "This site is undgoing maintenance. We are sorry for any inconvenience this has caused you."  Here's a current screen capture:


    While clicking on the original links in the story above return "file not found"messages, at least one of the pages is available via a Google cache here showing how the page appeared as of October 3.  A Google search of the site still turns up dozens of links to other pages from the hacking.  The "undergoing maintenance" message on the SAMHSA website comes in spite of the fact that many government websites have been shuttered or severely limited due to the ongoing federal government shut down.


Note: A version of this article first appeared at The Weekly Standard.

Saturday, August 17, 2013

Health Company Agrees to Pay HHS $1.2M After Security Breach

    Even as questions remain about the security of the Federal Services Data Hub to be used in conjunction with the Obamacare marketplaces beginning October 1st, the Department of Health and Human Services (HHS) has agreed to a settlement with the not-for-profit Affinity Health Plans, Inc., for the company's "potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules."  The case stemmed from a photocopier purchased by CBS News and previously leased by Affinity that still contained sensitive personal health information on up to 344,579 individuals:
Affinity filed a breach report with the HHS Office for Civil Rights (OCR) on April 15, 2010, as required by the Health Information Technology for Economic and Clinical Health, or HITECH Act...   
Affinity indicated that it was informed by a representative of CBS Evening News that, as part of an investigatory report, CBS had purchased a photocopier previously leased by Affinity.  CBS informed Affinity that the copier that Affinity had used contained confidential medical information on the hard drive.
    In addition to a payment of $1,215,780, Affinity must attempt to locate other copiers previously leased to remove hard drives containing additional personal data. 
    The OCR director for HHS stressed that this incident should be a lesson to entities that are responsible for storing and using sensitive data [emphasis added]:
"This settlement illustrates an important reminder about equipment designed to retain electronic information: Make sure that all personal information is wiped from hardware before it’s recycled, thrown away or sent back to a leasing agent," said OCR Director Leon Rodriguez.  “HIPAA covered entities are required to undertake a careful risk analysis to understand the threats and vulnerabilities to individuals’ data, and have appropriate safeguards in place to protect this information.
    This settlement could also put additional pressure on the Obama administration to provide assurance that necessary precautions are in place before the new healthcare exchanges are opened for business.  As John McCormack noted in THE WEEKLY STANDARD earlier this week, Michael Astrue, former HHS general counsel and Social Security commissioner, has warned
that "unless delayed and fixed" the Obamacare exchanges will "inflict on the public the most widespread violation of the Privacy Act in our history."
    It is unclear what if any consequences HHS will be subject to if privacy breaches occur due to inadequate safeguards in the Obamacare marketplaces.


Note: A version of this article first appeared at The Weekly Standard.

Tuesday, August 6, 2013

Security Lapse: White House Posts Details of Obama Trip on Website [TWS]

    Details of President Obama's west coast trip this week, information usually reserved for pre-screened media outlets, were apparently inadvertently posted on the White House website for about 24 hours this weekend before being abruptly removed without comment on Monday morning.
    Last week, White House Press Secretary Jay Carney announced that President Obama would be traveling to Arizona on August 6th for a speech, then on to California on for a TV appearance with Jay Leno, as well as a visit to Camp Pendleton the following day to visit with the troops and their families.  For security reasons, the White House limits the amount of information available in advance of such trips, but members of the press receive more details to allow planning of coverage.  These details are often emailed to reporters, but with the understanding that the extra information will not be publicly disclosed.
    On Sunday, however, the White House posted two detailed releases regarding this week's trips.  Both releases include the warning "FOR PLANNING PURPOSES ONLY, NOT FOR REPORTING." (Images of the releases reproduced below have been truncated to exclude the more sensitive information, and no links to the original documents have been provided.)





    Details not shown above include the gate number at the airport for media check-in; how to request permits for access, including email, phone and fax numbers; estimated times of arrival and departure for Air Force One; and previously unpublished phone numbers and an email address for White House Executive Office of the President personnel involved in logistical planning for such trips.  Also included are some technical details such as "throw" (distance from press area to podium) and "cable run" (distance relating to audio/video feed connections.)
    Although the publication of these details may be a comparatively minor security breach, the timing could not be worse with the Worldwide Travel Alert currently in place.  Fresh concerns about al-Qaeda and possible terror attacks should have all government officials on heightened alert, particularly those responsible for the safety and security of the president.
        The Weekly Standard contacted the White House via email Monday morning about the posting of the two press releases, and within an hour, both were removed from the White House website.  The White House did not respond directly to the email.


Note: A version of this article first appeared at The Weekly Standard.

Tuesday, July 16, 2013

Audit of State Dept.'s 'High Threat Level Posts' Finds 'Common' Security Deficiencies

    Nine months after the terror attacks at a U.S. diplomatic post in Benghazi, Libya, an audit of five "selected high threat level posts" of the State Department by the Office of the Inspector General [OIG] reveals cause for concern.  The report found that the facilities in question failed to comply with current security standards and that "common physical and procedural security deficiencies" were found [emphasis added]:
 The report presents the Office of Inspector General’s (OIG) audit of Department compliance with physical and procedural security standards at selected high threat level posts... 
OIG conducted physical security compliance reviews at the five posts and found that posts were not always in compliance with current physical security standards and that common physical and procedural security deficiencies occurred among the posts reviewed.
    In one case, an increase in personnel actually had a detrimental effect on the implementation of the security plan for the post:
OIG also found that the Chiefs of Mission in two of the selected posts used their National Security Decision Directive 38 authority to increase post personnel levels in alignment with their mission strategic plans. However, personnel levels increased beyond or near the compounds’ intended capacities, and at one post, this increase in personnel negatively affected the implementation of the post security program.
    The full report is not yet posted, and the summary does not reveal the location of the five posts under review.  Of the 24 recommendations made in the report to correct deficiencies, ten are closed or resolved, but fourteen remain "unresolved and require further management action before they can be resolved and closed."


Note: A version of this article first appeared at The Weekly Standard.