FACEbook

Monday, August 17, 2015

Government Websites Vulnerable to Phishing Scams

     The websites of several federal government agencies, including the National Weather Service (NWS), are unprotected from scammers looking to exploit a security weakness to fool potential victims. The sites in question allow what are known as "unvalidated redirects." An unvalidated redirect is a link to an external website that appears to be sanctioned by the sending website, but in reality can be created by anyone, including scammers and identity thieves. In many cases, the redirects do not even require an additional click; users are taken to the external website automatically after a short pause as an exit message is displayed.
     The website for the National Weather Service, www.weather.gov, has been a favorite target for those seeking to exploit the unvalidated redirect vulnerability. A Google search shows an extensive list of hundreds of websites linked with an automatic redirect. Some are legitimate, such as one on lightning strikes, but more common are those hawking website hosting, insurance, and even herpes cures:

     The links begin with the legitimate address of the National Weather Service, www.weather.gov. Clicking on these links, which can be embedded in other websites or included in an email, first brings up a page alerting users that they are exiting the NWS website and that the link does not constitute an endorsement of the site. However, the page also says, "NWS provides a link to this site because it may contain related information of interest to you." Following is a screenshot of the page that appears for about 10 seconds before, in this case, the user is taken to a video extolling the virtues of a natural cure for herpes:


     This is not the first time the federal government has exposed itself this way. In March 2014, an investigation by THE WEEKLY STANDARD found that the website of the US Senate, along with several others, were susceptible to this vulnerability. Soon after that story was published, the Senate website changed the exit message to include a more explicit warning and also to require an additional click. However, the website script still allows any web address to be entered as a redirect.
     The biometrics.gov website is another favorite platform for those seeking to exploit the unvalidated redirect. This website, pointed out in the 2014 story, is still being utilized more than a year later by dozens of external websites including a Turkish LGBT site, a site for diet pills, a poker blog, a site touting "manly yoga", and even a Bible study.
     Some sites are greater risks than others. For example, a subdomain of the website for the National Institutes of Health (nhlbi.nih.gov) is vulnerable. A malicious programmer could provide users what appears to be a legitimate NIH website address, but use a redirect to a website that could harvest personal and health information from unsuspecting victims. The NIH exit page contains some warnings, but since the page is only visible for 10 seconds before the automatic redirect kicks in, there is too little time to actually read the entire page. Serve.gov is yet another website with a complicated exit page that could misdirect those looking for opportunities for community service to a scammer's site instead.
     Many websites contain links to external sites, but the scripts to handle these links can be configured to prevent this type of manipulation. Due to the presumed authority of government websites, the unvalidated redirect vulnerability is particularly pernicious. The Open Web Application Security Project, a non-profit group that seeks to improve software security, lists the unvalidated redirect in its top ten list of security vulnerabilities, noting that "[w]ithout proper validation, attackers can redirect victims to phishing or malware sites, or use forwards to access unauthorized pages."



Note: A version of this post first appeared at The Weekly Standard.

Hotel for President Obama's Ethiopia Visit Cost $412K

     President Obama visited Kenya and Ethiopia during his recent trip to Africa, and the hotel bill for the president and his entourage totaled approximately $412,390.86 for the Ethiopia stay alone. A contract with the Hilton in the Ethiopian capital of Addis Ababa was posted online Tuesday:


     The president arrived in Addis Ababa on Sunday, July 26 and departed on July 28. The government also spent $7,540 for cell phones for the president's Ethiopia visit. The White House did not respond to a request for an explanation.



Note: A version of this post first appeared at The Weekly Standard.

Thursday, August 13, 2015

Feds Seek Dance, Poetry, Art, Music Therapy For Parolees

     The federal agency that oversees individuals on probation, parole or supervised release in Washington, DC is looking to expand options for "counseling and behavioral interventions" for offenders under its charge. The Court Services and Offender Supervision Agency for the District of Columbia (CSOSA) is seeking a contractor to conduct "expressive therapies" in an "integrated way to foster human growth, development, and healing" to offenders who may also be involved in "group interventions focused on changing criminal thinking, anger management, substance use, education, and employment skills development."
     Contractors offering therapies utilizing art, music, dance, drama, poetry and creative writing are expected to help develop a "variety of verbal and non-verbal expression in order to assist participants in exploring and potentially transforming emotional and social issues" that may be impediments to a successful transition back into society.
     CSOSA has provided extensive descriptions of the therapies under consideration:
Art Therapy - encourages clients to use art media, images, sound, digital photography, videography, computer-generated images, and the creative process as part of a therapeutic process to reconcile emotional conflicts, foster self-awareness, develop social skills, manage behavior, solve problems, reduce anxiety. 
Music Therapy - provides clients with activities geared toward creating music, music production, singing, moving to, and or listening to music.  These activities provide clients with opportunities to express themselves in verbal and non-verbal ways in order to increase motivation to change and engage in activities that promote education or healing. 
Drama Therapy - uses a drama/theater process, products and associations to achieve therapeutic goals.  Drama therapy provides clients with opportunities to tell his or her story to solve a problem, achieve a catharsis, extend the depth and breadth of inner experience, and increase flexibility in ways to address personal challenges. 
Dance/Movement Therapy - uses movement, dance, and other forms of physical activity to help clients draw a connection between body and mind.  These techniques are intended to help clients increase mind-body awareness so that they may use movement to facilitate healthy feeling, cognition, and behavior. 
Poetry/Creative Writing Therapy - relies on reading, discussing, and creating poetry or other forms of literature to help clients gain understanding of their feelings, develop empathy, enhance motivation, clarify personal goals, and identify alternative solutions to common challenges in personal behavior and relationships. 
Integrated arts (also known as multimodal) therapy - involves two or more expressive therapies to foster awareness, encourage emotional growth, and enhance relationship with others.  While it emphasizes the interrelatedness of the arts, it integrates a variety of activities that may consist of any of the aforementioned types of expressive therapy.
     CSOSA is an executive branch agency that handles offender supervision for Washington, DC, coordinating with the DC Superior Court and the US Parole Commission.



Note: A version of this post first appeared at The Weekly Standard.

Old Fashioned Crime: One-Quarter of Federal 'Security Incidents' are Non-Cyber

     While cyber-security incidents and computer system breaches such as the recent Office of Personnel Management (OPM) hack grab the headlines, a recent government reports shows that more mundane non-cyber incidents have skyrocketed as well. A graphic in a recent Government Accountability Office (GAO) report illustrates that a full 25% of "Information Security Incidents" are actually non-cyber in nature. This percentage represents 16,879 incidents in 2014 alone:



     When asked to explain the nature of these "non-cyber" incidents,  Gregory C. Wilshusen, Director, Information Security Issues for the GAO told THE WEEKLY STANDARD [emphasis added]:
The non-cyber incidents are those pertaining to the spillage or mishandling of personally identifiable information which involve hard copies or printed material as opposed to digital records. While my statement focused on cyber threats, it also touched upon data breaches which can be effected through cyber and non-cyber means.
     The GAO report indicated that in 2006, the total number of "information security incidents reported by federal agencies" (cyber and non-cyber) were 5,503. (The breakdown of cyber versus non-cyber for 2006 was not available.) But even using these figures, the number of non-cyber incidents alone in 2014 (16,879) is more than three times the total number of security incidents in 2006.
     Although cyber incidents have the potential to do widespread damage due to the nature of computer-based crime, the rapid increase in paper-based incidents involving personally identifiable information is worrisome as well. As bureaucrats and policy makers focus on high-tech mischief and crime, a growing number of criminals appear to be content to steal information the old fashioned way.


Note: A version of this post first appeared at The Weekly Standard.

Tuesday, August 11, 2015

Had Unprotected Sex? Planned Parenthood Will Pay You $70...And You Could Win $500!

   Although Planned Parenthood's most recent controversy revolves around "fetal tissue" trafficking, the organization is no stranger to eyebrow-raising activities. A recent solicitation for participants for Planned Parenthood's Sexual Health Evaluation (SHE) study promised at least $70 with a chance to win up to $500. Interested parties who had had unprotected sex were encouraged to visit the website to "get the deal on what the study is all about, the gift cards you'll earn, and how you can win additional big prizes — then sign up and get started!"
     Although enrollment for the study is now over (2,317 participants signed up), Planned Parenthood used the following page to invite site visitors to learn more about the study:


    Clicking through to learn more presented potential participants with a video explaining the study and the various incentives, including cash prizes and gift cards for retailers such as Apple, Starbucks, Target and H&M.


     The entire video can be seen here:



     The study, as the acronym SHE indicates, is targeted at women. Although the solicitation refers to "unprotected sex", the scope of the study covers all of Planned Parenthood's online resources and seeks to learn through four 10-minute surveys over three months how women use those resources:


     Planned Parenthood assures participants that the organization will keep "personal health information... 100% private", promising to "do everything we can to keep others from learning about your participation in this study" through the use of identifying code numbers.
     The study is a joint project of Planned Parenthood and New York University Silver School of Social Work. Two drawings were planned for the contest portion of the study, one in the Spring/Summer of 2015 and the second for Fall/Winter 2015.

Note: A version of this post first appeared at The Weekly Standard.

Feds Spend $7,540 for Cell Phones For President Obama's Trip to Ethiopia

     When the president of the United States travels, the White House and the Secret Service bring along a tremendous amount of communications equipment. Not only does the Secret Service set up a command post to coordinate communications for the visits, but secure connections are also needed for the president to keep in touch with Washington and the military around the world in case of emergencies. Despite all of these arrangements, however, a total of $7,540 was spent for foreign-made cell phones for President Obama's recent trip to Ethiopia.
     The phones were obtained via a contract signed on July 13, 2015 with a company in Ethiopia identified only as "Miscellaneous foreign awardees", the typical identifier for many overseas contracts with the US government. The contract was handled by the State Department through the US embassy in Addis Ababa, the capital of Ethiopia. A compilation of screenshots from the contract is shown here:


     It remains unclear exactly who used the cell phones during the Ethiopia visit, or what happened to the phones when the visit was over. After an initial response from the press office of the State Department about the contract, a state department spokesperson subsequently deferred to the White House, saying, "After speaking with my colleagues we think you should contact the WH Press Office for any comment on the President’s trip to Ethiopia."
     The White House press office did not respond to a request for an explanation of the cell phone contract.

Note: A version of this post first appeared at The Weekly Standard.

Sunday, July 12, 2015

Day Before Hack Announced, OPM Released 'Sexual Orientation and Gender Identity Discrimination' Guide

     The day before the Office of Personnel Management first announced a massive data breach of personal information, now former OPM director Katherine Archuleta's attention was focused elsewhere. Archuleta published a blog post on June 3 entitled "Celebrating Every Member of Our Federal Family" in recognition of "LGBT Pride Month." The White House reposted Archuleta's article the same day.
     In her post, Archuleta announced the release of an updated guide called "Addressing Sexual Orientation and Gender Identity Discrimination in Federal Civilian Employment: A Guide to Employment Rights, Protections, and Responsibilities."
 

As we celebrate LGBT Pride Month, I want to proudly reinforce my continued commitment to the lesbian, gay, bisexual, and transgender members of our federal family, and recognize the incredible contributions this community has made in service to the American people...

That’s why I’m so excited to announce that the Office of Personnel Management is joining our partners at the Equal Employment Opportunity Commission, the Merit System Protections Board, and the Office of Special Counsel to release an updated guide titled “Addressing Sexual Orientation and Gender Identity Discrimination in Federal Civilian Employment: A Guide to Employment Rights, Protections, and Responsibilities.” This informative resource will help LGBT federal employees make more informed choices about how best to pursue their individual claims when they believe they have suffered from discrimination.
    On the OPM website, the agency has seven "top priorities" listed. The first two are "Honoring the Workforce" and "Build a More Diverse and Engaged Workforce". Number four on the list is "IT Improvement" to "streamline and update IT systems" and number five is "Background Investigations" to "lead efforts to strengthen the background investigations program across government." The priorities list does not include any direct references to "security."
    When reporters questioned White House Press Secretary Josh Earnest on June 17 about calls for Archuleta's resignation over the data breach, Earnest said that Archuleta had made cyber security a priority and that the president had "confidence" in her to do the job:
[T]his is an issue that they’ve been working on for some time; that Director Archuleta, in one of her first priorities that she identified after taking that job, was to upgrade the OPM computer network, particularly their cyber defenses.  And this is obviously an ongoing process, and the President does have confidence that she is the right person for the job...
OPM, under the leadership of Director Archuleta, recognizes that this does need to be a priority and that there is significant and important work that needs to be done to make sure that they’re fulfilling their responsibility to protect the data of federal workers... 
[A] number of senior White House officials have been in touch with the senior leadership at OPM.
     As further information came to light that the OPM breach was far worse than first revealed, Director Archuleta initially said she had no intention of resigning (via Federal Times):
"When I took office in late 2013, one of my priorities was to upgrade OPM's antiquated legacy systems," she said during a call with reporters Thursday. "It is because of the efforts of OPM and its staff that we've been able to identify the breaches."
      Friday, however, news broke of Archuleta's resignation.



Note: A version of this post first appeared at The Weekly Standard.