Privacy Digest

News that can impact your privacy.
Login/Register
What is OpenID?
  • Log in using OpenID
  • Cancel OpenID login
  • Create new account
  • Request new password
Home Blogs MacRonin's blog
    • FAQ
    • Wishlists
    • Contact
    • Categories/RSS

Bookmark Us

Bookmark Privacy Digest 
Bookmark This Page 

Syndicate

Syndicate content
more

Advertisements

Tracking System
Tracking System
Private Detectives
Quality Security Services in California
Fleet Management
Hosting

Popular content

Last viewed:

  • Rulings Leave Online Student Speech Rights Unresolved
  • Do We Really Need a Security Industry?
  • Big Brother! ActyMac DutyWatch spies on your employees
  • TSA Launches Blog To Reach Out to Shoe-Removing Travelers
  • The Android fine print: Kill switch and other tidbits
  • CFP mentions some Functioning Iran proxies
  • Boston Subway Board Member Delivers Scathing Criticism -- "System Is a Mess"

tags in Topics

Activists Alert Anonymity Companies Congress Copyright Court (US) Databases Data Mining Editorial EFF Entertainment Exploits Fourth Amendment Government Hmmm ID Infrastructure Law Enforcement Laws Politics Privacy Remember Reports Rights Security Spin Zone Surveillance Telecommunications Tracking
more tags

View blog authority
Congressional Research
Broadcast Flag

Critical FBI Network Full of Security Holes, Government Auditors Report

Submitted by MacRonin on June 13, 2007 - 8:35pm
  • Government
  • Hmmm
  • Law Enforcement
  • Politics
  • Privacy
  • Remember
  • Reports
  • Security
  • Software

Critical FBI Network Full of Security Holes, Government Auditors Report: "A critical'FBI communications network containing sensitive law enforcement and investigative data is rife with security flaws and is vulnerable to attacks from outsiders and insiders alike, according to an audit released Thursday by the Government Accountability Office.

The unnamed network is'part of the long delayed and scandal plagued Trilogy system that the FBI wants to replace its network of computers and networks,' which for years was so bad that agents reportedly couldn't email one another.

System administrators have failed to keep obsolete software off the network, patch computers quickly, ensure passwords and data are strongly encrypted, log and audit security events'and prevent insiders from having more privileges than necessary for their job, according to the audit (pdf).' The report explicitly refers to rogue former agent Robert Hannsen, who misused his insider access to sell government secrets for years to the Soviets.

Ineffective controls threaten the confidentiality, integrity, and availability of the sensitive law enforcement and investigative information transmitted by the critical internal network. Certain information security control weaknesses existed in network devices and services, identification and authentication, authorization, cryptography, audit and monitoring, physical security, and patch management. The bureau’s lack of a comprehensive inventory of the current network operating environment— an enterprise wide view—compounds the effect of these weaknesses.[...] These weaknesses leave the bureau vulnerable to insider threats.

For its part, the FBI's Deputy Chief Information Officer Dean Hall'agrees'the FBI'needs to make some changes, but contends it mostly all good.

'The FBI does not agree that it has placed sensitive information at an unacceptable risk for unauthorized disclosure, modification, or insider threat exploitation,' Hall wrote'in response to the report.

(Read Original Article - Via Threat Level.)

Bookmark/Search this post with:
  • Twitter Twitter
  • Digg Digg
  • StumbleUpon StumbleUpon
  • Technorati Technorati
  • del.icio.us del.icio.us
  • Facebook Facebook
  • Furl Furl
  • LinkedIn LinkedIn
  • Yahoo Yahoo
  • MacRonin's blog
  • Add new comment

Recent blog posts

  • FBI Hoaxes Boost Online Fraud
  • NetFlix Cancels Recommendation Contest After Privacy Lawsuit
  • Advertising - Instant Ads Set the Pace on the Web
  • Best Practices for Government Datasets: Wrap-Up
  • TJX Hacking Conspirator Gets 4 Years
  • The Beginning of the End of Data Retention
  • Wanted: Trust Detector
  • Wikibooks Cryptography Textbook
  • Feds: TSA Worker Tried to Sabotage Terror Database
  • Hi-tech governments growing keener on snooping, says report
more

Performancing Metrics

Compilation © Copyright 1997-2010 Paul Hardwick, with Web Hosting provided by MacRonin.com.