All the latest UK technology news, reviews and analysis

US government security data compromised

by Robert Blincoe

28 Jul 2008

Be the first to comment

  • Tweet this
Professor John Walker
Professor John Walker has highlighted inadequate government security

The security of data held by the CIA, the FBI and the US Department of Defense was compromised earlier this year after a partner agency allowed zone transfer access of its Domain Name Services.

Professor John Walker, managing director of forensics consultancy Secure-Bastion, revealed the security blunder during the International Crime Science conference in London last week.

Professor Walker had been testing DNS environments as part of his academic research.

"In one case an organisation in the US, working with some government agencies, allowed me to get into their systems to see their servers named for their clients. Their servers were called 'CIA', 'FBI' and 'DoD'," he said.

Professor Walker confirmed to vnunet.com that these names referred to the actual US law enforcement and defence agencies.

"The DNS is a logical map of all the assets of a company. If you can take the logical map of the assets out (IP addresses, system names) you've got an awful lot of intelligence to work on," he said.

"And you can work quietly because you no longer have to go to the organisation to get the data because it's sitting on your PC."

When Professor Walker reported the security flaw, the organisation said " Thank God you've found it" and closed it down. "I didn't go down any further because I valued my liberty," he said.

"In my work I get the pleasure of seeing other people's systems. I invariably walk away not believing what I've seen. It's not that the criminals are so clever, but that we're so stupid."

The International Crime Science Conference was organised by the Centre for Security and Crime Science at University College London.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Assistant Director - IT Infrastructure - London

Assistant Director - Infrastructure - London - required...

Online Designer

A well established homeware brand is looking for an experienced...

Java Engineer, Real-Time Media, Agile, TDD

Join a team that is revolutionising the way media is...

Linux Server Support Analyst - Bristol/Bath

Linux Server Support Analyst - Bristol/Bath £20,000 plus...

To send to more than one email address, simply separate each address with a comma.