Domain: fcw.com
Stories and comments across the archive that link to fcw.com.
Stories · 46
-
Library of Congress Hit With a Denial-Of-Service Attack (fedscoop.com)
An anonymous reader writes: The Library of Congress (LOC) announced via Twitter Monday that they were the target of a denial-of-service attack. The attack was detected on July 17 and has caused other websites hosted by the LOC, including the U.S. Copyright Office, to go down. In addition, employees of the Library of Congress were unable to access their work email accounts and to visit internal websites. The outages continue to affect some online properties managed by the library. "In June 2015, the Government Accountability Office, or GAO, published a limited distribution report -- undisclosed publicly though it was sourced in a 2015 GAO testimony to the Committee on House Administration -- highlighting digital security deficiencies apparent at the Library of Congress, including poor software patch management and firewall protections," reports FedScoop. -
Not Just Healthcare.gov: NASA Has 'Significant Problems' With $2.5B IT Contract
schwit1 writes "According to the Inspector General, NASA and HP Enterprise Services have encountered significant problems implementing the $2.5 billion Agency Consolidated End-User Services (ACES) contract, which provides desktops, laptops, computer equipment and end-user services such as help desk and data backup. Those problems include 'a failed effort to replace most NASA employees' computers within the first six months and low customer satisfaction,' the report states (PDF). It adds that NASA lacked the technical and cultural readiness for an agencywide IT delivery model and did not offer clear contract requirements, while HP failed to deliver on multiple promises." -
Public Clearinghouse Proposed For Evoting Failures
Hugh Pickens writes "Alice Lipowicz writes in Federal Computer Week that Lawrence Norden, senior counsel to the Brennan Center for Justice at New York University School of Law, has reviewed hundreds of reports of problems with electronic voting systems during the last eight years. He is recommending a new regulatory system with a national database, accessible by election officials and others, that identifies voting system malfunctions reported by vendors or election officials and new legislation that requires vendors report evoting failures to the clearinghouse. 'We need a new and better regulatory structure to ensure that voting system defects are caught early, officials in affected jurisdictions are notified immediately, and action is taken to make certain that they will be corrected for all such systems, wherever they are used in the United States,' writes Norden. Adding that election officials rely on vendors to keep them aware of potential problems with voting machines, which is often done voluntarily and that voting system failures in one jurisdiction tend to be repeated in other areas, resulting in reduced public confidence and lost votes." -
Gov't App Contests Are Cool, But Are They Useful?
theodp writes "In 2008, Washington, DC, launched one of the hotter trends in public-sector technology: the 'apps contest'. But even as more jurisdictions jump on the bandwagon, the contests are reportedly producing uneven results, and the city that started it all is jumping off the bandwagon. 'I don't think we're going to be running any more Apps for Democracy competitions quite in that way,' says Bryan Sivak, who became the District's CTO in 2009. Sivak calls Apps for Democracy a 'great idea' for getting citizen software developers involved with government, but he also hints that the applications spun up by these contests tend to be more 'cool' than useful to the average city resident. 'If you look at the applications developed in both of the contests we ran, and actually in many of the contests being run in other states and localities,' Sivak says, 'you get a lot of applications that are designed for smartphones, that are designed for devices that aren't necessarily used by the large populations that might need to interact with these services on a regular basis.' Sivak also cited maintenance of the new apps over the long term as a concern." -
US Government Begins Largest IT Consolidation in History
miller60 writes "Saying 1,100 data centers is too many, the federal government has begun what looms as the largest IT consolidation in history. Federal CIO Vivek Kundra has directed federal agencies to inventory their assets by April 30 and prepare a plan to reduce the number of servers and data centers, with a focus on slashing energy costs (full memo). Kundra says some applications may be shifted to cloud computing platforms customized for government use." -
VA Mistakenly Tells Vets They Have Fatal Illness
An anonymous reader writes "Thanks to a computer glitch and bad diagnosis coding, the VA sent a letter to thousands of veterans telling them they have Lou Gehrig's Disease. Some were right, but many were mistakes. From the article, 'Recently, the VA determined ALS to be a service-connected disability and generated automatic letters to all veterans whose records included the code for the disease. However, since the coding contained both ALS and undiagnosed neurological disorders, some of those letters were erroneous.'" -
US Dept. of Defense Creates Its Own Sourceforge
mjasay writes "The US Department of Defense, which has been flirting with open source for years as a way to improve software quality and cut costs, has finally burst the dam on Defense-related open-source adoption with Forge.mil, an open-source code repository based on Sourceforge. Though it currently only holds three projects and is limited to DoD personnel for security reasons, all code is publicly viewable and will almost certainly lead to other agencies participating on the site or creating their own. Open source has clearly come a long way. Years ago studies declared open source a security risk. Now, one of the most security-conscious organizations on the planet is looking to open source to provide better security than proprietary alternatives." -
Is There a Cyberwar, and Is the US Losing It?
kenblakely writes "BusinessWeek is running a story asserting that the 'US is Losing the Global Cyberwar.' This whole cyberwar thing has been discussed a few times on Slashdot where the Chinese are asserted to be using cyberwarfare to attain military superiority. And, of course, there is the whole Russia-Georgia thing. Even the US military is getting in on the action, and the fear of a cyber Pearl Harbor seems almost palpable. I'm curious what the Slashdot crowd thinks about the growing fascination with 'cyberwar': hype to get more money and create new force structure, source of the next world war, or somewhere in between?" -
McCain Releases Technology Platform
I Don't Believe in Imaginary Property writes "John McCain has finally released a technology platform. Most of it is the same old stuff; lower corporate taxes, protect children from porn, and avoid Internet regulation unless 'necessary.' Alas, in his view, helping the RIAA's War on Sharing is necessary to stop the 'global epidemic' of piracy, while Net Neutrality is something he 'does not believe in.' Ars Technica has a review of McCain's platform." A brief analysis is also available from Federal Computer Week. In addition to the technology policy, McCain has also released a paper describing his stance on security and privacy. We've previously contrasted his views with those of Barack Obama. Obama's technology policies are also available online. -
NASA Employee Suspended For Blogging At Work
BobJacobsen writes "FCW has an article about a NASA employee that was suspended for blogging on government time. Seems the unnamed employee's 'politically partisan' blog entries were a violation of the Hatch Act. The article ends with a chilling quote from the government's Special Counsel in the case: 'Today, modern office technology multiplies the opportunities for employees to abuse their positions and — as in this serious case — to be penalized, even removed from their job, with just a few clicks of a mouse.'" Thing is, he was soliciting campaign donations and writing partisan stuff. -
Air Force to Get "Cyber Sidearms"
mlbtaz writes to mention that techs working on Air Force networks will soon be getting "cyber sidearms" to help alert them to potential security breaches. "The tool could be a small piece of software installed on Air Force computers or it could be a simple mechanism for taking a screenshot and relaying it to security experts, said Maj. Gen. William Lord, who will soon take command of the Air Force's provisional Cyber Command. In an interview this week, Lord said service officials have not made a final decision about which technology they will use for the program. " -
Chinese Hack Attacks on DoD Networks Coordinated
An anonymous reader writes " The Naval Network Warfare Command says that Chinese hackers are relentlessly targeting Defense Department networks with cyber attacks. The 'volume, proficiency and sophistication' of the attacks supports the theory that the attacks are government supported. The motives of the attacks emanating from China include technology theft, intelligence gathering, exfiltration, research on DOD operations and the creation of dormant presences in DOD network for future action. Onlookers warn that current US defenses against these attacks are 'dysfunctional', and that more aggressive measures should be taken to ensure government network safety." -
Department of Defense Now Blocking HTML Email
oKAMi-InfoSec writes "The Department of Defense (DoD) has taken the step of blocking HTML-based email. They are also banning the use of Outlook Web Access email clients. The DoD is making this move because HTML messages can easily be infected with spyware and executable lines of code that enable hackers to access DoD networks, according to an article in Federal Computer Week by Bob Brewin . A spokesman for the Joint Task Force for Global Network Operations (JTF-GNO) claims that this is a response to an increased network threat condition. The network threat condition has risen from Information Condition 5 to Information Condition 4 (also called Infocon 4). InfoCon 5 is normal operating conditions and Infocon 4 comes as a result of 'continuing and sophisticated threats' against DoD Networks. The change to Infocon 4 came in mid-November, after the Naval War College suffered devastating attacks that required their entire system be taken offline, but the JTF-GNO spokesman claims there is no connection." -
Army to Require Trusted Platform Module in PCs
Overtone writes "Federal Computer Week is reporting that the U.S. Army will require hardware-based security via the Trusted Platform Module standard in all new PCs. They are a large enough volume buyer that this might kick start an adoption loop." -
Pentium Computers Vulnerable to Attack?
An anonymous reader writes "One of the latest security scares is coming from security experts at CanSecWest/core '06 in the form of a possible hardware-specific attack. The attack is based on the built-in procedure that Pentium based chips use when they overheat. From the article: 'When the processor begins to overheat or encounters other conditions that could threaten the motherboard, the computer interrupts its normal operation, momentarily freezes and stores its activity, said Loïc Duflot, a computer security specialist for the French government's Secretary General for National Defense information technology laboratory. Cyberattackers can take over a computer by appropriating that safeguard to make the machine interrupt operations and enter System Management Mode, Duflot said. Attackers then enter the System Management RAM and replace the default emergency-response software with custom software that, when run, will give them full administrative privileges.'" -
Security Flaws Could Cripple Defense Network
userexec wrote to mention an FCW.com article about the uninspiring future for the Missile Defense System's software. The developers are apparently very worried about poor information security on the project. From the article: "The report said that neither MDA nor Boeing officials saw the need to install a system to conduct automated log audits on unencrypted communications and monitoring systems. Even though current DOD policies require such automated network monitoring, such a requirement 'was not in the contract.' The network, which was also developed to conform to more than 20-year-old DOD security policies rather than more recent guidelines, lacks a comprehensive user account management process, the report said. Neither MDA nor Boeing conducted required Information Assurance (IA) training for users before they were granted access to the network, the report stated. " -
Operation 'Cyber Storm' Starts Tomorrow
cyberbian writes "Federal Computing Week reports that the Department of Homeland Security have moved up their rescheduled cyber security exercise, designed to test enterprise and private sector alike. The tests are expected to run from February 6-10, and are intended to gauge the state of readiness for a cyber attack on critical infrastructure. FCW also reports that the scope of the fake attacks will be global, and they are coordinating with partners in Australia, Canada and the UK." -
Operation 'Cyber Storm' Starts Tomorrow
cyberbian writes "Federal Computing Week reports that the Department of Homeland Security have moved up their rescheduled cyber security exercise, designed to test enterprise and private sector alike. The tests are expected to run from February 6-10, and are intended to gauge the state of readiness for a cyber attack on critical infrastructure. FCW also reports that the scope of the fake attacks will be global, and they are coordinating with partners in Australia, Canada and the UK." -
Patent Examiners Flee USPTO
john-da-luthrun writes "Soaring numbers of patent applications for software and business processes is not only leading to the ludicrous patents for the likes of Amazon and Microsoft. The stress of dealing with vast numbers of applications is leading to an exodus of patent examiners from the USPTO, reports FCW.com. A US Government Accountability Office report (PDF) says that the USPTO has made progress in hiring examiners, 'but challenges to retention remain'. The IP Kat blog quotes Jason Schulz of the EFF, who comments that 'The incredible surge of patent applications, especially in the software and internet business method arena, is just crushing them, and the management problems are rising to the surface with greater visibility for those reasons. Where anything under the sun is patentable, it puts an unbelievable amount of pressure on the patent office'." -
Los Angeles to Consider Open Source Software
lientz writes "According to an article at FederalComputerWeek, the city of Los Angeles is considering using Open Source software as a cost cutting measure. From the article: "...city officials could save $5.2 million by switching to OpenOffice... rather than purchasing a Microsoft Office product at $200 per license for 26,000 desktops. The savings would go to a special fund to hire more employees for the police department, a major focus for city officials right now, he added."" -
US Air Force Building Space Router
Saint Aardvark writes "From the ISTS daily news comes a story on the US Air Force seeking to build a space router. From TFA: "Northrop Grumman and Caspian Networks are collaborating to develop an Internet Protocol router that can withstand the constant barrage of solar radiation in orbit. The space-hardened IP router will be part of the Air Force's Transformational Satellite Communications System, which will provide IP-based communications to warfighters." I wonder what the ping times would be like..." -
Open Source SpeedShop Project Opened
drjzzz writes "Federal Computer Week reports that the National Nuclear Security Administration of the US Department of Energy is paying about $3 million of a $6.8 million collaboration between Silicon Graphics and the Universities of Maryland and Wisconsin to develop an open-source version of SpeedShop, SGI's performance analysis tools. This will redress what a SGI engineer characterizes as scarce analysis software for Linux. A "Pro" version will also be developed and sold by SGI. Maybe even those of us without access to ASCI White can tweak our boxen to do 3D simulations of complete nuclear detonations, NNSA's main interest. Now that's what I call homeland security and real respect for the spirit of the second amendment." -
Eclipse Reaches Version 3.0
Tarantolato writes "The Eclipse Foundation has released version 3.0 of its open-source Java-based IDE. Eclipse backers like IBM say the program offers not only increased productivity and ease of use, but also a plugin-based architecture for creating 'rich client' applications with the networking capabilities of web-based apps and the persistence and native widgets of desktop applications. The Lotus Workplace platform is already Eclipse-based. Some in the Java community, however, are concerned with Eclipse's use of SWT rather than the standard Swing widget set, and some analysts think that project is part of a 'broader challenge to Microsoft's entire .Net development framework' from IBM. Meanwhile, Eclipse executives are attempting to woo Microsoft into joining the foundation." -
Rand Report Says Geospatial Data Not Big Threat
scupper writes "An article in Federal Computer Week came out Monday that announced The Rand Corporation has published a report (sponsored by the National Geospatial-Intelligence Agency) concerning the threat that publicly available geospatial data on US Government web sites might pose in the hands of terrorists that 'found that less than one percent of the 629 federal data sets they studied appeared to have notable value to would-be attackers', according to the report titled: Mapping the Risks:Assessing the Homeland Security Implications of Publicly Available Geospatial Information. A curious 'finding' from page xxv of the summary not mentioned in the article states: 'However, we cannot conclude that publicly accessible federal geospatial information provides no special benefit to the attacker. Neither can we conclude that it would benefit the attacker.' The release of this report reminded me strangly of the Washington Post news story about a George Mason University graduate student, whose dissertation mapped critical fiber optic network infrastructure." -
American Airlines Is Third Company To Share Data
crem_d_genes writes "American Airlines has become the third U.S. airline to admit sharing passenger records with the government. They were proceeded in admissions by Northwest Airlines and JetBlue Airways. At the heart of the matter is the implementation of the of U.S. Transportation Security Administration's (TSA) use of the provisions known as CAPPS II. Some privacy advocates have expressed strong dissent with this plan. Some concerns have even been brought up in Congress, though for different reasons. The Department of Homeland Security has a site entitled CAPPS II: Myths and Facts." -
Passenger Risk Database to be Implemented in U.S.
bluephile writes "CNN is running an article on the The Transport Security Administration's (TSA) renewed efforts to implement the CAPPS II color-coded passenger risk-assessment program, despite outcries by numerous privacy activism groups at the program's collection and redistribution of personal information. The TSA has made several claims that the system respects passengers' privacy, but their track record isn't impressive. Congress suspended the program last year in order to investigate its privacy implications. One MIT paper suggests that CAPPS II could make flying MORE dangerous, rather than less." -
NASA Installs Linux Supercomputer
unassimilatible writes: "Federal Computer Week reports that NASA plans to study the ocean's future with the help of the world's first supercomputer of its kind to run on the Linux operating system. The new supercomputer -- an SGI AltixT 3000 single-system image supercomputer -- has been installed at the space agency's Ames Research Center in California." -
US Army Signs $471,000,000 Deal for Microsoft Software
zero_offset writes "According to this article at Yahoo, Microsoft will provide software for 494,000 Army computers during the next six years. At roughly $950 per computer this clearly involves more than just the OS, although the article unfortunately doesn't provide details, and I was unable to find any references to this on the Microsoft website." The great things about this deal: the Army is going through a reseller, when clearly they have the purchasing power to buy direct; and most of the computers they purchase are normal consumer machines which will be purchased with Windows and Office already installed, so the Army will be paying twice for each machine. -
DARPA to Fund TIA Study
clonebarkins writes "Federal Computer Week has an article on a DARPA-funded study of privacy-related concerns related to TIA. "We envision software that will mask the identity of any individual whose pattern of activities triggers the suspicion of investigators," says the program manager of the Information and Intelligence Exploitation Division. Yeah, sure--that'll happen about as soon as Ashcroft converts to Islam." -
DARPA to Fund TIA Study
clonebarkins writes "Federal Computer Week has an article on a DARPA-funded study of privacy-related concerns related to TIA. "We envision software that will mask the identity of any individual whose pattern of activities triggers the suspicion of investigators," says the program manager of the Information and Intelligence Exploitation Division. Yeah, sure--that'll happen about as soon as Ashcroft converts to Islam." -
Microsoft Bug May Attract Big Worm
-
U.S. Army's Future Combat System Will Run Linux
jkastner writes "In 2001 Boeing was chosen to be the lead system integrator for the Army's Future Combat System. The bumper sticker description of this project is 'see first, understand first, act first and finish decisively,' and while Boeing's official FCS site doesn't have a lot of technical details, but you can find some good information at Global Security. To quote their page, "FCS is envisioned as a networked 'system of systems" that will include robotic reconnaissance vehicles and sensors; tactical mobile robots; mobile command, control and communications platforms; networked fires from futuristic ground and air platforms; and advanced three-dimensional targeting systems operating on land and in the air.' The Phase 2 request for proposals just appeared and the estimated price is $26 billion through fiscal year 2009. The fact that the Army is spending billions of dollars on a project isn't anything new, but a little known fact is that the OS for FCS will be Linux (FAQ 4 here.)" -
Publishers' Attack Free Government Sites
An anonymous reader writes "After succeding in getting the DOE's PubScience shutdown the Software and Information Industry Association and publishers' are now targeting more. If the trend continues local tax dollars will increasingly be spent to buy access to information the federal government used to provide." -
Idaho Gets Serious About Broadband
prostoalex writes "In an effort to boost the economy state of Idaho legislated tax credit for companies, who were investing in broadband Internet infrastructure. According to the latest news, the plan worked quite well, and about 150 thousand people can soon take advantage of tax-sponsored buildout. Speaking of wiring rural areas with cheap Internet access, there was an article in NY Times ($free_registration_quote), where Bill Gates admitted that in many cases building Internet in the rural area just speeded up the exodus of farmers, who were able to find a job somewhere else." -
Passenger Profiling: CAPPS II
gabec writes "'Initial rollout of what may eventually become the world's largest silicon repository of personal data could be less than 90 days away....The Computer Assisted Passenger Prescreening System II (CAPPS II) is designed to scan multiple public and private databases for information on individuals traveling into and out of the United States. The system will feed the results to an analysis application that mathematically ranks travelers' potential as security threats.' It will happen by the end of the year, if nothing is done to stop it: And here are some articles on this." -
MS Security: On A Path As Clear As It Is Reliable
bobthemonkey13 writes: "It appears that Microsoft's 'secure' E-Book system has been cracked. MIT Technology Review is reporting that an anonymous programmer has figured out how to bypass the 'advanced antipiracy features' in Microsoft Reader. This sounds a lot like what Dmitry did except for two things: The MS E-Book hacker has (wisely) decided to remain anonymous, and he's not publishing his program. God bless the U.S., where moving a book from your home to your office is a federal offence." Along similar lines, an Anonymous Coward indicates this story at USA Today titled "Expert Hacks Hotmail in 1 Line of Code." "I'm in awe! Unless someone can figure out how to execute pseudocode or half a line this isn't beatable. I hope this get's fixed or the whole future of pay-per-view web services could be impacted. :-q" Good thing Microsoft isn't quite sure what to do with all this universal-password stuff. (Thanks to Sacha Prins.)Jamie adds:
In other news about poor security where you least expect it, Kitetoa informed Veridian a little while ago that: "Any script kiddy can root your web site. And... By the way... Someone already did it (as you should have seen at www.veridian.com/upload/ if you knew anything about internet security)."
I don't know what that URL gives you now, but as of this writing, and for the last several hours, it's read:
fuck USA Government
fuck PoizonBOx
contact:sysadmcn@yahoo.com.cnThis is the same Veridian that the Defense Department picked to track computer network attacks on DoD systems, specifically attacks coming from China.
-
Red Hat/GTSI To Go After Government Market
-
Pentagon Says Improper Image Morphing is War Crime
mwdib writes "Here's a story in Federal Computing Week in which the Pentagon decides that certain forms of computer morphing could be war crimes." It was hard not to file this under "humor," but Federal Computer Week is a serious publication that almost always gets its stories straight. So loonie as this may seem, it's not a joke. -
FCW compares Unix workstations
EngrBohn writes "Federal Computer Weekly evaluated Unix workstations by Compaq, HP, IBM, and Sun -- they specified minimum hardware requirements and a maximum price; beyond that, all was fair. They did not include *BSD, Linux, or WinNT due to space limitations. Here's a chart (in PDF) comparing the workstations. IBM's RS6000 43P Model 260 won on technical merit, but it exceeded the $15K price cap. " -
FCW compares Unix workstations
EngrBohn writes "Federal Computer Weekly evaluated Unix workstations by Compaq, HP, IBM, and Sun -- they specified minimum hardware requirements and a maximum price; beyond that, all was fair. They did not include *BSD, Linux, or WinNT due to space limitations. Here's a chart (in PDF) comparing the workstations. IBM's RS6000 43P Model 260 won on technical merit, but it exceeded the $15K price cap. " -
Congress concerned about Echelon
Congress is concerned about Echelon invading the privacy of US citizens. Indeed, for the first time in its history, the NSA has refused to supply the House Permanent Select Committee with documents about Echelon. -
Microsoft looking at mail client for UNIX
Eater writes "Here's an article from Federal Computer Week. Seems they're afraid of losing Army dollars. " The Army is using Lotus Notes, because of "security concerns" with Exchange. Looks like military intelligence may not be such a misnomer. -
SGI x86 Linux Servers
I think I need an SGI icon- the news from out there just keeps streaming in- Mage sent us a link to an interesting bit from Federal Computer Week talking about x86 Servers designed to run NT or Linux. The article has a pretty glaring mistake though, saying that Red Hat and Caldera are "Public Domain" Operating Systems. Update: 02/08 05:11 by CT : Hooray! We have an SGI icon now. Anyone have one for mp3s now? -
Storage Dilemma Looms for NASA
John Keeton writes "Guys, This story talks about how NASA is moving its data from tapes as old as seven tracks to newer media, but then they get done, they have to start moving it again to new media, and how they are falling behind, and may have to lose TB's worth of data.. Really interesting.." It says it will take them 4 years to move all the data to tapes that have a 6 year life expectancy. Hmmm. -
NASA using Beowulf for Investigations
Brian Daniels writes " NASA's created a Beowulf to investigate the data seized from computer criminals. The article is short on technical detail, but Linux and the cost advantage of Beowulf vs supercomputers is mentioned. One wonders about exaggerations though - does the average computer criminal really have "hundreds of gigabytes of data", and where was he keeping it? " -
NSA Details Key-Recovery Risks
Felix Finch wrote in with This link where you can read an interesting article discussing risks with Key Recovery. Not a lot of really new information, but the fact that it actually comes from the NSA is pretty newsworthy. It also should raise a skeptical eyebrow.