Slashdot Mirror


Border Security System Left Open

7x7 writes "Wired News is running an article on documents they recovered via the Freedom of Information Act and a lawsuit. From the article:" A computer failure that hobbled border-screening systems at airports across the country last August occurred after Homeland Security officials deliberately held back a security patch that would have protected the sensitive computers from a virus then sweeping the internet, according to documents obtained by Wired News." It looks like Zotob made it in to the supposedly protected network."

45 of 195 comments (clear)

  1. Let me get this straight by pHatidic · · Score: 5, Funny

    The government agency in charge of US security runs windows?

    What next, making Ron Jeremy the pornography czar?

    1. Re:Let me get this straight by javaxman · · Score: 2, Insightful
      What next, making Ron Jeremy the pornography czar?

      That would actually make a lot more sense than running mission-critical security-sensitive apps on an unpatched Windows installation. If you like porn, that is.

      Heck, it would make more sense even if you *didn't* like porn, now that I think about it...

      But hey, remember, this is from the administration that brought you Iraq's WMDs and the post-Katrina disaster recovery response. Poor decisions ? Bungling?

      I'm shocked, I tell you, SHOCKED!!

    2. Re:Let me get this straight by Anonymous Coward · · Score: 3, Funny

      As our enterprising leaders promote mandatory travel checkpoints, screening and recording every citizen who arrogates to move faster than bicycle-pace, I can practically feel myself tingling with safety.

      How dare you joke about their ineptitude? Don't you realize that every dollar spent on Homeland security is a dollar that otherwise would have gone to some terrorist who snuck through the border and stole a job in preparation to launch a dirty nuclear bomb in the middle of a preschool, for God's sake?

      Instead of criticizing, please, take a moment to say thank you next time.

    3. Re:Let me get this straight by Beryllium+Sphere(tm) · · Score: 2, Informative

      Running Windows and neglecting the precautions that Windows requires.

      Zotob scanned for systems with port 445 open. In the name of the Flying Spaghetti Monster, why weren't those systems behind a firewall? On a closed network so that someone couldn't just plug in an infected laptop?

      Then comes a vulnerability that Microsoft marks as "critical" and a patch that Microsoft says should be installed immediately. A sane patch management policy *might* delay installations but only if some temporary mitigation were in place (like, say, a firewall, or less snarkily an updated IPS).

    4. Re:Let me get this straight by LurkerXXX · · Score: 2, Insightful

      Certainly that port shouldn't be open to the internet. That goes without saying. But more than one network totally disconnected from the internet has gotten nuked before when a repair technician, etc, plugged an infected laptop into that private LAN. With a network the size if the one we are talking about, it's only a matter of time before something infected from outside gets plugged in somewhere. Patching is still neccessary unless you absolutely know that no infected machine will ever have the possibility of being plugged into the net behind the firewall. With a national network, there's never going to be that certainty.

    5. Re:Let me get this straight by drinkypoo · · Score: 2, Interesting

      That port doesn't even need to be open between different locations on the same network. It's used for SMB over TCP and they ought to be using firewalls in between departments, as most major corporations do, and blocking it. If people need access to files then they can either make them available via secure intranet or they can rsync (or similar) the files between file servers in different departments. If they're using Win2k they're likely using AD and they should have different servers for different subdomains anyway - that is, if they're using AD properly, and have different subdomains for an organization with multiple locations and departments. Also, some types of military networks are often protected by a combination of physical protection and routine. You're not even allowed to bring a machine into a room where it could be plugged into such a network. In fact, you're not even allowed to bring an iPod in. Actually, let me take it one step further; they don't even permit having a phone - and I'm talking cellular, land line, whatever - in the same room as one of these systems. And by "room" I mean the phone and any computers on the network have to be separated by a door that closes itself and locks. When I worked for Tivoli Systems (part of IBM, though they weren't on the IBM campus when I worked there) I once worked on a support call where I was talking to a guy on a phone who was shouting what I said to a guy holding the door open, who in turn was shouting to the guy sitting at the TME10 console. To their credit, they got everything I said correct, and a good time was had by all except, probably, the poor bastard holding the door open.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    6. Re:Let me get this straight by xiang+shui · · Score: 2, Informative

      From 2001 to 2003 there was a 'porn czar' in Utah.

  2. Territorial Pissing by Anonymous Coward · · Score: 2, Funny

    This whole border monitoring and attempt at an omniscient fed is just plain silly. As for the terrorists, wouldn't it just be easier not to invade other countries and invoke the ire of the natives??
     
    And illegal immigrants wouldn't be streaming into the US if the dollar wasn't being artificially propped up. Probably would see the reverse if the free market would be allowed to work its course.

  3. Borders by Thedeviluno · · Score: 2, Interesting

    The great wall of China was also ineffective at keeping out intruders.In military terms, these walls are more frontier demarcations than defensive fortifications of worth.

    1. Re:Borders by Ohreally_factor · · Score: 4, Interesting

      Your plagiarism from wikipedia aside, the wall might have served another purpose, i.e., as a great public work, that would help accrue, consolidate, and maintain power for the ruling classes thru the use of "surplus" labor.

      --
      It's not offtopic, dumbass. It's orthogonal.
  4. Normal windows operations by mtenhagen · · Score: 4, Insightful

    This sounds like normal windows operations:
      - an exploit (bug) is discoverd
      - the virus is released
      - a patch is relesead by microsoft
      - the administrators dont trust the patch (cant see what it exactly does) so need to test
      - in the mean time the virus is spreading
      - there should be a profit line here, but I gues microsoft already made a profit before all of this started.

    --
    200GB/2TB $7.95 Coupon: SAVE90DOLLAR
    1. Re:Normal windows operations by mrchaotica · · Score: 4, Insightful
      the administrators dont trust the patch (cant see what it exactly does) so need to test
      So what? It's not as if they can see exactly what Windows itself does either!

      If they're going to run proprietary software, they might as well have blind faith that everything the vendor does is right, 'cause they have no choice anyway -- they've already chosen to trust it with the existing system. (This is why foreign governments are switching to Free Software, by the way -- they'd have to be run by morons to trust Microsoft.)
      --

      "[Regarding the 'cloud,'] ownership was what made America different than Russia." -- Woz

  5. Failures are routine apparently by frdmfghtr · · Score: 5, Funny
    Publicly, officials initially attributed the failure to a virus, but later reversed themselves and claimed the incident was a routine system failure.


    I guess when you run Windows, failures are routine...
    --
    Government's idea of a balanced budget: take money from the right pocket to balance...oh who am I kidding?
    1. Re:Failures are routine apparently by TubeSteak · · Score: 5, Insightful
      But two CBP reports obtained under the Freedom of Information Act show that the virulent Zotob internet worm infiltrated agency computers the day of the outage, prompting a hurried effort to patch hundreds of Windows-based US-VISIT workstations installed at nearly 300 airports, seaports and land border crossings around the country.
      If there wasn't a Freedom of Information Act, would the public ever really know what had happened?

      I'm surprised the information wasn't classified as relevant to National Security. Weaknesses in computer security are just as bad as weaknesses in physical security.
      --
      [Fuck Beta]
      o0t!
    2. Re:Failures are routine apparently by Beryllium+Sphere(tm) · · Score: 2, Interesting

      >If there wasn't a Freedom of Information Act, would the public ever really know what had happened?

      Even with the FOIA it took a lawsuit to get hold of these records, and they still have some unjustifiable omissions: "A public Microsoft security bulletin is included, but with the bulletin number (MS05-039) blacked out"

    3. Re:Failures are routine apparently by ScrewMaster · · Score: 2, Funny

      If you're suffering routine failures, check to make sure you aren't running Windows.

      --
      The higher the technology, the sharper that two-edged sword.
  6. I feel safer already! :-) by Philip+K+Dickhead · · Score: 2, Funny

    Let's give this system to Iran, then we can avoid a war in August - while they figure out their problems with illegals, terrorists and Bill O'Reilly commentaries! :-)

    In Soviet America, the border opens you!

    --
    "Speaking the Truth in times of universal deceit is a revolutionary act." -- George Orwell
  7. Should have used dumb terminals. by khasim · · Score: 5, Insightful
    These machines will sit in border offices, staffed by government employees.

    I wouldn't even trust *nix workstations in that environment.

    Not to mention the WHY of this. From TFA:
    The system has processed more than 52 million visitors, and allowed border officials to intercept more than 1,000 wanted criminals and immigration violators, according to DHS.
    Great. 1,000 people. Didn't I see something on the news recently about 11 million illegal aliens in this country?
    The documents raise new questions about the $400 million US-VISIT program, a 2-year-old system aimed at securing the border from terrorists by gathering biometric information from visiting foreign nationals and comparing it against government watch lists.
    1,000 people at a cost of $400 million.

    $400,000 per person caught?

    Someone REALLY needs to pitch the LTSP to the government.
    1. Re:Should have used dumb terminals. by geekoid · · Score: 2, Insightful

      Most illegal immigrants aren't on any wanted list.

      it is used to scan everyone, so it's cost is perperson scan. People catch criminals.

      --
      The Kruger Dunning explains most post on /. http://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect
    2. Re:Should have used dumb terminals. by codegen · · Score: 2, Funny
      Look for around 33 million illegal aliens.

      Which is about the entire population of Canada.

      --
      Atlas stands on the earth and carries the celestial sphere on his shoulders.
    3. Re:Should have used dumb terminals. by ezzzD55J · · Score: 2, Insightful
      I'd be happy if a government computer system cost $400,000,000 and caught 1000 people so long as it didn't materially help terrorists.

      It does, because it's such a huge waste of money.

  8. Beta stuff? by TubeSteak · · Score: 4, Insightful
    "Replacement of these systems and improved biometric systems will be required."

    [Former White House cybersecurity adviser Howard] Schmidt agrees, though he says the problem is hardly limited to US-VISIT. "We have to start moving at industry speed, not government speed, when it comes to the deployment of new technologies," says Schmidt. Instead of running Windows 2000, "I'd be racing to run the beta of the next generation of operating system ... and not worry about legacy stuff that we know isn't going to be supported too much longer and has had issues."
    I'm glad this guy is "Former" and not current. Why does he think a beta OS is going to be any more secure than 'legacy' OSes?
    --
    [Fuck Beta]
    o0t!
  9. Windows? by Cthefuture · · Score: 4, Insightful

    Instead of running Windows 2000, "I'd be racing to run the beta of the next generation of operating system ... and not worry about legacy stuff that we know isn't going to be supported too much longer and has had issues."

    Or how about this: Run a secure operating system that is stable and still maintained. Linux, OpenBSD, FreeBSD, anything other than Windows. No forced upgrade required since many of the old Linux distros are still maintained.

    I mean it's Microsoft forcing them to upgrade even though Windows 2000 is still a perfectly fine OS.

    --
    The ratio of people to cake is too big
  10. Non-computer Q about US Visit by Anonymous Coward · · Score: 5, Insightful

    Except for really dumb criminals, how does US Visit actually improve security? The terminals are away from the gates, you don't need to pass special check points between the domestic and international terminals and ID doesn't get rechecked at the gate. So unless I am gravely mistaken an easy way around it would be

    -subject A buys international ticket
    -subject B buys domestic ticket
    -both pass security
    -A checks out at US Visit terminal
    -A and B swap tickets
    -B gets on international flight
    -A gets on domestic flight or leaves the terminal
    -B gets off the plane outside the country and uses his or her own passport to pass the border control. IIRC, most countries including the US don't feed back who passes passport controls back to the airlines or country of origination. But even if, B could just take a fake passport to a third world country without scanners or live database hookup instead of Europe, Japan or the like.

    1. Re:Non-computer Q about US Visit by Ollierose · · Score: 2, Insightful

      As a person who has suffered this proceedure, I think I can shed some insight.

      As the people above have suggested, its not about keeping their eye on Americans (of the North sort, not the United States sort), but keeping their eye on Foreigners in general.

      When I flew in from London last summer, my flight was routed to go through a "Port of Entry" which is a location where they have installed the US-Visit fingerprint scanners and such. Lucky me, I got to go to Detroit as my first port of call into the US on my way down to Florida. On the transatlantic flight, they gave out a form which was different for where you started out - the guy next to me was a US citizen, so he got a blue form while I got a green one.

      In between arriving at Detroit and hooking up with the connecting flight south, there is a security bank where you need to collect your luggage from the inbound carrier, cart it across to another more sensitive luggage and body scanner (which picked up coins in my pocket that weren't noticed at Gatwick), check that on to your new flight, then go see the guy in the pseudo-military DHS uniform to make sure that you're not trying to overthrow the country. They then take your mugshot and index fingerprints on the scanner, part of the form you filled in on the plane inbound, and then over to the gates for the next stage of the trip.

      What is supposed to happen on the way out is that you return through the same process to make sure you leave in line with the form, and they use a standalone fingerprint scanner to make sure you're the you that checked in. Flight delays put paid to that, so I was sent on a direct flight out instead of the hop back to Detroit.

      I believe this privilege is reserved for countries that have an agreement with the US on such things, so the previous Visa system is still an option for entry if you pick a suitable source and destination airport.

      The DHS website has a list downloadable that shows which airports are ports of entry, so it might be worth checking if you have a trip to the US planned. I'd say most inbound flights from the UK are routed through entry ports, as my return trip has been organised to go through Atlanta this year.

  11. 42 by Wayne247 · · Score: 2, Funny

    If anyone is surprised by the incompetence of governmental bureaucracy, please email me about my new perpetual motion machine that taps the unlimited energy of herbal pills.

  12. Interesting... by nawcom · · Score: 5, Insightful
    An interesting question is to the Administrators:

    If you don't trust the patch that software developer provides for its product, then why trust to use the product at all?

    It sounds like someone saying, "Our OS has security holes in it, but we don't trust the fixes because they will just open up more holed until we verify for sure.. .. but since 90% of the world use this "hole-y" OS we'll just do what works. Like reporting a planned virus infection. *all hail bill*"

    -nawcom

    1. Re:Interesting... by Jose · · Score: 2, Insightful

      If you don't trust the patch that software developer provides for its product, then why trust to use the product at all?

      good admins..heck, even half decent admins don't trust any new software, including patches. Not neccessarily because they will introduce holes, but because they might break something. Even if it is not security patches, they still need to be tested to make sure they don't break anything in their particular environment.

      I'd wager that at least 90% of admins do not test patches for new security problems. Effectively testing patches for new security problems is very hard.

      I am not an MS fanboy. This goes for every single piece of software written.

      --
      The basic sleazeware produced in a drunken fury by a bunch of UCBerkeley grad students was still the core of BIND. --PV
  13. Re:Patch Cycle by LiquidCoooled · · Score: 2, Insightful

    No it wouldn't.

    With a border router nothing stops an infected laptop from attacking on the inside.

    --
    liqbase :: faster than paper
  14. The article has it backwards by tuxlove · · Score: 2, Interesting

    The failure here was not that the Windows boxes weren't patched. It's stupid to be patching thousands of systems that are in use w/o serious testing first. Full testing of patches in a world where new viruses/security holes appear every day is effectively impossible. Untested patches may cause new problems for the systems that could actually be worse than a problem caused by a virus.

    No, the problem here is that these systems are even on the Internet to begin with. Shouldn't such a network exist in an airspace as a totally private net, with no outside access? Of course, at the core of the private network must be some sort of control mechanism/database with some connectivity to an outside network. But that should be a chokepoint, the only source of ingress/egress to the private network, with no other access than what's needed to serve the system from the local DHS network. That limited access should not include web/email/instant messaging, etc. Just whatever custom/specialized protocol is needed to serve the system.

    I'm constantly amazed at the high profile companies/government offices that get nailed by viruses. It's inexcusable.

  15. Those dollars are earmarked. by twitter · · Score: 2, Insightful
    says Schmidt. Instead of running Windows 2000, "I'd be racing to run the beta of the next generation of operating system ... and not worry about legacy stuff that we know isn't going to be supported too much longer and has had issues."

    It's amazing someone who was in that position thinks the next Windoze won't have the same problems every other version has had. What a total waste of money.

    --

    Friends don't help friends install M$ junk.

    1. Re:Those dollars are earmarked. by pallmall1 · · Score: 2, Interesting

      What a total waste of money.

      No kidding. Using Windows garbage for any Homeland Security tasks means that every Windows vulnerability (and there are many, many, many of them) becomes a National Security vulnerability. That's a fact, PERIOD. That the clowns responsible for the safety of the citizens of the US think that Windows is suitable for Homeland Security applications shows they are more concerned with protecting Microsoft's profits than protecting our families.

      --
      3 things about computers: they're alive, they're self-aware, and they hate your guts.
    2. Re:Those dollars are earmarked. by biglig2 · · Score: 4, Insightful

      It's amazing that someone worried about security thinks running a beta of a security system is the way to go.

      This is of course the great counter to the "but FOSS doesn't have any support". "The US Government can't get support for W2K, what makes you think you can?"

      --
      ~~~~~ BigLig2? You mean there's another one of me?
    3. Re:Those dollars are earmarked. by HiThere · · Score: 3, Insightful

      Maybe it means the "Homeland Security" has a different job than the PR claims...and *that* is where it's attention lies.

      Don't believe what they say, watch what they do. They lie constantly, but you can't even depend on that.

      Watch your legislator. When they claim to be against something, but they vote for it, you know one of the things they are lying about.

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
  16. One born every minute. by twitter · · Score: 2, Insightful
    Why does he think a beta OS is going to be any more secure than 'legacy' OSes?

    Because someone lied to him.

    How many times M$ can get away with the same lie? "This OS is totally new and improved and does not have the problems our last one did." It's sickening to hear the head of a US government agency buy such stuff while perfectly usable and secure free software is available.

    --

    Friends don't help friends install M$ junk.

    1. Re:One born every minute. by MadUndergrad · · Score: 2, Funny

      "'This OS is totally new and improved and does not have the problems our last one did.'"

      Nope, it has a whole new set of problems!

      Fine print: it also has all the problems of the last one.

  17. This shouldn't come as a surprise by i_want_you_to_throw_ · · Score: 5, Interesting

    I spent ten years as a government contractor and this shouldn't surprise anyone. First Homeland Security runs Windows which in itself isn't bad if it's properly patched and maintained.
    The danger comes from the the people in government who control the money who have no technical knowledge. This is positively RAMPANT in government. Many times agencies just go with the cheapest bid and contractors give cheaper bids by hiring fairly inexperienced and not so knowledgable techs.

    Many government agencies can get by with using Windows but really important agencies whose security cannot be left to chance should not be using Windows....period. Sadly Homeland Security and NSA are both starting to deploy more Windows units and that's only going to be bad for everyone.

    Biggest reason why? Strong security requires techs that actually have technical knowledge and can do more than just set up insecure boxes by pointing and clicking. Big difference between *nix and Windows?
    *nix needs techs with a decent amount of computer aptitude.
    Windows does not
    The person attacking you, or entity, or rogue state will not be using script kiddies. This only gets worse from here. "Homeland Security" is fast becoming an oxymoron.

    1. Re:This shouldn't come as a surprise by stinky+wizzleteats · · Score: 2, Insightful

      First Homeland Security runs Windows which in itself isn't bad if it's properly patched and maintained.

      ...

      Big difference between *nix and Windows?
      *nix needs techs with a decent amount of computer aptitude.


      Well now wait a minute. Windows is OK if it is properly maintained, but those who run Windows are generally less capable of doing so, because they don't have to? That doesn't make any sense.

      Rather than trying to figure out which is the chicken and which is the egg in your causality loop there, why don't we admit to ourselves, and most importantly, the rest of the world, that Windows is just inherently insecure? How many more years is the IT community going to pretend that this elephant is not in the room? 5? 10? 20?

  18. Configuration Control by Detritus · · Score: 4, Insightful

    Because in large and complex systems, you don't install patches until they have been tested for unintended side effects. That may mean scheduling, running and evaluating some very complex tests. This can take weeks or months, depending on budgets, priorities, and operational commitments.

    --
    Mea navis aericumbens anguillis abundat
    1. Re:Configuration Control by metatruk · · Score: 2, Interesting

      If it's border security we're talking about, I'd sure as hell rather have a *broken* system than an *insecure* and *vulnerable* system.

      These people don't know what they're doing.

  19. Re:should have used unix by sh4na · · Score: 2, Insightful

    The question is not that you can filter packets coming in... the question is how in the hell did those packets ever get in to the network in the first place! I mean this is a private, supposedly isolated network we're talking here, not some house-brewed workgroup to play around with. You don't activate packet filtering in 3000 machines because they're supposed to be as isolated as it can be, with identified points of entry secured with *real* firewalls.

    There was a mention about a network not being secure if a laptop is plugged in, but a secure network does not allow unauthorized connections of any sort into it, for example, every device should only plug in to a single plug, identified and filtered by mac address. It's a lot of work, but that's what secure means. These are not workstations for checking mail and chatting away while watching movs.

    The virus coming in means someone was incompetent in setting it up, or someone was really smart in putting the virus in. Not updating the machines with the patch was correct, it shouldn't be a problem if the network was correctly setup, you can't be updating everything every time a new patch comes out without tests. Independently of the OS used, in a controlled environnment patches are not a means of security, frontend workstations should not be a point of breakage.

    So this is what homeland security means in the states eh? Why doesn't it surprise me? pffft...

    --
    shana
    ......gone crazy, back soon, leave message
  20. Irony with a 60lb mallet by caudron · · Score: 4, Informative

    It looks like Zotob made it in to the supposedly protected network.

    I'm supposed to be surprised that the department that is there to "protect" us from attack fell to an easily preventable virus?

    Not when that same agency appoints Gator (now Claria) executive, D. Reed Freeman, to their Data Privacy and Integrity Advisory Committee or when that very same agency hired its own Chief Privacy Officer from Doubleclick.

    No, I couldn't muster less shock at the irony if my nutsack depended on it.

    Tom Caudron
    http://tom.digitalelite.com/politics.html

    --
    -Tom
  21. It's about test automation, not MS by Precipitous · · Score: 3, Informative

    While stating "deliberately held back a security patch" might be factually correct and a good catch line, I think it's highly misleading: it directs the reader towards many of the wrong conclusions.

    Later in the article: "Officials -- not unreasonably, say security experts -- wanted to test the patch before installing it." Well, duh. This is the interesting story. They couldn't get through the tests that they SHOULD do fast enough.

    The problem is agility and testability of the systems and deployment. The easiest solution has nothing to do with MS, nothing to do with windows, and everything to do with giving your test group more respect and resources.

    This is not a problem inherently Microsoft's making. You can argue up and down that patches should be faster, product more secure etc. In the end, it's plausible that discovery, patch, exploit can come with bad timing in any system. System admins and project managers that don't plan for this are asking for trouble.

    Elaboration: I push very hard to ensure that all my products have automated tests. My company's Desktop Engineering department requires automated tests of all its myriad apps (DE is not my department, won't take credit). I force redesign if a product can't be tested cheaply. The benefit is: I need new feature x tomorrow (maybe some suprise regulation) or company needs patch y tomorrow (e.g. Zotob worm). Where we've achieved our test automation goals (haven't in all cases, but our coverage is good enough), we can hit a few buttons, run our tests. Repeat on all 20 configurations / platforms. 90% of the time, we find no problems, and can deploy. If it's critical, you take the risk and deploy. If not, you go on to slower manual testing to complete coverage.

    Had this US-VISIT program implemented adequate and automated tests, they could have deployed in a few days, not a few weeks. The methods and tools to do so have nothing to do with Microsoft. They don't even make the type of test automation tool required for this - although I know they have one for internal use.

    --
    My motto: "A cat is no trade for integrity."
  22. So that would make this by teamhasnoi · · Score: 2, Funny
    the first undoucumented Mexican virus?

    I'm confused. Who will clean my Walmart now?

  23. Spellcheckers do not catch all misspellings. by lifebouy · · Score: 2, Funny

    I guess all those boarders better make a run for the border.

    border
    1 : an outer part or edge.

    boarder
    one that boards.

    --
    Drop me a line at:
    Key ID: 0x54D1D809