indianz.com AMERIND Risk Management Corporation
Advertise on Indianz.Com
Home Whats New on Indianz.Com? News Forums
  About
Home > News > Headlines

printer friendly version
Computer expert hacked into Interior systems
Wednesday, May 4, 2005

Internet Vulnerability Documents:
OIG Memo 1 | OIG Memo 2 | OIG Findings | Internet Security Systems (ISS) Report
An Internet security expert testified on Tuesday that he was able to hack into computer systems housing Indian trust fund data without detection despite one Bush administration official's claim that the network is "bulletproof."

Scott Miles was the first witness called during an evidentiary hearing in the Cobell v. Norton case. His firm, Internet Security Systems, has been hired by the Interior Department's Inspector General to perform "penetration" tests to determine whether billions of dollars in Indian trust funds are vulnerable to hackers.

In his testimony, Miles gave the most detailed account so far of the department's security weaknesses. He confirmed that not only was he able to break into the Bureau of Land Management, as was previously disclosed, but also the U.S. Geological Survey and the Bureau of Reclamation.

"The goal of the penetration test is to get into the system and see how far you can go," the witness told the court.

Miles, who works out of an office in the Washington, D.C., area, testified that he got pretty far using an Internet connection available to anyone in the world. He said he broke into the BLM by going through the agency's public web server, which has since been taken offline.

Once he accomplished this task, he asked himself, "How far can we get from this point?" he recalled in his testimony. He said he was able to exploit vulnerabilities in the BLM system to gain access to yet another web application server -- but that wasn't the end of his journey.

Once he crossed that barrier, he could see "all of the systems inside the BLM network," he told the court. That's when he noticed he could hack into Indian trust funds, he added.

But Miles cautioned that he didn't actually break into the Indian trust. "I wouldn't characterize it that way," he said when asked about an Inspector General memo that warned of "unauthorized access" to Indian funds.

Yet Miles acknowledged that he was able to gain special access to at least one BLM system. With "administrative" privileges he said he could "do anything to that data -- write, change, delete [or] modify" it, something the Cobell plaintiffs have warned about for years.

"We did obtain administrative status to a least one of the Windows-based servers in the network," Miles told the court, referring to the popular Microsoft operating system.

Dennis Gingold, an attorney for the Cobell plaintiffs, used the testimony to contradict claims by the Bush administration that the Indian trust is secure thanks to a $100 million investment. Jim Cason, the Interior's associate deputy secretary, once told the court that the department has made improvements to "basically bulletproof" the network from hackers.

But Miles, who appeared at times uneasy with being described as a hacker, a term that carries negative connotations, said he probably wouldn't describe the situation that way. He testified his firm was initially blocked by the BLM's security protections but that he was able to fool the agency into letting down its guard by changing attack methods.

"Some of our testing was blocked," he confirmed. But to overcome that, "We moved to another network location to continue testing at a lighter pace," he said. After that, he gained access into BLM without detection, he said, and could have stayed in the system "for days," as Gingold put it.

The testimony filled some of the gaps in the record that has been released to the public so far. The Inspector General has provided copies of documentation related to the BLM hacking, including a critical ISS report, but most of it is heavily redacted.

Still, this isn't the first time that hackers have broken into Interior's network. In the spring and summer of 2001, Alan Balaran, the former special master in the case who was ousted amid a disqualification campaign by the Bush administration and other past and present government officials, hired a computer security firm that hacked into the Bureau of Indian Affairs and gained access to billions in trust funds.

The disclosure was brushed off senior Interior bureaucrats at the time -- much to their dismay. "And we're now in the mess that we're in," said Bob Lamb, a deputy assistant secretary, during the department's first Internet shutdown of winter 2001 that led to delays in trust payments to individual Indians and tribes.

U.S. District Judge Royce Lamberth has since ordered Interior to disconnect its computers from the Interior two times. The most recent shutdown, however, was lifted by an appeals court after being challenged by the Bush administration.

At the same time, the D.C. Circuit Court of Appeals affirmed that Interior has a fiduciary obligation to protect the computer data and the computer systems of the Indian trust. "It is indisputable that the Secretary has current and prospective trust management duties that necessitate maintaining secure IT systems in order to render accurate accountings now and in the future," the court said in December 2004.

The evidentiary hearing is set to continue today in federal court. It is not known how long it will last but the list of witnesses sought by the both the plaintiffs and the Department of Justice includes dozens of people.

Relevant Links:
Indian Trust: Cobell v. Norton - http://www.indiantrust.com
Cobell v. Norton, Department of Justice - http://www.usdoj.gov/civil/cases/cobell/index.htm
Indian Trust, Department of Interior - http://www.doi.gov/indiantrust

Related Stories:
Trust fund hearing dispute causes delay in testimony (5/3)
Lamberth to hold hearing on trust fund security (5/2)
Interior ordered to trial on trust fund security (4/26)
Cobell: Ross Swimmer and the truth rarely mix (4/22)
Trust fund security again an issue in Cobell case (4/21)
Lamberth schedules hearing on computer systems (4/20)
Norton blocking information technology report (4/18)
Appeals court supports Lamberth's authority on IT (12/06)
Lamberth critical of Norton's 'bad faith' on trust fund (10/25)
NCAI 04 Wrapup: Day 2 (10/13)
Interior denies attempt to halt trust fund payments (10/05)
Swimmer: Communication with account holders on hold (10/04)
Bush administration challenges trust fund ruling (09/16)
Appeals court takes on Cobell trust fund case (9/15)
Richardson pushes Norton to protect trust fund (08/16)
Small percentage of Interior's IT systems secure (08/10)
Johnson promises 'meaningful' investigation of OST (06/21)
BIA takes advantage of Internet shutdown (05/11)
DOI's Internet connection shut down for third time (03/16)
BIA shows off information technology facility (3/2)
Anderson touts benefits of Cobell trust fund case (02/25)
Lamberth orders DOI to turn over IT reports (12/12)
DOI fares poorly on computer security report card (12/11)
Judge seeks to break impasse over trust systems (07/29)
BIA incident prompts high-level recommendation (03/27)
Court report blasts McCaleb for destroying records (01/27)
Court: McCaleb 'fabricated' e-mail story (1/24)
BIA aides circumventing court (12/16)
Martin's role in incident surfaces (12/16)
BIA aides e-mail use prompts inquiry (12/17)
McCaleb admits to e-mail 'misunderstanding' (10/23)
Burns takes on BIA problems in stride (08/23)
McCaleb gets new computer official (6/5)
Retaliation charged as BIA official jumps ship (7/25)

Copyright © 2000-2005 Indianz.Com
More headlines...
Feature Story:
Off-reservation gaming policy survives challenge (10/6)
Indianz.Com Casino Stalker (10/6)
Federal Recognition Database 2.0 (10/6)
In The Hoop Column (10/6)
Indian Gaming News (10/6)
The Federal Register (10/6)
Tim Giago: Indian voters must remain independent (10/6)
Narragansett Tribe won't argue at Supreme Court (10/6)
Supreme Court won't hear Osage Nation case (10/6)
Supreme Court refuses to hear Kickapoo gaming case (10/6)
9th Circuit delays ruling in sacred site case (10/6)
White Mountain Apache water bill sent to Bush (10/6)
Rumsey chairman battles 'poverty of the soul' (10/6)
Mille Lacs Band banishes four over violence (10/6)
Letter: Release Indian crime declination data (10/6)
Border city might join Northern Arapaho lawsuit (10/6)
Editorial: New York can't ignore reservation taxes (10/6)
Cayuga Nation gives away gas amid tax protest (10/6)
Judge to consider Shinnecock Nation recognition (10/6)
Protest against tribal flags at 'Fighting Sioux' arena (10/6)
Letter: A slap in the face over 'Fighting Sioux' (10/6)
Rosebud Sioux Tribe set to open grocery store (10/6)
Muscogee Nation raises minimum wage to $9.25 (10/6)
Charter school helps Tohono O'odham succeed (10/6)
Kansas appeals decision on Wyandotte casino (10/6)
Fort Sill Apache Tribe welcomes NIGC review of casino (10/6)
Mashantucket Tribe challenges NLRB ruling on union (10/6)
Navajo President: Tribes work together on gaming (10/6)
Editorial: Connecticut tribes respond to economy (10/6)
more headlines...
A D V E R T I S E M E N T
AllNative.Com Home Decor

Home | Abramoff | Arts & Entertainment | Business | Canada | Cobell | Education | Environment | Forum | Health | Humor | Indian Gaming | Jobs | Law | National | News | Opinion | Politics | Recognition | Red Lake | Sports | Trust

Suggest a Site

Indianz.Com Terms of Service | Indianz.Com Privacy Policy
About Indianz.Com | Contribute to Indianz.Com | Advertise on Indianz.Com | Write to Indianz.Com

Indianz.Com is a product of Noble Savage Media, LLC and Ho-Chunk, Inc.