indianz.com Fredericks Peebles & Morgan LLP
Advertise on Indianz.Com
Home Whats New on Indianz.Com? News Forums
  About
Home > News > Headlines

printer friendly version
Second expert describes hack of Interior Department
Tuesday, May 10, 2005

Internet Vulnerability Documents:
OIG Memo 1 | OIG Memo 2 | OIG Findings | Internet Security Systems (ISS) Report on BLM

From the Indianz.Com Archive:
Interior's security weaknesses not unique: NBC vulnerable to attack (January 17, 2002)
A second Internet security expert testified on Monday that he was able to hack into the Interior Department's computer systems, obtain personal information Secretary Gale Norton and exploit other vulnerabilities that led him to "personal data on all the astronauts."

Phil Brass and his firm Internet Security Systems (http://www.iss.net) were hired by Interior's Inspector General to test the department's computer network. One Bush administration official has described the system as "bulletproof."

But Brass described a far different situation in testimony he gave in the Cobell v. Norton evidentiary hearing. He explained how he purposely looked for sensitive information about Norton and other top officials to show the department that its systems were vulnerable to hackers despite an investment of $100 million.

"We were able to retrieve credentials to many systems," Brass told the court.

Specifically, Brass hacked into the National Business Center (http://www.nbc.gov), an Interior agency that handles more than $9 billion in payroll for more than 200,000 government employees and more than $3 billion in other financial transactions. Over a period of six weeks in March and April, he obtained access to sensitive information about Norton and other top officials that would "make all executives go white."

"I felt empowered," he testified. Among other information, he said he found credit card numbers for "all DOI employees" contained in a database that had been inaccurately marked "bankcard_training_doiu." DOIU is the acronym for the Department of the Interior University (http://www.doiu.nbc.gov).

"This was real data, not training data," said Dennis Gingold, an attorney for the Cobell plaintiffs.

"Exactly," Brass said. He later verified with Interior that the credit card numbers were real.

During his time in the system, Brass prepared what he called "dossiers" on associate deputy secretary Jim Cason and P. Lynn Scarlett, the assistant secretary for policy, management and budget. Cason's dossier, for example, contained his government-issued credit card numbers and other personal information.

Brass was about to do the same for Norton until the Inspector General pulled the plug on the test, he said. "I believe they were worried about upsetting Gale," he testified.

Before that happened, he told the court he was able to find some sensitive information about Norton, a Cabinet official. "I believed I pulled some of her personal data," he said.

And because he knew the NBC processes payroll, financial and other data for a number of federal agencies, Brass kept looking to see how far he could get. Weaknesses in the system led him to NASA, where he found "personal data on all the astronauts." When asked if he could have changed the data, he said "I'm pretty sure I could have done that."

Cason, who has served in the Bush administration since August 2001, has previously told the court that the department has made improvements to "basically bulletproof" the network from hackers like Brass and Scott Miles, another ISS employee who testified in the hearing last week.

But Brass and Miles presented a conflicting view. Both said they performed "penetration" tests on Interior's systems without being detected.

"I hadn't been discovered," Brass said yesterday. Miles testified last week that he gained access to Indian trust data, something Brass said he didn't do.

Brian Dunbar, a spokesperson for NASA, said he was personally unaware that the Interior Department hired computer hackers to test the systems. "I can't comment on that because we don't have any first-hand reports on it," he said, adding that NASA normally doesn't comment on alleged security breaches.

The hearing continues today in federal court in Washington, D.C. The Cobell plaintiffs are seeking a court order to disconnect the vulnerable systems from the Internet, something Brass said was entirely reasonable.

"I personally say you can't ever eliminate the risk," he testified. "There really is no such thing as a secure computer."

Relevant Links:
Indian Trust: Cobell v. Norton - http://www.indiantrust.com
Cobell v. Norton, Department of Justice - http://www.usdoj.gov/civil/cases/cobell/index.htm
Indian Trust, Department of Interior - http://www.doi.gov/indiantrust

Related Stories:
Hacker tells court how he broke into DOI systems (5/4)
Trust fund hearing dispute causes delay in testimony (5/3)
Lamberth to hold hearing on trust fund security (5/2)
Interior ordered to trial on trust fund security (4/26)
Cobell: Ross Swimmer and the truth rarely mix (4/22)
Trust fund security again an issue in Cobell case (4/21)
Lamberth schedules hearing on computer systems (4/20)
Norton blocking information technology report (4/18)
Appeals court supports Lamberth's authority on IT (12/06)
Lamberth critical of Norton's 'bad faith' on trust fund (10/25)
NCAI 04 Wrapup: Day 2 (10/13)
Interior denies attempt to halt trust fund payments (10/05)
Swimmer: Communication with account holders on hold (10/04)
Bush administration challenges trust fund ruling (09/16)
Appeals court takes on Cobell trust fund case (9/15)
Richardson pushes Norton to protect trust fund (08/16)
Small percentage of Interior's IT systems secure (08/10)
Johnson promises 'meaningful' investigation of OST (06/21)
BIA takes advantage of Internet shutdown (05/11)
DOI's Internet connection shut down for third time (03/16)
BIA shows off information technology facility (3/2)
Anderson touts benefits of Cobell trust fund case (02/25)
Lamberth orders DOI to turn over IT reports (12/12)
DOI fares poorly on computer security report card (12/11)
Judge seeks to break impasse over trust systems (07/29)
BIA incident prompts high-level recommendation (03/27)
Court report blasts McCaleb for destroying records (01/27)
Court: McCaleb 'fabricated' e-mail story (1/24)
BIA aides circumventing court (12/16)
Martin's role in incident surfaces (12/16)
BIA aides e-mail use prompts inquiry (12/17)
McCaleb admits to e-mail 'misunderstanding' (10/23)
Burns takes on BIA problems in stride (08/23)
McCaleb gets new computer official (6/5)
Retaliation charged as BIA official jumps ship (7/25)

Copyright © 2000-2005 Indianz.Com
More headlines...
Feature Story:
BIA proposes new gaming compact regulation (7/4)
Indianz.Com Casino Stalker (7/4)
Federal Recognition Database 2.0 (7/4)
In The Hoop Column (7/4)
Indian Gaming News (7/4)
The Federal Register (7/4)
Have a safe and happy 4th of July weekend!! (7/4)
Jodi Rave: Good luck to Iroquois Nationals team! (7/4)
Jodi Rave: Get started on Indian estate planning (7/4)
Job Opportunity: Sac and Fox Nation chief of staff (7/4)
Job Opportunity: Keweenaw Bay social worker (7/4)
The Fives: Hot issues in South Dakota Indian Country (7/4)
Owners of Frank's Landing smokeshop plead guilty (7/4)
Sen. McCain backed Lumbee recognition in 2003 (7/4)
MOWA Choctaw recognition lawsuit dismissed (7/4)
NLRB certifies union at Mashantucket casino (7/4)
Pokagon Band casino brings in $24M a month (7/4)
Hannahville Tribe opens golf course at casino (7/4)
Letter: Boycott Detroit over casino opposition (7/4)
Florida Supreme Court rules in Seminole compact case (7/3)
San Diego Reader: Unlawful entry on reservations (7/3)
Crew returns home after firefighter's death (7/3)
Rosebud Sioux Tribe wraps up summit on suicides (7/3)
Media supports rehearing in Arapaho eagle case (7/3)
Soboba Band to sign law enforcement agreement (7/3)
Sen. Brownback hopeful for U.S. apology this year (7/3)
Opinion: Treatment of Native people a disgrace (7/3)
Native teen from Manitoba missing for two weeks (7/3)
Opinion: New France treated Natives with respect (7/3)
more headlines...
A D V E R T I S E M E N T
Indianz.Com Jobs! Find Employment

Home | Abramoff | Arts & Entertainment | Business | Canada | Cobell | Education | Environment | Forum | Health | Humor | Indian Gaming | Jobs | Law | National | News | Opinion | Politics | Recognition | Red Lake | Sports | Trust

Suggest a Site

Indianz.Com Terms of Service | Indianz.Com Privacy Policy
About Indianz.Com | Contribute to Indianz.Com | Advertise on Indianz.Com | Write to Indianz.Com

Indianz.Com is a product of Noble Savage Media, LLC and Ho-Chunk, Inc.