Search DominoPower's 11,441 Lotus-related article archive 
Home
EasyPrint
News details Click here for the RSS feed's XML code. This is not a browser URL.
Articles-only Click here for the RSS feed's XML code. This is not a browser URL.
Twitter Feed Click here for the Twitter feed.
U.S. government agencies' cyber-security and record-keeping worse than previously thought (continued)

In any case, I was just pointed to a new Web page entitled "New 'Red Flag' Requirements for Financial Institutions and Creditors Will Help Fight Identity Theft". The document discusses how financial institutions and creditors must comply with "red flag rules" and create programs to protect consumers from identity theft.

"At least I didn't pick on the White House this time."

So, wouldn't you think, of just about any agency, the FTC would be pretty secure from an identity theft risk of their own?

Nah, I didn't think so.

Here's what the GAO found out:

The CIO told us that agency staff cannot directly access external Web-based email through the agency's Web browsers, and agency employees have been instructed not to use such systems for official FTC business. However, this official said that agency employees may use the commission's remote application delivery environment to obtain limited access to external Web-based email as a convenience.

On the surface, it might seem that the FTC isn't as bad as Homeland Security. FTC officials aren't allowed to surf their personal Hotmail and Gmail accounts -- at least not directly.

But what the agency employees can do is use a Citrix-based solution (think Go-To-Meeting) to remote desktop their way out of the FTC firewall and, most likely, connect to their PCs at home.

Yep, rather than simply access the Web (with all its attendant risks), FTC employees are allowed to remotely tunnel out of their FTC offices to home, accessing PCs containing all sorts of who-knows-what.

To be fair, as long as the Citrix session remains secure, there's no problem because anything bad that's going to happen would happen on the employee's home computer and not make it back to the FTC. It's like watching an explosion on TV -- it might look cool, but you won't have any embers to clean up from your living room carpet.

However, if you were to go out to a nice fireworks store and bring an M-80 firecracker back to your living room and set it off under the ottoman, then you've got problems. Likewise, if employees are tunneling out to their home PCs, they now have a way to completely bypass the FTC firewall and bring files from their home computers (completely open to the Wild Wild West that's the Internet) inside the FTC's secured firewall.

In a sense, because FTC employees can tunnel through the FTC firewall in such a way that their individual Web accesses are hidden due to the Citrix remote desktop functionality, they're even less secure than the folks at Homeland Security. At least the Homeland Security firewalls can see every packet, every IP address, and every Internet protocol used. Not so for the FTC. All that's hidden inside the Citrix tunnel.

What makes this particularly disturbing is there's now a way for FTC employees to purposely bring data inside the firewall -- without any trace. It's possible to monitor the number of bytes used per employee, but no way at all to monitor what those bytes make up within the Citrix tunnel. So what might they bring inside? Hopefully nothing scary. But what if someone wanted to do harm? Who would know?

Remember, the FTC is our leading identity theft protection crusader. This sort of security flaw makes you feel all warm and fuzzy, doesn't it?

Nah, I didn't think so.

At least I didn't pick on the White House this time.

Product availability and resources
Read David's Where Have All The Emails Gone? and find more articles on this topic.

Read "National Archives and Selected Agencies Need to Strengthen E-Mail Management" (PDF).

Read "New 'Red Flag' Requirements for Financial Institutions and Creditors Will Help Fight Identity Theft".

Daniel Koffler is a Contributing Editor to DominoPower. Daniel is a R6 CLP and works as an IT consultant for major organizations in North America and Europe, specializing in network design, security analysis and knowledge management, he is also the author of several OpenSource projects. Daniel can be reached at dkoffler@users.sourceforge.net.


« Previous  ·  1  ·  2  ·  3  ·  4  ·  5
Other articles you might like
Home > Lotus Community > Editorials (71 articles)
   Five trends for 2010
   Say goodbye to the Uh-Ohs. Long live the Tens.
   The editorial strikes back
Home > Strategies > Security (19 articles)
   Incident report: denial of service attack against ConnectedPhotographer.com
   Centralised email encryption at the Domino server level
   Analysis: Spying Chinese temptress steals senior Brit's BlackBerry
Home > Strategies > Legal Issues (12 articles)
   Analysis: Spying Chinese temptress steals senior Brit's BlackBerry
   When the email flood inundates the Domino Server
   An interview with Roger Matus on email archiving and retrieval
Home > Special Reports > White House email controversy (25 articles)
   Analysis: Spying Chinese temptress steals senior Brit's BlackBerry
   The White House email controversy: it's time for a Special Prosecutor
   The worrisome implications of the Mexican theft of White House BlackBerry devices
Get Weekly Email Updates
Subscribe to our regular weekly email newsletter. It's packed with tips, reviews, deep analysis, and the latest news.
 
Recent DominoPower Articles
Application development, William Shatner, and the origin of the universe
Learn Domino Designer 8.5 for free
The (near) future of Sametime, Quickr, Connections, and Symphony
Inside the IBM Innovations lab
Lotusphere 2010: Hot fixes and cool news for Notes, Domino, and LotusLive
Lotusphere 2010: mobility and collaboration
2010: A Lotusphere of change
Latest Lotus Headlines
Xpages not loading? JVM errors? - Solution
How to implement an iCalendar feed into your Notes calendar with XPages
DWA Hotfixes for Domino 8.5.1FP1 - A Gotcha
IBM Adds DB2 to Lotus Foundations SMB Package
SNTT : XPages onclick Ghosts in the machine
Ports used by Lotus Sametime 8.5 servers
Exploring a Domino Date Bug
>> Read all the news
More from the ZATZ journals
Computing Unplugged: The iPad defenders have spoken
David Gewirtz Online: CNN commentary and analysis
OutlookPower: More about disappearing text
-- Advertisement --

Learn Notes and Domino 8 at your place and pace!
Learn Notes and Domino in your office and/or home! TLCC's highly acclaimed distance learning courses for users, developers, and admins will enhance your career and your resume.

The many included activities and demos will make you a pro! Expert instructor help is a click away.

Click here to try a FREE demo course!!

-- Advertisement --

Mark your calendar for in-depth Lotus training, May 12-14, Boston
Join experts and peers May 12-14 in Boston for educational and networking events that deliver real-world Lotus training so you can increase productivity and efficiency in your company, advance your skills, and squeeze the most from your current environment. One registration gets you into THE VIEW's Admin2010 and Lotus Developer2010.

Register by April 10 to save $200.
ZATZ Home  ·  News  ·  Back Issues  ·  Credits/Trademarks ·  Link To Us
Copyright © 1998-2010, ZATZ Publishing. All rights reserved worldwide.
Editor's Login