Contractor firewall shortcut reportedly exposed a route to 50 million immigration records
A former security officer says a low-security datacenter briefly gained network reachability to classified production servers before the rule was reversed.
TLDR
A former government-contractor security officer says developers once changed a firewall rule so a provisioning server in a commercial datacenter could reach production systems in a classified facility. The Register reports that one production server held about 50 million immigration records. Credentials were still required, but thousands could access the lower-security VPN, there was no multifactor authentication and password standards were weak. The rule was reversed after the officer demonstrated the path. The report does not say records were stolen.
Contractor firewall shortcut reportedly exposed a route to 50 million immigration records
A former security officer says a low-security datacenter briefly gained network reachability to classified production servers before the rule was reversed.
TLDR
A former government-contractor security officer says developers once changed a firewall rule so a provisioning server in a commercial datacenter could reach production systems in a classified facility. The Register reports that one production server held about 50 million immigration records. Credentials were still required, but thousands could access the lower-security VPN, there was no multifactor authentication and password standards were weak. The rule was reversed after the officer demonstrated the path. The report does not say records were stolen.