Saturday, October 6, 2007

How Secure Are Our Government Websites?

More on the Security Problem that knocked *.ca.gov off the Internet Wednesday afternoon.

Evidently the security problem was larger than first reported. PC World is reporting in Danger Lurks on Government Web Sites in addition to the websites of Madera County, California, Brookhaven National Laboratory websites were also compromised. And as of Thursday morning both Brookhaven and Superior Court of Madera County, California websites were still pointing to inappropriate content. The article continues:

Brookhaven has begun an investigation into the incident, said Tom Schlagel, a manager with the lab's information technology division. "From what I've been told, there isn't any evidence that there's any pornography on the server," he said. "It's all just redirections."

Brookhaven is a U.S. Department of Energy lab that specializes in nuclear and high-energy research.

The security of U.S. government Web sites has been front-page news in California this week after the U.S. General Services Administration, which administers the .gov top-level domain, temporarily removed California's state servers from the Internet's Domain Name System (DNS) infrastructure, apparently because of a security problem on the Web site of a small state agency, the Transportation Authority of Marin.

Observers said that this was an unusually extreme move and one that eventually would have knocked the entire state off the Internet.

The move was caught before it caused widespread service outages within the state government, but it drew attention to an underlying issue: compromised governmental Web sites.

The GSA on Thursday said it has revised its policies to avoid another possible statewide shutdown, but it defended its right to remove .gov sites from the Internet. "The potential exposure of pornographic material to the citizens -- and tens of thousands of children -- in California was a primary motivator for GSA to request immediate corrective action," a GSA spokeswoman said in an e-mailed statement. "Also, in these days of heightened security concerns from hackers, it is important to quickly stop potentially harmful damage to federal, state and local Web sites from those who have no love for our country."

Alex Eckelberry, the president of Sunbelt Software Inc. who first reported the problem that led to the California shutdown, said that the government could do better. "Once you're on the Web, especially if you're government, you really have to be responsible for your content," he said. "We have to have some sort of recognition that there is constant danger and that people need to stay on top of their sites."

However, educational sites, hosted within in the .edu top-level domain, have far more problems than the .gov sites, Eckelberry said.

Security professionals like Eckelberry complain that poor response from Web site administrators means that even when problems are discovered by outside researchers, it's often hard to report them.

For example, the Madera Superior Court site has a "Click Here To E-mail Our Webmaster" link on the bottom of its front page, but when Trend Micro Inc. Network Architect Paul Ferguson used it to inform the court that its site had been hacked, his e-mail bounced back as undeliverable. Madera Superior Court representatives did not return a call seeking comment.

"It is almost impossible for someone like, say, a security researcher to find the right person to report problems to," Ferguson said via e-mail. People outside of government cannot do "Whois" queries on the .gov domain, which would yield contact information for site administrators, he added. "In many cases, either the contact information is incorrect, nonexistent, or the 'lights are on and nobody is home'."

"Everyone has really got to do a better job on securing the Internet," Ferguson added. "You can't just put a Web server out there and forget about it any more."
Security problems with both data thefts and security breaches are going to continue to get worse as technology continues to allow us access to more and more data at our finger tips.

It is time for governments, on local, state and national levels to learn about the current risks, what the future risks are, and finally what our nation's security experts suggest to solve the problems.

If the government officials can't understand the complexities then they need to seek help in understanding them, and in helping the officials draft legitimate security laws that will be effective when implemented. Any new laws governing the industry will need to have teeth if there is any hope to bringing these problems under control.

Sphere: Related Content

0 comments: