Reading view

There are new articles available, click to refresh the page.

Sen. Wyden urges feds to discard older, insecure, public-facing VPNs

Sen. Ron Wyden implored a trio of federal leaders Monday to lead a comprehensive campaign to purge older, insecure virtual private networks that are directly accessible via the public internet from federal agencies.

“For too long, federal agencies and government contractors have suffered devastating cyberattacks due to their reliance on legacy, insecure, internet-facing VPN servers to grant employees remote access,” Wyden, D-Ore., wrote in his missive to top officials at the Office of Management and Budget, Cybersecurity and Infrastructure Security Agency and National Institute of Standards and Technology. They should coordinate “require the adoption of modern, secure remote-access technology across the federal government,” he said.

Such VPNs serve as a digital “front door” accessible via the public internet that allows mobile devices and remote employees to log in, Wyden said in a letter first reported by CyberScoop.

Wyden referenced several attacks that have affected federal agencies, including the ArcaneDoor attacks on Cisco firewalls, the FortiBleed credential exposures across Fortinet gateways and vulnerabilities that hackers exploited across Ivanti and Check Point VPN appliances.

“Modern remote-access solutions eliminate this vulnerability entirely. Instead of leaving an open door accessible from the public internet, modern solutions provide remote access without broadcasting their presence,” he said. “This effectively makes these servers invisible, ensuring that hackers cannot attack an entry point they cannot see.”

Agencies should move away from what a Congressional Research Service report to Wyden called a “castle-and-moat” approach of assuming anyone inside the network is authorized to access an organization’s resources that VPNs rely upon by extending virtual bridges to a more remote workforce, he said. They should instead focus on zero-trust architecture that uses a never-trust, always-verify approach, he said.

Furthermore, CISA, the OMB and NIST need to fundamentally change how the federal government approaches agency vulnerabilities, Wyden wrote. 

“The federal government has become trapped in an endless game of ‘whack-a-mole’ in responding to widespread compromises of legacy remote access technologies,” he said. “To keep federal networks online, CISA has been forced to repeatedly issue extraordinary Emergency Directives and hyper-accelerated patch mandates. These reactive emergency mandates are unsustainable for federal cybersecurity teams, and fail to address the fundamental issue that these flaws are inherent in the use of legacy remote-access appliances.”

CISA needs to issue a binding operational directive that gives agencies two years to fully expunge legacy, public-facing remote access systems, he said. NIST needs to issue implementation standards for transitioning to zero-trust architectures.

OMB needs to issue a memo directing agencies to prioritize zero-trust architecture spending. And OMB needs to team with CISA and the Defense Department to update procurement rules to block agencies and defense contractors from buying network edge, VPN or other remote access solutions unless a vendor supplies an attestation that it complies with NIST zero-trust standards, Wyden wrote.

The post Sen. Wyden urges feds to discard older, insecure, public-facing VPNs appeared first on CyberScoop.

ATF cancels controversial commercial geolocation contract

The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) canceled a contract with Penlink that used ad-surveillance technologies to track the location of Americans.

The contract was canceled a little more than a month after ATF Director Robert Cekada acknowledged under questioning from Rep. Michael Cloud, R-Texas, in a congressional hearing that the agency was purchasing the geolocation data of Americans through a contract for “an ad-tech type thing” that would provide the agency with geolocation data “based on the ads that go through.”

 “We have purchased access to that system but we have not used it for a criminal case because we have not established any policies yet on how we would do it,” Cekada said.

He described that system and data as novel and said ATF was still determining how to craft official guidance for how agents would use it in investigative work.

In an email, an ATF spokesperson confirmed to CyberScoop that the contract had been canceled, describing it as a limited pilot project for capabilities the agency was no longer seeking.

”ATF continually evaluates tools and techniques to enhance our investigations and ultimately reduce violent crime in American communities,” the spokesperson wrote. “We did conduct a pilot with Webloc to determine if it could improve our investigative capabilities. After completing our review, we determined the tool does not meet our needs and cancelled the contract. ATF is not currently using any other ad-tech-sourced services.”

According to Sen. Ron Wyden, D-Ore., he requested and his staff received a briefing from ATF on the matter on June 12. In the meeting, Cekada identified purchasing licenses for Penlink’s Webloc commercial location surveillance tool as the contract in question.

Further he said the ATF had already conducted more than 340 searches using the system, including more than 222 that were directly tied to active ATF case numbers.

On its website, Penlink describes itself as an open-source intelligence analysis platform that provides real time data collection, forensic and web analysis and digital evidence collection. The firm touts its use of “AI-driven analysis” to increase case resolution rates by 80% as well as the ability to “tie disparate data together to one subject, place, or group using comprehensive identity resolution capabilities.”

Wyden, who earlier this year led a group of 70 congressional Democrats calling for an investigation into the purchase of commercial location data by Immigration and Customs Enforcement, said that ATF ultimately did “the right thing” but called for Congress to pass his legislation that would change the practice throughout the federal government.

“After Representative Cloud and my staff informed the ATF about the legal and privacy quagmire surrounding adtech data,  the agency did the right thing,” Wyden said in a statement. “Canceling this contract is a victory for Americans’ constitutional rights, but Americans’ privacy shouldn’t depend on ad hoc congressional interventions. Congress must pass the Government Surveillance Reform Act to close the data broker loophole once and for all.”

Wyden’s office noted that the purchase of ad-tech geolocation data is illegal in some states, and that the Federal Trade Commission has already established that selling sensitive location data to government agencies and contractors falls under deceptive and unfair practices under the FTC Act.

The use of ad-tech to surveil and geolocate targets online is a growing problem. While such tools are commonly used by marketing and advertising agencies to send targeted ads based on geography or region, bad actors can also use use to unmask the identities or locations of individuals, or combine them with other public data in ways that worry privacy advocates. A University of Tennessee student is suing a company based in the Virgin Islands for pulling videos from her social media, turning them into nonconsensual ads for their dating service and then using ad-tech geolocation to serve the ads to men online near her.

Wyden’s office said in one instance, the tool was used to get location data for devices associated with a defense contractor at the same time as a suspected arson incident, but that the ATF later backed off from using it in court after both the prosecutor and judge expressed “serious discomfort with the use of warrantless adtech data.” The ATF ultimately opted to seek a court order for bulk cell phone tower data instead.

The post ATF cancels controversial commercial geolocation contract appeared first on CyberScoop.

Congress kicks the can down the road on surveillance law (again)

Congress extended a controversial surveillance law for 45 days on Thursday, hours before its latest expiration following an earlier extension.

The Senate passed — then the House cleared — a 45-day extension of Section 702 of the Foreign Intelligence Surveillance Act, which authorizes warrantless surveillance of foreign targets. But those targets are sometimes communicating electronically with Americans, and intelligence officials can search the database using their identifying information, which has long given privacy groups and privacy-minded lawmakers heartburn.

The 45-day reprieve gives lawmakers more time to hammer out a lasting deal, and comes after the leaders of the Senate Intelligence Committee agreed to send a letter to the Director of National Intelligence and attorney general, seeking swift declassification of a letter on a classified ruling from the Foreign Intelligence Surveillance Court.

Sen. Ron Wyden, D-Ore., had sought release of that opinion, and had resisted giving unanimous consent for the latest short-term extension to move forward until Senate Intelligence Chairman Tom Cotton, R-Ark., and top panel Democrat Mark Warner of Virginia agreed to send the letter.

A declassification review was already underway, but the Cotton-Warner letter states that “We expect that this declassification review will be completed and the FISC opinion released publicly within 15 days,” according to Wyden, speaking on the Senate floor.

The March 17 opinion reportedly came with annual recertification of the warrantless surveillance program. The Justice Department is appealing that ruling because it blocked them from using certain tools to analyze communications.

“A few weeks ago, the Foreign Intelligence Surveillance Court found major compliance problems related to the surveillance law known as section 702,” Wyden said earlier this month. “These compliance problems are directly related to Americans’ Constitutional rights.”

Senate Majority Leader John Thune, R-S.D., said the extension will give lawmakers additional room to hold “discussion on reforms.”

The House this week had passed a 3-year reauthorization with some changes to the surveillance program, but key to doing so was leadership’s agreement to attach legislative language on a separate matter that would ban a central bank digital currency. Thune had said that language was going nowhere in the Senate.

On Thursday, the House voted 261-111 to extend the law for 45 days. President Donald Trump has sought a “clean” 18-month reauthorization of the surveillance powers.

The extension continues a perennial ritual for the Hill when it comes to Section 702: A deadline looms, and Congress kicks the can down the road repeatedly.

The post Congress kicks the can down the road on surveillance law (again) appeared first on CyberScoop.

❌