Sensitive DoD emails exposed by unsecured Azure server
- Reference: 1677180613
- News link: https://www.theregister.co.uk/2023/02/23/azure_dod_emails_exposed/
- Source link:
According to security researcher Anurag Sen, who discovered the blunder and reported it, the openly accessible server was part of an internal mailbox system hosted on Azure Government Cloud and used by the Department of Defense for a variety of purposes – including the processing of security clearance paperwork.
Sen [1]reportedly found the exposed public-facing server over the weekend and determined it was sitting there without a password, allowing anyone who had its IP address and a browser to access the data.
[2]
Documents Sen shared with The Register said to be from the exposed server include a rich amount of data that certainly be valuable to a foreign adversary. It included all the usual PII, as well as blood type, religious affiliation, educational background, military service history and more, all in plain text. Sen told us that close to 3TB of data was available before the Azure server was taken offline on Monday.
[3]
[4]
Per Bloomberg, which [5]said it spoke to individuals at the DoD and Microsoft, both the Pentagon's Cyber Command and Microsoft are investigating the incident. The server was reportedly accessible to the internet since February 8 before being secured and removed from public access.
Thus far in the probe, there's no sign the data was accessed by miscreants, DoD sources told Bloomberg.
Blame is good for business, just probably not Microsoft's
The Pentagon and Microsoft have reportedly blamed each other for the error, but without receiving answers to our questions from either party there's only so much that can be determined, namely that an internal DoD email server appears to have been given a public IP without any sort of password protection.
No matter who's to blame, someone messed up. If the DoD's Inspector General's office is to be believed, there's a good chance that the fault lies within the government for misconfiguring its IT environment, and not Microsoft.
[6]
An audit of the DoD's compliance with commercial cloud security requirements [7]published [PDF] earlier this month found that every single branch was failing to properly evaluate commercial cloud service offerings (CSOs).
[8]AWS puts datacenter in shipping container for the Pentagon
[9]The Pentagon is shockingly bad at managing its employee smartphones
[10]Oracle, Microsoft barely compete for a quarter of their US Federal contracts
[11]Chinese surveillance balloon over US causes fearful gasbagging
According to the audit report, authorizing officials "did not review all required documentation to consider the … risks to their systems," nor did they "consider system risks that were identified in the supporting documentation" as "all five [authorizing officials] believed the [government acquisition] processes were sufficient to mitigate risk to their respective systems."
With that in mind, said the redacted report, the Inspector General wants CIOs from the Army, Navy/Marines and Air Force to "reevaluate the authorization to operate for the five cloud systems we reviewed," but didn't state which systems it investigated.
The government has contracts with Amazon Web Services, Google Cloud, Oracle, and Microsoft for its cloud program, and each offers several services as its part of the deal. The IG report said it examined five cloud systems from three authorized companies as part of the review.
The [12]latest Microsoft system to get approval – Office 365 Government Secret Cloud – is cleared for operation at Impact Level 6, the highest level of classification allowed in the commercial cloud. Other systems approved for DoD cloud use only reach IL5.
[13]
Approval for the new security level of Office 365 comes as the federal government tries to build out its $9 billion Joint Warfighting Cloud Capability program [14]authorized late last year that replaced the JEDI program, which intended to award Microsoft the sole cloud contract for the DoD. Amazon, Oracle and Google all complained that making Microsoft the sole awardee would be unfair, leading to the JEDI program being [15]canceled in 2021.
With the DoD and Microsoft now apparently trying to blame each other for an egregious security failure, the window is open for those other three to swoop in and further disrupt the Redmond/DC relationship.
A relationship that, mind you, has [16]already been reassessed once this year and found wanting. ®
Get our [17]Tech Resources
[1] https://techcrunch.com/2023/02/21/sensitive-united-states-military-emails-spill-online/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y-fwDzPV9eEhUJyo-PkUxgAAAA8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y-fwDzPV9eEhUJyo-PkUxgAAAA8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y-fwDzPV9eEhUJyo-PkUxgAAAA8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.bloomberg.com/news/articles/2023-02-22/pentagon-and-microsoft-investigating-leak-of-military-emails
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y-fwDzPV9eEhUJyo-PkUxgAAAA8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://media.defense.gov/2023/Feb/16/2003163086/-1/-1/1/DODIG-2023-052.PDF
[8] https://www.theregister.com/2023/02/15/aws_modular_datacenters/
[9] https://www.theregister.com/2023/02/13/pentagon_mobile_security/
[10] https://www.theregister.com/2023/02/01/oracle_microsoft_us_government/
[11] https://www.theregister.com/2023/02/03/chinese_surveillance_balloon_over_us/
[12] https://www.theregister.com/2023/01/31/microsoft_office_365_dod/
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y-fwDzPV9eEhUJyo-PkUxgAAAA8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[14] https://www.theregister.com/2022/12/08/joint_warfighting_cloud_capability_awarded/
[15] https://www.theregister.com/2021/07/06/jedi_contract_canceled_pentagon/
[16] https://www.theregister.com/2023/01/12/congress_hololens_microsoft/
[17] https://whitepapers.theregister.com/
Fools (+1)
Fools.
Running secret / top-secret / military stuff on someone`s else computer (the cloud).
Use ON-PREM hardware / software for classified stuff. Or else.
Back when I was in
Top secret information was hosted only on computers behind secure doors, and only connected to each other over direct link circuits that were encrypted on either side of the circuit before it hit a circuit access point. And, the crypto key was changed very regularly. And now they're using the regular internet and Microsoft servers maintained by foreigners? Somebody put their wallets ahead of national security, and it's already been compromised. How special. Whoever authorized this should be put away and never see the light of day again.
BlameShift
Sounds like a good idea for the new SaaS product that could keep blame resolutions in the blockchain and give NFT certificates to the interested parties with how has been assigned the blame for what.