CNN TürkMansur Yavaş neden şimdi istifa etti? CHP bu konuda ne dedi?InquirerMarcos honors Quirino Gov. Cua’s legacy in public servicePunchI bear no hatred towards those who abandoned me, says El-RufaiESPN Deportes¡En vivo! Primera práctica en GP de AzerbaiyánThe Jerusalem PostThree-year-old girl sold into marriage for $9000 under 'walwar' custom sparks international outrageBollywood HungamaBREAKING: Love & War to release in IMAX; Sanjay Leela Bhansali returns to the format 9 years after PadmaavatESPNTransfer rumors, news: Bayern's Karl to get 'dream' Real Madrid move?한겨레전통공연에 SKE48 무대까지 공연장으로 변한 펜싱장…25일부터 단체전 돌입Daily MaverickHERITAGE DAY: Reimagining SA’s true heritage somewhere over the rainbow beyond roots, rituals, myths, fairy talesThe South AfricanThe 502 bank branches that offer Smart ID services across South AfricaSky TG24Vanessa Incontrada e Rossano Laurini si sono sposati, cosa sappiamo del matrimonio3DNewsiFixit показала внутренности Steam Frame и похвалила гарнитуру за «продуманный дизайн»
The Daily Newsstand · Free, Always
Thursday, September 24, 2026

Government contractor exposed path to immigration records

Translate

IT took a shortcut when the boss was away, and it led to danger!

Welcome back to PWNED, the column where we look at all the ways your security can become self-owned. Today’s scary story involves government contractors who just had to make their lives easier at the expense of locking down sensitive information.

Have a story about someone leaving a gaping hole in their network? Share it with us at pwned@sitpub.com. Anonymity is available upon request.

Our tale of bureaucratic hell comes courtesy of security researcher Joe Brinkley, who previously worked for a government contractor as an information system security officer responsible for firewall rule changes, plus network intrusion detection and prevention.

REG AD

To improve the contractor's ability to deploy program changes, some of the org's developers wanted to change the firewall rules so it would be easier to move data from a low-security datacenter where they tested new code to the classified datacenter that housed the production server and data. They wanted to be able to VPN into a low-security commercial datacenter, where other non-governmental tenants, such as Microsoft and Oracle, had servers accessible through the same VPN connection. The datacenter itself provided the VPN, not the government. 

REG AD

Back then, in the early 2010s, developers would use a provisioning server to help deploy code from dev to production. But there was always a hard firewall between the classified datacenter and the non-classified datacenter. The developers wanted this provisioning server to be able to access all of the production servers that sat in the classified datacenter so they could more easily push the code around.

When the developers suggested they make this change for ease of deploying code, Brinkley told the Change Review Board that it was a very bad idea.

“It creates a very glaring issue that we are going from a low-level secured datacenter all the way up to a high-level, top secret secured datacenter for production, and you guys are opening up a firewall rule that would allow anybody from that low level datacenter to have access into, at a minimum, into the high level datacenter,” Brinkley said.

However, during a week when Brinkley was on vacation, the developers who wanted this firewall change talked directly to the Change Acceptance Board and got the rule changed.

When he got back, Brinkley got a member of his company and a government representative to sit down for a demonstration. Tethering his laptop to his cell phone, he logged into the dev server over the VPN — then turned the box on and off. Then he showed how, with the very same VPN connection, he could get into the prod server and control it. This was a server that had 50 million records about immigration: who was coming to the country, who those people stayed with, and so on. 

According to Brinkley, thousands of people had access to the commercial datacenter’s VPN, but only dozens were supposed to have access to the classified government datacenter. The change potentially made the production servers reachable from a network accessible to thousands of VPN users.

Yes, the servers still required a username and password for access, but an enterprising hacker could have tried guessing the correct combos or attempting a brute-force attack. There was no multi-factor authentication and password standards were low at the time.

After Brinkley showed supervisors what was going on, they immediately changed the rule back to the way it was before.

REG AD

What we can take away from this lesson is that, even when you have security measures like a VPN and password protection, sensitive data requires additional safeguards. It’s not enough to do the minimum. ®

View the original on The Register

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.