Security researcher Joe Brinkley, a former information system security officer for a government contractor, has described how a firewall rule change created a direct path from a low-security commercial datacenter to a classified server holding about 50 million immigration records.
In the early 2010s, the contractor used a provisioning server to deploy code from development to production. Developers wanted to ease that process by allowing the provisioning server to access production servers in the classified datacenter. Brinkley objected at a Change Review Board, warning that opening a firewall rule from a low-level secured datacenter to a top-secret production environment would let anyone on the commercial VPN — which was shared with non-government tenants like Microsoft and Oracle — potentially reach the high-level datacenter.
While Brinkley was on vacation, the developers took their request directly to the Change Acceptance Board and the rule was changed. Upon his return, Brinkley arranged a demonstration with a company colleague and a government representative. Tethering his laptop to his cell phone, he logged into the dev server over the VPN, then showed he could also reach and control the production server using the same connection.
That server held records on who was coming to the country and who they stayed with — around 50 million entries. According to Brinkley, thousands of people had access to the commercial VPN, but only dozens were supposed to reach the classified datacenter. The production servers still required usernames and passwords, but there was no multi-factor authentication and password standards were low at the time, making brute-force or guessing attacks feasible.
After the demonstration, supervisors immediately reverted the firewall rule. Brinkley told The Register that the incident illustrates how even layered defences like VPNs and passwords are insufficient if organisations sacrifice security for convenience.