Friday, November 15, 2013

China's Fake Fear of Cisco, et. al.

My grandmother used to tell us that accusing someone of doing something you were already doing yourself, was like the pot calling the kettle black.  Today that is not so easy to understand, but back in those days, cast iron was black, the stove fires burned every pot black, so it fit.

We have the best example, in a long time, characterized in a Spencer Ante article in today's Wall Street Journal.  (see NSA Fallout:  Tech Firms Feel a Chill Inside China)  The article says IBM, Cisco, HP, and Microsoft have all suffered declining sales in China due to two things:  increased emphasis on buying Chinese products and concern over NSA surveillance.  We should probably understand that businesses do not find this kind of setback very funny, but it was hard not to laugh at the reasons given for it.

The Chinese, who have so far managed to steal every piece of electronic data they could get their hands on, can't be very concerned with NSA.  They used the same kinds of excuses to harass Walmart and Rio Tinto, accusing the latter of stealing "state secrets" so named after they came into their possession.  It is just intimidation.  Walmart had action brought against them for making too much profit.

I'm surprised more wasn't made of Huawei and ZTE restrictions in the U.S.  We still acuse them of being connected to Chinese Intelligence and both deny any such association.  Maybe it is easier to say they "worry" about NSA surveillance, than to fight the allegations against both of them.  They undermine U.S. sales in China to benefit their own companies.  We owe them a little retribution.

Obamacare Website Security-2

We finally got to hear testimony from some of the people who were responsible for creating the mess on the Obamacare website, which poses risk to data in their networks.  A couple of interesting things came from it.

1.  MITRE was doing the Independent Verification &Validation part of the evaluation of the security features of the system.  CMS hired an ethical hacker to augment their security testing.  He found 7-10 items which were "not serious".

2.  MITRE published a report, portions of which were redacted because they showed vulnerabilities to the system.  This is actually a good thing, since publication would make it even easier to get into the site, something a normal user cannot do.

3.  Only a short part of MITRE's report was read in the open hearing, but it contained the following gem of information:  "MITRE was unable to evaluate the Confidentiality or Integrity of the system" because it wasn't ready.  The three elements of the security evaluation, Confidentiality, Integrity and Availability, were not even done, yet the Administrator of CMS felt confident enough in their design to sign off on the risks.  If good designs were enough, we could throw away those acquisitions manuals and buy good designs.  On what basis HHS could make such a decision is a mystery.  We know Availability failed.

Several sources today (http://www.nextgov.com/health/2013/11/cms-manager-who-okayed-healthcaregov-missed-security-memo/73625/) site portions of a report saying the security risks were "limitless" in this system.  When has anyone ever seen an evaluation like this result in an Authority to Operate (ATO)?

4.  Mr. Chao, the Deputy CIO at CMS, said security testing was completed at the component level, but was not able to be completed end-to-end.  Component level testing would not include the interfaces to the other systems that connect our sensitive data to this portal.  Does CMS feel comfortable accepting that level of risk?  Do the other agencies connecting to this portal feel comfortable with accepting them?  A Hill article today (http://thehill.com/blogs/healthwatch/health-reform-implementation/189916-top-cms-official-didnt-know-about-obamacare) says Chao was not included on parts of the request for sign-off on the ATO.  That didn't seem to keep him from rationalizing the lack of security testing.

5.  Mr. Powner, from GAO, twice cautioned that we should be concerned about security while the system is being built.  Considering that no security testing had been done that would justify granting an ATO, the risks climb dramatically with changes that are being made on the fly, where political pressures abound.  Will the system be tested before the 30th of November when all the changes are supposed to be done?  Not likely.  They cannot even get the portal to work like a portal. Until it is stable, it would be difficult to test.

We should think twice about putting any data into this system until it is operational, the security testing is complete, and the vulnerabilities are corrected.  You can bet the Chinese are already hacking this goldmine.  Amazon books:  

Friday, November 8, 2013

Obamacare Website Security Testing

The Obamacare website fiasco, about which much has been said, is not just the story of a failed website.  Lost in the analysis, was a small sentence that indicated security testing had not been done, "because there was a lack of time".  I have heard this excuse, more than once, by some of the biggest software vendors in the land.  What it boils down to is a priority list of things that must be done, and security testing doesn't make the list.

What it means to users is simple:  We will take the risk with your data, while we make improvements to the website.

Who can make that kind of decision, and how can they rationalize signing off on risks that are not theirs to take?  The person responsible for security of the site was a man named Tony Trenkle, CIO at Centers for Medicare and Medicade Services, who according to the CBS news story at http://www.cbsnews.com/8301-250_162-57611202/departing-obamacare-security-official-didnt-sign-off-on-site-launch/, resigned this week and is now gone.  He would not sign off on the acceptance of risk, but CMS Administration, Marilyn Tavenner did.  CBS's article goes on to say "HHS also says there is an aggressive risk mitigation plan in effect, "the privacy and security of consumers personal information is a top priority for us" and personal information is "protected by stringent security standards."  Of course, without security testing, they are not in any position to say what the risks are to the data.  

Tavenner's testimony http://oversight.house.gov/wp-content/uploads/2013/07/Tavenner-CMS-Statement-PPACA-Data-Hub-7-17.pdf  gives broad assurances that security was met through FISMA, indicating she neither understands, nor appreciates, what FISMA actually does.  Years from now, we might see a FISMA report telling us what shortcomings have to be corrected to meet existing requirements, but it won't be soon.  

More than once, I have been in the position to brief the person responsible for acceptance of risk.  I asked them to acknowledge the risks, accept the mitigation strategy (which limits the amount of time the risk will exist), and fund the mitigation effort.  Only on rare occasions will the person in charge decline, and almost always, they decline for a good reason.  Usually, there is enough significant risk that going operational is not a good option, but delaying will have serious political consequences.    Trenkle would have known there was no security testing, so there was no way to measure the amount and type of risk that had to be mitigated.  He also knew the consequences of delay were higher up the food chain.  So, he declined to sign.  Smart man.  

Today's Politico http://www.politico.com/politico44/2013/11/white-house-blocks-tech-chief-from-testifying-on-obamacare-177047.html  says the White House is declining to allow Todd Park to testify on the Hill because he is "too busy" repairing damage to the site. The House Committee on Oversight and Government Reform will call a witness list that includes HHS Deputy Assistant Secretary for Information Technology Frank Baitman, CMS Deputy Chief Information Officer Henry Chao, U.S. Chief Information Officer Steve VanRoekel and David Powner, Director of IT management at the Government Accountability Office.  Maybe someone could ask how they make a risk assessment on a system that had no security testing done on it.   Amazon books: