
Government contractor's firewall shortcut exposed path to 50M immigration records
In The Register's PWNED column, security researcher Joe Brinkley recounts how a firewall rule approved while he was on vacation opened a path from a commercial datacenter to a classified server holding 50 million immigration records.
A firewall rule altered while the security officer was away on vacation briefly opened a path from a commercial datacenter to a classified government production server holding 50 million immigration records. The account, published in The Register's PWNED column on September 24, comes from security researcher Joe Brinkley, who worked at a government contractor as an information system security officer in charge of firewall rule changes, network intrusion detection, and prevention.
The events date to the early 2010s. Developers tested new code in a low-security datacenter and shipped it onward to a classified datacenter that housed the production server and its data, and they wanted that flow made easier. They asked for firewall changes so their provisioning server — the machine that helped deploy code from development to production — could reach every production server inside the classified facility. They also wanted to VPN into a low-security commercial datacenter where non-government tenants, Microsoft and Oracle among them, kept servers reachable through the same connection. The datacenter itself provided the VPN, not the government.
Warned against, approved anyway
Brinkley told the Change Review Board the change was a bad idea. "It creates a very glaring issue that we are going from a low-level secured datacenter all the way up to a high-level, top secret secured datacenter for production," he said, "and you guys are opening up a firewall rule that would allow anybody from that low level datacenter to have access into, at a minimum, into the high level datacenter." While he was away, the developers took the request straight to the Change Acceptance Board and got the rule changed.
A laptop, a phone, and the production server
Back at work, Brinkley gathered a company colleague and a government representative for a demonstration. Tethering his laptop to his cell phone, he logged into the development server over the VPN and turned the machine on and off. Then, through the very same connection, he logged into the production server and controlled it. That box held 50 million records about immigration: who was coming to the country, who those people stayed with, and more. Thousands of people could reach the commercial datacenter's VPN; only dozens were supposed to access the classified government network, so the rule had put production servers within reach of everyone in the larger pool. A username and password were still required, but with no multi-factor authentication and low password standards at the time, guessing or brute-forcing was plausible.
The takeaway
After the demonstration, supervisors immediately changed the rule back. The lesson, as The Register frames it: a VPN and a password prompt are not safeguards on their own. Sensitive data needs more, and doing the minimum is not enough.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.