Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Networking
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
Computerworld 2007Subscribe to Computerworld
40 years of the most authoritative source of news and information for IT leaders.

Los Alamos Confirms E-mail Security Holes

Latest problem at nuclear lab: Workers sent classified messages insecurely
 

Sign up to receive Security Resource Alerts

July 26, 2004 (Computerworld) -- Security troubles at Los Alamos National Laboratory continued last week as officials confirmed that workers recently sent out an undisclosed number of classified e-mails over a nonsecure system.
The disclosure came less than two weeks after the New Mexico-based lab announced that two removable computer disks containing classified nuclear weapons data were missing . That incident marked at least the third time since 2000 that storage media containing classified information has been lost at the facility.
Los Alamos spokesman Kevin Roark last week confirmed that the lab recently discovered new incidents of classified information being sent through a nonclassified e-mail system. "We have had occurrences recently, yes," he said. "We have had them in the past. It's anticipated we will have them in the future."
Questionable Judgment
Roark said the incidents occurred when scientists at the lab, which employs about 12,000 people, incorrectly judged information as being classified versus unclassified and sent it without asking for assistance in categorizing the content of their e-mails. Such incidents are always promptly reported to the U.S. Department of Energy and other agencies, as required by law, he said.
When such incidents recur, employees are given additional training to remind them of the proper procedures, Roark said. The problem is that there are "vagaries in the classification rules" that can make it difficult to determine what's classified. Roark said that he couldn't comment on the number of classified e-mails that were sent over the unclassified e-mail system but that it was "a very small number."
"We'd like to get that to zero," he said. "But you've got to understand, you can't legislate perfection on people. All you can do is tell them in security briefings and reiterate it every time you talk about security."
Earlier this month, the lab suspended most activities while continuing the investigation into the missing disks.
Security experts and analysts expressed varied opinions on the recent security incidents at Los Alamos.
Scott Larson, a managing director at Stroz Friedberg LLC, a New York-based consultancy that specializes in computer forensics, acknowledged that accidental releases of sensitive information using nonsecure e-mail systems are unavoidable. But he was critical of the lab's position that such incidents are mostly attributable to human judgment.
"The ... throwing-your-hands-up approach is unacceptable for this kind of information," Larson said. Classified and nonclassified e-mail systems must be completely separate, and the people who use them must be trained to know the difference, he said.
Nathaniel Palmer, a security analyst at Delphi Group in Boston, called the security lapses "scary." Palmer said he's amazed that a nonsecure e-mail system is even used in the lab, when instead one system could be used by everyone and all correspondence could be better monitored.
Other analysts were more forgiving.
Pete Lindstrom, an analyst at Spire Security LLC in Malvern, Pa., said it's possible that the Los Alamos facility experiences no more security lapses than other classified government facilities but that officials there are more willing to discuss problems publicly.




Print this Story Send Us Feedback E-mail this Story Digg! Digg this Story Slashdot this Story
"Mozilla's successful attempt to set a world record for downloads of a single program, Firefox 3 was dumb...." Read more...
"It's the early 1990s when this pilot fish is challenged to find a better way to support telecommuting — and..." Read more...
Read more Networking posts or See all Blogs
Microsoft promises four patches next week
Google gives away home-cooked Web application security scanner
Storm botnet stages Fourth of July attacks
More top stories...
Microsoft trumpets security additions in upcoming IE8
Apple cuts price of high-end SSD MacBook Air by $500
Ultrathin showdown: Apple MacBook Air vs. Lenovo ThinkPad X300 vs. Toshiba Portege R500
All it takes is a couple hours and about $125 to breathe new life into an old laptop. Here's how.
Is Microsoft's Golden Age over? What are Gates' most memorable quotes? Find out in Computerworld's complete coverage of the end of the Bill Gates era at Microsoft.
There are some things your CIO definitely doesn't want to hear. Also don't miss the flipside, Five things you should always tell your boss.
With its latest version, Mozilla's browser continues to raise the bar for what Web browsers should be.
Reviews, analyses, how-tos, visual tours, hot issues and predictions about Microsoft's new OS.
Four years from now, the IT field will be a vastly different place. Will you be ready?
All Zones
Application Performance Zone
Business Continuity Zone
Data Center Management Zone
Enterprise-Class Security Zone
The File Data Management Zone
Grid Computing on Windows Zone
Security Management Zone
ITIL Best Practices Zone
The SAS Zone
Storage Virtualization Zone
Business Intelligence and Analytics Zone

Ads by TechWords

See your link here
Advance your BlackBerry(R) solution management know-how this July
Advance your BlackBerry(R) solution management know-how this July
BlackBerry Technical Seminar, register today!
Go to the webcast 
Accelerate Your Pursuit of Perfection.
Download this white paper, free, compliments of Kodak!
(Source: Kodak) For almost 80 years, Kodak has been helping banks, insurance companies, healthcare providers, government agencies and other businesses produce billions of document images. So Kodak is uniquely positioned to know - and deliver-what customers want: easy-to-use scanners that output the best possible image quality.
Download this white paper go
Computerworld Executive Briefing: Automating Network Management
Download this Executive Briefing now (a $195.00 value), compliments of ProCurve Networking by HP.
(Source: Computerworld) This briefing looks at the basics of network management, which tend to get lost in the dizzying array of products and processes. It also examines new tools that are on the way to help IT executives deal with management in the new era of automation. Download this Executive Briefing now (a $195.00 value), compliments of ProCurve Networking by HP.
Download this executive briefing download
White Papers
Read up on the latest ideas and technologies from companies that sell hardware, software and services.
Deploying Virtualized NetWare on Linux Whitepaper
Toward More Flexible, Next-Generation Collaboration Solutions
Driving Business Success Through Workgroup Choice and Flexibility
View more whitepapers 
Troubleshooting Remote Site Networks - Best Practices
Management and remote site employees expect the same level of network service as the headquarters site. However, when IT staff are faced with limited resources to support remote site networks, often the applications, services and performance at those sites is not as robust as the headquarters site. See how to deliver a high level of network service at remote sites using the best practices outlined in this white paper.

Read whitepaper now
Super-size your LAN with fiber
Fiber optic technology frees the Local Area Network (LAN) from the confines of a single building, allowing a LAN to extend across a campus or a metropolitan area. Read how the selection of fiber optic components affects repeaterless transmission distance and how one school district used fiber to build a more reliable and more cost effective high-speed, district-wide network. Also, read how Metropolitan Area Network (MAN) ownership may require self-assessment of network performance.

Read whitepaper now
Determining the cause of poor application performance
Are users constantly complaining that your network is too slow? Or that they can’t connect or can't stay connected? Are network applications hanging and slowing productivity? Do you spend way too much time trying to isolate the source of the problem and to prove that often the issue isn't the network at all but the application? In this on demand webcast, learn best practices and common root causes of application problems using case studies and live network traffic.

Watch webcast now