Snowden's role provided 'perfect cover' for NSA data theft
NSA official says fugitive document leaker wasn't "that clever,' he just happened to be in right place at the right time
Computerworld - Fugitive document leaker Edward Snowden's role as a systems administrator provided easy access to classified National Security Agency documents sitting in a file-sharing location on the spy agency's intranet portal.
The documents were kept in the portal so that NSA analysts and other officials could read and discuss them online, NSA CTO Lonny Anderson told National Public Radio in an interview Wednesday.
As a contracted NSA systems administrator with top-secret Sensitive Compartmented Information (SCI) clearance, Snowden could access the intranet site and move especially sensitive documents to a more secure location without raising red flags, Anderson said.
Thus, Snowden could steal the NSA Power Point slides, secret court orders and classified agency reports that he leaked to the media. "The assignment was the perfect cover for someone who wanted to leak documents," Anderson told NPR.
"His job was to do what he did. He wasn't a ghost. He wasn't that clever. He did his job," Anderson said.
Since the leaks, the NSA has taken several steps to plug such holes in its security. For instance, a new "two-person rule," which stipulates that two individuals with similar roles and authority must act together to execute specific functions, including the storing or backing up of data.
Those with privileged access to systems, like system and network administrators, are no longer anonymous on the NSA network -- all of their actions will be observable, Anderson told NPR.
The NSA has also started "tagging" sensitive data and documents to ensure that only people with a need to see a documents can access it. The document tagging rule also lets security auditors see how individuals with legitimate access to the data are actually using it, Anderson said.
While NSA employees can still access the intranet used by Snowden to steal documents, new controls won't allow such thefts to happen again, he said. "Could someone today do what [Snowden] did? No," Anderson claimed.
Anderson's revelations shed a bit more light on how Snowden could access and download tens of thousands of sensitive documents from the protected NSA systems. It's still unclear, though, how he managed to download the data onto thumb drives and take them from the workplace without being noticed.
Security experts have pointed to the Snowden caper as a classic example of how insiders, especially workers with privileged access to systems, could steal corporate data.
A survey of mostly medium-sized companies by security vendor Symplified earlier this year found that more than half had authorized network access to 250 or more external partners, contractors and consultants. About 55% of respondents said 1,500 or more employees have privileged access to corporate applications.
"Insider attacks and unauthorized access happen much more often than you may think," said Darren Platt, CTO of Symplified.
Platt said an employee, for instance, could download a customer database and take it to a competitor, a contractor could use his or her access to personnel information for personal gain, or a former employee could access applications as a corporate spy.
"Companies need to shift their thinking from an outside-in model of security to an inside out approach," said Eric Chiu, founder of Hytrust, a cloud infrastructure management company.
"Only by implementing strong access controls [like] the recent NSA 'two-man' rule as well as role-based monitoring, can you secure critical systems and data against these threats and prevent breaches as well as data center failures," he said.
Jaikumar Vijayan covers data security and privacy issues, financial services security and e-voting for Computerworld. Follow Jaikumar on Twitter at @jaivijayan, or subscribe to Jaikumar's RSS feed . His email address is email@example.com.
- Researcher claims two hacker gangs exploiting unpatched IE bug
- Update: Third of Internet Explorer users at risk from attacks
- Microsoft plans another short patch slate for next week, but finds a few XP bugs to crush
- Target attack shows danger of remotely accessible HVAC systems
- Target hackers try new ways to use stolen card data
- Update: Microsoft to patch just-revealed Windows zero-day tomorrow
- NSA spying prompts open TrueCrypt encryption software audit to go viral
- Microsoft warns of Office zero-day, active hacker exploits
- Hackers move to create next Blackhole after 'Paunch' arrest
- Adobe hack shows subscription software vendors lucrative targets
Read more about Security in Computerworld's Security Topic Center.
- 15 Non-Certified IT Skills Growing in Demand
- How 19 Tech Titans Target Healthcare
- Twitter Suffering From Growing Pains (and Facebook Comparisons)
- Agile Comes to Data Integration
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- The 12 PCI DSS 3.0 requirements addressed by Peer 1 Hosting This handy quick reference outlines the 12 PCI DSS 3.0 requirements, who needs to be compliant and how Alert Logic solutions address the...
- Defense Throughout the Vulnerability Life Cycle This whitepaper provides insight into how to leverage threat and log management technologies to protect your IT assets throughout their vulnerability life cycle.
- Mobile Policy Checklist Here's what to consider when putting together a mobile policy designed to support a highly productive workforce.
- Securing BYOD Mobile computing is becoming so ubiquitous that people no longer bat an eye seeing someone working two devices simultaneously. Individuals and organizations are...
- Live Webcast On-demand webinar: "Mobility Mayhem: Balancing BYOD with Enterprise Security" Check out this on-demand webinar to hear Sophos senior security expert John Shier deep dive into how BYOD impacts your enterprise security strategy...
- Live Webcast Endpoint Backup & Restore: Protect Everyone, Everywhere Arek Sokol from the bleeding-edge IT team at Genentech/Roche explains how he leverages cross-platform enterprise endpoint backup in the public cloud as part...
- Streamline Software Asset Management, Compose a software Management Symphony Keeping track of your organization's software is easy with effective software management solutions from CDW. View the videos in our software solutions channel
- Druva inSync: Endpoint Data Protection & Governance CLICK HERE to watch this video about protecting corporate data on laptops and mobile devices, sponsored by Druva. All Security White Papers | Webcasts