Juniper Hack: DHS Tells Agencies to Close Encryption Backdoors

A view of the National Cybersecurity and Communications Integration Center in Arlington, Va., Tuesday, Jan. 13, 2015, before President Barack Obama spoke. Obama renewed his call for Congress to pass cybersecurity legislation, including a proposal that enc

A view of the National Cybersecurity and Communications Integration Center in Arlington, Va., Tuesday, Jan. 13, 2015, before President Barack Obama spoke. Obama renewed his call for Congress to pass cybersecurity legislation, including a proposal that enc AP Photo/Evan Vucci

The government is scouring its IT inventory to identify affected Juniper systems.

The Department of Homeland Security and federal agencies are in incident-response mode as they work to remove listening posts in software planted by suspected cyberspies.

The unauthorized code can allow attackers to invisibly decrypt communications passing through widely used Juniper Networks firewalls, according to the company. The existence of the 3-year old bug was disclosed Dec. 17. The government has spent about $13 million on Juniper products since 2012, according to the federal funding-tracker USASpending.gov.

Currently, the government is scouring its IT inventory to identify affected Juniper systems -- plus any information that ever touched a Juniper firewall.

It is believed a foreign party rigged the software. Reports this week suggested the assailants might have taken advantage of a weakness the National Security Agency allegedly placed in a popular encryption formula.

Dave Aitel, who worked at the code-breaking agency and now serves as chief technology officer at cybersecurity firm Immunity, said the discovery of an unauthorized backdoor in Juniper's encryption program demonstrates precisely why even legal backdoors can backfire. 

The hack reinvigorated an already-tense debate about encrypted communications, which consumers increasingly are using for privacy and terrorists increasingly are using to evade law enforcement's eyes and ears. The FBI wants tech providers to be able to break coded messages, when served with a warrant. 

"We have every presidential candidate talking about crypto backdoors and no one can really point to why they are so dangerous,” Aitel said. But the Juniper software tampering is "a perfect case example of why cryptographic backdoors are so dangerous in the real world.”

As it happens, DHS Secretary Jeh Johnson, whose agency is responsible for helping agencies fix the Juniper vulnerabilities, recently raised alarms about a world without so-called backdoors for law enforcement.

In April, Johnson told RSA cybersecurity conference attendees, "I understand the importance of what encryption brings to privacy," but "our inability to access encrypted information poses public safety challenges." 

Taking Stock

DHS currently is assessing the risk the Juniper compromise poses to government systems, according to the department.

"It's not just about the machine," Aitel said. "It's about all the data that ever went through the networks that that machine was connected to. It's really painful. They have to look at their supply chain," including the many corporate contractors handling agency data. What if one of their major suppliers uses juniper and now they can't trust that supplier either?"

Many federal agencies do not have a firm grasp on how many systems they have, in general, which could complicate the scavenger hunt. 

The Internal Revenue Service could not update 1,300 of its computers from Microsoft Windows XP to Windows 7 because the agency couldn’t find them all, according to a report released by the Treasury Inspector General for Tax Administration. As of the third quarter of fiscal 2015, 17 of the 24 major federal agencies could not automatically identify the number of software programs running on their network, according to Performance.gov, a federal goal-tracking site. And 16 departments could not detect how many devices were connected to it. 

Homeland Security, which oversees civilian cybersecurity, has a few tools at its disposal to spur agency action. 

DHS spokesman S.Y. Lee said in an emailed statement the department is aware of reports regarding Juniper's software and is still evaluating the potential ramifications. 

"As we routinely do when such vulnerabilities are brought to light, we are assessing the potential impact, if any, on federal networks, and will take any appropriate mitigation measures in close coordination with interagency partners," he said. The department is advising agencies to review the critical steps recommended by Juniper and "to update their software."

A DHS official told Nextgov that Homeland Security has been and remains in close touch with the company. The department’s U.S. Computer Emergency Readiness Team "has provided information to all federal agencies to patch this potential vulnerability and stands ready to offer further assistance if requested," the official said. 

The 2014 Federal Information Security Modernization Act empowers DHS to issue "binding operational directives,” but it is unclear whether Homeland Security has done so in this situation.

It’s also unknown whether DHS is scanning all other agencies’ networks for vulnerabilities through an intrusion-prevention tool called EINSTEIN, an action permitted under an executive branch memo issued last year. A federal spending bill that Congress cleared last week, and now awaits President Barack Obama's signature, would cement into law DHS' ability to scan every civilian agency network.  

A Whodunit

The Juniper emergency brings to mind a 2014 governmentwide race to root out "Heartbleed," a bug discovered in April of that year that allowed hackers to weasel into another type of widely-used encryption software. Similarly, after Chinese spyware pinched private records on 21.5 million former personnel, individuals applying for clearances to handle classified information, and their families. Homeland Security deployed EINSTEIN during both incidents. 

On Tuesday, Wired's Kim Zetter reported NSA inadvertently might be to blame for the Juniper software bug.

An analysis "suggests that the Juniper culprits repurposed an encryption backdoor previously believed to have been engineered by the NSA, and tweaked it to use for their own spying purposes," according to Wired.

Aitel, the former spy agency employee, said the Juniper campaign cast too wide a net to be the brainchild of NSA.

The federal government "could not legally covertly trojan the source code of a US company," he said in a Dec. 18 blog post, shortly after the revelations. Past NSA hacking operations, such as one that allegedly bugged select Cisco equipment shipments en route to adversaries, demonstrate that America's "policy in this area” is “specificity when it comes to targets.”

Early news reports indicated the FBI is investigating the Juniper matter. On Tuesday, FBI officials referred Nextgov to DHS and said they had no comment on whether any investigation is underway. 

Juniper officials on Dec. 17 acknowledged the security vulnerabilities in virtual private network tools ScreenOS 6.2.0r15 through 6.2.0r18 and 6.3.0r12 through 6.3.0r20, and the company simultaneously released patches.  

"During a recent internal code review, Juniper discovered unauthorized code in ScreenOS that could allow a knowledgeable attacker to gain administrative access to NetScreen devices and to decrypt VPN connections," Juniper Chief Information Officer Bob Worrall said in a post on the company's website. As of now, the company has not received any reports of the vulnerabilities being exploited.

When Nextgov asked how the company is assisting federal victims, a Juniper spokeswoman said, "We have reached out to affected customers, strongly recommending that they update their systems and apply the patched releases with the highest priority."

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.