United States

Ban on Wireless Modems In Voting Machines Should be Optional, Suggests US Election Agency (apnews.com) 147

The U.S. agency overseeing elections has "quietly weakened a key element of proposed security standards..." reports the Associated Press, "raising concern among voting-integrity experts that many such systems will remain vulnerable to hacking." The Election Assistance Commission (EAC) is poised to approve its first new security standards in 15 years after an arduous process involving multiple technical and elections community bodies and open hearings. But ahead of a scheduled February 10 ratification vote by commissioners, the EAC leadership tweaked the draft standards to remove language that stakeholders interpreted as banning wireless modems and chips from voting machines as a condition for federal certification. The mere presence of such wireless hardware poses unnecessary risks for tampering that could alter data or programs on election systems, say computer security specialists and activists, some of whom have long complained than the EAC bends too easily to industry pressure.

Agency leaders argue that overall, the revised guidelines represent a major security improvement. They stress that the rules require manufacturers to disable wireless functions present in any machines, although the wireless hardware can remain.

In a February 3 letter to the agency, computer scientists and voting integrity activists say the change "profoundly weakens voting system security and will introduce very real opportunities to remotely attack election systems." They demand the wireless hardware ban be restored...

The ban on wireless hardware in voting machines would force vendors who currently build systems with off-the-shelf components to rely on more expensive custom-built hardware, said EAC Chair Benjamin Hovland, which could hurt competition in an industry already dominated by a trio of companies. He also argued that the guidelines are voluntary, although many state laws are predicated on them... Hovland stressed that the amended guidelines say all wireless capability must be disabled in voting equipment. But computer experts say that if the hardware is present, the software that activates it can be introduced. And the threat is not just from malign actors but also from the vendors and their clients, who could enable the wireless capability for maintenance purposes then forget to turn it off, leaving machines vulnerable...

Experts are pushing for universal use of hand-marked paper ballots and better audits to bolster confidence in election results.

Security

Plex Media Servers Are Being Abused For DDoS Attacks (zdnet.com) 15

DDoS-for-hire services have found a way to abuse Plex Media servers to bounce junk traffic and amplify distributed denial of service (DDoS) attacks, security firm Netscout said in an alert this week. From a report: The company's alert warns owners of devices that ship with Plex Media Server, a web application for Windows, Mac, and Linux that's usually used for video or audio streaming and multimedia asset management. The app can be installed on regular web servers or usually ships with network-attached storage (NAS) systems, digital media players, or other types of multimedia-streaming IoT devices. Netscout says that when a server/device running a Plex Media Server app is booted and connected to a network, it will start a local scan for other compatible devices via the Simple Service Discovery Protocol (SSDP). The problem comes when a Plex Media Server discovers a local router that has SSDP support enabled. When this happens, the Plex Media Server will add a NAT forwarding rule to the router, exposing its Plex Media SSDP (PMSSDP) service directly on the internet on UDP port 32414. Since the SSDP protocol has been known for years to be a perfect vector to amplify the size of a DDoS attack, this makes Plex Media servers a juicy and untapped source of DDoS bots for DDoS-for-hire operations.
Chrome

Google Chrome Sync Feature Can Be Abused For C&C and Data Exfiltration (zdnet.com) 13

Threat actors have discovered they can abuse the Google Chrome sync feature to send commands to infected browsers and steal data from infected systems, bypassing traditional firewalls and other network defenses. From a report: For non-Chrome users, Chrome sync is a feature of the Chrome web browser that stores copies of a user's Chrome bookmarks, browsing history, passwords, and browser and extension settings on Google's cloud servers. The feature is used to sync these details between a user's different devices, so the user always has access to his most recent Chrome data wherever they go. Bojan Zdrnja, a Croatian security researcher, said on Thursday that during a recent incident response, he discovered that a malicious Chrome extension was abusing the Chrome sync feature as a way to communicate with a remote command and control (C&C) server and as a way to exfiltrate data from infected browsers. Zdrnja said that in the incident he investigated, attackers gained access to a victim's computer, but because the data they wanted to steal was inside an employee's portal, they downloaded a Chrome extension on the user's computer and loaded it via the browser's Developer Mode.
Chrome

Google Boots 'The Great Suspender' Off the Chrome Web Store For Being Malware (xda-developers.com) 48

Google has blocked The Great Suspender extension from the Chrome store "because it contains malware." The extension was very popular for users running Chrome with 8GB or less of RAM, as it would automatically suspend tabs you hadn't used in a while, freeing up precious memory and CPU power. It would then allow you to return to the tab and reload back to where you were. Mishaal Rahman writes via XDA Developers: For some people, this isn't news. Since November of 2020, close followers of the extension have warned that it may be running malicious code. The old maintainer of the extension sold it to an unknown party in June of 2020, and users alleged that the unknown party quietly slipped some trackers into version 7.1.8 of the extension. Although version 7.1.9 removed the tracker, many users were understandably suspicious of the extension. Then in early January of this year, multiple media outlets picked up on the news, and many, including myself, decided to ditch it. Earlier today, however, Google pulled the plug entirely on the popular Chrome extension, forcibly removing The Great Suspender from people's Chrome installations and removing the extension's listing on the Chrome Web Store. You can recover your suspended tabs by opening up your search history and searching for "klbibkeccnjlkjkiokjodocebajanakg." If that doesn't work, you can try the other options outlined in this GitHub post.

Some alternatives to The Great Suspender, as recommended by XDA Developers community member TheMageKing, include: Tabs Outliner, Auto Tab Discard, or Session Buddy.
China

Biden Commerce Pick Sees 'No Reason' To Lift Huawei Curbs (bloomberg.com) 99

President Joe Biden's nominee for Commerce secretary, Gina Raimondo, said she knows of "no reason" why Huawei and other Chinese companies shouldn't remain on a restricted trade list. From a report: Raimondo, in written questions from Senate Republicans, was asked about the company, as well as Semiconductor Manufacturing International Corp., Hangzhou Hikvision Digital Technology Co. and others. They are on a list that requires U.S. firms to obtain government licenses if they want to sell American tech and intellectual property to the companies. "I understand that parties are placed on the Entity List and the Military End User List generally because they pose a risk to U.S. national security or foreign policy interests," said Raimondo, the Democratic governor of Rhode Island. "I currently have no reason to believe that entities on those lists should not be there. If confirmed, I look forward to a briefing on these entities and others of concern."
Security

SolarWinds Patches Vulnerabilities That Could Allow Full System Control (arstechnica.com) 15

An anonymous reader quotes a report from Ars Technica: SolarWinds, the previously little-known company whose network-monitoring tool Orion was a primary vector for one of the most serious breaches in US history, has pushed out fixes for three severe vulnerabilities. Martin Rakhmanov, a researcher with Trustwave SpiderLabs, said in a blog post on Wednesday that he began analyzing SolarWinds products shortly after FireEye and Microsoft reported that hackers had taken control of SolarWinds' software development system and used it to distribute backdoored updates to Orion customers. It didn't take long for him to find three vulnerabilities, two in Orion and a third in a product known as the Serv-U FTP for Windows. There's no evidence any of the vulnerabilities have been exploited in the wild.

The most serious flaw allows unprivileged users to remotely execute code that takes complete control of the underlying operating system. Tracked as CVE-2021-25274 the vulnerability stems from Orion's use of the Microsoft Message Queue, a tool that has existed for more than 20 years but is no longer installed by default on Windows machines. [...] The second Orion vulnerability, tracked as CVE-2021-25275, is the result of Orion storing database credentials in an insecure manner. Specifically, Orion keeps the credentials in a file that's readable by unprivileged users. Rakhmanov facetiously called this "Database Credentials for Everyone." While the files cryptographically protect the passwords, the researcher was able to find code that converts the password to plaintext. The result: anyone who can log in to a box locally or through the Remote Desktop Protocol can gain the credentials for the SolarWindsOrionDatabaseUser.

The third vulnerability, tracked as CVE-2021-25276, resides in the Serv-U FTP for Windows. The program stores details for each account in a separate file. Those files can be created by any authenticated Windows user. Rakhmanov wrote: "Specifically, anyone who can log in locally or via Remote Desktop can just drop a file that defines a new user, and the Serv-U FTP will automatically pick it up. Next, since we can create any Serv-U FTP user, it makes sense to define an admin account by setting a simple field in the file and then set the home directory to the root of C:\ drive. Now we can log in via FTP and read or replace any file on the C:\ since the FTP server runs as LocalSystem."
Fixes for Orion and Serv-U FTP are available here and here.
Chromium

Chromium Cleans Up Its Act -- and Daily DNS Root Server Queries Drop by 60 Billion (theregister.com) 35

The Google-sponsored Chromium project has cleaned up its act, and the result is a marked decline in queries to DNS root servers. From a report: As The Register reported in August 2020, Chromium-based browsers generate a lot of DNS traffic as they try to determine if input into their omnibox is a domain name or a search query. Verisign engineers Matthew Thomas and Duane Wessels examined the resulting traffic and reached the conclusion that it accounted for up to 60 billion DNS queries every day. Wessels has since penned a new post that went unreported when it appeared on January 7 -- the day after the US Capitol riot -- but was today resurfaced by APNIC, the Regional Internet Registry for the Asia-Pacific region. In the post he says the Chromium team redesigned its code to stop junk DNS requests, and released the update in Chromium 87. The result? "Before the software release, the root server system saw peaks of ~143 billion queries per day," he wrote. "Traffic volumes have since decreased to ~84 billion queries a day. This represents more than a 41 per cent reduction of total query volume."
Chrome

Malicious Chrome and Edge Add-Ons Had a Novel Way To Hide On 3 Million Devices (arstechnica.com) 19

In December, Ars reported that as many as 3 million people had been infected by Chrome and Edge browser extensions that stole personal data and redirected users to ad or phishing sites. Now, the researchers who discovered the scam have revealed the lengths the extension developers took to hide their nefarious deeds. Ars Technica reports: Researchers from Prague-based Avast said on Wednesday that the extension developers employed a novel way to hide malicious traffic sent between infected devices and the command and control servers they connected to. Specifically, the extensions funneled commands into the cache-control headers of traffic that was camouflaged to appear as data related to Google analytics, which websites use to measure visitor interactions. Referring to the campaign as CacheFlow, Avast researchers wrote: "CacheFlow was notable in particular for the way that the malicious extensions would try to hide their command and control traffic in a covert channel using the Cache-Control HTTP header of their analytics requests. We believe this is a new technique. In addition, it appears to us that the Google Analytics-style traffic was added not just to hide the malicious commands, but that the extension authors were also interested in the analytics requests themselves. We believe they tried to solve two problems, command and control and getting analytics information, with one solution."

The extensions, Avast explained, sent what appeared to be standard Google analytics requests to https://stats.script-protection[.]com/__utm.gif. The attacker server would then respond with a specially formed Cache-Control header, which the client would then decrypt, parse, and execute. Avoiding infecting users who were likely to be Web developers or researchers. The developers did this by examining the extensions the users already had installed and checking if the user accessed locally hosted websites. Additionally, in the event that an extension detected that the browser developer tools were opened, it would quickly deactivate its malicious functionality. Waiting three days after infection to activate malicious functionality. Checking every Google search query a user made. In the event a query inquired about a server the extensions used for command and control, the extensions would immediately cease their malicious activity.

Bug

Recent Root-Giving Sudo Bug Also Impacts macOS (zdnet.com) 24

A British security researcher has discovered this week that a recent security flaw in the Sudo app also impacts the macOS operating system, and not just Linux and BSD, as initially believed. From a report: The vulnerability, disclosed last week as CVE-2021-3156 (aka Baron Samedit) by security researchers from Qualys, impacts Sudo, an app that allows admins to delegate limited root access to other users. Qualys researchers discovered that they could trigger a "heap overflow" bug in the Sudo app to change the current user's low-privileged access to root-level commands, granting the attacker access to the whole system. The only condition to exploit this bug was that an attacker gain access to a system, which researchers said could be done by either planting malware on a device or brute-forcing a low-privileged service account. In their report last week, Qualys researchers said they only tested the issue on Ubuntu, Debian, and Fedora. They said that are UNIX-like operating systems are also impacted, but most security researchers thought the bug might impact BSD, another major OS that also ships with the Sudo app.
Security

Hackers Lurked in SolarWinds Email System for at Least 9 Months, CEO Says (wsj.com) 23

The newly appointed chief executive of SolarWinds is still trying to unravel how his company became a primary vector for hackers in a massive attack revealed last year, but said evidence is emerging that they were lurking in the company's Office 365 email system for months. From a report: The hackers had accessed at least one of the company's Office 365 accounts by December 2019, and then leapfrogged to other Office 365 accounts used by the company, Sudhakar Ramakrishna said in an interview Tuesday. "Some email accounts were compromised. That led them to compromise other email accounts and as a result our broader [Office] 365 environment was compromised," he said. It is the latest development in the eight-week investigation into one of the worst breaches in U.S. history. SolarWinds, previously a little-known but critical maker of network-management software, is still trying to understand how the hackers first got into the company's network and when exactly that happened. One possibility is that the hackers may have compromised the company's Office 365 accounts even earlier and then used that as the initial point of entry into the company, although that is one of several theories being pursued, Mr. Ramakrishna said.
Security

Microsoft Defender ATP is Detecting Yesterday's Chrome Update as a Backdoor (zdnet.com) 56

Microsoft Defender Advanced Threat Protection (ATP), the commercial version of the ubiquitous Defender antivirus and Microsoft's top enterprise security solution, is currently having a bad day and labeling yesterday's Google Chrome browser update as a backdoor trojan. From a report: The detections are for Google Chrome 88.0.4324.146, the latest version of the Chrome browser, which Google released last night. As per the screenshot (embedded in the linked story), but also based on reports shared on Twitter by other dismayed system administrators, Defender ATP is currently detecting multiple files part of the Chrome v88.0.4324.146 update package as containing a generic backdoor trojan named "PHP/Funvalget.A." The alerts have caused quite a stir in enterprise environments in light of recent multiple software supply chain attacks that have hit companies across the world over the past few months. System administrators are currently awaiting a formal statement from Microsoft to confirm that the detection is a "false possitive" and not an actual threat.
Security

Ransomware Gangs Made at Least $350 Million in 2020 (zdnet.com) 15

Ransomware gangs made at least $350 million in ransom payments last year, in 2020, blockchain analysis firm Chainalysis said in a report last week. From a report: The figure was compiled by tracking transactions to blockchain addresses linked to ransomware attacks. Although Chainalysis possesses one of the most complete sets of data on cryptocurrency-related cybercrime, the company said its estimate was only a lower bound of the true total due. The company blamed this on the fact that not all victims disclosed their ransomware attacks and subsequent payments last year, with the real total being many times larger than what the company was able to view. But despite the low figure, Chainalysis says that ransomware was actually on the rise. According to numbers released in a previous report, ransomware payments accounted for 7% of all funds received by "criminal" cryptocurrency addresses in 2020.
Security

Suspected Chinese Hackers Used SolarWinds Bug To Spy on US Payroll Agency (reuters.com) 18

Suspected Chinese hackers exploited a flaw in software made by SolarWinds to help break into U.S. government computers last year, Reuters reported Tuesday, citing five people familiar with the matter, marking a new twist in a sprawling cybersecurity breach that U.S. lawmakers have labeled a national security emergency. From a report: Two people briefed on the case said FBI investigators recently found that the National Finance Center, a federal payroll agency inside the U.S. Department of Agriculture, was among the affected organizations, raising fears that data on thousands of government employees may have been compromised. The software flaw exploited by the suspected Chinese group is separate from the one the United States has accused Russian government operatives of using to compromise up to 18,000 SolarWinds customers, including sensitive federal agencies, by hijacking the company's Orion network monitoring software. Security researchers have previously said a second group of hackers was abusing SolarWinds' software at the same time as the alleged Russian hack, but the suspected connection to China and ensuing U.S. government breach have not been previously reported.
IT

Why Webcams Aren't Good Enough (reincubate.com) 118

Jeff Carlson, writes in a post: After consulting numerous webcam buying guides and reviews, purchasing a handful of the most popular models, and testing them in varying lighting situations, I can't escape the grim truth: there are no good webcams. Even webcams recommended by reputable outlets produce poor quality imagery -- a significant failing, given it's the one job they're supposed to provide. Uneven color. Blown highlights. Smudgy detail, especially in low light. Any affordable webcam (even at the high end of affordability, $100+), uses inadequate and typically years-old hardware backed by mediocre software that literally makes you look bad. You might not notice this if you're using video software that makes your own image small, but it will be obvious to other people on the call. [...] Why are webcams like this?

[...] Two main factors currently hinder serious webcam innovations, one a technical limitation and one a business shortcoming. As with all photography, the way to create better images is to capture more light, and the method of capturing more light is to use larger image sensors and larger lenses. That's why a consumer DSLR or mirrorless camera produces much better images than a webcam. Primarily this is about size: webcams are designed as small devices that need to fit onto existing monitors or laptop lids, so they use small camera modules with tiny image sensors. These modules have been good enough for years, generating accolades, so there's little incentive to change. The StreamCam appears to have a better camera and sensor, with an aperture of f/2.0; aperture isn't listed for the other cameras.

Contrast this technology with the iPhone, which also includes small camera modules by necessity to fit them into a phone form factor. Apple includes better components, but just as important, incorporates dedicated hardware and software solely to the task of creating images. When you're taking a photo or video with an iOS device, it's processing the raw data and outputting an edited version of the scene. Originally, Logitech's higher-end webcams, such as the C920, also included dedicated MPEG processing hardware to decode the video signal, but removed it at some point. The company justified the change because of the power of modern computers, stating, "there is no longer a need for in-camera encoding in today's computers," but that just shifts the processing burden to the computer's CPU, which must decode raw video instead of an optimized stream. It's equally likely Logitech made the change to reduce component costs and no longer pay to license the H.264 codec from MPEG LA, the group that owns MPEG patents. That brings us to the other factor keeping webcam innovation restrained: manufacturers aren't as invested in what has been a low margin business catering to a relatively small niche of customers.

Security

Amazon Says Government Demands For User Data Spiked By 800% in 2020 (techcrunch.com) 31

New transparency figures released by Amazon show the company responded to a record number of government data demands in the last six months of 2020. From a report: The new figures land in the company's bi-annual transparency report published to Amazon's website over the weekend. Amazon said it processed 27,664 government demands for user data in the last six months of 2020, up from 3,222 data demands in the first six months of the year, an increase of close to 800%. That user data includes shopping searches and data from its Echo, Fire, and Ring devices. The new report presents the data differently from previous transparency disclosures. Amazon now breaks down the top requesting countries. U.S. authorities historically made up the bulk of the overall data demands Amazon receives, but this latest report shows Germany with 42% of all requests, followed by Spain with 18%, and Italy and the U.S. with 11% share each. But the report also removes the breakdown by legal process, and now only differentiates between the requests it gets for user's content and for non-content. Amazon said it handed over user content data in 52 cases. For its Amazon Web Services cloud business, which it reports separately, Amazon said it processed 523 data demands, with 75% of all requests made by U.S. authorities, and Amazon turned over user's content in 15 cases.
GNU is Not Unix

A 'Severe' Bug Was Found In Libgcrypt, GnuPG's Cryptographic Library (helpnetsecurity.com) 39

Early Friday the principal author of GNU Privacy Guard (the free encryption software) warned that version 1.9.0 of its cryptographic library Libgcrypt, released January 19, had a "severe" security vulnerability and should not be used.

A new version 1.9.1, which fixes the flaw, is available for download, Help Net Security reports: He also noted that Fedora 34 (scheduled to be released in April 2021) and Gentoo Linux are already using the vulnerable version... [I]t's a heap buffer overflow due to an incorrect assumption in the block buffer management code. Just decrypting some data can overflow a heap buffer with attacker controlled data, no verification or signature is validated before the vulnerability occurs.

It was discovered and flagged by Google Project Zero researcher Tavis Ormandy and affects only Libgcrypt v1.9.0.

"Exploiting this bug is simple and thus immediate action for 1.9.0 users is required..." Koch posted on the GnuPG mailing list. "The 1.9.0 tarballs on our FTP server have been renamed so that scripts won't be able to get this version anymore."
IT

Study Finds The Least-Affordable City for Tech Workers: Silicon Valley's San Jose (thestar.com.my) 63

The Bay Area Newsgroup reports: Despite high salaries and world-class amenities, San Jose is the least affordable place for tech workers to buy a home. [Alternate URL here] A new analysis by the American Enterprise Institute found the typical tech worker and his or her partner — with two incomes totaling $200,000 — can afford just 12 percent of the homes for sale in the San Jose metro area.

The picture in San Francisco and the East Bay is nearly as bad, with just 21 percent of homes for sale fitting in the budget of an average tech couple. The high-hurdles to home ownership are fueling a Bay Area exodus that has contributed to the state's sluggish population growth in recent years, researchers say. Study author Ed Pinto, director of the AEI Housing Center, said tech workers can afford their pick of homes in almost every other U.S. city. "But in those places like San Jose, San Francisco and Los Angeles," he said, "that is not the case."

The analysis gives another explanation for the Bay Area exodus. And it's not only workers who are leaving. Tech heavyweights HPE and Oracle have announced moves of their headquarters from Silicon Valley to Texas. Pinto believes the spread of remote work will only accelerate migration from the Bay Area. With new workplace flexibilities, tech workers have a choice between high-cost regions near their offices and low-cost regions with bigger houses and remote work. "Work from home is winning," he said.

Privacy

'We Spoke To a Guy Who Got His Dick Locked In a Cage By a Hacker' (vice.com) 242

An anonymous reader quotes a report from Motherboard: Sam Summers was sitting at home with his penis wrapped in an internet-connected chastity cage when he got a weird message on the app that connects to the device. Someone told him they had taken control and they wanted around $1,000 in Bitcoin to give control back to Summers. "Initially, I thought it was my partner doing that," Summers told Motherboard in a phone call. "It sounds silly, but I got a bit excited by it." But when Summers called his partner, she told him it wasn't her, even after he told her their safe word. That's when he realized he had gotten hacked. His penis was locked in the cage, and he had no way out.

Summers is one of several people who purchased a chastity cage device called Cellmate and produced by Qiui, a China-based manufacturer. Some of the device's owners got their accounts -- and thus their devices as well -- hacked at the end of last year, after security researchers warned that the manufacturer left an exposed and vulnerable API, which could allow hackers to take control of the devices.

Scared and a bit desperate, Summers realized he had some Bitcoin stashed in an old account. So he sent the hacker what they wanted, hoping that would be it. But when the hacker got the money, they asked for more, according to Summers. "That's when I felt fucking stupid and angry," Summers said. At that point, Summers and his partner started brainstorming ways to get his penis out of the cage. At home, they only had a hammer, so they went out and bought a pair of bolt cutters. His partner tried first, but she couldn't break through. So Summers had to do it himself. The way he was holding his penis put it "in a dangerous spot," he said, so it was "very scary." Nonetheless, he was able to break the cage, but the cutters still cut through him, he said. "I don't have a scar or anything but I was bleeding and it fucking hurt," Summers said.

United States

Suspected Russian Hack Extends Far Beyond SolarWinds Software, Investigators Say (wsj.com) 35

Investigators probing a massive hack of the U.S. government and businesses say they have found concrete evidence the suspected Russian espionage operation went far beyond the compromise of the small software vendor publicly linked to the attack. From a report: Close to a third of the victims didn't run the SolarWinds software initially considered the main avenue of attack for the hackers, according to investigators and the government agency digging into the incident. The revelation is fueling concern that the episode exploited vulnerabilities in business software used daily by millions [Editor's note: the link may be paywalled; alternative source]. Hackers linked to the attack have broken into these systems by exploiting known bugs in software products, by guessing online passwords and by capitalizing on a variety of issues in the way Microsoft cloud-based software is configured, investigators said.

Approximately 30% of both the private-sector and government victims linked to the campaign had no direct connection to SolarWinds, Brandon Wales, acting director of the Cybersecurity and Infrastructure Security Agency, said in an interview. The attackers "gained access to their targets in a variety of ways. This adversary has been creative," said Mr. Wales, whose agency, part of the U.S. Department of Homeland Security, is coordinating the government response. "It is absolutely correct that this campaign should not be thought of as the SolarWinds campaign." Corporate investigators are reaching the same conclusion. Last week, computer security company Malwarebytes said that a number of its Microsoft cloud email accounts were compromised by the same attackers who targeted SolarWinds, using what Malwarebytes called "another intrusion vector."

United States

After SolarWinds Breach, Lawmakers Ask NSA for Help in Cracking Juniper Cold Case (cyberscoop.com) 15

As the U.S. investigation into the SolarWinds hacking campaign grinds on, lawmakers are demanding answers from the National Security Agency about another troubling supply chain breach that was disclosed five years ago. From a report: A group of lawmakers led by Sen. Ron Wyden, D-Ore., are asking the NSA what steps it took to secure defense networks following a years-old breach of software made by Juniper Networks, a major provider of firewall devices for the federal government. Juniper revealed its incident in December 2015, saying that hackers had slipped unauthorized code into the firm's software that could allow access to firewalls and the ability to decrypt virtual private network connections. Despite repeated inquiries from Capitol Hill -- and concern in the Pentagon about the potential exposure of its contractors to the hack -- there has been no public U.S. government assessment of who carried out the hack, and what data was accessed.

Lawmakers are now hoping that, by cracking open the Juniper cold case, the government can learn from that incident before another big breach of a government vendor provides attackers with a foothold into U.S. networks. Members of Congress also are examining any role that the NSA may have unwittingly played in the Juniper incident by allegedly advocating for a weak encryption algorithm that Juniper and other firms used in its software. Lawmakers want to know if, more than a decade ago, the NSA pushed for a data protection scheme it could crack, only for another state-sponsored group to exploit that security weakness to gather data about the U.S. "Congress has a responsibility to determine the root cause of this supply chain compromise and the NSA's role in the design and promotion of the flawed encryption algorithm that played such a central role," Wyden and other lawmakers wrote to Gen. Paul Nakasone, head of the NSA and U.S. Cyber Command, in a letter made public Friday.

Slashdot Top Deals