| "Only dull people are brilliant at breakfast" -Oscar Wilde |
![]() |
"The liberal soul shall be made fat, and he that watereth, shall be watered also himself." -- Proverbs 11:25 |
Senior military leaders took the exceptional step of briefing President Bush this week on a severe and widespread electronic attack on Defense Department computers that may have originated in Russia -- an incursion that posed unusual concern among commanders and raised potential implications for national security.
Defense officials would not describe the extent of damage inflicted on military networks. But they said that the attack struck hard at networks within U.S. Central Command, the headquarters that oversees U.S. involvement in Iraq and Afghanistan, and affected computers in combat zones. The attack also penetrated at least one highly protected classified network.
Military computers are regularly beset by outside hackers, computer viruses and worms. But defense officials said the most recent attack involved an intrusive piece of malicious software, or "malware," apparently designed specifically to target military networks.
"This one was significant; this one got our attention," said one defense official, speaking on condition of anonymity when discussing internal assessments.
Although officials are withholding many details, the attack underscores the increasing danger and potential significance of computer warfare, which defense experts say could one day be used by combatants to undermine even a militarily superior adversary.
Bush was briefed on the threat by Navy Adm. Michael G. Mullen, chairman of the Joint Chiefs of Staff. Mullen also briefed Defense Secretary Robert M. Gates.
Military electronics experts have not pinpointed the source or motive of the attack and could not say whether the destructive program was created by an individual hacker or whether the Russian government may have had some involvement. Defense experts may never be able to answer such questions, officials said.
The defense official said the military also had not learned whether the software's designers may have been specifically targeting computers used by troops in Afghanistan and Iraq.
Labels: information security
Three or four FBI laptop computers are lost or stolen each month and many times the agency doesn't know whether information on the machines is sensitive or classified, the Justice Department's inspector general said in a report Monday.
Inspector General Glenn Fine said the FBI is reducing thefts and disappearances of weapons and laptop computers, but the bureau acknowledged in a statement Monday that "more needs to be done."
The Boston field office reported a stolen laptop containing software for creating identification badges. The laboratory division at Quantico, Va., said a stolen laptop had names, addresses and phone numbers of FBI personnel.
"Perhaps most troubling, the FBI could not determine in many cases whether the lost or stolen laptop computers contained sensitive or classified information," the report said. "Such information may include case information, personal identifying information or classified information on FBI operations."
Of the 160 laptops lost or stolen over a 44-month period, 10 contained sensitive or classified information. The bureau did not have records on whether 51 others had such data.
The Department of Veterans Affairs began notifying 1.8 million veterans and doctors Monday that their personal and business information could be on a portable hard drive that has been missing from an Alabama hospital for nearly three weeks.
The hard drive may have contained Social Security numbers and other personal information from about 535,000 individuals and billing information on 1.3 million doctors nationwide, the VA said. That's more than 37 times more people than authorities initially believed were affected.
An employee at the VA medical center in Birmingham reported the external hard drive missing on Jan. 22. The drive was used to back up information on the employee's office computer. It may have contained data from research projects, the department said.
U.S. Rep. Artur Davis (news, bio, voting record) questioned why it took the agency so long to begin sending out notification letters.
"I certainly understand that the VA wanted to get a handle on the facts. But it became very apparent very early on that they had a breach of security," said Davis, a Democrat from Birmingham.
Veterans Affairs officials said they were moving as quickly as they could. "We are providing information as we learn it from an investigation," said spokesman Matt Burns in Washington.
The VA first publicly revealed the equipment was missing 11 days after it was reported, saying then that personal information on as many as 48,000 veterans may have been stolen.
The VA said Monday it doesn't have any reason to believe anyone has misused data from the hard drive, which is also at the center of a criminal investigation. The agency offered a year of free credit monitoring to anyone whose information is compromised.
Davis said the department told him that the missing storage unit included the Social Security numbers and names of about 10,000 people, plus another 525,000 Social Security numbers. The information on doctors includes names and Medicare billing codes, he said.
Labels: information security, Veterans Affairs
