Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Digg this story   Add to del.icio.us  
Passport-peeking probably pervasive
cwalsh, Emergent Chaos 2008-07-04

Back in March, we wrote about unauthorized access to Barack Obama's passport file.

At the time, a Washington Post article quoted a State Department spokesman:

"The State Department has strict policies and controls on access to passport records by government and contract employees"

The idea was that, while snooping might occur, it would be caught by controls put in place specifically to detect accesses to the records of high-profile people.

Well, as it turns out the State Department may not be quite as good at detecting such accesses, or at following up (shocking, I know).

In a July 4 article, the Los Angeles Times reports:

A federal investigation of unauthorized snooping into government passport files has found evidence that such breaches may be far more common than previously disclosed, and the State Department inspector general is calling for an overhaul of the program's management.

In a report issued Thursday, the inspector general found "many control weaknesses" in the department's administration program, including what investigators said was a lack of sound policies on training staff, accessing electronic records and disciplining workers who break privacy rules.

According to the article, passport files may be viewed by over 20,000 government workers and contractors. In a sample of 150 celebrities chosen for examination by investigators, 85% had been accessed at least once. One was accessed over 100 times (!) in the last six years.

Amusingly, at a press conference held on July 4, State said that half of those who had access in March no longer have it. They also were unable to say whether spot-checks on detected accesses were taking place in the past. Put those together and you have a system where at least twice as many people have access as need it, and privileged operations are recorded but the folks in charge do not know if the audit trail is used.

The redacted report is available at the C-SPAN web site, but not at the State Department's near as I can tell. Draw your own conclusions.




The information, views, and opinions contained on this page are those of the author and do not necessarily reflect the views and opinions of SecurityFocus.






 

Privacy Statement
Copyright 2007, SecurityFocus