WASHINGTON – The Pentagon says a foreign spy agency pulled off the most serious breach of Defense Department computer networks ever by inserting a flash drive into a U.S. military laptop.
The previously classified incident took place in 2008 in the Middle East and was disclosed in a magazine article by Deputy Defense Secretary William J. Lynn and released by the Pentagon Wednesday. The Pentagon did not say what nation's spy agency was involved.
He said a ‘malicious code' on the flash drive spread undetected on both classified and unclassified Pentagon systems, ‘establishing what amounted to a digital beachhead,' for stealing military secrets.
Read the full list of Laptop counter-intelligence measures at Securing Our eCity
Lost in translation: Cybersecurity
While working 10 years ago as a wireless engineering tech in San Diego for a Canadian wireless company, our newly negotiated partnership with a Taiwanese firm had stipulated a mandatory training session for their engineers. We had the ability to provide a webinar, which was rejected. At the very last minute, I was sent to fulfill the contract since corporate partner training was my responsibility.After a 14-hour flight, I arrived in Taiwan – not speaking and barely reading a lick of Mandarin. I was picked up at midnight by my host company's ‘best man,' whisked down the dark freeway and deposited at the entry to my hotel, which was to be my home for three days.Just like Bill Murray in Sofia Coppola's film Lost in Translation, there were several things which left me disoriented: no reading material in my native language, and worse, no internet access at the hotel I would be staying at. Topping it off, the television offered only three channels, all Taiwanese.Threat intelligence: Increasing awareness
I had deliberately decided not to bring a laptop for three reasons. It seemed to be more trouble than it could have been worth with power cords, there was no compatible wireless standard, and the top of my list – being conscious of the risk factors my personal laptop could have posed for the company.I happened to be the central testing resource for more than 200 software vendors who wanted to partner with our hardware solutions, which spanned the four top commercial wireless spectrums – CDPD, GSM, Ricochet, and CDMA.My laptop was a goldmine and I knew it. Therefore, I didn't bring it along. All this resulted in my being bored to death for about a week, including the flight back out. What it avoided: my laptop data being compromised. Further information, which led to my choice, was the pre-departure briefing that informed me that this company may really want more details than I could give them. My product manager confided he wasn't sure what they really were after with a mandatory live meeting.Therefore, I copied the data I needed onto several CDRs and, as a backup, I uploaded the data into my offsite email. The meeting went as planned and I never worried about a laptop, although my hosts were surprised I hadn't brought one. I assured them that my Palm V was all I needed – even though the power adapters I brought wouldn't work!In recent Spy vs. spy articles, we took a look at the six questions in our counter-intel corporate traveler checklist:Counter-intel corporate traveler checklist
- What role does this traveler have?
- Where is this person heading?
- Who are they visiting with?
- What information can they completely leave behind?
- What information must they have to perform their duties?
- What sensitive projects or information may they need to access while they are traveling?
Read the full list of Laptop counter-intelligence measures at Securing Our eCity
Three rules to laptop security
Rule One: You'll never lose what you don't bring.
Compare this to SERE: nothing more invigorating than a week-long desert evasion course complete with bad guys and prison camp guard towers to provide the elements required for Kirkpatrick's third to fifth training evaluation of counter intelligence. Again, not passing meant not flying. Most of us passed: some with broken wrists, ribs and arms.Rule Two: It's easier to think security about tangible items than those which aren't visible.
Rule Three: See Rule One – you'll never lose what you don't bring.
