Cybersecurity

Army: Log-off flaw creates no risk of outside hacks

padlocked keyboard

The Army's deputy of cybersecurity said last week that the service's systems are vulnerable to hacks when verified users are logging off, Buzzfeed reported. That story came just days after the same news site revealed that two anonymous sources had identified the same flaw.

Now, however, the Army is saying that the flaw exposes its networks only to people who have physical access to the machines.

"There are instances where the logoff process does not immediately complete upon removal of the [Common Access Code card]," Roy Lundgren, director of the Army Cyber Directorate, told Buzzfeed. "This occurs when the system is running logoff scripts and shutting down applications. The period of time that a system can be accessed following CAC removal before system logoff completes is normally not sufficient to gain unauthorized access."

An Army public affairs officer told FCW on Sept. 5 that even though there are situations where computers do not completely log off upon removal of the CAC, that vulnerability cannot be exploited remotely.

"The risk of the type of compromise alleged in the article is considered to be low," Army Public Affairs Officer Margaret McBride said in an email. "Only those with physical access to an Army computer could take advantage; an outside hack is not possible via this methodology."

"The Army is analyzing the alleged flaw in the logoff procedure," she added said. "Once the architecture issues are understood and the likelihood of occurrence is fully determined, the Army will design appropriate mitigation, such as technical solutions, revised user procedures and policy enforcement."

About the Author

Reid Davenport is an FCW editorial fellow. Connect with him on Twitter: @ReidDavenport.

Featured

  • Cybersecurity
    malware detection (Alexander Yakimov/Shutterstock.com)

    Microsoft targets copycat influence websites

    Microsoft went to court to take down websites it believes to be part of a foreign intelligence operation targeting conservative think tanks and the U.S. Senate.

  • Cybersecurity
    secure network

    FAA explores shifting its network to FISMA high

    The Federal Aviation Administration is exploring an upgrade to the information security categorization of IT systems as part of air traffic control modernization.

  • Cybersecurity
    Shutterstock photo id 669226093 By Gorodenkoff

    The disinformation game

    The federal government is poised to bring new tools and strategies to bear in the fight against foreign-backed online disinformation campaigns, but how and when they choose to act could have ramifications on the U.S. political ecosystem.

Stay Connected

FCW Update

Sign up for our newsletter.

I agree to this site's Privacy Policy.