GSA / GSA/modernization

Comment from email: Protect Machine Identities - IT Modernization Targeted Vision

Open
#94 0 comments 0 reactions 0 assignees View on GitHub
Public comment
Dominant language
CSS
Stars
59
Forks
8
PR merge metrics
No merged PRs in 30d

Description

_[Below are comments sent in by email. Author details below.]_

-------

To: ATC/Signatory Agencies and Whom it May Concern


The White House Office of Management and Budget (OMB) issued the HTTPS-Only Standard directives:

OMB M-15-13:
https://www.whitehouse.gov/sites/default/files/omb/memoranda/2015/m-15-13.pdf

OMB M-17-06: https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/memoranda/2017/m-17-06.pdf

Thus, requiring that all publicly accessible federal websites and web services only provide service through a secure HTTPS connection.

With these directives, the federal government adapted better encryption practices which lead cyber criminals and nation states towards Secure Sockets Layer and Transport Layer Security (SSL/TLS) vulnerabilities to deliver malicious attacks by effectively utilizing techniques of impersonating a machine while hiding what is coming and going and this is a major attribute that is missing from your targeted vision.

Why are SSL/TLS attacks on the rise? BECAUSE THEY WORK.
Bad guys and nation states are very smart and frugal. They only increase something because it is working.

Why do they work? BECAUSE MALWARE CAN HIDE IN TRAFFIC AND MACHINES CAN BE SPOOFED.

Machine identities govern the confidentiality and integrity of information between machines. To assure their unique identities, machines use keys and certificates, much like people employ user names and passwords. Without the proper protection for machine identities, organizations can’t guarantee the confidentiality of information that flows to authorized machines and prevent the flow of information to unauthorized machines.

Compromised machine identities can have a significant security impact on organizations.
Attackers can misuse machine identities to establish hidden or concealed encrypted communication tunnels on enterprise networks and gain privileged access to data and resources.
Attackers can misuse machine identities to create fraudulent encrypted tunnels on corporate networks to hide malicious actions.
Forged or stolen machine identities can also allow an attacker’s machine to masquerade as a legitimate machine, and be trusted with sensitive data.

So, machine identity protection will be required to improve the federal government’s cybersecurity, reduce risk and support regulatory, legal, and the overall operational mission.

In conclusion, the number of machines is growing faster than the number of people using them. The sheer scale of machine identities that need to be protected makes it far more challenging to keep machine identities secure. As machines become more intelligent, they are replacing humans in tasks that require reasoning, perception, logical thought, memory, and learning. The federal government’s increasing reliance on smart machines makes it ever more important to validate and defend their identities. Protection of machine identities will also need to be addressed as the federal government continues to utilize cloud services. The cloud provides many benefits but along within this IT modernization medium will be an increased need to rapidly assess the trustworthiness of machines, including cloud workloads, virtual machines, containers and micro services. The fluid nature of the interaction within the cloud can expose additional identities for nation states and bad actors to abuse which again means the federal government will need to mandate how all agencies protect our nation’s machine identities.

Thank you for the consideration and keep up the great work protecting this great nation!

Venafi | Ben Boykin| Director of Federal Sales | www.venafi.com

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.