// COMPLETE THREAD

Re: A serious question of ethics

3 expanded posts ยท every known parent and child

NODE f7363567Re: A serious question of ethics
On Mon, 7 Feb 1994, Tom Allard wrote:

> -----BEGIN PGP SIGNED MESSAGE-----
> 
> nobody@pmantis.berkeley.edu wrote:
> 
> > Ok, I'm in a bit of a quandry.  While surfing the net last week, I
> > happened across an address addached to a machine that belongs the the 
> > federal reserve.  No big deal.  I telnetted there on a lark, and entered 
> > 'guest' for the account.  It dropped me into a shell.  It didn't ask for 
> > a password.  Intrigued, I did a little looking around.  Nothing special, 
> > a CDRom and about 80 accounts.  But(!!), /etc/passwd was there and 
> > available and not using shadows.  No, I didn't snatch a copy.
> 
> - ------- Forwarded Message
> 
> Date:    Mon, 07 Feb 94 11:10:05 -0500 
> From:    m1rcd00
> To:      m1tca00
> Subject: Cypherpunk...
> 
> Guest login was denied this morning...
> 
> Well, since someone seems to be home now at Minneapolis, if you wanted
> to send something back to that list, I suppose it would be OK. If you
> happened to mention in such a missive that the technical contact here
> at the Board has no responsibility for or involvement with the Bank
> machine or network involved, did not fuck up, and was not amused, the
> technical contact would probably not mind.
> 
> - - --Bob
> 
> 
> - ------- End of Forwarded Message

Does that mean that I no longer should report the open system (I don't 
dare telnet there to find out if it is the same one)?

Also, and I'm purely curious, what actually became of my anonymous 
report, and do I need to be worried about SS agents in dark sunglasses 
coming to my home and dragging me away?  (Truely worried and scared)
NODE 500c7e38Re: A serious question of ethics
- --------
nobody@pmantis.berkeley.edu wrote:

> Does that mean that I no longer should report the open system (I don't 
> dare telnet there to find out if it is the same one)?

> Also, and I'm purely curious, what actually became of my anonymous 
> report, and do I need to be worried about SS agents in dark sunglasses 
> coming to my home and dragging me away?  (Truely worried and scared)

I work on the Federal Reserve *Board*'s Research Network.  This network
is hidden behind a firewall, and won't even let you finger (much less telnet)
into.

I sent your message to the network administrator, Janice Shack-Marquez
(m1jsm00@frb.gov).  Obtw, Libby Flanagan has fled to the private sector
(lf@nwu.edu) where vendors can now give her coffee cups with filling out
forms.

Janice (quickly) got at least three people looking into the problem.
Bob Drzyzgula (m1rcd00@frb.gov) found a machine that perfectly matched the
problems you described.  Bob contacted them, and they seem to have corrected
the problem.

Don't worry about black hats, though.  If anything gets investigated, it outta be
the district bank.

I *would* like to know the IP address you had connected to to verify that
we're talking about the same machine.  You can use the remailers, and encrypt
to my public key (available on the servers, key ID C744CD).  

All the "cool" secrets (wire transfers and the like) don't get anywhere NEAR
the internet.  The Federal Reserve System has a separate (yes, encrypted)
network for sharing data.  The Federal Reserve Banks are all "private"
companies, and several offer various other services (such as economic
bulletin boards and the like).  The Federal Reserve *Board* has Research
network (where I am) used to prepare statistical releases and act as a data
service for the Chairman & Governors.  The Board does not offer any services
to the internet (we should, but that's a long story).  The point of all this
is that you didn't really find anything very sensitive, although we do
appreciate closing gaping holes like that.

rgds-- TA  (tallard@frb.gov)
[awaiting approval of new disclaimer]
pgp fingerprint: 10 49 F5 24 F1 D9 A7 D6  DE 14 25 C8 C0 E2 57 9D

              

-----BEGIN PGP SIGNATURE-----
Version: 2.3a

iQCVAgUBLVekwaAudFplx0TNAQHOdAP/WqSUic8PwvEuCkdOBSPZVlxJFwTlYXr8
0lLhnJDgs8+tUPp0Vd9Atc7nsvQM3mZ56xOIWED21KBcBRpaNlUG4E6bT9QrKKDi
dwfR/sHHysdpHx9yB2xlpunlkeBw2jMDEm5YbusgZNHbVpt7AaixcqKVyRrL2wJM
aNaFwEBJFOM=
=gME3
-----END PGP SIGNATURE-----
NODE 97a299f5on Fedwire and FRCS-80
>All the "cool" secrets (wire transfers and the like) don't get anywhere NEAR
>the internet.  The Federal Reserve System has a separate (yes, encrypted)
>network for sharing data.  

A touchy spot?  Interestingly enough, the Fedwire network was only
recently encrypted.

The following information comes from a GAO report _Electronic Funds
Transfer: Oversight of Critical Banking Systems Should Be
Strengthened_.  GAO/IMTEC-90-14.  To get a fre copy, call 202-512-6000
or fax 301-258-4066.  And if you pay US taxes, you've already paid for
it!

In a reply letter from the Board of Governers of the Federal Reserve
System, they talk about FRCS-80, the Federal Reserve Communications
System, implemented in 1982.  In September 1989 a request for proposal
went out to encrypt the backbone network.  Encryption was supposed to
have been completed in the first half of 1990.  (I hear that it
slipped.  Given that FRCS-80 was implemented in '82, are we
surprised?)

I understand that Fedwire-II is now in operation, but I don't know if
that's new hardware and/or new software.

Here's the curious thing.  DES came out in 1976, and was supposed to
be secure for financial communications.  FRCS-80 had plenty of
opportunity to use DES, but didn't, for at least the first eight years
of operation.

Hmm.

And save the conspiracy theories about the Federal Reserve for
alt.conspiracy, please.

Eric