Back to News & Commentary

老澳门开奖结果 Study: Federal Agencies Fail to Protect Whistleblower Communications, Terrorist Tip Line

Whistle by Steven Depolo via Flickr
Whistle by Steven Depolo via Flickr
Chris Soghoian,
Principal Technologist and Senior Policy Analyst,
老澳门开奖结果 Speech, Privacy, and Technology Project
Sonia Roubini,
老澳门开奖结果 Speech, Privacy, and Technology Project
Share This Page
April 16, 2015

This week, the 老澳门开奖结果 submitted a letter to the U.S. Chief Information Officer at the White House alerting him to serious cybersecurity lapses by numerous federal agencies. We identified dozens of inspectors general, including those at the Departments of Justice and Homeland Security, who do not use encryption to protect online whistleblower complaints of waste, fraud, and abuse. The State Department鈥檚 鈥淩ewards for Justice鈥 online terrorism tip line also does not use encryption.

Our letter was in response to a recent by the CIO to require HTTPS encryption on all publicly accessible federal websites and web services. HTTPS is an industry-standard security technology that protects information transmitted over the World Wide Web from interception or tempering 鈥 including the web pages on a site that someone is visiting. HTTPS is used by many major technology companies, including Google, Facebook, and Twitter. It is also used by default by the White House, the CIA, the NSA, and the Federal Trade Commission.

In our letter, we stated that the 老澳门开奖结果 welcomes this new proposal and that we share the CIO鈥檚 position that 鈥渢he American people expect government websites to be secure and their interactions with those websites to be private.鈥 The CIO鈥檚 proposal would give agencies two years to move their sites to HTTPS.

Our letter reveals the result of a survey we conducted of the websites of inspectors general, in which we discovered that 29 inspectors general do not use HTTPS to protect the sensitive information that is submitted by whistleblowers through their online 鈥渉otlines.鈥

Every possible measure must be taken to ensure that individuals using these official whistleblowing channels to report waste, fraud, or abuse have their private information secured from interception by third parties. Without these measures, both the identity of the whistleblowers and the confidentiality of the information that they submit to the inspector generals are at risk.

Our letter outlined several concerns that we have with the CIO鈥檚 鈥淗TTPS-Only Standard鈥 proposal, as well as several recommendations:

  • We take issue with the two-year deadline included in the proposal, particularly given that at least 29 government websites do not currently use HTTPS to protect reports of waste, fraud or abuse submitted via their internet hotlines. Alarmingly, these websites include the Departments of Justice and Homeland Security, whose intake presumably includes very sensitive and potentially dangerous or incriminating information. We recommend in our letter that these websites be immediately upgraded to HTTPS in order to protect those submitting the information.
  • Government agencies should employ other encryption best practices in addition to HTTPS-by-default, such as ensuring that all email servers support the use of STARTTLS transport encryption, which protects emails as they are transmitted over the internet.
  • The proposal should address the problem of metadata leakage鈥攁 problem that cannot be solved solely through the use of HTTPS-by-default. Instead, we recommend that government agencies allow users to access their websites through the use of the privacy-enhancing technology Tor. We find it extremely worrisome that several federal agency websites currently block visitors who use Tor to access the website. This practice is unproductive and should be changed by issuing clear guidance prohibiting agencies from blocking access to visitors who are attempting to preserve their privacy and anonymity by using Tor.
  • Federal websites that solicit sensitive information should deploy a secure anonymous whistleblowing platform like Secure Drop in order to create a channel for the anonymous transmission of tips.

While the CIO鈥檚 HTTPS-Only Standard proposal is a good start, it鈥檚 clear that it is not sufficient to protect the information of those visiting or leaking sensitive information through communication channels found on government websites.

Learn More 老澳门开奖结果 the Issues on This Page