Thursday, December 15, 2011

HR 3671 Introduced – Consolidated Appropriations FY 2012

Yesterday Rep. Rogers (R,KY), the Chair of the House Appropriations Committee, introduced HR 3671, the Consolidated Appropriations Act 2012. This bill is the spending bill for the remainder of the federal government for this fiscal year. The GPO does not yet have a copy of the bill available, but a Committee press release contains links to the drafts of the various ‘Divisions’ of the bill.

Division A (DOD) and Division D (DHS) are the two primary parts of the bill that will be of potential interest to the cyber security and chemical security communities. Needless to say I have not yet had time to peruse either of these sections in detail. I can tell you however that §540 of Title D does provide the standard extension of the CFATS program through October 4, 2012.

More info to follow.

Wednesday, December 14, 2011

House passes HR 1540

This evening the House passed HR 1540, the FY 2012 DOD appropriations bill, by a bipartisan vote of 283 – 136. Democrats were evenly split on their voting on the bill and the Republican leadership was apparently able to hold more of their caucus under control for this bill, keeping all but 43 Republicans voting in favor of the bill.
While the Senate could vote on it this evening it may be tomorrow before it comes to the floor of the Senate. The Senate will almost certainly also vote to pass this bill; then it will go to the President. There are some unconfirmed media reports that President Obama’s threatened veto has been quietly lifted.

HR 2845 Passes in Senate

Yesterday, the Senate took up HR 2845, the Pipeline Safety, Regulatory Certainty, and Job Creation Act Of 2011, under a ‘unanimous consent motion’ and passed it in record time. As is typical with this procedure in the Senate, there was no discussion and no vote; in fact I would bet that there were fewer than a dozen Senators in the chambers.
While that sounds like a good way to ram stuff through the Senate, it really works out rather well. The leadership of both parties usually coordinate the bills that are dealt with in this manner and it only takes a single voice in opposition to stop the proceedings. That is why both parties always have at least one person on the floor while the Senate is in session.

No Conference

My comments in yesterday’s blog about S 275 and conference committee no longer apply to this bill. With it being considered under unanimous consent there were no amendments made to the bill, so the House language was adopted by both bodies. The bill now goes to the President for signature.

S 1966 Introduced – TWIC Processing

Last week Sen. Ayotte (R,NH) introduced S 1966, a bill to reform the Transportation Worker Identification Credential (TWIC) processing. The bill would direct revisions of the application renewal process so that only a single visit would be necessary to the TWIC Processing Center.

This bill is very similar to HR 3173 that was introduced last month. The major difference in this bill is that it does not include as much verbiage describing the problem as the House bill. A minor difference in the action language of the bill may have significant implications however. As I noted in my earlier blog HR 3173 includes language that requires the processing change to require, “in total [emphasis added], not more than one in-person visit to a designated enrollment center” {§3}. That specific language is not included in this Senate bill.

One reading of the House bill would be that since all current TWIC holders have already made multiple trips to the enrollment center, subsequent trips for renewals would not be necessary. There could be all sorts of fraud and security implications of such a requirement that I addressed in an earlier blog.

The language in S 1966 demands that the new procedures “to require not more than 1 in-person visit to a designated enrollment center”. The subtle difference in the wording could certainly be argued to mean only a single trip for the initial card and only one for renewing that card. This argument would be less credible if the language in HR 3173 did not pre-date this bills introduction.

Interestingly the language in HR 3173 has already been incorporated in HR 3116, the DHS Authorization Bill, as adopted by the House. If it remains in the final version of the bill, S 1966 will become just another bill cluttering up the record of the 112th Congress. The introduction of this bill will, however, certainly show up in Ayotte’s campaign literature.

Tuesday, December 13, 2011

HR 2845 Passed in House – Pipeline Safety

Yesterday the House, as expected, passed HR 2845, the Pipeline Safety, Regulatory Certainty, and Job Creation Act of 2011, by a voice vote (page H8339). The ‘debate’ on the bill took just under the allotted 40 minutes; but no one spoke in opposition to the bill.

As I mentioned in an earlier posting, the bill will now go to the Senate where they will most likely substitute the language from S 275 (a very similar bill) and approve that version. The bill will then likely have to go to conference to work out the minor differences. Or, the House could just accept the Senate version.

Cyber Security Provisions of HR 1540

I’ve had a chance to review the Conference Report on HR 1540. There are three cyber-security provisions included in the revised language and the one chemical security related provision (Pakistani IED precursors) that I previously reported on has been removed. The three cyber-security provisions are (links to previous discussion provided):

§911 Harmful interference to Department of Defense Global Positioning System (it includes the stronger House language prohibiting the LightSquared deployment);

§953 Strategy to acquire capabilities to detect previously unknown cyber-attacks; and

§1090 Cybersecurity collaboration between the Department of Defense and the Department of Homeland Security

There will be no further changes to the bill (besides the inevitable technical correction) and it will almost certainly pass in both the House and Senate this week.

An Alert and an Advisory from ICS-CERT

Yesterday the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) issued a new alert and a new advisory for control system vulnerabilities. The advisory concerns a vulnerability in 7T IGSS and the alert deals with multiple vulnerabilities in a Schneider Electric system.

SafeNet Sentinel


The advisory actually concerns an input sanitization vulnerability in SafeNet Sentinel HASP Software Rights Management (HASP-SRM) license management application but the 7T IGSS control system software uses this program for its digital license manager. The vulnerability was discovered by Carlos Mario Penagos Hollman of Synapse-labs.

The advisory notes that a moderately skilled attacker could use this vulnerability to inject HTML code into the configuration file, but it does not provide ICS-CERT’s normal description of the potential impact of such injection. They provide the minimally helpful information that due to the many factors that are unique to each organization “ICS-CERT recommends that organizations evaluate the impact of this vulnerability based on their operational environment, architecture, and product implementation”.

SafeNet has provided a patch to mitigate the vulnerability and provides more detailed information on the vulnerability and the patch installation.

Schneider Electric


The alert concerns a public reporting of a partially coordinated disclosure (ICS-CERT was apparently given at least some advance notice of the disclosure) by Ruben Santamarta of a vulnerability in the Schneider Electric Quantum Ethernet Module. NOTE: That convoluted sentence describes a situation that probably has a very interesting story associated with it, perhaps dealing with a recent post about another Schneider vulnerability reported in a post at Digital Bond’s SCADA Security Portal.

The multiple vulnerabilities concern hardcoded credentials in three different services associated with this product. There is a long list of affected systems in this alert. The vulnerabilities in two of the services could allow “remote attackers the ability to view the operation of the module’s firmware, cause a denial of service, modify the memory of the module, and execute arbitrary code”. The third service vulnerability only (small sarcasm alert) may allow “an attacker to modify the module website, download and run custom firmware, and modify the http passwords”.

Schneider has a ‘fix’ developed to remove two of the services, but it is not yet posted to their web site. Of course, this fix will not be too helpful for organizations that actually use these services (Telenet Port and Windriver Debug Port).
 
/* Use this with templates/template-twocol.html */