In a move to thwart future attempts by hackers to gain unauthorized access to IU computing systems, IU Research and Academic Computing, a division of University Information Technology Services, is setting in motion a series of safety measures. \nThe changes, to be completed by spring 2002, are the result of a recent surge in attempts to illegally pilfer authentification data, Craig Stewart, director of RAC, said. \nAt the heart of the changes is the elimination of services that transmit data across the network without protecting it with encryption -- one of the single largest security vulnerabilities of RAC computer systems. These services include Telnet, an e-mail service that has increasingly raised concerns about computer system security, Stewart said.\n"In today's computing environment, attacks on computer system security are the biggest threat to our ability to deliver reliable services," he said. "The problem with Telnet is that it sends a person's username and password across the network as plain text, making it possible for other people to obtain that information and then have unauthorized access to a computer system."\nStewart said such services have widespread appeal among "cyber thieves," whose chief objective is to gain unauthorized access to computing systems for fraudulent purposes.\nThe University has not been impervious to hackers' attempts to gain access to personal information. The IDS reported in August 2001 that over the course of the last five years, four separate security breaches were discovered on campus, the most prominent of which occurred when more than 3,000 student Social Security numbers were accessed by an outside individual when a security "hole" was left open in an Office of the Bursar database. The breach prompted IU's board of trustees to pass a resolution calling for tougher security policies governing IU's computing system.\nTo ensure the safety of authentification data, RAC will be disabling Telnet access to UITS' research systems, including the Steel clusters. Those systems will switch over to Secure Shell (SSH) protocol, which encrypts the username and password. \nAccording to RAC's Web site, "Secure Shell protocol provides an encrypted channel for logging into another computer over a network, executing commands on a remote computer and moving files from one computer to another." SSH also enables strong host-to-host and user authentication as well as secure encrypted communications over an insecure Internet.\nStewart said the changes have caused minimal confusion. \n"This change was implemented on Feb. 1, and while we received a few phone calls, the change seems to have gone smoothly," he said. "We have looked at the number of logins per day, and there is no perceptible change as a result of switching from telnet access to SSH only in part because many people were using SSH anyway."\nStewart said RAC is currently working on plans to implement additional changes, adding that the changes are being made under the rubric of safeguarding personal authentification data. \n"Ultimately, our plan is to create a much more secure environment for the research systems without placing a significant burden upon our customers," Stewart said. "All of the specific services being eliminated have some alternative way in which people can do what they were doing before -- just more securely"
Change will help security
Possibile security breaches prompt e-mail improvements
Get stories like this in your inbox
Subscribe



