Clinton email server setup risked intrusions

WASHINGTON — The private email server running in Hillary Rodham Clinton’s home basement when she was secretary of state was connected to the Internet in ways that made it more vulnerable to hackers while using software that could have been exploited, according to data and documents reviewed by The Associated Press.

Clinton’s server, which handled her personal and State Department correspondence, appeared to allow users to connect openly over the Internet to control it remotely, according to detailed records compiled in 2012. Experts said the Microsoft remote desktop service wasn’t intended for such use without additional protective measures, and was the subject of U.S. government and industry warnings at the time over attacks from even low-skilled intruders.

Records show that Clinton additionally operated two more devices on her home network in Chappaqua, New York, that also were directly accessible from the Internet. One contained similar remote-control software that also has suffered from security vulnerabilities, known as Virtual Network Computing, and the other appeared to be configured to run websites.

The new details provide the first clues about how Clinton’s computer, running Microsoft’s server software, was set up and protected when she used it exclusively over four years as secretary of state for all work messages. Clinton’s privately paid technology adviser, Bryan Pagliano, has declined to answer questions about his work from congressional investigators, citing the U.S. Constitution’s Fifth Amendment protection against self-incrimination.

Some emails on Clinton’s server were later deemed top secret, and scores of others included confidential or sensitive information. Clinton has said that her server featured “numerous safeguards,” but she has yet to explain how well her system was secured and whether, or how frequently, security updates were applied.

Clinton has apologized for running her homebrew server, and President Barack Obama said during a “60 Minutes” interview Sunday it was “a mistake.” Obama said national security wasn’t endangered, although the FBI still has yet to complete its review of Clinton’s server for evidence of hacking.

Clinton spokesman Brian Fallon said late Monday that “this report, like others before it, lacks any evidence of an actual breach, let alone one specifically targeting Hillary Clinton. The Justice Department is conducting a review of the security of the server, and we are cooperating in full.”

The AP exclusively reviewed numerous records from an Internet “census” by an anonymous hacker-researcher, who three years ago used unsecured devices to scan hundreds of millions of Internet Protocol addresses for accessible doors, called “ports.” Using a computer in Serbia, the hacker scanned Clinton’s basement server in Chappaqua at least twice, in August and December 2012. It was unclear whether the hacker was aware the server belonged to Clinton, although it identified itself as providing email services for clintonemail.com. The results are widely available online.

Remote-access software allows users to control another computer from afar. The programs are usually operated through an encrypted connection — called a virtual private network, or VPN. But Clinton’s system appeared to accept commands directly from the Internet without such protections.

“That’s total amateur hour,” said Marc Maiffret, who has founded two cybersecurity companies. He said permitting remote-access connections directly over the Internet would be the result of someone choosing convenience over security or failing to understand the risks. “Real enterprise-class security, with teams dedicated to these things, would not do this,” he said.

The government and security firms have published warnings about allowing this kind of remote access to Clinton’s server. The same software was targeted by an infectious Internet worm, known as Morta, which exploited weak passwords to break into servers. The software also was known to be vulnerable to brute-force attacks that tried password combinations until hackers broke in, and in some cases it could be tricked into revealing sensitive details about a server to help hackers formulate attacks.

“An attacker with a low skill-level would be able to exploit this vulnerability,” said the Homeland Security Department’s U.S. Computer Emergency Readiness Team in 2012, the same year Clinton’s server was scanned.

Also in 2012, the State Department had outlawed use of remote-access software for its technology officials to maintain unclassified servers without a waiver. It had banned all instances of remotely connecting to classified servers or servers located overseas.

The findings suggest Clinton’s server “violates the most basic network-perimeter security tenets: Don’t expose insecure services to the Internet,” said Justin Harvey, the chief security officer for Fidelis Cybersecurity.

Clinton’s email server at one point also was operating software necessary to publish websites, although it was not believed to have been used for this purpose. Traditional security practices dictate shutting off all of a server’s unnecessary functions to prevent hackers from exploiting design flaws.

In Clinton’s case, Internet addresses the AP traced to her home in Chappaqua revealed open ports on three devices, including her email system. Each numbered port is commonly, but not always uniquely, associated with specific features or functions. The AP in March was first to discover Clinton’s use of a private email server and trace it to her home.

Mikko Hypponen, the chief research officer at F-Secure, a top global computer security firm, said it was unclear how Clinton’s server was configured, but an out-of-the-box installation of remote desktop would have been vulnerable. Those risks — such as giving hackers a chance to run malicious software on her machine — were “clearly serious” and could have allowed snoops to deploy so-called back doors.

The U.S. National Institute of Standards and Technology, the federal government’s guiding agency on computer technology, warned in 2008 that exposed server ports were security risks. It said remote-control programs should only be used in conjunction with encryption tunnels, such as secure VPN connections.

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Local News

Traffic idles while waiting for the lights to change along 33rd Avenue West on Tuesday, April 2, 2024 in Lynnwood, Washington. (Olivia Vanni / The Herald)
Lynnwood seeks solutions to Costco traffic boondoggle

Let’s take a look at the troublesome intersection of 33rd Avenue W and 30th Place W, as Lynnwood weighs options for better traffic flow.

A memorial with small gifts surrounded a utility pole with a photograph of Ariel Garcia at the corner of Alpine Drive and Vesper Drive ion Wednesday, April 10, 2024 in Everett, Washington. (Olivia Vanni / The Herald)
Death of Everett boy, 4, spurs questions over lack of Amber Alert

Local police and court authorities were reluctant to address some key questions, when asked by a Daily Herald reporter this week.

The new Amazon fulfillment center under construction along 172nd Street NE in Arlington, just south of Arlington Municipal Airport. (Chuck Taylor / The Herald) 20210708
Frito-Lay leases massive building at Marysville business park

The company will move next door to Tesla and occupy a 300,0000-square-foot building at the Marysville business park.

Everett
Red Robin to pay $600K for harassment at Everett location

A consent decree approved Friday settles sexual harassment and retaliation claims by four victims against the restaurant chain.

A Tesla electric vehicle is seen at a Tesla electric vehicle charging station at Willow Festival shopping plaza parking lot in Northbrook, Ill., Saturday, Dec. 3, 2022. A Tesla driver who had set his car on Autopilot was “distracted” by his phone before reportedly hitting and killing a motorcyclist Friday on Highway 522, according to a new police report. (AP Photo/Nam Y. Huh)
Tesla driver on Autopilot caused fatal Highway 522 crash, police say

The driver was reportedly on his phone with his Tesla on Autopilot on Friday when he crashed into Jeffrey Nissen, killing him.

Janet Garcia walks into the courtroom for her arraignment at the Snohomish County Courthouse on Monday, April 22, 2024 in Everett, Washington. (Olivia Vanni / The Herald)
Everett mother pleads not guilty in stabbing death of Ariel Garcia, 4

Janet Garcia, 27, appeared in court Monday unrestrained, in civilian clothes. A judge reduced her bail to $3 million.

magniX employees and staff have moved into the company's new 40,000 square foot office on Seaway Boulevard on Monday, Jan. 18, 2020 in Everett, Washington. magniX consolidated all of its Australia and Redmond operations under one roof to be home to the global headquarters, engineering, manufacturing and testing of its electric propulsion systems.  (Andy Bronson / The Herald)
Harbour Air plans to buy 50 electric motors from Everett company magniX

One of the largest seaplane airlines in the world plans to retrofit its fleet with the Everett-built electric propulsion system.

Logo for news use featuring the municipality of Snohomish in Snohomish County, Washington. 220118
Driver arrested in fatal crash on Highway 522 in Maltby

The driver reportedly rear-ended Jeffrey Nissen as he slowed down for traffic. Nissen, 28, was ejected and died at the scene.

Logo for news use featuring the municipality of Mountlake Terrace in Snohomish County, Washington. 220118
3 charged with armed home invasion in Mountlake Terrace

Elan Lockett, Rodney Smith and Tyler Taylor were accused of holding a family at gunpoint and stealing their valuables in January.

PAWS Veterinarian Bethany Groves in the new surgery room at the newest PAWS location on Saturday, April 20, 2024 in Snohomish, Washington. (Olivia Vanni / The Herald)
New Snohomish hospital makes ‘massive difference’ for wild animals

Lynnwood’s Progressive Animal Welfare Society will soon move animals to its state of the art, 25-acre facility.

Traffic builds up at the intersection of 152nd St NE and 51st Ave S on Tuesday, April 16, 2024, in Marysville, Washington. (Ryan Berry / The Herald)
Here’s your chance to weigh in on how Marysville will look in 20 years

Marysville is updating its comprehensive plan and wants the public to weigh in on road project priorities.

Mountlake Terrace Mayor Kyko Matsumoto-Wright on Wednesday, April 10, 2024 in Mountlake Terrace, Washington. (Olivia Vanni / The Herald)
With light rail coming soon, Mountlake Terrace’s moment is nearly here

The anticipated arrival of the northern Link expansion is another sign of a rapidly changing city.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.