Within Early Insecurity
How Exposed Passwords Threatened Wider Defense Networks
An Army Corps audit found unencrypted passwords and open connections that could let stolen credentials unlock wider Defense networks.
On this page
- Why usernames and passwords crossed networks unencrypted
- How unauthenticated server access increased exposure
- How captured credentials could be reused elsewhere
Page outline Jump by section
Introduction
A key lesson from the early internet era that enabled intrusions such as those associated with Gary McKinnon was not simply that individual systems were vulnerable, but that authentication weaknesses could spread beyond the first compromised computer. A 2002 audit of the U.S. Army Corps of Engineers found that usernames and passwords were still being transmitted across parts of its network without encryption, while some servers accepted unauthenticated connections. Those weaknesses meant that an attacker who obtained credentials on one segment of the network might be able to reuse them elsewhere, increasing the risk to other Department of Defense (DoD) systems connected to the Corps’ infrastructure rather than only to the machines originally targeted.[GAO]gao.govgaoInformation Security: Corps of Engineers Making Improvements, But Weaknesses Continue | U.S. GAOJune 10, 2002…
Within the broader story of early government network insecurity, this audit is important because it documented concrete authentication failures and explained why credential theft could have consequences extending beyond a single organisation or application.
Why usernames and passwords crossed networks unencrypted
The Government Accountability Office (GAO) examined controls protecting the Corps of Engineers Financial Management System (CEFMS), a critical system supporting military and civil works financial operations. Although the audit concluded that the Corps had corrected many earlier deficiencies, it also identified continuing weaknesses in general computer controls that affected confidentiality, integrity and availability.[GAO]gao.govgaoInformation Security: Corps of Engineers Making Improvements, But Weaknesses Continue | U.S. GAOJune 10, 2002…
Among the most significant findings was that usernames and passwords continued to travel across parts of the network in unencrypted form. At the time, many enterprise systems still relied on older authentication protocols or legacy configurations that did not protect credentials while they were in transit across local networks. Anyone able to observe that traffic on the affected network segment could potentially capture valid login details.
The concern extended beyond simple password disclosure. Once valid credentials had been intercepted, they could be used to authenticate as a legitimate user rather than exploiting a software flaw. That made intrusion detection more difficult because the attacker could appear to be using authorised accounts rather than obviously malicious techniques.[GAO]gao.govgaoUnited States General Accounting Office Report…
How unauthenticated server access increased exposure
The audit also found that certain Corps servers permitted unauthenticated connections. Although such connections did not necessarily provide immediate administrative access, they exposed information that could assist an attacker in understanding the environment and planning subsequent attacks.
According to the GAO, allowing unauthenticated access increased the likelihood that an attacker could gather information useful for obtaining further access. Information about available services, system configuration or network structure can reduce the effort required to identify valid targets or exploit additional weaknesses. Combined with exposed credentials, these reconnaissance opportunities created a layered security problem rather than an isolated technical defect.[Global Security]globalsecurity.orgglobalsecurity.orgGlobal SecurityGAO-02-589 INFORMATION SECURITY Corps of Engineers Making Improvements, But Weaknesses ContinueJune 10, 2002…
The report identified these authentication weaknesses alongside broader shortcomings in:
- access management and least-privilege controls;[oversight.gov]oversight.govFebruary 17, 2026 — Brought to you by the Council of the Inspectors General on Integrity and Efficiency AUDIT OF INTEGRATED FINANCIAL AND… * protection of system software;[legistorm.com]legistorm.comSource details in endnotes. * network security controls;[gao.gov]gao.govGA O-09-232G, Federal Information System Controls Audit Manual (FISCAMGA O-09-232G, Federal Information System Controls Audit Manual (FISCAM
- change management and documentation; and
- continuity and security management processes.
Taken together, these issues indicated that weaknesses were reinforcing one another instead of existing independently.[GAO]gao.govgaoInformation Security: Corps of Engineers Making Improvements, But Weaknesses Continue | U.S. GAOJune 10, 2002…
How captured credentials could be reused elsewhere
The most consequential aspect of the audit was its warning that credential theft was not confined to the Corps’ own systems. The GAO explicitly observed that vulnerabilities in the Corps’ network increased risks to other DoD networks and systems to which it was connected.[GAO]gao.govgaoInformation Security: Corps of Engineers Making Improvements, But Weaknesses Continue | U.S. GAOJune 10, 2002…
The mechanism was straightforward:
- An attacker captures an unencrypted username and password from network traffic.
- The stolen credentials are used to access the corresponding database or application.
- If that account possesses additional privileges—or if the same or similar credentials are accepted elsewhere—the attacker can expand access to other connected resources.
- The compromised system becomes a trusted foothold from which to explore neighbouring DoD networks.
This risk reflected a common practice of the period: users frequently reused passwords across multiple systems, while organisations often relied on interconnected networks with varying security standards. Even if the audit did not document widespread credential reuse directly, it recognised that compromised authentication information could facilitate broader unauthorised access beyond the initially affected machine.[Global Security]globalsecurity.orgglobalsecurity.orgGlobal SecurityGAO-02-589 INFORMATION SECURITY Corps of Engineers Making Improvements, But Weaknesses ContinueJune 10, 2002…
What the audit revealed about early Defence network security
The Corps audit did not portray an organisation that had ignored security altogether. In fact, the GAO noted substantial progress since previous reviews, including completion of dozens of earlier recommendations and correction of newly identified weaknesses during the audit itself. Nevertheless, the remaining deficiencies were significant because they affected fundamental trust mechanisms rather than isolated applications.[GAO]gao.govgaoInformation Security: Corps of Engineers Making Improvements, But Weaknesses Continue | U.S. GAOJune 10, 2002…
The report concluded that continuing vulnerabilities impaired the Corps’ ability to protect sensitive and financial information and warranted management attention because they increased the risk of unauthorised disclosure, modification of data, misuse of computing resources and disruption of operations. Importantly, the GAO also emphasised that these vulnerabilities increased risks to connected DoD networks, highlighting that interconnected government systems could inherit the consequences of weak authentication practices in one organisation.[GAO]gao.govgaoInformation Security: Corps of Engineers Making Improvements, But Weaknesses Continue | U.S. GAOJune 10, 2002…
Why this evidence matters for understanding early UFO-related intrusions
In the context of early internet-era intrusions associated with UFO-seeking hackers such as Gary McKinnon, the Army Corps findings illustrate that the underlying problem was often ordinary network administration rather than extraordinary offensive capability. Weak authentication, unencrypted credential transmission and permissive server configurations created opportunities for attackers to obtain legitimate credentials and move through interconnected environments.
The significance of the 2002 audit therefore lies less in any single vulnerable server than in its demonstration that authentication failures could propagate risk across linked Defence networks. It provided contemporaneous evidence that credential exposure was recognised as a systemic issue with implications extending well beyond the individual systems under direct examination.[GAO]gao.govgaoInformation Security: Corps of Engineers Making Improvements, But Weaknesses Continue | U.S. GAOJune 10, 2002…
Amazon book picks
Further Reading
Books and field guides related to How Exposed Passwords Threatened Wider Defense Networks. Use these as the next step if you want deeper reading beyond the article.
Ghost in the Wires: My Adventures as the World's Most Wanted...
In this "intriguing, insightful and extremely educational" novel, the world's most famous hacker teaches you easy cloaking and counter-me...
Where Wizards Stay Up Late
Rating: 3.8/5 from 11 Google Books ratings
In 1990, the ARPANET itself was shut down, fully merged by then with the Internet it had spawned.
Security Engineering: A Guide to Building Dependable Distribu...
Rating: 4.5/5 from 7 Google Books ratings
Now that there's software in everything, how can you make anything secure? Understand how to engineer dependable systems with this newly...
eBay marketplace picks
Marketplace Samples
Live-tested eBay searches with available results related to this page.
Selected fromUFO enamel pin oneBay.co.uk.
Endnotes
1.
Source: gao.gov
Title: gao 02 589
Link:https://www.gao.gov/products/gao
Source snippet
Information Security: Corps of Engineers Making Improvements, But Weaknesses Continue | U.S. GAOJune 10, 2002...
Published: June 10, 2002
2.
Source: gao.gov
Title: gao 02 589
Link:https://www.gao.gov/assets/gao-02-589.pdf
Source snippet
United States General Accounting Office Report...
3.
Source: files.gao.gov
Link:https://files.gao.gov/reports/GAO-26-108771/index.html
Source snippet
gao.govGAO-26-108771, INFORMATION ENVIRONMENT: DOD Faces Risks with Publicly Available DataOctober 7, 2025 — Chairwoman Ernst, Ranking Me...
Published: October 7, 2025
4.
Source: files.gao.gov
Link:https://files.gao.gov/reports/GAO-26-107492/index.html
Source snippet
gao.govGAO-26-107492, INFORMATION ENVIRONMENT: DOD Needs to Address Security Risks of Publicly Accessible InformationOctober 7, 2025 — IN...
Published: October 7, 2025
5.
Source: gao.gov
Title: gao 26 107492
Link:https://www.gao.gov/products/gao-26-107492
6.
Source: gao.gov
Title: gao 26 108771
Link:https://www.gao.gov/products/gao-26-108771
7.
Source: gao.gov
Title: gao 20 241
Link:https://www.gao.gov/products/gao
8.
Source: gao.gov
Link:https://www.gao.gov/products/gao
9.
Source: gao.gov
Link:https://www.gao.gov/products/gao
10.
Source: gao.gov
Link:https://www.gao.gov/assets/a295691.html
11.
Source: gao.gov
Title: GA O-09-232G, Federal Information System Controls Audit Manual (FISCAM)
Link:https://www.gao.gov/assets/a77155.html
12.
Source: gao.gov
Link:https://www.gao.gov/assets/a77127.html
13.
Source: gao.gov
Link:https://www.gao.gov/assets/a258653.html
14.
Source: gao.gov
Link:https://www.gao.gov/assets/a94320.html
15.
Source: gao.gov
Link:https://www.gao.gov/assets/a76724.html
16.
Source: gao.gov
Link:https://www.gao.gov/ig/audit-reports
17.
Source: globalsecurity.orgglobalsecurity.org
Link:https://www.globalsecurity.orgwww.globalsecurity.org/security/library/report/gao/d02589.pdf
Source snippet
Global SecurityGAO-02-589 INFORMATION SECURITY Corps of Engineers Making Improvements, But Weaknesses ContinueJune 10, 2002...
Published: June 10, 2002
18.
Source: oversight.gov
Link:https://www.oversight.gov/reports/audit/audit-integrated-financial-and-acquisition-management-system-access-controls
Source snippet
February 17, 2026 — Brought to you by the Council of the Inspectors General on Integrity and Efficiency AUDIT OF INTEGRATED FINANCIAL AND...
Published: February 17, 2026
Additional References
19.
Source: irs.gov
Title: Each audit record captures the details related to the underlying event e.g.: *
Link:https://www.irs.gov/privacy-disclosure/meeting-irs-safeguards-audit-requirements
Source snippet
Meeting IRS Safeguards audit requirements | Internal Revenue ServiceJune 28, 2026 — Audit records should also be produced when adversarie...
Published: June 28, 2026
20.
Source: govinfo.gov
Title: GAOREPORTS GAO 02 589
Link:https://www.govinfo.gov/app/details/GAOREPORTS-GAO
Source snippet
GAO-02-589 - Information Security: Corps of Engineers Making Improvements, But Weaknesses Continue - GAOREPORTS-GAO-02-589 | Conte...
21.
Source: youtube.com
Title: A Brief History of Passwords and NIST’s New Rules
Link:https://www.youtube.com/watch?v=75Z2XBChNZA
Source snippet
These videos provide historical context on early military network intrusions such as the [Gary McKinnon case]({{ 'mc-kinnon-case/' | relative_url }}), as well as the broader cyber...
22.
Source: ojp.gov
Link:https://ojp.gov/ncjrs/virtual-library/abstracts/information-security-corps-engineers-making-improvements-weaknesses
23.
Source: legistorm.com
Link:https://www.legistorm.com/reports/gao_by_subject/id/10542/name/System_vulnerabilities.html
24.
Source: dodig.mil
Link:https://www.dodig.mil/Reports/Audits-and-Evaluations/Article/1118771/identification-of-classified-information-in-an-unclassified-dod-system-and-an-u/
25.
Source: youtube.com
Title: The Man Who Hacked the U.S. Government
Link:https://www.youtube.com/watch?v=ND0zQX1rGdg
Source snippet
Hacking for UFOs and fighting for his life. Who is Gary McKinnon?...
26.
Source: legistorm.com
Link:https://www.legistorm.com/reports/view/gao/33177/Corps_of_Engineers_Making_Improvements_But_Weaknesses_Continue.html
27.
Source: youtube.com
Title: Gary Mc Kinnon wins extradition battle
Link:https://www.youtube.com/watch?v=y4lecD44F5E
Source snippet
A Brief History of Passwords and NIST's New Rules...
28.
Source: youtube.com
Title: Hacking for UFOs and fighting for his life. Who is Gary Mc Kinnon?
Link:https://www.youtube.com/watch?v=OImdnvQx7sQ
Source snippet
UK hacker's extradition to US blocked...


