The team at General Services Administration’s 18F lives by the latest agile workflow models — they get stuff done, often by “hacking bureaucracy.” Unfortunately, sometimes moving too fast breaks things, which is good in Silicon Valley but can put you on the wrong side of federal policy when working for a government agency.
That appears to be what happened in a small-scale data breach at 18F that left sensitive information — including personally identifiable information and contracting data — from more than 100 accounts exposed.
Flash Alert: GSA Data Breach
According to a flash alert issued by GSA’s inspector general on May 12, inadequate permissions on a sharing app used by 18F staff left the Google Drive accounts for more than 100 employees accessible to others outside the team and GSA. These accounts were exposed for at least five months until an 18F supervisor noticed the problem on March 4.
18F Executive Director Aaron Snow and Director of Delivery Architecture and Infrastructure Noah Kunin asserted in a May 13 blog post that “no sensitive information was shared inappropriately.”
The whole issue could be seen as a minor trip-up, except that the apps being used are not condoned by GSA policy.
18F staff collaborate using the Slack platform and use an app called OAuth 2.0 to link their Slack accounts to Google Drive’s free cloud storage.
“18F’s use of both OAuth 2.0 and Slack is not in compliance with GSA’s Information Technology Standards Profile,” according to the flash alert. “The order allows information technology to be approved for use in the GSA IT environment if they comply with GSA’s security, legal and accessibility requirements. Currently, neither OAuth 2.0 nor Slack are approved for use in the GSA IT standards profile.”
As of March 9, 18F supervisors have severed the connection between Slack and employees’ Drive accounts.
The IG also dinged 18F leadership for waiting five days to report the issue, a violation of GSA’s Information Breach Notification Policy, which requires reporting within one hour of discovery.
The IG recommended 18F and other GSA components cease using Slack and OAuth 2.0 unless or until they are certified and that GSA leadership crack down on 18F’s compliance with agency policies.




