Showing posts with label British Secret Service. Show all posts
Showing posts with label British Secret Service. Show all posts

Sunday, 22 March 2015

British Secret Service Gives Companies Security Tips


British intelligence service GCHQ has all manner of security tips on how they can protect their systems, networks and information, including things like risk management, secure configurations, network, user, user awareness and prevent malware. A total of ten steps discussed to a safer environment.

The report with recommendations dating from 2013 ( pdf ), but appeared this week in the British media. The Daily Telegraph wrote about the measures in the report, partly because of the advice to turn off unnecessary input / output devices and remove access to removable media. Thus, companies should consider whether their staff access to things like MP3 players and smartphones requires. Would unused functionality should be disabled, such as USB ports, floppy drives and CD and DVD players.

According GCHQ users remain the weakest link in the security chain. "And will always be the primary target of all kinds of attacks. A successful attack simply by a user to leave open an email with malicious content." Organizations therefore be advised to monitor all user activity, as well as network traffic and all IT systems.

USB Flash Drives

In the advisory, a special chapter included drawing attention to removable media such as USB drives. For example, it is recommended to limit the use of removable media. "What use is unavoidable, organizations must limit the types of media that can be used together with the users, systems and the type of data that can be stored or moved to removable media."

Organizations would be wise to regularly scan removable media for malware and the information stored on it, depending on its value and the risks to which it, encrypt. In addition, removable media should be managed and disposed of active, to ensure that previously stored information is no longer accessible.

Wednesday, 25 February 2015

Gemalto Denies Scale Theft Encryption Keys


SIM card manufacturer Gemalto denies that the American and British secret services widely encryption keys of SIM cards have been stolen. That leaves the Netherlands-based company after research know.Last week The Intercept came with the message that the US NSA and the British GCHQ in 2010 had obtained access to the network of Gemalto there and had the encryption keys sim captured.

According to the SIM card manufacturer is discovered in 2010 and 2011, two sophisticated attacks against the company that seem to correspond to the attack methods that are defined in the document of The Intercept. In 2010, the company discovered suspicious activity on one of the French sites where a "third party" the office trying to spy.

In July 2010 a second incident was discovered, which were sent phishing e-mails to a telecommunications company seemed from Gemalto and contained an infected attachment. Also, this time it happen several times tried to gain access to the computers of Gemalto staff. The company calls it "likely" that an operation has been carried by the NSA and GCHQ. This would, however, only the office have been compromised.

There has therefore been no large-scale theft of encryption keys. In addition, Gemalto says it had already rolled out a secure exchange system in 2010 for the exchange of these keys with telecom providers, which is the risk of theft would create exceptional. However if keys are captured, they would only intelligence second generation 2G networks can eavesdrop. 3G and 4G networks would not be vulnerable to such attacks.

Sunday, 22 February 2015

Researcher: "Gemalto was specifically targeted by GCHQ"


The chip maker based in the Netherlands Gemalto was indeed a specific target of the British secret service GCHQ, although Gemalto denies this in a press release. Yesterday The Intercept dropped on the basis of documents that the NSA and GCHQ in 2010 had broken at Gemalto .

In addition, the encryption keys were to secure mobile communications captured. In a press release states that Gemalto would appear from the publication that it was not necessarily the target. "It was an attempt to maximize net eject and as many mobile phones as possible to reach, with the aim to monitor the mobile communications without the consent of telecom providers and users."

Andrew Fishman, researcher and journalist at The Intercept let on Twitter know that Gemalto was indeed the target of the secret services. Codenamed "Dapino GAMMA" which appears in the documents of the GCHQ are namely GCHQ code name for Gemalto. In an operation of the British secret service, named HIGHLAND FLING, Gemalto is even named. This operation was intended to access the email accounts of Gemalto employees in France and Poland. Because of the revelations is the share of Gemalto on the AEX stock market currently more than 6% in the minus.

Saturday, 21 February 2015

NSA And GCHQ Would Have Hacked Sim Manufacturer Gemalto


The American and British secret services were established in the Netherlands SIM card manufacturer Gemalto five years ago there have been hacked and stolen the encryption keys used to secure mobile communications. Thus, the NSA and the British GCHQ would mobile communications eavesdropping without permission of telecom operators and foreign governments.


That claims The Intercept using documents whistleblower Edward Snowden. Gemalto product annually honors 2 billion SIM cards and is one of the largest manufacturers in the world SIM card. According to a presentation in 2010 of the GCHQ, different computers are infected with malware Gemalto that the British secret service at the time thought full access to the network.

Gemalto CEO Paul Beverly called the news disturbing. "The important thing for me is to understand how this could happen just so we can take steps to prevent it does not happen again," he tells The Intercept opposite. After being informed Gemalto's security team has conducted an investigation, but could find no trace of any hack. However, the slides of Snowden dating five years ago.

D66 MP Gerard Schouw call it incredible. He and other policymakers will ask for clarification from the government and want to know whether the AIVD knew Gemalto was a target. "We have a law in the Netherlands on the activities of secret services and hacking is not allowed," said the MP. He also does not think Plasterk such operations would approve by foreign secret services.