Britain, Government, National Security, Russia, Society, Technology, Terrorism, United States

Russia funded cyber terrorists targeting West under guise of Islamic State…

CYBER TERRORISM

A cyber security expert has warned that Vladimir Putin’s Russia is funding Islamic State hacking groups which pose a serious threat to some of the UK’s largest organisations.

Richard Turner, President of EMEA, has claimed his firm has proof that a crack team of highly skilled hackers with links to the Kremlin are targeting UK energy suppliers, defence networks, financial and telecommunication companies.

Mr Turner also claims they are responsible for bringing down a major television broadcaster in France.

Islamic State (IS) cyber terrorists were cited as the source as TV5 Monde was taken off air and the websites of smaller companies were hit by pro-IS propaganda in April. Mr Turner says, however, that the attacks were not carried out by IS but by a troupe of cyber terrorists, known as the APT28 group, which he believes are being sponsored by the Russian government and are masquerading as IS.

The security chief warns that hackers could easily bring down a media organisation in the UK or US. Mr Turner said his company has been tracking the work of APT28 since 2007.

An analysis of the information and data within the cyber caliphate website during the French attacks has been identified as being the same online data used by ATP28 in the past.

Their motives, according to Mr Turner, could be to push the news agenda away from Russia or by spreading fear and disinformation. He said: ‘If you can disrupt broadcast media through a cyber-attack you get the upper hand in spreading fear and propaganda.’

Mr Turner says that such attacks have been present for a number of years now and that many firms and individuals are only starting to realise the extent of it.

Such reports come amid increasing tensions between the west and Russia. RAF aircraft have been deployed numerous times over the past few months to fend off Russian bomber jets that have made frequent incursions into UK airspace. Russia has also beefed up its nuclear weaponry in response to US government plans to base military hardware in Eastern Europe.

Standard
Government, Intelligence, National Security, Society, Technology

Britain’s security and intelligence services: Responsibility not just power

SECURITY SERVICES

Intro: Given the extent of their reach and a recent parliamentary report into their activities an operational realignment is called for

Our security and intelligence agencies face greater challenges today than ever before. Advanced and sophisticated technology has become commonplace, and the world strains to keep up or nearly buckles under the weight of our digital communications. Monitoring the activities of terrorists, criminals and other malign forces have become difficult to spot because of the subversive methods they use in defying detection.

Bodies such as GCHQ, though, are hardly mere victims of the electronic advance. You may often hear security chiefs talking about their desperate searches for needles in haystacks, but the fact is they have an impressive operational capacity to cut through a lot of the chaff in order to find what they seek.

The Security and Intelligence Services (SIS) ability to obtain and examine vast swathes of raw data and processed information has been furiously debated ever since the revelations of Edward Snowden, the US fugitive, about how the British agency received data relating to UK citizens from America’s National Security Agency up to 2014 – a practice which was branded unlawful by the Investigatory Powers Tribunal. Notwithstanding, there will always be a divergence of views between those who place primacy on GCHQ doing anything in its power to maintain public safety, and those who feel unease at the prospect of innocent people being subjected to continued intrusion.

Earlier this month a report on these matters by Parliament’s Intelligence and Security Committee was a notable intervention. The committee members, like many of their peers across other government departments, believe that the bulk collection of data by GCHQ is legitimate and does not amount to unjustified, Orwellian surveillance. But they do appear to accept that the current legislation, which sets the parameters for such activities, is overly complex and lacks transparency. The legislation may have political oversight in regulating the activities of SIS, but its lack of public transparency and accountability was summed up well by the committee’s description of the existing legal framework. Intelligence agencies, they said, were being provided with a ‘blank cheque to carry out whatever activities they deem necessary’. In essence that is a damning indictment on the legislation that governs the work of our intelligence agencies. The committee has called for a new, single piece of legislation to replace and clarify current statutes as a matter of priority by the next government.

The discovery that a handful of intelligence officers have misused surveillance powers and have subsequently been disciplined by their superiors should also be of concern. The committee may speak reassuringly about the number of wrongdoers being in ‘very small single figures’ but the disclosure will hardly boost public confidence in the integrity of Britain’s security personnel. The recommendations of the committee are right, therefore, to suggest that the next government should consider criminalising such improper use of surveillance techniques.

Despite these positive proposals, there is nevertheless something troublingly simplistic about the committee’s top-line conclusion about GCHQ’s bulk interception capability. It says soothingly: ‘GCHQ are not reading the emails of everyone in the UK’. Whilst it is true that thousands of emails are read by security analysts every day, and that there remains a feeling that individual privacy of citizens comes a poor second to other considerations, few would have suggested otherwise against GCHQ’s simple assertion. That may be comforting for some, but surveillance does have the ability to antagonise as well as protect.

At a time when threats to this country are at a pitch not previously seen Britain’s security and intelligence agencies have a difficult job in tracking and monitoring those who wish to do us harm. But it must not be forgotten that the powers invested at their disposal are immense and more than proportionate for which they are needed. Simply asking that they be used responsibly is surely reason enough to help appease those who clamber to an argument of unnecessary state intrusion into many innocent people’s lives. Such a request stems from a belief that the glue which binds British society is primarily the combined force of its liberal values, not one that erodes it through a heavy-booted security capability.

 

Standard
Government, Legal, Scotland, Technology

Legitimate concerns exist over access to personal information…

GOVERNMENT DATABASE

The rapid growth of information technology and the huge amount of information that can now be stored (and searched for) within seconds has brought some considerable advantages. It has, however, also raised some big challenges, particularly in relation to privacy and human rights.

Recently, the Scottish Government narrowly won a debate at Holyrood on a plan to allow public bodies to access data through an individual’s NHS number. Such data can be retrieved from a database known as NHSCR. Anyone who was born in Scotland or registered with a GP practice north of the border has a Unique Citizen Reference number held in the NHSCR.

The concern is not so much to do with the data that is already held here, but that the government wants various streams of data held by the National Registers of Scotland by postcode to be added to the register and freely shared with other public bodies.

A simple adding of the postcode information would remove by default the consent currently required by the address system.

Protagonists will argue that adding individual postcodes to a database has existed since the 1950s. They might add, as they should, that it helps to trace children missing from the education system and by helping to identify foreign patients accessing the NHS. And with laws currently moving through parliament, it will make it much harder to avoid paying Scottish rate income tax (SRIT), which comes into force next year. It has to be a good thing when better ways are found of ensuring everyone due to pay tax does pay that tax, setting aside of course the Scottish Government’s position on poll tax defaulters who have been allowed to see their debts owed to local authorities written-off in full.

The Scottish Government has tried to give assurances that no medical records will be shared, but there have to be causes for legitimate concern. Losing the crucial consent from the public for the information to be stored under an individual’s postcode is one. The sheer breadth of the public bodies this would be available to is another. What would be preventing Scottish Canals, Quality Meat Scotland or even Botanic Gardens Scotland from accessing personal information on any individual, which quite clearly would be far outside of their own operational domain?

Because no-one can predict the future with any accuracy and political environments can change quite quickly, thinly laid down arguments tend to perform poorly and can easily be lost within the plethora of the wider debate. But that is not the same as raising perfectly legitimate fears about the security of access to an individual’s personal data. The creation of one universal number, the huge amount of data stored by postcode and the number of organisations that would have access must increase the opportunity for abuse, either through wrongful proliferation, malevolent external hacking practices, rogue individuals permitted access to the network, or even by a government agency itself.

The least we should expect is that safeguards are spelled out in parliament so that there are reassurances on these reasonable points before the green light is given on these proposals. Otherwise, the whole plan will be seen as introducing ID cards by stealth by the back door, a process which, similarly, relies on the proliferation of information across a single database.

Standard