<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-GB"
                       href="https://www.itpro.com/uk/feeds/tag/gchq"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from ITPro UK in Gchq ]]></title>
                <link>https://www.itpro.com/uk/tag/gchq</link>
        <description><![CDATA[ All the latest gchq content from the ITPro  UK team ]]></description>
                                    <lastBuildDate>Tue, 01 Apr 2025 08:26:25 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Former GCHQ intern risked national security after taking home top secret data  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/former-gchq-intern-risked-national-security-after-taking-home-top-secret-data</link>
                                                                            <description>
                            <![CDATA[ A former GCHQ intern has pleaded guilty to transferring data from a top-secret computer onto his work phone. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VMNecwqF2F4BkoWszYuyHi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5gNAC373HykFTKUUc8wwwN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 01 Apr 2025 08:26:25 +0000</pubDate>                                                                                                                                <updated>Tue, 01 Apr 2025 08:37:40 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Bobby Hellard) ]]></author>                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Bobby Hellard&amp;nbsp;is&amp;nbsp;ITPro&#039;s Reviews Editor and has worked on&amp;nbsp;CloudPro and ChannelPro since 2018. In his time at ITPro, Bobby has covered stories for all the major technology companies, such as Apple, Microsoft, Amazon and Facebook, and regularly attends industry-leading events such as AWS Re:Invent and Google Cloud Next.&lt;/p&gt;
&lt;p&gt;Bobby mainly covers hardware reviews, but you will also recognize him as the face of many of our video reviews of laptops and smartphones.&lt;/p&gt;
&lt;p&gt;He has been a journalist for ten years, originally covering sports, before moving into business technology with ITPro. He has bylines in The Independent, Vice and The Business Briefing. Contact him at &lt;a href=&quot;mailto:bobby.hellard@futurenet.com&quot;&gt;bobby.hellard@futurenet.com&lt;/a&gt; or find him on Twitter: &lt;a href=&quot;https://twitter.com/bobbyhellard&quot;&gt;@bobbyhellard&lt;/a&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5gNAC373HykFTKUUc8wwwN-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person with a smartphone in a security zone ]]></media:description>                                                            <media:text><![CDATA[A person with a smartphone in a security zone ]]></media:text>
                                <media:title type="plain"><![CDATA[A person with a smartphone in a security zone ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5gNAC373HykFTKUUc8wwwN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A former GCHQ intern has pleaded guilty to transferring data from a top-secret computer onto his work phone. </p><p>Hassaan Arshad, who was arrested in 2022, is alleged to have downloaded the stolen data onto a hard drive connected to a personal computer. He pleaded guilty to a charge under Section 3ZA of the <a href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act">Computer Misuse Act 1990</a>, which relates to "unauthorised acts causing, or creating risk of, serious damage". </p><p>Areas and equipment labeled "top secret" within GCHQ house the government's most sensitive data. Information compromised here might cause a threat to life and/or the economic security of allied countries. </p><p>The case raises many questions about the highest level of the UK's national security and is a stark reminder of the vulnerability that mobile phones can create. </p><p>As <a href="https://www.itpro.com/security/phishing/356581/what-are-you-giving-away-on-social-media">Jake Moore</a>, global cybersecurity advisor at ESET, puts it, the most serious data breaches often don't come from outsiders; they can simply stem from internal errors, poor controls, or invisible insider threats. </p><p>Moore previously worked for the Digital Forensics Unit and Cyber Crime Teams in the Dorset Police force, and spent 14 years investigating computer crime. He said the GCHQ case is another reminder of how easily sensitive data can fall into the wrong hands without robust preventative measures. </p><p>"Organizations need to remember to implement strict access controls such as locking down removable media and ensuring that only those with direct operational needs have access to sensitive areas," Moore said. </p><p>"Businesses also need to think about reducing the risk of mobile devices being used to capture sensitive data. It is worrying that personal devices were not banned from certain areas, but when phones are required, it can be effective to deploy <a href="https://www.itpro.com/mobile/29775/best-mdm-solutions">Mobile Device Management (MDM)</a> tools to limit device capabilities in high-risk zones, such as removing the use of the cameras."</p><p>When and where we use our phones has always been a big concern for security teams. Devices with electronic signals are often completely barred from high-level institutions, such as the CIA.</p><p>In the fallout of the <a href="https://www.spytalk.co/p/signalgate-did-cia-boss-ratcliffe?utm_campaign=post&utm_medium=web" target="_blank">Signal leak</a>, where a journalist was inadvertently added to a classified conversation about an impending air attack in Yemen, the focus has mainly been on the use of the chat app. </p><p>However, as former CIA official William D. Murray pointed out, why was the director of the CIA using a mobile phone in the headquarters of the CIA? </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/370411/nearly-half-of-security-practitioners-told-to-keep-data-breaches-under-wraps">Nearly half of security practitioners told to ‘keep data breaches under wraps’</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/businesses-must-get-better-at-sharing-cyber-information-urges-former-gchq-chief">Businesses must get better at sharing cyber information, urges former GCHQ chief</a></li><li><a href="https://www.itpro.com/security/data-breaches/nearly-half-of-emea-data-breaches-were-due-to-internal-blunders-in-2023">Nearly half of EMEA data breaches were due to internal blunders</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Businesses must get better at sharing cyber information, urges former GCHQ chief ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/businesses-must-get-better-at-sharing-cyber-information-urges-former-gchq-chief</link>
                                                                            <description>
                            <![CDATA[ Jeremy Fleming, the former head of GCHQ, has warned businesses face increasingly sophisticated cyber attacks on critical national infrastructure (CNI). ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3GsFAWzCAcTAfYGApWJirW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JNkiJBMBkZLBf84aNJyL9n-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 14 Mar 2025 16:23:54 +0000</pubDate>                                                                                                                                <updated>Mon, 17 Mar 2025 14:26:48 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ rory.bathgate@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rory Bathgate is the Features and Multimedia Editor at ITPro, overseeing all in-depth content and case studies. He is a subject expert on artificial intelligence and business networks but in his time at ITPro has also covered a wide range of areas including cyber security and hardware. Throughout his time at ITPro, Rory has charted the rise in popularity of generative AI and specifically companies such as Microsoft, OpenAI, and Google.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Alongside this, he has delved into increasing calls for ethical and responsible AI as global legislators circle the technology, as well as the latest in mobile networking technology, from 5G mmWave to the 3G sunset and how it will affect businesses.&lt;/p&gt;
&lt;p&gt;He has provided coverage from high-profile tech conferences such as Dell Technologies World, SuiteWorld, and VMware Explore Europe. His on-the-ground coverage has included live blogs, extensive daily coverage of the most significant announcements, analysis pieces, and podcasts.&lt;/p&gt;
&lt;p&gt;Indeed, Rory is also a full-time co-host of the ITPro Podcast alongside Jane McCallion, where he swaps a keyboard for a microphone to discuss the latest learnings in tech. Each week, a guest comes onto the show to discuss topics such as cyber security, productivity, or digital transformation in detail.&lt;/p&gt;
&lt;p&gt;Rory has an MA in Eighteenth-Century Studies from King’s College London, as well as a BA in English and American Literature from the University of Kent. He joined ITPro in 2022 as a graduate, after four years in student journalism.&lt;/p&gt;
&lt;p&gt;In his free time, Rory enjoys photography and video editing, and can often be found at the cinema or reading a good science fiction paperback.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JNkiJBMBkZLBf84aNJyL9n-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Jeremy Fleming, former head of GCHQ, onstage with Haider Pasha, chief security officer, EMEA &amp; LATAM at Palo Alto Networks at Ignite London 2025.]]></media:description>                                                            <media:text><![CDATA[Jeremy Fleming, former head of GCHQ, onstage with Haider Pasha, chief security officer, EMEA &amp; LATAM at Palo Alto Networks at Ignite London 2025.]]></media:text>
                                <media:title type="plain"><![CDATA[Jeremy Fleming, former head of GCHQ, onstage with Haider Pasha, chief security officer, EMEA &amp; LATAM at Palo Alto Networks at Ignite London 2025.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JNkiJBMBkZLBf84aNJyL9n-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The former head of GCHQ has warned businesses face increasingly sophisticated cyber attacks on critical national infrastructure (CNI), urging firms to pay closer attention to geopolitics and collaborate on fighting the next generation of threats.</p><p>Jeremy Fleming, who served as director of the agency from 2017 to 2023, says the ‘big four’ – generally understood as <a href="https://www.itpro.com/security/cyber-attacks/china-cyber-threats">China</a>, <a href="https://www.itpro.com/security/cyber-attacks/russia-is-targeting-unpatched-vulnerabilities-what-to-do">Russia</a>, <a href="https://www.itpro.com/security/cyber-crime/north-korean-insider-attacks-are-skyrocketing-dozens-of-us-firms-didnt-spot-the-hacker-in-their-midst">North Korea</a>, and <a href="https://www.itpro.com/security/cyber-attacks/the-iran-cyber-threat">Iran</a> – are launching <a href="https://www.itpro.com/security/cyber-attacks/why-attacks-against-critical-national-infrastructure-cni-are-such-a-threat"><u>attacks on CNI</u></a> to an unprecedented degree. </p><p>He also noted attackers are using pre-positioning, in which they <a href="https://www.itpro.com/security/cyber-attacks/volt-typhoon-threat-group-electric-grid"><u>embed themselves into systems for future attacks</u></a>.</p><p>“Some of the things we're seeing and the way in which particularly pre-positioning is happening on critical national infrastructure, we haven't seen that before,” Fleming told attendees at the Palo Alto Networks <em>Ignite </em>event in London this week.</p><p>“Now you know that's really hard to do, I know as an intelligence professional, that's really hard to do but we are seeing it. We've seen it in the water industry particularly in America, we're seeing it across healthcare, we're seeing it in other areas.”</p><p>Fleming pointed to the recent <a href="https://www.itpro.com/security/fcc-tells-telcos-to-sharpen-up-security-after-salt-typhoon-chaos"><u>Salt Typhoon</u></a> attack on US telecoms infrastructure as an example of the sophisticated threat posed by <a href="https://www.itpro.com/security/cyber-attacks/state-sponsored-cyber-attacks-the-new-frontier"><u>state-sponsored threat actors</u></a>, noting that more attacks of its kind using <a href="https://www.itpro.com/security/five-eyes-advisory-raises-alarm-over-state-backed-living-off-the-land-attacks"><u>living off the land</u></a> techniques can be expected in the near future.</p><p>Fleming said that regardless of company size, from small businesses to the largest enterprises, can repel these threats on their own. To achieve this, however, he called for far more information sharing between firms.</p><p>“We have to do better, you all have to do better, at sharing your understanding of the threats,” he said.</p><p>“It’s the pace at which we're able to share this information because some of you, one of you will solve something which is important from a state actor perspective for anyone else. That’s just the way it works. So how are we going to accelerate that data sharing amongst that?”</p><p>Haider Pasha, chief security officer, EMEA & LATAM at Palo Alto Networks, led the discussion with Fleming onstage during the <em>Ignite </em>keynote. He pointed to the Palo Alto Networks’ Cyber Threat Alliance, which grew from an information sharing agreement with a few close competitors to an organization of 26-27 industry leaders in cybersecurity, as an example of </p><p>“But I think, as you said, we need to do a better job of this,” Pasha noted.</p><p>This will be especially key as <a href="https://www.itpro.com/technology/artificial-intelligence/ai-threats-the-importance-of-a-concrete-strategy-in-fighting-novel-attacks"><u>AI threats ramp up</u></a>, Fleming noted, adding that sentiment on whether AI benefits attackers or defenders more is shifting due to growing caution in the cyber field. </p><p>While Fleming maintained that he’s still optimistic about how AI can benefit cybersecurity, he qualified that pace of delivery would make all the difference here.</p><h2 id="competing-pressures-on-cyber-teams">Competing pressures on cyber teams</h2><p>One of the major barriers organizations and nation states face in the coming years will be to meet their own <a href="https://www.itpro.com/security/data-protection/data-sovereignty-a-growing-priority-for-uk-enterprises"><u>data sovereignty</u></a> requirements without withdrawing from vital information sharing agreements.</p><p>“So we are going to find that whilst I am airily talking about partnerships and whilst I’m airily talking about information sharing, quite a lot of the political pressure is going to get us to look inwards as nations,” Fleming said.</p><p>Against the backdrop of state-backed groups, Fleming also issued a stark warning:</p><p>“If you are faced with a determined state adversary, you will not stop them. That’s just the reality. Because a determined state adversary is not only trying to attack you from a cyber perspective, it’ll be looking for insider weakness, it'll be looking for other aspects of leverage.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Z9ggB3xs29f2quPySea2Xc" name="Nine steps to proactively manage data privacy and protection_listing.jpg" caption="" alt="Whtiepaper cover with green title over image of female wearing glasses smiling at camera" src="https://cdn.mos.cms.futurecdn.net/Z9ggB3xs29f2quPySea2Xc.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: ServiceNow)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/370011/nine-steps-to-proactive-manage-data-privacy-and"><em>Reduce risks, comply with regulations, and protect data</em></a></p></div></div><p>But Fleming clarified that most businesses don’t need to be concerned about state adversaries, suggesting instead that raising cybersecurity levels to the level required to block most attacks is sufficient and not beyond any capable organization.</p><p>He also acknowledged what Palo Alto Networks calls ‘mega breaches’, large attacks on organizations that severely disrupt services and cause hundreds of millions of dollars in losses. Fleming stated that these attacks are lucrative and often carried out by groups based in North Korea.</p><iframe allow="" height="200px" width="100%" data-lazy-priority="high" data-lazy-src="https://player.captivate.fm/episode/a696c78c-0d94-4bc0-b1cf-106e70c68480/"></iframe><p>A recent example is the recent <a href="https://www.reuters.com/technology/cybersecurity/cryptos-biggest-hacks-heists-after-15-billion-theft-bybit-2025-02-24/" target="_blank"><u>Bybit crypto heist</u></a>, in which $1.5 billion of digital tokens were stolen from an international cryptocurrency exchange. Fleming cited this as an example of a for-profit attack typical of North Korean threat actors. </p><p>Profit-driven groups also lean on ransomware attacks to an increasing degree, with February 2025 having been the <a href="https://www.itpro.com/security/ransomware/ransomware-attacks-worst-month-ever"><u>worst month for ransomware</u></a> on record. </p><p>Despite efforts by international law enforcement to <a href="https://www.itpro.com/security/ransomware/alphv-leak-site-seized-by-law-enforcement-as-decryption-tool-released"><u>seize leak sites</u></a> on the <a href="https://www.itpro.com/security/32117/what-is-the-dark-web"><u>dark web</u></a> and <a href="https://www.itpro.com/security/ransomware/lockbit-takedown-is-a-huge-win-for-law-enforcement-but-lets-not-celebrate-too-soon-security-experts-warn"><u>take down groups like LockBit</u></a>, ransomware groups persist – and Fleming was frank about the low chance these efforts will succeed.</p><p>“Globally, we haven't been able to take the steps necessary to disrupt ransomware at its source,” he said.</p><p>“And by that I mean, because many of the spaces where the ransomware actors are operating are denied spaces, law enforcement is unable to go after those in a way which is broad enough to make material difference.”</p><p>As with the threat posed by state-backed groups, Fleming urged firms to focus on the fundamentals and greater collaboration to shield themselves from ransomware.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/global-cyber-attacks-jumped-44-percent-last-year">Global cyber attacks jumped 44% last year</a></li><li><a href="https://www.itpro.com/security/ransomware/ransomware-attacks-worst-month-ever">February was the worst month on record for ransomware attacks</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/manufacturing-firms-are-struggling-to-handle-rising-ot-security-threats">Manufacturing firms are struggling to handle rising OT threats</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Plans submitted for new £1 billion 'Golden Valley' tech hub in Cheltenham ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/plans-submitted-for-new-pound1-billion-golden-valley-tech-hub-in-cheltenham</link>
                                                                            <description>
                            <![CDATA[ The Golden Valley development will house the new National Cyber Innovation Centre ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eZAuGSKcubvztgimPPeJkH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fxEjCom5FVqMkfWfuZnJ7g-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 06 Nov 2023 11:05:01 +0000</pubDate>                                                                                                                                <updated>Tue, 16 Jan 2024 11:00:34 +0000</updated>
                                                                                                                                            <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fxEjCom5FVqMkfWfuZnJ7g-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Map of United Kingdom on digital pixelated display]]></media:description>                                                            <media:text><![CDATA[Map of United Kingdom on digital pixelated display]]></media:text>
                                <media:title type="plain"><![CDATA[Map of United Kingdom on digital pixelated display]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fxEjCom5FVqMkfWfuZnJ7g-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Plans have been submitted for a £1 billion development in Cheltenham that will include one of Europe&apos;s largest tech campuses.</p><p>Golden Valley will cover 47 hectares and, along with 1,000 low-carbon residential properties, include more than a million square feet of commercial space, targeting businesses with a focus on science and technology. </p><p>The development is expected to create 12,000 new jobs.</p><p>"Golden Valley is the first development of its kind to be delivered in the UK – it sits at the heart of the Government’s Cyber and Technology strategy and underpins the UK’s ambitions to become a science and <a href="https://www.itpro.com/business/policy-legislation/369874/uk-silicon-valley-plans-are-antiquated-and-misguided">technology superpower</a> by 2030," said Adam Brady, executive director at developer HBD x Factory.</p><p>The site will house the National Cyber Innovation Centre, which received £95 million in funding last month. Detailed proposals are expected to be submitted in the new year. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="fxEjCom5FVqMkfWfuZnJ7g" name="digital_uk_GettyImages-1368022904 (1).jpg" caption="" alt="Map of United Kingdom on digital pixelated display" src="https://cdn.mos.cms.futurecdn.net/fxEjCom5FVqMkfWfuZnJ7g.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/sexism-in-the-uk-tech-sector-is-rife-and-shows-no-sign-of-abating">Sexism in the UK tech sector is rife and shows no sign of abating</a><a data-analytics-id="inline-link" href="https://www.itpro.com/business/careers-and-training/jobs-in-uk-tech-on-the-rise-after-a-turbulent-two-years">Jobs in UK tech on the rise after a turbulent two years</a><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/uk-finance-industry-calls-for-launch-of-quantum-technology-taskforce">UK finance industry calls for launch of quantum technology taskforce</a></p></div></div><p>As well as serving as a general innovation centre focused on the <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a>, <a href="https://www.itpro.com/technology/what-is-deep-tech">deep tech</a> and <a href="https://www.itpro.com/technology/31818/what-is-quantum-computing">quantum</a> sectors, there are plans to use the site as a test ground for new <a href="https://www.itpro.com/smart-city/34234/are-smart-cities-a-disaster-waiting-to-happen">smart city</a> concepts.</p><p>"Here in Cheltenham, we will be host to an internationally significant cyber and technology focused campus which, subject to planning permission, will provide the catalyst for delivering economic growth for the town and regeneration of local communities," said councilor Mike Collins at Cheltenham Borough Council.</p><p>Developers said Gloucestershire is already home to one of the UK’s most significant technology clusters, and has the largest concentration of cyber companies outside of London. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="o8ao8cA4QtNy6a2aeFqYmi" name="AWS-Healthcare_digital_front_door_listing.jpg" caption="" alt="A whitepaper from AWS on how digital engagement tools and a strong cloud-based infrastructure, can reduce the demands on healthcare providers" src="https://cdn.mos.cms.futurecdn.net/o8ao8cA4QtNy6a2aeFqYmi.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: AWS)</span></figcaption></figure><p class="fancy-box__body-text"><em>Discover how digital engagement tools can reduce demands on the NHS<br></em><br><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/the-digital-front-door">DOWNLOAD NOW</a></p></div></div><p>In Cheltenham alone, there are an estimated 590 technology firms employing over 3,100 people, with Gloucestershire as a whole housing 2,300 businesses.</p><p>More than 120 of these are <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> businesses, developers said, making the density of cyber security firms 11 times the UK average.</p><p>The location, developers said, boasts good rail and road links to Bristol, Birmingham, London, and other key parts of the country, and is within 90 minutes&apos; travel to 20 universities.</p><h2 id="golden-valley-security-collaboration">Golden Valley security collaboration</h2><p>The new development is also close to <a href="https://www.itpro.com/cyber-security/33079/gchq-boss-says-uk-must-be-vigilant-againt-chinese-tech-firms">GCHQ</a>, which is supporting the creation of the new centre.</p><p>Paul Killworth, deputy chief scientific adviser for national security at GCHQ, said the launch of the centre could foster closer collaboration between the security service and cyber security sector. </p><p>"The opportunity offered by Golden Valley will lead to a sea-change in national-security relations between government, academia and industry," he said.</p><p>"The National Cyber Innovation Centre was described as &apos;a true international centre of innovation&apos; in the National Cyber Strategy, and the development will also be a key part of the transformation of the intelligence community’s science and technology effort," Killworth added. </p><p>“GCHQ already plays a prominent role in these sectors both locally and nationally and it looks forward to participating in this exciting development."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK and US pledge to punish cyber criminals at annual meeting ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/361598/uk-and-us-pledge-to-punish-cyber-criminals-at-annual-meeting</link>
                                                                            <description>
                            <![CDATA[ Intelligence and defence officials met at the annual forum to discuss approaches to cyber security for the years ahead ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sDFnvhqzfyZcNtWQvzyfER</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nDtCmjHmnhZpaxHRJWa3wc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 19 Nov 2021 10:00:32 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nDtCmjHmnhZpaxHRJWa3wc-1280-80.jpg">
                                                            <media:credit><![CDATA[Ministry of Defence]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An aerial shot of the GCHQ building]]></media:description>                                                            <media:text><![CDATA[An aerial shot of the GCHQ building]]></media:text>
                                <media:title type="plain"><![CDATA[An aerial shot of the GCHQ building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nDtCmjHmnhZpaxHRJWa3wc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Intelligence and defence chiefs in the UK and US have confirmed their intentions to "impose consequences" on shared enemies in the world of cyber space.</p><p>Meeting at the Cyber Management Review in Maryland earlier this month, the two nations also pledged to continue to jointly innovate to tackle evolving threats in the <a href="https://www.itpro.com/security/28196/the-cybersecurity-skills-your-business-needs" data-original-url="https://www.itpro.com/security/28196/the-cybersecurity-skills-your-business-needs">cyber security</a> landscape.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/careers-training/361587/dhs-cyber-security-hiring-initiative" data-original-url="/business-strategy/careers-training/361587/dhs-cyber-security-hiring-initiative">US gov initiative aims to attract 'world-class' cyber security talent</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/national-cyber-security-centre-ncsc/361570/ncsc-covid-19-vaccines-prime-target-hackers-2021" data-original-url="/security/national-cyber-security-centre-ncsc/361570/ncsc-covid-19-vaccines-prime-target-hackers-2021">NCSC: COVID-19 vaccines were prime target for hackers in 2021</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28170/what-is-cyber-warfare" data-original-url="/security/28170/what-is-cyber-warfare">What is cyber warfare?</a></p></div></div><p>It said cyber space is an increasingly contested space and continued threats from both <a href="https://www.itpro.com/security/hacking/360395/number-of-hacking-tools-increasing-as-cyber-criminals-become-more-organized" data-original-url="https://www.itpro.com/security/hacking/360395/number-of-hacking-tools-increasing-as-cyber-criminals-become-more-organized">sophisticated criminals</a> and <a href="https://www.itpro.com/security/34794/what-threat-do-nation-state-hackers-pose-to-businesses" data-original-url="https://www.itpro.com/security/34794/what-threat-do-nation-state-hackers-pose-to-businesses">hostile states</a> continue to impact both countries' people and ways of life.</p><p>Representatives from Government Communications Headquarters (GCHQ), the National Security Agency (NSA), and the US Cyber Command met at the annual forum which helps to shape the two countries' intelligence relationship and helps drive "world-class cyber capabilities," GCHQ said.</p><p>"As like-minded allies for two centuries, the United Kingdom and the United States share a close and enduring relationship," read a joint statement issued by the intelligence and defence chiefs. "Our two nations today face strategic threats in an interconnected, digital world that seek to undermine our shared principles, norms, and values. </p><p>“We agree that strategic engagement in cyber space is crucial to defending our way of life, by addressing these evolving threats with a full range of capabilities. To carry this out, we will continue to adapt, innovate, partner, and succeed against evolving threats in cyber space," it added.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="QDksvAYJFwkcCugTbPvwS9" name="QDksvAYJFwkcCugTbPvwS9.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/QDksvAYJFwkcCugTbPvwS9.png" mos="https://cdn.mos.cms.futurecdn.net/QDksvAYJFwkcCugTbPvwS9.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Protecting every edge to make hackers’ jobs harder, not yours</strong></p><p class="fancy-box__body-text">How to support and secure hybrid architectures</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/firewalls/361592/protecting-every-edge-to-make-hackers-jobs-harder-not-yours" data-original-url="/security/firewalls/361592/protecting-every-edge-to-make-hackers-jobs-harder-not-yours">FREE DOWNLOAD</a></p></div></div><p>The two nations didn't identify specifically any common threat actors but said proportionate action would be taken to stop anyone or any group committing <a href="https://www.itpro.com/security/national-cyber-security-centre-ncsc/361570/ncsc-covid-19-vaccines-prime-target-hackers-2021" data-original-url="https://www.itpro.com/security/national-cyber-security-centre-ncsc/361570/ncsc-covid-19-vaccines-prime-target-hackers-2021">malicious cyber activity</a>.</p><p>Any action would be "legal, proportionate, and necessary," the two countries said.</p><p>"As democratic cyber nations, the UK and US are committed to doing so in a responsible way in line with international law and norms, setting the example for responsible state behaviour in cyberspace,” the officials added.</p><p>The meeting earlier this month was the first time the UK and US had met at the Cyber Management Review in 2 years.</p><p>In attendance were Jeremy Fleming, Director at GCHQ, and General Sir Patrick Sanders, commander of UK Strategic Command, for the UK. General Paul Nakasone, director of the US National Security Agency and Commander of US Cyber Command represented the US.</p><p>The Cyber Management Review is supported by work carried out at multiple levels of the intelligence and defence organisations involved, providing guidance for future military and intelligence efforts specific to <a href="https://www.itpro.com/security/28170/what-is-cyber-warfare" data-original-url="https://www.itpro.com/security/28170/what-is-cyber-warfare">cyber space</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GCHQ opens up about concealing cyber threats from global community ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/32470/gchq-opens-up-about-concealing-cyber-threats-from-global-community</link>
                                                                            <description>
                            <![CDATA[ In a series of publications from GCHQ and the NCSC, security directors explain why and how it keeps security threats a secret ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tCfey63tdUbyAReTdX1ton</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/seSgxMPjXMmtiA6bH8j66e-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 30 Nov 2018 10:51:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/seSgxMPjXMmtiA6bH8j66e-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Aerial view of the GCHQ building]]></media:description>                                                            <media:text><![CDATA[Aerial view of the GCHQ building]]></media:text>
                                <media:title type="plain"><![CDATA[Aerial view of the GCHQ building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/seSgxMPjXMmtiA6bH8j66e-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>GCHQ and NCSC have revealed that when they encounter vulnerabilities in its tech, including the technology that other government departments and some businesses use, they don't always inform the vendor.</p><p>In an impressive display in transparency, the two national security agencies said that during daily operations, analysts working at GCHQ or other areas of government sometimes encounter vulnerabilities and while its default stance on the situation is to notify the vendor as soon as practicable, "sometimes - after weighing up the implications - we decide to keep the fact of the vulnerability secret and develop intelligence capabilities with it".</p><p>Stockpiling exploits doesn't have a strong history. Most recently, the <a href="https://www.itpro.com/wannacry/32103/wannacry-cost-the-nhs-92-million-report-estimates" target="_blank" data-original-url="https://www.itpro.com/wannacry/32103/wannacry-cost-the-nhs-92-million-report-estimates">WannaCry</a> ransomware, which cost the NHS an estimated 92 million, was so successful as a result of stolen exploit information from the NSA. While the NCSC understands that its process might not be met with everyone's approval, the logic is sound.</p><p>"We've tried to make the description of the process as simple as possible to show the important characteristics," said Ian Levy, Technical Director at the NCSC in a <a href="https://www.ncsc.gov.uk/blog-post/equities-process" target="_blank">blog post</a>.</p><p>"We say our default position is to disclose the problem and there has to be a very good reason not to - either an overriding intelligence case or the fact that disclosing could reduce the security of people who use the product - and we really do mean it."</p><p>Levy says that the decision not to disclose a tech vulnerability that could leave businesses open to attack is not an easy one, but a necessary one. To make the difficult decision, it has a codified process called the 'Equity Process'.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/32135/global-cyber-security-skills-gap-widens-to-three-million" data-original-url="/security/32135/global-cyber-security-skills-gap-widens-to-three-million">Global cyber security skills gap widens to three million</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/careers/28212/a-guide-to-cyber-security-certification-and-training" data-original-url="/careers/28212/a-guide-to-cyber-security-certification-and-training">A guide to cyber security certification and training</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28196/the-cybersecurity-skills-your-business-needs" data-original-url="/security/28196/the-cybersecurity-skills-your-business-needs">The cyber security skills your business needs</a></p></div></div><h3 class="article-body__section" id="section-the-equity-process"><span>The Equity Process</span></h3><p>There are three separate bodies by which decisions must have approval before they are made. The Equities Technical Panel (ETP), The GCHQ Equity Board (EB) and The Equities Oversight Committee all consist of industry experts and NCSC representatives are involved at all stages. All decisions are reviewed within twelve months and sooner if new evidence is acquired. The decision pathway is illustrated below.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="t4fz6DLHeh8SqaX4tcgBKN" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/t4fz6DLHeh8SqaX4tcgBKN.jpg" mos="https://cdn.mos.cms.futurecdn.net/t4fz6DLHeh8SqaX4tcgBKN.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>A set of decision criteria are used and the decision on whether to retain or release known vulnerabilities must be considered on the basis of: </p><p><strong>1)</strong> Exploring routes to mitigate the vulnerability, would the release of it be at the detriment of national security?</p><p><strong>2)</strong> Consideration of value to intelligence, is it worth keeping a secret?</p><p><strong>3)</strong> Consideration of the potential risk to the UK and its allies in not releasing it</p><p>Essentially, decisions are made on the balance of potential damage. If the NCSC believes that knowledge of the vulnerability could be used to the UK's advantage, then it's retained, if not, then it's released.</p><p>"Some people will say that we don't need this process and that we should just disclose everything. In my opinion, that's nave - and I don't think it's got much to do with the NCSC being part of GCHQ and the wider UK intelligence community," Levy said.</p><p>"If we were separate, the rest of the community would still do vulnerability research and we would be much less likely to see those vulnerabilities and have a voice in how they're handled, so the UK would likely be at a greater security risk. But the NCSC is integral to the process and our job is to minimize the harm that cyber attacks can cause to the UK, and to also make the UK the safest place to live and do business online."</p><h3 class="article-body__section" id="section-benefits-of-non-disclosure"><span>Benefits of non-disclosure</span></h3><p>While it understands that businesses, hospitals, government departments and private citizens could be left vulnerable to attacks as a result of its silence, <a href="https://www.gchq.gov.uk/features/equities-process" target="_blank">GCHQ</a> ensures that the same vulnerabilities could be used to gain actionable intelligence. This means terrorist groups and child exploitation rings could be discovered and neutralised.</p><p>In the age where <a href="https://www.itpro.com/security/28170/what-is-cyber-warfare" target="_blank" data-original-url="https://www.itpro.com/security/28170/what-is-cyber-warfare">cyber intelligence</a> is the deciding difference between having a bomb detonate in a school and the arrest of the bomber, there's an argument that it's paramount trust is placed in UK security services.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GCHQ has "over-achieved" at developing state hacking tools ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/30188/gchq-has-over-achieved-at-developing-state-hacking-tools</link>
                                                                            <description>
                            <![CDATA[ The organisation has developed double the offensive cyber attacks than that of criminals ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7uLbAcdEwgPVfDDFMvG8UL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nDtCmjHmnhZpaxHRJWa3wc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 21 Dec 2017 08:59:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nDtCmjHmnhZpaxHRJWa3wc-1280-80.jpg">
                                                            <media:credit><![CDATA[Ministry of Defence]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An aerial shot of the GCHQ building]]></media:description>                                                            <media:text><![CDATA[An aerial shot of the GCHQ building]]></media:text>
                                <media:title type="plain"><![CDATA[An aerial shot of the GCHQ building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nDtCmjHmnhZpaxHRJWa3wc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A report by the Intelligence and Security Committee said GCHQ spies have "over-achieved" in the last 12 months, developing twice as many potential hacks than its targets.</p><p>The GCHQ is developing these hacking capabilities to use against criminals when they launch cyber crimes. It means the UK government is prepared to attack another country's vital infrastructure, such as their communications systems or automated weapons.</p><p>There are three stages to the GCHQ's mission, the first of which has been completed ahead of schedule according to the Intelligence and Security Committee report.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/27419/gchq-mi5-and-mi6-unlawfully-collected-data-for-over-a-decade" data-original-url="/data-protection/27419/gchq-mi5-and-mi6-unlawfully-collected-data-for-over-a-decade">GCHQ, MI5 and MI6 "unlawfully" collected data for over a decade</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/government-it-strategy/27945/gchq-to-make-spies-of-tech-savvy-teenage-girls" data-original-url="/government-it-strategy/27945/gchq-to-make-spies-of-tech-savvy-teenage-girls">GCHQ to make spies of tech-savvy teenage girls</a></p></div></div><p>"We actually over-achieved and delivered [almost double the number of] capabilities [we were aiming for]," an official from the agency told the Committee (via the <em><a href="http://www.bbc.co.uk/news/technology-42425960">BBC</a></em>).</p><p>Although much of the information has been omitted from the public version of the Committee's report, it did reveal that not all attempts to create offensive cyber-weapons were successful. For example, the Foxtrot project was designed to combat encryption, with the project described as an "equipment interference programme to increase GCHQ's ability to operate in an environment of ubiquitous encryption".</p><p>However, a lack of skills in the specific area means it hasn't been able to complete the work and needs to find better resources to help it finish the project.</p><p>Also highlighted was Project Golf, which focuses on supercomputing and enhancing the government's data analysis to help combat threats, but its development has been halted until next year.</p><p>Similarly, the MI5's Alfa project, which has been designed to manage the organisation's information, has been delayed and "significant risks" are stopping it from being completed.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Canada's spy agency releases its own anti-malware tool to the public ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/29770/canadas-spy-agency-releases-its-own-anti-malware-tool-to-the-public</link>
                                                                            <description>
                            <![CDATA[ The CSE says its scalability makes it an ideal fit for enterprise applications ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5cbHE1H18LMPyn98Lrxo2v</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WnSsR7AE2r2NRM6srdT94g-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 20 Oct 2017 10:24:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dale Walker ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/YhUVp3rWtcZPM5XznPeTmX.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WnSsR7AE2r2NRM6srdT94g-1280-80.jpg">
                                                            <media:credit><![CDATA[Bigstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Canadian flag with binary code on it]]></media:description>                                                            <media:text><![CDATA[Canadian flag with binary code on it]]></media:text>
                                <media:title type="plain"><![CDATA[Canadian flag with binary code on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WnSsR7AE2r2NRM6srdT94g-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Canada's cyber defence agency has made the source code for its internal malware prevention tool publicly available to help in the fight against online threats.</p><p>The <a href="https://www.cse-cst.gc.ca/en/assemblyline" target="_blank">Communications Security Establishment</a>, which is essentially Canada's equivalent to GCHQ in the UK, has released its "Assemblyline" tool as "an opportunity for the cyber security community to take what CSE has developed and build upon it to benefit all Canadians".</p><p>The tool is described as a highly configurable early warning system that is able to alert agents to malicious files when they are received.</p><p>An example given by the CSE describes how a financial officer may receive an email from an external sender that includes a password-protected zip file containing a word document and spreadsheet. This email may then be passed on to three colleagues within the department.</p><p>"Assemblyline will start by examining the initial email," the CSE explained in a statement. "It automatically recognizes the various file formats and triggers the analysis of each file. In this example, the Word document contains embedded malware, although the financial officer is unaware of this. The whole file is given a score when the analysis of each file is complete."</p><p>High scores will trigger alerts to a security analyst, who would then manually examine a file and disarm the malware to prevent it spreading further.</p><p>The main benefit of the system is its scalability, according to the CSE, as the tool is able to automatically rebalance workloads depending on the volume of data, making it an ideal catch-all solution for enterprises.</p><p>"Assemblyline was built using public domain and open-source software; however the majority of the code was developed by CSE," the statement added. "It does not contain any commercial technology, but it is easily integrated into existing cyber defence technologies. As open-source software, businesses can modify Assemblyline to suit their requirements."</p><p>The complete program is available on <a href="https://bitbucket.org/cse-assemblyline" target="_blank">bitbucket</a> to anyone who owns an account.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/government-it-strategy/25752/gchq-releases-open-source-analysis-tools-on-github" data-original-url="/government-it-strategy/25752/gchq-releases-open-source-analysis-tools-on-github">GCHQ releases open source analysis tools on Github</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29322/if-youre-surprised-the-nsa-can-hack-your-computer-you-need-a-reality-check" data-original-url="/security/29322/if-youre-surprised-the-nsa-can-hack-your-computer-you-need-a-reality-check">If you're surprised the NSA can hack your computer, you need a reality check</a></p></div></div><p>It's relatively uncommon for a national security agency to willingly share its tools with the world. The UK's GCHQ released the source code for its graph database program <a href="https://www.itpro.com/government-it-strategy/25752/gchq-releases-open-source-analysis-tools-on-github" target="_blank" data-original-url="https://www.itpro.com/government-it-strategy/25752/gchq-releases-open-source-analysis-tools-on-github">Gaffer</a> in 2015, which is able to sift through vast amounts of data and analyse information to determine patterns.</p><p>At the time GCHQ promised further contributions to the open source community, but has yet to release any more of its toys to the public.</p><p>The National Security Agency in the US also has 32 projects running on GitHub, although these are mostly outdated programs, or specialist tools such as a GPS tracker, and are fairly useless as business tools. For the NSA's most high profile projects, you'll need to turn to the <a href="https://www.itpro.com/security/27273/cisco-customers-targeted-using-leaked-nsa-hacking-tools" target="_blank" data-original-url="https://www.itpro.com/security/27273/cisco-customers-targeted-using-leaked-nsa-hacking-tools">Shadow Brokers</a>. </p><p><em>Image: Bigstock</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The Queen formally opens National Cyber Security Centre ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/28121/the-queen-formally-opens-national-cyber-security-centre</link>
                                                                            <description>
                            <![CDATA[ UK cyber chief talks tough in the face of hacker threats ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fzmMUBCL9owJXDgYvovtbj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jpMiuQLHHoxgan6q6eJeDg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Feb 2017 14:56:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jpMiuQLHHoxgan6q6eJeDg-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A padlock on a motherboard surrounded by keys]]></media:description>                                                            <media:text><![CDATA[A padlock on a motherboard surrounded by keys]]></media:text>
                                <media:title type="plain"><![CDATA[A padlock on a motherboard surrounded by keys]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jpMiuQLHHoxgan6q6eJeDg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Britain's new National Cyber Security Centre, a new institution tasked with defending the country against cyber attacks, was officially opened today by Queen Elizabeth II.</p><p>The new division, which is part of GCHQ, officially replaces various other government agencies that had cybersecurity roles, including the CCA, CESG, CERT UK and more.</p><p>It will be responsible for advising businesses and public bodies on infosec issues, as well as undertaking security research and handling incident response for major security breaches.</p><p>Speaking at the opening ceremony, NCSC chief Ciaran Martin was bullish about the future of cybersecurity in the UK, saying that he aims to make it "the best place to live and work online".</p><p>"Today, London becomes a key global player in the fight against the world's biggest and fastest growing threat," he said, "and it is the perfect location for the National Cyber Security Centre. It is the perfect place to coordinate our cybersecurity and manage incidents across the UK."</p><p>He also highlighted the importance of education and training among young people, presenting a gender-balanced roster of some of the first beneficiaries of the NCSC's youth outreach programmes.</p><p>However, Martin also said cyber attacks are "a fact of modern life" for a prosperous country like the UK.</p><p>His comments follow on from a statement he made yesterday, in which he warned of the dangers posed by state-sponsored Russian hackers and said that he expects a <a href="https://www.itpro.com/security/28111/uk-hit-by-almost-200-russian-cyber-attacks-in-three-months" target="_blank" data-original-url="https://www.itpro.com/security/28111/uk-hit-by-almost-200-russian-cyber-attacks-in-three-months">"category one" cyber attack</a> to hit the UK at some point in the future. </p><p>Martin was frank about the potentially rocky start the institute will face, too. "It's ambitious. We will make mistakes. Initiatives will disappoint. Things will go wrong. Bear with us, because we'll make it work for the whole country."</p><p>Philip Hammond MP, Chancellor of the Exchequer, said the digital sector is worth 118 billion to the UK economy, adding: "This cutting-edge centre will cement our position as world leader in cyber security and work carried out here will ensure our country remains resilient to potential attacks.</p><p>"Britain is transforming its capabilities in cyber defence and deterrence. It's crucial we take action now to defend ourselves and protect our economy."</p><p><strong>Private sector welcomes NCSC</strong></p><p>The private sector has responded favourably to the NCSC's opening, praising the government's commitment to strengthening the country's infosec position. "Whilst the UK has not suffered from a tier one cyber threat, the growing level of sustained cyber attacks on UK businesses means we must not be complacent," said techUK's head of programme for cyber and national security, Tala Rajab.</p><p>"The NCSC, with the help of the private sector, must work to make the UK the hardest possible target for cyber criminals and help protect our growing digital economy. In order for the NCSC to do this, it must be accessible by both businesses and the general public, protecting a far wider range of sectors beyond just Critical National Infrastructure."</p><p>Rajab added: "Recently announced policy initiatives, such as the trialling of proactive cyber defence services on government departments before recommending them to businesses, are to be applauded and techUK looks forward to working with the NCSC to help it achieve its target of making the UK the safest place in the world to live and work online."</p><p>Kaspersky Lab's principal security researcher, David Emm, was particularly pleased with the NCSC's engagement with young people, saying: "Our dependence on technology and the ever-growing online security threat go hand-in-hand, so it's crucial that we start raising awareness and equipping children with cybersecurity skills as early as possible. It is crucial that, once taught cybersecurity skills, young people use these skills for the good of society instead of turning to cybercrime." </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28111/uk-hit-by-almost-200-russian-cyber-attacks-in-three-months" data-original-url="/security/28111/uk-hit-by-almost-200-russian-cyber-attacks-in-three-months">UK hit 'by almost 200 Russian cyber attacks' in three months</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/27729/are-we-ready-for-cyber-war" data-original-url="/security/27729/are-we-ready-for-cyber-war">Are we ready for cyber war?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/27335/government-takes-fight-to-hackers-with-national-cyber-security-centre" data-original-url="/security/27335/government-takes-fight-to-hackers-with-national-cyber-security-centre">Government takes fight to hackers with National Cyber Security Centre</a></p></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK hit 'by almost 200 Russian cyber attacks' in three months ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/28111/uk-hit-by-almost-200-russian-cyber-attacks-in-three-months</link>
                                                                            <description>
                            <![CDATA[ Cybersecurity chief: Britain could soon be hit by a "category one" attack ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6yeqt92xaf6U2bTiJLWYbG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/TP8wPiU4TUYp7pMGbngKdE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 13 Feb 2017 11:02:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/TP8wPiU4TUYp7pMGbngKdE-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacking Hacker Security]]></media:description>                                                            <media:text><![CDATA[Hacking Hacker Security]]></media:text>
                                <media:title type="plain"><![CDATA[Hacking Hacker Security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/TP8wPiU4TUYp7pMGbngKdE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Britain is under attack from Russian hackers attempting to steal classified government data, the country's top cybersecurity chief has warned in an interview with <a href="http://www.thetimes.co.uk/article/russia-steps-up-cyber-attacks-on-uk-rl262pnlb" target="_blank"><em>the Sunday Times</em></a>.</p><p>Over the past three months, the UK has been hit by 188 serious cyber attacks, averaging out at more than 60 per month, according to the National Cyber Security Centre (NCSC), the new GCHQ division set up to strengthen the UK's defences against cyber attacks. The department is set to be officially opened by the Queen on Tuesday.</p><p>NCSC head Ciaran Martin told <em>the Sunday Times</em> that Putin's government has been stepping up its attacks against Western nations like the US and the UK.</p><p>"Over the last two years there has been a step change in Russian aggression in cyber-space," he said. "Part of that step change has been a series of attacks on political institutions, political parties, parliamentary organisations and that's all very well evidenced by our international partners and widely accepted."</p><p>Martin classified the attacks on the UK as "category two and three" and said that many of them "threatened national security".</p><p>"In the case of government departments, [the aim is] getting into the system to extract information on UK government policy on anything from energy to diplomacy to information on a particular sector. With companies, it could be to steal intellectual property and sometimes you would get states in that business," he said.</p><p>Britain has yet to experience a 'category one' cyber attack, which would be comparable <a href="https://www.itpro.com/security/24760/opm-refusing-to-co-operate-with-government-data-breach-enquiry" target="_blank" data-original-url="https://www.itpro.com/security/24760/opm-refusing-to-co-operate-with-government-data-breach-enquiry">to the hack of the US Office of Personnel Management in 2015</a>, an incident which resulted in the theft of 25 million federal employees' personal and biometric details.</p><p>However, Martin said that he expects "there will be a category one incident at some point in the future," citing the fact that "most of our major allies in similar countries have experienced what I would call a category one attack" and that "the intent and capabilities are there to deploy the sort of attack against similar and allied partner countries".</p><p>The US election was plagued with accusations of Russian hacking, with US security agencies and former President Barack Obama accusing the country of <a href="https://www.itpro.com/hacking/26988/us-officially-accuses-russia-of-leaking-dnc-emails" target="_blank" data-original-url="https://www.itpro.com/hacking/26988/us-officially-accuses-russia-of-leaking-dnc-emails">hacking emails belonging to the Democratic National Committee</a>, with President Donald Trump eventually suggesting the country <a href="https://www.itpro.com/hacking/27766/donald-trump-russia-was-likely-behind-dnc-hack" target="_blank" data-original-url="https://www.itpro.com/hacking/27766/donald-trump-russia-was-likely-behind-dnc-hack">was likely behind these breaches</a>.</p><p>However, Martin is confident about Britain's prospects of repelling such attacks. "We've got some very capable adversaries, but we've done a good job in detecting and managing those sorts of attacks," he said.</p><p>"We have very good capabilities where we watch the main actors that we know about very closely and we look at where they're attacking and we work very closely with key government departments and the parliamentary network to protect their systems."</p><p>"We can't eliminate the threat, but defeatism drives me mad," he added. "We shouldn't be defeatist about this; there's plenty we can do to strengthen defences at all levels."</p><p>The government <a href="https://www.itpro.com/government-it-strategy/28096/gds-prioritises-data-and-digital-skills-in-new-strategy" target="_blank" data-original-url="https://www.itpro.com/government-it-strategy/28096/gds-prioritises-data-and-digital-skills-in-new-strategy">outlined its Government Transformation Strategy last week</a>, citing the increasing range of cyber threats as a motivating factor to improving Whitehall's digital skills.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/27766/donald-trump-russia-was-likely-behind-dnc-hack" data-original-url="/hacking/27766/donald-trump-russia-was-likely-behind-dnc-hack">Donald Trump: Russia was likely behind DNC hack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/26988/us-officially-accuses-russia-of-leaking-dnc-emails" data-original-url="/hacking/26988/us-officially-accuses-russia-of-leaking-dnc-emails">US officially accuses Russia of leaking DNC emails</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/28110/what-to-expect-from-rsa-conference-2017" data-original-url="/security/28110/what-to-expect-from-rsa-conference-2017">What to expect from RSA Conference 2017</a></p></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GCHQ to make spies of tech-savvy teenage girls ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/government-it-strategy/27945/gchq-to-make-spies-of-tech-savvy-teenage-girls</link>
                                                                            <description>
                            <![CDATA[ Competition will pit teams of girls against each other to test their security skills ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bDCtbaiX8Q1nLEfnzEcLXX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nDtCmjHmnhZpaxHRJWa3wc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 19 Jan 2017 16:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Public Sector]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dale Walker ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/YhUVp3rWtcZPM5XznPeTmX.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nDtCmjHmnhZpaxHRJWa3wc-1280-80.jpg">
                                                            <media:credit><![CDATA[Ministry of Defence]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An aerial shot of the GCHQ building]]></media:description>                                                            <media:text><![CDATA[An aerial shot of the GCHQ building]]></media:text>
                                <media:title type="plain"><![CDATA[An aerial shot of the GCHQ building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nDtCmjHmnhZpaxHRJWa3wc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Teenage girls across the UK are being invited to test their hacking skills in a cybersecurity competition, in a bid to raise interest and increase the number of women joining security agencies.</p><p>The <a href="https://www.ncsc.gov.uk/news/national-challenge-will-develop-schoolgirls-cyber-security-skills" target="_blank">CyberFirst Girls</a> competition, hosted by GCHQ's newly formed <a href="https://www.itpro.com/security/27335/government-takes-fight-to-hackers-with-national-cyber-security-centre" target="_blank" data-original-url="https://www.itpro.com/security/27335/government-takes-fight-to-hackers-with-national-cyber-security-centre">National Cyber Security Centre (NCSC)</a>, will pit young security enthusiasts against each other in a series of challenges designed to test cyber skills that are sorely needed across all industries.</p><p>Girls aged 13-15 will be able to enter the competition in teams of four to engage in preliminary online challenges, with the possibility of advancing to the national final held in London in March. This initial stage will last one-week, between 27 February and 6 March, and consist of puzzles in four categories: Logic and coding, networking, cyber security and cryptography. </p><p>The top ten teams will then compete against each other in a series of tasks that challenge participants to investigate suspicious cyber activity and identify the source of the threats.</p><p>"I work alongside some truly brilliant women who help protect the UK from all manner of online threats," said GCHQ director Robert Hannigan. "The CyberFirst Girls competition allows teams of young women a glimpse of this exciting world and provides a great opportunity to use new skills."</p><p>The pupils from the winning team will each take home individual prizes, and their school's IT department will receive 1,000 worth of new equipment.</p><p>Teachers from all subjects are encouraged to enter, as there are no knowledge or computer skill requirements for pupils, and a single school may enter multiple teams.</p><p>The competition forms part of the new National Cyber Security Strategy unveiled in November 2016, which aims to address the cyber skills gap - a problem that has seen women massively underrepresented in the industry. Globally women make up only 10% of the entire cyber workforce, and in the UK the number of women employed in computer services accounts for just <a href="https://www.itpro.com/strategy/27929/why-women-must-fill-growing-tech-skills-gap" target="_blank" data-original-url="https://www.itpro.com/strategy/27929/why-women-must-fill-growing-tech-skills-gap">16%</a>.</p><p>CyberFirst will also be launching a series of free activity days and courses in February 2017, for pupils in Year 8 through Year 13, which will give students the possibility of applying for a CyberFirst Student Bursary of 4,000 per year for undergraduate study.</p><p>Teachers can now <a href="https://www.ncsc.gov.uk/events/cyberfirst-girls-competition" target="_blank">pre-register</a> their interest at the NCSC website, where they will receive an information and Q&A pack. Once registered, teams will then be invited to register fully for the competition from 13 February.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/strategy/27902/aws-restart-to-teach-digital-skills-to-young-people-and-military-veterans" data-original-url="/strategy/27902/aws-restart-to-teach-digital-skills-to-young-people-and-military-veterans">AWS re:Start to teach digital skills to young people and military veterans</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/data-protection/27419/gchq-mi5-and-mi6-unlawfully-collected-data-for-over-a-decade" data-original-url="/data-protection/27419/gchq-mi5-and-mi6-unlawfully-collected-data-for-over-a-decade">GCHQ, MI5 and MI6 "unlawfully" collected data for over a decade</a></p></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Top GCHQ director calls security industry "witchcraft" ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/27502/top-gchq-director-calls-security-industry-witchcraft</link>
                                                                            <description>
                            <![CDATA[ Dr Ian Levy accuses the industry of creating a climate of fear ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9T7tEt3XNMrXF5SNtaPf5D</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LonnfLS3dormnc6GCZ9LXG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 01 Nov 2016 14:50:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/LonnfLS3dormnc6GCZ9LXG-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LonnfLS3dormnc6GCZ9LXG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The National Cyber Security Center's technical director Ian Levy has slammed commonly-accepted cyber security advice, equating the security industry to "witchcraft" and accusing it of deliberately creating unnecessary fear around cyber threats.</p><p>Speaking at Future Decoded 2016, Microsoft's annual digital transformation conference, Levy argued that cyber security is not transparent and that the industry is "blaming the user for designing the system wrong".</p><p>"We have to make [security] much more user-centric - stop blaming the user, give them information, let them make decisions," he said.</p><p>He also argued that traditional security wisdom regarding email attachments and passwords is too complex and difficult for users to follow. According to his team's research, maintaining secure, regularly changed passwords for the average number of online sites and services equates to memorising a different 660-digit number every month.</p><p>Another target of his ire was the level of hyperbole surrounding the security industry. He took particular issue with the portrayal of hackers, which are commonly labelled 'advanced persistent threats', or APTs.</p><p>Instead, he argued that it should stand for 'adequate pernicious toerags', based on the fact that many attackers use older exploits and vulnerabilities with patches that are available, but not installed. By presenting hackers as super-skilled experts, however, he states that security companies are creating a climate of fear.</p><p>"Everything that we do as an industry is about making it sound really, really bad; because then you can't possibly defend yourself," he told attendees. "There's no other part of public policy that I'm aware of that allows this to happen. Nowhere else in public policy do you allow fear to rule."</p><p>The sentiment clashed somewhat with a statement from chancellor Phillip Hammond, who stated that the UK needed to develop offensive cyber weapons in order to prepare the country for retaliation in case of a cyber attack from a foreign nation.</p><p>Levy argued for greater transparency within the secure industry, and the creation of a climate in which the UK can have an informed national conversation about the threats facing both private citizens and companies operating in Britain. To that end, the National Cyber Security Centre will be publishing information and documents through their website in order to inform the public.</p><p>"I want to get to a point where we have data, we have metrics, and we can start to explain to the public how we're defending the UK," he said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Government takes fight to hackers with National Cyber Security Centre ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/27335/government-takes-fight-to-hackers-with-national-cyber-security-centre</link>
                                                                            <description>
                            <![CDATA[ The scheme will coordinate response to cyber security threats using intel collated from the public and private sector ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">shLdqjyZ392FUdWeiCkq4Q</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7DXRAPmbzLmcKUsSQbkU2n-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 Oct 2016 07:39:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7DXRAPmbzLmcKUsSQbkU2n-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cyber Threat]]></media:description>                                                            <media:text><![CDATA[Cyber Threat]]></media:text>
                                <media:title type="plain"><![CDATA[Cyber Threat]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7DXRAPmbzLmcKUsSQbkU2n-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The government has announced its latest initiative to fight cyber crime in business - the National Cyber Security Centre (NCSC).</p><p>The scheme will see the public sector joining forces with private sector companies, sharing the information they have about cyber threats so a more unified approach to prevent hackers from breaking into their systems.</p><p>"The Centre will be the bridge between industry and government, simplifying the current complex structures, providing a unified source of advice and support, including on managing incidents," Matt Hancock, Minister for the Cabinet Office, explained. "It will be a single point of contact for the private and public sectors alike."</p><p>Ciaran Martin, who will head up the National Cyber Security Centre as CEO explained the facility will unify intelligence from CESG, the information security arm of GCHQ, the Centre for the Protection of National Infrastructure, CERT-UK and the Centre for Cyber Assessment, sharing knowledge and using it to identify and address vulnerabilities.</p><p>"Whilst retaining access to the world-leading capabilities, partnerships and people of the intelligence community, this new centre will have an open door' policy which will make it easier for businesses of all sizes to get the best support available for cyber issues," Ben Gummer, minister for the Cabinet Office and paymaster general, added.</p><p>The NCSC's first project will be working with the Bank of England to advise other companies in the financial sector about the impact of cyber crime on their business.</p><p>Another scheme will be to work with some of the biggest companies in the UK to set up a giant firewall, which will be used to filter malicious content and websites.</p><p>"Given the industrial-scale theft of intellectual property from our companies and universities, as well as the numerous phishing and malware scams that waste time and money, the NCSC shows that the UK is focusing its efforts to combat the threats that exist online," Robert Hannigan, director of GCHQ, added.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/611713/government-plans-national-cyber-security-centre" data-original-url="/611713/government-plans-national-cyber-security-centre">Government plans national cyber security centre</a></p></div></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ “High-profile” individuals targeted by UK security services ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/26999/high-profile-individuals-targeted-by-uk-security-services</link>
                                                                            <description>
                            <![CDATA[ Up to 20 people were spied upon by British intelligence ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hqRBQpr7mQmP6kMcFVN1v7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/w3LpY94RhY5XWRsHmBDKbH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 27 Jul 2016 15:34:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/w3LpY94RhY5XWRsHmBDKbH-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/w3LpY94RhY5XWRsHmBDKbH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Around 20 celebrities were spied on by British security services and these operations may not have been justified or warranted.</p><p>The disclosure came to light at an investigatory powers tribunal brought by campaigning organisation Privacy International.</p><p>According to a <a href="https://www.theguardian.com/world/2016/jul/27/mi5-and-gchq-spied-on-20-high-profile-people-in-questionable-operations?CMP=twt_gu">report</a> by <em>the Guardian</em>, government lawyers on behalf of GCHQ and MI5 showed that between 2009 and 2013, three searches into high-profile people were "not operationally justifiable."</p><p>Another 17 searches, carried out by five officers were said to be possibly not "operationally justifiable". The lawyers added that conversations with those officers were not recorded, meaning it is "not possible to ascertain whether they were in fact operationally justifiable".</p><p>The report said that these individuals were not notified of the surveillance and officers were warned that if they were caught misusing their powers they could face disciplinary action.</p><p>Government lawyers initially refused to release the figures on grounds of "damage to national security", but documents were released on the second day of the hearing following repeated request by Privacy International.</p><p>The intelligence officers have since been banned from using the security services' data to "search for and/or access information other than that which is necessary and proportionate for [their] current work".</p><p>Millie Graham Wood, legal officer at Privacy International, said the security services should have informed the celebrities involved they were being spied upon. She said it should be a serious concern that there is no procedure to notify victims.</p><p>"Without such a mechanism, and in the absence of independent or judicial authorisation, a victim of abuse has no prospect of ever securing a remedy."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Tribunal will not automatically listen to unlawful spying claims ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/public-sector/26550/tribunal-will-not-automatically-listen-to-unlawful-spying-claims</link>
                                                                            <description>
                            <![CDATA[ The 650 Investigatory Powers Tribunal claimants will need to provide further evidence they were wrongfully spied on ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gJVj8uJJE9MpKkfu7z1yoA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/imb7WFABdZ6a3RsWxX7LKR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 17 May 2016 07:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/imb7WFABdZ6a3RsWxX7LKR-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[spying]]></media:description>                                                            <media:text><![CDATA[spying]]></media:text>
                                <media:title type="plain"><![CDATA[spying]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/imb7WFABdZ6a3RsWxX7LKR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Investigatory Powers Tribunal has ruled that the 650 people who said they were wrongfully spied upon by British and American authorities will have to provide further evidence of surveillance before the government will listen to their claims.</p><p>If the claimants provide the evidence, the Tribunal will then decide whether the cases will be fully investigated or not. The Tribunal stressed that they will not automatically be looked into.</p><p>The complaints came forward after Privacy International campaigned for people who thought they had been unlawfully watched to state their concerns about GCHQ digging into their digital life without their permission last year.</p><p>Around 650 people responded and said they wanted the government to investigate into what information had been mined and why they had been selected for investigation.</p><p>"Given that these claims arise in the context of the bulk surveillance activities of the UK and US Governments, the Tribunal's requirement that claimants submit further information on why they think they would be spied on before deciding whether to fully investigate their claims is unacceptable," Scarlet Kim, legal officer at Privacy International said.</p><p>The Investigatory Powers Tribunal also stated that non-UK residents could not make a claim against the UK government for violating the European Convention on Human Rights, but Privacy International believes this is wrong and goes against the Convention, because the law states that anyone is protected, regardless of where they are located.</p><p>"The Tribunal's refusal to recognise the human rights claims of non-UK residents is ill-founded," Kim added. "When a member state to the European Convention on Human Rights commits a human rights violation on its own territory - whether by unlawfully suppressing free speech rights, expropriating property, or conducting surveillance - the victims are entitled to judicial relief no matter where they live."</p><p>"An essential feature of any true democratic society is that covert breaches of the law are disclosed to the victims. The Tribunal's decision is yet another example of the lack of genuine and rigorous public scrutiny of the British intelligence services," she concluded.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GCHQ joins Twitter in drive for openness ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/public-sector/26546/gchq-joins-twitter-in-drive-for-openness</link>
                                                                            <description>
                            <![CDATA[ Intelligence body is the first UK security agency to join social network ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">t1RZdJ2VzFe2ujEua7EA52</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nY8JTPANeySKpSdWpNyCge-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 16 May 2016 14:39:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Social Media]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Aaron Lee ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nY8JTPANeySKpSdWpNyCge-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nY8JTPANeySKpSdWpNyCge-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>UK government listening post GCHQ revealed today that its has <a href="https://twitter.com/GCHQ" target="_blank">joined Twitter</a>, with a view to becoming more transparent.</p><p>GCHQ is the first UK government intelligence agency to join the social network.</p><p>Andrew Pike, director of communications at GCHQ, <a href="https://www.gchq.gov.uk/news-article/hello-world-gchq-has-officially-joined-twitter" target="_blank">said in a statement</a>: "In joining social media GCHQ can use its own voice to talk directly about the important work we do in keeping Britain safe."</p><p>The agency added that it wanted to be "more accessible and to help the public understand more about our work".</p><p>Part of this will include reaching out to the technical community and adding its voice to social media conversations about technology, maths, cybersecurity and other topics, the agency said.</p><p>GCHQ's Twitter account <a href="https://twitter.com/GCHQ/status/732149091476639745" target="_blank">first tweeted</a> at 11:02 BST, and so far has more than 6,000 followers.</p><p>Social media has become an important arena for security agencies, who have used it to scour for developing threats and leads on parties they have taken an interest in. Services, such as Dataminr, which Twitter invests in, are also known to have <a href="https://www.itpro.com/security/26500/twitter-blocks-us-intelligence-agencies-from-dataminr-alerts" target="_blank" data-original-url="https://www.itpro.com/security/26500/twitter-blocks-us-intelligence-agencies-from-dataminr-alerts">provided security agencies will early alerts of terror attacks and other crises</a>.</p><p>Elsewhere in the world, other intelligence agencies have had Twitter accounts for several years. The <a href="https://twitter.com/FBI" target="_blank">FBI</a> has had a presence on the social network since November 2008, and the <a href="https://twitter.com/NSAGov" target="_blank">NSA</a> since December 2013.</p><p>GCHQ, however, has preferred a less talkative demeanour. Reports that the agency has allegedly been spying on all UK citizens, in the <a href="https://www.itpro.com/security/25349/gchq-snooped-on-every-single-internet-user" target="_blank" data-original-url="https://www.itpro.com/security/25349/gchq-snooped-on-every-single-internet-user">wake of the Edwad Snowden revelations</a>, had also fuelled fears that giving the intelligence agency further powers in the form of the <a href="https://www.itpro.com/public-sector/26269/home-office-faces-eu-court-battle-over-snooper-s-charter" target="_blank" data-original-url="https://www.itpro.com/public-sector/26269/home-office-faces-eu-court-battle-over-snooper-s-charter">Investigatory Powers Bill</a>, or Snooper's Charter could be a <a href="https://www.itpro.com/government-it-strategy/26182/gchq-boss-denies-snooper-s-charter-will-weaken-encryption" target="_blank" data-original-url="https://www.itpro.com/government-it-strategy/26182/gchq-boss-denies-snooper-s-charter-will-weaken-encryption">bad thing for privacy</a>.</p><p>The intelligence agency has made some efforts to make some its own technology available, though, such as making its <a href="https://www.itpro.com/government-it-strategy/25752/gchq-releases-open-source-analysis-tools-on-github" target="_blank" data-original-url="https://www.itpro.com/government-it-strategy/25752/gchq-releases-open-source-analysis-tools-on-github">database retrieval tool, Gaffer, to the data community</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GCHQ VoIP software can be used to eavesdrop ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/government-it-strategy/25907/gchq-voip-software-can-be-used-to-eavesdrop</link>
                                                                            <description>
                            <![CDATA[ The backdoor could allow agents, employers or third parties to listen in on conversations ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qF9ubsACvE1wmrJrTBJbBV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nzUxpj7jRvPYD8sdFZdMbk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 22 Jan 2016 08:26:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Smart City]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nzUxpj7jRvPYD8sdFZdMbk-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Snooping]]></media:description>                                                            <media:text><![CDATA[Snooping]]></media:text>
                                <media:title type="plain"><![CDATA[Snooping]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nzUxpj7jRvPYD8sdFZdMbk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The GCHQ has developed VoIP encryption tools with a built-in backdoor, allowing both authorities and third parties to listen in on conversations.</p><p>The backdoor is embedded into the MIKEY-SAKKE encryption protocol and has a 'key escrow' built in, allowing those with authority - whether an employer or government agency - to access it if a warrant or request is made.</p><p>The backdoor was uncovered by Dr Steven Murdoch, a security researcher from the University of London, who wrote a blog about the potential snooping tool.</p><p>He explained that MIKEY-SAKKE has a monopoly over other security protocols used by approved government voice communications, meaning almost all software used for communication is using the encryption, with the enbedded backdoor. GCHQ can also insists the technology is used in other products used by the public sector and companies "operating critical national infrastructure".</p><p>"Although the words are never used in the specification, MIKEY-SAKKE supports key escrow," Murdoch wrote. "That is, if the network provider is served with a warrant or is hacked into it is possible to recover responder private keys and so decrypt past calls without the legitimate communication partners being able to detect this happening."</p><p>He explained this is being marketed as a benefit to using MIKEY-SAKKE rather than a bug, with documentation issued by GCHQ advertising it means employers can listen into voice communications when investigating into misconduct trials.</p><p>"The Government should come to the realisation that the inclusion of backdoors in encryption isn't merely a legislative or privacy mandate, however, it is technically impossible to control the use of a backdoor in this way." Justin Harvey, chief security officer at Fidelis Cybersecurity said. </p><p>"I liken the pro-backdoor encryption movement to complaints about the weather; some people complain about rain, snow or sunshine and wish it were otherwise, but in the end, we can't do anything about it. The same is true for strong encryption."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GCHQ releases open source analysis tools on Github ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/government-it-strategy/25752/gchq-releases-open-source-analysis-tools-on-github</link>
                                                                            <description>
                            <![CDATA[ UK spy agency promises further contributions to open source community ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nt4oDHkTePmp9XChpL4DUd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LonnfLS3dormnc6GCZ9LXG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 17 Dec 2015 13:29:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Public Sector]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/LonnfLS3dormnc6GCZ9LXG-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LonnfLS3dormnc6GCZ9LXG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Government spy agency GCHQ has released one of its tools, Gaffer, on Github.</p><p>Gaffer is a graph database program which is "optimised for retrieving data on nodes of interest", and "makes it easy to store large-scale graphs in which the nodes and edges have statistics such as counts, histograms and sketches".</p><p>Essentially, it acts as Big Data analytics, sifting through huge volumes of information in order to determine patterns.</p><p>The software also lets the user "specify flexible views on the data", and "can be used for machine-learning applications".</p><p>The target audience for this code is likely to be those with intensive research and analysis needs, rather than more general users.</p><p>The software has been released for free under an open source Apache 2 license, meaning anyone is free to edit or use it.</p><p>Intelligence agencies releasing open source code is not unheard of - Gaffer itself is based on the Accumulo framework, which was released by the NSA under the same license in 2008.</p><p>Speculation is rife as to exactly why the repository has been released, but according to a spokesperson, "Gaffer is expected to be the first of many contributions that GCHQ will make to open source software".</p><p>"GCHQ hopes that Gaffer will be useful to others in the community, as well as helping its own technical staff as they continue to develop the software in the future," a GCHQ representative told <em>TechWeekEurope</em>.</p><p>"As a government department and technology organisation, GCHQ software developers and technologists aim to contribute to open source software projects."</p><p><em>Image credit: <a href="http://www.shutterstock.com/gallery-438445p1.html?cr=00&pl=edit-00">Stephen Clarke</a> / <a href="http://www.shutterstock.com/editorial?cr=00&pl=edit-00">Shutterstock.com</a></em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GCHQ can control your smartphone, Edward Snowden says ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/25398/gchq-can-control-your-smartphone-edward-snowden-says</link>
                                                                            <description>
                            <![CDATA[ The US whistleblower said GCHQ can track the location, power management and conversations using 'Smurf' tools ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5ShEdoQNATnHm2oSpzevbr</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dp3vwfsfpSJLQJES7D7iXe-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 07 Oct 2015 07:40:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Mobile Phones]]></category>
                                                    <category><![CDATA[Hardware]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dp3vwfsfpSJLQJES7D7iXe-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[&amp;quot;Privacy&amp;quot; written atop a circuit board]]></media:description>                                                            <media:text><![CDATA[&amp;quot;Privacy&amp;quot; written atop a circuit board]]></media:text>
                                <media:title type="plain"><![CDATA[&amp;quot;Privacy&amp;quot; written atop a circuit board]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dp3vwfsfpSJLQJES7D7iXe-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>US whistleblower Edward Snowden has revealed that UK intelligence agency GCHQ has the tools to hack into and control phones without the owners being aware they are being tracked.</p><p>He explained that authorities can implement tools - called Dreamy Smurf, Nosey Smurf, Paranoid Smurf and Tracker Smurf - by sending a smartphone an encrypted text message.</p><p>"Dreamy Smurf is the power management tool which means turning your phone on and off without you knowing," Snowden said."Nosey Smurf is the 'hot mic' tool. For example if it's in your pocket, [GCHQ] can turn the microphone on and listen to everything that's going on around you - even if your phone is switched off because they've got the other tools for turning it on."</p><p>He explained that Tracker Smurf is a geo-location tool that could potentially allow GCHQ to follow smartphone users better than using standard cellular location towers.</p><p>Paranoid Smurf is a self-protection tool that can be used to stop you getting rid of the other tools on a device. If you spot something strange is going on with your device and take it to a phone shop to fix the problem, for example, Paranoid Smurf would hide the evidence so technicians wouldn't find anything wrong.</p><p>Snowden spoke to the BBC's Panorama programme from his base in Russia, where he ran away to after leaking other snooping allegations about the GCHQ and US's National Security Agency (NSA).</p><p>The NSA also have a similar set of tools to use in the fight against terrorism, Snowden said. The US security organisation reportedly spent $1bn on the tools to respond to terrorists' increased use of smartphones.</p><p>Although he did not specifically say the GCHQ and NSA wanted to partake in mass surveillance, they have both invested in software that would allow them to hack into devices in order to track what you're saying, what you're doing and where you are.</p><p>"They want to own your phone instead of you," he said.</p><p>The UK government commented: "All of GCHQ's work is carried out in accordance with a strict legal and policy framework, which ensures that our activities are authorised, necessary and proportionate, and that there is rigorous oversight, including from the secretary of state, the interception and intelligence services commissioners and the Parliamentary Intelligence and Security Committee. All our operational processes rigorously support this position."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NSA and GCHQ have been spying on you for 50 years ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/25092/nsa-and-gchq-have-been-spying-on-you-for-50-years</link>
                                                                            <description>
                            <![CDATA[ Journalist reveals very first mass surveillance programme, Project Echelon ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gFLV1PgvD5BUfMshKcq839</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Z3HUmmqX7aoCAVcoySmdum-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 Aug 2015 10:33:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Joe Curtis ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Z3HUmmqX7aoCAVcoySmdum-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[NSA data]]></media:description>                                                            <media:text><![CDATA[NSA data]]></media:text>
                                <media:title type="plain"><![CDATA[NSA data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Z3HUmmqX7aoCAVcoySmdum-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A spy programme known as Project Echelon has been tapping into billions of phone calls a year for the last half-century, according to a campaigning journalist writing for <a href="https://firstlook.org/theintercept/2015/08/03/life-unmasking-british-eavesdroppers" target="_blank"><em>The Intercept</em></a>.</p><p>The scheme was jointly-run by US agency NSA and British agency GCHQ, and signalled the advent of mass surveillance by ushering in an age of "Big Brother"-style snooping, according to one source.</p><p>Starting in 1966, the project leapt into life when the NSA fronted the money for the GCHQ to build a station in Bude, Cornwall, capable of intercepting satellite communications from Intelsat, the first commercial communications satellite network.</p><p>Journalist Duncan Campbell and fellow reporter Jim Bamford located a second site in Yakima, America, that intercepted US-Asia communications.</p><p>Campbell wrote: "At the dawn of the era of mass surveillance, almost 50 years ago, the ECHELON stations at Bude and Yakima were the global mass surveillance system."</p><p>The Echelon system was automated, and able to sift through vast swathes of data from these satellites to sort and categorise it all.</p><p>Speaking to a former Lockheed (now Lockheed Martin) employee in the late 1980s who was responsible for managing NSA databases at a new site in California, Campbell learned how Echelon was spying on politicians, and his source also shared plans for the IT system underpinning the project.</p><p>He wrote: "The plans showed how ECHELON, also called Project P415, intercepted satellite connections, sorting phone calls, telex, telegraph and computer signals.</p><p>"Although the internet was then in early infancy, what was carried digitally was covered. The way ECHELON had been designed, she said, demonstrated the targeting of U.S. political figures was not an accident."</p><p>Campbell added that the scale of the operation had shocked him.</p><p>"The NSA and its partners had arranged for everything we communicated to be grabbed and potentially analyzed," he said. "ECHELON was at the heart of a massive, billion-dollar expansion of global electronic surveillance for the 21st century."</p><p>However, Campbell's expose of the spying programme in 1988 was ignored for 11 years, until the European Parliament commissioned an investigation in 1999.</p><p>Though the parliament mandated extensive action against mass surveillance in 2001, a few days later the Twin Towers were destroyed in the 9/11 terrorist attack.</p><p>"Any plans for limiting mass surveillance were buried with the victims of 9/11," wrote Campbell.</p><p>Since Edward Snowden's revelations about the NSA laid bare the extent of spying programmes against US and European citizens, public interest has spiked in privacy, and some of the documents leaked actually confirmed Campbell's reports.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GCHQ and NSA try to crack Kaspersky software and others ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/public-sector/24846/gchq-and-nsa-try-to-crack-kaspersky-software-and-others</link>
                                                                            <description>
                            <![CDATA[ Snowden files reveal reverse-engineering attempts on popular consumer anti-virus firms, as well as web forum surveillance ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mFrYoGvLDquVFaMceynYRr</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pRDu8iYQjogvCLxqPKuWbE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 23 Jun 2015 11:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Adam Shepherd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/3n2BoLAtRj8Z5eRfxtwyK8.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pRDu8iYQjogvCLxqPKuWbE-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Kaspersky sign on a white post]]></media:description>                                                            <media:text><![CDATA[Kaspersky sign on a white post]]></media:text>
                                <media:title type="plain"><![CDATA[Kaspersky sign on a white post]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pRDu8iYQjogvCLxqPKuWbE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>GCHQ and the NSA stand accused of reverse-engineering consumer anti-virus software in order to hide their operations, it has been revealed.</p><p>Hacking efforts by UK spy body GCHQ have been stymied in the past by security vendors such as Kaspersky Labs, according to <a href="https://www.documentcloud.org/documents/2106826-gchq-application-for-renewal-of-warrant-gpw-1160.html#document/p1" target="_blank">a warrant renewal request</a> published by The Intercept.</p><p>The warrant states that the Russian AV company in particular continues to "pose a challenge" to GCHQ, and that the agency's goal is to be able to "exploit such software and to prevent detection of [their] activities".</p><p>In order to circumvent this type of security, the agency examined various elements of it for vulnerabilities, using a technique known as Software Reverse Engineering.</p><p>As part of the "computer network exploitation" tactics covered by the warrant, GCHQ likewise examined popular forum software vBulletin, which the document claims is "widely used to run terrorist web forums".</p><p>It is also, however, used to run and maintain a huge majority of legitimate forums such as NEOGAF and SomethingAwful, and SRE methods have previously yielded the recovery of an unspecified number of user credentials.</p><p>As these SRE techniques could potentially constitute "an infringement of copyright", GCHQ requires a legally-protecting warrant from the government that must be renewed every six months.</p><p>It was one such renewal request, dated from 2008, that was published today as part of <a href="https://www.itpro.com/hacking/24814/bruce-schneier-russia-hacked-nsa-for-snowden-docs" target="_blank" data-original-url="https://www.itpro.com/hacking/24814/bruce-schneier-russia-hacked-nsa-for-snowden-docs">the Snowden files</a>. It is unclear whether this practise of reverse-engineering security software is still common, as well as what GCHQ hoped to achieve in the process.</p><p>The warrant also notes that the agency's success in reverse-engineering strategies have led to developing capabilities against Cisco routers. This allows UK spies entry into the Pakistan Internet Exchange, where they have "access to almost any user of the internet inside Pakistan".</p><p>The NSA has also been undertaking similar projects. In a briefing from 2010, also part of the Snowden files, the US spy agency's "Project CAMBERDADA" was revealed to be intercepting malware-flagging email traffic between end-users and anti-virus vendors.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="8fYaZzGGEmNDiU8we4i5FE" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/8fYaZzGGEmNDiU8we4i5FE.jpg" mos="https://cdn.mos.cms.futurecdn.net/8fYaZzGGEmNDiU8we4i5FE.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>This information is used to compile a list of malware that vendors like Kaspersky have not yet adapted to combat. The agency's Tailored Access Operation unit then "repurpose the malware", allowing them piggyback access to machines and networks.</p><p>Kaspersky has been a notable opponent of state-sponsored intrusion. The Russian company had a hand in detecting and flagging multiple examples of suspected government malware such as the Gauss, Flame and Stuxnet viruses.</p><p>Earlier this month, the company discovered that it had itself been hit by <a href="https://www.itpro.com/malware/24793/what-is-duqu-20" target="_blank" data-original-url="https://www.itpro.com/malware/24793/what-is-duqu-20">the Duqu 2.0 worm</a>, which founder Eugene Kaspersky believes to be a "nation-state sponsored campaign".</p><p>The company said in a statement that "we find it extremely worrying that government organizations are targeting security companies instead of focusing their resources against legitimate adversaries."</p><p>It decried the fact that government divisions are "actively working to subvert security software that is designed to keep us all safe."</p><p>Along with Kaspersky Labs, a total of 23 vendors were listed in the presentation on a slide jauntily titled "more targets!" These included Bit-Defender, Avast, Avira and Checkpoint, with examples from multiple US-allied countries although none from within the US itself, or the UK.</p><p>However, while this may come as a shock to some, others in the infosec community are less than astonished. Ben Johnson, Chief Security Strategist for Bit9 + Carbon Black, points out that "AV tools can be bought and pulled apart by anyone".</p><p>He notes the logic of GCHQ's operations, asking "is it really a surprise that intelligence agencies try to circumvent technologies that might prevent them from collecting information? Or test these technologies for weaknesses?" </p><p>He likens this probing of vendor proficiency to real-world combat tactics; "In the hacker world as well as the military world before conducting any operation it is vital to test offensive tools against defensive capabilities".</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Infosec 2015: Has GCHQ lost the cyber security plot? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/24830/infosec-2015-has-gchq-lost-the-cyber-security-plot</link>
                                                                            <description>
                            <![CDATA[ It's more about what GCHQ doesn't say about the Snooper's charter than what it does, according to Davy Winder ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mq63dwzFN9aJ1X912bEesq</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/uHCw3ayyduDRJoCmaGvCLa-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 04 Jun 2015 08:03:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Davey Winder ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/qKL6BZiS7oo9Hmyy2yd3WJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/uHCw3ayyduDRJoCmaGvCLa-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cyber spy]]></media:description>                                                            <media:text><![CDATA[Cyber spy]]></media:text>
                                <media:title type="plain"><![CDATA[Cyber spy]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/uHCw3ayyduDRJoCmaGvCLa-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Infosecurity 2015 has been a great place to be if you care about IT security either from the vendor or enterprise perspective. The biggest event of its type in Europe, you would have expected a big-hitter to open things and that's what you got in the shape of Ciaran Martin, Director General of Cyber Security at GCHQ.</p><p>Or at least that's what you might think you were getting, until the actual point that Martin started talking that is and you realised that what you actually got was a spin-doctor. The key theme of the <a href="https://www.itpro.com/security/24725/infosec-2015-power-money-and-propaganda-are-main-aims-of-cyberattacks-says-gchq-chief" data-original-url="https://www.itpro.com/security/24725/infosec-2015-power-money-and-propaganda-are-main-aims-of-cyberattacks-says-gchq-chief">keynote presentation</a> was how cyber attacks are driven by power, money and propaganda, and how apt that turned out to be seeing as Mr Martin used his position of power to push the government privacy argument position of you have nothing to fear from us'.</p><p>An odd mix of vendors going for the hard sell alongside technical workshops and roundtable discussions pretty much sums up Infosecurity. I attended one of those roundtable events an hour or so after the GCHQ presentation, which included our very own occasional contributor Tom Brewster asking whether vendors control the narrative when it comes to media reporting of IT security. You may not categorise GCHQ as a vendor, but I would argue that Mr Martin was certainly trying to sell a product; namely the ability to pry on our private communications wrapped up in the packaging of protecting us from evil.</p><p>Vendor-esque overtones or not, Mr Martin certainly attempted to control the narrative by not only stating from the get go that he wouldn't be talking about the so-called Snoopers' Charter but also ended things by only having time for one question from the floor. A question asking about <a href="https://www.itpro.com/it-legislation/24741/should-tech-firms-leave-the-uk-over-encryption-laws" data-original-url="https://www.itpro.com/it-legislation/24741/should-tech-firms-leave-the-uk-over-encryption-laws">tech firms leaving the UK over the likelihood of forced encryption back doors</a>, I hasten to add, that was answered by quoting someone else confirming that GCHQ was no threat to our privacy.</p><p>None of this should come as any great shock of course, what with Mr Martin previously having been the lead negotiator on the referendum for Scottish independence for the Prime Minister in his role as Constitution Director' at the Cabinet Office. Something of a career civil servant with roles as Head of the Cabinet Secretary's Office and Director of Security and Intelligence behind him, I wasn't that surprised when his speech ended up like something from Sir Humphrey out of Yes Minister.</p><p>Now it would be disingenuous of me to suggest that Mr Martin, given both that Director of Security role and his current one, knows nothing about IT security. Just like it would be disingenuous of the government to suggest there is no political motivation behind speeches such as this one.</p><p>A speech entitled Building Cyber Security for Tomorrow' with Sir Humphrey, sorry I mean Mr Martin, spelling out right from the start that he would be focusing his comments on who is attacking us and how, what defensive and response strategies are most effective to combat them and what the role of GCHQ is in all of this.</p><p>Needless to say we never really discovered the who or how, and the combat strategies were just a repeat of usual broad sweep basics of business IT security 101. He did, however, take some time to explain why he wouldn't be talking about the Snoopers' Charter, which he didn't mention by name.</p><p>Here's exactly what Mr Martin said:</p><p>"Our role only really works because we have a world class intelligence capability to draw on. If we want to protect the UK from the darkest aspects of cyber space, we have to be able to understand how that works. That intelligence role has been the source of well-known controversy around privacy.</p><p>"I won't and can't talk about that in any detail today. The Queen's speech set out a process for considering legislation on the proper powers for national security and law enforcement bodies and it is for Ministers to propose and for Parliament to debate. All I would say is that everyone in GCHQ is acutely conscious that we are entrusted with significant power under the law, and we use it extremely carefully.</p><p>"Just over a year ago, the Interception Commissioner, Sir Anthony May, who was formerly one of England's three most senior judges and had ruled against the intelligence services in the past, compiled a report on the various allegations. He had full access to the papers and staff of GCHQ. He asked the question: "does GCHQ engage in the random mass intrusion into the private lives of law-abiding citizens?" The answer was "emphatically no".</p><p>"To get back to cyber, one of the things that has almost flippantly been said in our defence is that even if we wanted to do such things we don't have enough people to engage in such unlawful mass intrusion. And size naturally affects our role on cyber. We're simply not big enough to put a big cyber umbrella over the UK: no single organisation could possibly do that over any country."</p><p>The clue is at the end of all of that, of course, in that the bill which the Home Secretary and Prime Minister want passed into law would mean that it's the Internet Service Providers which would be forced into both collecting and storing the vast amounts of data required to snoop on users, and then handing over the bits (no pun intended) to GCHQ that relate to specific users upon request.</p><p>Which puts quite a different perspective upon it. David Cameron has also made it quite clear that he wants encrypted messaging services banned, and/or back doors put into encryption services.</p><p>Quite how an ability to devalue the ability to encrypt data serves to help British business in the fight against cyber crime, which was the main thrust of the Martin presentation remember, is frankly beyond me. Just as all the themes of Intelligent Security' as set out by Infosecurity Europe appear to be beyond Mr Martin, GCHQ and this government. Those themes were Protect - Defend - Respond - Recover. Mr Martin certainly achieved the first two with his presentation, and when he responds properly we might be able to tell if GCHQ can recover...</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Infosec 2015: Power, money and propaganda are main aims of cyberattacks, says GCHQ chief ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/24725/infosec-2015-power-money-and-propaganda-are-main-aims-of-cyberattacks-says-gchq-chief</link>
                                                                            <description>
                            <![CDATA[ Spook avoids talk of Snooper’s Charter ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">24H66g3CWnfhxCNBafejHZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sJWnbsvGiDPgprexyUwQR3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 02 Jun 2015 15:31:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sJWnbsvGiDPgprexyUwQR3-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sJWnbsvGiDPgprexyUwQR3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>GCHQ's cyber security chief warned that the nation's businesses are at risk of being attacked by criminals and terrorists whose main motivations are money, power and propaganda.</p><p>Giving a keynote speech at the Infosec conference held in London this week, the intelligence agency's Director General for Cyber Security, Ciaran Martin, said that organisations should take their lead from GCHQ and render them as "irrelevant as possible".</p><p>He said that in the last 10 years, the security industry has moved from talking about "what might happen" to what is now happening on a daily basis". He told delegates that it had fallen to the agency to be the UK's "top scarer". He explained that the three main motives in cyber-attacks were money, power and propaganda - particularly as intellectual property and corporate reputation gain increasing importance to organisations.</p><p>"We're genuinely surprised at the variety of UK organisations that can been subject to intrusion," he said. He urged firms to think about what would make them "attractive as a target" to criminals as a good way of approaching IT security.</p><p>Martin said that organisations faced too many incidents to be concerned about "stopping attacks everywhere" and now the main aim in IT security was to protect "what you care about most".</p><p>But the UK market, despite increased awareness of attacks, displayed a "relative immaturity of norms and practices", even in supposedly secure institutions, said Martin. He hoped that new GCHQ standards would prevent the sorts of attacks that wiped bank drives in Asia and affected a Saudi Arabian oil firm in 2012.</p><p>Martin distanced his agency from the controversial allegations that it conducted mass surveillance of British citizens and said that GCHQ's powers were "strictly circumscribed" and "needed clear justifications as laid down by parliament".</p><p>When questioned on <a href="https://www.itpro.com/data-protection/24685/snoopers-charter-returns-as-the-investigatory-powers-bill" target="_self" data-original-url="https://www.itpro.com/data-protection/24685/snoopers-charter-returns-as-the-investigatory-powers-bill">the upcoming Investigatory Powers Bill</a>, or 'Snooper's Charter', that the government plans to enact, Martin refused to give an answer but added that the agency's roles only worked "because we have an intelligence capability".</p><p>"If we want to protect the UK from the darkest reaches of cyberspace, we have to know how it all works."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GCHQ now exempt from hacking laws ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/public-sector/24633/gchq-now-exempt-from-hacking-laws</link>
                                                                            <description>
                            <![CDATA[ Privacy International claims UK government has pushed through legislation meaning GCHQ isn't subject to same rules ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cifffDJoqCfuR7HUqDpAPn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nY8JTPANeySKpSdWpNyCge-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 19 May 2015 07:52:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nY8JTPANeySKpSdWpNyCge-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nY8JTPANeySKpSdWpNyCge-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Privacy International has revealed the GCHQ cannot get in trouble for hacking after the government pushed through legislation that makes it exempt from surveillance laws.</p><p>The organisation said it heard from the government ahead of a court case relating to the GCHQ's operations which, it claims, includes hacking in the Investigatory Powers Tribunal.</p><p>The government notified the claimants in the trial that the Computer Misuse Act was amended on 3 March 2015 to exempt the GCHQ intelligence service from rules set out in the act relating to hacking.</p><p>Privacy International, along with a group of other privacy and human right organisations filed complaints to the Investigatory Powers Tribunal, claiming the actions of the organisation were classed as hacking under the Computer Misuse Act and were therefore illegal.</p><p>The changes mean the GCHQ is able to continue carrying out its work by whatever means possible. Privacy International said it appears "no regulators, commissioners responsible for overseeing the intelligence agencies, the Information Commissioner's Office, industry, NGOs or the public were notified or consulted about the proposed legislative changes."</p><p>In February, a draft code was released giving UK spy agencies like the GCHQ powers to hack targets, including theose that don't have any link to crime or are a risk to national security, Privacy International said. However, very few details about the code have been released.</p><p>Eric King, deputy director of Privacy International, said: "The underhand and undemocratic manner in which the Government is seeking to make lawful GCHQ's hacking operations is disgraceful. Hacking is one of the most intrusive surveillance capabilities available to any intelligence agency, and its use and safeguards surrounding it should be the subject of proper debate.</p><p>"Instead, the government is continuing to neither confirm nor deny the existence of a capability it is clear they have, while changing the law under the radar, without proper parliamentary debate."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why restricting porn access opens door to spying ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/data-protection/24412/why-restricting-porn-access-opens-door-to-spying</link>
                                                                            <description>
                            <![CDATA[ Tories' election pledge to introduce age restrictions is more worrying than it appears ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gUwnG6P5D9awmeR2Nq2RcF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Pi5yeHk2GSNcfTrGD9hVAD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Apr 2015 08:46:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Joe Curtis ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Pi5yeHk2GSNcfTrGD9hVAD-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Porn]]></media:description>                                                            <media:text><![CDATA[Porn]]></media:text>
                                <media:title type="plain"><![CDATA[Porn]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Pi5yeHk2GSNcfTrGD9hVAD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><strong>OPINION:</strong><a href="https://www.itpro.com/strategy/24341/government-consults-on-porn-site-age-checks" target="_blank" data-original-url="https://www.itpro.com/strategy/24341/government-consults-on-porn-site-age-checks">Porn sites will have proper age restrictions</a> if the Conservatives are returned to government following May's general election.</p><p>Prime Minister David Cameron's pledge aims to protect children after a Childline survey found 18 per cent of 12-13 year-olds had seen upsetting pornography pictures on the web.</p><p>Many porn sites do require a visitor to enter their date of birth or confirm they're aged over 18, but users can simply select a date or tick a box rather than provide any real proof of age.</p><p>However, the Tories say an independent regulator would require ISPs to block porn sites that don't comply.</p><p>Culture secretary Sajid Javid said: "We need effective controls online that apply to UK and overseas.</p><p>"This is about giving children the best start in life; we do not want to prevent adults from accessing legal content but we do want to protect our children from harmful material, so they are free to develop a healthy attitude to sex and relationships."</p><p>This regulator would also be tasked with finding out the best way to introduce age restrictions, the Conservatives say.</p><p>But Javid told <em>BBC Breakfast</em> one way to age-check porn users would be with credit cards presumably for paid-access sites.</p><p>Another method, he said, was adopting electronic IDs (EIDs) as used in countries such as Finland.</p><p>Restricting porn access is a laudable principle, but not one that should be automatically supported without consideration of just how it will be done.</p><p>Javid's suggestions of age-checking people with their credit cards, or with EIDs, is worrying due to the potential for misuse.</p><p>But, as Sally Annereau, data protection analyst from Taylor Wessing law firm, says, it's probably the only way to do it.</p><p>"Implementing online processes that can reliably verify a person's age will inevitably require the collection of, access to, or sharing of even more unique information about people," she warns.</p><p>Such a measure raises many questions around data protection how can these details be collected and safeguarded to protect privacy?</p><p>Furthermore, it raises the risk of ID theft, fraud, and surveillance.</p><p>"It would be a privacy own goal to implement online safeguards without first taking account of all the wider risks and legal challenges for society that those measures also raise," Annereau says.</p><p>The GCHQ isn't exactly averse to a bit of spying, with ex-NSA whistleblower Edward Snowden revealing the <a href="http://www.pcpro.co.uk/security/1000496/gchqs-mass-data-collection-was-legal-rules-parliament" target="_blank">NSA had provided the British spy agency with data on UK citizens</a> from its own snooping programmes.</p><p>Additionally, the Tories' own record on security is questionable in the extreme.</p><p>Cameron recently <a href="https://www.itpro.com/security" target="_blank" data-original-url="https://www.itpro.com/security/23840/whatsapp-imessage-face-uk-ban-on-anti-terrorism-grounds">pledged to ban encrypted communication services</a> that make it hard for spooks to see what people are saying.</p><p>Then there's the <a href="https://www.itpro.com/it-legislation/21012/home-office-bids-revive-snoopers-charter-despite-snowden-revelations" target="_blank" data-original-url="https://www.itpro.com/it-legislation/21012/home-office-bids-revive-snoopers-charter-despite-snowden-revelations">Snooper's Charter</a>, officially the Communications Data Bill, which the Lib Dems managed to block, but introduced by their coalition partners.</p><p>If passed, it would have made it easier for law enforcement and intelligence agencies to access communications data, forcing ISPs and websites to store information on users for at least 12 months.</p><p>The Tories may try to push the bill through Parliament again after May 7, and GCHQ is no doubt resorting to other methods to collect data on citizens but why make it easier for them?</p><p>As content filtering company Bloxx's sales director, Mark Gibson, says: "It seems naive to suggest this would not impeach on people's privacy - if implemented the system will, to a degree, monitor people's browsing."</p><p>Instead, there must be another way forward - Taylor Wessing's Annereau certainly thinks there is.</p><p>She points to a range of potential technologies that also offer more privacy-friendly features and give parents greater control and peace of mind.</p><p>However, she adds: "One big consideration around placing the onus on sites is that it may be challenging to develop standardised solutions."</p><p>Gibson suggests another route. "There needs to be education and discussion about adult content, to try and tackle the reason more and more children are searching it out, rather than placing it behind a set of easily bypassed barriers," he says.</p><p>Either way, while we might agree with the sentiment proposed by the Conservatives, it's hard to see how it will prove practical without further eroding the privacy of UK citizens.</p><p>A discussion on the prevalence of porn in today's society should be encouraged, but there's no quick answer thinking through the possible consequences takes time and introducing such a measure shouldn't be left to a single party with a poor record on privacy.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Amnesty International takes Gov to court over spying ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/public-sector/24378/amnesty-international-takes-gov-to-court-over-spying</link>
                                                                            <description>
                            <![CDATA[ Ten human rights orgs take government to the European Court of Human Rights to stop surveillance ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4ZfSeiq4eBXSz5iWXBMoo7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/X9oPGA7KjDNvUQ64DTUhNf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 13 Apr 2015 08:29:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/X9oPGA7KjDNvUQ64DTUhNf-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Spyglass]]></media:description>                                                            <media:text><![CDATA[Spyglass]]></media:text>
                                <media:title type="plain"><![CDATA[Spyglass]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/X9oPGA7KjDNvUQ64DTUhNf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.amnesty.org/articles/news/2015/04/amnesty-international-takes-uk-government-to-european-court-of-human-rights-over-mass-surveillance" target="_blank">Amnesty International</a> is taking the government to the European Court of Human Rights over its mass surveillance of UK citizens.</p><p>The organisation claims the government's practice of mass surveillance goes against human rights, and has issued the legal challenge with another nine bodies.</p><p>All object to the government's methods of interception, collection, inspection, distribution and retention of communications "without any judicial authorisation," their filing said.</p><p>Their complaint is based on revelations leaked by ex-NSA contractor <a href="https://www.itpro.com/security/22857/edward-snowden-awarded-three-year-russian-permit" target="_blank" data-original-url="https://www.itpro.com/security/22857/edward-snowden-awarded-three-year-russian-permit">Edward Snowden</a>, who revealed information on secret US data collection programmes like <a href="https://www.itpro.com/security/20408/nsa-prism-surveillance-necessary-evil-or-misuse-power" target="_blank" data-original-url="https://www.itpro.com/security/20408/nsa-prism-surveillance-necessary-evil-or-misuse-power">PRISM</a>, collecting communications data including emails, text messages, phone calls and social media without permission.</p><p><a href="https://www.amnesty.org/en/documents/ior60/1415/2015/en" target="_blank">The court filing</a> mentioned Tempora, Upstream and PRISM as three of the mass surveillance programmes it was hoping to stop, saying the operations were making it increasingly difficult for Amnesty International to carry out its work.</p><p>While based in the US, the PRISM and Upstream programmes extended to UK-held data. Meanwhile Tempora is the UK's own GCHQ programme, giving spooks access to vast swathes of data on millions of people.</p><p>"It is thanks only to Edward Snowden's revelations, and the scant disclosures we and the other claimants have been able to prise from the government, that we know anything whatsoever about what the intelligence services are up to," said James Welch, Legal Director for Liberty.</p><p>The filing also detailed how a closed hearing took place, outlining Amnesty International and the other applicants' concerns, but none of the bodies were invited to attend because of the sensitive nature of the country's security.</p><p>Nick Williams, Amnesty International's legal counsel said: "The UK government's surveillance practices have been allowed to continue unabated and on an unprecedented scale, with major consequences for people's privacy and freedom of expression. No-one is above the law and the European Court of Human Rights now has a chance to make that clear."</p><p>Carly Nyst, legal director of Privacy International, added: "Mass surveillance is a violation of our fundamental rights. Intercepting millions of communications every day, and secretly receiving millions more from the NSA by the back door is neither necessary nor proportionate."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NSA & GCHQ SIM card hack: Gemalto denies encryption keys stolen through hack ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/24092/nsa-gchq-sim-card-hack-gemalto-denies-encryption-keys-stolen-through-hack</link>
                                                                            <description>
                            <![CDATA[ Special mobile unit was set up in 2010 to steal encryption keys ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2vQCZeEWZ3jQitAEuBYocQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/k37fm6trAKsUViJAxfXzEZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 25 Feb 2015 10:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Khidr Suleman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/k37fm6trAKsUViJAxfXzEZ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/k37fm6trAKsUViJAxfXzEZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>SIM card maker Gemalto has shared details of its investigation into claims British and US securities services hacked the company to steal billions of encryption keys.</p><p><strong>Privacy International blasts security services</strong></p><p>"GCHQ has lost it's way. In stealing the SIM card encryption keys of millions of mobile phone users they have shown there are few lines they aren't willing to cross," the charity told <em>IT Pro</em>.</p><p>"Hacking into law-abiding companies, spying on their employees and stealing their data should never be considered 'fair game.' </p><p>"The mentality of 'Act first, worry about the law later' has to come to an end. Unrestrained, unregulated Government spying of this kind is the antithesis of the rule of law and they must be held accountable for their actions."</p><p>The two agencies are said to have joined forces to set up a specialist Mobile Handset Exploitation Team (MHET) in April 2010, documents by <em><a href="https://firstlook.org/theintercept/2015/02/19/great-sim-heist/https:/firstlook.org/theintercept/2015/02/19/great-sim-heist" target="_blank" data-original-url="https://firstlook.org/theintercept/2015/02/19/great-sim-heist/https://firstlook.org/theintercept/2015/02/19/great-sim-heist">The Intercept</a></em> revealed. The unit's mission was to target vulnerabilities in mobile devices.</p><p>Operatives worked to infiltrate Dutch company Gemalto, which produces 2 billion SIM cards a year and serves 450 telecoms operators across the globe, it was claimed.</p><p>A top secret slide (below) confirmed the NSA and GCHQ had gained access to Gelmato's network and mined the private communications of engineers and sales employees.</p><p>The claims are the latest in a long line of revelations to have been made public by NSA whistleblower Edward Snowden.</p><p>By stealing encryption keys, the intelligence agencies were able to monitor mobile communications without approval from telecom companies and foreign governments, all without being traced.</p><p>In a statement published on 25 February, the organisation said it has reason to believe the NSA and GCHQ were behind a series of attempts made in 2010 and 2011 to hack into the company and its network. </p><p>"At the time we were unable to identify the perpetrators but we now think they could be related to the NSA and GCHQ operation," the statement reads. </p><p>"These intrusions only affected the outer parts of our networks - our office networks - which are in contact with the outside world.</p><p>"The SIM encryption keys and other customer data in general, are not stored on these networks," the statement added.</p><p>Therefore, it denied claims the security services were able to steal the SIM encryption keys because the NSA and GCHQ appear to have only succeeded in breaching its office networks.</p><p>Instead, Gemalto's investigation into the matter has suggested the NSA and GCHQ may have targeted other parts of its SIM card supply chain to get access to the encryption keys, rather than via its own network.</p><p>Furthermore, it also denies that it ever sold SIM cards to four out of the 12 operators listed in the leaked documents.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="F3FfKGoHAmboAJq59jFDFm" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/F3FfKGoHAmboAJq59jFDFm.png" mos="https://cdn.mos.cms.futurecdn.net/F3FfKGoHAmboAJq59jFDFm.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Gemalto described the attacks as as "serious and sophisticated", but said no signs of malicious activity were observed anywhere else in its networks.</p><p>"No breaches were found in the infrastructure running our SIM activity or in other parts of the secure network which manage our other products such as banking cards, ID cards or electronic passports," the statement continued. </p><p>"We are conscious that the most eminent state agencies, especially when they work together, have resources and legal support that go far beyond that of typical hackers and criminal organisations.</p><p>"And, we are concerned that they could be involved in such indiscriminate operations against private companies with no grounds for suspicion," the statement concluded. </p><p>When the allegations first came to light last week, Gelmato said in a statement that the security services appear to have tried to reach as many mobile phones as possible.</p><p>"We cannot at this early stage verify the findings of the publication and had no prior knowledge that these agencies were conducting this operation," the firm said.</p><p>"We take this publication very seriously and will devote all resources necessary to fully investigate and understand the scope of such sophisticated techniques."</p><p><strong><em>This article was originally published on 25/2/15 and updated on the same day to include details of Gemalto's investigation.</em></strong></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK tribunal rules GCHQ's NSA data-sharing deal "unlawful" ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/24005/uk-tribunal-rules-gchqs-nsa-data-sharing-deal-unlawful</link>
                                                                            <description>
                            <![CDATA[ Civil liberty groups cheer court ruling, but claim there is more work to do ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2x4oWP8kCmFdzXmHJ2RmUz</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Y77hj8aZMbVpoAPp3mtk5D-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 06 Feb 2015 16:34:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Smart City]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Y77hj8aZMbVpoAPp3mtk5D-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Surveillance]]></media:description>                                                            <media:text><![CDATA[Surveillance]]></media:text>
                                <media:title type="plain"><![CDATA[Surveillance]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Y77hj8aZMbVpoAPp3mtk5D-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Investigatory Powers Tribunal (IPT) has declared British intelligence services acted unlawfully by accessing the personal communications data gathered by the US National Security Agency (NSA).</p><p>The IPT, set up 15 years ago to oversee the activities of GCHQ, MI5 and MI6, ruling follows a complaint made by several civil liberties organisations, including Amnesty International, Privacy International, Bytes for All and Liberty.</p><p>The Tribunal said the way intelligence was shared between GCHQ and the NSA's Prism surveillance programme was unlawful up until December 2014, because the rules governing the practice were kept secret.</p><p>Post-December 2014, this was no longer the case, as the details of it were made public through the work of the Tribunal.</p><p>The existence of Prism came to light in a series of disclosures by NSA whistleblower Edward Snowden during the summer of 2013.</p><p>Through the programme, it's alleged the NSA was able to access data used by the a wide range of tech giants, including Microsoft, Yahoo, Google and Facebook, and share it with GCHQ if needed.</p><p>As a result of today's outcome, Privacy International and Bytes for All have asked for further clarification from the court regarding the interception and collection of their communications data.</p><p>If it transpires that their data was unlawfully collected before December 2014, the parties are set to demand its immediate deletion.</p><p>They also want to challenge the assertion that GCHQ's activities after December 2014 were lawful, and have vowed to lodge an application with the European Court of Human Rights on this point.</p><p>Eric King, deputy director of Privacy International, said the ruling should put an end to security agencies acting like they can operate outside of the law.</p><p>"We must not allow agencies to continue justifying mass surveillance programs using secret interpretations of secret laws. The world owes Edward Snowden a great debt for blowing the whistle, and today's decision is a vindication of his actions," he said.</p><p>"But more work needs to be done. The only reason why the NSA-GCHQ sharing relationship is still legal today is because of a last-minute clean-up effort by Government to release previously secret arrangements'.</p><p>"That is plainly not enough to fix what remains a massive loophole in the law, and we hope that the European Court decides to rule in favour of privacy rather than unchecked State power."</p><p>James Welch, legal director for Liberty, added: "The Intelligence Services retain a largely unfettered power to rifle through millions of people's private communications and the Tribunal believes the limited safeguards revealed during last year's legal proceedings are an adequate protection of our privacy. We disagree, and will be taking our fight to the European Court of Human Rights."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Edward Snowden claims iPhones have built-in spyware ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/mobile/23900/edward-snowden-claims-iphones-have-built-in-spyware</link>
                                                                            <description>
                            <![CDATA[ Edward Snowden said Apple is tracking iDevice users via remote access ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8VdgQAUGToUVChDX8Kcaqr</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DK5otXH2psHpazet9bGye5-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Thu, 22 Jan 2015 09:19:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/DK5otXH2psHpazet9bGye5-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DK5otXH2psHpazet9bGye5-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Whistleblower Edward Snowden has claimed all iPhones feature spyware that can track users' every move via remote tracking.</p><p>The ex-NSA contractor, who was responsible for leaking confidential intelligence documents to expose government spying, thinks the software embedded on iDevices can be switched on by whoever fancies keeping tabs on the owner.</p><p>Snowden's lawyer Anatoly Kucherena said: "Edward never uses an iPhone, he's got a simple phone. The iPhone has special software that can activate itself without the owner having to press a button and gather information about him, that's why on security grounds he refused to have this phone."</p><p>Neither Kucherena or Snowden revealed what type of spyware is allegedly integrated in the devices or who has access to the data mined from them, although Apple has been accused of spying in the past by Snowden.</p><p>The iPhone manufacturer was said to be part of the NSA's PRISM data mining initiative, which apparently allowed the security agency to access SMS messages, on-board data, live microphone feeds, and positioning information from smartphones.</p><p>According to other documents, leaked by Snowden to <em>The <a href="http://www.independent.co.uk/life-style/gadgets-and-tech/news/iphone-has-secret-software-that-can-be-remotely-activated-to-spy-on-people-says-snowden-9991754.html">Independent</a></em>, British intelligent agency GCHQ also may have used iPhones' UDID identifiers to track people, although none of Snowden's leaked documents so far refer to spyware installed on smartphones.</p><p>Apple said in a statement: "Apple has never worked with the NSA to create a backdoor in any of our products, including iPhone. Additionally, we have been unaware of this alleged NSA program targeting our products. We care deeply about our customers' privacy and security."</p><p>At the launch of iOS 8, Apple said its newest update prevented any law enforcement officers from accessing personal phone data.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[  Anti-terror measures: How tech helps fight the counter-terrorism war ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/23685/anti-terror-measures-how-tech-helps-fight-the-counter-terrorism-war</link>
                                                                            <description>
                            <![CDATA[ Davey Winder examines how technology can help and hinder in the fight against terrorism ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mwuhZ2Z1n6wmHewmaWeFeE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xPZqvJFthBNFwUWQeLDGCY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 09 Dec 2014 12:27:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Smart City]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xPZqvJFthBNFwUWQeLDGCY-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xPZqvJFthBNFwUWQeLDGCY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Science is being used to counter "technically aware terrorists", as part of a wider technology push for countering international terror threats, according to the UK government's recent <em>Protecting the UK Against Terrorism </em><a href="https://www.gov.uk/government/policies/protecting-the-uk-against-terrorism/supporting-pages/using-science-and-technology-to-counter-the-threat-from-terrorists">policy document</a>.</p><p>Because of the nature of the counter-terrorism beast, exactly what technology is being used and how it is being implemented is not in the public domain. That doesn't mean, however, we are unaware that communication monitoring techniques are at the very heart of the surveillance and interception policy and have been for many years.</p><p>Indeed, the 1991 Intelligence Services Act and the 2000 Regulation of Investigatory Powers Act give law enforcement and security agencies fairly sweeping authority to intercept and monitor everything from mobile phone calls to email and social media usage.</p><div><blockquote><p>There's a very fine line between counter-terrorism and wholesale State monitoring of citizens. Which is why, post-Snowden, the big players have woken up to encryption and the newly-enlightened public's desire to embrace it.</p></blockquote></div><p>I'm not going to cover old ground, on the basis that everyone knows about the Edward Snowden <a href="https://www.itpro.com/security/22650/snowden-just-10-of-nsa-data-is-terrorism-related" data-original-url="https://www.itpro.com/security/22650/snowden-just-10-of-nsa-data-is-terrorism-related">revelations by now</a>. However, only a fool would think spies are going to stop spying; it's what they do, and when 'the threat' could be any one of us they will spy on all of us.</p><p>I don't like it and there's a very fine line between counter-terrorism and wholesale State monitoring of citizens. Which is why, post-Snowden, the big players have woken up to encryption and the newly-enlightened public's desire to embrace it.</p><p>It's also why Robert Hannigan, the UK spymaster general at GCHQ, has accused companies of enabling platforms that have become "the command and control networks of choice" for terrorist groups like ISIS.</p><p>Breaking encryption is, one would assume and if you'll excuse the pun, another key to counter-terrorism success. Which is why during a recent visit to Professor Andrew Blyth, director of the Information Security Research Group based at the University of South Wales, I wasn't surprised to learn government agencies have already expressed an interest in his lab's ability to break the device encryption employed by iOS 8.</p><p>Intercepting communications will be at the heart of every counter-terrorist investigation, just as it has always been, because as one intelligence officer so aptly put it "terrorists have to communicate." How they communicate, of course, is also part of the growing problem for the counter-terrorism guys.</p><p>Looking beyond the cloak and dagger, encoded messages and dark corner conversations, some terrorist communication is much more open. Use of the web, via YouTube videos and social media has become de rigueur when it comes to the distribution of extremist material, propaganda and misinformation alike.</p><p>All of which are powerful weapons in the terrorist arsenal, and which have been used with devastating effect recently by ISIS for both showcasing executions and recruiting new fighters for its cause. In an attempt to proactively defend against such tactics, the Metropolitan Police established a dedicated <a href="http://www.acpo.police.uk/ACPOBusinessAreas/PREVENT/TheCounterTerrorismInternetReferralUnit.aspx">Counter Terrorism Internet Referral Unit</a> (CTIRU) in 2010 that deals with public reports of online content "of a violent extremist or terrorist nature." Since it started, CTIRU has removed some 55,000 pieces of content and 34,000 of those have been in the last year alone.</p><p>More controversially, the UK government is putting pressure on Internet Service Providers to block 'extremist' content at source, so that customers would not be able to see it. This blocking would, if successful, take the form of optional filtering such as is already in place for pornographic content, for example.</p><p>Quite how effective this might be is one legitimate question being raised by both the ISPs themselves and internet rights groups, with opt-in filters not proving that popular with the public and methods of circumventing them being readily available for anyone who cares to Google for it.</p><p>Another legitimate question is who determines what content is extremist, and how is that determination reached? Whenever we talk of political censorship we have to be very careful to be transparent and open, otherwise it's a very slippery slope leading further down the road to state-controlled media.</p><p>I appreciate such a view will, no doubt, have some readers on the verge of an aneurysm but there has to be a method of knowing who is blocked and why, and an appeals mechanism for when the system inevitably screws up.</p><p>According to CTIRU, examples of what is currently considered extremist include speeches or essays calling for racial or religious violence, videos of violence with messages of glorification' or praise for terrorists, postings inciting people to commit acts of terrorism or violent extremism and messages intended to generate hatred against any religious or ethnic group.</p><p>Of course, even if such a method of filtering online material were to be agreed it would need to be implemented by every UK-based ISP to be effective. And there lies the next stumbling block, and one the likes of CTIRU has to deal with: most social media organisations are not based in the UK and are not obligated to remove content when asked to by UK law enforcers.</p><p>I'm not saying they won't or don't, but the process is an entirely voluntary one and that's why definitions of extremism and terrorism have to be front and centre of the counter-terrorism tech debate. The international element also raises another concern over counter-terrorism measures when they flow into the social media and online realm, namely who gets to participate in the takedown process? Free speech is a two-way street and with social media being a global game there are players whose politics and definitions of extremism and terrorism differ from ours.</p><p>Social media is no longer a two-horse race with just Facebook and Twitter to deal with, smaller players quickly gain traction with the young (who are the main targets of extremist propaganda, remember) and may be less amenable to kicking the freedom of speech ball out of play. Especially in a post-Snowden world where tech companies have seen the backlash when any hint of being in bed with the spymasters becomes public.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Facebook outed as host of Lee Rigby murder chat ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/23599/facebook-outed-as-host-of-lee-rigby-murder-chat</link>
                                                                            <description>
                            <![CDATA[ Extremist had "online exchange" via Facebook claiming he wanted to kill a soldier, it has emerged ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">beqe2MiCtXXPKWPJSw3eyE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/efEsxopTc8zj7ctpbKUYVK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 26 Nov 2014 12:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Social Media]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/efEsxopTc8zj7ctpbKUYVK-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Facebook]]></media:description>                                                            <media:text><![CDATA[Facebook]]></media:text>
                                <media:title type="plain"><![CDATA[Facebook]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/efEsxopTc8zj7ctpbKUYVK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Facebook has been outed as the unnamed internet company accused of failing to flag details of an online conversation between one of Fusilier Lee Rigby's killers and a fellow extremist where he outlined plans to kill a solider.</p><p>A report <a href="https://b1cba9b3-a-5e6631fd-s-sites.googlegroups.com/a/independent.gov.uk/isc/files/20141125_ISC_Woolwich_Report%28website%29.pdf?attachauth=ANoY7co8-06O2Fk8Kf9e_hXtQ2V5UlgStlYCFg1WSl7tcUO33wSx-ZHI_i1u3FVCdd8iHRCCF2dsMVSKPZ4Y7eivtXY7j_bML_EOBJHf4U4txraiSnDaG_JoVZdc3ygfJ8QYuEpcuc4pN-5-7fDNReZIeSbC4RDdZ1Z5b7Yf5JhWcKem7LgZ6CTLkXeJMy_gNK5DNts7bqqEkdgrNZB3uK4VTCkePZibXQcVeRX2BHi1Ekl0wlhgM6Zscat3YEMVQ7XSqMZNXqvB&attredirects=0">published</a> yesterday by the Intelligence and Security Committee (ISC) of Parliament into the circumstances that led to the murder of Lee Rigby in May 2013 said an "unnamed "internet company could have taken steps to prevent it, and the <a href="http://www.bbc.co.uk/news/technology-30199131">BBC has since confirmed</a> the company in question is social networking giant Facebook.</p><p>According to the ISC document, one of the perpetrators of the crime - Michael Adebowale had an online exchange with a fellow extremist where he detailed plans to murder a British soldier in December 2012.</p><p>Details of this exchange only emerged after the fatal attack against Rigby took place, but it could have been detected earlier, the report claims, if the social network had flagged it.</p><div><blockquote><p>To pass the blame to internet companies is to use Fusilier Rigby's murder to make cheap political points.</p></blockquote></div><p>The report claims the unnamed communications service provider automatically closed several accounts belonging to Adebowale for terrorism-related reasons without passing on details to the authorities about the nature of his discussions.</p><p>"They [the communications provider] had not been aware of the content of these accounts before as they did not routinely monitor content in this way," it was noted.</p><p>"GCHQ understands that Adebowale's accounts were disabled as a result of an automated process, where activity met the above descriptors, but that the company did not then manually review the content of these accounts, nor pass any information to the authorities," it adds.</p><p>The report goes on to claim that, had the company passed on details of Adebowale's online activities, his discussion with the extremist may have come to light sooner.</p><p>"We take the view that, when possible links to terrorism trigger accounts to be closed, the company concerned and other communications service providers should accept their responsibility to review these accounts immediately and, if such reviews provide evidence of specific intention to commit a terrorist act, they should pass this information to the appropriate authority," the report continues.</p><p>In a statement to <em>IT Pro</em>, a Facebook spokesperson said the company does take action to prevent terror-related content from being shared on the site. </p><p>"Like everyone else, we were horrified by the vicious murder of Fusilier Lee Rigby. We don't comment on individual cases but Facebook's policies are clear, we do not allow terrorist content on the site and take steps to prevent people from using our service for these purposes," the spokesperson said.</p><p>The report's conclusion has been criticised by Jim Killock, executive director of privacy organisation The Open Rights Group, who said the government is wrong to use Rigby's murder to build a case for keeping closer tabs on the online activities of UK citizens.</p><p>"To pass the blame to internet companies is to use Fusilier Rigby's murder to make cheap political points," he said.</p><p>"And it is quite extraordinary to demand that companies pro-actively monitor email content for suspicious material. Internet companies cannot and must not become an arm of the surveillance state."</p><p>He goes on to add that mass surveillance, rather than reassure citizens, actually makes them more distrustful of the authorities.</p><p>"The security services should focus their efforts on the targeted surveillance of individuals like Michael Adebolajo [Adebowale's accomplice] rather than continuing to monitor every citizen in the UK," Killock continues.</p><p>"Mass surveillance erodes the basic trust between citizen and state by treating us all as suspects. If the government keeps finding new ways to justify indiscriminate whole population trawls, it will be fair to say that we have lost our liberty and the terrorists have won."</p><p>The Internet Service Providers' Association (ISPA) has also hit back at the report's suggestion that online comms providers should do more to keep tabs on users, and that the internet as a whole has become a "safe haven for terrorists."</p><p>In a statement, the ISPA said: "It is for the intelligence agencies and not service providers to identify potential subjects, and when identified by the authorities CSPs (communication service providers) can and do assist in providing communications data under a clear legal process.</p><p>"The proposal that companies should monitor all communications online runs counter to the legal framework that underpins the internet, which forbids unwarranted monitoring of customers' communications. </p><p>ISPA and its members are in active discussions around communications data capabilities, including the current Anderson Review, and the ISC's report adds to the ongoing discussions," it concluded.</p><p><em><strong>This article was originally published on 25 November, before being updated with further comment from Facebook, the ISPA and others.</strong></em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GCHQ boss says tech giants “in denial” over online terrorism threat ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/23427/gchq-boss-says-tech-giants-in-denial-over-online-terrorism-threat</link>
                                                                            <description>
                            <![CDATA[ Social media has become “command and control” network of choice for online criminals, claims new GCHQ boss ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cLpqg3bwwvXoAKqR4AcD2p</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/aCdmb3mYgH4i2NhTufZv5Z-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 Nov 2014 11:41:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Social Media]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/aCdmb3mYgH4i2NhTufZv5Z-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[GCHQ]]></media:description>                                                            <media:text><![CDATA[GCHQ]]></media:text>
                                <media:title type="plain"><![CDATA[GCHQ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/aCdmb3mYgH4i2NhTufZv5Z-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The new boss of GCHQ, Robert Hannigan, has warned that social networking sites have become central to terrorist groups and tech giants need to work more closely with spy agencies to address this.</p><p>In an article in the <em><a href="http://www.ft.com/cms/s/2/4a35c0b2-636e-11e4-9a79-00144feabdc0.html#axzz3I2ciadbl">Financial Times</a></em>, Hannigan said however much the tech companies may dislike it, "they have become the command and control networks of choice for terrorists and criminals, who find their services as transformational as the rest of us."</p><p>While not singling out Facebook or Twitter, Hannigan said social media sites are used by terrorists to disseminate propaganda and communicate with other members and the wider world.</p><p>YouTube was used to show beheadings of journalists and aid workers. These videos were quickly spread on Twitter.</p><p>Hannigan said freely available technology has helped terror groups hide from the security services and said major tech firms were "in denial" about this. He added that smartphones and tablets had "increased the options available exponentially" to conceal terrorist activity.</p><p>Furthermore, privacy is not an "absolute right", he continued, and GCHQ has to enter the debate over it.</p><p>"GCHQ is happy to be part of a mature debate on privacy in the digital age. But privacy has never been an absolute right and the debate about this should not become a reason for postponing urgent and difficult decisions," he said.</p><p>"I think we have a good story to tell. We need to show how we are accountable for the data we use to protect people, just as the private sector is increasingly under pressure to show how it filters and sells its customers' data."</p><p>Eric King, deputy director of Privacy International, <a href="http://www.theguardian.com/uk-news/2014/nov/03/privacy-gchq-spying-robert-hannigan">told the <em>Guardian</em></a> that it was "disappointing to see GCHQ's new director refer to the internet the greatest tool for innovation, access to education and communication humankind has ever known as a command-and-control network for terrorists."</p><p>King added that GCHQ had lost the trust of the public and does need to enter a public debate over privacy "but attacking the internet isn't the right way to do it."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GCHQ to test UK citizens' ability to prevent cyber attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/22943/gchq-to-test-uk-citizens-ability-to-prevent-cyber-attacks</link>
                                                                            <description>
                            <![CDATA[ Surveillance service teams up with Cyber Security Challenge to help uncover new infosecurity experts ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6pSn4ivgKgedvjhyak554M</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8Dbhg95jWo2ofqg7DtRfBm-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 21 Aug 2014 10:09:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rosie Clarke ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8Dbhg95jWo2ofqg7DtRfBm-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cyber security]]></media:description>                                                            <media:text><![CDATA[Cyber security]]></media:text>
                                <media:title type="plain"><![CDATA[Cyber security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8Dbhg95jWo2ofqg7DtRfBm-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>UK surveillance service GCHQ has teamed up with the Cyber Security Challenge (CSC) to launch a virtual game, dubbed Astute Explorer, to encourage more people to consider a career in information security.</p><p>In the game, which is named after GCHQ's automated code scanning tool, players are tasked with deciphering a code to locate vulnerabilities, and explain how hackers could exploit these to carry out a cyber attack against fictitious aerospace and engineering company Ebell Technologies.</p><p>Stephanie Daman, CEO of the Cyber Security Challenge, said: "Astute Explorer is an ingenious game from GCHQ which will not only provide an enjoyable challenge but will test skills that are in high demand by employers in this sector."</p><p>The game is part of a series of initiatives that Cyber Security Challenge has rolled out over the past year, and follows on from a task set by security vendor Sophos over the weekend, which asked the public to analyse a hard drive obtained from faux hacking group the Flag Day Associates.</p><p>As a result of that task, participants were made aware of a cyber threat by the Flag Day Associates against Ebell, and the shape that potential attack could take is what Astute Explorer is designed to ascertain.</p><p>This is the fourth year CSC has run a national competition like this, designed to draw talented people into the cyber security profession. GCHQ is one of CSC's platinum sponsors and one of the three UK-based intelligence agencies.</p><p>Participants who show the most promise will be invited to report for duty at secret locations scattered around the UK, investigating face-to-face in teams.</p><p>Successful candidates will take on the Flag Day Associates hacker group at the Masterclass final next year. Anyone living in the UK is invited to participate.</p><p>Those interested in taking part can register to <a href="https://cybersecuritychallenge.org.uk/registration">play here</a>. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK tech skills gap could increase risk of cyber attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/22851/uk-tech-skills-gap-could-increase-risk-of-cyber-attacks</link>
                                                                            <description>
                            <![CDATA[ Industry heads across the UK have warned that a lack of skills in cyber security could leave businesses more vulnerable ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">q1hj2qp2BcE9nFMtaSmi1j</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wxoifjSY89cHo4N7WKAwtb-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 07 Aug 2014 11:37:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Preece ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/MfwwRmvRe3qucjt85cMgeg.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wxoifjSY89cHo4N7WKAwtb-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[security key on keyboard]]></media:description>                                                            <media:text><![CDATA[security key on keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[security key on keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wxoifjSY89cHo4N7WKAwtb-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A lack of skills in cyber security among UK graduates could lead to increased risk for businesses, industry leaders have warned.</p><p>According to statistics, only 0.6 per cent of recent graduates (2012-2013) are currently working in the cyber security sector, with others left unprepared when leaving computer science degree programs. Many technology qualifications reportedly gloss over the issue of security, creating a significant skills gap.</p><p>The concerns were brought to light by a study from the International Information Systems Security Certification Consortium, which revealed that less than 1 per cent of the 7,635 computer science graduates across the UK were working in cyber security positions.</p><p>Dr Yiannis Pavlosoglou, risk and security specialist at YBS, told the <a href="http://www.ft.com/cms/s/0/76b1eef4-1d3c-11e4-8b03-00144feabdc0.html#axzz39h7P39qZ">Financial Times</a>: "The majority of graduates coming out of UK computer science and computing departments have not spent the necessary amount of time with the basic principles that govern information security and risk management."</p><p>In terms of cyber security, computer science graduates may not have an advantage over those coming from other subjects, Dr Adrian Davis, European director of IISSCC has claimed.</p><p>Organisations have been warned about this shortcoming inherent to many recent graduates, with those in the industry pointing out the risk they pose to cyber security when unable to properly protect sensitive data, extending to basic tasks such as data disposal.</p><p>"It is like building a house without locks," Derrick Bates, senior information security officer for the North Cumbria University Hospitals NHS Trust added. "What is the point in universities turning our great software developers and web designers if they have no idea how to design them securely."</p><p>In an effort to address the problem, <a href="https://www.itpro.com/government-it-strategy/22819/six-university-security-masters-degrees-approved-by-gchq" data-original-url="https://www.itpro.com/government-it-strategy/22819/six-university-security-masters-degrees-approved-by-gchq">GCHQ has approved</a> six masters degrees focused on online security. These include offerings from Edinburgh Napier University, Lancaster University, the University of Oxford and Royal Holloway and University of London.</p><p>GCHQ said of the accreditations: "The National Cyber Security Strategy recognises education as key to the development of cyber security skills and, earlier in the year, UK universities were invited to submit their cyber security Masters degrees for certification against GCHQ's stringent criteria for a broad foundation in cyber security.</p><p>"Partnerships have been key throughout the process with the assessment of applicants based on the expert views of the industry, academia, professional bodies, GCHQ and other government departments."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GCHQ snooping tribunal hearing starts today ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/it-legislation/22705/gchq-snooping-tribunal-hearing-starts-today</link>
                                                                            <description>
                            <![CDATA[ Spooks under scrutiny by regulators after demands for hearings by privacy groups ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">a8Achi6w2XjK1XwUrWzaKQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/aCdmb3mYgH4i2NhTufZv5Z-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 15 Jul 2014 15:38:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/aCdmb3mYgH4i2NhTufZv5Z-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[GCHQ]]></media:description>                                                            <media:text><![CDATA[GCHQ]]></media:text>
                                <media:title type="plain"><![CDATA[GCHQ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/aCdmb3mYgH4i2NhTufZv5Z-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Lawyers representing GCHQ and the government will appear before the Investigatory Powers Tribunal (IPT) to decide if the spy agency violated laws with surveillance activities unearthed by revelations from Edward Snowden.</p><p>The IPT will also hear complaints from privacy campaigners Liberty, Privacy International, Amnesty International as well as several other groups from abroad. The case will be heard at the Royal Courts of Justice.</p><p>The case has been lodged with the IPT to challenge a ruling in July 2013 by the Intelligence and Security Committee (ISC) that the use of data collected during the Prism programme was legal.</p><p>It is the first of several to be examined by the tribunal. The civil liberties groups alleged that private communications may have been monitored under GCHQ's Tempora programme. The groups also said that data gained through the NSA Prism programme might have been shared with UK spy agencies, which circumvented UK legal protections.</p><p>"The UK government is manipulating national laws to ensure it can continue to flout international ones," said Michael Bochenek, senior director for Law and Policy at Amnesty International. </p><p>"For the first time, UK intelligence agencies will have to answer for their activities and defend their indefensible policy for mass surveillance," Bochenek said. </p><p>In a witness <a href="https://www.privacyinternational.org/sites/privacyinternational.org/files/downloads/press-releases/witness_st_of_charles_blandford_farr.pdf">statement</a> to the tribunal, Charles Farr, the director general of the Office for Security and Counter Terrorism, said that sharing intelligence with foreign agencies had led to terrorist attacks being prevented.</p><p>He added that interception under the Regulation of Investigatory Powers Act 2000 (RIPA) is a "critical tool in investigations into the full range of threats to national security". In Farr's submission to the court he said he could "neither confirm or deny" the existence of Tempora, but did acknowledge Prism's existence as it had "been expressly avowed by the executive branch of the US government".</p><p>The tribunal may hear some of the most sensitive evidence regarding interceptions in private. It will look at whether Tempora and Prism exist and also whether either violates articles 8 and 10 of the European Convention on Human Rights.</p><p>The case comes after emergency surveillance legislation was brought in and is expected to pass in a couple of day's time. The legislation has been fast tracked after back room deals were made between the government and opposition parties.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Angry Birds, Squeaky Dolphin, NoseySmurf: The NSA programs you never knew about ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/22640/angry-birds-squeaky-dolphin-noseysmurf-the-nsa-programs-you-never-knew-about</link>
                                                                            <description>
                            <![CDATA[ IT Pro takes you on a run down of some of the major NSA projects that may have passed you by over the last 12 months ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">k6wA47KBez4T4otymWJony</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/k37fm6trAKsUViJAxfXzEZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Jul 2014 14:12:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Alex Hamilton ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/k37fm6trAKsUViJAxfXzEZ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Angry Birds in space]]></media:description>                                                            <media:text><![CDATA[Angry Birds in space]]></media:text>
                                <media:title type="plain"><![CDATA[Angry Birds in space]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/k37fm6trAKsUViJAxfXzEZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The National Security Agency (NSA), set up to combat foreign and domestic intelligence threats to the US, has had its reputation turned upside down since whistleblower Edward Snowden began to leak details of its clandestine activities.</p><p>In the past year, Snowden's leaks have revealed more than 40 separate intelligence campaigns undertaken by the NSA or its UK allies at GCHQ.</p><p>Among the most infamous was the news the NSA had been infiltrating the data centres of US technology companies - including Facebook, Microsoft and Google - and snatching user data from the traffic.</p><p>Upstream and PRISM, the names of the surveillance operations that conducted those clandestine acts, caused outrage throughout the technology industry and the world. People began to wonder if their data was truly safe in the hands of the big companies and on the internet.</p><p>The ripples of that discovery can still be felt today, as companies attempt to <a href="http://www.google.co.uk/url?sa=t&rct=j&q=&esrc=s&source=web&cd=4&cad=rja&uact=8&ved=0CEAQFjAD&url=http%3A%2F%2Fwww.itpro.com%2Fsecurity%2F20476%2Fnsa-paid-google-yahoo-and-microsoft-cover-prism-compliance-costs&ei=p5a2U5nEJeKR0QXYtoF4&usg=AFQjCNGzaX0iYIZ">side-step their involvement</a> or relocate their services to assuage worried customers.</p><p>Yet those two operations were only part of myriad of projects the NSA and GCHQ have undertaken. The details of many more have been released by Snowden over the past year, some of which you might never even have heard of.</p><h3 class="article-body__section" id="section-angry-birds"><span>Angry Birds</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="KVDQadPyDpdDqyKYiVoDmC" name="" alt="Angry Birds in space" src="https://cdn.mos.cms.futurecdn.net/KVDQadPyDpdDqyKYiVoDmC.jpg" mos="https://cdn.mos.cms.futurecdn.net/KVDQadPyDpdDqyKYiVoDmC.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Nowhere is safe from the prying eyes of government agencies, it seems, not even much-loved mobile game Angry Birds.</p><p>As soon as a player opened up the game and began their bird-slinging adventures, algorithms within the game's code relayed their age, sex and other information to intelligence agents.</p><p>This is according to documents leaked from GCHQ, which revealed how it and the NSA had been working on ways to tap into mobiles and collect data through apps. Not just Angry Birds fell foul of the surveillance program: Google Maps, Facebook, Twitter and LinkedIn were also targeted.</p><p>"It effectively means that anyone using a smartphone is working in support of a GCHQ system," a secret 2008 report by the British agency said.</p><h3 class="article-body__section" id="section-noseysmurf"><span>NoseySmurf</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="HT86y5RYWJyUcSbQZs6aK5" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/HT86y5RYWJyUcSbQZs6aK5.jpg" mos="https://cdn.mos.cms.futurecdn.net/HT86y5RYWJyUcSbQZs6aK5.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Also known by the names "TrackerSmurf" and "DreamySmurf", the NoseySmurf project tied into the Angry Birds scheme by tapping into mobile phones to scrape data from users.</p><p>The NSA spent over $1 billion (580 million) in its search to find more efficient tracking and piggybacking methods for infiltrating targeted devices. In one top-secret presentation, the agency describes a victim uploading an image to Facebook from their phone as a "Golden Nugget!!"</p><p>From the simple act of someone uploading a picture to a social media site, later slides say, agents could glean a victim's contacts, location, gender, age, income, ethnicity, education level and even number of children.</p><h3 class="article-body__section" id="section-happyfoot"><span>HappyFoot</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="7sStEf86W6dUrez2CpsErb" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/7sStEf86W6dUrez2CpsErb.jpg" mos="https://cdn.mos.cms.futurecdn.net/7sStEf86W6dUrez2CpsErb.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>HappyFoot was the codename for an operation designed to track internet users' movements by piggybacking onto their cookies and location data.</p><p>When a consumer visits a site cookies are enabled on their computer, allowing the site's company to tailor advertisements to them, something government snoops were keen to exploit.</p><p>Slides released by Snowden and published by the <a href="http://www.washingtonpost.com/blogs/the-switch/wp/2013/12/10/nsa-uses-google-cookies-to-pinpoint-targets-for-hacking"><em>Washington Pos</em>t</a> revealed the NSA had been latching onto these cookies in order to identify possible targets for further hacking operations.</p><p>Using a <a href="http://www.google.co.uk/url?sa=t&rct=j&q=&esrc=s&source=web&cd=1&cad=rja&uact=8&ved=0CCUQFjAA&url=http%3A%2F%2Fwww.itpro.com%2Fsecurity%2F21218%2Fnsa-and-gchq-tracked-google-cookies&ei=gJe2U6j6KoyY0AXhqIDwDA&usg=AFQjCNG4k16kB_vQZV576ZQaiF8N4duJEA&sig2=NB">unique cookie from Google</a> called PREF, intelligence agents could pick out one person from a sea of internet data in order to focus on them specifically. The NSA slides indicated that Google complied with this action entirely after being compelled to by the US government.</p><h3 class="article-body__section" id="section-squeaky-dolphin"><span>Squeaky Dolphin</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="mYfA6XJ83wCzVQv9iuVdMS" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/mYfA6XJ83wCzVQv9iuVdMS.jpg" mos="https://cdn.mos.cms.futurecdn.net/mYfA6XJ83wCzVQv9iuVdMS.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>There's a prize for anyone who can understand the reasoning behind this codename. Squeaky Dolphin was an initiative thought up by the UK's GCHQ. It involved tapping into the cables carrying the world's web traffic in order to monitor what people are up to on social media.</p><p>Documents leaked to <a href="http://investigations.nbcnews.com/_news/2014/01/27/22469304-snowden-docs-reveal-british-spies-snooped-on-youtube-and-facebook?lite">NBC news</a> by Snowden revealed how British spies showed off their new invention to their US counterparts. GCHQ demonstrated how it could monitor YouTube in real time and collect addresses from the billions of videos watched every day.</p><p>Analysts demonstrated how, through a central information hub, they could determine which videos were popular in which cities and at what times, as well as what each demographic preferred to click on.</p><p>The UK spooks did mention to their allies that this program was for general trends only and not for spying on individuals, but there are as yet unconfirmed rumours GCHQ used the tech to target Twitter users with propaganda.</p><h3 class="article-body__section" id="section-gilgamesh"><span>Gilgamesh</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="uUVoc2pXzySqc54GT8JR2Q" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/uUVoc2pXzySqc54GT8JR2Q.jpg" mos="https://cdn.mos.cms.futurecdn.net/uUVoc2pXzySqc54GT8JR2Q.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Unfortunately, this operation has nothing to do with the fifth king of Uruk Mesopotamia.</p><p>According both to documents released by Snowden and the testimony of a former drone operator, the NSA used telecommunications devices as targets for drone strikes.</p><p>Rather than confirming with operatives on the ground, said the whistleblower, the NSA would identify a target based on the geolocation of their phone and order an assassination.</p><p>The drone operator was adamant the technology was aiding the War on Terror but that civilians were "absolutely" being killed en masse by the strikes.</p><p>Terrorists cottoned on to the NSA's idea, though, and began to mix up their SIM cards to avoid being tracked. Commanders would switch them with footsoldiers and footsoldiers with civilians.</p><p>The NSA often located targets based on their activity levels and not on the content of the calls, resulting in, according to the former pilot "death by unreliable data."</p><h3 class="article-body__section" id="section-egotisticalgoat"><span>EgotisticalGoat</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="eLmE65LLf74yLyexi7Wgnh" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/eLmE65LLf74yLyexi7Wgnh.jpg" mos="https://cdn.mos.cms.futurecdn.net/eLmE65LLf74yLyexi7Wgnh.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>EgotisticalGoat and its sister program, EgotisticalGiraffe, were designed to help facilitate attacks on people using the anonymous network Tor.</p><p>Techniques included targeting web browsers like Firefox and giving the NSA full control over a target's computer keystrokes, online activity and files.</p><p>The Tor network is relied upon by journalists, activists and campaigners around the world to maintain the secrecy of their communications and avoid reprisals from their respective governments.</p><p>The network, oddly enough, is provided with 60 per cent of its funding by the US government.</p><p>Agents operating EgotisticalGoat admitted the Tor network was too large for them to completely crack. In one top-secret presentation named "Tor Stinks" it stated "We will never be able to de-anonymize all Tor users all the time ... with manual analysis we can de-anonymize only a very small fraction of Tor users."</p><p>With more information to come from Snowden, who claims his leaks to date are just the tip of the iceberg, do we have more cause for concern over our data than ever before? Are all of these operations a gross misconduct or a necessary evil? Let us know what you think by emailing us at <a href="mailto://comments@itpro.co.uk" data-original-url="mailto:comments@itpro.co.uk?Subject=Snowden%leaks">comments@itpro.co.uk</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GCHQ taken to court by ISPs over network spying ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/22621/gchq-taken-to-court-by-isps-over-network-spying</link>
                                                                            <description>
                            <![CDATA[ GCHQ under threat of lawsuit from ISP companies angered over Snowden spying revelations ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ryemDmFLxx1WCqQgTQRvL8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/yhKX3DZHm8gumPwrje3Lw7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Jul 2014 12:26:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Alex Hamilton ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/yhKX3DZHm8gumPwrje3Lw7-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/yhKX3DZHm8gumPwrje3Lw7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Seven Internet Service Providers (ISPs) from the UK, US, Netherlands, South Korea and others have banded together to take the UK intelligence service GCHQ to court.</p><p>It is the first time GCHQ has had to defend itself in court to a corporate body and it will have to answer snooping accusations that stem from the Edward Snowden leaks.</p><p>The group claim the government agency performed a series of "network attacks" that undermined "the goodwill the organisations rely on".</p><p>Charges filed against GCHQ include claims that Belgian telecoms company Belgacom was infected with malware, that the agency used intrusion technology to covertly monitor communications and that it spied on internet traffic flowing through Germany.</p><p>The ISPs involved in the case are GreenNet (UK), Riseup (US), Greenhost (Netherlands), Mango (Zimbabwe), Jinbonet (South Korea) People Link (US) and Chaos Computer Club (Germany).</p><p>All seven are noted as being easy targets' as they are not independent firms and not the major service provider in their respective countries.</p><p>A supporter of the case, Privacy International, claimed "the type of surveillance being carried out allows them to challenge the practices... because they and their users are at threat of being targeted."</p><p>The campaign group has filed two similar cases in the past against the surveillance programmes Tempora, Prism and against GCHQ's deployment of spyware.</p><p>"These widespread attacks on providers and collectives undermine the trust we all place on the internet and greatly endangers the world's most powerful tool for democracy and free expression," said Eric King, deputy director of Privacy International</p><p>Cedric Knight, of ISP GreenNet, added: "Snowden's revelations have exposed GCHQ's view that independent operators like GreenNet are legitimate targets for internet surveillance, so we could be unknowingly used to collect data on our users. We say this is unlawful and utterly unacceptable in a democracy."</p><p>GCHQ told the <em><a href="http://www.bbc.co.uk/news/technology-28106815">BBC</a></em> that all its work is conducted "in accordance with a strict legal and policy framework which ensures that our activities are authorised, necessary and proportionate".</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GCHQ launches threat intelligence sharing pilot ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/data-protection/22515/gchq-launches-threat-intelligence-sharing-pilot</link>
                                                                            <description>
                            <![CDATA[ The initiative will help providers of national infrastructure defend themselves against cyber attacks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iMSXxkcjCXzuWrfKEL7kWM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VE3YKMYJx4fzWPVBFuGCqR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 19 Jun 2014 07:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VE3YKMYJx4fzWPVBFuGCqR-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cyber war]]></media:description>                                                            <media:text><![CDATA[Cyber war]]></media:text>
                                <media:title type="plain"><![CDATA[Cyber war]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VE3YKMYJx4fzWPVBFuGCqR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Government Communications Headquarters (GCHQ) has announced the first stage of a pilot scheme allowing communications service providers to receive intelligence regarding cyber attacks earlier than was previously possible.</p><p>The initiative was revealed in the closing keynote of the private government IA14 security conference in London by Iain Lobban who will be leaving his post as director at the agency this year.</p><p>Lobban said the pilot scheme will protect those at risk of cyber attacks through the sharing of data the government and individual organisations already hold.</p><p>"Ultimately, we're seeking to use our unique capabilities and the range of insights gleaned from our intelligence and security work to offer at scale and pace classified information about threats to the UK's most critical networks," he told the group of central government, public sector, industry and academia decision-makers.</p><p>"They will be able to use this privileged awareness to take early action on the networks they manage, whether government or other critical UK networks," he continued.</p><p>The initiative will help those involved in the scheme act as the UK's first line of defence in countering cyber threats to the nation from state actors and cyber criminals, Lobban explained.</p><p>Previously, CERT-UK was the main body to deliver support to the industry and to provide information and advice regarding cyberthreats, but GCHQ's new initiative will embrace a more automated process and will extend beyond CERT-UK's partners.</p><p>Although the initial stages of the pilot will only involve service providers, there are plans to extend this to other industries in the future.</p><p>Martin Sutherland, managing director of BAE Systems Applied Intelligence, commented: "It is essential that we continue to improve the ways in which government and industry work together and we welcome this bold step by GCHQ to improve the quality of threat intelligence that the private sector has access to it will help to protect consumers, businesses and the economy as a whole."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ CESG dishes out security advice for Blackberry, Android & Chrome OS ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/22444/cesg-dishes-out-security-advice-for-blackberry-android-chrome-os</link>
                                                                            <description>
                            <![CDATA[ Advice for organisations from the spooks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qHDkZbLgCcJS4ETJ8epNk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wxoifjSY89cHo4N7WKAwtb-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 11 Jun 2014 08:19:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Mobile Phones]]></category>
                                                    <category><![CDATA[Hardware]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wxoifjSY89cHo4N7WKAwtb-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[security key on keyboard]]></media:description>                                                            <media:text><![CDATA[security key on keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[security key on keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wxoifjSY89cHo4N7WKAwtb-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Communications and Electronics Security Group (CESG) has published security guidance to enable organisations to safely deploy BlackBerry 10.2.1, Android 4.4 and Chrome OS devices.</p><p>The information security arm of GCHQ has revised its rules to assist those working in IT departments on how best to rollout and use these mobile operating systems securely.</p><p>The <a href="https://www.gov.uk/government/publications/end-user-devices-security-guidance-android-44/end-user-devices-security-guidance-android-44">updated guidance</a> is available now on Gov.uk and forms part of the Cabinet Office's End User Device Security Framework. It shows how the platforms can be configured to meet security recommendations and details the threats and other security problems for each of them.</p><p>It said the advice aims to "take a balanced approach between security and usability for remote or mobile working devices" by helping to reduce common risks to an organisation's information while still providing flexibility and ease of use. </p><p>There is also information on system architectures for deploying the devices. The CESG said the advice was not an endorsement of the platforms and only there to improve the UK's overall cyber security stance. </p><p>"Rather than being an 'approval' or 'endorsement' by CESG of any of these products, this guidance helps organisations to understand and manage the risks associated with the different devices, as part of their normal risk management processes," it said.</p><p>It added that each platform's virtual private network (VPN) and encryption efforts should be areas organisations should be aware of and manage appropriately.</p><p>It said Chrome OS's VPN "has not been independently assured to Foundation Grade, and does not currently support some of the mandatory requirements expected from assured VPNs."</p><p>"The VPN can be disabled by the user and some Google traffic is sent prior to the VPN being established resulting in potential for data leakage onto untrusted networks. Without assurance in the VPN there is a risk that data transiting from the device could be compromised," it added.</p><p>It also noted similar problems with Android's VPN as well as pointing out the lack of security of SD cards and non-data partitions. Blackberry OS 10.2's VPN and native data encryption also fell short, according to the CESG. </p><p>Minor updates have also been made to guidance for iOS 7, Windows 7 and Windows 8.1.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GCHQ accused of using fake LinkedIn pages to access company data ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/strategy/21866/gchq-accused-of-using-fake-linkedin-pages-to-access-company-data</link>
                                                                            <description>
                            <![CDATA[ Latest Edward Snowden revelations suggest GCHQ used spoof LinkedIn pages to spy on telcos. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6nuuV3X65brDTy9jjpTv5t</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Y77hj8aZMbVpoAPp3mtk5D-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 19 Mar 2014 10:11:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Smart City]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Y77hj8aZMbVpoAPp3mtk5D-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Surveillance]]></media:description>                                                            <media:text><![CDATA[Surveillance]]></media:text>
                                <media:title type="plain"><![CDATA[Surveillance]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Y77hj8aZMbVpoAPp3mtk5D-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>British intelligence and security organisation GCHQ hacked Belgian telecommunications company Belgacom via spoof employee LinkedIn profiles.</p><p>The top secret' project was leaked by NSA whistleblower Edward Snowden in a presentation and revealed the victim would not have known they were being watched because the malware was invisible to them.</p><p>Profiles would have displayed as normal despite being fake set-ups, not hosted on LinkedIn - but the malware allowed intelligence officers to access their computers.</p><p>The majority of those targeted worked in network maintenance and security for the company.</p><p>LinkedIn has denied having anything to do with the hack, saying it takes the privacy of its users very seriously and "does not sanction the creation or use of fake LinkedIn profiles or the exploitation of its platform for the purposes alleged in this report. To be clear, LinkedIn would not authorise such activity for any purpose,' and was not notified of the alleged activity."</p><p>When the GCHQ had managed to access the computers of engineers, they were able to access information about the company and its subsidiary BICS, which operates a GRX router system that allows people to make and receive calls or use data abroad.</p><p>This enabled the organisation to access data about the locations of targets and who they are communicating with.</p><p>Mobile networks expert Philippe Langlois told German website <em><a href="http://www.spiegel.de/international/world/ghcq-targets-engineers-with-fake-linkedin-pages-a-932821.html">Spiegel</a></em>: "This way, an intelligence service could read the entire Internet communications of the target and even track their location or implant spying software on their device."</p><p>He explained, since there are several hundred wireless companies, but only about two-dozen GRX providers worldwide, it is a much easier way to track the activities of targets.</p><p>The presentation revealed by Snowden (and reportedly seen by <em>Spiegel</em>) mentioned other telecommunications companies GCHQ was interested in, including Swiss company Comfone and Mach, which is now owned by Syniverse and Starhome Mach.</p><p>The document went into detail about a particular employee at Mach, listing all the devices he uses, identifying work devices and personal technology. GCHQ is said to have accessed cookies on his computer and lists his Skype name, Gmail user name and other social accounts he uses.</p><p>In January this year, GCHQ was accused of <a href="https://www.itpro.com/apps/21486/gchq-and-nsa-accused-of-using-angry-birds-and-google-maps-to-nab-user-data" data-original-url="https://www.itpro.com/apps/21486/gchq-and-nsa-accused-of-using-angry-birds-and-google-maps-to-nab-user-data">hacking mobile apps Angry Birds and Google Maps</a> to collect user data with the NSA.</p><p>It was another of the security leaks revealed by Snowden and it's said the organisations were trying to take advantage of "leaky apps" that inadvertently spill details about the age, sex and location of their users.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GCHQ spied on Yahoo webcam sessions, claims report ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/public-sector/21729/gchq-spied-on-yahoo-webcam-sessions-claims-report</link>
                                                                            <description>
                            <![CDATA[ Documents leaked by Edward Snowden reveal scope of Optic Nerve programme. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jKjMSXkxmVivtmSZzKdy3k</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xMZc5fjLjbs8BmKn7D5xXL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 28 Feb 2014 12:32:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Digital Transformation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xMZc5fjLjbs8BmKn7D5xXL-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Big Brother eye]]></media:description>                                                            <media:text><![CDATA[Big Brother eye]]></media:text>
                                <media:title type="plain"><![CDATA[Big Brother eye]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xMZc5fjLjbs8BmKn7D5xXL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>GCHQ, the UK Government listening post, intercepted the web chats of millions of Yahoo customers in a programme codenamed Optic Nerve, it has been alleged.</p><p><a target="_blank" href="http://www.theguardian.com/world/2014/feb/27/gchq-nsa-webcam-images-internet-yahoo">According to documents shared with <em>The Guardian</em></a> by Edward Snowden, users who were not suspected of any wrongdoing had their webcam images intercepted and stored by the British intelligence agency, working in collaboration with its American counterpart the NSA.</p><p><em>The Guardian</em> claims the documents it has received show the programme from 2008 until at least 2012 and was being used for experiments in facial recognition.</p><p>Those targeted would, without their knowledge or consent, have a freeze-frame image from their chat taken every five minutes and stored by the NSA, the publication said.</p><p>It is alleged that in just one six-month period in 2008 the agency collected webcam images "including substantial quantities of sexually explicit communications" from over 1.8 million Yahoo user accounts worldwide.</p><p>Indeed, the scale of intimate imagery being collected through Optic Nerve between 3 and 11 per cent was believed to contain "undesirable nudity" led to GCHQ trying to find a way to make it "safer to use".</p><p>The revelation that Yahoo's webcam chat facility has allegedly been used as a conduit for broad-based, untargeted spying has provoked a furious response from the internet giant.</p><p>In a statement, Yahoo said: "We were not aware of nor would we condone this reported activity. This report, if true, represents a whole new level of violation of our users' privacy that is completely unacceptable and we strongly call on the world's governments to reform surveillance law consistent with the principles we outlined in December.</p><p>"We are committed to preserving our users' trust and security and continue our efforts to expand encryption across all of our services."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GCHQ and NSA accused of using Angry Birds and Google Maps to nab user data ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/apps/21486/gchq-and-nsa-accused-of-using-angry-birds-and-google-maps-to-nab-user-data</link>
                                                                            <description>
                            <![CDATA[ Surveillance agencies have reportedly tried to collect personal information leaked from smartphone and tablet apps. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oB66kLmJPdtjcS2bzTVNTL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KVDQadPyDpdDqyKYiVoDmC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 28 Jan 2014 10:37:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Business Apps]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KVDQadPyDpdDqyKYiVoDmC-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Angry Birds in space]]></media:description>                                                            <media:text><![CDATA[Angry Birds in space]]></media:text>
                                <media:title type="plain"><![CDATA[Angry Birds in space]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KVDQadPyDpdDqyKYiVoDmC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>US and British surveillance agencies have been accused of using Angry Birds and other popular smartphone apps to gather users' personal information.</p><p>That's according to the latest round of revelations from National Security Agency whistleblower Edward Snowden, which have been made public by the <a target="_blank" href="http://www.nytimes.com/2014/01/28/world/spy-agencies-scour-phone-apps-for-personal-data.html?_r=0"><em>New York Times</em></a> and <em>Guardian</em> newspaper.</p><p>It's claimed the NSA and its British counterpart GCHQ have colluded on how to take advantage of "leaky apps" that inadvertently spill details about the age, sex and location of their users.</p><p>These include mapping, gaming and social networking apps, although the amount of data that's been collected in this way is not yet clear, nor is the number of users likely to be affected.</p><p>The documents suggest GCHQ and the NSA have "traded methods" for collecting location data from Google Maps users, along with address book and phone log data when users post pictures to mobile versions of Facebook, Flickr, LinkedIn and Twitter.</p><p>The report claims the two surveillance agencies have been working on ways to collect and store these types of data since 2007.</p><p>Its work to-date has reportedly focused on collecting data from older apps, but newer ones including Angry Birds are being targeted too, the latest tranche of documents from Snowden suggest.</p><p>In particular, they set out how to obtain information from Angry Birds running on Android-based devices.</p><p>The latest revelations come hot on the heels of <a target="_blank" href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security/21428/president-obama-sets-out-us-surveillance-reforms">President Obama's pledge earlier this month to curb the surveillance activities of the NSA</a>.</p><p>In a statement to the <em>New York Times</em>, the NSA insisted it does not profile "everyday Americans" during its foreign intelligence missions.</p><p>"Because some data of US persons may at times be incidentally collected in NSA's lawful foreign intelligences mission, privacy protections for US persons exist across the entire process," the statement added.</p><p>GCHQ declined to comment, aside from saying its activities complied with British law.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NSA accused of collecting 200 million text messages a day ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/21425/nsa-accused-of-collecting-200-million-text-messages-a-day</link>
                                                                            <description>
                            <![CDATA[ Latest twist in NSA surveillance scandal suggests its been snooping on millions of text messages every day. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9feVJCeNN2fNBtp8gy581s</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mwqWFkJsHHpmTgTuTbQgJ5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jan 2014 15:07:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Smart City]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mwqWFkJsHHpmTgTuTbQgJ5-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Text message on phone]]></media:description>                                                            <media:text><![CDATA[Text message on phone]]></media:text>
                                <media:title type="plain"><![CDATA[Text message on phone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mwqWFkJsHHpmTgTuTbQgJ5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US National Security Agency (NSA) has been collecting up to 200 million SMS text messages every day, according to a report in <em>The Guardian</em>.</p><p>The revelations came through a joint investigation with Channel 4 News. The NSA managed to collect large volumes of text messages through its Dishfire surveillance programme. The agency then sifts through the messages and analyses them.</p><p>Documents leaked by whistleblower Edward Snowden revealed the NSA selects random targets and collects SMS messages from them regardless of who they are.</p><p>The NSA has also been colluding with GCHQ on the surveillance programme with the former sharing access to the SMS messages with the latter. According to <a href="https://www.documentcloud.org/documents/1006111-sms.html">slides</a> released by the newspaper, the operation has been running since 2008.</p><p>The programme managed to collect 1.6 million notifications when people roamed from one network to another and around 800,000 messages relating to financial transactions.</p><p>With such a large amount of data collected, the NSA had to create an automated scanning tool, dubbed Prefer, to extract key metadata from the messages to "enhance current analytics".</p><p>However, an NSA spokeswoman played down the reports and told <em>The Guardian</em> the tool was only used "against foreign intelligence targets".</p><p>Dishfire has also helped Britain's spies as it has collected a lot of information on UK citizens without needing to make formal requests under the Regulation of Investigatory Powers Act.</p><p>A GCHQ spokesman said the organisation would not comment on intelligence matters.</p><p>"All of GCHQ's work is carried out in accordance with a strict legal and policy framework which ensures that our activities are authorised, necessary and proportionate, and that there is rigorous oversight, including from the Secretary of State, the Interception and Intelligence Services Commissioners and the Parliamentary Intelligence and Security Committee," he told <em>The Guardian</em>.</p><p>In other NSA-related news, President Obama is set to outline changes later today he wants the surveillance organisation to make to the way it operates.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NSA and GCHQ tracked Google cookies ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/21218/nsa-and-gchq-tracked-google-cookies</link>
                                                                            <description>
                            <![CDATA[ Cookie eating monster surveillance is alleged to have occurred. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6D28vUYF7NVfdWFaR8FF9S</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Du3nPNWBN6Zjdrxf8YJEaF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 12 Dec 2013 12:51:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Du3nPNWBN6Zjdrxf8YJEaF-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cookies]]></media:description>                                                            <media:text><![CDATA[Cookies]]></media:text>
                                <media:title type="plain"><![CDATA[Cookies]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Du3nPNWBN6Zjdrxf8YJEaF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Leaked NSA documents have revealed that the spy agency used Google's advertising cookies to identify and track targets in a hacking operation.</p><p>According to reports by the <a href="http://www.washingtonpost.com/blogs/the-switch/wp/2013/12/10/nsa-uses-google-cookies-to-pinpoint-targets-for-hacking">Washington Pos</a>t, based on documents leaked by NSA whistle-blower Edward Snowden, both the NSA and GCHQ used the cookies to help track users across the internet.</p><p>The operation used Google's PREF cookies, which are used by the search giant to provide personalised web pages for users based on previous browsing habits and preferences.</p><p>While the cookies don't contain information such as usernames or email addresses, they do contain details such as location, language preference, search engine settings, number of search results to display per page as well as other bits of information that advertisers can use to identify a particular browser.</p><p>The newspaper said that these cookies along with those from other companies have allowed the NSA to track user habits and allow remote exploitation of computers.</p><p>While the document does not say how the NSA obtained the cookies, other documents unearthed by Washing Port reporters said the agency could have made a direct request to Google using a Fisa order. Under the Fisa law, Google would not have been allowed to inform users of such an action by the NSA.</p><p>The cookies were collected by NSA's Special Source Operations (SSO) unit and are sent to the agency's Tailored Access Operations (TAO) unit. This specialises in offensive operations such as infecting target computers and networks with malware designed to obtain information and create backdoors.</p><p>As reported by sister publication PC Pro, a <a href="http://www.pcpro.co.uk/news/security/385948/mps-push-for-tighter-laws-against-online-spying">Lib Dem MP is pushing for greater protection</a> for UK citizens from online spying. Former minister David Heath called for new laws to prevent spy agencies from tapping emails and calls without a warrant.</p><p>Heath wants loopholes in the Regulation of Investigative Powers Act 2000 and the Intelligence Services Act 1994 that allow wholesale data collection to be closed. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NSA spies targeted World of Warcraft and Xbox Live ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/21196/nsa-spies-targeted-world-of-warcraft-and-xbox-live</link>
                                                                            <description>
                            <![CDATA[ Wizard plan saw spooks became elves and trolls to hunt for terrorists. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uVHgN9ishvzj2XCvcvnzjE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KDyqt2dLucEFziCrPXhToB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 10 Dec 2013 17:06:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Smart City]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KDyqt2dLucEFziCrPXhToB-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[World of Warcraft]]></media:description>                                                            <media:text><![CDATA[World of Warcraft]]></media:text>
                                <media:title type="plain"><![CDATA[World of Warcraft]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KDyqt2dLucEFziCrPXhToB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>GCHQ and the NSA both infiltrated games such as World of Warcraft and the Xbox Live platform as part of their Prism operations, it has emerged.</p><p>The <a href="http://www.theguardian.com/world/2013/dec/09/nsa-spies-online-games-world-warcraft-second-life"><em>Guardian</em> reported</a> the campaign of spying was leaked in a document from Edward Snowden.</p><p>The document, entitled Exploiting Terrorist Use of Games & Virtual Environments, was written in 2008 and claimed games were a "target rich communications network" and that agencies slurped up vast amounts of data.</p><p>The NSA said the games could allow surveillance targets to hide in plain sight.</p><p>"We know that terrorists use many feature-rich internet communications media for operational purposes such as email, VoIP, chat, proxies, and web forums and it is highly likely they will be making wide use of the many communications features offered by Games and Virtual Environments (GVE) by 2010," the document said.</p><p>"The SIGINT Enterprise needs to begin taking action now to plan for collection, processing, presentation, and analysis of these communications."</p><p>The document also show how spy agencies tried to recruit informants to help find terrorists using games as a cover.</p><p>However, so many spies infiltrated the games leading to spy agencies setting up a "de-confliction" group to make sure agents didn't erroneously spy on each other.</p><p>It is unclear if the action taken by spies to infiltrate games ever resulted in the foiling of a terrorist plot. The document said the "amount of GVEs in the world is growing but the specific ones that CT [counter-terrorism] needs to be methodically discovered and validated. Only then can we find evidence that GVEs are being used for operational uses."</p><p>In a statement, Blizzard Entertainment, the company behind World of Warcraft, said: "We are unaware of any surveillance taking place. If it was, it would have been done without our knowledge or permission."</p><p>Microsoft also made similar statements.</p><p>The news comes as a group of major tech companies have <a href="https://www.itpro.com/public-sector/21185/apple-microsoft-and-google-urge-governments-to-address-surveillance" data-original-url="https://www.itpro.com/public-sector/21185/apple-microsoft-and-google-urge-governments-to-address-surveillance">asked the US government to reform surveillance laws</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Apple, Microsoft and Google urge governments to address surveillance ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/public-sector/21185/apple-microsoft-and-google-urge-governments-to-address-surveillance</link>
                                                                            <description>
                            <![CDATA[ Internet-focused firms lobby Washington for reform. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">m4748qotNazBFg2EdEioYi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9XhhSSSFeN75egJ99xgRVF-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Mon, 09 Dec 2013 13:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Social Media]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/9XhhSSSFeN75egJ99xgRVF-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9XhhSSSFeN75egJ99xgRVF-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Tech firms including Apple, Facebook and Google have co-authored and co-signed a letter to US President Barack Obama and the US Congress petitioning them to reform government surveillance practices across the globe.</p><div><blockquote><p>Reports about government surveillance have shown there is a real need for greater disclosure and new limits on how governments collect information.</p></blockquote></div><p>The action has been taken in light of continuing revelations from former NSA contractor Edward Snowden regarding the widespread use of interception techniques by the American National Security Agency (NSA) and its UK equivalent GCHQ to monitor internet traffic and electronic communications.</p><p>The letter, <a href="http://reformgovernmentsurveillance.com">which has been published on reformgovernmentsurveillance.com</a>, says: "We understand that governments have a duty to protect their citizens. But this summer's revelations highlighted the urgent need to reform government surveillance practices worldwide.</p><p>"The balance in many countries has tipped too far in favour of the state and away from the rights of the individual rights that are enshrined in our Constitution. This undermines the freedoms we all cherish. It's time for a change."</p><p>The companies, which include AOL, Apple, Facebook, Google, LinkedIn, Microsoft, Twitter and Yahoo, are urging the US to take the lead in carrying out this reform.</p><p>In an individual comment posted on the same website, Larry Page, Google's CEO, said: "The security of users' data is critical, which is why we've invested so much in encryption and fight for transparency around government requests for information.</p><p>"This is undermined by the apparent wholesale collection of data, in secret and without independent oversight."</p><p>Facebook CEO Mark Zuckerberg added: "Reports about government surveillance have shown there is a real need for greater disclosure and new limits on how governments collect information.</p><p>"The US government should take this opportunity to lead this reform effort and make things right."</p><p>However, Rafael Laguna, CEO of open source software firm Open-Xchange, criticised their arguments as "flawed".</p><p>"This very public display of unity is essentially an acknowledgement from these large internet companies the public has begun to lose trust in them, and as a result in the internet as a whole.</p><p>"However, a fundamental flaw in their argument is the double standard of condemning governments for data surveillance, while at the same time harbouring the unquantifiable amounts of data that governments wish to access in the first place."</p><p>He added: "Charity begins at home, and the first step to rebuilding trust in an open internet is to address their own data retention policies before pointing the finger elsewhere."</p><p>Further revelations from the Snowden Papers this week include <a href="http://www.theguardian.com/world/2013/dec/09/nsa-spies-online-games-world-warcraft-second-life?CMP=twt_gu">the infiltration of Massive Multiplayer Online (MMO) games</a>, such as World of Warcraft, and digital communities by the NSA and GCHQ in order to spy on and, in some cases attempt, to recruit users.</p><p>Separately, <a href="http://www.washingtonpost.com/business/technology/fbis-search-for-mo-suspect-in-bomb-threats-highlights-use-of-malware-for-surveillance/2013/12/06/352ba174-5397-11e3-9e2c-e1d01116fd98_story.html"><em>Washington Post</em> has allegedly uncovered the FBI's use of malware</a> in order to track down a suspect who made repeated bomb threats online.</p><p>The agency also requested to be allowed to activate the suspect's webcam remotely, but a judge ruled such an action would be excessively intrusive and could violate his fourth amendment right to protection from unreasonable searches and seizures.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Home Office bids to revive Snooper's Charter despite Snowden revelations ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/it-legislation/21012/home-office-bids-revive-snoopers-charter-despite-snowden-revelations</link>
                                                                            <description>
                            <![CDATA[ Counter-terrorism head says police still need more power to access people’s data ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jEQhUeB6YXU8ZdCozYpBor</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hPV3oeC6bRSaxEdMbWwvdP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 13 Nov 2013 15:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kurt Wallace ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hPV3oeC6bRSaxEdMbWwvdP-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[eye binary code]]></media:description>                                                            <media:text><![CDATA[eye binary code]]></media:text>
                                <media:title type="plain"><![CDATA[eye binary code]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hPV3oeC6bRSaxEdMbWwvdP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Home Office's counter-terrorism chief has reiterated the government's willingness to pass the Communications Data Bill, better known as Snooper's Charter, despite evidence of mass surveillance uncovered by whistleblower Edward Snowden.</p><p>The bill would make it easier for law enforcement and intelligence agencies to access communications data, forcing ISPs and internet firms like Facebook and Google to store information on users for at least 12 months.</p><div><blockquote><p>There's no doubt Charles Farr will seek to get the Snooper's Charter into law. But he'd be unwise to do so.</p></blockquote></div><p>It was supposed to have been killed off by deputy prime minister Nick Clegg, but a number of government officials have attempted to keep it alive, using terrorist events such as the <a target="_blank" href="http://www.independent.co.uk/news/uk/crime/drummer-lee-rigby-murder-trial-suspects-michael-adebolajo-and-michael-adebowale-deny-woolwich-killing-8843965.html">death of Lee Rigby</a> as evidence that more powers are needed.</p><p>Charles Farr, head of the office of security and counter-terrorism, told the Home Affairs Select Committee yesterday that home secretary Theresa May supported him in his bid to get Snooper's Charter back on the table.</p><p>He said that the powers were needed, claiming GCHQ had "never collected the data required by law enforcement". "GCHQ has never and will never collect the communications data required by law enforcement which we were seeking to provide for in the communications data legislation," he added, according to the <a target="_blank" href="http://www.theguardian.com/uk-news/2013/nov/12/counter-terror-chief-charles-farr-snoopers-charter?CMP=twt_gu">Guardian</a>.</p><p>"Of course they do collect communications and communications data. My point was specifically about the UK and the data we were seeking to obtain through legislation. GCHQ cannot provide that data itself."</p><p>Farr's claim appears to be at odds with what the head GCHQ Iain Lobban said during <a target="_blank" href="https://www.itpro.com/technology/blockchain" data-original-url="https://www.itpro.com/government-it-strategy/20985/gchq-head-defends-cyber-espionage-operations">a meeting with the Intelligence and Security Committee last week</a>. Talking about GCHQ's work on tracking people using modern technologies, Lobban talked up the agency's work to "uncover the identities and track down some of those who are involved in online sexual exploitation of children within the UK".</p><p>The Home Office has repeatedly said law enforcement needed the additional powers to fight terrorists and track paedophiles - the same targets as GCHQ.</p><p>Privacy advocates remain deeply concerned about the bill and the Snowden revelations.</p><p>"There's no doubt Charles Farr will seek to get the Snooper's Charter into law. But he'd be unwise to do so, as he'd open up the whole surveillance debate," Jim Killock, executive director of the Open Rights Group, told IT Pro.</p><p>"We do need that debate, although it should be focused directly on accountability. It's farcical to imply, as Farr did, that there is no need for everyone to know that GCHQ are hoovering up as much data as possible. That ought to be the subject of a specific parliamentary decision, not built on the back of warrants designed for targeted surveillance operations."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Tim Berners-Lee slams encryption-busting surveillance agencies  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/public-sector/20978/tim-berners-lee-slams-encryption-busting-surveillance-agencies</link>
                                                                            <description>
                            <![CDATA[ Inventor of World Wide Web brands decision “appalling and foolish." ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">meuRE6ugx76QjBPymsL8iA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/eJJgLj3Ys9LMtALXn97jk9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 07 Nov 2013 11:19:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/eJJgLj3Ys9LMtALXn97jk9-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/eJJgLj3Ys9LMtALXn97jk9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Tim Berners-Lee, the British computer scientist who invented the World Wide Web, has hit out at spies who cracked encryption to monitor communications on the internet.</p><p>His comments, made in an interview with <a href="http://www.theguardian.com/world/2013/nov/06/tim-berners-lee-encryption-spy-agencies?CMP=twt_gu">The Guardian</a>, come ahead of a the first ever appearance of the heads of UK intelligence agencies MI5, MI6 and GCHQ together in front of Parliament's Intelligence and Security Committee at 2.00pm today.</p><p>Referring to the <a href="http://www.google.co.uk/url?sa=t&rct=j&q=&esrc=s&source=web&cd=1&cad=rja&ved=0CDAQFjAA&url=http%3A%2F%2Fwww.itpro.com%2Ftags%2Fprism&ei=RGx7UtGtJ5SShgfV9YGwCA&usg=AFQjCNGdrt8tAqjXrJ_4xk0xWV1pCKxI5Q&sig2=yGfO6Lyyi6x5yFc2aBeUvg&bvm=bv.56146854,d.ZG4">Prism</a> internet monitoring scandal, Berners-Lee said the decision by spy agencies in the UK and US to crack open encrypted communications was both "appalling and foolish." He added that it was also counterproductive for their efforts to fight cyber crime and cyber warfare as it weakens online security.</p><p>"It's nave to imagine that if you introduce a weakness into a system you will be the only one to use it," Berners-Lee said, likening the behaviour of the agencies to those of a totalitarian state," he said. </p><p>"Any democratic country has to take the high road; it has to live by its principles. I'm very sympathetic to attempts to increase security against organised crime, but you have to distinguish yourself from the criminal." </p><p>He also slammed the oversight of surveillance by UK and US authorities as "dysfunctional and unaccountable," while commending the <em>Guardian's</em> reporting on the issue of Prism and whistleblower Edward Snowden.</p><p>GCHQ is descended from the UK Governmenr Code & Cypher School (GC&CS), which was founded during the First World War and whose employees, including Alan Turing, famously broke the German Enigma Code during the Second World War.</p><p><em>IT Pro</em> will be reporting the news from the Intelligence and Security Committee hearing later today.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GCHQ extends cyber security network certification scheme ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/20685/gchq-extends-skills-cyber-security-certification-scheme-private-sector</link>
                                                                            <description>
                            <![CDATA[ GCHQ infosecurity experts want more security professionals to get CESG Certified Professional scheme accreditation. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9nbaeAfPTjK2JGUqgR9Z5J</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DdCJcxE9PUV28ZvdCrxhsS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 30 Sep 2013 09:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/DdCJcxE9PUV28ZvdCrxhsS-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[IT skills]]></media:description>                                                            <media:text><![CDATA[IT skills]]></media:text>
                                <media:title type="plain"><![CDATA[IT skills]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DdCJcxE9PUV28ZvdCrxhsS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The information security arm of GCHQ has expanded its Government network certification programme to include private sector firms responsible for safeguarding industry networks.</p><p>The CESG Certified Professional (CCP) scheme was launched in October 2012 to certify the skills of cyber security professionals tasked with looking after Government networks.</p><p>According to CESG, nearly 700 cyber security professionals have succeeded in becoming certified through the scheme, which is operated by several certification bodies.</p><div><blockquote><p>With demand growing from industry to be part of the scheme, now is the right time to open up CCP and set a unified standard for cyber security professionals.</p></blockquote></div><p>They include the APM Group, the BCS, and IISP, CREST and Royal Holloway ISG consortium.</p><p>However, the scheme is now being extended to include IT professionals responsible for protecting all industry networks from threats and vulnerabilities, as part of the CESG's plans to create a community of people with recognised qualifications in cyber security.</p><p>All qualifications awarded through the scheme are valid for three years.</p><p><strong>Guest Editor Ken Deeks says:</strong></p><p>"The extension of the CCP scheme by GCHQ to include private sector firms is a brilliant move.</p><p>"This swiftly follows the announcement of the joint cyber reserve scheme which aims to recruit hundreds of computer experts as 'cyber reservists'.</p><p>"Both initiatives have a good chance of success because they are both practical and highly collaborative.</p><p>"It sends out a signal that the industry as a whole has a responsibility to safeguard all networks - private and government - and this can only be a good move in the fight against cybercrime."</p><p>"I would particularly encourage those organisations...to endorse the scheme and help build a community of UK cyber security professionals that is the envy of the world," he added.</p><p>Chloe Smith, minister for political and constitutional reform, hailed the popularity of the scheme to date.</p><p>"Since its launch last year, the CESG Certified Professional scheme has been warmly welcomed and endorsed by Government cyber security professionals," she said.</p><p>"With demand growing from industry to be part of the scheme, now is the right time to open up CCP and set a unified standard for cyber security professionals right across the UK."</p><p>The scheme is a central part of the Government's wide-ranging Cyber Security Strategy, which aims to bolster the number of recognised cyber security experts in the UK.</p><p>The announcement about its extension follows on from the launch of the Government's Joint Cyber Reserve scheme, which was announced over the weekend.</p><p>Its aim is to recruit hundreds of computer experts as "cyber reservists" who will be tasked with defending the UK's cyber defences.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NSA and GCHQ accused of taking part in sustained web encryption-cracking campaign ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/20559/nsa-and-gchq-accused-taking-part-sustained-web-encryption-cracking-campaign</link>
                                                                            <description>
                            <![CDATA[ Security agencies are alleged to have unraveled encryption used to protect web users' data. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hVW3QvmBgA1YbGVibVYyb1</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/28cc5pC9jCkXSFbkgD54WP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 06 Sep 2013 11:23:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Smart City]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Caroline Donnelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/28cc5pC9jCkXSFbkgD54WP-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Magnifying glass inspecting computer code]]></media:description>                                                            <media:text><![CDATA[Magnifying glass inspecting computer code]]></media:text>
                                <media:title type="plain"><![CDATA[Magnifying glass inspecting computer code]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/28cc5pC9jCkXSFbkgD54WP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>GCHQ and the US National Security Agency (NSA) have reportedly cracked many of the encryption methods used to protect web users' personal data and online transactions.</p><p>The claim has been published in a joint article by the <a target="_blank" href="http://www.theguardian.com/world/2013/sep/05/nsa-gchq-encryption-codes-security"><em>Guardian</em></a> newspaper, the <em>New York Times</em> and <em>Propublica</em>, and is based on confidential documents leaked by notorious NSA whistleblower Edward Snowden.</p><p>The report claims the security agencies allegedly have the means to unravel the encryption used to protect emails, banking transactions and medical records.</p><p>This has reportedly been made possible through the employment of supercomputers that use brute force to crack encryption methods.</p><p>It is also claimed the agencies have colluded with tech firms and internet service providers to insert vulnerabilities into commercially available encryption software.</p><p>The Snowden documents suggest the NSA invests around $250 million a year in working with technology companies to influence their product designs, and claims the Agency considers its decryption work to be "the price of admission for the US to maintain unrestricted access to...cyberspace."</p><p>GCHQ, meanwhile, has been accused of trying to find a way into Hotmail, Google, Yahoo and Facebook's encrypted traffic.</p><p>The documents claim the NSA has been involved in a decade-long encryption-busting programme, which made a major breakthrough in 2010 that has resulted in "vast amounts of encrypted internet data" becoming exploitable.</p><p>Exact details about the discovery that made this possible was not disclosed in the documents.</p><p>The <em>Guardian</em> report is the latest in a long line of revelations about GCHQ and the NSA's alleged surveillance techniques, which have been trickling out since Snowden started releasing documents back in June 2013.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GCHQ unveils schemes to help UK companies defend against cyber attack ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/20394/gchq-unveils-schemes-help-uk-companies-defend-against-cyber-attack</link>
                                                                            <description>
                            <![CDATA[ Cyber Incident Response Scheme aims to boost infrastructure defences. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7aE9seAh5F8ZxSNQLVUjpB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/aCdmb3mYgH4i2NhTufZv5Z-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 14 Aug 2013 09:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/aCdmb3mYgH4i2NhTufZv5Z-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[GCHQ]]></media:description>                                                            <media:text><![CDATA[GCHQ]]></media:text>
                                <media:title type="plain"><![CDATA[GCHQ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/aCdmb3mYgH4i2NhTufZv5Z-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>GCHQ has announced it is putting in place two incident response operations that could protect critical national infrastructure from hackers.</p><p>CESG, the Information Security arm of GCHQ, and the Centre for the Protection of National Infrastructure (CPNI), has been running pilot programmes of the initiatives since November 2012.</p><div><blockquote><p>[This is] a great example of government and industry working together.</p></blockquote></div><p>Following the success of the pilots, it was decided that a twin-track approach was needed to protect infrastructure critical to the UK as well as defending public and private sector organisations.</p><p>The first scheme is 'broad-based' and will be led by the Council of Registered Ethical Security Testers (CREST), the professional body representing the technical security industry. Endorsed by GCHQ and CPNI, it will focus on "appropriate standards for incident response aligned to demand from all sectors of industry, the wider public sector and academia."</p><p>The second scheme is a smaller and more focused Government run Cyber Incident Response scheme certified by GCHQ and CPNI responding to sophisticated, targeted attacks against critical national networks.</p><p>GCHQ said that the approach would help organisations under cyber attack to "source an appropriate incident response service tailored to their particular needs and allow GCHQ and CPNI to focus on the most challenging attacks."</p><p>"We know that UK organisations are confronted with cyber threats that are growing in number and sophistication," said cyber security minister Chloe Smith.</p><p>"The best defence for organisations is to have processes and measures in place to prevent attacks getting through, but we also have to recognise that there will be times when attacks do penetrate our systems and organisations want to know who they can reliably turn to for help."</p><p>Industry figures have given their support to the scheme. Rob Cotton, chief executive of NCC Group said that this was a "a great example of government and industry working together to help improve standards of cyber security for businesses across the board."</p><p>"Having clear channels of help and support in place when the worst does happen will provide organisations with a massive boost, and also remove the confusion and panic in the immediate aftermath of a breach."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>