Re: "He spoke about four pillars upon which this trust is built:"
"a change to Windows 10 such that the user can turn off all telemetry"
Even better - a change that removes the "telemetry" so there's nothing to turn off.
42420 publicly visible posts • joined 16 Jun 2014
'Cloud customers should also be aware that they may not be able to control where data is stored and that sub-contracting arrangements may exist without them "initially realising", it said.
The draft guidance outlines ... and ensure regulators have effective access to data.
...
One of the recommendations the FCA made was for financial services companies to determine whether their cloud contracts are governed by UK law and subject to UK court jurisdiction. It said that even if it is not those cloud customers must ensure that they, their auditor and the FCA have "effective access" to its data as well as the cloud provider's "business premises".'
Given the premise in the first paragraph the other points seem likely to be difficult to achieve. In particular there'd be a need to ensure other court jurisdictions (other than higher EU courts) don't try to push their noses in and that other organisations don't have access to the data.
'It said companies need to have an "exit plan" that is "understood, documented and regularly rehearsed" which allows it to come out of outsourcing arrangements "without undue disruption to their provision of services, or their compliance with the regulatory regime".'
And one that will still work when the cloud operator's administrators walk in?
"We asked the TalkTalk boss what she had made of Virgin Media's chief Tom Mockridge recently coming out in support of Openreach remaining wedded to BT."
Was that really the best question you could have asked her? How about "Shouldn't the next head of a telecoms company like Openreach be someone with an engineering backgorund rather than another banker?".
" It needs to be baked into the mail protocols so that encryption is the default. It would need to be phased in in a backwards compatible manner
You've already got that. SMTP aleady supports the STARTTLS verb"
But that's only encryption in transit. AIUI what Eugene was looking for was PGP to encrypt the message end-to-end so it would only be readable by its intended recipient. And, of course, there would also be the possibility of signing it to verify the sender.
The impediments to this are (a) if your correspondents aren't set up to use it there's no point setting it up for yourself so almost nobody uses it and (b) as Pascal says, it needs an infrastructure for the public keys.
As I see it the solution for that would be to revise the protocol to build in message encryption rather than making it an add-on. It would need to be rolled out in stages so that in the interim stage new versions of clients would prompt users to set up their key-pair and make use of keys where both ends had them set up but after a given date email to a user who didn't have a key would require specific user approval followed by an end stage where unencrypted email wouldn't be supported.
I don't think it's a matter for Google alone. It needs to be baked into the mail protocols so that encryption is the default. It would need to be phased in in a backwards compatible manner but at some point the existing SMTP would be deprecated and any lagging clients & servers would find themselves shut out.
What Google needs to do is start pushing RFCs for this. Except I'm not sure Google would be the best party for this. They're likely to want something that would end up with plain text on their servers so they can scan it.
Presumably all this wifi enabled stuff, routers, kettles, webcams or whatever, has to have FCC, UL & a stack of other approvals. That provides a chance to introduce a very simple rule. When first installed factory settings only make provision for setup. Only when it's been configured to at least some degree of security does it start to route, boil water, show pictures or whatever.
"TalkTalk takes cyber security extremely seriously and we have increased investment in this area by a third over the last three years"
1. Increasing expenditure by a percentage is only meaningful if you say what the previous expenditure was. And even so....
2. It's not the inputs that matter, it's the outputs, in this case the security of the systems.
And that's ignoring the usual ritual "we take it very seriously".
Do these MBA types actually believe all this stuff they spout or does it just flow from textbook to mouth without passing through the brain?
"You could not make it up."
Far from it. It's common to large organisations of all kinds. They are unable to learn from experience. The people involved in one cycle might be badly burned enough to learn but next time round they've gone on to other employers or left to spend more time with their money. There's no mechanism which records "we don't do that because..." so a whole new lot of people come along to make the same mistake.
Of course there may well be people in the organisation who do remember but they're in pay grades which rate their knowledge as irrelevant.
"I really don't understand Microsoft on this."
It's not difficult to understand. Enterprise doesn't want untested software so the little people get to be beta testers. It's not enterprise coming second, it's non-enterprise clearing the minefield first.
"Thus W10 will act more consistently like a very late beta/release candidate over time; which is the nature of rolling release Linux distros."
AFAICS that was the plan for the consumer versions. The business versions get the fixes after the beta testers have checked them out. They've learned from Red Hat/Fedora.
Back when ATX PSUs, Win95 etc were new I was just leaving the client's premises for the night & got waylaid by the MD - or maybe he was just the FD back then. His PC wouldn't shut down either by software or the power-button-that's-not-not-really-a-power-button-but-just-sends-an-interrupt-to-the-motherboard-if-it's-listening. That sort of thing happened back then. Windows PCs weren't really my thing except that Windows was good for lots of Telnet sessions to the Unix box. But I wandered over to take a look. As he said, it wouldn't shut down from the button or anything else and you can't do "shutdown -g0 -i0 -y" on Windows. So I just leaned over & unplugged the mains from the back. Cue a silent "why didn't I think of that?" expression.
The problem is that HMRC is staffed by salaried people with secure employment contracts. They've designed an income tax system for salaried people with secure employment contracts because that's what they understand. I have a slight variation on this which might help here. Firstly everyone pays income tax on receipts which is what HMRC want and understand. We then treat security of employment as a benefit in kind and tax that. BIK is also something HMRC understand so they shouldn't have a problem with that. Because part of the tax is being collected as BIK the tax on income can be at a much lower than at present. It works out reasonable equitably. Zero hours contracts have no security at all so they have no benefit. A contractor on a 3-month gig with an easy termination rate will have some security so they pay more tax than the zero-rate.
It shouldn't raise political problems. MPs should like it, they have a 5-year fixed term contract with no guarantee of renewal so their benefit is also limited. Ministerial appointments such as the Chancellor's are essentially at the whim of the PM but usually there aren't more than one reshuffle a year so this can be taken as a 1-year rolling contract so the cabinet would approve.
Really secure jobs provide the largest benefit so they have to pay more tax and, for this to be tax neutral, the overall tax paid by those holding such jobs would end up more than is paid at present. The unfortunate side effect of this is that HMRC staff would end up paying much more than they currently do. However, as this is the consequence of a fairer tax system I'm sure they wouldn't mind.
"But even if it did do you really think that the Home Secretary and minions will not be making a MITM attack as soon as it goes live?"
That's the problem with any country whose govt doesn't grok privacy. It'll probably need someone to take them to the ECJ. I think we'll probably see a few iterations of that before govts. start to get the idea.
The use of non-US intermediaries has been on the cards for a good while now. Customers are starting to be concerned about security from spying, hence the the appearance of end-to-end encryption, Google pushing for HTTPS everywhere and so on.
The Irish access case has been a wake-up call for MS who must have been thinking about it since before the ECJ decision on Safe Harbour. The only surprise is that they now seem to be looking at establishing data centres to serve individual EU countries rather than just setting up a fire break for the Irish operation. Given the amount of time they've had, however, they've probably taken a lot of legal advice as to the best way to achieve their objective under German law. They may take different approaches in other countries.
I think we'll see other US corporations looking at similar solutions. There's been a window of opportunity for EU companies to get a slice of the action as well. I hope some of them take it.
When the details of the UK data centre are revealed I wouldn't be surprised to see something similar, at least in principle. As I've written here a number of times since the MS/Ireland case started, it's the obvious solution - set up a legal firebreak. A franchise operation is the one that comes to mind but presumably the trustee arrangement is one appropriate to Germany.
As MoD are being talked about as an initial customer for the UK site it seems likely that they've looked at what's proposed. Unfortunately they might be comfortable with an arrangement that gave GCHQ access so it might not be ideal for everyone else. If I were in a business looking for a secure hosting company I'd still be looking at Switzerland as a preferred location.
"MS could do something similar by spinning off their Irish datacenters as local businesses except that might unravel a lot of their current tax avoidance schemes."
I doubt it would unravel it by much. The obvious approach would be to have an Irish company, not owned by MS - repeat for the hard of reading NOT OWNED BY MS - as the intermediary operating as a franchise. Franchise operations seem to have worked pretty well for Starbucks as a mechanism for handling tax avoidance. I'm sure MS can find a few lawyers not too far from home who can advise them on such details.
"ISP's have to log activities because YOU voted for the idiots who made that a law that they collect the info."
Dunno about your environment but here the effective choice is between two parties each of who will put either such an idiot into the Home Office or at least one who will promptly go native.
"an FM baseband receiver that's either lying unused in a device, or could be cheaply added to it."
Oh yes? Here's a device without an FM receiver. Now how do you propose to cheaply add one? Soldering iron, piece of twin-flex & a cheap tranny? Or is "add" an abbreviation for "throw it away & buy a new one"?
"On civil construction / arquitecture[sic], normally, the project is sucessful when the building stands the test of time (aka doesn't fall due to structural flaws)."
The ratio of design/physical construction phases are very different.
The civil engineer/architect team draws up a design & then hands it over to the construction contractor who in turn hands over to the direct labour to the brickies, sparkies, plumbers etc. but a good deal of the detailed design to the host of manufacturing companies who make the bricks, the cement, the screws etc. (and good old nature which has been in the wood making business for millions of years).
In software the physical construction is trivial. The design team is responsible for a much higher proportion of the work. Where pre-built components (libraries) are available the effort needed by the design team in understanding their interfaces is much greater (how complex is the interface of the common house brick?).
There is also a difference in the regulative environment. The building client can't decide that proper lintels, electrical insulation and ventilation aren't needed but nobody will stop the software client deciding to forego proper encryption or sanity checks between the web front-end and the database.
I posted a comment under the T-Moblie/Experian report to the effect that one solution to dealing with major corporate failings would be that adopted after the Apple ebook pricing case: the appointment by TPTB of a competent, independent auditor/inspector to be paid for by the company. The role would be to investigate thoroughly and require any remedial action. I'll extend that idea to include vetting any statements made by or on behalf of the company during and after the event and to correct them and censure the spokesperson where appropriate.
Maybe the way to deal with this would be similar to the conditions imposed on Apple after the ebook pricing business. TPTB impose an auditor who the company has to pay for who can go through everything they consider relevant to the issue - in this case security - to ensure appropriate action is being taken.
@A/C
I think things are more nuanced than you imply. For a start some of the problems we've seen recently were implementation problems, Heartbleed for example. Then there's the question of computational resources and message value & currency.
Consider, for example that an announcement is due to be made tomorrow which will affect a company's share price. If you could get the content now you could make a killing but the message is encrypted with a system it would take you until next week to decrypt then you won't get any benefit. If it used a system you could decrypt in the next minute you could. According to your definition both would be broken but one is strong enough to do the job it's used for and the other isn't.