Feeds

French ministers told to use only secure comms post-PRISM

Reminder of best practice issued after Snowden's revelations

Securing Web Applications Made Simple and Scalable

French newspaper L'Express has published a memo it says comes from Christophe Chantepy, chief of staff to French prime minister Jean-Marc Ayrault, and which recommends French cabinet ministers stop using smartphones for phone calls because they are not secure.

The paper's report includes three images of the memo, one for each of its pages.

Native French speaker Elodie Quievre, who works in the office where Vulture South camps, was kind enough to translate all three and we rammed L'Express' report through Google and Bing to help out.

Dated August 19th, the memo opens by referring obliquely to recent Snowden-related events and suggesting the make now an ideal time for to “remind elementary rules which must be applied within the administration.”

Those rules state the following0:

  • BYOD is forbidden
  • Mobile phones are a bad idea: landline phones secured by Thales' TEOREM technology for voice calls are far better idea
  • Smartphones should be secured by French spook house ANSSI before being used for anything
  • ANSSI will make sure you encrypt everything
  • TXT? Fuggedaboutit!
  • Intranet-based secure email is mandatory for even low-level secrets
  • Computers and phones should be in the same room as ministers when overseas, and beware snooping when abroad
  • Twelve-character passwords please, using letters and numbers, changed every six months and use different passwords for personal and work devices please!
  • Are you sure that attachment is safe to click on? Don't unless you are.

Cabinet ministers are busy folks who may not encounter basic infosec advice often, so the suggestions in the document don't look like evidence France has been caught with its pants down. The mere fact the memo was issued, and the fact it says it will be backed up by an official ANSSI edict, does however show that Edward Snowden's revelations have made at least one nation feel it is time to get the basics right among a user population that represents an obvious target. ®

Application security programs and practises

More from The Register

next story
ONE EMAIL costs mining company $300 MEEELION
Environmental activist walks free after hoax sent share price over a cliff
Arrr: Freetard-bothering Digital Economy Act tied up, thrown in the hold
Ministry of Fun confirms: Yes, we're busy doing nothing
Help yourself to anyone's photos FOR FREE, suggests UK.gov
Copyright law reforms will keep m'learned friends busy
Apple smacked with privacy sueball over Location Services
Class action launched on behalf of 100 million iPhone owners
US judge: YES, cops or feds so can slurp an ENTIRE Gmail account
Crooks don't have folders labelled 'drug records', opines NY beak
UK government officially adopts Open Document Format
Microsoft insurgency fails, earns snarky remark from UK digital services head
You! Pirate! Stop pirating, or we shall admonish you politely. Repeatedly, if necessary
And we shall go about telling people you smell. No, not really
prev story

Whitepapers

Top three mobile application threats
Prevent sensitive data leakage over insecure channels or stolen mobile devices.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.