Feeds

French ministers told to use only secure comms post-PRISM

Reminder of best practice issued after Snowden's revelations

3 Big data security analytics techniques

French newspaper L'Express has published a memo it says comes from Christophe Chantepy, chief of staff to French prime minister Jean-Marc Ayrault, and which recommends French cabinet ministers stop using smartphones for phone calls because they are not secure.

The paper's report includes three images of the memo, one for each of its pages.

Native French speaker Elodie Quievre, who works in the office where Vulture South camps, was kind enough to translate all three and we rammed L'Express' report through Google and Bing to help out.

Dated August 19th, the memo opens by referring obliquely to recent Snowden-related events and suggesting the make now an ideal time for to “remind elementary rules which must be applied within the administration.”

Those rules state the following0:

  • BYOD is forbidden
  • Mobile phones are a bad idea: landline phones secured by Thales' TEOREM technology for voice calls are far better idea
  • Smartphones should be secured by French spook house ANSSI before being used for anything
  • ANSSI will make sure you encrypt everything
  • TXT? Fuggedaboutit!
  • Intranet-based secure email is mandatory for even low-level secrets
  • Computers and phones should be in the same room as ministers when overseas, and beware snooping when abroad
  • Twelve-character passwords please, using letters and numbers, changed every six months and use different passwords for personal and work devices please!
  • Are you sure that attachment is safe to click on? Don't unless you are.

Cabinet ministers are busy folks who may not encounter basic infosec advice often, so the suggestions in the document don't look like evidence France has been caught with its pants down. The mere fact the memo was issued, and the fact it says it will be backed up by an official ANSSI edict, does however show that Edward Snowden's revelations have made at least one nation feel it is time to get the basics right among a user population that represents an obvious target. ®

Combat fraud and increase customer satisfaction

More from The Register

next story
Lavabit loses contempt of court appeal over protecting Snowden, customers
Judges rule complaints about government power are too little, too late
Don't let no-hire pact suit witnesses call Steve Jobs a bullyboy, plead Apple and Google
'Irrelevant' character evidence should be excluded – lawyers
Record labels sue Pandora over vintage song royalties
Companies want payout on recordings made before 1972
EFF: Feds plan to put 52 MILLION FACES into recognition database
System would identify faces as part of biometrics collection
Edward Snowden on his Putin TV appearance: 'Why all the criticism?'
Denies Q&A cameo was meant to slam US, big-up Russia
Ex-Tony Blair adviser is new top boss at UK spy-hive GCHQ
Robert Hannigan to replace Sir Iain Lobban in the autumn
Judge halts spread of zombie Nortel patents to Texas in Google trial
Epic Rockstar patent war to be waged in California
US Supreme Court supremo rakes Aereo lawman in oral arguments
Antenna-array content streamers: 'Ruling against us could dissipate the cloud'
German space centre endures cyber attack
Chinese code retrieved but NSA hack not ruled out
prev story

Whitepapers

Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.