Feeds

French ministers told to use only secure comms post-PRISM

Reminder of best practice issued after Snowden's revelations

Internet Security Threat Report 2014

French newspaper L'Express has published a memo it says comes from Christophe Chantepy, chief of staff to French prime minister Jean-Marc Ayrault, and which recommends French cabinet ministers stop using smartphones for phone calls because they are not secure.

The paper's report includes three images of the memo, one for each of its pages.

Native French speaker Elodie Quievre, who works in the office where Vulture South camps, was kind enough to translate all three and we rammed L'Express' report through Google and Bing to help out.

Dated August 19th, the memo opens by referring obliquely to recent Snowden-related events and suggesting the make now an ideal time for to “remind elementary rules which must be applied within the administration.”

Those rules state the following0:

  • BYOD is forbidden
  • Mobile phones are a bad idea: landline phones secured by Thales' TEOREM technology for voice calls are far better idea
  • Smartphones should be secured by French spook house ANSSI before being used for anything
  • ANSSI will make sure you encrypt everything
  • TXT? Fuggedaboutit!
  • Intranet-based secure email is mandatory for even low-level secrets
  • Computers and phones should be in the same room as ministers when overseas, and beware snooping when abroad
  • Twelve-character passwords please, using letters and numbers, changed every six months and use different passwords for personal and work devices please!
  • Are you sure that attachment is safe to click on? Don't unless you are.

Cabinet ministers are busy folks who may not encounter basic infosec advice often, so the suggestions in the document don't look like evidence France has been caught with its pants down. The mere fact the memo was issued, and the fact it says it will be backed up by an official ANSSI edict, does however show that Edward Snowden's revelations have made at least one nation feel it is time to get the basics right among a user population that represents an obvious target. ®

Beginner's guide to SSL certificates

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Reducing the cost and complexity of web vulnerability management
How using vulnerability assessments to identify exploitable weaknesses and take corrective action can reduce the risk of hackers finding your site and attacking it.
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.