F
ffox
- Original Poster
- #1
So, Damian Green has gone. The popular, well supported and hardworking politician has been forced to resign.
It would appear that everyone now accepts pornography was found on the computer he used back in 2008. If that’s the case it got there either by Mr Green downloading it, or by someone else using his account to download it.
I noticed that when the debate as to who was responsible for the images was at its height, several politicians volunteered that allowing staff to use login credentials not allocated to them was common practice.
The ICT Security Policy for parliament states –
"Passwords and Network Access Control
1. To ensure privacy of data and to prevent unauthorised users gaining access to systems, including email accounts and business documents, login to the Parliamentary Network is password protected. Passwords must be considered as confidential and must be used only by the originator (and so not shared with other users) and should be stored securely. The Parliamentary Digital Service provides guidelines on password complexity to help users apply passwords that cannot be easily guessed or hacked. If it is necessary for a colleague to have access to another's email account, special arrangements are possible that avoid the need for sharing passwords."
This was picked up by a number of journalists –
https://eandt.theiet.org/content/articles/2017/12/information-commissioner-s-office-warns-mps-of-dangers-of-sharing-passwords/
But, was largely ignored by the mainstream press. Interestingly, the claims of poor authentication practice stopped very quickly. As soon, I suspect, as those controlling ICT security in the houses of parliament pointed out that such practice could lead to the culprits being lockout out of the system altogether.
Interestingly, if Mr Green had followed established practise and required the pornographer aide to log on under their own username/password it would have been simple to place the blame where Mr Green claims it should lie. As it stands, we shall never know for sure.
The moral of the story is two fold –
1. If you have a secret that you wish to remain a secret, don’t tell it to a computer
2. Carefully controlled authentication is a two edged sword. While it will identify ‘who done it’, it can also clearly identify ‘who didn’t do it’
It would appear that everyone now accepts pornography was found on the computer he used back in 2008. If that’s the case it got there either by Mr Green downloading it, or by someone else using his account to download it.
I noticed that when the debate as to who was responsible for the images was at its height, several politicians volunteered that allowing staff to use login credentials not allocated to them was common practice.
The ICT Security Policy for parliament states –
"Passwords and Network Access Control
1. To ensure privacy of data and to prevent unauthorised users gaining access to systems, including email accounts and business documents, login to the Parliamentary Network is password protected. Passwords must be considered as confidential and must be used only by the originator (and so not shared with other users) and should be stored securely. The Parliamentary Digital Service provides guidelines on password complexity to help users apply passwords that cannot be easily guessed or hacked. If it is necessary for a colleague to have access to another's email account, special arrangements are possible that avoid the need for sharing passwords."
This was picked up by a number of journalists –
https://eandt.theiet.org/content/articles/2017/12/information-commissioner-s-office-warns-mps-of-dangers-of-sharing-passwords/
But, was largely ignored by the mainstream press. Interestingly, the claims of poor authentication practice stopped very quickly. As soon, I suspect, as those controlling ICT security in the houses of parliament pointed out that such practice could lead to the culprits being lockout out of the system altogether.
Interestingly, if Mr Green had followed established practise and required the pornographer aide to log on under their own username/password it would have been simple to place the blame where Mr Green claims it should lie. As it stands, we shall never know for sure.
The moral of the story is two fold –
1. If you have a secret that you wish to remain a secret, don’t tell it to a computer
2. Carefully controlled authentication is a two edged sword. While it will identify ‘who done it’, it can also clearly identify ‘who didn’t do it’