Damian Green and computer system security

  • Thread starter Thread starter ffox
  • Start date Start date
F

ffox

So, Damian Green has gone. The popular, well supported and hardworking politician has been forced to resign.

It would appear that everyone now accepts pornography was found on the computer he used back in 2008. If that’s the case it got there either by Mr Green downloading it, or by someone else using his account to download it.

I noticed that when the debate as to who was responsible for the images was at its height, several politicians volunteered that allowing staff to use login credentials not allocated to them was common practice.

The ICT Security Policy for parliament states –

"Passwords and Network Access Control

1. To ensure privacy of data and to prevent unauthorised users gaining access to systems, including email accounts and business documents, login to the Parliamentary Network is password protected. Passwords must be considered as confidential and must be used only by the originator (and so not shared with other users) and should be stored securely. The Parliamentary Digital Service provides guidelines on password complexity to help users apply passwords that cannot be easily guessed or hacked. If it is necessary for a colleague to have access to another's email account, special arrangements are possible that avoid the need for sharing passwords."

This was picked up by a number of journalists –
https://eandt.theiet.org/content/articles/2017/12/information-commissioner-s-office-warns-mps-of-dangers-of-sharing-passwords/

But, was largely ignored by the mainstream press. Interestingly, the claims of poor authentication practice stopped very quickly. As soon, I suspect, as those controlling ICT security in the houses of parliament pointed out that such practice could lead to the culprits being lockout out of the system altogether.

Interestingly, if Mr Green had followed established practise and required the pornographer aide to log on under their own username/password it would have been simple to place the blame where Mr Green claims it should lie. As it stands, we shall never know for sure.

The moral of the story is two fold –

1. If you have a secret that you wish to remain a secret, don’t tell it to a computer

2. Carefully controlled authentication is a two edged sword. While it will identify ‘who done it’, it can also clearly identify ‘who didn’t do it’
 
And then you have idiots like Nadine Dorries M.P. whosays that she freely shares her password because, after all, it's only a password.

My staff log onto my computer on my desk everyday. Including interns on exchange programmes.

She apparently sometimes forgets her own password and when she does she shouts out to the rest of the staff and they shout the password back to her.

That, unfortunately, is the attitude to security displayed by a lot of the population. It is not unique to MPs and, hopefully, the sad fate of Damian Green will make MPs more cautious.

People log into free wifis all over the place without the slightest concern for man-in-the-middle attacks, openly write passwords and post them on office noticeboards etc. Visitors to our house have often asked for our wi-fi password. Yes, seriously, people think nothing of asking for your wifi password. After all, it's only a password! (Never mind that your machine may be infected and may infect my network, that you are using my IP to access goodness knows what, that your mobile is going to store my wi-fi password and possibly share it with your apps, whatever.)
 
Last edited:
  • Like
Reactions: ffox
Upvote 0
And some simply leave system logged in when not on it.

Not forgetting of course malicious software and hackers who can download images even when no one else is.

Parliament computer security used to be a joke. Not helped by MPs who WILL NOT follow instructions.
 
  • Like
Reactions: ffox
Upvote 0
So a middle-aged man was caught cracking one off, during working hours - and that has been the main news story again and again? Just how dumb is the media getting? Is that the most important thing that we have to worry about?

Quite honestly, if an ex-cop came to me in the days when I was a journalist and told me that he had seen porn thumbnails on the computer of some vapid B-Class politician nine years earlier, I would have told him to go away and get a life. Of course I was not working in the UK, where it seems the standards of journalism today are, at almost every level, firmly planted in the gutter.

So he didn't want to admit that he was working with his flies open and his research was limited to lesbian bondage, when, I suspect, there were more important issues to investigate - and one could accuse him of rank stupidity and the operation of a computer without due care and attention (learn how to clear your browsing history, you moron!) but quite honestly, the print and broadcast media should be worrying about weightier issues.

Of today's newspapers, even the 'i' has put this pointless tittle-tattle on its front page, albeit as a small tag above the mast-head. Even the FT has put it right at the top and the Guardian and the Mirror have covered their entire front pages with nothing else.

Deputy Prime Minister is not the most important cabinet appointment and TBH, it is largely a PR role that could be done by a sock-puppet.
 
  • Like
Reactions: Clinton
Upvote 0
So a middle-aged man was caught cracking one off, during working hours - and that has been the main news story again and again?

That's not of serious interest. Green says he didn't, the cops say he did. Use of proper authentication, as per the ICT guidelines, would have ensured that the user responsible for the images could be identified.

- and one could accuse him of rank stupidity and the operation of a computer without due care and attention (learn how to clear your browsing history, you moron!)

Won't work. Deleted stuff on a computer disk remains on the disk. The sectors are flagged as available for new data to overwrite the old, but data is not removed. The only way to completely clear data is to overwrite the entire drive with inert data.
 
Upvote 0
1. I don't care about Mr.Green. He can explode for all I care - and with a bit of luck, take half of parliament with him.

2. We all know that you have to overwrite deleted data - or at least we should know that - unless of course, you are a complete idiot. (Other methods of hiding browser and other temp data are available!)
 
Upvote 0
A few years back an MP had a right go at google over the fact that 'filth' kept showing up on his computer. Thai rent boys and so on.
One of my friends was the guy who had to clear the MPs computer of the 'disgusting images' as the MP called them.

You know how when you search for stuff in a browser using a search engine and then other similar stuff pops up in adverts?
Yes, the stuff showing up was based on searches.
Someone had been using the MPs own laptop to search for the information. Who usually gets access to your own laptop....? :)

My friend was rather naughty and didn't tell the MP how the images kept coming up.
 
Upvote 0
1. I don't care about Mr.Green. He can explode for all I care - and with a bit of luck, take half of parliament with him.

2. We all know that you have to overwrite deleted data - or at least we should know that - unless of course, you are a complete idiot. (Other methods of hiding browser and other temp data are available!)

We know it. Some of those using computers appear unaware of it.
No wait, someone will claim we need to have people tested before they gain access to a computer.... :)
 
Upvote 0
We know it. Some of those using computers appear unaware of it.
No wait, someone will claim we need to have people tested before they gain access to a computer.... :)

Hehe. First line telephone IT support - "Sorry but I can't fix your problem. Place the computer back in the original packing, take it to the store where you bought it, and tell them 'I want to return this because I'm not fit to own a computer'"
 
Upvote 0

Latest Articles