News: 1617717013

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Their 'next job could be in cyber': UK Cyber Security Council launches itself by pointing world+dog to domain it doesn't own

(2021/04/06)


The UK Cyber Security Council announced itself to the public realm last week by touting a domain it doesn't own. Helpfully, internet jokesters then bought up variations on the official address.

A brainchild of the Department for Digital, Culture, Media and Sport, the UK Cyber Security Council is billed by government as "the regulatory body, and voice, for UK cyber security education, training and skills." As part of that it "drives progress towards meeting the key challenges the profession faces."

[1]

All very worthy and important. When British infosec folk noticed that [2]the official press release mentioned an email address for ukcybersecurity[.]org[.]uk, however, everything started unravelling.

UK govt advert encouraging re-skilling for cyber jobs implodes spectacularly [3]READ MORE

[4]

Why? Because the UK Cyber Security Council didn't own ukcybersecurity[.]org[.]uk. Nobody did – until Adrian Kennard bought it and pointed it at his personal [5]blog , where he dispensed some gentle advice to the new org.

"One of the tips I can give you when it comes to cyber security is that you should be careful to ensure that contact details you publish actually belong to you," wrote Kennard, who runs a UK ISP, adding: "It took a while to stop laughing at the irony first, but now, yes, the UK Cyber Security Council are welcome to ukcybersecurity.org.uk. They can email me at press@ukcybersecurity.org.uk for more information (be nice)."

[6]

The UK Cyber Security Council domain doesn't even have a parking page, let alone a working website behind it

So far nobody's asked for the domain, Kennard told The Register – though there were a couple of attempts to [7]register GPG keys for the address which he said weren't by him. This could have been serious had an actual fraudster got hold of the domain: they would then be able to present themselves as an authenticated representative of UKCSC.

Others who picked up on the missing domain were slightly less nice. The domain ukcybersecuritycouncil.uk currently returns this actually-quite-helpful page…

[8]

Some joker set up a spoof UK Cyber Security Council webpage to answer an obvious question

… which points out what happens when you visit what appears to be the legitimate domain, ukcybersecuritycouncil.org.uk. Yes, that's an HTTP 502 error: there's nothing there to view. Inspired viral marketing move, there.

We have asked both DCMS and the UK Cyber Security Council to comment, the latter via what we hope is its actual email address. If this article disappears after publication and is replaced by offers from "Elon Musk" for "free Bitcoin", we might have to keep asking around.

Your next job could be in cyber....

The UKCSC was [9]first mooted in 2018 before being formally announced in [10]the government's Defence Industrial Strategy in March . It's not clear exactly what the new body will do, though it boasts a variety of professional membership bodies as members including the British Computer Society (aka the Chartered Institute for IT), the Institution of Engineering and Technology and, inevitably, TechUK.

In its marketing fluff UKCSC declared it will deliver "thought leadership, career tools and education resources to the cyber security sector and those seeking a career in the industry, alongside helping influence government, industry and academia with the aim of developing and promoting UK cyber security excellence globally and growing the skills base."

[11]

El Reg suggests that constructing a website and not directing the press to a non-existent domain would be two good pieces of thought leadership to start with. ®

Get our [12]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YGyFnYlBCiGRWnu9mSDwKQAAAEA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pressreleases.responsesource.com/news/101075/uk-cyber-security-council-begins-as-independent-body/

[3] https://www.theregister.com/2020/10/13/cyberfirst_ads_cancelled/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YGyFnYlBCiGRWnu9mSDwKQAAAEA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.revk.uk/2021/04/uk-cyber-security-council.html

[6] https://regmedia.co.uk/2021/04/06/ukcsc502.jpg

[7] http://keys.gnupg.net/pks/lookup?search=press%40ukcybersecurity.org.uk&fingerprint=on&op=index

[8] https://regmedia.co.uk/2021/04/06/ukcscspoof.jpg

[9] https://www.theregister.com/2018/07/19/cyber_security_pro_strategy_uk/

[10] https://www.theregister.com/2021/03/25/defence_industrial_strategy_infosec_industry_lures/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YGyFnYlBCiGRWnu9mSDwKQAAAEA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[12] https://whitepapers.theregister.com/

Doctor Syntax

"Department for Digital, Culture, Media and Sport"

A good example of why I prefer to leave the second comma out of their name.

Anonymous Coward

Cybersecurity - brought to you by media studies graduates and PE teachers

Clown government turns everything to clown

tfb

News at 11.

dot org ?

Yet Another Anonymous coward

>the government's Defence Industrial Strategy

I know defence spending is tight (unless you are an aircraft carrier or an F35) and industry is strapped for cash and the government has no money whatsoever - but are they really a charity ?

Re: dot org ?

Tom Chiverton 1

Nukes, don't forget nukes.

Can't pay the nurses, can afford to blow the planet up a few more times...

Re: dot org ?

Yet Another Anonymous coward

Nuke the nurses

Double bluff

Phil O'Sophical

If they react quickly enough maybe they could spin it as a test, to show who's paying attention to cyber security?

Er ...

Blofeld's Cat

It could be that the "Ministry of Fun" simply requested a web site that nobody could hack.

The ultimate in security by obscurity .,,

Thought leadership

Mike 137

Thought leadership, like strategy, is something you talk about, not something you do (credit to Dogbert for the observation).

Almost all these "initiatives" are pure waffle shops. I've participated in several over the years, and all they ever produced were "reports" that stated the obvious and drove zero change. Which is why the state of information risk has been worsening, not improving, for at least the last couple of decades.

Looks like they are retraining

nsld

As ballet dancers, they just don't know it yet........

Re: Looks like they are retraining

Steve Foster

Well, they've got the whole foot in mouth thing down pat...

Global Operating Devices to ACTive Astute Internetional Rescue with AI Virtual Interventionism

amanfromMars 1

What more can one say other than GOD help us.

And I know it is cold comfort to know all Five Eyes are definitely in the same sinking ship, but what is one to do whenever no one within their ranks and leadership are smart enough to listen to the better than just average Jane Doe and Joe Sixpack.

Here's news of another hamstrung operation forever trying to play catchup while it continues to serially fail with its support for what is existing in their overall command rather than what is to be beyond their exclusive control.

...... just saying on [1]https://www.nationaldefensemagazine.org/articles/2021/3/31/northern-command-leads-global-wargame-to-test-ai-capabilities

“We need to go faster.”

There is no doubt about the veracity of the need for that prime directive if one wants to be considered as leading in any effective position. However, and especially so in the virtually real cyber domain, it is not without its novel, extremely disruptive and/or destructive problems to address, with probably the major one being that one has no idea who almighty friend or hellish foe ..... who/which be well versed and highly experienced in what are surely virgin fields of overwhelming engagement for traditional and conventional forces and sources .... are.

One is effectively only able to stumble around as if blind in such a space.

And to consider that solutions are only to be provided by US citizens, because of the requirement to comply with national security obligations, renders one also deaf and dumb to everyone/everything else out there with a viable voice and rare raw view on unfolding matters.

That is a fundamental handicap which guarantees failure in anything and everything mooted to be tried and tested.

Take care, IT's an AI Jungle out there.

...... which may or may not be there as advertised here should it fall foul of the following advisory issued upon posting .... [Thank you. Your comment will be displayed soon after reviewing]

Some folk and horses you can help and bring to water, others you can't and they would die of thirst for that which they have been led to, to freely partake of, and how idiotic of them is that. One would just have to accept then that they be beyond the reasonable help of all possible assistance and their personal prognoses are imminently terminal in any and every fast moving scenario.

[1] https://www.nationaldefensemagazine.org/articles/2021/3/31/northern-command-leads-global-wargame-to-test-ai-capabilities

Re: Global Operating Devices to ACTive Astute Internetional Rescue with AI Virtual Interventionism

Yet Another Anonymous coward

I think we found the perfect job for our very own amanfromMars 1

Why?

Commswonk

We already have an established National Cyber Security Centre; do we really need an Cyber Security Council (answerable to a different department of government) as well?

If the answer to the above is yes then can someone please tell me (us!) what the reason is? At the moment it looks like another bunch of people just sucking on the public teat while serving no new purpose.

I just hope the answer doesn't involve "thought leadership", although the article rather suggests that it will. If it does then IMHO we're doomed.

Your code should be more efficient!