Spy agency GCHQ told me Gmail's more secure than Microsoft 365, insists British MP as facepalming security bods tell him to zip it
- Reference: 1618391767
- News link: https://www.theregister.co.uk/2021/04/14/tom_tugendhat_email_security_outburst/
- Source link:
The outspoken parliamentarian, who is chairman of the Foreign Affairs Select Committee, made his comments to BBC radio after person or persons unknown sent emails to his colleagues claiming he had quit the committee.
[1]
"I was told by friends at GCHQ that I was better off sticking to Gmail rather than using the parliamentary system because it was more secure," Tugendhat told the BBC’s Today Programme. He continued to splutter: "Frankly, that tells you the level of security and the priority we're giving to democracy in the United Kingdom."
Tugendhat has been outspoken on China’s treatment of the Uighur minority ethnic group, which has been subjected to concentration camps branded "reeducation" camps. Uighurs who move abroad to escape this targeted maltreatment [2]continue to receive intimidation from the state , whose officials have repeatedly refused to accept their camps or their [3]bizarre medical experiments are wrong.
[4]
In return for his campaigning, Tugendhat has been hit with personal sanctions, as gleefully announced by [5]Chinese state-run Global Times. In the eyes of the Middle Kingdom’s ruling Communist Party, Tugendhat’s Foreign Affairs Committee has sinned by launching “unreasonable inquiries into Xinjiang affairs citing ‘forced labor’ and is behind many foreign policies coercing China over Xinjiang.”
Yet today’s email security outburst prompted officials to start wagging their fingers at Tugendhat after he suggested using Google’s email service.
A Parliamentary spokesperson said in a statement: "We have robust cybersecurity measures in place and work closely with partners in the National Cyber Security Centre. In line with guidance from the NCSC we would always encourage MPs to use parliamentary email, which offers significantly higher levels of security than external providers."
The only way is Office: UK Parliament to migrate to Microsoft cloud [6]READ MORE
An email was sent around Parliament purporting to have proceeded from the parliamentarian himself, proffering his resignation from the Foreign Affairs committee.
Unbelievable. Email sent to MPs, pretending to be a resignation letter by [7]@TomTugendhat . It’s fake. Origin unknown... [8]pic.twitter.com/AxeXTJYU3i — Alistair Bunkall (@AliBunkallSKY) [9]April 9, 2021
The House of Commons’ spokeswoman added that the above email was sent from an AOL account impersonating Tugendhat and not from an official account.
GCHQ declined to comment, referring us to its NCSC offshoot. A spokesman for that told us: "The NCSC works closely with the Parliamentary Digital Service who make use of the NCSC’s cyber security guidance, support and Active Cyber Defence services. The Parliamentary email system follows NCSC best practice, including the use of two-factor authentication (2FA), and MPs should continue to use it.”
We have asked Microsoft for comment.
Back in 2017 Parliament’s network was [10]hit by a brute-forcing attack that saw 90 email addresses [11]compromised by Iranian criminals .
[12]
The mother of parliaments adopted Office 365 in 2013, with the House of Lords Management Board [13]deciding at the time that “only a small amount of House data” required “a high level of security”. Times and attitudes have changed a fair bit since then – or so we hope. ®
Get our [14]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YHa9OkwBajw55KNQuyVPsgAAAMo&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://www.bbc.co.uk/news/world-asia-china-56563449
[3] https://www.itv.com/news/2020-09-09/mps-protest-against-ethnic-cleansing-of-uighurs-in-china
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YHa9OkwBajw55KNQuyVPsgAAAMo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.globaltimes.cn/page/202103/1219512.shtml
[6] https://www.theregister.com/2013/12/03/parliament_heads_for_ms/
[7] https://twitter.com/TomTugendhat?ref_src=twsrc%5Etfw
[8] https://t.co/AxeXTJYU3i
[9] https://twitter.com/AliBunkallSKY/status/1380456998949548032?ref_src=twsrc%5Etfw
[10] https://www.theregister.com/2017/06/26/parliament_email_hack/
[11] https://www.theregister.com/2017/10/16/iran_blamed_uk_parliament_cyberattack/
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YHa9OkwBajw55KNQuyVPsgAAAMo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[13] https://www.theregister.com/2013/12/03/parliament_heads_for_ms/
[14] https://whitepapers.theregister.com/
Re: Either or both secure or insecure?
Schrödinger's email, perchance?
Where an email provider can be good, evil or both at the same time.
Conflicting statement....??
wtf?
"we would always encourage MPs to use parliamentary email, which offers significantly higher levels of security than external providers."
article is about how Parliament moved to Office365 in 2013....are Microsoft that comfortably in bed with governments that they are no longer even considered an external provider....
This is no different than if a government used the commercial G suite offering
Oh dear....
When folks like this are running the country no wonder we are fecked.....
To even possibly think that a free, publicly available email system, run by a foreign company, who have scant regards for the laws of the land is more secure than one provided by their own internal highly skilled professionals with all kinds of traceability..... You couldn't make it up.
I wonder if his "friends" in GCHQ were only ever spoken to on the phone and had a chinese accent?
This really should be a serious disciplinary offence (assuming he used it for any official work)
Re: Oh dear....
This story appeared on the BBC website yesterday, and i could not e-mail the reporter to provide some information about Google looking at the contents of your e-mail.
I did find it surprising what was said by the MP, and thought it must have been a crossed wires thing.
Either or both secure or insecure?
When I attempted to investigate Office 365 security on behalf of an international scale client, none of my detailed questions got answered. I was fobbed off instead with truisms including ISO 27001 certification, which everyone really knows (but may not admit) doesn't ensure security at all - only that you follow a formal process. The actual results of following it don't get audited. Consequently the question of relative security between gmail and 365 remains an open question.
If I want a secure service I either run it myself or I outsource it to those who will keep me fully informed at the detail level. But of course that's more expensive than vaguely specified "cloud" offerings.