UK Ministry of Defence apologises – again – after another major email blunder in Afghanistan
- Reference: 1632402011
- News link: https://www.theregister.co.uk/2021/09/23/afghan_email_fail_ministry_defence/
- Source link:
The BBC reported [1]overnight that the details of a further 55 Afghans – claimed to be candidates for potential relocation – had been leaked through the classic cc-instead-of-bcc email blunder, echoing [2]the previously reported breach of 250 Afghan interpreters' data through a similar failure.
An MoD spokeswoman said in a statement: "We have been made aware of a data breach that occurred earlier this month by the Afghan Relocation and Assistance Policy (Arap) team. This week, the defence secretary instigated an investigation into data-handling within that team."
[3]
A defence official has reportedly been suspended from duty, following demands from defence secretary Ben Wallace for an immediate enquiry into how the blunder happened.
[4]
[5]
After the US-led military coalition left Afghanistan, a number of local civilians employed as translators were left behind as the Taliban re-established control over the country. Some of those civilians have since been murdered for their perceived support of the Western militaries.
Efforts to evacuate those people have been patchy, though the British government has established a scheme to admit them to the UK as refugees. Security, however, is an obvious priority; for many of the interpreters left behind after the British military pulled out, security through obscurity is the only defence they have left.
[6]East London council blurts thousands of residents' email addresses in To field blunder
[7]Brit housing association blabs 3,500 folks' sexual orientation, ethnicity in email blunder
[8]150 infosec bods now know who they're up against thanks to BT Security cc/bcc snafu
[9]When selling security awareness training by email, probably a good shout not to hit 'reply all'
[10]London NHS trust fined £180,000 after second bcc fail on HIV email list
As we reported when the first breach came to light, in the tech industry we joke about data breaches having lethal consequences for people's careers. Failures like these expose people to the risk of torture and murder.
In [11]early September , as the dust was still settling from the West's departure, the Taliban got its hands on biometric data that the US-backed Afghan security forces had collected from voters – including women and other minorities. ®
Get our [12]Tech Resources
[1] https://www.bbc.co.uk/news/uk-58654630
[2] https://www.theregister.com/2021/09/21/mod_email_fail_afghan_interpreters_data/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YUykw0mHcnfI194AakkSlwAAAA0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YUykw0mHcnfI194AakkSlwAAAA0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YUykw0mHcnfI194AakkSlwAAAA0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2021/05/05/tower_hamlets_email_fail/
[7] https://www.theregister.com/2020/03/25/watford_community_housing_data_breach/
[8] https://www.theregister.com/2019/11/12/bt_security_cc_bcc_email_fail/
[9] https://www.theregister.com/2018/11/21/security_awareness_train_reply_all_gaffe/
[10] https://www.theregister.com/2016/05/09/london_nhs_trust_fined_180000_by_ico_over_hiv_newsletter_breach/
[11] https://apnews.com/article/technology-business-taliban-c007f85fb1b573c43a4391b947a5dcd4
[12] https://whitepapers.theregister.com/
Why does it happen so often ?
This kind of so called accidental breach seems to happen so frequently one could get the impression it is willful.
No, it is people just doing things without thinking. You could send them on a training course once a month and it would still happen.
They will (hopefully) bollock whoever did it. This person will be careful for a while but might do it again next year.
Re: Why does it happen so often ?
Wasn't this the plot of a Bond movie?
Moneypenny has to shoot Daniel Craig before he leaves a disk with list of all the agents on a train
SNAFU after SNAFU (2)
I am starting to seriously think maybe there is a reason to that - they want to relocate less people.
More graves = less people to relocate.
Those so-call blunders kill, dammit!
Does the concept of "reckless homicide" exist in UK's laws?
This was the MoD, laws don't apply to people with nukes
Presumably the suspended person is the muppet who included the addresses in the cc field.
It should be people at the very to of the MoD who ultimately get suspended. The system is at fault, not an admin clerk. Being able to paste the addresses into the cc field means they were somehow available on a standard email distribution list or most likely an Excel fu**ing spreadsheet. They should be on a secure list server where nobody can see the addresses and where each recipient receives an individual copy of the email, preferrably with the address in bcc, and the sending of which is logged and stamped with the ID of the user who authorised the sending. Nobody, whether within the MoD or outside it should see these addresses on screen.
Or even better, use a secure portal to communicate.
FFS Mailchimp would be a thousand times more secure than what the MoD is doing, apparently routinely.
These twats have put actual lives of actual people, along with their families in grave danger of death or worse. No fine is big enough - a spell in prison should send the right message.
Timing unclear
BBC story clarifies that Wallace was not aware of leak of 55 names when he announced disciplining of an official for the leak of 250+ names. However, it is not clear in what order those breaches occurred. It could still be the same chump responsible for both. Investigation of 250+ leak may have led to second discovery.
ARAP covers a problem that did not exist two months ago so was probably thrown together using whatever and whoever was available.
Am still not impressed by any mail system that accepts a very large number of recipients for a single message, regardless of address mode.
Smple safeguards
I am always a bit surprised that my mail client asks me if I use the word "attatched" in an email without and attatchment but does not at least put a an "are you sure" screen if I am sending to >10 people in the To: or CC: sections who will see each others emails.
Would this be a hard feature?
BCC should be the default
BCC should be the default. CC should be more hidden.
If you make a mistake, it's far less damaging to re-send a BCC'd mail you meant to send CC'd !
Email works fine as it is.
For the people who use their brain, that is.
You can't implement safeguards against everything. The only safeguard against everything is shutting down the computer.
You might not be able to implement safeguards against everything but you should implement an obvious one to something with such a long history of errors with potentially extremely serious consequences.
"the Afghan Relocation and Assistance Policy (Arap) team"
Good thing they didn't name it the Afghan Relocation and Assistance Bureau.
That would have been a bit messy.
Re: "the Afghan Relocation and Assistance Policy (Arap) team"
ARAP is just a small part of the MoD's general "Country Relocation and Assistance Policy"
Re: "the Afghan Relocation and Assistance Policy (Arap) team"
No, it's definitely the Kabul Relocation and Assistance Policy team.
Re: "the Afghan Relocation and Assistance Policy (Arap) team"
Joking aside, that comment might frame the problem with the West's policy in Afghanistan over the last 15 years rather well.
This kind of so called accidental breach seems to happen so frequently one could get the impression it is willful.
Perhaps the perpetrators of these mistake could be sent oversee something in Afghanistan?
Such as cleaning Taliban toilets.