News: 1632402011

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

UK Ministry of Defence apologises – again – after another major email blunder in Afghanistan

(2021/09/23)


A second leak of personal data was reportedly committed by the Ministry of Defence, raising further questions about the ministry's commitment to the safety of people in Afghanistan, some of whom are its own former employees.

The BBC reported [1]overnight that the details of a further 55 Afghans – claimed to be candidates for potential relocation – had been leaked through the classic cc-instead-of-bcc email blunder, echoing [2]the previously reported breach of 250 Afghan interpreters' data through a similar failure.

An MoD spokeswoman said in a statement: "We have been made aware of a data breach that occurred earlier this month by the Afghan Relocation and Assistance Policy (Arap) team. This week, the defence secretary instigated an investigation into data-handling within that team."

[3]

A defence official has reportedly been suspended from duty, following demands from defence secretary Ben Wallace for an immediate enquiry into how the blunder happened.

[4]

[5]

After the US-led military coalition left Afghanistan, a number of local civilians employed as translators were left behind as the Taliban re-established control over the country. Some of those civilians have since been murdered for their perceived support of the Western militaries.

Efforts to evacuate those people have been patchy, though the British government has established a scheme to admit them to the UK as refugees. Security, however, is an obvious priority; for many of the interpreters left behind after the British military pulled out, security through obscurity is the only defence they have left.

[6]East London council blurts thousands of residents' email addresses in To field blunder

[7]Brit housing association blabs 3,500 folks' sexual orientation, ethnicity in email blunder

[8]150 infosec bods now know who they're up against thanks to BT Security cc/bcc snafu

[9]When selling security awareness training by email, probably a good shout not to hit 'reply all'

[10]London NHS trust fined £180,000 after second bcc fail on HIV email list

As we reported when the first breach came to light, in the tech industry we joke about data breaches having lethal consequences for people's careers. Failures like these expose people to the risk of torture and murder.

In [11]early September , as the dust was still settling from the West's departure, the Taliban got its hands on biometric data that the US-backed Afghan security forces had collected from voters – including women and other minorities. ®

Get our [12]Tech Resources



[1] https://www.bbc.co.uk/news/uk-58654630

[2] https://www.theregister.com/2021/09/21/mod_email_fail_afghan_interpreters_data/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YUykw0mHcnfI194AakkSlwAAAA0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YUykw0mHcnfI194AakkSlwAAAA0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YUykw0mHcnfI194AakkSlwAAAA0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2021/05/05/tower_hamlets_email_fail/

[7] https://www.theregister.com/2020/03/25/watford_community_housing_data_breach/

[8] https://www.theregister.com/2019/11/12/bt_security_cc_bcc_email_fail/

[9] https://www.theregister.com/2018/11/21/security_awareness_train_reply_all_gaffe/

[10] https://www.theregister.com/2016/05/09/london_nhs_trust_fined_180000_by_ico_over_hiv_newsletter_breach/

[11] https://apnews.com/article/technology-business-taliban-c007f85fb1b573c43a4391b947a5dcd4

[12] https://whitepapers.theregister.com/



Chris G

This kind of so called accidental breach seems to happen so frequently one could get the impression it is willful.

Perhaps the perpetrators of these mistake could be sent oversee something in Afghanistan?

Such as cleaning Taliban toilets.

Why does it happen so often ?

alain williams

This kind of so called accidental breach seems to happen so frequently one could get the impression it is willful.

No, it is people just doing things without thinking. You could send them on a training course once a month and it would still happen.

They will (hopefully) bollock whoever did it. This person will be careful for a while but might do it again next year.

Re: Why does it happen so often ?

Yet Another Anonymous coward

Wasn't this the plot of a Bond movie?

Moneypenny has to shoot Daniel Craig before he leaves a disk with list of all the agents on a train

SNAFU after SNAFU (2)

Clausewitz 4.0

I am starting to seriously think maybe there is a reason to that - they want to relocate less people.

More graves = less people to relocate.

Potemkine!

Those so-call blunders kill, dammit!

Does the concept of "reckless homicide" exist in UK's laws?

Yet Another Anonymous coward

This was the MoD, laws don't apply to people with nukes

Dr Who

Presumably the suspended person is the muppet who included the addresses in the cc field.

It should be people at the very to of the MoD who ultimately get suspended. The system is at fault, not an admin clerk. Being able to paste the addresses into the cc field means they were somehow available on a standard email distribution list or most likely an Excel fu**ing spreadsheet. They should be on a secure list server where nobody can see the addresses and where each recipient receives an individual copy of the email, preferrably with the address in bcc, and the sending of which is logged and stamped with the ID of the user who authorised the sending. Nobody, whether within the MoD or outside it should see these addresses on screen.

Or even better, use a secure portal to communicate.

FFS Mailchimp would be a thousand times more secure than what the MoD is doing, apparently routinely.

These twats have put actual lives of actual people, along with their families in grave danger of death or worse. No fine is big enough - a spell in prison should send the right message.

Timing unclear

Diogenes8080

BBC story clarifies that Wallace was not aware of leak of 55 names when he announced disciplining of an official for the leak of 250+ names. However, it is not clear in what order those breaches occurred. It could still be the same chump responsible for both. Investigation of 250+ leak may have led to second discovery.

ARAP covers a problem that did not exist two months ago so was probably thrown together using whatever and whoever was available.

Am still not impressed by any mail system that accepts a very large number of recipients for a single message, regardless of address mode.

Smple safeguards

Gavin Jamie

I am always a bit surprised that my mail client asks me if I use the word "attatched" in an email without and attatchment but does not at least put a an "are you sure" screen if I am sending to >10 people in the To: or CC: sections who will see each others emails.

Would this be a hard feature?

BCC should be the default

Anonymous Coward

BCC should be the default. CC should be more hidden.

If you make a mistake, it's far less damaging to re-send a BCC'd mail you meant to send CC'd !

Pascal Monett

Email works fine as it is.

For the people who use their brain, that is.

You can't implement safeguards against everything. The only safeguard against everything is shutting down the computer.

Doctor Syntax

You might not be able to implement safeguards against everything but you should implement an obvious one to something with such a long history of errors with potentially extremely serious consequences.

"the Afghan Relocation and Assistance Policy (Arap) team"

Pascal Monett

Good thing they didn't name it the Afghan Relocation and Assistance Bureau.

That would have been a bit messy.

Re: "the Afghan Relocation and Assistance Policy (Arap) team"

MiguelC

ARAP is just a small part of the MoD's general "Country Relocation and Assistance Policy"

Re: "the Afghan Relocation and Assistance Policy (Arap) team"

Anonymous Coward

No, it's definitely the Kabul Relocation and Assistance Policy team.

Re: "the Afghan Relocation and Assistance Policy (Arap) team"

Diogenes8080

Joking aside, that comment might frame the problem with the West's policy in Afghanistan over the last 15 years rather well.

Just remember, wherever you go, there you are.
-- Buckaroo Bonzai