بجویبجویبجوی
  • صفحه اصلی
  • محتوا
  • جستجو
  • نشان ها
  • دسته بندی ها
    • خبری
    • فناوری
    • ورزش
    • فیلم و سینما
    • اقتصادی
    • بازی رایانه ای
    • مجلات اینترنتی
    • سفر و گردشگری
    • خودرو
    • مذهبی
    • مادر و کودک
    • معماری و چیدمان
    • زیبایی و سلامت
    • کاریابی
    • منابع خارجی
    • ویدئو
جستجو
صفحات تخصصی
  • آخرین نتایج ورزشی
  • بورس و اوراق بهادار
  • صفحات روزنامه ها
  • قیمت ارز و فلزات گران بها
سایر
  • دسته بندی ها
  • منابع
  • ارتباط با ما
  • حریم خصوصی
در ما بجوی او را ، در او بجوی ما را
خواندن: Sensitive UK police data vulnerable to ‘compromise’ by US government and foreign actors
به اشتراک بگذارید
تغییر اندازه فونتآآ
بجویبجوی
تغییر اندازه فونتآآ
  • خبری
  • ورزش
  • فناوری
  • مذهبی
  • معماری و چیدمان
  • زیبایی و سلامت
  • اقتصادی
  • بازی رایانه ای
  • خودرو
  • سفر و گردشگری
  • فیلم و سینما
  • مادر و کودک
  • مجلات اینترنتی
  • کاریابی
  • منابع خارجی
  • ویدئو
جستجو
  • صفحه اصلی
  • محتوا
  • جستجو
  • نشان ها
  • دسته بندی ها
    • معماری و چیدمان
    • منابع خارجی
    • زیبایی و سلامت
    • فناوری
    • ورزش
    • مجلات اینترنتی
    • اقتصادی
    • خودرو
    • مذهبی
    • خبری
    • سفر و گردشگری
    • بازی رایانه ای
    • کاریابی
    • مادر و کودک
    • فیلم و سینما
    • منابع خارجی
    • ویدئو
ما را دنبال کنید
در ما بجوی او را ، در او بجوی ما را
بجوی > منابع خارجی > Sensitive UK police data vulnerable to ‘compromise’ by US government and foreign actors
منابع خارجی

Sensitive UK police data vulnerable to ‘compromise’ by US government and foreign actors

آخرین به روز رسانی: شنبه 28 شهریور 1405 00:33
گاردین
به اشتراک بگذارید
16 دقیقه مطالعه
Sensitive UK police data vulnerable to ‘compromise’ by US government and foreign actors
اشتراک گذاری

Vast troves of highly sensitive police data are lying on Microsoft cloud platforms which an official UK security assessment deemed to be vulnerable to “compromise” by foreign actors and the US government, a Guardian investigation can reveal.

The files include criminal records, victim statements, internal emails and sensitive information held by more than ۴۰ police forces across the UK.

Some files exceed “official” classification, according to a police document seen by the Guardian, raising the possibility the information could be classed as “secret” or “top secret”.

The cloud platform is Microsoft Azure, one of the main commercial offerings of the US tech company. It is used by businesses and governments globally and rests on a web of IT infrastructure – datacentres, networking gear, fibre optic cables – that spans more than ۱۰۰ countries.

In recent years, doubts have surfaced about how cloud platforms store data and whether they are truly secure.

British police decided to put some of their most sensitive data on the Microsoft platform in a ۲۰۱۷ meeting, a record of which was examined by the Guardian.

In doing so, officers accepted that “US government insiders” would be able to see the data, and that it could be “transmitted worldwide”, with “the extent of this … unknown”.

According to five specialists who reviewed the Guardian’s findings, the risks identified in that document persist today. Almost every UK police force now depends on Microsoft Azure, and the UK government spends at least £۱.۹bn on Microsoft software each year.

“There’s no evidence that this has been properly understood,” said one source who has held senior roles in UK policing. The data is “some of the most sensitive that exists”, he added. “You’re talking about information that, if it gets into the wrong hands, or if the information is incorrect, [means] people can get hurt or may die.”

When the Guardian approached the police about the possibility that sensitive information was not secure, they appeared to wave aside these risks, saying Britain’s contracts with Microsoft meant US authorities could not view data without express permission and that the data it stored on Microsoft remained in the UK.

These statements appeared to contradict public admissions by Microsoft, which said in a disclosure to Police Scotland in ۲۰۲۳ that data “can go outside the UK” and that it “cannot guarantee data sovereignty”.

Microsoft said it “does not provide any government with direct or unfettered access to customer data”, and that it had not provided UK data in response to a US government request. It added that, like all US-based tech companies, it responded to US government requests made through valid legal processes.

The threat of ‘US government insider attackers’

In ۲۰۱۷, a senior police officer, Ian Dyson, chaired a meeting in which stakeholders considered ۱۵ risks the UK would face if police forces decided to transfer their data to Microsoft’s global cloud.

Ian Dyson, pictured in ۲۰۱۶. Photograph: Jamie Smith

That meeting considered both the police’s use of Microsoft’s software, such as Office ۳۶۵, and the reliance on the cloud that underpins these services, Azure. Those risks, and the resulting police decisions, were set out in a summary document seen by the Guardian and signed off by Dyson.

This was four years after the advent of a policy called “cloud first”. Introduced by the Cabinet Office in ۲۰۱۳, it became a government-wide effort to push almost all departments to migrate their data on to the “public cloud” – commercial offerings by tech companies, often based in the US. Departments that did not want to do this had to jump through burdensome administrative hoops.

Dyson was the police commissioner of the City of London at the time, but he held another title: senior information risk owner for all of Britain, or the SIRO. It was his job to set the norms for how British police could safely handle their data.

In their assessment, officers came to startling conclusions about what would happen if they put police data on Azure. Firstly, they considered it would be vulnerable to hackers: Microsoft’s software “carries vulnerabilities which will be exploited by cybercriminals and other threat actors in due course”.

Separately, it added: “Police forces cannot be certain where their data will be processed or stored.

“The hyper-scale and global nature of the Microsoft cloud means that police data, and metadata relating to police data could be transmitted and stored worldwide by Microsoft, and the extent of this will be unknown.”

The document specifically identified the potential risk from what it described as “US government insiders”. It said: “There is a risk of compromise of sensitive data shared by, or taken from, Microsoft by the US government being released by US government insider attackers.”

The document explained that the data intended for migration was sensitive. In fact, “a significant volume” of it exceeded the classification “official”. In the UK, this suggests it was either “official sensitive”, “secret”, or “top secret”.

The assessment also suggested Microsoft’s platform was unable to guarantee this data would be secure. “This places sensitive data, inadequately protected in an environment which then becomes a significantly more attractive target for attackers,” it said.

double quotation mark

We really don’t know if the data has been breached or not

Former senior policing source

As well as risks, the report also listed mitigations. On the problem of cyber-attacks, it mandated that police servers should be repaired promptly, kept up to date and have antivirus software.

To address the risk of “US government insiders” and the concern that Microsoft might store UK policing data “worldwide” it suggested “applying Microsoft’s ‘out-of-the-box’ native encryption” and leaving the final decision about using Microsoft up to individual police chiefs.

Several experts interviewed by the Guardian, including cloud computing specialists and engineers working for Microsoft, suggested these mitigations were inadequate. Microsoft’s internal encryption does not prevent its employees accessing UK police data; nor would it stop the US government obtaining British policing files.

The National Police Chief’s Council (NPCC) said access to data stored on the cloud is limited to those with a genuine need to access it and that this is subject to strict controls. Despite that claim, a Microsoft engineer who reviewed the Guardian’s findings said the information “could be viewed by hundreds of people around the world, some of them not vetted, many of them not directly employed by Microsoft”.

Despite the risks identified by the assessment, every police force in the UK put its data, wholly or in part, on Microsoft’s cloud. Some began migrating their information in ۲۰۱۷. A few forces, such as Police Scotland, are still finalising their adoption of the technology.

The files cover the “full gamut of data: intelligence, body-worn video, digital evidence and case files, as well as the non-law enforcement data any organisation has”, said the source who held senior roles in UK policing.

‘We do not expect any sharing … without permission’

The UK government spends billions each year on services offered by three US tech companies: Amazon, Google and Microsoft.

Up to ۶۰% of its IT infrastructure is hosted on cloud platforms. Britain’s intelligence data is hosted on Amazon’s cloud services, as is its customs data. The Ministry of Defence uses Azure. There is “a deep dependency on US hyperscalers”, said Dave Michels, a researcher with the Cloud Legal Project, at Queen Mary University of London.

This is the result of ۱۳ years of decisions like Dyson’s. It is unclear if the potential consequences are broadly understood.

When the Guardian approached the NPCC over the document signed by Dyson, it said: “UK policing as standard requires the use of UK-only datacentres,” but added that “on occasion” Microsoft employees could access the data “to provide support”.

Asked whether the US government could access the data, a police spokesperson said they could not comment on the phrase “US government insiders”, because “terminology … changes continuously” and the document was “outdated”.

“In line with the contract signed with Microsoft, we do not expect any sharing with the US government without the express permission of the UK government,” they added.

Microsoft said: “The suggestion that use of Microsoft cloud services means customer data is inherently insecure or automatically exposed to foreign governments is inaccurate.” It said it had “never provided UK government data in response to any US or global authority request”.

Two legal experts, as well as several Microsoft engineers who spoke anonymously to the Guardian, suggested these assertions did not give an accurate picture of the potential risks.

double quotation mark

The risk is obvious, even though the providers of the cloud and the government both have an interest in talking it down

Douwe Korff, professor of international law

By default, Microsoft’s cloud was “a global network of datacentres”, said Michels. It had facilities on every continent and this meant, generally, that data stored on it was stored everywhere: pieces of a single file could be held across multiple countries, from Sweden to Ethiopia.

In recent years, Michels said, Microsoft had begun to offer clients in Europe greater assurances about where their data was stored, including assuring some customers that their data would remain within EU borders. But “the focus on data location is a bit of a red herring”, he said.

This was because thousands of engineers from more than ۱۰۰ countries maintained Microsoft’s systems. Some were directly employed by Microsoft, others worked for subcontractors in countries potentially hostile to the UK, from Israel to Egypt, China and Kazakhstan. “You’ve seen the list of their sub-processors of people who have access to customer data,” said Michels. “It’s a long list.”

Some of the engineers could access data, such as UK police data, directly as part of customer support. Many more could see key features of what the data included.

A Microsoft datacentre in the Netherlands. Photograph: Ramon van Flymen/EPA

Microsoft said it had “strong guardrails” around data access by engineers.

Douwe Korff, a professor of international law at London Metropolitan University, said the police statement that “we do not expect any sharing [of our data] with the US government” was “typical lawyers’ wriggling”.

“The risk is obvious, even though the providers of the cloud and the government both have an interest in talking it down,” he said.

Michels said: “As a cloud customer, if you’re relying on a contractual commitment from a cloud provider not to hand over data when forced to under foreign law, that is not worth much more than the piece of paper it’s written on.”

US law, including the Cloud Act, allows US authorities to access any data held by US cloud companies, including data held abroad. US authorities do not need a warrant to do this, and they can require US companies to not disclose such access to cloud customers.

Microsoft, Amazon and Google have insisted they would fight such requests, said Korff. But there is “nothing that is legally binding” that would prevent them from sharing other governments’ data if US authorities demanded it.

In response to a query from the Guardian, Microsoft said it “has never provided UK government data in response to any US or global authority request”. It added in a follow-up that it was bound by its “contractual commitments”.

“If UK law prohibits us from turning over data to another government, that is a binding law that would govern our response to any hypothetical demand,” it said.

‘The security guys expected a big breach by now’

The Guardian spoke to six people who have closely followed the country’s data storage arrangements over the past decade. Several of them said that senior leaders did not view dependence on US tech companies as a concern, and trusted them not to give data to US authorities.

“Government security departments are painfully aware of all the risks,” said Mark Butcher, a cloud expert who acts as a strategic adviser across government. “But the way that most senior leaders talk about it is: ‘Well, we’ve been reassured by Microsoft that it would never happen.’”

But the source who has held senior policing roles said: “All the security guys I worked with when this policy came in expected a big breach by now, and we know it will take that to change the police’s position.

“The truth is, however, the level of logging and information in the cloud systems would not necessarily tell us if there was a problem. We really don’t know if the data has been breached or not.”

برای مشاهده منبع محتوا اینجا کلیک کنید 

سرفصل های مطالب
  • The threat of ‘US government insider attackers’
  • ‘We do not expect any sharing … without permission’
  • ‘The security guys expected a big breach by now’
برچسب ها:English
این مقاله را به اشتراک بگذارید
فیس بوک پینترست واتساپ واتساپ لینکدین تلگرام لینک را کپی کنید چاپ کنید
مقاله قبلی ‘Daughter of Damascus’ Assala performs in Syria after ۱۵-year exile ‘Daughter of Damascus’ Assala performs in Syria after ۱۵-year exile
مقاله بعدی بودجه ساخت بازی The Blood of Dawnwalker فاش شد – زومجی بودجه ساخت بازی The Blood of Dawnwalker فاش شد – زومجی
بدون دیدگاه بدون دیدگاه

دیدگاهتان را بنویسید لغو پاسخ

نشانی ایمیل شما منتشر نخواهد شد. بخش‌های موردنیاز علامت‌گذاری شده‌اند *

انسان بودن خود را ثابت کنید: 5   +   3   =  

برچسب ها

English game IT اخبار ارز دیجیتال استخدام اقتصاد انیمیشن بازی بازی کامپوتری بیماری تور تکنولوژی خبر خودرو درمان دیجیتال دین زیبایی سبک زندگی سریال سفر سلامت سلامتی علمی فناوری فوتبال فیلم مادر ماشین محتوا اینترنتی مذهب معماری موتور موفقیت نوزاد هنر ورزش ورزشی چهره ها چیدمان کاریابی کشتی کودک گردشگری

ما را دنبال کنید

Xدنبال کنید
اینستاگرامدنبال کنید
Tiktokدنبال کنید
تلگرامدنبال کنید

موارد مرتبط

Jammertest: Arctic exercise to counter satellite jamming
منابع خارجی

Jammertest: Arctic exercise to counter satellite jamming

یکشنبه 29 شهریور 1405
One child dead and two children and woman in critical condition after Blue Mountains stabbing
منابع خارجی

One child dead and two children and woman in critical condition after Blue Mountains stabbing

یکشنبه 29 شهریور 1405
إغلاق طرق وحرق إطارات فی الحسکه احتجاجاً على أزمه المحروقات – قناه العالم الاخباریه
منابع خارجی

إغلاق طرق وحرق إطارات فی الحسکه احتجاجاً على أزمه المحروقات – قناه العالم الاخباریه

یکشنبه 29 شهریور 1405
How did the US recall a billion products in six months?
منابع خارجی

How did the US recall a billion products in six months?

یکشنبه 29 شهریور 1405
نمایش بیشتر

درباره ما

بجوی با جستجو در منابع وب فارسی محتوا متنوع برای شما جمع آوری کرده و در زمان شما صرفه جویی می کند. شما در بجوی می توانید محتوا جدیدترین منابع مورد علاقه خود را مشاهده و سپس در منبع اصلی دنبال کنید.کلیه محتوا نمایش داده شده توسط منابع جستجو تولید شده و بجوی هیچ گونه مسئولیتی در قبال محتوا تولید شده ندارد.

دسته بندی های پر بازدید

  • خبری
  • ورزش
  • فناوری
  • مجلات اینترنتی
  • اقتصادی
  • خودرو

دسترسی سریع

  • قیمت ارز و فلزات گران بها
  • آخرین نتایج ورزشی
  • بورس و اوراق بهادار
  • صفحات روزنامه ها
  • دسته بندی ها
  • منابع

بجویبجوی
ما را دنبال کنید
© 1405 تمامی حقوق برای بجوی محفوظ است.
  • حفظ حریم خصوصی
  • ارتباط با ما