Security News

UK think tank proposes Online Safety Bill reviewer to keep tabs on Ofcom decisions
2022-02-02 16:09

Even think tanks with close links to the UK's Conservative government are now criticising the Online Safety Bill, with the Institute of Economic Affairs describing it today as "a significant threat to freedom of speech, privacy and innovation." The IEA, which tends to side with free-market conservatives, said today that the controversial legislation needs an independent reviewer to prevent it causing harms to people using the internet in Britain.

NCSC alerts UK orgs to brace for destructive Russian cyberattacks
2022-01-28 16:20

The UK's National Cyber Security Centre is urging organizations to bolster security and prepare for a potential wave of destructive cyberattacks after recent breaches of Ukrainian entities. The NCSC openly warns that Russian state-sponsored threat actors will likely conduct the attacks and reminds of the damage done in previous destructive cyberattacks, like NotPetya in 2017 and the GRU campaign against Georgia in 2019.

Internet Society condemns UK's Online Safety Bill for demonising encryption using 'think of the children' tactic
2022-01-28 12:56

Britain's controversial Online Safety Bill will leave Britons more exposed to internet harms than ever before, the Internet Society has said, while data from other countries suggests surveillance mostly isn't used to target child abusers online, despite this being a key cited rationale of linked measures. Government efforts to depict end-to-end encryption as a harm that needs to be designed out of the internet as it exists today will result in "Fraud and online harm" increasing, the Internet Society said this week.

Infosec big dogs break out the bubbly over UK government's latest cyber strategy emission
2022-01-26 11:55

The snappily titled Government Cyber Security Strategy, wheeled out yesterday, will set UK domestic cybersecurity strategy for the next eight years. "The UK's legitimacy and authority as a cyber power is however dependent upon its domestic cyber resilience, the cornerstone of which is government and the public sector organisations that deliver the functions and services which maintain and promote the UK's economy and society," said the strategy, authored by the Cabinet Office.

UK govt releasing Nmap scripts to find unpatched vulnerabilities
2022-01-25 18:45

The United Kingdom's National Cyber Security Centre, the government agency that leads UK's cyber security mission, is releasing NMAP Scripting Engine scripts to help defenders scan for and remediate vulnerable systems on their networks. The scripts, authored by i100 partners or security experts who want to share their scripts with the community, will be published on GitHub through a new project named Scanning Made Easy.

UK government opens consultation on medic-style register for Brit infosec pros
2022-01-25 10:14

Frustrated at lack of activity from the "Standard setting" UK Cyber Security Council, the government wants to pass new laws making it into the statutory regulator of the UK infosec trade. Government plans, quietly announced in a consultation document issued last week, include a formal register of infosec practitioners - meaning security specialists could be struck off or barred from working if they don't meet "Competence and ethical requirements."

UK, Australia, to build 'network of liberty that will deter cyber attacks before they happen'
2022-01-21 08:02

The United Kingdom and Australia have signed a Cyber and Critical Technology Partnership that will, among other things, transport criminals to a harsh penal regime on the other side of the world. What we do know is that the two nations have pledged to "Increase deterrence by raising the costs for hostile state activity in cyberspace - including through strategic co-ordination of our cyber sanctions regimes." That's code for both nations adopting the same deterrents and punishments for online malfeasance so that malfeasants can't shop jurisdictions to find more lenient penalties.

UK mulls making MSPs subject to mandatory security standards where they provide critical infrastructure
2022-01-20 17:15

NIS is the main law controlling security practices in the UK today. Currently a straight copy of the EU NIS Directive, one of the benefits of Brexit leapt upon by the Department for Digital, Culture, Media and Sport is the new ability to amend NIS's reporting thresholds.

Privacy is for paedophiles, UK government seems to be saying while spending £500k demonising online chat encryption
2022-01-20 15:06

The British government's PR campaign to destroy popular support for end-to-end encryption on messaging platforms has kicked off, under the handle "No Place To Hide", and it's as broad as any previous attack on the safety-guaranteeing technology. Judging by videos earnestly distributed by organisations supporting it, the No Place To Hide campaign is much wider than merely targeting Facebook Messenger as was previously thought.

NortonLifeLock and Avast tie-up falls under UK competition regulator's spotlight
2022-01-20 11:03

The UK's Competition and Markets Authority has invited comments from industry and interested parties about NortonLifeLock's proposed $8bn purchase of fellow infosec outfit Avast. "The CMA is considering whether it is or may be the case that this transaction, if carried into effect, will result in the creation of a relevant merger situation under the merger provisions of the Enterprise Act 2002," it said.