UK Government scans all web servers hosted in the UK for vulnerabilities
ncsc.gov.uk
ncsc.gov.uk
[1] - https://www.shodan.io/
You can poke around at https://viz.greynoise.io/ to see who is doing what.
It is ironic that the very link [1] you provided proves you wrong. The top 5 countries of origin doing IP scanning in the last seven days are China (120k), India (67k), US (52), Iran (44k), and Russia (27k).
Actual GRU agents have been identified by a receipt for taxi from GRU hq to Sheremetievo airport
https://mobile.twitter.com/bellingcat/status/151894316662756...
https://www.bellingcat.com/news/2022/08/25/socialite-widow-j...
If other people (and arguably other govt's) are scanning too, then saying 'west scans internet' seems somewhat superficial. Not that I deny western state actors scanning the internet, its just that everybody does it.
We tend to hold them to a higher standard than the ones who much more shamelessly operate pseudo-blackhat hacking teams. The west at least tries to maintain a sheen of legality. Or morality. Or whatever.
And yet despite all the messed up stuff they do every day they still get held to a higher standard.
(But there are also other reasons your conclusion is wrong I think)
When you say: "Look, the people from village A north are stealing apples from the city orchard. Here is a list of apple thieves and the direction (N,E,S,W) from which they came." And this list shows that it appears to be majorly the directions E,S,W (so not directly from village A). Then how is this an argument?
It just shows that everybody steals apples, making the accusation "villagers of A are to blame" superficial. That's the point it tried to make.
> But there are also other reasons your conclusion is wrong I think
I would be interested on why my conclusion is wrong. At best, one could draw nothing from the data as it does not show any relation to state actors. And if this conclusion is drawn, then why did `mike_d` blame the western state actors in the first place?
Think for a second about this: Did you think that the link `mike_d` provided supported the argument "... feed the data to western governments" with the emphasis on 'western'?
You could get somewhat closer by inspecting public DNS records for those IP addresses and then attempting to load each site by DNS name, but it still wouldn't be a complete index of all websites in the country. I'm thinking that's impossible to collect, or at least very nearly.
It’s just not widely known and they don’t have any good information on their website about it. The only thing I found was this (in German, there does not seem to be an English version): https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisati...
Personally I was very grateful.
I would rather hope that EU/Anglosphere/Japan/Korea etc. 'team up' on this one and at minimum exchange notes and best practices.
Im going to say this isn’t technologically useful.
REASONS:
1. Over 80% of breaches happen because of KNOWN but unfixed vulnerabilities.
2. Most attacks lead with phishing and account takeovers not software vulns.
Most people assume that if you scan all the things it fixes the problem or even empowers people to fix problems but it doesn’t.
If governments want to do something truly progressive then here’s a better option.
1. Use MFA preferably hardware tokens everywhere.
2. Catalog all externally exposed assets
3. Catalog all high-risk internal assets
4. Regularly white box pentest your assets (switch vendors annually) and implement a bug bounty program as well
5. Penalize any organization that doesn’t remediate their critical pentest and bug bounty findings
EQUIFAAAAAAAAAAAAAX!!!!!!!!!
(Yes, the Equifax hack was due to a widely-known vulnerability in Apache Commons that apparently the DHS warned about but Equifax didn't bother to patch it.)
Also, knowing that hospital equipment still runs Windows XP (with some sturdy-but-aged machines running Windows 2000), I'm not sure if there's any good benefit for this. Sure, small businesses might take action on a genuine oversight but larger businesses tend to know already that their systems are insecure (even when taking state-level/sponsored attack out of the equation).
You don't need to connect your MRI scanner to the internet.
> REASONS:
> 1. Over 80% of breaches happen because of KNOWN but unfixed vulnerabilities.
This reason only makes sense to me if I assume that all KNOWN vulnerabilities are (and remain) UNFIXED. Assuming otherwise doesn't make sense because I can't tell how many attacks the KNOWN and FIXED vulnerabilities prevented.
> Most attacks lead with phishing and account takeovers not software vulns.
This might be true, but you seem to suggest that we can only concentrate on preventing one type of attack at a time, and therefore we should only pick defensive strategies for the most common attack,
It’s the same reason state govs in the US mandate car insurance or bonds for drivers.
Companies like people have limited resources, time and money so they should focus on where the risk lies.
Risk being impact multiplied by likelihood.
If you have to choose, which do you do first?
- Bump your library versions for all your apps
- Implement MFA for your customers
First - that vulnerabilities are 'known' does not mean any specific instance of vulnerability is 'known'.
Second - that 'most attacks occur some other way' isn't hugely relevant. We don't 'not check the door locks' because most criminals 'go in through the window'.
Having a government entity knock on the doors and remind folks that they have a problem gives the issue impetus, and even legitimacy within the organization aka instead of 'powerless IT figure from sector 8G' saying we have a problem, now, it's the Government saying 'you should to fix this' thereby giving execs the mandate to spend on it.
This is exactly what the government should be doing - it's proportional, non-invasive, note hugely expensive or complicated, they're not making legal requirements here (because none are needed) etc..
Your litany of solutions is not comprehensive, moreover, item #5 'penalize those for not appropriately respond to bug bounty' is a bit glib - this would definitely be government overstepping their bounds. There are always bugs in software. Weighing the risk v. consequences is not something gov can do.
Maybe you thought I made this stuff up but I just stated what the latest best practices and research shows for at least the last 3 years.
1. The specific vulns are known. We’re not talking about 0days here.
2. Attack vectors are completely relevant. Any security professional will tell you this.
You may want to read up:
- https://www.verizon.com/business/resources/reports/dbir/
- https://zerotrust.cyber.gov/
- https://security.googleblog.com/2019/05/new-research-how-eff...
- https://www.oecd.org/sti/consumer/37863861.doc
LASTLY…
GDPR, SEC, HIPAA, NYDFS and NYSE all mandate risk management measures if not outright penalize companies and citizens for data breaches after the fact which unfortunately means your Grandmas Syphillis medication has to hit Twitter before there’s intervention.
Without strong financial penalties or an impetus to fix at least critical vulns earlier we’ll continue with the status quo.
I don't want that for you, your Grandma or my own. You shouldn’t want it either.
Additionally, I hate this "If it doesn't fix every issue, it's not worth doing" argument
The intention is good, but in practice I think it's mostly useless because:
* The reports go to the AS operator, who in most cases are not the actual admins of the vulnerable software. Some hosting providers such as Hetzner and Manitu have scripts in place to forward reports to the respective customers, but most don't since it involves a lot of parsing of the email (which is not in an easily machine readable format).
* The emails often warn about security issues that may not actually be problematic (i.e. merely warning about some open port that may be intentionally open, and especially if you operate, say, a honeypot), with no way to opt out for specific hosts/ports. So you can only really filter them entirely in your mail client which I think most people do.
Please elaborate.
For their computer to resolve this domain name, it's going to call out to a DNS server, of which Google hosts a major one. It can be assumed that they log these names, and can then use that as a "notification" for a site coming up.
So you need: IP address and port for the TCP headers, and the domain name to go in the TCP packet content.
One example of a vulnerability would be having phpMyAdmin with a database password hardcoded and no login needed. Without the domain name it would still be impossible to access. (Of course, domain names shouldn't be considered secret so this would be a very insecure setup.)
If the site operators are unresponsive then that sucks, but it would still help secure those that are responsive.
We have detected a dangerous virus or service in your hosting environment. Conspiracy theorists and foreign state actors often use these types of methods to spread fake news and influence our elections. These are serious threats to our Democracy, but Fatherland Security is here to help you through this difficult time. Your local neighborhood Security Helper will be at your home in the next few minutes to assist you in removing the dangerous HTTP service. For your safety, please stay away from all doors and windows.
Sincerely,
Rob E. Friendly
This seems like only a minor problem. If people are unresponsive, then oh well, they tried to tell you you're hacked. If the site owner cannot be determined, they can email your ISP. This seems to work well for "one of your customers is torrenting movies", and since every ISP is known by definition (thanks, IP addresses), it should be fairly straightforward to get that message to the actual customer. (Send it with the invoice; if the customer doesn't pay invoices, then it's easy to resolve the hacked site. You were shutting them off anyway.)
Nothing in the article suggests that they contact site-owners (I haven't re-read the article, so might be wrong).
I'm not sure why you think it's a potential violation of CFAA to connect to a public server and probe it. There's no suggestion of unauthorized access; that would involve exploiting vulnerabilities they find, and that would be unauthorized access.
Things that are illegal for individuals to do aren't necessarily illegal for governments to do. This is a reason why the government should be vigorously doing this, rather than leaving it to private citizens, who risk being charged under the Computer Fraud and Abuse Act.
-----
> Also, what should the government do when it finds something?
It should contact the site operator.
-----
> What if the site operators are unresponsive or cannot be contacted?
I would imagine that in the case that site operators couldn't be contacted, they wouldn't be contacted.
"Who can receive services? Federal, state, local, tribal and territorial governments, as well as public and private sector critical infrastructure organizations."
However, methinks US definition of critical infrastructure organizations, both public and private, will be quite broad.
I hope they aren't using a perl script triggered by a cronjob on a hand-rolled VM though..
It was a charming little outfit that has since sold out to iomart. Alas.
On the other hand, a custom built tool that tries to find the most serious known vulnerabilities with a low false positive rate would probably be a good thing for the government to run.
I'm reading that the UK government is spying on us, and their retrospective plausible excuse is that they are scanning web servers for, erm, vulnerabilities.
No, I don't think that the government is here to help. It allows itself only to maintain force, that it then uses to forcibly extract wealth from its herd, er, sorry citizens.
Downvoting "It's raining because Soros and his globalist Jewish cabal control the weather" does not mean I disagree that it's raining but the edit always comes in [downvoters can't handle the TRUTH, stay classy HN] or similar.
e.g. how is scanning for vulnerabilities "spying on us"? How is scanning for vulerabilities "forcibly extracting wealth"? How is informing people of vulernabilities "not here to help"? It's a thinly disguised flamewar comment, not a comment on the topic.
To play Devil's advocate: once you discover a vulnerability you always have two options: report it and have it fixed, or exploit it for your own gain. You charitably assume that government is somehow obligated to chose the former, while in reality in some cases it might choose the latter.
This assumes that the government that wants to compromise a domestic host can't do it in a way that is a lot more deniable than porting scanning you from a gov owned IP range.
If the government wants to find and exploit a vulnerability they likely will find a way they don't need some loose cover story for it.
https://yougov.co.uk/topics/politics/articles-reports/2014/1...
Maybe they put it like this to exempt themselves...
(NOTE: I have no idea if this specific link is related to Alex or anything he's done)
Why is scanning web servers for vulnerabilities bad?
I suspect those opposing it are the ones that eventually get caught with glaring vulnerabilities and then we have to hear BS like "they care for security and privacy" when they didn't even use password hashes
No, it refers to a state that is intrusive into personal choices.
"pre-presumes"?
If this service causes a bunch of crashes (somehow) or they end up DoSing someone they should be responsible for the harm that they cause, but since these scans are no different that what criminals are already doing every day I don't imagine it'll be a huge problem unless they really screw something up.
I'd also guess that the costs in both time and money spent on the traffic generated by DDoS attacks, malware infections, and phishing sites are much much greater than the costs for 'security guys' to review logs, safely automate scans, and notify webhosts of problems. This is a sensible measure that should save massive amounts of time and money for people all around the globe and make the internet better for UK citizens in the process.
The gist of your argument is if I go up and try to pick your pocket but say my intentions are only to help you from real pickpockets, there's nothing but your personal choice to walk on public sidewalk and should just accept it.
the people who would opt in aren't likely to be the problem. The problem with your pickpocket example is that you lose something when someone picks your pocket, but you lose nothing when someone checks to see what ports are open.
In fact, that's something that's already happening all the time anyway. The only difference is that in this case the person checking for your failures to secure your devices will notify you of the problem instead of exploiting your devices like everyone else will (assuming that they haven't already).
This should not only help people secure their devices, but it should also make the internet a better place for everybody.
We already know where that path leads, thanks to countries like the former USSR and China. Do not want!
Not the OP.
I think it's fine in general with one big proviso, that they change the law first to make it lawful.
With a different government it would look more benevolent, with the current government growing ever-more fascist--having now found a surreptitious way to ditch the ECHR, for example--it gets somewhat worrying.
* It is pretty obvious to the user if their door is locked, so they don't need pentesters to help them figure it out.
* Houses aren't under attack from the entire planet at all times.
* It not that uncommon to have circumstances arranged such that if someone does barge into your house, you know about it.
If the local government wanted to do something that is closer to to what's going on here -- maybe go door to door offering a security assessment for non-obvious stuff -- that might be a well-received service.
Is it, in your view, better that criminals jiggle the handles?
They're maintaining a vulnerability database. That's like what CERTs do. It's analagous to maintaining a database of safe foodstuffs or drugs.
CISA will jiggle your door handles for free, if you ask and consent first. Web server operators who aren't asking for vuln assessments aren't apt to keep them regularly patched to begin with.
Connecting to a webserver using HTTP is not a criminal act, under any colour of the law. If you have a listening port open to the internet, you are inviting connections.
Picking pockets is stealing; this is more like saying "Hello!" to someone who is standing in their own open doorway, and observing their response.
I don't think there's anything in the article about this programme providing server operators with reports. They're not trying to save operators from themselves.
I suppose the differences in how those two equivalent departments approach this, likely come from national mindset differences, and the political differences they cause. At least it seems reasonable to me: that in Washington people might all agree that the right to decide if you are tested is more important than finding insecure webservers, whilst in London people might well all agree on the opposite.
But the gov.uk website is pretty good and they did replace IT with computing in schools.
ps: Anybody? [1]
[1] https://serverfault.com/questions/1112995/prevent-the-git-di...
i.e., add a .* to the end so that it matches anything coming after .git
I love seeing this.
It's interesting because there are two main methods for what to do when you find a vulnerability: 1) hold onto it so you can later use it as a weapon or 2) disclose it and patch it. The offensive method has problems because as soon as you use it you are disclosing it. It also has the issue that your enemies may be able to (are likely to) find the same vulnerability and exploit it first. But the second method means you're losing your weapons but instead gaining a shield.
As I see it, the shield is a lot bigger and has far higher utility. But part of that is that I see democracies as having differing vulnerabilities than autocracies. Attacking autocracies is more spear phishing, very directed attacks on the specific people that control power. But attacking democracies is in some sense easier (and in another sense harder) because more power is held by the average person. People who are more vulnerable to manipulation, especially at the large scale. But now we're edging into the data privacy domain and that's probably out of scope here.
I really think there should be a very strong blue team effort by these organizations. I am okay holding on to a specific vulnerability if you're going to attack a specific person in the ,,immediate'' future, but these agencies should also be working with companies to patch these vulnerabilities. That is the government providing a social good. You know, the reason we have the social contract and government in the first place.
Allied nations regularly perform war games for practice. What about cyber war games?
I really do think a country should be proactively red teaming its own infrastructure and repairing any holes it finds. But it doesn't seem like the best interest of people who are more focused on offensive techniques.
When you are found out by the government, you're going to think really carefully about frivolous lawsuits to save face.
Not sure if a cost-benefit analysis would find such ops positive for the society.
Think of the time wasted by people who read such emails vs the money spent protecting from attacks.
Factor in the cost to the taxpayer.
That's a good topic for a Master thesis in Economics.
Anyone interested?
Might have been part of this scheme.
Don't have that box anymore (was around 5 years ago) or a PC on the DMZ so haven't received any since.
I doubt it. Network operators like Virgin have very good business reasons to ensure their own network isn't infested with computers running services like NetBIOS, which has no business being exposed on the internet (it is rather verbose, and completely useless outside of a LAN).
Edit: Looks like it has happened more than once
https://cybernews.com/security/we-hacked-28000-unsecured-pri...
https://www.bleepingcomputer.com/news/security/a-hacker-just...
https://paul.reviews/police-cyberalarm-abysmal-security-yet-... https://scottarc.blog/2022/07/04/police-cyberalarm-uses-alar...
And you might be interested in the ip space of all UK entities.
If you put it this way then the problem becomes way easier. Just check public ip databases for AS and technical contact.
But, at least at some level, this is true.
For those not aware, UK gov has pretty world leading tech services, the best example is the UX of the main sites like car tax
To give you a comparison, in the US you need to go down to the DMV with a wad of forms, get the bits you can't fill in filled in, let someone make up a price, decide you haven't filled a bit in properly, send you away to a different window, get something else filled in, pay a fee for the filling in, hand the papers in at yet another window, pay for the actual registration, get a temporary registration slip, pay for a set of plates to actually be fixed onto the vehicle, pay for the stickers that say you've paid for a plate, all of which paid by cheque at various windows, with no real idea of the total cost up front.
In the UK (where cars tend to keep the registration number they're given on first registration), you go to the DVLA website, follow the prompts for the kind of paperwork you have (reminder letter, V5 registration certificate, V5C "green slip" if you've just bought it that the previous owner tears off the bottom of the V5 and gives you), it tells you how much it'll be per month or per year, you put your credit card details in, and that's it. Paid, done, nothing more to do.
So every problem needs to be solved independently fifty times. People who live in continental Europe might have examples similarly because there are undoubtedly things European countries, especially EU member states could co-ordinate and don't. The difference in population between Luxembourg and Germany is even bigger than between Vermont and California.
Few years ago I got a similar notification. A government agency here in Lithuania was happy to remind that my wordpress instance was outdated.
Access to a MongoDB server should be restricted to trusted systems (for example, the related web application server)."
My mongodb had with auth - but port was open.
> The NCSC is committed to conducting scanning activities in a safe and responsible manner. As such, all our probes are verified by a senior technical professional and tested in our own environment before use. We also limit how often we run scans to ensure we don’t risk disrupting the normal operation of systems.
That is it? So... One gal looks at in and says, yep, fire up the guns! All is go!? Can I see the publish test? Can I see your "own environment"?
What will they do if (when) this service gets whacked and delivers a DoS on a bunch of sites? Send the webmaster a free credit check?
How does cloudflare, akamai, and similar feel about this?
Personally, I would not trust my dog's toothbrush to any gouvernement.
I would be happy to see this if it was opt in.
In my opinion, they should have spent all the money on securing themselves, increase their own security education, increase security staff compensation to get higher caliber staff, and public education.
The HN crowd is probably thinking about startups with in-house apps, but the canonical case for this argument is the Microsoft Exchange or Confluence servers that are consistently abused by ransomware actors - which then go on to cost that Government a lot of money as they get dragged into suppliers and contractors being held up for ransom, or investigatory resources being spent in response. It's very easy to tell who owns such a server, and being proactive helps address that.
It's fine to "not trust", but if this service poses any more of a threat to an organisation than the dozens of services already running you've got other issues.
Personally, I would not trust my dog's toothbrush to any gouvernement.
From https://news.ycombinator.com/newsguidelines.htmlEschew flamebait. Avoid generic tangents. Omit internet tropes.
Please don't use Hacker News for political or ideological battle. It tramples curiosity.
Please don't pick the most provocative thing in an article or post to complain about in the thread. Find something interesting to respond to instead.
curious to know how long until the scanning source IP's wind up in my pihole.
Opt in would miss exactly the sites they're targeting. People who don't bother to even think about security let alone do anything about security since as long as it works for them they don't care what happens to anyone else or their data. Opt in would also miss anyone who has been setting up their servers/sites maliciously or acting as safe havens for crime for profit.
If these scans end up causing problems they should be on the hook for damages, but I'm glad they aren't waiting around for people to find them and reach out begging for scans. The responsible people keeping up with security issues and doing things proactively are rarely the problem and do their own scanning already.
You dislike this not because it could be defined as invasive (it's not), or because it could DoS websites (it won't). You dislike this because it's done by the government.
The gov spending money on this endeavour hardly bleeds the coffers dry nor does it prevent investment in other sectors. This kind of radical, tech-first thinking is the kind of thing we should appluad the governments IT service for doing, because not too long ago there was virtually no innovation, anything tech related was offloaded to incompetent contractors such as Accenture and Deloitte.
In fact you're contradicting yourself in multiple ways.
> "[should have spent money on] public education.": this can be defined as public education.
> "increase security staff compensation": as noted, not too long ago lots of this work was delegated to contractors. This is a step in the right direction and soon we can hope the compensation will increase.
> "increase their own security education": have you got a source which states software engineers working for the gov aren't educating themselves?
> "That is it? So... One gal looks at in and says, yep, fire up the guns!": What were you expecting, a full panel of industry experts scrutinising the code followed up with a parliamentary committee? This is called a peer code review, a rather simple process which you'll find at any tech firm.
What about other kinds of servers?
Do they scan SMTP servers? What about POP/IMAP servers?
Do they scan web servers not on 80/443?
Do they scan IoT servers? Login servers on routers? SSH servers on anything?
Do they scan VPN servers, TOR exit nodes, or open proxies?
18.171.7.246 35.177.10.231
Block these IPs.
because that's literally how the internet works. Their ports are and will always be subject to arbitrary inspection while they are reachable on the internet.
Consider, for example, the possibility that the government might have technical people at least as adept as the average teenager looking to pirate movies. If they were trying to something you consider malicious, would they a) put up a public web page telling you how to detect their traffic and stop it[1] or b) scan it from IPs which are not easily attributed? Using cheap commercial hosting for that would cost a fraction of what they pay a single employee per month and it's not exactly a technically-daunting task — and if it were, they'd toss a few thousand at Shodan.io to do it for them, an amount which could be buried in the printer supply budget of any national government.
1. https://www.ncsc.gov.uk/information/ncsc-scanning-informatio...
That is a value judgment better made by the server owner, don't you think? It is their private (perhaps leased) property we're talking about after all. Perhaps the government should ask first before periodically scanning someone's property?
Again, I’m not saying you don’t have the right to block them - they even give you an easy way to opt-out - but that it seems misdirected to worry about the people asking nicely when the internet is full of actually malicious people who don’t ask.
If NCSC scan my systems for vulnerabilities, they're unlikely to exploit them, and they'll (somehow?) attempt to notify me of the risk.
I'm curious which systems they scan; cloud systems only? Will they scan the stuff I host at home too?
Would be nice if they'd give us some of the tools to run ourselves; any one know if it's on their Github?
Here's [0] a good example of the guidance they offer, password policy in this case
[0] https://www.ncsc.gov.uk/collection/passwords/updating-your-a...
I didn't think it would be.
Fun watching all the foreign traffic trying to hit Wordpress vulns on it, though.
“This page provides information on the [UK’s National Cyber Security Centre] NCSC’s scanning activities”
to assist the scanned site with fixing the vulnerabilities, right?
Their mission is to make online activities safe.
I think "maybe" drastically undersells the amount of time and things some people do online (generally the younger generations).
You're also overlooking that a very large portion of daily life has moved online and it's important to protect that. Everything from buying groceries, booking doctors appointments to looking up the menu of local restaurants.
I'd want all my personal and payment details protected, and it's reassuring to know information I'm reviewing hasn't been maliciously tampered with.
for NET in $UK_NETS; do nmap -p 80,443 $NET; donehttps://www.amnesty.org.uk/why-taking-government-court-mass-...
I suspect it's well over 50%. I mean, the UK is far from the only power capturing all our traffic.
Canada has a different approach, where institutions can sign up to using a federal DNS service provided through the domain registrar, which I interpret is not unlike 1.1.1.1 or 9.9.9.9, but with malware detection. I believe it's called Canadian Shield, and it's not active scanning, but rather passive collection from institutions that manage infrastructure.
Active scans by government seems a bit like domestic intelligence collection. Given the techincal capabilities of most of these agencies when they work with ISPs, hairpinning traffic from one of these scanned servers for inspection is trivial. Fine if the threat model involved exceptional cases with clear oversight, and individual decision accountability in response to ticking bomb situations, but the examples of how similar powers have been used in the past are so abundant that I'm having trouble remembering a situation where they were used to protect a mere citizen.
Am I interpreting correctly that you can join HackerOne to do work on UK public service projects? I tried to get something like that done for a municipality and a province, where it was going to be a way to engage college students on doing vulnerability hunting on public infrastructure, but also use it as a recruiting pipeline to get people interested in public service.
It's very easy to forget such laws exist because 99.99% of cybercrime goes unpunished - but that's for small victims, with hard-to-find attackers who are likely beyond the police's jurisdiction. If the 'victim' is an important government department, and you are within the police's jurisdiction, you could be one of the few people to actually face punishment - unjust though that may seem.
I believe CISA in the US has something similar too.
This is like saying foot patrols are a bit like SWAT raids. They are, a bit, but they are a lot more than a bit entirely unlike them.
It seems far more invasive to route all your DNS traffic through a untrusted source than having that same source use the exact types of scans attackers are using every day already and report problems they find to you.
I can learn a hell of a lot more about you by your DNS history than I can from knowing what ports you have open and what vulnerable services you're running.
The domain registrar is CIRA, and has only one of twelve board members having a federal government affiliation. See cira.ca for the facts. Their Canadian Shield services uses data from Akamai, Mozilla, and CCCS.
It is not "federal".
Sigh. Another comment from someone's memory that takes only 2 minutes to fact-check and discover to be incorrect.
https://cyber.gc.ca/en/news-events/canadian-shield-sharing-c...
It's a useful service that I was commenting on as analogous to the one being provided in the UK, and it taking a different and passive approach. Instead of apologizing, my favourite charity can be found at victimsofcommunism\.org
>In the unlikely event that we do discover information that is personal or otherwise sensitive, we take steps to remove the data and prevent it from being captured again in the future.
beyond a promise, what assurances do you get it wont be weaponzed?
what is preventing a government to disregard the removal of sensitive data? why can they not weaponize this?
http://www.cac.gov.cn/2021-07/13/c_1627761607640342.htm https://www.cpomagazine.com/cyber-security/is-china-looking-...
It's a part of the UK's security services running scans for vulnerabilities they already know about to tell you that you've got an issue.
> anything discovered in the country must now be reported to the CCP *and to no one else* (in most cases).
The "no one else" part is terrible and completely changes the story. However, I do generally support a "tell the government about discovered vulnerabilities" law. Ideally, the government would then inform affected users and investigate whether the vuln could be considered negligence and the company prosecuted.
I've been in a few situations where I reported very easily exploitable vulns that leaked sensitive user data and in all cases, I couldn't for the life of me convince the companies to disclose the leak. Yes, I could've gone public myself where I didn't have a contract, but I would've 100% ended up in jail for some poorly defined crime of "hacking".