SSI Veille- Découvrez le n°1 de CyberRisques

Il est paru malgré la pandémie, l’annulation de tous les événements professionnels et la désorganisation des services postaux. Alors tout le monde va en profiter ! Nous vous proposons l’édition PDF complète de ce numéro un à découvrir, à lire, à faire connaître et à commenter afin de préparer un numéro deux qui réponde si possible encore mieux à vos attentes.

https://cyber-risques.news/decouvrez-le-n1-de-cyberrisques/

CyberRisques est une nouvelle publication trimestrielle destinée aux professionnels de la sécurité informatique : CISO, CSO, DPO… L’objectif est d’apporter un éclairage business sur les enjeux de la cybersécurité et les meilleurs moyens de répondre aux défis croissants de ce domaine.
CyberRisques aborde la gestion des risques, la gouvernance, la conformité, les enjeux juridiques, les technologies et outils sous l’angle des métiers et des secteurs d’activité des entreprises.

STOPCOVID – Le « Bureau des légendes » ou jouir de la surveillance

Surveiller et jouir, pourquoi il est difficile de faire entendre à la population les dangers du numérique

https://www.franceculture.fr/emissions/la-vie-numerique/le-bureau-des-legendes-ou-jouir-de-la-surveillance

D’autres curiosités culturels liées au monde de l’Espionnage

La Taupe, film inspiré de la Trilogie de Karla de John Le Carré

cf. https://fr.m.wikipedia.org/wiki/Karla

En complément cf. L’aristocratie de l’Espionnage dans

https://www.franceculture.fr/emissions/conversations-secretes-le-monde-des-espions

Le Bureau des légendes n’est pas une série d’espionnage, mais une série sur la bureaucratie.

https://www.franceculture.fr/emissions/la-conclusion-daurelien-bellanger/le-bureau-des-legendes

Zoom : plus de 500 000 comptes piratés et disponibles sur le dark web

3-4 minutes


Ces comptes sont tous disponibles à la vente pour une bouchée de pain sur le dark web, avec à la clé un accès facile à toutes les conversations des utilisateurs.

Pourtant, Zoom s’était enfin décidé à sécuriser vos appels. Mais visiblement ce n’est pas encore tout à fait le cas. D’après la société spécialisée en sécurité informatique Cyble, plus de 500 000 comptes Zoom ont été piratés et vendus sur le dark web contre une bouchée de pain, voire cédés gratuitement dans certains cas.

Problème, ces données contiennent ni plus ni moins que les adresses mails, les mots et identifiants ainsi que les URL des conférences privées des utilisateurs Zoom. Les pirates ont pu également se procurer les mots de passe qui régissent l’accès à ces conversations personnels. De fait, ces centaines de milliers d’utilisateurs sont à la merci d’un « Zoom Bombing » à répétition.

https://www.android-mt.com/news/zoom-plus-de-500-000-comptes-pirates-et-disponibles-sur-le-dark-web/100883/

SSI COVID-19 – Dans quelles mesures l’application StopCovid pourrait-elle être privacy by design ?

globalsecuritymag.fr

9-11 minutes


Dans quelles mesures l’application StopCovid pourrait-elle être privacy by design ?

Écartée par le gouvernement dans les premiers jours de la pandémie de coronavirus, la possibilité d’une application de backtracking conçue pour identifier les chaînes de transmission du Covid-19 est finalement au coeur des débats.

https://www.globalsecuritymag.fr/Dans-quelles-mesures-l-application,20200414,97624.html

France Weighs Its Love of Liberty in Fight Against Coronavirus

https://www.nytimes.com/2020/04/17/world/europe/coronavirus-france-digital-tracking.html

By Norimitsu Onishi and Constant Méheut 16-20 minutes


The French are cautiously considering digital tracking, which has proved effective in Asia. But can a country that so prizes personal freedom and privacy ever accept it?

Police officers in Paris checking for certificates that people are required to produce when they are outside.
Police officers in Paris checking for certificates that people are required to produce when they are outside.Credit…Dmitry Kostyukov for The New York Times

PARIS — As France sought clues last month on how to tame the coronavirus, experts looked at one tool that has been central to the strategy of some Asian nations: digital tracking. Citing threats to “individual liberties,” the powerful interior minister dismissed it as alien to “French culture.”

But three weeks — and a tenfold spike in deaths — later, French culture could be changing, along with those of other Western democracies as they struggle to adjust the balance between personal privacy and the public good while attempting to reopen their societies and economies without setting off another wave of coronavirus infections.

In Italy, politicians have proposed blood tests to detect antibodies to the virus before licensing people to leave their lockdowns. President Trump may push for hiring hundreds of people to perform contact tracing as part of his effort to allow Americans to go back to work and school.

And in France, as President Emmanuel Macron extended a nationwide lockdown by at least another month this week, he said his government was considering using a smartphone tracking app that would inform people if they have come in contact with an infected person.

Such steps are particularly fraught in Europe, the continent with the world’s toughest online privacy rules.

The fight against fascism and communism in the 20th century left societies wary of the intrusions of authoritarian power. That is true from Eastern Europe, through Germany and Italy. France, where the nation’s values sprang from revolution against monarchy, is particularly attached to notions of individual rights.

“It has to do with French history and a sensitivity to freedom that is inherent to French culture,” Cédric O, who is spearheading the development of the app as France’s junior minister in charge of digital affairs, said in an interview.

Even so, recent experience in Asia shows that comprehensive tracing of infection chains, along with aggressive testing, has proved critical to fighting the pandemic, which is calling into question a host of Western assumptions, whether the use of digital tracking or the wearing of face masks.

With nearly 18,000 official deaths, France’s toll is surpassed only by that of Italy and Spain, which have also prolonged restrictions on their populations, and the United States. But the authorities are cautiously optimistic that the worst is over.

As the country, like others, struggles to find a way out of a lockdown that is now entering its second month and has kept a population of 67 million confined to their homes and paralyzed its economy, options that once seemed unfathomable have steadily become more palatable.

“We gave up an absolutely fundamental freedom, that of movement, while most of the Asian countries chose instead to be much more coercive on the individuals,” said Gilles Babinet, vice president of the French Digital Council, a commission that advises the French government.

Mr. Babinet said there was more to learn from Asian democracies, like South Korea, whose use of intrusive digital tracking has helped it avoid imposing the kind of strict lockdowns experienced in Europe.

“You must have a device that is both coercive to those infected and as gentle as possible to the others,” Mr. Babinet said.

So far, many Asian governments have handled the crisis by limiting deaths to a fraction of those suffered in the West. In most cases, that was done not by resorting to debilitating nationwide lockdowns, but rather in part by employing digital tracking, a practice embraced even by strong democracies like South Korea and Taiwan.

In Europe, the possibility conjures up images of China’s authoritarian rulers. An app created by the semi-authoritarian government of Singapore, the longtime proponent of Asian values, is the inspiration for versions being developed by the French, Germans and other Europeans.

Those who argue in favor of allowing its intrusiveness say that it is fair to infringe on people who are infected rather than inhibit the freedom of society as a whole.

“We know the patient’s contacts, where the patient goes and stays, and so we don’t need to lock down everybody,” said Ki Mo-ran, an epidemiologist who is advising the South Korean government’s coronavirus response.

Sign up to receive an email when we publish a new story about the coronavirus outbreak.

Without digital tracking, governments cannot know precisely “which place is contaminated, which place is clean, so they need to lock down,” Ms. Ki said. “Everybody’s freedom is affected. We have to ask ourselves if one person’s privacy is more important than the lives of a family or other people.”

Thanks to multipronged digital tracking — of cellphones, credit card usage and security camera footage — the South Korean authorities are able to closely monitor the movements of infected people. Health officials can then carry out tests on people who are potentially infected. People ordered into self-quarantine are monitored through an app.

Faced with a major outbreak, South Korea, with 52 million people, has managed to limit its official deaths to 230.

The South Korean government can make use of such intrusive tracking — though only during epidemics — because lawmakers changed privacy laws after an outbreak of MERS killed nearly 40 people in 2015.

Back then, health officials practicing traditional contact-tracing found that infected people, including “super spreaders,” often failed to reveal all of the people with whom they had been in touch, or patients were too sick to be interviewed, Ms. Ki said.

Weakening privacy laws was a consequential step for South Korea, where people in their 50s and older remember snatching democracy from the country’s military rulers in 1987.

They included people like Ahn Byong-jin, a political scientist at Kyung Hee University in Seoul who was a student activist during the democratization era. He has come to regard Western liberal democracies, with their overriding emphasis on “personal liberty and privacy,” as being ill-equipped to respond to situations like terrorism or epidemics.

“In these kinds of emergency situations, we need to adapt,” Mr. Ahn said.

Early instances in which a large amount of personal information was released raised fears of a government overreach. But in what was regarded as a referendum on the handling of the crisis, voters handed South Korea’s governing party a landslide victory in parliamentary elections on Wednesday.

“If you look at Korea compared with Europe or the United States, the critical difference seems to be tracking and testing,” said Kim Seok-hyeon, a researcher at the Science and Technology Policy Institute in Seoul. “In the West, they will have to think more about those measures.”

But for some French, the idea of giving up personal liberties is a non-starter.

While tracking technology has been used by Asian democracies, they are “democracies where the rule of law is not as strong as it is here,” said Gaspard Koenig, a philosopher who has written about the relationship between technology and freedom, including in Asia.

When Mr. Macron said that France’s lockdown would be extended until May 11, he immediately framed the debate that lawmakers are expected to have on tracking technology.

“This epidemic cannot weaken our democracy, nor impinge on liberties,” he said.

Mr. O, the official leading the development of France’s technology, said that after studying the tracking technology used in Asia, France had settled on the least intrusive form — the Singaporean app, called “TraceTogether.”

But there are concerns that the app, relying mainly on a sense of civic duty, will be so watered down in France that it will prove ineffective.

The app — called “StopCovid” in France — would be installed voluntarily on people’s smartphones, would not track their locations or movements, and would use only Bluetooth technology to help trace a person’s recent contacts.

If users tested positive for the coronavirus and indicate their status on the app, their recent contacts would be automatically alerted, and it would be up to them to take the appropriate steps by getting tested, seeking treatment or self-quarantining.

The French version would be different from Singapore’s in at least one fundamental way, Mr. O said. In France, the list of recent contacts would never be made available to the government.

“To be honest, people are asking whether it’s enough and whether we need to take it up a notch,” Mr. Babinet said.

Mr. O acknowledged that one of his main worries was whether enough people in France would install the app on their smartphones to work as a broad contact-tracing tool. The French, he said, are “by nature cautious toward technology and even progress,” especially compared with Asians.

Even in Singapore, only about 20 percent of people have downloaded the app, and the authorities recently introduced stricter confinement measures to curb a jump in infections. Singapore — which has officially suffered only 10 deaths out of a population of 5.6 million — has said that three-quarters of the population needs to use the app in order for it to be effective.

Despite being a weakened version of the least intrusive tracking technology used in Asia, the app has already drawn fierce opposition from Mr. Macron’s party in Parliament, La République En Marche.

Sacha Houlié, a lawmaker, said that using the app would signify a “profound cultural shift” in France.

“We are France,” Mr. Houlié said. “In terms of civil liberties, being France means something. It means that, in a sense, the world is watching what we do.”

  • Updated April 11, 2020
    • When will this end? This is a difficult question, because a lot depends on how well the virus is contained. A better question might be: “How will we know when to reopen the country?” In an American Enterprise Institute report, Scott Gottlieb, Caitlin Rivers, Mark B. McClellan, Lauren Silvis and Crystal Watson staked out four goal posts for recovery: Hospitals in the state must be able to safely treat all patients requiring hospitalization, without resorting to crisis standards of care; the state needs to be able to at least test everyone who has symptoms; the state is able to conduct monitoring of confirmed cases and contacts; and there must be a sustained reduction in cases for at least 14 days.
    • How can I help? The Times Neediest Cases Fund has started a special campaign to help those who have been affected, which accepts donations here. Charity Navigator, which evaluates charities using a numbers-based system, has a running list of nonprofits working in communities affected by the outbreak. You can give blood through the American Red Cross, and World Central Kitchen has stepped in to distribute meals in major cities. More than 30,000 coronavirus-related GoFundMe fund-raisers have started in the past few weeks. (The sheer number of fund-raisers means more of them are likely to fail to meet their goal, though.)
    • What should I do if I feel sick? If you’ve been exposed to the coronavirus or think you have, and have a fever or symptoms like a cough or difficulty breathing, call a doctor. They should give you advice on whether you should be tested, how to get tested, and how to seek medical treatment without potentially infecting or exposing others.
    • Should I wear a mask? The C.D.C. has recommended that all Americans wear cloth masks if they go out in public. This is a shift in federal guidance reflecting new concerns that the coronavirus is being spread by infected people who have no symptoms. Until now, the C.D.C., like the W.H.O., has advised that ordinary people don’t need to wear masks unless they are sick and coughing. Part of the reason was to preserve medical-grade masks for health care workers who desperately need them at a time when they are in continuously short supply. Masks don’t replace hand washing and social distancing.
    • How do I get tested? If you’re sick and you think you’ve been exposed to the new coronavirus, the C.D.C. recommends that you call your healthcare provider and explain your symptoms and fears. They will decide if you need to be tested. Keep in mind that there’s a chance — because of a lack of testing kits or because you’re asymptomatic, for instance — you won’t be able to get tested.
    • How does coronavirus spread? It seems to spread very easily from person to person, especially in homes, hospitals and other confined spaces. The pathogen can be carried on tiny respiratory droplets that fall as they are coughed or sneezed out. It may also be transmitted when we touch a contaminated surface and then touch our face.
    • Is there a vaccine yet? No. Clinical trials are underway in the United States, China and Europe. But American officials and pharmaceutical executives have said that a vaccine remains at least 12 to 18 months away.
    • What makes this outbreak so different? Unlike the flu, there is no known treatment or vaccine, and little is known about this particular virus so far. It seems to be more lethal than the flu, but the numbers are still uncertain. And it hits the elderly and those with underlying conditions — not just those with respiratory diseases — particularly hard.
    • What if somebody in my family gets sick? If the family member doesn’t need hospitalization and can be cared for at home, you should help him or her with basic needs and monitor the symptoms, while also keeping as much distance as possible, according to guidelines issued by the C.D.C. If there’s space, the sick family member should stay in a separate room and use a separate bathroom. If masks are available, both the sick person and the caregiver should wear them when the caregiver enters the room. Make sure not to share any dishes or other household items and to regularly clean surfaces like counters, doorknobs, toilets and tables. Don’t forget to wash your hands frequently.
    • Should I stock up on groceries? Plan two weeks of meals if possible. But people should not hoard food or supplies. Despite the empty shelves, the supply chain remains strong. And remember to wipe the handle of the grocery cart with a disinfecting wipe and wash your hands as soon as you get home.
    • Can I go to the park? Yes, but make sure you keep six feet of distance between you and people who don’t live in your home. Even if you just hang out in a park, rather than go for a jog or a walk, getting some fresh air, and hopefully sunshine, is a good idea.
    • Should I pull my money from the markets? That’s not a good idea. Even if you’re retired, having a balanced portfolio of stocks and bonds so that your money keeps up with inflation, or even grows, makes sense. But retirees may want to think about having enough cash set aside for a year’s worth of living expenses and big payments needed over the next five years.
    • What should I do with my 401(k)? Watching your balance go up and down can be scary. You may be wondering if you should decrease your contributions — don’t! If your employer matches any part of your contributions, make sure you’re at least saving as much as you can to get that “free money.”