Advertisement
Guest User

urgent letter from National hacker community on government I

a guest
Sep 15th, 2011
653
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.93 KB | None | 0 0
  1. original (dutch) letter on http://wordpress.metro.cx/2011/09/15/brandbrief-ict-overheid/
  2. translated via google translate
  3.  
  4. urgent letter from National hacker community on government IT security
  5.  
  6. Just below is urgent letter to the Round Table of the House Committee on NASA awarded. The hacker spaces and organizations in the Netherlands speak here specifically about the lack of awareness of ICT security in the Dutch government. The letter was drafted and signed by all Dutch hacker spaces and three Dutch organizations that the hacker community together. The fire also sent a letter to the national media. We hackers are simply tired of repeatedly having to learn that in the implementation of large IT government systems childish mistakes are made that affect the privacy of citizens and sometimes even risk to human life suffers.
  7.  
  8. The united Dutch hacker spaces and organizations
  9. PO Box 503
  10. 2501 HJ Den Haag
  11.  
  12. To: Members of the Committee on Internal Affairs of the House of Representatives
  13.  
  14. Subject: urgent letter from National hacker community on government IT security
  15.  
  16. The Hague, 15 September 2011
  17.  
  18. Dear members of the permanent Parliamentary Committee NASA,
  19.  
  20. The Dutch hacker community, represented by the undersigned
  21. organizations, is concerned about the security of ICT systems
  22. Dutch government. Again and again we see how basic security principles
  23. not be applied within existing and new IT systems.
  24.  
  25. Recent examples include the issue Diginotar and SSL certificates,
  26. OV-chip card, electronic patient records (EPR) and many others
  27. systems and environments. We have an extensive list of examples of
  28. government systems containing personal data or personal questions
  29. citizens that the security is not in order.
  30.  
  31. These are not complicated hacks, but mistakes uneducated
  32. could exploit. This is standard software available on the Internet.
  33. These basic security principles are not structurally
  34. applied and a blind faith in technology, based on insufficient understanding
  35. the risks. Audits and certifications are paper tigers. It is
  36. sufficiently looked at the systems themselves and blindly relied on statements
  37. example of the developers.
  38.  
  39. It is not enough to test whether the promises of ICT companies hired
  40. government are realistic and met. Adequate protection of
  41. databases containing personal data is not sufficiently ensured. There is no
  42. thinking about possible abuse of new systems. At the same time to
  43. government-related bodies such as the Data Protection
  44. (CBP) and GOVCERT not sufficiently involved in ICT projects.
  45.  
  46. The hacker community is moved these items to denounce.
  47. However, there is currently a climate in which the messenger
  48. punished and the relevant departments and businesses are not accountable to
  49. are called. We are therefore reluctant to share information about
  50. these vulnerabilities.
  51.  
  52. We are concerned about the fact that the vulnerabilities are so elementary
  53. , that it is virtually certain that these are people with bad intentions
  54. awareness and exploit these mistakes. As the recent issue with the
  55. Iranian government has shown. We therefore call on the issue
  56. Diginotar as incident, but as a symptom of a lack of
  57. monitoring the security of ICT systems in government. It is time for the
  58. Members of the House, those who represent the people, believed to be
  59. the people to guard against such mistakes, realize that there
  60. is a structural problem.
  61.  
  62. The Dutch hacker community has the knowledge and skills with
  63. regarding the above issues, and shares this love with
  64. Representatives.
  65.  
  66. Sincerely,
  67.  
  68. Koen Martens
  69. On behalf of the united Dutch hacker spaces and organizations:
  70.  
  71. Foundation Hack42 Arnhem
  72. ACKspace Foundation, Heerlen
  73. Foundation TkkrLab in Enschede
  74. Bitlair Foundation, Amersfoort
  75. Revelation Space Foundation in The Hague
  76. Random Data Foundation in Utrecht
  77. Frack Foundation in Leeuwarden
  78. Sk1llz Foundation in Almere
  79.  
  80. Foundation eth0
  81. 2600nl.net
  82. Foundation HXX
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement