Jump to content

Recommended Posts

Posted

I've just received the following message from an MP friend:

 

"There has been a "significant" cyber attack on the parliamentary e-mail system so I.T. security have shut off access for the time being"

 

Somehow I'd assumed that of all places the IT Security for Politicians would have been the bee's knees with nuts and bolts as well as bells and whistles on!

Posted

This posted to The Telegraph website a few minutes ago:

 

Link: Parliament hit by cyber attack leaving MPs unable to access their emails remotely

 

Parliament has been hit by a cyber attack that has left MPs unable to access their emails if not in Westminster.

 

MPs were alerted to the hack on Friday night and have reported problems getting into their email accounts on Saturday.

 

The attack comes just days after reports that passwords of ministers were being flogged online after hacking groups managed to gain access...

 

[Aside: 'Flogged' Not a typically Telegraph word. :lol:]

Posted

I noticed this as well. Sounds like they have taken the decision to turn off email as a way to contain it, so probably not that bad.

 

I'm sure more info will come out of it soon :-)

Posted
I hope they've got strong and stable security!

 

It'll be Boris sitting in the server room listening for good and bad data coming down the data pipes. They're screwed.

Posted

I have just received a password change request for my mail administrator (I did not initiate this, so I am guessing that someone has turned their attention to our E-Mail set up)

 

:(

Posted
As a side to this, anyone running office 365/ gmail etc should be running 2FA as a minimum on admin accounts.

 

We've just implemented 2FA for all staff on gmail. Took a while but and had a fair bit of moaning but we're almost there!

  • Thanks 1
Posted

Anyone get the feeling this is only going to get worse?

 

Main reasons why Schools have have avoided this kind of mess is because we've suffered it years ago or we know some one that did. We became obsessed with security because we know it can happen to us. In my time I've seen three major outbreaks all because the people responsible didn't care or think about security.

 

How many of us even work extra hours to make the system safe or have to fight against staff who don't want it.

 

I hate to put a positive spin on this but it gives us great ammo to use when doing any security work. NHS and Parliament both suffering issues in a short time.

Posted
Apparently a very small percentage of users had weak passwords, but you'd think password complexity rules would be enabled as standard?
Posted
I can picture several MPs who would struggle to type their own name, let alone a complex password. I suspect they threw a hissy fit when it was suggested.
  • Thanks 2
Posted
We've just implemented 2FA for all staff on gmail. Took a while but and had a fair bit of moaning but we're almost there!

 

Can you switch on 2FA just for Staff even if you have student accounts in the same G Suite domain?

 

Also I take it the 2FA relies on them having a mobile ? Is there an App similar to Microsoft where you can accept or decline approval for login?

Posted (edited)
Can you switch on 2FA just for Staff even if you have student accounts in the same G Suite domain?

Yes. You can force it on for all users in a particular organisation (rather than at the domain level).

 

Also I take it the 2FA relies on them having a mobile?

It doesn't have to. You can use authenticator apps or U2F USB keys (among other things).

 

Is there an app similar to Microsoft where you can accept or decline approval for login?

Google's version of that is called Google Prompt.

 

https://www.howtogeek.com/260369/how-to-set-up-google%E2%80%99s-new-code-less-two-factor-authentication/

Edited by Arthur
  • Thanks 1
Posted
Can you switch on 2FA just for Staff even if you have student accounts in the same G Suite domain?

Yes, we've not yet enforced 2 Factor Authentication on accounts yet as we want all staff to be enroled before we do this or they'll get locked out of their account. We're just making staff turn 2 factor on. We've got a few more to do and then we'll flip the switch on the google admin console to make it enforced and new starters will have to set it up as part of their induction. You can turn it on/off based on OU's in the Google Admin console so you can make sure only staff have it enforced.

Also I take it the 2FA relies on them having a mobile ? Is there an App similar to Microsoft where you can accept or decline approval for login?

Not necessarily a mobile but a phone is required for the initial setup (turning it on). Once it's turned on you can setup other methods of 2 step verification. For example, a USB stick (example: https://www.amazon.co.uk/d/USB-Gadgets/Key-ID-FIDO-U2F-USB-Security/B01JLRT33W). We had to get a couple of these as some support staff don't have mobiles or an iPad from the school.

 

Another method which most of our teachers are using it the Google Authenticator app: https://support.google.com/accounts/answer/1066447?hl=en . This works offline also. It's not 100% effective but works most of the time.

 

Another method is backup codes. You can create 10 backup codes which can be used only once. When they've all been used you have to generate more.

 

We're using GAM to generate reports to see who we have left to turn on 2 step verification. Once they're all done we'll enforce it on the staff OU so people can't turn it off.

  • Thanks 1
Posted (edited)
Yes. You can force it on for all users in a particular organisation (rather than at the domain level).

 

 

It doesn't have to. You can use authenticator apps or U2F USB keys (among other things).

 

 

Google's version of that is called Google Prompt.

 

https://www.howtogeek.com/260369/how-to-set-up-google%E2%80%99s-new-code-less-two-factor-authentication/

 

Google prompt only works on android devices that has your google account attached to it. This will work if you have android phones/tablets. If you have iPads you'll need to use the Google Authenticator app.

 

Edit: Just read the page and looks like it can work on IOS. Going to test this out! Thanks for the info.

 

Edit2: Yep it works really well. This seems better then the authenticator app although it doesn't work offline.

Edited by RLR

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...