urgent letter from National hacker community on government I - Pastebin.com

3 min read Original article ↗
  1. original (dutch) letter on http://wordpress.metro.cx/2011/09/15/brandbrief-ict-overheid/

  2. translated via google translate

  3. urgent letter from National hacker community on government IT security

  4. Just below is urgent letter to the Round Table of the House Committee on NASA awarded. The hacker spaces and organizations in the Netherlands speak here specifically about the lack of awareness of ICT security in the Dutch government. The letter was drafted and signed by all Dutch hacker spaces and three Dutch organizations that the hacker community together. The fire also sent a letter to the national media. We hackers are simply tired of repeatedly having to learn that in the implementation of large IT government systems childish mistakes are made that affect the privacy of citizens and sometimes even risk to human life suffers.

  5. The united Dutch hacker spaces and organizations

  6. PO Box 503

  7. 2501 HJ Den Haag

  8. To: Members of the Committee on Internal Affairs of the House of Representatives

  9. Subject: urgent letter from National hacker community on government IT security

  10. The Hague, 15 September 2011

  11. Dear members of the permanent Parliamentary Committee NASA,

  12. The Dutch hacker community, represented by the undersigned

  13. organizations, is concerned about the security of ICT systems

  14. Dutch government. Again and again we see how basic security principles

  15. not be applied within existing and new IT systems.

  16. Recent examples include the issue Diginotar and SSL certificates,

  17. OV-chip card, electronic patient records (EPR) and many others

  18. systems and environments. We have an extensive list of examples of

  19. government systems containing personal data or personal questions

  20. citizens that the security is not in order.

  21. These are not complicated hacks, but mistakes uneducated

  22. could exploit. This is standard software available on the Internet.

  23. These basic security principles are not structurally

  24. applied and a blind faith in technology, based on insufficient understanding

  25. the risks. Audits and certifications are paper tigers. It is

  26. sufficiently looked at the systems themselves and blindly relied on statements

  27. example of the developers.

  28. It is not enough to test whether the promises of ICT companies hired

  29. government are realistic and met. Adequate protection of

  30. databases containing personal data is not sufficiently ensured. There is no

  31. thinking about possible abuse of new systems. At the same time to

  32. government-related bodies such as the Data Protection

  33. (CBP) and GOVCERT not sufficiently involved in ICT projects.

  34. The hacker community is moved these items to denounce.

  35. However, there is currently a climate in which the messenger

  36. punished and the relevant departments and businesses are not accountable to

  37. are called. We are therefore reluctant to share information about

  38. these vulnerabilities.

  39. We are concerned about the fact that the vulnerabilities are so elementary

  40. , that it is virtually certain that these are people with bad intentions

  41. awareness and exploit these mistakes. As the recent issue with the

  42. Iranian government has shown. We therefore call on the issue

  43. Diginotar as incident, but as a symptom of a lack of

  44. monitoring the security of ICT systems in government. It is time for the

  45. Members of the House, those who represent the people, believed to be

  46. the people to guard against such mistakes, realize that there

  47. is a structural problem.

  48. The Dutch hacker community has the knowledge and skills with

  49. regarding the above issues, and shares this love with

  50. Representatives.

  51. Sincerely,

  52. Koen Martens

  53. On behalf of the united Dutch hacker spaces and organizations:

  54. Foundation Hack42 Arnhem

  55. ACKspace Foundation, Heerlen

  56. Foundation TkkrLab in Enschede

  57. Bitlair Foundation, Amersfoort

  58. Revelation Space Foundation in The Hague

  59. Random Data Foundation in Utrecht

  60. Frack Foundation in Leeuwarden

  61. Sk1llz Foundation in Almere

  62. Foundation eth0

  63. 2600nl.net

  64. Foundation HXX