Showing posts with label Pavitt. Show all posts
Showing posts with label Pavitt. Show all posts

Thursday, 23 May 2013

CloudStore and OJEU

The question was asked yesterday Is CloudStore entirely legal? and an impressively prompt response was received which deserves equal prominence:
Anonymous said...

*sigh*

The G-Cloud framework *is* procured through the OJEU process (every 6 months, hence we are on G-Cloud III now - see the official notice here: http://ted.europa.eu/udl?uri=TED:NOTICE:14199-2013:TEXT:EN:HTML&src=0). Once a framework has been established, public sector organisations can procure from that framework without the need for OJEU (because the suppliers on that framework have already been through the process). Page 7 of the document you quote has the relevant guidance (note that a mini-competition can be run by the buyer against the framework).

This is exactly the same as any one of the 104 framework agreements that the Government currently has in place (see: http://gps.cabinetoffice.gov.uk/i-am-buyer/find-a-product-or-service). Also note that this isn't just the UK - in 2010, 21,500 framework agreements were awarded across the EU (see: http://ec.europa.eu/internal_market/publicprocurement/docs/modernising_rules/cost-effectiveness_en.pdf)

22 May 2013 15:38
The Page 7 citation leads to:
Framework Agreements - These can be used for repeat but irregular purchases for example stationery supplies, legal services, building repairs. Generally they are of no more than four years’ duration.  There are four main types, single-supplier, multi-supplier, single user, multi-user.  Suppliers are selected following an initial OJEU notice, in the case of multi-suppliers (no less than three) subsequent mini-competitions are used to select winning contracts.  The same selection and award criteria used when setting up the framework agreement must be used when procuring services from this agreement.  Provided the agreement is compliant with these requirements, pre-existing framework agreements may be used to select suppliers to the project.  Contracting Authorities utilising a framework agreement need to ensure that they are eligible to make use of it and that the framework agreement has been properly established
There may be all sorts of problems with Whitehall's cloud computing strategy but so flagrantly infringing OJEU that even DMossEsq can spot it doesn't seem to be one of them.

----------

Updated 23 May 2013 12:04 p.m.
That is the case, at least, as long as you first agree that arranging to host the entire public administration of the country in the cloud is like making "irregular purchases for example stationery supplies, legal services, building repairs".

Take an example. See Skyscape bags biggest deal on G-Cloud EVER. Skyscape will be hosting the heir to the Criminal Records Bureau. How much like ordering the paper clips is that?

Updated 24 May 2013 19:45 p.m.
Even if the definition of "irregular services" is being stretched a bit, clearly OJEC think it's legal. So they won't object.

Who would?

Answer, maybe some of the long-established cloud services suppliers with impressive track records whose bids lost against Skyscape, a company that won contracts from GDS, the MOD and HMRC almost before it existed, please see Skyscape – would you invest £4 million? Thousands haven't., and who have now won a big contract from the Home Office. How did Skyscape manage to be accredited, let alone win?

CloudStore and OJEU

The question was asked yesterday Is CloudStore entirely legal? and an impressively prompt response was received which deserves equal prominence:
Anonymous said...

*sigh*

The G-Cloud framework *is* procured through the OJEU process (every 6 months, hence we are on G-Cloud III now - see the official notice here: http://ted.europa.eu/udl?uri=TED:NOTICE:14199-2013:TEXT:EN:HTML&src=0). Once a framework has been established, public sector organisations can procure from that framework without the need for OJEU (because the suppliers on that framework have already been through the process). Page 7 of the document you quote has the relevant guidance (note that a mini-competition can be run by the buyer against the framework).

This is exactly the same as any one of the 104 framework agreements that the Government currently has in place (see: http://gps.cabinetoffice.gov.uk/i-am-buyer/find-a-product-or-service). Also note that this isn't just the UK - in 2010, 21,500 framework agreements were awarded across the EU (see: http://ec.europa.eu/internal_market/publicprocurement/docs/modernising_rules/cost-effectiveness_en.pdf)

22 May 2013 15:38
The Page 7 citation leads to:
Framework Agreements - These can be used for repeat but irregular purchases for example stationery supplies, legal services, building repairs. Generally they are of no more than four years’ duration.  There are four main types, single-supplier, multi-supplier, single user, multi-user.  Suppliers are selected following an initial OJEU notice, in the case of multi-suppliers (no less than three) subsequent mini-competitions are used to select winning contracts.  The same selection and award criteria used when setting up the framework agreement must be used when procuring services from this agreement.  Provided the agreement is compliant with these requirements, pre-existing framework agreements may be used to select suppliers to the project.  Contracting Authorities utilising a framework agreement need to ensure that they are eligible to make use of it and that the framework agreement has been properly established
There may be all sorts of problems with Whitehall's cloud computing strategy but so flagrantly infringing OJEU that even DMossEsq can spot it doesn't seem to be one of them.

----------

Updated 23 May 2013 12:04 p.m.
That is the case, at least, as long as you first agree that arranging to host the entire public administration of the country in the cloud is like making "irregular purchases for example stationery supplies, legal services, building repairs".

Take an example. See Skyscape bags biggest deal on G-Cloud EVER. Skyscape will be hosting the heir to the Criminal Records Bureau. How much like ordering the paper clips is that?

Updated 24 May 2013 19:45 p.m.
Even if the definition of "irregular services" is being stretched a bit, clearly OJEC think it's legal. So they won't object.

Who would?

Answer, maybe some of the long-established cloud services suppliers with impressive track records whose bids lost against Skyscape, a company that won contracts from GDS, the MOD and HMRC almost before it existed, please see Skyscape – would you invest £4 million? Thousands haven't., and who have now won a big contract from the Home Office. How did Skyscape manage to be accredited, let alone win?

Wednesday, 15 May 2013

"When it comes to cyber security QinetiQ couldn’t grab their ass with both hands"

So said Bob Slapnik, vice president at HBGary, the security experts "detecting tomorrow's threats today", as reported by Bloomberg, the company that's been using its financial information terminals to spy on its clients. So says the New York Times, the company whose cyberdefences were breached in 2012 by the Chinese, seeking to stop people being rude about Prime Minister Wen Jiabao. Although the Chinese say they didn't.

You can see why Mr Slapnik was cross back in 2010. QinetiQ had just won a contract to advise the Pentagon on how to counter cyberespionage despite QinetiQ's own computer systems having been comprehensively hacked for the previous three years.

But talk about the pot calling the kettle black, one reason QinetiQ's inability to grab its ass with both hands came to light was an examination of the documents hacked out of HBGary in 2011 by Anonymous, the cybervigilantes previously derided as mere "script kiddies", who were so piqued by Aaron Barr, HBGary's CEO, pretending that he had infiltrated them that Anonymous ...
... infiltrated HBGary’s servers, erased data, defaced its website with a letter ridiculing the firm with a download link to a leak of more than 40,000 of its emails to The Pirate Bay, took down the company’s phone system, usurped the CEO’s twitter stream, posted his social security number, and clogged up fax machines ... 'You brought this upon yourself. You’ve tried to bite the Anonymous hand, and now the Anonymous hand is bitch-slapping you in the face', said the letter posted on the firm’s website ...
That's according to Dr Thomas Rid, who finishes his report with: "the attack badly pummeled the security company’s reputation". Yes, you can see how it would, but HBGary (detecting yesterday's threats tomorrow) had been commissioned to sort out QinetiQ's cybersecurity problems so circumspice, Mr Slapnik.

Not to be left out, Bloomberg had been targeted by the same Chinese hackers in pursuit of the same object – keeping Mr Wen's business dealings out of the news. Fail. Everyone who is anyone had been hacked. The Pentagon briefed "about 30" defence contractors like QinetiQ about Chinese hacking in 2007-08, too late to stop the Chinese acquiring so much information on Lockheed Martin's F-22 and F-35 fighter jets that it's doubtful now whether it's worth deploying them. Ditto the designs for the US combat helicopter fleet, drones, satellites and military robotics, all of which were copied from QinetiQ's computers.

Bloomberg's computers weren't hacked straight from China. The Chinese tried to come in via computers they had taken over in various US universities. Same modus operandi, NASA complained to QinetiQ that it was under attack by the Chinese via QinetiQ's computers and would QinetiQ please sort it out. Investigators into that hack found that you could just sit in the car park and connect to QinetiQ's network via an unsecured wifi. They also found that the Russians had been stealing trade secrets from QinetiQ for 2½ years.

Towards the end, the Chinese had access to 13,000 internal passwords at QinetiQ and they could do pretty much whatever they wanted: "by 2009, the hackers had almost complete control over TSG’s computers". TSG is QinetiQ's Technology Solutions Group, whose boss reckoned that investigating all this hacking took too long. "You finally have to reach a point where you say let’s move on" and, indeed, he has now moved on.

HBGary weren't the only security experts trying to sort out QinetiQ. Mandiant were in there (and at the New York Times) and suggested using two-factor authentication to log on to the QinetiQ network, the way those of us with a Lloyds business account do. No, said QinetiQ, and off went all their robotics designs.

HBGary's counter-espionage software was installed on 1,900 QinetiQ computers but it wouldn't run on a lot of them and when it did it missed some rogue software and reported some benign software and it slowed the machines down so users did what they always do and deleted it. HBGary accused another consultant, Terremark, part of Verizon, of withholding information and Terremark said damned if they were telling HBGary anything, their clunky software was alerting the hackers to the investigation.

Two months after the all-clear, the FBI had to tell QinetiQ they were losing data again and all the consultants came back and tried to clear out the malware they had missed last time round. Meanwhile, the Chinese have got bomb disposal robots on the market that look remarkably like QinetiQ's but they're cheaper.

All of which is just by way of introductory remarks. Setting the scene.

Remember Skyscape? The cloud computing company owned by just one man? The company with contracts from the MOD, HMRC and the Government Digital Service (GDS)?

GDS never did respond to the letter asking them how they had seen fit to entrust GOV.UK to a one-man company. But HMRC did. Twice. Which is very proper of them.

The HMRC response came from Phil Pavitt, HMRC's Director General Change, Security and Information. He said (22 October 2012):
Skyscape’s services are provided through a number of key, or “Alliance”, Partners. These partners are industry leading organisations that provide services in the data centre or “cloud” arena such as EMC (storage  and security services), Cisco (networking) and Ark Continuity (UK based high security data centres) ...

... data security remains integral to HMRC and a pre-requisite of any of our data being migrated to Skyscape is for their solution, including all the constituent parts, to be formally accredited by CESG (the Communications-Electronics Security Group) to Impact Level 3 (IL3) ...

This accreditation is expected imminently, at which point HMRC will be in a position to begin securely moving data over to Skyscape and decommissioning our old servers ... will be re-competed to ensure HMRC continues to take advantage of innovative, secure and low cost solutions ...

It should also be noted that for security reasons HMRC does not discuss details of the data that it holds, or where it stores it, however we are able to confirm that by using Skyscape HMRC data will continue to be kept in accordance with existing legislation and HMRC security policies ...

The data, which will be securely stored by Skyscape, currently resides on several hundred servers, across multiple HMRC office locations. This change will consolidate that data and place it into a small number of secure and highly resilient cloud data centres hence improving the security of the data, the efficiency of managing that data ...
and (28 November 2012):
I must reiterate our assurance that using Skyscape HMRC data will continue to be kept in accordance with existing legislation and HMRC security policies.

When fully operational, Skyscape Cloud Services Ltd will securely host all HMRC data currently held on office File and Print Servers (FAPS) ... FAPS do not hold the definitive tax records for the UK and these records remain distributed across a number of secure systems.

HMRC routinely risk assesses and tests the security of our solutions and services. Our secure connection to Skyscape will be delivered in line with HM Government standards to protect our data, with ongoing assurance checks throughout the life of this service ...

Data security remains integral to HMRC and a pre-requisite of any of our data being migrated to Skyscape is for their solution, including all the constituent parts, to be formally accredited by CESG (the Communications-Electronics Security Group) to Impact Level 3 (IL3). All security aspects of the service will have to be proven in line with HM Government security standards. This will include the need to ensure the ‘cloud’ is hosted in a UK domiciled, secure data centre(s) and operated by staff with appropriate security clearance ...
It's not just HMRC. Here's GDS in their Government Digital Strategy:
We know that our users often find it hard to register for our online services, so it is
vital that we offer a more straightforward, secure way to allow our users to identify
themselves online while preserving their privacy ... (p.34)

Legality, security and resilience

Transactional services will be redesigned to:
  • be robustly protective of the security of sensitive user information
  • maintain the privacy and security of all personal information ... (p.46)
And here's Mydex, one of the UK's eight identity providers, writing about PDSs (personal data stores):
Personal Data Stores create a single, secure, easy-to-access store for such information so that when we need it it’s at our finger tips ... (p.8)

... the PDS can create one single message informing them of the fact that the card has been lost. It can then be sent securely, direct to their systems ... (p.9)

... behind each payment there is a hugely sophisticated system of highly secure data ‘handshakes’ taking place across a complete eco-system of supporting players ... (p.14)

Etc ...
Skyscape is in an alliance with QinetiQ. That doesn't bode well. But it's not just QinetiQ. The Pentagon felt it necessary, remember, to brief about 30 contractors on cybersecurity. They all have problems. Are any of them capable of grabbing their ass with both hands?

Judging by the daily diet of cyberattack stories, no. Cybersecurity looks like a myth. Just bear that in mind whenever a supplier offers you security.

----------

(Hat tip: Anonymous @ 3 May 2013 10:31, see also the excellent 'Chinese' attack sucks secrets from US defence contractor in ElReg®)

----------

Updated 22.5.14

There were bound to be consequences.

With all these allegations of Chinese hacking flying around, the US had to do something. And now they have. 19 May 2014:
America sues China over corporate spying
America's fraught trading relationship with China turned even more hostile on Monday, after Washington filed an unprecedented lawsuit against Beijing for corporate spying.

The US Department of Justice accused members of China’s military, the People’s Liberation Army, of stealing sensitive information from major energy and metal companies, including Alcoa, the aluminium producer, and Westinghouse, which makes nuclear reactors.
The post above was written three weeks before the Edward Snowden revelations. We now know what we didn't in mid-May 2013 that the US is quite capable of a bit of hacking themselves. It's not just China.

Which may be what China had in mind in their initial response to the US suing them. They called the US a "high-level hooligan". Not entirely impolite – it's better than being a low-level hooligan.

Then they raised the stakes, by calling the US a "mincing rascal". It's not clear which international law being a mincing rascal contravenes. But it sounds bad. China wins phase one of the epithet war.

This whole cybersecurity and countersecurity business is fraught with dilemmas. Ethical, legal, diplomatic and trade dilemmas.

Given that you are a rascal, is it better to be a mincing one than not? It's not clear.

And then there's the FBI problem.

Like everyone else, they're trying to recruit infosec/information security experts. These experts are exceptional people. Few and far between, an inordinate number of them lead lives fuelled on drugs, 21 May 2014:
Wacky 'baccy making a hash of FBI infosec recruitment efforts

... FBI Director James Comey ... reportedly told the White Collar Crime Institute that he needs a “great work force” to compete with the black hats, but “some of those kids want to smoke weed on the way to the interview”.
Ethics, the law, diplomacy or trade? Which one will win?

Trade. It often doesCisco to Obama: get NSA out of our hardware. Etc ...


Updated 19.1.15

China now knows what most people in the west are catching up with: that the F-35 Joint Strike Fighter is a lemon.

The latest round of managed information release by Edward Snowden via Spiegel (one of a series) includes the snippet that Chinese security services copied “terabytes” of data about the aircraft ...
Please see also China calls Snowden's stealth jet hack accusations 'groundless'. "Lockheed Martin is producing the F-35 for the U.S. military and allies in a $399 billion project, the world's most expensive weapons program.".

So much for the security of Lockheed Martin's computer systems.

Lockheed Martin must be among the best in the business. The security business. And $399 billion should buy you the best of ... just about everything. And yet "the F-35 Joint Strike Fighter is a lemon".

Charming old stick-in-the-muds that they are, the Government Digital Service may believe that they can offer the public a secure national identity scheme, GOV.UK Verify. But they really can't expect us to believe it. Not now.


Updated 25.5.15

John Bercow mood music

"Read our blog", said the self-proclaimed Digital Leaders on 25 May 2015, and pointed us all at a 12 February 2015 blog post by John Bercow MP, Speaker of the House of Commons, British democracy and the digital revolution.

Mr Speaker established a special Commission in late 2013 to "consider how the digital revolution has changed or might further develop British representative democracy".

The Commission has reported now. It sets five targets. And target #4 is:
By 2020, secure online voting should be an option for all voters.
 Feasible?

Just reading over the post above, you can't help noticing that Lockheed Martin of all people couldn't keep the design of the F-35 Joint Strike Fighter secure. Ditto the F-22. Ditto the designs for the US combat helicopter fleet, drones, satellites and military robotics, all of which were copied from QinetiQ's computers. But Mr Speaker thinks that on-line voting could be secure.

Why does he think that? What does he know that Lockheed Martin and QinetiQ don't?

And Sony. What does Mr Speaker know that Sony don't know?

Remember Sony?
For two weeks or so now [we said in December 2014], we have all watched as Sony's private and confidential correspondence has been published by hackers, personal details about the stars of their films have been revealed and the value of the company's intellectual property has been destroyed.
If Mr Speaker can obtain endorsements from Lockheed Martin, QinetiQ and Sony to the effect that they have good reason to believe that he knows how to deliver secure on-line services including electronic voting, maybe we'll believe that his target #4 is feasible. Otherwise, no, his words are just John Bercow mood music.

"When it comes to cyber security QinetiQ couldn’t grab their ass with both hands"

So said Bob Slapnik, vice president at HBGary, the security experts "detecting tomorrow's threats today", as reported by Bloomberg, the company that's been using its financial information terminals to spy on its clients. So says the New York Times, the company whose cyberdefences were breached in 2012 by the Chinese, seeking to stop people being rude about Prime Minister Wen Jiabao. Although the Chinese say they didn't.

You can see why Mr Slapnik was cross back in 2010. QinetiQ had just won a contract to advise the Pentagon on how to counter cyberespionage despite QinetiQ's own computer systems having been comprehensively hacked for the previous three years.

Sunday, 4 November 2012

Cloud computing – how to lose control of your data #94

It's Sunday. Give us a break
Cloud computing is supposed to be cheaper than the alternatives. How many times have we heard that some new management fashion will save us money? How many times can we fall for it? How many times has it turned out to be true? Exactly.

Cloud computing is meant to be more efficient, more reliable, more trusted, more flexible, more scalable, more resilient, more modern, more transformative, ... In each case, the claim is either false or, at best, unproven.

No need to keep banging on about it, the point has been made.

Sign up for cloud computing, like what Her Majesty's Government has in the UK, and you lose control of your data. You want to go out of business? Go ahead. Up to you. Stick your data in the cloud.

We know that. It's all a bit relentlessIt's Sunday. Give us a break.

The gift that keeps on giving
Actually, there's another reason to avoid cloud computing, one that hasn't been mentioned so far on DMossEsq, a new answer to the question why is it foolish to store your data in the cloud.

Kim Dotcom, mega
Still very young, Mr Schmitz
or Dotcom
or Kimble (c.f. The Fugitive)
will be all of 39 years old
on 21 January 2013
6'6" tall and weighing 290lb, the only reason Kim Dotcom (né Schmitz) didn't go to prison after being found guilty on 11 counts of fraud was that ... he was under age at the time of the offences and the judge put it all down to youthful foolishness.

Like most teenagers, he had hacked into NASA. And Citibank. He had also found out how to make international phone calls for free and, unlike most teenagers, had a nice little sideline selling access to these free telecommunications facilities.

He got off the 11 fraud charges with a suspended sentence. And the 10 data espionage charges. But when the insider trading charges started to look a bit serious, he decamped to Thailand. The Thais extradited him back to Germany and he finally served a stretch there. Five months on remand. Quite right, too.

Mr Dotcom loves playing computer games, particularly Modern Warfare 3.

That is not a recognised sign of intellectual achievement, you say.

As you wish. But some people are better at problem-solving than others. How good are you? There are over 15 million players of Modern Warfare 3 worldwide and Mr D was ranked #1, only falling to #2 after a sojourn in a New Zealand prison, about which, more anon.

He also loves cars. Driving in Morocco one day, he became impatient with the car in front and rammed it off the road. These things happen. How was he to know it was being driven by the chief of police?

Kim next set up shop in Hong Kong, picked up a few fines for false declarations to the stock exchange and for marketing a hedge fund that had many fine qualities, like artificial intelligence, but didn't happen to exist and the good ship Dotcom next struck land in New Zealand.

Megaupload
But before that, while in Hong Kong, he had set up a real company, Megaupload. A cloud services company, with 150 staff and and revenues of $175 million p.a., Megaupload had 60 million users, or 180 million according to some reports, it was ranked #13 among all the websites in the world and accounted for 4% of web traffic. Worldwide.

If New Zealand had any qualms about Kim Dotcom's application for residence, the thought of uploading some his money into New Zealand seems to have allayed them. He rented the most expensive house in the country, he laid on a $600,000 fireworks display in Auckland and he donated $50,000 to the mayor's re-election campaign.

Mr Dotcom was rich.

There was a problem when the mayor later had trouble remembering this donation. What would you do, you who have never played Modern Warfare 3? Kim recorded a song called Amnesia. See? Problem-solving. Some people are good at it.

Megaupload was so big that it rented no less than 1,100 servers from another cloud services company, Carpathia, to store all the data people kept handing over.

Got it. You're going to lecture us about contracts. Users may have a contract with one cloud services supplier (e.g. Megaupload) but, if that company hands the users' data over to another cloud services supplier (e.g. Carpathia) with whom the users have no contract, then they have lost control of their data. Ha!

Wrong. Everyone knows that already. That's not a new reason to beware the perils of cloud computing. Think again ...

Hollywood loves a swashbuckler
Not this one they don't.

According to Hollywood, Megaupload has cost them $500 million. It was a seat of piracy, Hollywood's intellectual property rights were being stolen by felons illegally uploading films and TV programs to Megaupload.

That's just my point, you say, you shouldn't be making light of the activities of a seedy criminal.

No-one is making light of anything, least of all Mr Dotcom, who may be a criminal but he is entertaining as well, both, the one doesn't exclude the other.

And not so fast with the "criminal". His Megaupload crimes are alleged. He hasn't been found guilty of them. There's a law. The Digital Millennium Copyright Act (DMCA), which protects the suppliers of a website from the illegal activities of the users of that website. Without that, Sergey Brin of Google would spend his whole time in prison because of all the porn on YouTube. So stick that in your pipe, Roundhead, smoke it and inhale.

DMCA and the evidence against Kim Dotcom were presumably considered by a grand jury and on 5 January 2012 he was indicted on charges of online piracy, racketeering, copyright infringement, and money laundering. That was in Virginia. In the US.
But Mr Dotcom was in New Zealand.

I know. You're going to hold forth on RICO, the Racketeer Influenced and Corrupt Organizations Act, the law they said would only ever be used against suspected gangsters, when opponents of its introduction suggested that its powers were so useful that prosecutors would be unable to resist the temptation to charge everyone with offences under RICO. No, no, said the legislators, that will never happen. But of course it has.

You mean like the surveillance laws here in the UK? The ones they said would only ever be used against suspected terrorists and now local councils use them for fly-tipping offences and dogs fouling the pavement and parents lying about living in the catchment area for desirable schools? No. Completely wrong. Everyone already knows about that. The question is what new reason is there to believe that it's foolish to store your data in the cloud? If all else fails, as teachers used to tell their students, try reading the question.

Due process
The indictments are in Virginia and Dotcom's in Auckland. What would Clarice Sparrow Starling do?

She would probably have a quiet word with her opposite numbers in New Zealand's Government Communications Security Bureau (GCSB). Point out how much appreciated it would be if they could help in this matter. She might maybe exert a bit of pressure. US tariffs on New Zealand lamb imports could be lifted. Or they could be increased. Extraordinary rendition? That kind of thing.

Kim Dotcom appears in court in Auckland in January.
The US wants New Zealand to extradite him
to face internet piracy allegations.
Photograph: AFP/Getty Images
Whatever the FBI said, GCSB went into action immediately. They put Dotcom under surveillance and two weeks later, on 19 January 2012, they got the assault rifles out, started up the helicopter and armed police invaded the Dotcom manor, impounded his possessions right, left and centre, arrested Kim, locked him in prison and froze his assets worldwide.

Which made it hard for him to pay his rent. Or his lawyers. When he was finally allowed access to a bit of his money, the lawyers argued successfully that it was against the law for GCSB to put New Zealand citizens under surveillance, including Kim Dotcom, and that the arrest warrant had been wrongly drafted – too non-specific.

The Prime Minister of New Zealand has subsequently apologised for these mistakes to Mr Dotcom personally and to New Zealanders in general and he has confirmed that GCSB officers mistakenly allowed FBI officers, who happened coincidentally to be present, to take copies of Mega Kim's impounded disk drives.

Prime Minister Key's re-election prospects are in doubt. So are President Obama's. Kim Dotcom blames him personally for his enforced stay in Mt Eden prison, Auckland.

At some point, Mrs Dotcom gave birth to their fourth and fifth children, girl twins, and Kim toyed with the idea of sending the placenta to the FBI to check for pirated DNA, another solution that would never have occurred to you, would it, but let's leave him there, he's clearly quite big enough to look after himself, and turn our attention instead to Kyle Goodwin.

OhioSportsNet
Back in January, the FBI took control of all Megaupload's domain names and their computers and they told Carpathia to keep the 1,100 servers Megaupload rented from them untouched.

The FBI also managed to freeze Megaupload's bank accounts.

Given that Megaupload is a Hong Kong company, how?

Bloomberg think it's something to do with one of Mr Dotcom's fellow defendants having a US address and being an "alter-ego" of the company. Any port in a storm.

Thing is, among the 60 million users of Megaupload, just a couple of them may not be copyright pirates or pornographers. Some of them, like Kyle Goodwin, may run their own legitimate business in Ohio, filming sports events for local high schools, and streaming the footage to sports coaches and the doting parents of the athletes. And Mr Goodwin would kind of like his footage back, please, he's got a business to run, Megaupload have no objection to the return of his data and neither have Carpathia but the courts have:
  • Who says it's his data, the US government asks? Or as their lawyers put it: “Mr. Goodwin has yet to demonstrate whether he has an interest in any property seized by the government ... the mere fact that he may claim, for example, an initial copyright to a version of the files he uploaded is not sufficient to establish that he has an ownership interest in the property that is the subject of this motion”.
  • Suppose we look at what is allegedly Mr Goodwin's data and find he's been infringing copyright? Then what? If he doesn't have "clean hands", we just might start doing a bit of indicting in Ohio.
  • But look, we can't possibly entertain Mr Goodwin's request. It would take ages.
  • And suppose everyone else started asking for their data back, too? Then where would we be?
  • And Carpathia are moaning, too, claiming that it's costing them $9,000 a day to keep these pestilential 1,100 servers out of use. Far as we're concerned Carpathia can just delete all the data on them, all 25 petabytes of it (that's 25 million gigabytes), a course of action various fussy defence lawyers have asked Carpathia please to not pursue.
http://www.megaupload.com today

Your data
And there, ladies and gentlemen, we have the answer.

Mr Goodwin is being represented by lawyers from the Electonic Frontier Foundation (EFF) and they say that "the [US] government maintains that Mr. Goodwin lost his property rights in his data by storing it on a cloud computing service ... both the contract between Megaupload and Mr. Goodwin ... and the contract between Megaupload and the server host, Carpathia ..., likely limit any property interest he may have in his data".

Sign a cloud computing contract and you lose the rights to your property.

The question was, what new reason is there to believe that storing your data in the cloud is a mistake?

And the answer is that you're going to have the devil of a job getting your solicitor to nip over to Quantico to prove that it's yours at all. And as for actually getting it back, forget it. The courts don't have time for all that nonsense. Easier just to delete it.

They wouldn't do that to HMRC and all our tax data stored on Skyscape Cloud Services Ltd's servers. Would they? There are 60 million of us for goodness sake. That could never happen. Could it? And then there's GDS and all our state benefits data stored on ditto ...

Don't you worry about that. Whitehall aren't worried. Don't you worry.

----------

Updated 5.11.12

Philip Johnston, Daily Telegraph, 'Whitehall has its head stuck in the cloud'


Updated 21.2.17

Andrew Orlowski, ElReg, 'NZ High Court rules US can extradite Kim Dotcom after all'

Cloud computing – how to lose control of your data #94

It's Sunday. Give us a break
Cloud computing is supposed to be cheaper than the alternatives. How many times have we heard that some new management fashion will save us money? How many times can we fall for it? How many times has it turned out to be true? Exactly.

Cloud computing is meant to be more efficient, more reliable, more trusted, more flexible, more scalable, more resilient, more modern, more transformative, ... In each case, the claim is either false or, at best, unproven.

No need to keep banging on about it, the point has been made.

Sign up for cloud computing, like what Her Majesty's Government has in the UK, and you lose control of your data. You want to go out of business? Go ahead. Up to you. Stick your data in the cloud.

We know that. It's all a bit relentlessIt's Sunday. Give us a break.

The gift that keeps on giving
Actually, there's another reason to avoid cloud computing, one that hasn't been mentioned so far on DMossEsq, a new answer to the question why is it foolish to store your data in the cloud.

Wednesday, 24 October 2012

HMRC and Skyscape 2

The following open letter has been sent by email and by post to Phil Pavitt in his capacity as HMRC Director General Change, Security and Information with a copy to Lin Homer, Chief Executive, HMRC:

[Skyscape has subsequently changed its name to UKCloud: "London – August 1, 2016 – Skyscape Cloud Services Limited, the easy to adopt, easy to use and easy to leave assured cloud services company, has today renamed and relaunched as UKCloud Ltd (www.ukcloud.com), to reinforce the company’s exclusive focus on supporting the UK public sector in the digital transformation of services".]

Open letter [1]

Phil Pavitt          Your ref. CETO /03531/2012
HMRC Director General
Change, Security and Information
100 Parliament St
London SW1A 2BQ          24 October 2012

Dear Mr Pavitt

HMRC and Skyscape Cloud Services Ltd

Thank you for your letter dated 22 October 2012 [2] in response to my letter to Lin Homer dated 11 October 2012 [3].

The point is well taken, of course, that for security reasons HMRC can’t say what data is held where. We're in we-can-neither-confirm-nor-deny territory here. It’s difficult but, given the bizarre nature of the Skyscape contract, HMRC are going to have to find some way to reassure the public about the security with which our tax records, both personal and corporate, are being held.

“The data will continue to be kept in accordance with existing legislation and HMRC security policies”, you say. I should hope so, too – the public want, need, deserve and pay for nothing less.

But your statement begs the question.

The public is bound to assume that the data to be stored at Skyscape’s cloud computing facilities is the tax records of every individual and legal person in the country. What other data does HMRC have?

And the public is bound to assume that our data is intended to be stored at Hartham Park, Corsham, Wilts SN13 0RP because that’s the address of the registered office of Skyscape Cloud Services Ltd and it’s the address of the registered office of its “ally” ARK Continuity Ltd and it’s the address of ARK’s Spring Park data centre as noted for everyone to see on ARK’s website [4]. If that isn’t a breach of security, what is?

Skyscape is a young start-up, it hasn’t yet submitted any accounts to Companies House, it has no track record, it has only one director and he owns all the shares in the company. If the Government Procurement Service (GPS) and HMRC believe that Skyscape is an appropriate company to trust with the care of our tax records, then there is something wrong with GPS’s and HMRC’s selection criteria.

CloudStore make the point that the inclusion of a company and its services in its on-line store is not a warranty of appropriateness. It’s up to the customer – in this case HMRC – to determine appropriateness. Eleanor Stewart, the Assistant Director of G-Cloud, says [5]: “as with everything on the G-Cloud framework the customer can determine whether they are happy with any associated risk at the point of selection”.

The references to GPS and to CloudStore in your letter can provide the public with no comfort.

You mention the Skyscape Cloud Alliance [6] in your letter.

Goodness knows what ARK Continuity is doing in the Alliance. HMRC doesn’t promote itself as being in an alliance with Mapeley. Why does Skyscape expect the public to find it commercially persuasive to include its landlord in the Alliance?

QinetiQ, VMware, Cisco and EMC on the other hand are all industry leaders and if HMRC had entered into a contract with a joint venture company involving them then we wouldn’t be having this correspondence.

But you haven’t.

HMRC have entered into a contract with a one-man start-up. That was the case before you wrote your letter and it remains the case subsequently. The question therefore persists, how can HMRC make such an odd-looking decision? How can they risk the nation’s tax records on Skyscape?

There’s no joint venture company there for a Tax Inspector to get his or her teeth into. Just an “alliance”. What is an alliance in this case?

The contract is to provide cloud computing services. “Cloud computing” means losing control [7]. Whitehall promotes cloud computing on the basis that it turns IT into a utility [8]. That is not attractive, as this month’s news about gas and electricity prices will confirm.

None of us has control over the price our suppliers charge for gas and electricity at home or control over their staff. If HMRC enter into a cloud computing contract with any supplier, big or small, they will have the same problem. How can HMRC risk the nation’s tax records on cloud computing?

Salesmen sometimes unfortunately make over-enthusiastic claims about cloud computing being more resilient, secure and efficient than the alternatives. Lawyers don’t believe them. Lawyers don’t use cloud computing. Lawyers are paid to keep their clients’ data under control and confidential. So are public authorities like HMRC.

As I write, I note that the latest cloud computing dĂ©bâcle is unfolding. Amazon are the biggest cloud computing suppliers in the world and they’ve just had a 12-hour outage [9].

Our tax records are currently stored on hundreds of servers at “multiple” HMRC offices, you say. Good. That looks secure. Much more secure than storing them all in one place with a one-man start-up in some sort of nugatory alliance. And, since you mention it, the allegedly dainty carbon footprint of cloud computing will be no consolation if our records go up in smoke.

According to HMRC’s press release [10] the Skyscape contract will save £1 million a year on running costs. We need to be guided here by the National Audit Office (NAO) report on HMRC’s on-line filing [11].

The NAO examined HMRC’s £8 billion 10-year ASPIRE contract with Capgemini and said:

HMRC uses a range of indicators to measure the performance of its ICT services, which include online services, and it measures availability that relates specifically to online filing. HMRC has a high-level view of the overall costs of ICT provision through the ASPIRE contract. It has been taking steps to improve that information and achieve cost savings. It does not yet have a detailed breakdown of the costs of online filing services, so it cannot benchmark those costs to assess their value for money. HMRC is currently negotiating with the ASPIRE contractors to obtain a clearer breakdown of the costs of ICT services provided. (p.8)
Also:

[HMRC] should proceed with its plans to identify ICT costs specific to online filing services and ensure that current negotiations with the ASPIRE contractors provide sufficient breakdown of cost information for regular benchmarking of costs. (p.13)
In the circumstances, with the suppliers not even prepared to tell HMRC what they are charging for, some scepticism is in order about claims to be able to identify £1 million of on-line filing costs in among the £8,000 million.

CESG have rescued the nation before from other-worldly decisions taken by Whitehall. The Home Office wanted to use DWP’s National Insurance number database as the National Identity Register for the ID cards scheme. CESG pointed out that it was inappropriate and that was the end of that [12].

Let’s hope that they repeat the trick in their review of Skyscape. I look forward to a small piece appearing in the technical press somewhere out of the way regretting that for security reasons which cannot be given the HMRC contract with Skyscape has had to be revoked.

Yours sincerely
David Moss

cc      Lin Homer, Chief Executive, HMRC
          Chartered Institute of Taxation
          Institute of Chartered Accountants in England and Wales




[7]Cloud computing and the Gadarene lemmings of Whitehall, http://www.dmossesq.com/2012/10/cloud-computing-and-fashion-conscious.html
[8]Cloud computing turns IT into a utility, and that's a good thing?, http://www.dmossesq.com/2012/10/cloud-computing-turns-it-into-utility.html
[9]Amazon outage started small, snowballed into 12-hour event, http://www.networkworld.com/news/2012/102312-amazon-outage-263617.html
[11]HM Revenue & Customs – The expansion of online filing of tax returns, http://www.nao.org.uk//idoc.ashx?docId=cd237708-5c6b-472a-af13-f432f80d80cc&version=-1
Updates:
24.5.12
Phil Pavitt says "we don't currently have ID authentication in UK government".
24.10.12
Letter emailed to Phil Pavitt and Lin Homer
25.10.12
Hard copy of letter posted to Phil Pavitt and Lin Homer, links sent to Eleanor Stewart, CIOT and ICAEW
28.10.12
Re last two paragraphs of letter, see Andy Smith affair.
4.11.12
US government argue that signing a cloud services agreement reduces your property rights in the data stored in the cloud, according to EFF.
13.11.12
Cloud computing, and GDS's fantasy strategy: "To which, all one can say is that there must be something wrong with the Cabinet Office, GPS and HMRC procurement criteria ...".
23.11.12
UK.gov to upgrade buying tool after mega cockup downs £1bn deal – Government Procurement Service computer system incapable of handling tenders for government procurement.
26.11.12
HMRC soon to be Pavittless – will Aviva store all our insurance details with Skyscape?

HMRC and Skyscape 2

The following open letter has been sent by email and by post to Phil Pavitt in his capacity as HMRC Director General Change, Security and Information with a copy to Lin Homer, Chief Executive, HMRC:

[Skyscape has subsequently changed its name to UKCloud: "London – August 1, 2016 – Skyscape Cloud Services Limited, the easy to adopt, easy to use and easy to leave assured cloud services company, has today renamed and relaunched as UKCloud Ltd (www.ukcloud.com), to reinforce the company’s exclusive focus on supporting the UK public sector in the digital transformation of services".]

Sunday, 30 September 2012

G-Cloud, GDS, HMRC and Skyscape, the company with just one director, who owns all the shares – Whitehall SNAFU

The story so far ...

The Government Digital Service (GDS) have contracted with Skyscape Cloud Services Ltd to host the new unified central government website, GOV.UK, in the cloud.

Episode 1, Insanity – are they mad? Skyscape is a £1,000 company. Isn't that a bit small for this monumental responsibility?

Whitehall's G-Cloud team say this is an example of good practice, using small and medium-sized enterprises (SMEs) instead of the ponderous and expensive big boys.

Episode 2, Mendacity – are they lying? Skyscape claims to be in alliance with five other companies whose combined turnover is £43.3 billion and who have over 100,000 staff. Isn't that a bit big for an SME?

Now read on ...

[Skyscape has subsequently changed its name to UKCloud: "London – August 1, 2016 – Skyscape Cloud Services Limited, the easy to adopt, easy to use and easy to leave assured cloud services company, has today renamed and relaunched as UKCloud Ltd (www.ukcloud.com), to reinforce the company’s exclusive focus on supporting the UK public sector in the digital transformation of services".]

Episode 3, Confusion – what's going on?

HMRC
Now HMRC have signed up with Skyscape as well as GDS. Phil Pavitt, HMRC's CIO (Chief Information Officer) says that the shift to cloud ...
... will save over £1 million a year in running costs and will increase reliability and security of HMRC's internal IT services.

The Skyscape contract is a major step for HMRC in moving away from traditional ways of working with large service providers. And it's a great example of how we're exploring smarter, more innovative solutions that make life simpler for us and help us provide a better deal for our customers ...
  • Will Mr Pavitt's head roll if the Skyscape contract doesn't "save over £1 million a year in running costs"?
  • Suppose Skyscape put their prices up?
  • Suppose Skyscape go bust – it's only a £1,000 company after all?
  • Suppose Skyscape's servers fall over for a fortnight like the Royal Bank of Scotland's did earlier this summer?
  • Does HMRC have good enough book-keeping systems to know if £1 million has been saved and where and why?
  • HMRC is no SME – its ASPIRE contract with Capgemini and Fujitsu is worth £8 billion over ten years. Is it worth taking the risk of using Skyscape to save one eight-thousandth eight-hundredth of the value of just one contract among many?
  • ...
We know the answer to one of those questions. The National Audit Office have told us that when HMRC asked their suppliers to be a bit more explicit what they were charging for on their invoices, the suppliers refused. HMRC pay anyway, whatever it is they're paying for.

God, but Lin Homer's got a lot of work to do.

Skyscape
Never mind all those questions for the moment, the point at issue is that Mr Pavitt thinks that Skyscape is a small company.

How small?

We already know that it has only £1,000 of paid up share capital. And that the company is too young to have filed any accounts yet, so we have no idea about its P&L and balance sheet. The G-Cloud team have approved Skyscape to sell its wares on HMG's Cloudstore, GDS have bought from them and so have HMRC – how did they satisfy themselves as to Skyscape's commercial health?

They may not have filed any accounts but Skyscape have filed an annual return, as at 3 May 2012, according to which:
  • The registered address is Hartham Park, Hartham, Corsham, Wilts SN13 0RP
  • The company has one director – Mr Jeremy Robin Sanders
  • And one shareholder – Mr Jeremy Robin Sanders
GDS and HMRC haven't signed up with one company so much as with one man. One man owns all the shares and is the only director of the company which hosts the central government website and hosts some of HMRC's data. One man. What's going on?

GOV.UK depends on one man. Mr Sanders. Bits of HMRC depend on one man. Mr Sanders. The G-Cloud team have approved one man to sell his wares on the Cloudstore. Mr Sanders. The UK is a big, complicated, modern state with 1,000 years of democracy behind it and government contracts affecting the entire population are signed with just one man. Mr Sanders.

While that's sinking in, en passant, note that Mr Sanders didn't always own all the shares in Skyscape. Mr Jeffery (sic) Paul Thomas used to own one share. Then on 19 April 2012 he transferred it to Mr Sanders. You won't forget that name, will you – Jeffery (sic) Paul Thomas.

The Skyscape Cloud Alliance
The following note appears on the Skyscape website ...
SKYSCAPE CLOUD ALLIANCE

The Skyscape Cloud Alliance partners; QinetiQ ,VMware, Cisco, EMC, and Ark Continuity bring together an end to end cloud solution which is Skyscape. This Alliance also provides a collaborative resource which drives innovation and our technical product development programme.
What does it mean?

If it means that Skyscape is a joint venture company set up by the allies, then Skyscape has the backing of £43.3 billion of annual revenue and 100,000 staff worldwide. Which means that it's not really an SME at all.

But it doesn't say that. The five companies are called "partners". But Skyscape isn't a partnership, it's a limited company.

Presumably Skyscape haven't just put these names on their website because it looks good. Because it's handy for marketing. If they used these names without the allies' permission, they'd be sued. There must be some sort of a commercial arrangement between Skyscape, QinetiQ and the others. But what sort of arrangement?

Skyscape are not mentioned in the accounts of QinetiQ or VMware or any of the allies. The nature of this commercial arrangement is a mystery. A gentlemen's agreement of some sort, perhaps? Surely that's not enough for G-Cloud, GDS and HMRC to rely on.

ARK Continuity
ARK Continuity is the odd one out among the Skyscape allies. It's relatively tiny. According to its annual return as at 16 December 2011:
  • The registered address is Hartham Park, Hartham, Corsham, Wilts SN13 0RP, the same as Skyscape's.
  • It has a company secretary and three directors – two bankers plus Mr Jeffrey (sic) Paul Thomas, possibly the ex-shareholder of Skyscape.
  • It has two classes of 1p ordinary shares, A and B, 800 of each issued, so it has £16 of share capital, not all paid up at the date of the return.
  • Revcap Properties 25 Ltd owns all 800 A ordinaries and Mr Jeffrey (sic) Paul Thomas owns 320 of the B ordinaries.
According to the 30 April 2011 Ark Continuity annual report and accounts, the two bankers are appointed as directors to represent the interests of Revcap Properties 25 Ltd, the 75% majority shareholder, the ultimate parent company of Revcap Properties 25 Ltd is Real Estate Venture Capital Partners LLP and:
The principal activity of the company and the group is the design, construction and operation of data centres
Nearly finally, on 9 August 2012, ARK Continuity appointed Baroness Elizabeth Lydia Manningham-Buller a director. The Rt Hon The Baroness Manningham-Buller was of course, formerly, the Director General of MI5.

On their website, ARK Continuity are naturally proud of their Spring Park data centre. They're a property company. Of course they're proud.

That's Spring Park at Hartham Park, Corsham, Wilts SN13 0RP, they provide a map of how to get there and they say that:
Spring Park affords occupiers the opportunity to embrace best practice and sustainable principles in the design, construction, engineering and operation of their data centres

Spring Park is one of Europe's premier data centre locations. Strategically positioned and built on a legacy of over 50 years investment in critical national infrastructure, Spring Park comprises 14.79ha of surface land, 9.29ha of underground, access to 114MVA diverse power supply and c93,000m² of consented data centre and office development

Located one mile from the A4 and 8 miles from J17 of the M4 between Swindon and Bristol, the site is adjacent to secure MoD facilities and benefits from significant connectivity infrastructure

To see the location map click here
To watch the History of Spring Park click here
The early footage of the Romans quarrying stone at Corsham to build the new town of Bath in the green belt is fascinating but someone should tell ARK about security. The Rt Hon The Baroness Manningham-Buller, perhaps?

The MoD might prefer it if ARK Continuity didn't tell people where their secure facilities are. GDS and HMRC, too.

And let's hope to God that that's not where GOV.UK is being hosted and where HMRC have stored their records. Because otherwise, now, thanks to ARK Continuity's website, everyone will know.

G-Cloud, GDS, HMRC and Skyscape, the company with just one director, who owns all the shares – Whitehall SNAFU

The story so far ...

The Government Digital Service (GDS) have contracted with Skyscape Cloud Services Ltd to host the new unified central government website, GOV.UK, in the cloud.

Episode 1, Insanity – are they mad? Skyscape is a £1,000 company. Isn't that a bit small for this monumental responsibility?

Whitehall's G-Cloud team say this is an example of good practice, using small and medium-sized enterprises (SMEs) instead of the ponderous and expensive big boys.

Episode 2, Mendacity – are they lying? Skyscape claims to be in alliance with five other companies whose combined turnover is £43.3 billion and who have over 100,000 staff. Isn't that a bit big for an SME?

Now read on ...

[Skyscape has subsequently changed its name to UKCloud: "London – August 1, 2016 – Skyscape Cloud Services Limited, the easy to adopt, easy to use and easy to leave assured cloud services company, has today renamed and relaunched as UKCloud Ltd (www.ukcloud.com), to reinforce the company’s exclusive focus on supporting the UK public sector in the digital transformation of services".]