Technology

How Russian password technology made its way into Irish State agencies

Irish State Agencies Handed Sensitive Information to Russian-Linked Password Manager

A password manager claiming to be EU-based has secretly been tied to a Russian company licensed by Russia’s security service, raising concerns about the potential compromise of sensitive government data. Passwork, a password manager that boasts of its robust security features, has been used by several Irish State agencies, including the Dublin Institute for Advanced Studies.

Last October, Dmitri Grigoriev, the head of IT at the Dublin Institute for Advanced Studies (DIAS), received an unsolicited email from Passwork. Grigoriev, unaware of the company’s true affiliations, agreed to a free trial of the password manager, which was subsequently rolled out to the institute’s employees.

Links to Russia’s Security Service

Passwork’s ties to a Russian company called P@ssword, which is licensed by Russia’s Federal Security Service (FSB), were uncovered by investigative journalists. P@ssword’s website, which is hosted on a Russian domain, explicitly states that it is licensed by the FSB, Russia’s primary security agency. The company’s website also features a logo bearing the insignia of the FSB.

The FSB has a history of involvement in cybersecurity threats, hacking, and surveillance. Its ties to Passwork raise concerns about the potential compromise of sensitive government data stored on the password manager.

What this means

The revelation highlights the importance of verifying the authenticity and security credentials of third-party vendors used by government agencies. The incident serves as a stark reminder that even seemingly robust security measures can be compromised by hidden affiliations or vulnerabilities.

The Irish government has yet to comment on the issue, but the episode raises serious questions about data protection and the vetting process for third-party vendors used by State agencies.

The incident is a stark reminder that the lines between security and surveillance can become easily blurred, and that even the most seemingly secure systems can be compromised by hidden affiliations or vulnerabilities. What’s more, it highlights the need for greater transparency and scrutiny when it comes to the security credentials of third-party vendors used by government agencies.

Leave a Comment

Your email address will not be published. Required fields are marked *