Data loss

Oh dear. Child support records bunged on disc and stuck in the internal post from HM. Revenue & Customs to the National Audit Office. They didn't arrive, and now the bank details, National Insurance numbers, names, addresses, and dates of birth of basically everyone in the UK with a child under 16 ... are out in the open. Somewhere.

This in the same week that a Colossus has been working again. Ironic that we seem to know less about cryptographic data security now than we did sixty years ago.

We've just had a Treasury Secretary on the radio defending the forthcoming ID card concept as being a wholly different animal, since it'd be a new system, and not an old one like the Child Support set-up. While there's some merit in that argument, what seems fishy is that this feels like a systems design issue, not an IT issue at all.

Records are (apparently) sent to the NAO unencrypted? Does the NAO really need all those bits of information, or would a partial set reduce the data exposure? How could 'junior officials' be in a position to 'ignore security procedures'? Is plain-text data export just something that's viewed as routine?

Remarkable.

And no, I'm not a data security expert. On the other hand, I did once build an end-to-end encrypted data collection website, and I'm not a complete twit on this stuff. Witness my decision to build that system myself, because the web security 'experts' I consulted were uniformly clueless. Ah. Bingo.

1 Comment

Some reports claim it is password protected - http://news.bbc.co.uk/1/hi/uk_politics/7103566.stm - but given the other comments I suspect it is not a good password…

Leave a comment

About Jonathan

Lapsed: physicist and television producer. Now: media consultant/freelance film-maker, trying to reignite public-service children's media, particularly around science and engineering.

Categories

Recent Entries

  • Internet Watch Foundation filtering

    Lots of talk on Twitter today about [this](http://en.wikinews.org/wiki/UK_ISPs_erect_%27Great_Firewall_of_Britain%27_to_censor_Wikipedia): six major UK ISPs (including mine, the previously-rather lovely [Be](https://www.bethere.co.uk/)/O2, also Orange, Virgin, Demon, EasyNet, PlusNet and...

  • Building buzz without a budget

    Here's an excellent, [short presentation from the Nature Conservancy](http://www.slideshare.net/jcolman/building-buzz-without-a-budget-presentation?nocache=5510&type=powerpoint), outlining their use of Digg to drive traffic to a new website they were promoting. I...

  • The supercomputer in your web browser

    Computational Fluid Dynamics... [in Flash](http://www.joecutting.com/windTunnel.php). This is plain *wrong*, I tell you....

  • Things to know about the Panasonic HMC150/1

    I finally succumbed, and bought a proper camera. A video camera, none of your stills nonsense, nor yet a [stills camera masquerading as a video...

  • Alexandria Railway Station is in Dalaman, Turkey.

    Quoth [Wikipedia](http://en.wikipedia.org/wiki/Dalaman): > In 1906, Alexandria train station was built by mistake in Dalaman. ... In 1905 the then Khedive of Egypt Abbas Hilmi Pasha...

Close