Showing posts with label Data Security. Show all posts
Showing posts with label Data Security. Show all posts

Yet another USB stick lost by British government agency

by Michel Smith

London, September 15, 2008: The Home Office has this evening announced that one of its police forces – believed to be the West Midlands Force – has lost a data memory stick with sensitive data.

While the Home Office refuses to comment as to the contents of the memory stick it is believe to contain sensitive information of anti-terrorist operations. When you thought it could not get an y worse, apparently it can. One of these days, as I said in the previous piece, the luck will run out and someone is going to use the data against this country and its people.

The more we hear of such losses the more a sense of deja vu overcomes me and the more I want to scream at this people to, at least, have hardware encrypted sticks on which to carry the data. It is NOT rocket science and they are easily available. I have reviewed a few of them by now.

Maybe someone should point the government agencies into the direction of this journal and the reviews done by yours truly. They might just get the idea, but then again, they still may not. I am beginning to lose confidence that this government can actually learn how to deal with sensitive data of any kind.

© M Smith (Veshengro), September 2008
<>

The umpteenth case of data loss – due to wild party?

by Michael Smith

How blasé can any government actually be as regards of sensitive data? It would appear that the British government is trying to provide an answer to that question for there is no other way, I am sure, to explain all this kind of careless sloppiness, which by now borders on the criminal negligent, in the handling and dealing with sensitive information and data.

Now, this time, the travel plans and destinations and other details of seventy soldiers of the 3rd Battalion the Yorkshire Regiment.

The data in question was stored on a USB-Stick and this little comrade is now, since the year 2004, the 120th stick that has been lost by the British government and it agents.

The lost stick was lost and found in the Nightclub “The Club” in Newquay, Cornwall. How it got there and how it was lost is till now unknown. Maybe it would be a good idea to actually ask which member of staff it was who had the grandiose idea to carry that stick with him or her with such sensitive data into a nightclub.

The loss of this stick and the unencrypted data on the stick could have been rather dangerous for the soldiers concerned, especially in light of the always mentioned danger from terrorists. In fact it is rather amazing that to this very day none of the lost data has, apparently, not fallen into the wrong hands and been misused. This despite the fact that in most instances none of the data has been encrypted in any way, shape or form.

To any terrorist the lost stick with the data of the soldiers would have been a goldmine and would have made them very happy indeed. On the UBS stick were contained the exact times of travel, the destinations and all routes and planned accommodation. Phew! Only good it did not get into the wrong hands and was found by an honest person. One day the luck will, however, run out, of that we can be sure.

The Ministry of Defence has only called this incident in its statement a “unhappy incident”. To call this attitude blasé probably is an understatement. How can any government and government agency have such attitude with such kind of sensitive data? This is especially difficult to understand as hardware encrypted USB sticks are no longer costing a fortune and regardless of cost, such data should, if stored on USB sticks, should, nay must, be put onto such sticks that are encrypted to the highest standard. Otherwise the day will come when the luck will finally run out and such data found will be used against this country and us, as the people of this country.

© M Smith (Veshengro), September 2008
<>

Another case data loss by UK Government another case of deja vu

by Michael Smith

Slowly but surely the feeling of deja vu overcomes one when one hears how well the British government, either directly or via private contractors and subcontractors, deals with the private data of its citizens and employees.

On Saturday, September 6, 2008 the Justice Minister was informed of the fact that a contractor to the government has lost a hard drive with the private and personal information of 5,000 prison service staff. While it is, obviously, worrying enough that such a hard disk has been lost, the most worrying part is the fact that it has been lost for about a year already and only now the company acting as a contractor to HM government had the integrity to actually inform the relevant department of the fact that this hard drive is gone, lost, cannot be found.

First question in my mind, aside from the fact of asking what took them that long to admit the loss, is how on earth you can lose a hard drive. While, I am sure, we all, to some extent, can understand how one could mislay and lose an USB stick or a CD with data, losing a hard drive, whether, and we have not been told, this is one that actually sits in a PC or is removable, is something entirely different. This loss in my mind smells to high heaven of theft, probably stolen for financial gain. What is the bet that none of the data held on that hard drive is encrypted in any way, shape or form?

So far we have one incident after the other of data loss from the offices of the British government and/or its contractors or subcontractors and they still expect the people to trust them with personal data.

They tell us that the data for the new passports and the ID cards that they want to introduce on a voluntary compulsory basis (yes, that is a contradiction in terms) is going to be completely safe and cannot be misused (ever) by anyone.

Right, sure, and on an airfield nearby a squadron of pigs is preparing for takeoff.

The same contractor that recently has lost data on the stick and in other ways is the same one that has the contract for the national ID card scheme. That really inspires confidence – NOT. In addition to that hackers have already announced that they are capable of getting into the chip on the passports and ID cards and that they can alter data or extract data from them.

Not that they seem to need to do that. All they need to do is watch the employees of the contractors losing USB sticks and such.

The way this country, in government and banking, is dealing with data is making the UK a laughing stock amongst the countries of the world as far as data security is concerned. Small companies have, more often than not, better security measures in place as regards to their data sticks and such than, it would appear, the British government and all its branches. Worrying indeed, this is.

© M Smith (Veshengro), September 2008
<>

British Justice Ministry loses 45,000 sets of data

by Michael Smith (Veshengro)

If losing data would be an Olympic discipline Britain sure would be topping the league table for gold medals. Shame that this is not something to write home about really. But it nigh on has become a sports discipline of the authorities in Britain to lose sensitive data of its citizens. And then the people should trust them with the data for a national bio-metric ID card. Methinks not.

Once again has a department of the British government – in this case the Justice Ministry – lost sensitive data, thousands of them, without the faintest idea as to where those currently reside.

If ordinary businesses would treat data in such a lackadaisical manner they would find themselves prosecuted – and rightly so – by this very same government. When it itself, however, treats data, which is even more sensitive than “mere” credit card details, in such a manner nothing seems to be happening at all.

Slowly but surely the reliability of all government departments in the UK are being called in question seeing how one scandal chases the other and more often than not such a scandal has to do with the loss of sensitive data of the people.

The Justice Ministry has now become part of the long line of UK government departments that are incapable of securely store, retain and protect the sensitive data of the people of the British Isles which they have been entrusted with. Around 45,000 sets of data have been lost by the said ministry, and those include the date of birth, the national insurance number, the extracts from the criminal records, as well as, in many cases, also bank details. Wost of all in this is that 30,000 of those people thus affected have not even been informed by the authorities as to the fact that their details have been lost in such as way because the department reckoned that the loss of such data – despite the fact that it is, so we understand, unencrypted, as per usual with the British government – did not pose any risks for those whose details have been lost. Oh really? This government is getting more and more incompetent and it really expects people to trust it with information. They really do not live on this planet, I am sure.

This all points, yet again, to the apparent fact that the British authorities seem to have absolutely no interest in proper protection of the personal data of its citizens.

Not so long ago 1,000s of new blank passports – the kind with the chip – have been stolen and the people were told as well that there is no problem there and that those passports could never be used. Well, tell that the hackers that have managed to get into the chips and are thus able insert any data that they desire.

The British government, including its intelligence service and defence ministry, must be holding the world record in data loss, at least in the loss of unsecured data.

Apparently, with reference to the first – reported one – of these incidents when millions of sets of data of child benefit recipients went missing, the reason that those two CDs with all the data were not encrypted is because the two departments have different encryption programs and neither can read the other system. HELP!!!

Oh well, maybe one day we find all those sets of data again, somewhere. Let us then just hope that no one in the meantime makes use of the material on those disks and laptops for criminal or terrorist goals. I think praying might be in order here to which ever deity the reader may chose.

© M Smith (Veshengro), August 2008
<>

Strategic Security Seminar – Tower of London

Good food, good company and great seminar

by Michael Smith (Veshengro)

The Strategic Security Seminar was held Wednesday July 2, 2008, at the Tower of London and was organized by CM Logic in conjunction with IBM Partners and the venue chosen with reference to securing your assets.

What the presentations showed and what we recently have come to realize with regards to lost data on CDs and such is that too many companies, government departments, organizations, and many others, take far too a lackadaisical attitude to database and general computer information security and security of (critical) data.

We do not even want to talk about in this instance about the ordinary home and or even small business users of computers, including those that have sensitive data on their PCs and small networks.

Other important and sensitive computers that are so often also unsecured, as we have noticed recently with the loss of a number of laptops of members of the military and security forces.

During the seminar it was mentioned that a survey had found that:

10% of all websites that accept payment details do not encrypt them.

35% of all companies and institutions have no control over staff use of instant messaging.

67% of all companies and institutions do nothing to prevent confidential data leaving on USB sticks and similar devices.

78% of all companies and institutions that had computers stolen did admit that those computers did not have encrypted hard drives.

84% of all companies and institutions do not scan outgoing emails for confidential data.

I am sure now everyone is really feeling secure and that their data held by others is safe – hardly.

The Strategic Security Seminar was held in the “New Armouries” of the Tower of London and the venue and the food was brilliant.

The presentations of the speakers of the various companies were most informative and it might have been good if more CIOs and CEOs from more companies would have attended this seminar and would attend other such seminars.

There does, however, seems to be the attitude about that while it may happen to others it could never happen to them. False security and a false sense of security is no security at all.

I know we not only find this attitude as regards to computer and data security. In many cases people and organizations who should know better also treat perimeter and site security, as well as personal security, with this “it won't ever happen to us because we have this or that in place.” Right! And? Has it actually be tested as to whether it works. I mean tested as in “properly tested”, as in “penetration tested” and this applies equally to computers, computers systems and networks, as it does to perimeter and site security.

Military sentries can get into deep and hot water for waving an officer through even without checking his or her credentials. “But I know you, Sir!”, I was once told by a young PFC on guard who I challenged when I entered the base in civilian dress as to why he had not asked to see my ID, “I have seen you many times in uniform.” Wrong answer that was and the sentry was lucky that I was in a good mood.

This attitude, however, prevails everywhere, and also and especially in regards to access to sensitive data with people having far too many privileges than necessary to do their job. This even includes temporary staff in many cases. Why should a temp have the permission to access data, of whatever kind, and transfer same to, say, a USB stick or similar.

How do you know where your data goes from there?

© M Smith (Veshengro), July 2008