Here we go again, someone at Barnet Council decided to store unencrypted data about school children on CDs and USB sticks which were then stolen in a burglary and are out at large. Just another example of the incompetence that exists at every level in our public services related to the protection of data.
Firstly, the council say that the person in question has been suspended but why aren't they jailed? Why do we still not take data protection seriously. More importantly, the council says they have now blocked external drives to prevent this - why wasn't this already the case? Why, when there could be a simple 2-sided document on data protection sent to all public services in the country, was this a reactionary measure rather than a proactive one? Why do companies still assume that people can be trusted to do do something properly? People are not perfect, they do not always understand what they are doing, they sometimes act maliciously or to make their life easier so quite simply you must prevent people as far as possible being able to circumvent protection tools.
Interestingly, the data in its normal form was encrypted so the council presumably partly understood what they were doing but didn't go far enough.
"An independent review is underway". What's the point? We have enough of these already, let me give you some free very obvious advice and pass this onto the IT Services division of the Cabinet Office:
"Put together a small team of experts in IT security and decide what all public services must adhere to in terms of data security. Imagine all scenarios, lay them out, send the document to all public departments and make them follow it at pain of prosecution" Why is that so hard?
Showing posts with label security. Show all posts
Showing posts with label security. Show all posts
Wednesday, 31 March 2010
Monday, 9 November 2009
Government says no to encryption
I feel the need to rant again because of the stupidity endemic in our current government. I don't think it is a political disagreement just another example of incompetence. This article here relates how information obtained from RIPA (the Regulation of Investigatory Powers) does not require encryption as it is handled and passed around. According to our government, who of course excel in every area of IT, it would be "impractical" to require this burden and the existing systems of "physical security", "security procedures", "staff vetting" and "training" are considered suitable for the job. This again clearly demonstrates that the government have no idea what they are talking about. Most security leaks appear to be related to a common theme: humans make mistakes. They leave stuff lying around, they get their properties burglarled, things get dropped, mislaid and criminals who want this information often obtain it without any input from employees of these systems. In which cases none of the so-called adequate measures does anything. The only way to prevent accidental disclosure of information is to make it exceedingly hard to do (i.e. encryption or inability to move the data outside of a closed network). People disboey procedures to save themselves time, they often ignore the fit-for-purpose hardware and transport stuff around in the Demilitarised Zone and as for staff training and vetting, it doesn't really add security, it is small and cheap operation that actually adds very little benefit.
They also miss an important point that actually encryption is extremely simple even using free tools. Even if what they used was not US Military Spec, it would be better than nothing!
Maybe one day the government will emply someone who actually knows about the departments they are managing. I won't hold my breath!
They also miss an important point that actually encryption is extremely simple even using free tools. Even if what they used was not US Military Spec, it would be better than nothing!
Maybe one day the government will emply someone who actually knows about the departments they are managing. I won't hold my breath!
Wednesday, 2 September 2009
More data loss, again, another time, etc.
http://www.theregister.co.uk/2009/09/02/uk_eu_data_menace/
Nice, a story about another loss of important computer data, in this instance the supplier of a government gateway data system had a load of access codes on a USB stick and dropped it in a car park. Of course, the person will probably be sacked but again, I protest, that so-called system experts are missing the basics of data security. I have gone through them before but:
People make mistakes so design the system so they can't
Rather than the old excuse, "well never mind, mistakes happen" which gets touted a lot by the government (because they make lots of mistakes) we should build things in a way that prevents those mistakes or at least makes them unfeasibly hard. You wouldn't take all the windows out of a school building and then when a child falls out and dies say, "well never mind, mistakes happen". You put railings in because you know that mistakes happen, you might even put the windows back in!
Software and computer systems are no different. If you do not want people to take copies of personal data (and you generally don't) you only physically allow authorised machines to connect in and they have their USB ports and disk drives locked-out. You run in a terminal window so you cannot copy things to your local hard drive or you simply do not allow things like copy and paste. Not rocket science honestly. What happens then is that someone has to take a photo of the screen (unless you set the contrast low!) at which point you know they have done something totally unacceptable which is not the case with a USB drive ("I just needed to take this home to work on the login screen").
The principle of least privilege should be at work but I am still convinced that most IT companies don't have a clue about it.
Nice, a story about another loss of important computer data, in this instance the supplier of a government gateway data system had a load of access codes on a USB stick and dropped it in a car park. Of course, the person will probably be sacked but again, I protest, that so-called system experts are missing the basics of data security. I have gone through them before but:
People make mistakes so design the system so they can't
Rather than the old excuse, "well never mind, mistakes happen" which gets touted a lot by the government (because they make lots of mistakes) we should build things in a way that prevents those mistakes or at least makes them unfeasibly hard. You wouldn't take all the windows out of a school building and then when a child falls out and dies say, "well never mind, mistakes happen". You put railings in because you know that mistakes happen, you might even put the windows back in!
Software and computer systems are no different. If you do not want people to take copies of personal data (and you generally don't) you only physically allow authorised machines to connect in and they have their USB ports and disk drives locked-out. You run in a terminal window so you cannot copy things to your local hard drive or you simply do not allow things like copy and paste. Not rocket science honestly. What happens then is that someone has to take a photo of the screen (unless you set the contrast low!) at which point you know they have done something totally unacceptable which is not the case with a USB drive ("I just needed to take this home to work on the login screen").
The principle of least privilege should be at work but I am still convinced that most IT companies don't have a clue about it.
Wednesday, 25 March 2009
"people with nothing to hide wouldn't be so opposed to them"
I read the title in an article about Polygraph machines or 'lie detectors' and it reminded me of similar things I had read about ID cards, routine DNA testing and just about everything else that a government churns out for 'our security'. The problem is that the phrase is so common, most people won't notice that the logic is very much flawed.
The logic to the statement is based on the assumption that the piece of equipment or system is 100% foolproof. If indeed a lie detector was 100% accurate then surely only a liar would be concerned with taking one (ignoring people who might *have* to tell lies like security services or government officials protecting the public). Of course the problem is that none of these things are foolproof.
Take a lie-detector for example. Suppose you were interviewed in a murder investigation and failed a lie-detector test. The information was then presented in a Court alongside other circumstantial or inconclusive evidence. You might very well be found guilty. Take ID cards, there could be any one of a number of technical errors that might make your card read as a fake or that would enable someone to copy it and make it look you were somewhere else to where you actually were etc. Imagine the DNA information from your routine test is mis-entered or polluted into the system and 'your' DNA is then found at a crime scene. Can you imagine getting out of that by accusing the system of a defect somewhere?
Quite honestly the original statement is nonsense and I for one will ensure I do not agree to any of these man-made systems that somehow promise our security at the expense of liberty, annonymity, money and security.
The logic to the statement is based on the assumption that the piece of equipment or system is 100% foolproof. If indeed a lie detector was 100% accurate then surely only a liar would be concerned with taking one (ignoring people who might *have* to tell lies like security services or government officials protecting the public). Of course the problem is that none of these things are foolproof.
Take a lie-detector for example. Suppose you were interviewed in a murder investigation and failed a lie-detector test. The information was then presented in a Court alongside other circumstantial or inconclusive evidence. You might very well be found guilty. Take ID cards, there could be any one of a number of technical errors that might make your card read as a fake or that would enable someone to copy it and make it look you were somewhere else to where you actually were etc. Imagine the DNA information from your routine test is mis-entered or polluted into the system and 'your' DNA is then found at a crime scene. Can you imagine getting out of that by accusing the system of a defect somewhere?
Quite honestly the original statement is nonsense and I for one will ensure I do not agree to any of these man-made systems that somehow promise our security at the expense of liberty, annonymity, money and security.
Tuesday, 26 August 2008
Securing Data
I was just reading AGAIN about the loss of personal data by a government contractor who copied the data to a USB stick and then lost it. What I don't understand is the amount of lethargy the government and others have had when it comes to understanding 2 things: 1) Security sensitive data is NOT the same as data in normal unimportant documents like many email etc and should not be treated thus and 2) It will NEVER be enough to rely on people following procedures to ensure safety or security in ANY scenario, let alone one that involves people's actual identity.
Security sensitive data (SSD) is treated like most data. It is stored in a database, many of which can't distinguish between someones bank details and their favourite colour. It is then possible to back it up to file, move it between computers, send it to external drives and in some cases read it physically from the disk with no encryption to break. What is needed is simply a linking up of various software vendors to agree on a new type of data in software systems and databases. This data will always be encrypted and can be forceably restricted to, for instance, only be allowed to live on a nominated server(s) and not be allowed to be copied onto an external drive. This would be defined by the person who creates the data so that even if it is sent to an external contractor, the safeguards would not be able to be removed (although presumably if the contractor wanted to copy the data off the screen somehow into another document that would be possible). Sure it would be quite a bit of work but with the amount of investment in these large systems and the potential cost of information loss, you would think that the powers that be would have finished this by now. This also mitigates the second point which is for one reason or another, people don't always follow a process, either at all, or 100% correctly. Somebody is covering for someone else's job, a new starter doesn't understand the ropes, communication is misunderstood, costs are cut etc, etc. By securing the data itself in a way that is coherent across platforms, peope don't have to remember not to write it to CD because the data will not let them do it. With basic tools like mandatory encryption and password protection, even if the data is mislaid, the chances of it being useful are very slim.
Come on everyone - sort it out!!
Security sensitive data (SSD) is treated like most data. It is stored in a database, many of which can't distinguish between someones bank details and their favourite colour. It is then possible to back it up to file, move it between computers, send it to external drives and in some cases read it physically from the disk with no encryption to break. What is needed is simply a linking up of various software vendors to agree on a new type of data in software systems and databases. This data will always be encrypted and can be forceably restricted to, for instance, only be allowed to live on a nominated server(s) and not be allowed to be copied onto an external drive. This would be defined by the person who creates the data so that even if it is sent to an external contractor, the safeguards would not be able to be removed (although presumably if the contractor wanted to copy the data off the screen somehow into another document that would be possible). Sure it would be quite a bit of work but with the amount of investment in these large systems and the potential cost of information loss, you would think that the powers that be would have finished this by now. This also mitigates the second point which is for one reason or another, people don't always follow a process, either at all, or 100% correctly. Somebody is covering for someone else's job, a new starter doesn't understand the ropes, communication is misunderstood, costs are cut etc, etc. By securing the data itself in a way that is coherent across platforms, peope don't have to remember not to write it to CD because the data will not let them do it. With basic tools like mandatory encryption and password protection, even if the data is mislaid, the chances of it being useful are very slim.
Come on everyone - sort it out!!
Subscribe to:
Posts (Atom)