ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Home Office admits to database breaches

Tom Espiner ZDNet.co.uk

Published: 31 Aug 2006 09:40 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The Home Office has admitted that the security of its ID and passport service database has been compromised several times, but denied that remote hackers were responsible.

In a response to a parliamentary question at the end of last week, the Home Office said it had had five security breaches in five years, mostly caused by civil service staff.

"The security breaches didn’t involve people hacking into the systems," a Home Office spokesperson told ZDNet UK on Thursday.

Four of the five incidents involved members of staff accessing the ID and Passport databases for unauthorised purposes. Three used their systems access privileges to conduct checks that were "not connected to their duties", according to an ID and Passport service spokesman, while in the other breach the staff member "misused data he was entitled to access".

In each of the cases "disciplinary action resulting in dismissal was undertaken", with one staff member "resigning before the proceedings came to an end" said the spokesman.

The fifth security breach occurred in a prison service legacy system, where a "technical failure" caused the system to crash. The system has since been replaced, according to the Home Office.

The ID and Passport Service (IPS) denied that this did not bode well for the ID card project, which will involve a massive database of personal and biometric data. Experts have raised questions about how secure a National Identity database linked to the Government's ID card scheme could be.

"The IPS takes the protection of systems and data very seriously. A range of protection and procedures are in place to prevent the misuse or abuse of official systems, and to detect it where it does occur. IPS is committed to investigating any such misuse or abuse, and will deal with it in the strongest manner," said the spokesman.

However, the IPS admitted that the security breaches had still occurred, even with the protection systems in place.

"At the end of the day it's an issue of trust," said the spokesman. "People are security vetted, but trust can be breached. Anyone identified as breaching the system will be treated severely."

Many security experts have cast doubts over how secure an ID card system and database could be, while senior civil servants appeared in July to be concerned about the viability of the scheme.

The Liberal Democrats warned in May that organised criminals will try and crack the identity cards database. Last year it was revealed that the identities of 13,000 civil servants had been stolen and used by criminals to make fake tax credit claims.

Liberal Democrat home affairs spokesman, Nick Clegg, said then that the theft was a "terrible omen" for the forthcoming ID cards scheme.

Clegg said that if organised criminals are capable of infiltrating the Department for Work and Pensions (DWP), "it is clear they will target the identity cards database, where the stakes are even higher".

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
173 out of 270 people found this useful



Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Civil Engineer - Structural

Fantastic 6 month initial contract opportunity for an Independent Civil Engineer to assist with a Power Plant construction project. You must be a ...

Business Development Manager - Market leaders in Civil Engineering

Business Development Manager - Market leaders in Civil Engineering South East - Offices in Weybridge, Surrey The Position: This is an excellent ...

Network Support (VMWare & SQL) - CIVIL SERVICE CO. (37,000k)

I have a fantastic opportunity to join a global Civil Service Department based in SW London. VMWare & Sharepoint experience required! My client are ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation