ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Security experts criticise government database plans

Tom Espiner ZDNet.co.uk

Published: 19 Jan 2007 12:28 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security experts are hugely nervous about the government's latest database plans, and have pointed out numerous grave security concerns over two of its proposed schemes.

What worries me is the increased risk. If you're joining databases, you're creating a tremendously more valuable resource for ID thieves

Paul Davie, Secerno

The Home Office announced in December that the National Identity Register — the planned database behind the controversial ID cards scheme — would comprise three existing databases. The Department of Work and Pensions (DWP), the Identity and Passport Service (IPS) and the Immigration and Nationality Directorate (IND) databases would be combined to store people's biometric and biographic information. This plan, which negates the need to build a single new database, has sparked alarm in the security space.

The second government initiative worrying security experts is this week's proposals to relax data-sharing laws that govern how civil servants access and share citizens' personal data. At present, the privacy rights of the UK public are protected by the Data Protection Act. But, according to a Number 10 policy review published on Monday, "overzealous data-sharing rules may be an obstacle to improving public services". Relaxing these rules could help create a super-database, where public workers had greater access to the personal details of the public.

Security vendors see problems common to both initiatives. Principal among them are the increased opportunities for data theft, if more civil servants are accessing more data.

Greg Day, security analyst at McAfee, said that online data theft is increasing, through the use of software to log people's keystrokes and through attempts to dupe users into revealing personal details, a practice known as phishing.

"It's a simple reality that ID theft is on the up, and is growing online," Day told ZDNet UK. "There's been a 250 percent increase in keyloggers in the last two years, and a hundredfold increase in the number of anti-phishing alerts by the Anti-Phishing Working Group."

Day said that government-held personal details could be divulged easily. According to Zone-h, a website that reports on hacks and hacking, an investigation has been demanded recently into a "digital accident" at the Israeli Interior Ministry where Israeli Vital Population Registry information was leaked and posted on the internet.

"The database is compiled by officials at the Interior Ministry and it includes information about all Israeli citizens and personal details that could potentially be used without authorisation by internet marketers, and of course cybercriminals," Zone-h reported.

Day also had technical concerns with the government plans, including proposals to allow the databases to be accessed over the internet. This could lead to chaos, he warned.

"With the existing databases, they are trying to make them internet-available. It would make me hugely nervous to have that personal information on the internet," said Day. "With multiple databases mixing data they face lock fields, with multiple people trying to modify records simultaneously."

Shlomo Kramer, founder and chief executive officer of Imperva, a data-centre security specialist whose clients include governmental organisations, was also nervous about the plans for internet facing databases.

"Last year more than 100 million user records were compromised in the US alone," Kramer told ZDNet UK. "The issue is that when data is available online it can be compromised — especially [in conjunction with] web services."

Even if the information is only available within governmental organisations, Imperva is seeing that within its user base there are many internal security issues —  including abuse of credit card data, or abuse of privileges.

"Data is at risk if it is made available to a large community of users," said Kramer.

Security issues are compounded when multiple organisations are interacting in...

Next

Previous

1 2


  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
10 out of 10 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Director of Quality Assurance and Compliance, Pharmaco, Berkshire

For more information, please contact: Tom Froggatt at Real Pharma on 0207 758 7311 KEYWORDS: Quality Assurance, QA, quality, assurance, GMP, good ...

Network Operations Manager

Staff at Suffolk New College enjoy many of the following benefits: generous holidays; flexible working arrangements; final salary pension schemes; ...

Implementation Engineer - Unix / Servers - London

Resolve queries from engineering staff within the organisation to enable them to complete tasks -For operational reasons, record and maintain all ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment