The Core

Why We Are Here => Water Cooler => Topic started by: Rooftop on August 19, 2015, 10:02:24 PM

Title: UK to create the world's biggest target for hackers
Post by: Rooftop on August 19, 2015, 10:02:24 PM
If anyone knows of a more moronic government initiative please do share:

http://www.telegraph.co.uk/news/shopping-and-consumer-news/11804682/How-your-entire-financial-life-will-stored-in-a-new-digital-vault.html
Title: Re: UK to create the world's biggest target for hackers
Post by: JasonD on August 19, 2015, 10:37:35 PM
134 gov.uk email addresses in the Ashley Madison hack.

Does any more need to be said about the lack of common sense in British government or their understanding of online risk?
Title: Re: UK to create the world's biggest target for hackers
Post by: Rooftop on August 20, 2015, 06:16:58 AM
I don't mind them being morons with their own details!

Wasn't their just another report showing that local govt employees already massively abuse the data they have access to?
Title: Re: UK to create the world's biggest target for hackers
Post by: Rupert on August 20, 2015, 07:08:53 AM
Quotealready massively abuse the data they have access to

It has to be tempting...

But frankly I dont trust any big organisation to do the "right" thing.

I wish we had an answer. Trouble is if you stay offline, the way I see it,  it will be difficult to get credit, bank accounts, jobs, welfare.. probably even food and water eventually.
Title: Re: UK to create the world's biggest target for hackers
Post by: Gurtie on August 20, 2015, 07:43:53 AM
I just want the choice. I chose to do many things I know are stupid, thats fine, if it backfires I only have myself to blame.

I personally would rather face the hassle of making a photocopy than having all my financial details in one data store. So let me opt out and I don't care if they build it, If I later find the inconvenience too bad then I'll opt in (and yes, something somewhere will become impossible to do without it I know)

Title: Re: UK to create the world's biggest target for hackers
Post by: Rooftop on August 20, 2015, 08:20:35 AM
The official reasons for this initiative just don't make sense either.   "You could just use an app to prove your earnings when you buy something".  Wow, I could avoid a minor inconvenience once every few years and I only have to make every detail in my life available to anyone in order to get that improvement.  No thanks.

UK Govt can't possibly get this right based on their track record either.  It'll cost 3-5 times that they think, will take forever and become a political embarrassment. 
Title: Re: UK to create the world's biggest target for hackers
Post by: JasonD on August 20, 2015, 09:36:09 AM
If I play devil's advocate for a moment....

All of this kind of data already exists over disparate and separate data stores already. If you have a Dr., car insurance, bank accounts etc etc, it's already out there.

So in reality, if this new mega data store is well done, security is done properly (fully encrypted etc) needs 2FA to access it and is limited in how the data can be accessed, then we may be in a better position security wise than we are at present.
Title: Re: UK to create the world's biggest target for hackers
Post by: Gurtie on August 20, 2015, 12:11:24 PM
absolutely, but if security is not done well all of my data will be hacked at the same time.

plus the sum of the data is incredibly valuable. between all of those datasets you give away much more data than you would in any individual one. 

Title: Re: UK to create the world's biggest target for hackers
Post by: JasonD on August 20, 2015, 03:48:33 PM
And to counter that point, if this is done properly it will be more secure than all the other data stores already out there, meaning that you could be much more secure this way, then we are at present and actually deliver only the data that each separate provider would need, rather than the total they collect at present.

N.B. The above may or may not necessarily be my views. I'm posting to play the devil's advocate and invoke discussion.
Title: Re: UK to create the world's biggest target for hackers
Post by: Rooftop on August 20, 2015, 05:04:06 PM
Quote from: JasonD on August 20, 2015, 03:48:33 PM
And to counter that point, if this is done properly it will be more secure than all the other data stores already out there, meaning that you could be much more secure this way, then we are at present and actually deliver only the data that each separate provider would need, rather than the total they collect at present.

N.B. The above may or may not necessarily be my views. I'm posting to play the devil's advocate and invoke discussion.

The main issue with this argument is that "properly" means that it needs to both be unbreakable and managed flawlessly.  I don't know whether either of those things are possible.  If they are then I don't believe that the UK government is the most likely organisation to achieve either. 
Title: Re: UK to create the world's biggest target for hackers
Post by: Gurtie on August 20, 2015, 07:57:00 PM
if you want to pit a security expert against a hacker (cracker?) you're gambling big time with this that the expert you employ is better than every other expert out there.

They aren't good odds. And even the best has to have the occasional bad day. And will leave at some stage.

I appreciate that a lot of the people who may turn out to be better are also honest. But again, for a big enough reward many very honest people do dishonest things.
Title: Re: UK to create the world's biggest target for hackers
Post by: JasonD on August 20, 2015, 09:25:03 PM
I agree on all points...

But the same arguments apply to where the data is stored now in all the differing locations.
Title: Re: UK to create the world's biggest target for hackers
Post by: Rupert on August 21, 2015, 09:29:07 AM
Is it location that is relevant here?  Or the security methods used.

Or am I just being pedantic?

Title: Re: UK to create the world's biggest target for hackers
Post by: JasonD on August 21, 2015, 09:41:12 AM
I think both.

And when I say location, I don't mean location of server but more that they are different and as such all likely to have differing security measures in place. I am sure some will be robust, but others as weak as say Carphone Warehouse or other recent hacked companies.

For me, the physical location only comes into play when the data is within the EU. It grants massive advantages to us to keep the data within the EU as the penalties and laws are much more stringent that in the US. However, the security of the data is more important than any laws surrounding it and I personally feel that extremely secure data storage, where I control who does and doesn't get access to it, is a better position than it being slung across the world in disparate and separate containers and holders of that data, ready to be used / abused, by anyone who can find a simple SQLi due to poor coding practices.