UK to create the world's biggest target for hackers

Started by Rooftop, August 19, 2015, 10:02:24 PM

Previous topic - Next topic

JasonD

134 gov.uk email addresses in the Ashley Madison hack.

Does any more need to be said about the lack of common sense in British government or their understanding of online risk?

Rooftop

I don't mind them being morons with their own details!

Wasn't their just another report showing that local govt employees already massively abuse the data they have access to?

Rupert

Quotealready massively abuse the data they have access to

It has to be tempting...

But frankly I dont trust any big organisation to do the "right" thing.

I wish we had an answer. Trouble is if you stay offline, the way I see it,  it will be difficult to get credit, bank accounts, jobs, welfare.. probably even food and water eventually.
... Make sure you live before you die.

Gurtie

I just want the choice. I chose to do many things I know are stupid, thats fine, if it backfires I only have myself to blame.

I personally would rather face the hassle of making a photocopy than having all my financial details in one data store. So let me opt out and I don't care if they build it, If I later find the inconvenience too bad then I'll opt in (and yes, something somewhere will become impossible to do without it I know)


Rooftop

The official reasons for this initiative just don't make sense either.   "You could just use an app to prove your earnings when you buy something".  Wow, I could avoid a minor inconvenience once every few years and I only have to make every detail in my life available to anyone in order to get that improvement.  No thanks.

UK Govt can't possibly get this right based on their track record either.  It'll cost 3-5 times that they think, will take forever and become a political embarrassment. 

JasonD

If I play devil's advocate for a moment....

All of this kind of data already exists over disparate and separate data stores already. If you have a Dr., car insurance, bank accounts etc etc, it's already out there.

So in reality, if this new mega data store is well done, security is done properly (fully encrypted etc) needs 2FA to access it and is limited in how the data can be accessed, then we may be in a better position security wise than we are at present.

Gurtie

absolutely, but if security is not done well all of my data will be hacked at the same time.

plus the sum of the data is incredibly valuable. between all of those datasets you give away much more data than you would in any individual one. 


JasonD

And to counter that point, if this is done properly it will be more secure than all the other data stores already out there, meaning that you could be much more secure this way, then we are at present and actually deliver only the data that each separate provider would need, rather than the total they collect at present.

N.B. The above may or may not necessarily be my views. I'm posting to play the devil's advocate and invoke discussion.

Rooftop

Quote from: JasonD on August 20, 2015, 03:48:33 PM
And to counter that point, if this is done properly it will be more secure than all the other data stores already out there, meaning that you could be much more secure this way, then we are at present and actually deliver only the data that each separate provider would need, rather than the total they collect at present.

N.B. The above may or may not necessarily be my views. I'm posting to play the devil's advocate and invoke discussion.

The main issue with this argument is that "properly" means that it needs to both be unbreakable and managed flawlessly.  I don't know whether either of those things are possible.  If they are then I don't believe that the UK government is the most likely organisation to achieve either. 

Gurtie

if you want to pit a security expert against a hacker (cracker?) you're gambling big time with this that the expert you employ is better than every other expert out there.

They aren't good odds. And even the best has to have the occasional bad day. And will leave at some stage.

I appreciate that a lot of the people who may turn out to be better are also honest. But again, for a big enough reward many very honest people do dishonest things.

JasonD

I agree on all points...

But the same arguments apply to where the data is stored now in all the differing locations.

Rupert

Is it location that is relevant here?  Or the security methods used.

Or am I just being pedantic?

... Make sure you live before you die.

JasonD

I think both.

And when I say location, I don't mean location of server but more that they are different and as such all likely to have differing security measures in place. I am sure some will be robust, but others as weak as say Carphone Warehouse or other recent hacked companies.

For me, the physical location only comes into play when the data is within the EU. It grants massive advantages to us to keep the data within the EU as the penalties and laws are much more stringent that in the US. However, the security of the data is more important than any laws surrounding it and I personally feel that extremely secure data storage, where I control who does and doesn't get access to it, is a better position than it being slung across the world in disparate and separate containers and holders of that data, ready to be used / abused, by anyone who can find a simple SQLi due to poor coding practices.