Home  News   Product reviews  Website reviews  Forums  Competitions  Subscribe 
Magazine
Latest issue
Next issue
Subscribe to
Web User
magazine
Renew your
subscription
Find your nearest UK newsagent
  Highlights 
Gadget blog
Play Games
WIN! WIN! WIN!
Top gadgets
Google Earth Fun
Watch TV online
Web User Videos
Free software
Shopping Directory
Daily Online Fun
Broadband guide
Award Winners
More...
Vote Now

Do you use iTunes?


Shopping directory button
Imaging Home Study Courses
News > McAfee slams HMRC data fiasco

McAfee slams HMRC data fiasco
November 20, 2007
Web User

McAfee Confidential data about 25 million recipients of Child Benefit has been compromised by the loss of two computer discs by HM Revenue and Customs (HMRC).


HMRC Chairman Paul Gray has announced his resignation following the scandal, but one security expert has said that the whole fiasco could have been avoided by adopting better security practices.


"The loss of this data by HM Revenue and Customs is yet another example of the danger of putting sensitive information on an easy-to-lose format such as discs and the result of internal policies not being backed up by good security practice," said Greg Day, security analyst at McAfee.


It emerged this afternoon that the incident happened over a week ago and it is still unclear just how much damage has been done.


"The department will need to explain to consumers why it has taken 10 days to disclose this breach and the extent of the risk to their personal details. At this point we would have to assume the worst until more details are given and the public and the government should be taking steps to limit the damage and risk, if and when the data enters the wrong hands," said Day.


Chancellor Alistair Darling made a statement in the House of Commons this afternoon, telling the House: "This is an extremely serious matter. The HMRC has failed to meet the high standards expected of it."


Darling admitted that the lost discs had still not been found but there was "no evidence" that it had fallen into the wrong hands.


According to the Chancellor, some 25 million individuals' records have been compromised, with data such as names, addresses, dates of birth and bank account numbers exposed.


The breach occured when the discs were posted from HMRC to the National Audit Office.


Another security expert questioned the need for the data to be downloaded onto discs and put in the post.


Chris Mayers, chief security architect at Citrix, said: "Why did this information even need to be transported at all? In these days of secure remote access there is rarely any need for data to be written onto a CD and transported anywhere.


"All organisations handling sensitive data need to realise there is nothing more important than their responsibility to keep that data secure. That means ensuring data is properly encrypted, and travels only when necessary: not on ordinary CDs, print-outs, or even on laptops - all of which appear to go missing with appalling regularity," Mayers continued.


Dominic Hoskins of Panda UK was concerned that the data on the discs wasn't even encrypted.


"Not content with physically sending the discs via an unsecured and untraceable delivery system they also failed to protect the data on the discs by not even encrypting it," Hoskins said.


Analyst Graham Titterington of Ovum cautioned that the security breach had serious implications for any proposed national identity card scheme.


"Politicians will inevitably warn of the risks of concentrating much personal data into a single system, as is planned for the National Identity Card. These fears are fully founded. There was a recent leakage of information from the UK Visa applications system and an earlier leak from the Department of Work and Pensions - two of the key components of the proposed National Identity database," he said.


"So long as it is physically possible for junior officials to download complete databases there can be no confidence in the security of information contained in them," Titterington warned.


www.mcafee.com
www.hmrc.gov.uk
www.citrix.com
www.ovum.com
www.pandasoftware.co.uk


Claim 50p off Web User's Ultimate PC & Web Workshops!



More news via RSS
Post item to Del.icio.us
Post item to Digg.com



Back to index

  Newsletter 


more details

Quick Links
Subscribe to Web User
Free magazine
Buy digital copies
Tech help forum
Watch TV online
Contact us
Web User Videos
Listen to our podcast
Media contacts
Find the best broadband deals
Your BT phone:
Your Post Code:
Latest News
Watch England - Kazakhstan online
Watch Grand Prix snooker online
Scammers target PINsentry users
More disaster advice online
MTV presenter search goes online

RSS Feed
Welcome
Welcome to Web User magazine's online home, where you'll find news, reviews and a buzzing forum. For the best websites, practical advice and the latest music and film downloads every fortnight, get Web User, the UK’s best selling internet magazine.
Claire WoffendenClaire Woffenden, Editor

Web User Shopping Directory


Hitwise Top 10 Award Winner - Jan-Mar 2005

About us | Contact us | Link to us | Terms & Conditions | Privacy Policy

Sister sites: Amateur Photographer | House to Home | Trusted Reviews | What Digital Camera

© Copyright IPC Media Limited, All rights reserved




Daily.co.uk - Great Hosting... it's about time.
Search for your domain name
Domain names £2.79 pa
Email Service £1.08 pm
Web Hosting £1.77 pm
Website Builder £1.99 pm


Check out the latest iPod
MP3 Players from Apple

Find also our GPS range. Popular TomTom GPS
and new Garmin GPS

  Huge range of Flat Screen TV
Make your choice between
 Lcd tvs and Plasma tv
Review our selection of Sony lcd tv and Samsung lcd tv