Showing posts with label data protection act. Show all posts
Showing posts with label data protection act. Show all posts

Tuesday, 22 December 2015

Information control: individual trust in the state

2015 may been seen as the year when the state started to try to regain control over the internet.

In the UK we have the Investigatory Powers Bill, in Europe the new Data Protection Act and in the US the Cyber Security Act.

Going the other way the United Nations chipped in with a Draft Resolution supporting freedom of the internet from state control and stressing the need for freedom of expression, privacy and right to peaceful assembly.

Arguably everything was going along quite nicely with massive levels of state surveillance going on undetected until Edward Snowden decided enough was enough in what are supposed to be liberal democracies. Hero or villain he certainly made an impact.

Quite clearly the internet should not be a free for all and the state should be able to check for illegal activity in a reasonable way to protect national security and be able to stop blatantly illegal activity quickly. Incidents in Paris and elsewhere in the world make an unanswerable case.

However, at the other end of the scale, petty and vindictive activities of the type described re Constable Savage below (Happy Xmas) are facilitated by mass surveillance and should be clearly ruled out.   The odd bad apple who misuses state surveillance powers for their own ends needs to be dealt with as harshly as the journalists put through hell on phone hacking charges.


The elephant in the room is a question of trust by the individual in the state and the importance therefore that the state does not abuse the surveillance powers it is granting to itself.

Thursday, 5 November 2015

Have TalkTalk breached the Data Protection Act ? Certainly a possibility..........

With admirable gusto TalkTalk have answered the above question on their own website by saying "No, this is a criminal attack. We have notified the ICO and we will work closely with them over the coming weeks and months".

There we are - no need for any type of judicial system we can all simply decide for ourselves if we have complied with legislation.

In the real world (and given the sanctions from the ICO that TalkTalk has received previously) it is not likely to be as simple as that.

Principle 7 of the Data Protection Act states that "Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data."

If reports are true that the attack on TalkTalk was based on SQL injection then, given that Input Validation methods will prevent this, a company the size of TalkTalk would not appear to have taken appropriate measures.

No doubt a commercial decision was taken somewhere within TalkTalk that the cost of defending against an SQL type attack was not justified and that the risk was acceptable.

The problem perhaps is that TalkTalk were trusted to keep customer data safe and had they asked the customer base to decide between staff bonuses or slightly better protection against having all their data stolen the decision would probably have been the latter.

Until we know the nature of the attack and whether appropriate measures had been taken to prevent it it is too early say if a breach has occurred.