There is a really strong moment in Jurassic Park when the character played by Jeff Goldblum delivers the line "they were so pre-occupied with whether they could they didn't stop to think if they should".
Whoever is the current (or maybe former by now) head of IT / Security at Panama law firm Mossak Fonseca must be wishing nostalgically for the days of typewriters and attractive people reaching for the bottom drawer of the metal filing cabinet.
According to reports the data breach which is by some measurements the largest ever at 2.6 TB of data with documents going back to the 1970's was achieved through a breach of the security on the email server leading to the download of its entire contents. Since 1970 was pre-digital the decision must have been taken to digitize hard documents and add them to the servers.
One might expect a massive download of this type to be picked up by network monitoring systems and therefore it seems likely that the external hackers had some internal assistance - but that is speculation. The alternative is that no network monitoring was occurring which might leave you wondering what the IT dept were up to (other than watching dodgy online content and surfing social media).
As none of the documents were encrypted once breach had occurred it was very much "good night Vienna" both for the clients of Mossac Fonseca and the concept of confidentiality between lawyer and client.
As a broader issue medical records and all other digitally stored content that is not encrypted must now be considered semi-public.
While 3TB may seem large (maybe 10 million docs) portable storage for this can be bought off the shelf for about £115. Any unhappy person in any IT department can simply walk out the door with sensitive data.
The ethics around the actions of Edward Snowden and the hackers involved in the Mossak Fonseca case are not clear cut and unless you are an ends justifies the means merchant they will always be in a grey area.
The key thing to now accept is that the old adage from Benjamin Franklin rings true "Three people can keep a secret, if two of them are dead."
Showing posts with label edward snowden. Show all posts
Showing posts with label edward snowden. Show all posts
Wednesday, 6 April 2016
Tuesday, 22 December 2015
Information control: individual trust in the state
2015 may been seen as the year when the state started to try to regain control over the internet.In the UK we have the Investigatory Powers Bill, in Europe the new Data Protection Act and in the US the Cyber Security Act.
Going the other way the United Nations chipped in with a Draft Resolution supporting freedom of the internet from state control and stressing the need for freedom of expression, privacy and right to peaceful assembly.
Arguably everything was going along quite nicely with massive levels of state surveillance going on undetected until Edward Snowden decided enough was enough in what are supposed to be liberal democracies. Hero or villain he certainly made an impact.
Quite clearly the internet should not be a free for all and the state should be able to check for illegal activity in a reasonable way to protect national security and be able to stop blatantly illegal activity quickly. Incidents in Paris and elsewhere in the world make an unanswerable case.
However, at the other end of the scale, petty and vindictive activities of the type described re Constable Savage below (Happy Xmas) are facilitated by mass surveillance and should be clearly ruled out. The odd bad apple who misuses state surveillance powers for their own ends needs to be dealt with as harshly as the journalists put through hell on phone hacking charges.
The elephant in the room is a question of trust by the individual in the state and the importance therefore that the state does not abuse the surveillance powers it is granting to itself.
Thursday, 17 December 2015
The liability aspect of handling personal data - 4% of turnover
It seems that Europe has had enough of companies processing personal data without appropriate consideration and safeguards in place.Earlier this week wording was agreed for new data protection legislation which is expected to come into force in 2 years.
Key wording is that personal data must be "processed in a way that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures".
The agreed wording identifies the types of issues that companies might consider to meet this threshold;
1. Pseudonymisation / encryption of personal data
2. Ability to ensure ongoing confidentiality, integrity, availability and resilience
3. Data restoration post breach
4. Regular testing
The bottom line is that the profitability of data processing will drop as the costs of maintaining a secure digital environment are material and most businesses will face additional compliance costs. As a minimum companies who process personal data will require either in house or as a contractor an individual who can assess digital security risks sensibly and address problems (a data protection officer).
Amusingly the governments have secured broad exceptions to these rules even though they tend to make the greatest howlers in this area - see Edward Snowden.
On that note a clip from Catch 22...............
Subscribe to:
Posts (Atom)
