home office logo
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

'Home Office' disc wedged in laptop sold on eBay

Another potential data breach scandal for the government

Rosalie Marshall, IT Week 28 Feb 2008
ADVERTISEMENT

A laptop containing what could be sensitive Home Office data has been sold on eBay.

The laptop was bought by an unsuspecting consumer who subsequently took the equipment to be fixed by Leapfrog computer repairs in Greater Manchester. It was only as the laptop casing was opened that a disc was discovered wedged beneath the keyboard.

“It is a real mystery as to why the disc was jammed there, although it was obviously put there deliberately," said Lee Bevan, Leapfrog's managing director.

“The only way a disc can get inside the system would be through the CD Rom but this is a sealed unit,” Bevan added.

The disc had the words "Home Office" and "Confidential" written on it. But Leapfrog was not able to verify the authenticity as the contents were encrypted. If the disc is proven to be from the Home Office, it would be another major public sector IT security embarrassment.

IT experts said that encryption on the disc shows the public sector is learning from previous mistakes, but warned that the Home Office remains vulnerable to data leaks.

“Unfortunately accidents like this are not going to stop happening so we can only hope that other government departments follow the Home Office's lead and adopt full disc encryption,” said Brian Spector, general manager for content protection firm Workshare, adding “With the statistics showing that nearly 500 government devices have gone missing since 2001, it was only a matter of time before a confidential disc inadvertently ended up on eBay.”

Alan Bentley, Lumension Security European vice president, pointed out encryption alone is not infallible. “Computer hackers are determined individuals with the potential to crack one layer of security,” Bentley said. “And, we certainly shouldn’t be relying on one line of protection when it comes to our national security.”

Bentley said safeguarding sensitive data needs to begin at the network level. “By monitoring and only allowing known good devices and authorised individuals to connect to a network and download data is essential.”

He added the key is to reducing data breach risk is to have data access control and encryption working hand-in-hand, as well as giving individuals who have rights to download data from the network stringent security checks.

The encrypted IT equipment is now in the hands of the Greater Manchester Police, who are investigating the incident.

See also:

padlock and chainSecurity breaches have far reaching implications for businesses finds report  27 Feb 2008
houses of parliamentScience and Technology Committee disappointed with government response to its 2007 report  21 Feb 2008
The sheer number of laptops lost, or misplaced, by the government highlights the need for tech solutions  20 Feb 2008
an NHS workerIs there yet another data loss disaster for the government to face?  06 Feb 2008
someone using a laptopA laptop belonging to Marks and Spencer was stolen in May 2007 it has been revealed  29 Jan 2008
a laptop, easy to lose apparentlyLaptop losses at the Ministry of Defence will only add to government woes  22 Jan 2008

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
NEWCASTLE UPON TYNE, Tyne And Wear, United Kingdom | EDS
Position # 396338 Job Description We require a Network Architect who is responsible for the day to day technical oversight of the GNE organization within their assigned account. The GNE Network Architect is responsible for ... more >
Reading, Berkshire, United Kingdom | EDS
Technical Hosting Engineer Location - Reading Job Description: This is an applications infrastructure and engineering role within the team. This role is primarily focussed on developing and evolving a quarantine application hosting service. The quarantine ... more >
London, United Kingdom | Deloitte
Technology and Systems Consulting Event - LondonWith the right balance, you'll achieve great things. Join our Consulting practice and have the opportunity to balance your technical and business consulting skills to bring out the best ... more >
Aylesbury, Buckinghamshire, United Kingdom | Grass Roots
SQL Database Administrator - Aylesbury - £DOE Grass Roots are one of the Sunday Times Top 100 companies to work for (2007 and 2008). Established in 1980, we're part of the Grass Roots Group, which is ... more >
More job opportunities