<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: HMRC loses confidential details of 15 25 million benefit recipients</title>
	<atom:link href="http://www.openrightsgroup.org/2007/11/20/hmrc-loses-confidential-details-of-15-million-benefit-recipients/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.openrightsgroup.org/2007/11/20/hmrc-loses-confidential-details-of-15-million-benefit-recipients/</link>
	<description>Protecting your rights in the digital age</description>
	<pubDate>Fri, 16 May 2008 02:57:28 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: The Open Rights Group : Blog Archive &#187; Copyright commotions 101: Free event at LSE next month</title>
		<link>http://www.openrightsgroup.org/2007/11/20/hmrc-loses-confidential-details-of-15-million-benefit-recipients/#comment-163160</link>
		<dc:creator>The Open Rights Group : Blog Archive &#187; Copyright commotions 101: Free event at LSE next month</dc:creator>
		<pubDate>Fri, 15 Feb 2008 17:34:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.openrightsgroup.org/2007/11/20/hmrc-loses-confidential-details-of-15-million-benefit-recipients/#comment-163160</guid>
		<description>[...] the government mailed half the nation&#8217;s bank details to the darknet at the end of last year, it looked like 2008 was going to be the year privacy issues hit the [...]</description>
		<content:encoded><![CDATA[<p>[...] the government mailed half the nation&#8217;s bank details to the darknet at the end of last year, it looked like 2008 was going to be the year privacy issues hit the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The Open Rights Group : Blog Archive &#187; MPs call for tougher data protection regime</title>
		<link>http://www.openrightsgroup.org/2007/11/20/hmrc-loses-confidential-details-of-15-million-benefit-recipients/#comment-162819</link>
		<dc:creator>The Open Rights Group : Blog Archive &#187; MPs call for tougher data protection regime</dc:creator>
		<pubDate>Thu, 03 Jan 2008 12:26:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.openrightsgroup.org/2007/11/20/hmrc-loses-confidential-details-of-15-million-benefit-recipients/#comment-162819</guid>
		<description>[...] The House of Commons Justice Committee has today released a report into the protection of public data. The report is a good summary of the state of play and, in particular, of developments since the Chancellor announced to Parliament in Novemeber last year that HMRC had lost confidential records affecting 25 million UK citizens. [...]</description>
		<content:encoded><![CDATA[<p>[...] The House of Commons Justice Committee has today released a report into the protection of public data. The report is a good summary of the state of play and, in particular, of developments since the Chancellor announced to Parliament in Novemeber last year that HMRC had lost confidential records affecting 25 million UK citizens. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jonathan</title>
		<link>http://www.openrightsgroup.org/2007/11/20/hmrc-loses-confidential-details-of-15-million-benefit-recipients/#comment-145025</link>
		<dc:creator>Jonathan</dc:creator>
		<pubDate>Wed, 21 Nov 2007 13:31:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.openrightsgroup.org/2007/11/20/hmrc-loses-confidential-details-of-15-million-benefit-recipients/#comment-145025</guid>
		<description>If it really is all those details for 25 million people on two CDs, that only leaves &#60; 60 bytes per person. It really needs to be compressed, so could it be a password protected zipfile?

How about a FOI request asking how many of the 100,000 HMRC employees have this level of database access? If it's many, never mind the loss of these CDs: it would only take one crooked worker to take a copy.</description>
		<content:encoded><![CDATA[<p>If it really is all those details for 25 million people on two CDs, that only leaves &lt; 60 bytes per person. It really needs to be compressed, so could it be a password protected zipfile?</p>
<p>How about a FOI request asking how many of the 100,000 HMRC employees have this level of database access? If it&#8217;s many, never mind the loss of these CDs: it would only take one crooked worker to take a copy.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom</title>
		<link>http://www.openrightsgroup.org/2007/11/20/hmrc-loses-confidential-details-of-15-million-benefit-recipients/#comment-145001</link>
		<dc:creator>Tom</dc:creator>
		<pubDate>Wed, 21 Nov 2007 11:21:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.openrightsgroup.org/2007/11/20/hmrc-loses-confidential-details-of-15-million-benefit-recipients/#comment-145001</guid>
		<description>Looking at the coverage in the Guardian this morning, they cover the password vs. encrypted issue, and state they understood that the database was only protected with a password, crackable in minutes by an expert.

Crazy to think that the records for 25 million people will fit on two CDs - I have an 8GB pen-drive, and could probably therefore steal not only the current database, but some archive versions too.</description>
		<content:encoded><![CDATA[<p>Looking at the coverage in the Guardian this morning, they cover the password vs. encrypted issue, and state they understood that the database was only protected with a password, crackable in minutes by an expert.</p>
<p>Crazy to think that the records for 25 million people will fit on two CDs - I have an 8GB pen-drive, and could probably therefore steal not only the current database, but some archive versions too.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Becky</title>
		<link>http://www.openrightsgroup.org/2007/11/20/hmrc-loses-confidential-details-of-15-million-benefit-recipients/#comment-144964</link>
		<dc:creator>Becky</dc:creator>
		<pubDate>Wed, 21 Nov 2007 09:02:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.openrightsgroup.org/2007/11/20/hmrc-loses-confidential-details-of-15-million-benefit-recipients/#comment-144964</guid>
		<description>Check out Open Rights Group Advisory Council member Dr Ian Brown on Newsnight last night: http://news.bbc.co.uk/1/hi/programmes/newsnight/default.stm (starts 11 minutes into the programme).</description>
		<content:encoded><![CDATA[<p>Check out Open Rights Group Advisory Council member Dr Ian Brown on Newsnight last night: <a href="http://news.bbc.co.uk/1/hi/programmes/newsnight/default.stm" rel="nofollow">http://news.bbc.co.uk/1/hi/programmes/newsnight/default.stm</a> (starts 11 minutes into the programme).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ewan</title>
		<link>http://www.openrightsgroup.org/2007/11/20/hmrc-loses-confidential-details-of-15-million-benefit-recipients/#comment-144668</link>
		<dc:creator>Ewan</dc:creator>
		<pubDate>Tue, 20 Nov 2007 18:31:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.openrightsgroup.org/2007/11/20/hmrc-loses-confidential-details-of-15-million-benefit-recipients/#comment-144668</guid>
		<description>Hi Dennis, while I very much hope that you are right, there's nothing in Alistair Darling's speech that refers to encryption, just 'password protected', which lets face it is another thing altogether, zip files and excel files can be password protected but noone should trust them for 25 million people's details.

And the second reason I doubt it's just the tapes and not the full database extract is that they were sending the copy to the national audit office, who wouldn't (I presume) have the decryption key for normal backups of the database, instead there would have to be one created especially for them.</description>
		<content:encoded><![CDATA[<p>Hi Dennis, while I very much hope that you are right, there&#8217;s nothing in Alistair Darling&#8217;s speech that refers to encryption, just &#8216;password protected&#8217;, which lets face it is another thing altogether, zip files and excel files can be password protected but noone should trust them for 25 million people&#8217;s details.</p>
<p>And the second reason I doubt it&#8217;s just the tapes and not the full database extract is that they were sending the copy to the national audit office, who wouldn&#8217;t (I presume) have the decryption key for normal backups of the database, instead there would have to be one created especially for them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dennis Howlett</title>
		<link>http://www.openrightsgroup.org/2007/11/20/hmrc-loses-confidential-details-of-15-million-benefit-recipients/#comment-144650</link>
		<dc:creator>Dennis Howlett</dc:creator>
		<pubDate>Tue, 20 Nov 2007 18:08:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.openrightsgroup.org/2007/11/20/hmrc-loses-confidential-details-of-15-million-benefit-recipients/#comment-144650</guid>
		<description>As I understand it the official got their hands on the encrypted tapes - not the database. There is a process problem here that's not been fully explained. If you check the BBC website, they've been giving this a lot of comment space. Last count - 1585 comments - guess how many unhappy citizens?</description>
		<content:encoded><![CDATA[<p>As I understand it the official got their hands on the encrypted tapes - not the database. There is a process problem here that&#8217;s not been fully explained. If you check the BBC website, they&#8217;ve been giving this a lot of comment space. Last count - 1585 comments - guess how many unhappy citizens?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ewan</title>
		<link>http://www.openrightsgroup.org/2007/11/20/hmrc-loses-confidential-details-of-15-million-benefit-recipients/#comment-144629</link>
		<dc:creator>Ewan</dc:creator>
		<pubDate>Tue, 20 Nov 2007 17:33:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.openrightsgroup.org/2007/11/20/hmrc-loses-confidential-details-of-15-million-benefit-recipients/#comment-144629</guid>
		<description>I can't quite get my head around this yet, there's so many sides to this story, not least of which is how exactly does 'a junior official within HRMC' get full unrestricted access to this database?

Aren't we always told this kind of access is extremely restricted to protect peoples privacy, and that systems are heavily monitored to stop stalking of celebrities through their government records?

Shouldn't some internal data security alarms have been ringing the moment the member of staff did the data extract, long before it was actually shipped out (twice) and finally reported as missing?</description>
		<content:encoded><![CDATA[<p>I can&#8217;t quite get my head around this yet, there&#8217;s so many sides to this story, not least of which is how exactly does &#8216;a junior official within HRMC&#8217; get full unrestricted access to this database?</p>
<p>Aren&#8217;t we always told this kind of access is extremely restricted to protect peoples privacy, and that systems are heavily monitored to stop stalking of celebrities through their government records?</p>
<p>Shouldn&#8217;t some internal data security alarms have been ringing the moment the member of staff did the data extract, long before it was actually shipped out (twice) and finally reported as missing?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John Drinkwater</title>
		<link>http://www.openrightsgroup.org/2007/11/20/hmrc-loses-confidential-details-of-15-million-benefit-recipients/#comment-144599</link>
		<dc:creator>John Drinkwater</dc:creator>
		<pubDate>Tue, 20 Nov 2007 16:08:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.openrightsgroup.org/2007/11/20/hmrc-loses-confidential-details-of-15-million-benefit-recipients/#comment-144599</guid>
		<description>Make that 25 million :s</description>
		<content:encoded><![CDATA[<p>Make that 25 million :s</p>
]]></content:encoded>
	</item>
</channel>
</rss>
