Feeds

Home Secretary in ID card gaffe

Unhackable? Up to a point, minister

Next gen security for virtualised datacentres

Security experts have rubbished claims by the Home Secretary that databases for the controversial National ID Cards will be "unhackable" because they are being kept off the public internet.

In an interview with BBC Radio 4's Today programme on Thursday, Jacqui Smith said "none of the [ID card] databases will be online, so it won't be possible to hack into them". Experts, such as GCHQ accredited penetration testing firm SecureTest, said the Home Secretary's claims demonstrate complete lack of understanding of the security issues affecting databases.

"There are numerous routes to compromise a database that is not available on the public internet," SecureTest managing director Ken Munro told El Reg.

Internal attacks, where a database could be compromised by an employee or visitor from the inside, and attacks via email are both possible vectors. If an external hacker was able to deliver an exploit to an unsuspecting internal user via email he might be able to get access to a machine that in turn allowed him access to the database.

"The Government Secure Intranet (GSI) mail filtering systems are not sufficient to prevent an unknown [zero day] vulnerability being delivered by email. Using this, the exploited machine would connect outbound to a third party, giving a degree of remote address, and potentially access to the database," Munro explained.

The UK's National Infrastructure Security Co-ordination Centre (NISCC), and other government agencies, have periodically warned of the active use of this kind of targeted attack since at least June 2005. The GSI's mail filtering system is well designed and blocks many of these attacks, but it would be foolish to think it provides complete protection against such assaults.

Munro describes Smith's faith in the inherent security of databases kept off the internet as "misguided" and symptomatic of wider government IT security shortcomings. "The minister's lack of appreciation gives us great concern that government ministers have no significant understanding of security, as evidenced by the recent data losses on CD," he said. "What hope have we got that the National ID card database will be any more secure?"

The Home Secretary's interview with Today can be found here. Smith's interview starts about the 12:00 minute mark and her comment on database security for the National ID Cards project can be found after the 18:20 mark.

In the course of her interview, Smith goes on to explain a revised rollout of ID cards, initially targeting non-EU foreign nationals and young adults. El Reg's take on this "boil a frog" plan can be found here. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
Super Cali signs a kill-switch, campaigners say it's atrocious
Remote-death button bad news for crooks, protesters – and great news for hackers?
UK government accused of hiding TRUTH about Universal Credit fiasco
'Reset rating keeps secrets on one-dole-to-rule-them-all plan', say MPs
Caught red-handed: UK cops, PCSOs, specials behaving badly… on social media
No Mr Fuzz, don't ask a crime victim to be your pal on Facebook
Ex US cybersecurity czar guilty in child sex abuse website case
Health and Human Services IT security chief headed online to share vile images
Don't even THINK about copyright violation, says Indian state
Pre-emptive arrest for pirates in Karnataka
The police are WRONG: Watching YouTube videos is NOT illegal
And our man Corfield is pretty bloody cross about it
Felony charges? Harsh! Alleged Anon hackers plead guilty to misdemeanours
US judge questions harsh sentence sought by prosecutors
prev story

Whitepapers

A new approach to endpoint data protection
What is the best way to ensure comprehensive visibility, management, and control of information on both company-owned and employee-owned devices?
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Maximize storage efficiency across the enterprise
The HP StoreOnce backup solution offers highly flexible, centrally managed, and highly efficient data protection for any enterprise.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.