Feeds

Spooks want to go fishing in Oyster database

Pearl-diving in London's smartcard beds

Internet Security Threat Report 2014

The UK's spooks have sought full automated access to Transport for London (TfL)'s "Oyster" smartcard network, further extending the amount of travel data available to the government.

The Observer said this weekend that the Information Commissioner's Office (ICO) has confirmed that the clandestine services have requested full Oyster access, and would target other cities' smartcard travel schemes as they come online.

At present they can request details of an Oyster user's transactions - and hence, time-slugged locations - on an individual basis only, rather than having free rein to search the system as they please. This could include mining the entire database to look for suspicious patterns, and tracking named individuals.

It isn't difficult to avoid Oyster monitoring, as one need merely pay cash when using public transport. The smartcard scheme is significantly cheaper than cash, however, and many righteous citizens might resent paying extra for privacy. Of course, there's always the option of registering an Oyster card under a false name and only ever topping up by cash. Or simply buying a pay as you go Oyster at a ticket window.

Driving in TfL's central area of responsibility offers no escape, since the congestion-charge numberplate-scan camera net was hooked up to the secret terror police following a series of "bomb" outrages in which no bombs were used and only terrorists were hurt. Other cities are also looking at their own electronic traffic management schemes, while the UK motorway system has a handy network of ANPR cameras.

The ICO apparently refused any further comment on the progress of the Whitehall debate regarding MI5/SS and MI6/SIS access to Oyster, citing "national security" concerns as the reason for conducting the discussion in secret.®

Secure remote control for conventional and virtual desktops

More from The Register

next story
MI6 oversight report on Lee Rigby murder: US web giants offer 'safe haven for TERRORISM'
PM urged to 'prioritise issue' after Facebook hindsight find
Assange™ slumps back on Ecuador's sofa after detention appeal binned
Swedish court rules there's 'great risk' WikiLeaker will dodge prosecution
NSA mass spying reform KILLED by US Senators
Democrats needed just TWO more votes to keep alive bill reining in some surveillance
'Internet Freedom Panel' to keep web overlord ICANN out of Russian hands – new proposal
Come back with our internet! cries Republican drawing up bill
What a Mesa: Apple vows to re-use titsup GT sapphire glass plant
Commits to American manufacturing ... of secret tech
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
Designing and building an open ITOA architecture
Learn about a new IT data taxonomy defined by the four data sources of IT visibility: wire, machine, agent, and synthetic data sets.
How to determine if cloud backup is right for your servers
Two key factors, technical feasibility and TCO economics, that backup and IT operations managers should consider when assessing cloud backup.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.