Feeds

Home Office reaches half-way hash in secure data handling

Encryption bureau to operate like internal post office

The Power of One eBook: Top reasons to choose HP BladeSystem

While it would be better for the Home Office bureau to publish its own public key and apply public-key cryptography to provide end-to-end encryption the use of a centralised encryption bureau is at least workable and perhaps appropriate, according to Cowper.

"It's preferable to have end-to-end cryptography but it all depends on the nature of the information you are trying to protect and the scale of the network," he said.

Government departments aiming to improve security have focused most of their energy on rolling out laptop encryption. "Laptop activity is the immediate problem. The government is less focused on email security. We'd argue that's where the data flows but there is still a perception about ease of use of email encryption," Cowper explained.

Sending encrypted communications in the form of a self-decrypting archive means that no client is required, but also requires accepting executable files in email messages, a dangerous practice in general - especially bearing in mind that UK government departments are a prime target for targeted Trojan attacks.

However we understand that the PC that accepts the encrypted email from third parties is a standalone machine, not networked to internal Home Office IT systems or connected to the Government Secure Intranet.

"There's a balance between scanner and encryption which is why the Home Office have taken a sandbox approach. For communication with small third party organisations - who have few resources - the centralised encryption bureau is an interesting model. For secure communications with commercial bodies this may need another pass," Cowper concluded.

The Home Office explanation on how encrypted communications will be handled raises further concerns about possible impersonation.

Encrypted data from 3rd party originator to Encryption Bureau
  1. Email/CD/DVD is received by the Bureau.
  2. Bureau will contact the originator to confirm receipt and provide reference number and gain passphrase.
  3. Bureau will decrypt file.
  4. Bureau will forward decrypted file via email to Home Office intended recipient. If data is too large to email, the recipient will be advised and the data will be placed in ‘pick-up’ zone on the network folder for immediate retrieval and deletion.
  5. Bureau will send a confirmation email to the originator that the data has been sent to the Home Office recipient.
  6. Bureau will shred/delete Originator’s CD/DVD/email.

The possibility of potential fraudsters or mischief-makers posing as the Home Office could be addressed if the bureau published its own public key. As things stand the Central Cryptography Service is being run more like an internal postal service that simply receives messages from the outside before distributing them internally.

In fairness these procedures are much better than what existed previously. The Home Office expresses a strong preference for information sent to it to be encrypted and sets out procedures to handle this.

The Home Office said it was implementing the recommendations of the Hannigan report for improving the handling of data across Whitehall departments.

"The Home Office is determined to learn from earlier security breaches in Government and the programme initiated in response to the Hannigan report will help ensure that our systems and processes to protect personal data are as good as they can be. We are fully committed to implementing all of the recommendations in the report and have already established a programme to drive the work forward," it said.

"Many of the recommendations are already in effect in the Home Office and we recently launched a new, centralised encryption service at the Home Office. No personal information may be sent beyond the secure boundary of Government IT networks (e.g. GSI and PNN) without first being encrypted. Third parties sending personal information to the Home Office are also encouraged to encrypt their information.

"In addition to this, the Home Office already has in place a Hannigan-compliant system for reporting security incidents. Any breaches of security at the department will be taken very seriously and investigated thoroughly to avoid any possibility of recurrence." ®

Designing a Defense for Mobile Applications

More from The Register

next story
Mozilla fixes CRITICAL security holes in Firefox, urges v31 upgrade
Misc memory hazards 'could be exploited' - and guess what, one's a Javascript vuln
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Don't look, Snowden: Security biz chases Tails with zero-day flaws alert
Exodus vows not to sell secrets of whistleblower's favorite OS
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Researcher sat on critical IE bugs for THREE YEARS
VUPEN waited for Pwn2Own cash while IE's sandbox leaked
Four fake Google haxbots hit YOUR WEBSITE every day
Goog the perfect ruse to slip into SEO orfice
prev story

Whitepapers

Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.