Feeds

Home Office reaches half-way hash in secure data handling

Encryption bureau to operate like internal post office

Using blade systems to cut costs and sharpen efficiencies

While it would be better for the Home Office bureau to publish its own public key and apply public-key cryptography to provide end-to-end encryption the use of a centralised encryption bureau is at least workable and perhaps appropriate, according to Cowper.

"It's preferable to have end-to-end cryptography but it all depends on the nature of the information you are trying to protect and the scale of the network," he said.

Government departments aiming to improve security have focused most of their energy on rolling out laptop encryption. "Laptop activity is the immediate problem. The government is less focused on email security. We'd argue that's where the data flows but there is still a perception about ease of use of email encryption," Cowper explained.

Sending encrypted communications in the form of a self-decrypting archive means that no client is required, but also requires accepting executable files in email messages, a dangerous practice in general - especially bearing in mind that UK government departments are a prime target for targeted Trojan attacks.

However we understand that the PC that accepts the encrypted email from third parties is a standalone machine, not networked to internal Home Office IT systems or connected to the Government Secure Intranet.

"There's a balance between scanner and encryption which is why the Home Office have taken a sandbox approach. For communication with small third party organisations - who have few resources - the centralised encryption bureau is an interesting model. For secure communications with commercial bodies this may need another pass," Cowper concluded.

The Home Office explanation on how encrypted communications will be handled raises further concerns about possible impersonation.

Encrypted data from 3rd party originator to Encryption Bureau
  1. Email/CD/DVD is received by the Bureau.
  2. Bureau will contact the originator to confirm receipt and provide reference number and gain passphrase.
  3. Bureau will decrypt file.
  4. Bureau will forward decrypted file via email to Home Office intended recipient. If data is too large to email, the recipient will be advised and the data will be placed in ‘pick-up’ zone on the network folder for immediate retrieval and deletion.
  5. Bureau will send a confirmation email to the originator that the data has been sent to the Home Office recipient.
  6. Bureau will shred/delete Originator’s CD/DVD/email.

The possibility of potential fraudsters or mischief-makers posing as the Home Office could be addressed if the bureau published its own public key. As things stand the Central Cryptography Service is being run more like an internal postal service that simply receives messages from the outside before distributing them internally.

In fairness these procedures are much better than what existed previously. The Home Office expresses a strong preference for information sent to it to be encrypted and sets out procedures to handle this.

The Home Office said it was implementing the recommendations of the Hannigan report for improving the handling of data across Whitehall departments.

"The Home Office is determined to learn from earlier security breaches in Government and the programme initiated in response to the Hannigan report will help ensure that our systems and processes to protect personal data are as good as they can be. We are fully committed to implementing all of the recommendations in the report and have already established a programme to drive the work forward," it said.

"Many of the recommendations are already in effect in the Home Office and we recently launched a new, centralised encryption service at the Home Office. No personal information may be sent beyond the secure boundary of Government IT networks (e.g. GSI and PNN) without first being encrypted. Third parties sending personal information to the Home Office are also encouraged to encrypt their information.

"In addition to this, the Home Office already has in place a Hannigan-compliant system for reporting security incidents. Any breaches of security at the department will be taken very seriously and investigated thoroughly to avoid any possibility of recurrence." ®

The smart choice: opportunity from uncertainty

More from The Register

next story
NEW, SINISTER web tracking tech fingerprints your computer by making it draw
Have you been on YouPorn lately, perhaps? White House website?
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
LibreSSL RNG bug fix: What's all the forking fuss about, ask devs
Blow to bit-spitter 'tis but a flesh wound, claim team
Black Hat anti-Tor talk smashed by lawyers' wrecking ball
Unmasking hidden users is too hot for Carnegie-Mellon
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
Own a Cisco modem or wireless gateway? It might be owned by someone else, too
Remote code exec in HTTP server hands kit to bad guys
British data cops: We need greater powers and more money
You want data butt kicking, we need bigger boots - ICO
prev story

Whitepapers

Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.