Feeds

Government Gateway login details found in pub car park

Transformational security breaches

Maximizing your infrastructure through virtualization

Updated Key government services were taken offline over the weekend after the discovery in a pub car park of a pocket storage device containing details of the Government Gateway. The Gateway is intended to provide a central secure login service for a range of government systems, including tax credits and self assessment, so taking it offline paralyses these too, before you can say 'single point of failure'.

The device, which was passed to the Mail on Sunday last week, was lost two weeks ago outside a pub in Cannock, Staffordshire, by an employee of Atos Origin. In 2006 Atos Origin won a £46.7m five-year contract to provide managed IT services for the Government Gateway.

The Department of Work & Pensions claims that the data on the device was encrypted and the security of the Government Gateway had not been breached. However, according to the Mail, Jacques Erasmus, a security expert who examined the device for the paper, said it contained passwords, security software and "source code". Erasmus told the paper: "I could decrypt those passwords to log in to the system and roam around the network. As we can see from the data on the USB stick, the systems contain highly sensitive personal information. If you can crack those encrypted passwords, and it would just be a matter of time, you could potentially access those 12 million accounts and those details."

In a statement Atos Origin said that the removal of the device from its premises was in direct breach of its operating principles, while the DWP said that an "urgent investigation" was under way.

By lunchtime, the Information Commissioner had weighed in, with a statement informing us Richard Thomas "is now awaiting the results of ongoing investigations to establish the facts and the nature and extent of any risk to individuals."

The statement added, "The Information Commissioner expects the Government to take appropriate damage limitation steps as its first priority."

A year after the MHMRC data debacle, this sounds hopeful, at best.

Meanwhile, in an entirely unrelated piece of joined-up data loss, DWP Secretary James Purnell has been spotted shedding confidential documents on a train. ®

Top three mobile application threats

More from The Register

next story
Arrr: Freetard-bothering Digital Economy Act tied up, thrown in the hold
Ministry of Fun confirms: Yes, we're busy doing nothing
Help yourself to anyone's photos FOR FREE, suggests UK.gov
Copyright law reforms will keep m'learned friends busy
Apple smacked with privacy sueball over Location Services
Class action launched on behalf of 100 million iPhone owners
US judge: YES, cops or feds so can slurp an ENTIRE Gmail account
Crooks don't have folders labelled 'drug records', opines NY beak
ONE EMAIL costs mining company $300 MEEELION
Environmental activist walks free after hoax sent share price over a cliff
UK government officially adopts Open Document Format
Microsoft insurgency fails, earns snarky remark from UK digital services head
You! Pirate! Stop pirating, or we shall admonish you politely. Repeatedly, if necessary
And we shall go about telling people you smell. No, not really
prev story

Whitepapers

Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.