Feeds

CEOP accused of misleading public over site security fail

User who discovered the flaw says agency 'whitewashed' insecurity incident

Website security in corporate America

The person who discovered that the child abuse reporting mechanism on the website of the Child Exploitation and Online Protection Centre was insecure has reacted with anger to suggestions from the agency that the flaw had only affected surfers visiting the site from either Facebook or Google.

He says that contrary to CEOP's claims, the child abuse reporting page itself – and not just a landing page – had been available via a webpage that failed to apply an industry-standard SSL connection for the transmission of highly sensitive material. As a result confidential abuse reports submitted through the page would have been sent "in the clear" making them vulnerable to eavesdropping, according to Terry B, the person who discovered the flaw.

After the discovery of the problem, CEOP issued statements to the media, including El Reg and the BBC, downplaying the severity of the flaw, which was quickly resolved. In a statement, CEOP's chief exec, Peter Davies, said: "The risk was a hypothetical one and there is no evidence to suggest anyone's details have been jeopardised."

A spokeswoman further assured El Reg by telling us that the abuse report form itself was always encrypted and the problem, such as it was, was limited to users arriving from either Facebook and Google at a HTTP landing page on CEOP's website. It would have been better to have used a secure HTTPS page instead, CEOP admits, adding that the security weakness (which it said was fixed on the same day as notification) could only ever have been exploited by a "technically advanced" hacker.

Nonsense, according to Terry B, who has complained to data privacy watchdogs at the Information Commissioner's Office over both the flaw and CEOP's reaction to the problem.

Terry B has also arranged to speak to his MP over what he perceives to be an "attempted whitewash" and the difficulties that he has had in making a complaint about CEOP, for example its failure to provide him with a complaint form or a copy of their complaints process.

CEOP therefore stands accused of not only being more than a little clueless about web security, but of making misleading public statements about its mistakes.

We put Terry B's criticism to CEOP, asking whether it had anything further to say on the matter, but had yet to hear back from the child protection agency by the time we went to press. We'll update this story as and when we hear more.

Presumption of risk

Terry B told El Reg: "I am upset at Peter Davies from CEOP claiming that the vulnerability was only accessible from third-party sites such as Google, Yahoo! etc.

"The vulnerability was on the CEOP website itself. The reporting page itself was going over HTTP (insecure) and not HTTPS (secure)," he said, adding that CEOP had failed to apply an SSL connection by default.

Despite CEOP's assurances, Terry B still contends that there had been a real risk that highly sensitive child abuse reports were left open to interception.

"People who have submitted reports might think that they are only affected if they have submitted through Google etc," he said.

The highly sensitive and personal nature of the data submitted – which would include suspicions of child abuse – threatens not just victims but also those suspect of abuse, should the information fall into the hands of vigilantes.

"You have SSL on e-commerce sites because there is a presumption of risk," Terry B explained. "That's why CEOP's report function must run over an SSL link."

He said he had only contacted the media about the issue after the flaw had been resolved. He confirmed that CEOP had changed its site to use an SSL-encrypted connection by default within a day but is otherwise highly critical of the whole business, describing it as a "whitewash".

Terry B added that despite quickly carrying out some security improvements, CEOP had still left the insecure reporting page available to users by allowing the reporting page to be accessed simply by typing in the address directly or following old (and insecure) http links.

The Information Commissioner's Office has confirmed that it has launched an investigation into the incident, which remains ongoing.

CEOP was set up in 2006 to lead UK policing efforts in the fight against child abuse. It also runs education programmes. CEOP successfully lobbied for Facebook to put a panic button on its website, a measure the social network introduced even after criticism that the measure, though well-intentioned, was misconceived and bound to be ineffective. ®

Protecting users from Firesheep and other Sidejacking attacks with SSL

More from The Register

next story
Early result from Scots indyref vote? NAW, Jimmy - it's a SCAM
Anyone claiming to know before tomorrow is telling porkies
Home Depot: 56 million bank cards pwned by malware in our tills
That's about 50 per cent bigger than the Target tills mega-hack
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
UK.gov lobs another fistful of change at SME infosec nightmares
Senior Lib Dem in 'trying to be relevant' shocker. It's only taxpayers' money, after all
Critical Adobe Reader and Acrobat patches FINALLY make it out
Eight vulns healed, including XSS and DoS paths
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
TOR users become FBI's No.1 hacking target after legal power grab
Be afeared, me hearties, these scoundrels be spying our signals
Blood-crazed Microsoft axes Trustworthy Computing Group
Security be not a dirty word, me Satya. But crevice, bigod...
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
The next step in data security
With recent increased privacy concerns and computers becoming more powerful, the chance of hackers being able to crack smaller-sized RSA keys increases.