Home Office laptop and data sold on eBay
By Chris Green,
The Home Office is today under well-deserved scrutiny after a disc containing confidential data from the government department was discovered hidden under the keyboard of a laptop that had been sold on the internet auction site eBay.
The disc, concealed under the keyboard of the laptop was discovered by a Machester-based PC repair centre when the machine was brought in for a problem to be investigated.
"This seemed like just another repair" said Lee Bevan, the managing director of LeapFrog Computers, the computer repair company that made the discovery.
"The customer said he bought it on eBay and seemed quite innocent. It was only when we opened it up we found the disc with the words Home Office Confidential written on it hidden under the keyboard. We tried to read it, but couldn't as it was encrypted."
The Home Office has launched an inquiry into the incident, and a spokesman for the department confirmed that the data, which along with the laptop have been handed to Greater Manchester Police, is encrypted not merely password protected. This is in stark contrast to many recent data losses and thefts where data has either been completely unprotected or locked with little more than a basic password.
This is the latest in a number of high-profile and embarrassing data losses by government departments and agencies. In addition to the HM Revenue and Customs CD loss that compromised 25 million data records that has dominated the news in recent months, the Ministry of Defence, HNS and Ministry of Justice have all been found to have lost confidential data relating to personnel, the public and matters of state.
Industry commentators have been quick to speak out about this latest failure by the public sector to implement best practice in its data security.
"If it transpires that this is a device that the Home Office disposed of because it was no longer needed, then some serious questions need to be asked," said Philip Wicks, a consultant at IT firm Morse.
"When getting rid of old IT equipment all organisations should be following a strict disposal process. Whether it is being sold off or thrown out, when getting rid of old laptops, PCs or servers organisations should be removing all data from the device regardless of whether it is encrypted or not. This isn't as simple as hitting the delete button to erase the data from the disk drive; this won't necessarily clear the data, it just hides it."
This is not the first time that a government laptop has turned up on eBay. "With the statistics showing that nearly 500 government devices have gone missing since 2001, it was only a matter of time before a confidential disc inadvertently ended up on eBay," said Brian Spector, general manager of the content protection group at Workshare.
"The good news with this latest data breach is that the data was encrypted," added Alan Bentley, vice president of Lumension Security. "However, encryption alone is not infallible - computer hackers are determined individuals and we certainly shouldn't be relying on one line of protection when it comes to our national security."
advertisement
Latest Security Features
Who should be Britain’s cyber security czar?
Experts reveal what a UK head of cyber security would need to do, while we put forward possible candidates for the role.
- The reality of movie technology
- Do smartphones need security software?
- Protecting the London 2012 Olympic Games
- Focus on... Flexible working
- Cyber policing and surveillance in Britain today
- How an FBI agent transformed Microsoft security
- Can security concerns kill cloud computing?
- GhostNet: Did the Chinese government hack the world?
- How poor web security nearly lead to a jail term
Latest Security Reviews
HP BladeSystem c3000 review: blade server
Rating: ![]()
- CA ARCserve Backup r12.5 review
- FaceTime Communications USG530 - web filtering appliance review
- Guardium 7 – database security review
- Google Apps Premier Edition
- SmoothWall UTM-1000 review
- Lenovo ThinkPad USB Portable Secure Hard Drive
- LogRhythm LR-500-XM review
- EXCLUSIVE - eSoft ThreatWall 250
- Zebra RZ400 - RFID Printer
advertisement
Latest News Videos in Security
Video: Mobile security threats and Mac complacency
Part two: Eugene Kaspersky, chief executive and founder of Kaspersky Lab, talks about the increasing security threats mobile users are facing.
Whitepapers
Want more background on today's hottest IT trends?
Visit IT PRO's whitepaper library for more on virtualisation, encryption and other topics.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.



Social Bookmark this article: What is this?