Home Office laptop and data sold on eBay
By Chris Green,
The Home Office is today under well-deserved scrutiny after a disc containing confidential data from the government department was discovered hidden under the keyboard of a laptop that had been sold on the internet auction site eBay.
The disc, concealed under the keyboard of the laptop was discovered by a Machester-based PC repair centre when the machine was brought in for a problem to be investigated.
"This seemed like just another repair" said Lee Bevan, the managing director of LeapFrog Computers, the computer repair company that made the discovery.
"The customer said he bought it on eBay and seemed quite innocent. It was only when we opened it up we found the disc with the words Home Office Confidential written on it hidden under the keyboard. We tried to read it, but couldn't as it was encrypted."
The Home Office has launched an inquiry into the incident, and a spokesman for the department confirmed that the data, which along with the laptop have been handed to Greater Manchester Police, is encrypted not merely password protected. This is in stark contrast to many recent data losses and thefts where data has either been completely unprotected or locked with little more than a basic password.
This is the latest in a number of high-profile and embarrassing data losses by government departments and agencies. In addition to the HM Revenue and Customs CD loss that compromised 25 million data records that has dominated the news in recent months, the Ministry of Defence, HNS and Ministry of Justice have all been found to have lost confidential data relating to personnel, the public and matters of state.
Industry commentators have been quick to speak out about this latest failure by the public sector to implement best practice in its data security.
"If it transpires that this is a device that the Home Office disposed of because it was no longer needed, then some serious questions need to be asked," said Philip Wicks, a consultant at IT firm Morse.
"When getting rid of old IT equipment all organisations should be following a strict disposal process. Whether it is being sold off or thrown out, when getting rid of old laptops, PCs or servers organisations should be removing all data from the device regardless of whether it is encrypted or not. This isn't as simple as hitting the delete button to erase the data from the disk drive; this won't necessarily clear the data, it just hides it."
This is not the first time that a government laptop has turned up on eBay. "With the statistics showing that nearly 500 government devices have gone missing since 2001, it was only a matter of time before a confidential disc inadvertently ended up on eBay," said Brian Spector, general manager of the content protection group at Workshare.
"The good news with this latest data breach is that the data was encrypted," added Alan Bentley, vice president of Lumension Security. "However, encryption alone is not infallible - computer hackers are determined individuals and we certainly shouldn't be relying on one line of protection when it comes to our national security."
advertisement
Latest Security Features
How to be a successful online fraudster
Ever wanted to know how easy it is to be an identity thief and earn a fortune? IT PRO reveals all…
- What you need to know about ID cards
- Lessons to learn from a year of data breaches
- Q&A: DNS inventor Paul Mockapetris
- Is the password ill-equipped for the modern world?
- Why is backing up given short shrift?
- Defending Europe against cyber attack
- The present and future of IT security
- I’m an IT manager, get me out of here!
- IT around the world: Russia
Latest Security Reviews
Fortinet FortiGate-3810A
Rating: ![]()
- Clearswift MIMEsweeper Web Appliance ENW
- NetASQ U6000 UTM appliance
- AVG Internet Security SBS Edition 8.0
- Finjan Vital Security Web Appliance NG-6000S
- LogLogic MX2010
- Exclusive: WatchGuard Firebox Core X750e
- Sophos ES4000 Security Appliance
- Microsoft Forefront Security for Exchange and SharePoint
- EXCLUSIVE: Juniper Networks SSG 550 UTM appliance
advertisement
Latest News Videos in Security
Video: Eugene Kaspersky outlines security threats
IT PRO speaks to Eugene Kaspersky, chief executive and founder of Kaspersky Lab.
White papers
Want more background on today's hottest IT trends?
Visit IT PRO's white paper library for more on virtualisation, encryption and other topics.
Register for IT PRO
You'll get exclusive member benefits including free white papers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.



Social Bookmark this article: What is this?