Rather than unverified nonsense about the 'scrapping' of state national digital ID plans @andyburnham, it's now time to make it a *reality* considering the state of UK data-breaches across multiple departments and agencies.
SCOOP: Apple has launched a new legal challenge against the UK's attempt to force it to create a "back door" to access customer cloud data https://t.co/qAQiO3mKfx
The only 'brute-force' shown is from ransomware groups hacking state agencies, incl. The Dept for Education, UK Statement Investment Agency & Police National Legal Database.
As usual, the State have their priorities wrong and it's the public who pay the heaviest price.
- Full names & contact details: 100,000+ officers/staff
- Data incl. officials from MoD, Home Office, NCA, CPS
- Source of breach: The Police National Legal Database
- Same group responsible for DfE breach last week, 607,000 records
How bad do things have to get @andyburnham?
607,000 records pulled from two systems: Turing Scheme & Help Desk portals.
Names, e-mail addresses, phone numbers, job titles of education sector contacts incl. govt officials.
And just *how* is a national digital ID system viable with such serious breaches?
Not a good week for Data Breach Britain.
- Dept. for Education: 607,000 records pulled from two portals incl. details of govt officials.
- UKGI: 51 govt officials details left exposed for 40hrs.
Cybersecurity resilience must be the #1 priority, not One Login centralisation.
- Britons don't like centralised state identity systems
- Britons don't like National ID
- The state has had at least 20 years to modernise infrastructure & strengthen cybersecurity
- The state dream of modern digital governance is not achievable
https://t.co/uxZskLELWS
The Department for Education has referred itself to the Information Commissioner’s Office after hackers gained access to hundreds of thousands of lines of information in a cyberattack.
Story ⬇️
https://t.co/dysS633WxQ
Key findings:
- Data breach not discovered for 1.5 years
- Data breach was preventable
- Extraordinary secrecy used by HMG
- Not simply human error: poor systems, weak oversight
A public interest existed & the public should have been informed a breach had occurred.
Attacks keep on coming because the crims keep getting hits & using pulled data for secondary attacks.
The painful truth is that the govt haven't learned from past mistakes yet want to modernise digital services. It's dangerous and it's going to cost the public dearly.
They're not just soft targets, they're high-value targets.
Imagine a scenario where One Login is integrated with DfE on an identity verification level using SSO.
You're looking at an even greater risk of compromise & larger blast surface potentially impacting multiple depts.