NHS email encryption

Ross Anderson ukcrypto at chiark.greenend.org.uk
Sat, 25 Aug 2007 08:41:37 +0100


> The new one is SSL to server, SSL from server to reader

Which makes you feel more comfortable - unencrypted email about you sent 
from one doctor's demon account to another doctor's pipex account - or
this encrypted thingy that uses a server maintained by the government?

The same issue arose in the context of legal communications. While there
may be no basic objection to a CPS solicitor communicating with a 
barrister he instructs using a Ministry of Justice webmail server, I
would not be relaxed about my lawyers doing this were I a defendant.

If the government is now saying that data protection law means you have
to share your private data with the government, then the wheels have 
come off. 

Ross