MTAS and other NHS websites
Brian Morrison
ukcrypto at chiark.greenend.org.uk
Mon, 7 May 2007 18:51:07 +0100
--Sig_bKH4uSZ46eC=SCrQtoAssyl
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: quoted-printable
On Mon, 7 May 2007 11:35:36 -0400
vickyvicky@egypt.com wrote:
> Quoting Matthew Byng-Maddick <ukcrypto@lists.colondot.net>:
>=20
> >> This was really only a minor breach of security, an act of stupidity,
> >> although maybe symptomatic of a general attitude.
> >
> > Please feel free to tell that to someone whose sexual orientation (not
> > well-known to colleagues) had their data revealed to Channel 4 News. I'm
> > sure they'll agree with you that it was only a "minor breach of securit=
y".
> >
> > The question in my mind is now, "if this is only a minor breach of secu=
rity
> > what do you class as a major breach?".
> >
>=20
> Mathew
>=20
> Obviously this is more than a minor breach of security, and I'm not =20
> trying to underplay the importance of this to anyone whose personal =20
> data was made public.
It's that alright, and the mere fact that it was allowed to happen is
utterly shocking.
> The point that I was trying to make, though, is that this was a =20
> one-off goof. A mistake like this would not in itself have led to the =20
> site being off line for 10 days. Something more sinister mus be going =20
> on as well.
It looks like a major re-engineering job is being carried out, or at
least I hope so. Whether the result will be an improvement or not
remains to be seen; I for one won't be holding my breath because the
state of the system seen already suggests that no one out there has a
clue what they are doing.
--=20
Brian Morrison
bdm at fenrir dot org dot uk
"Arguing with an engineer is like wrestling with a pig in the mud;
after a while you realize you are muddy and the pig is enjoying it."
=20
GnuPG key ID DE32E5C5 - http://wwwkeys.uk.pgp.net/pgpnet/wwwkeys.html
--Sig_bKH4uSZ46eC=SCrQtoAssyl
Content-Type: application/pgp-signature; name=signature.asc
Content-Disposition: attachment; filename=signature.asc
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (GNU/Linux)
iD8DBQFGP2cL9BNjUd4y5cURAg6GAKCD30YfSWKiH7xKQK19vktN0ve1KQCff+9V
J/bX4SfVRB/6DTdIC+kWM4I=
=lorV
-----END PGP SIGNATURE-----
--Sig_bKH4uSZ46eC=SCrQtoAssyl--