The Great Zero Challenge

Matthew Pemble ukcrypto at chiark.greenend.org.uk
Mon, 08 Sep 2008 12:31:19 +0100


ken wrote:
> Ian Batten wrote:
>>>
>>> For HMG use only wiping systems listed at the link below should be 
>>> used, which have been tested to be suitable:
>>
>>
>> I think that at the moment HMG might prefer to give its own staff 
>> advice on beams, prior to giving the rest of us advice on motes.  
>> We're soon going to reach a point where you're unusual _not_ to have 
>> had your data lost by the government.
>
> AFAICT HMG staff almost never lose data. Its nearly always the 
> contractors or consultants or whoever that they are forced to 
> outsource to (and have been forced to outsource to for about thirty 
> years) because the government doesn't believe that its own employees 
> are as competent as 23-year-old recent economics graduates who did a 
> six week course in Business Analysis and want to grow up to be 
> Management Consultants
>
I'm not sure the HMRC CDs example quite fits that, nor does the MOD 
recruiter's laptop.  I would suggest that it also often occurs at the 
(contractually rarely properly specified and never, in my experience, so 
with regard to data security) interfaces between different government 
departments (eg HMRC and NAO) or between the government department and 
the outsourcer.  Add in a lack of budget to spend on security measures 
(MOD laptop again), a callous disregard for security rules, especially 
amongst politicians (Blears & her constitiuency computer) and senior 
civil servants (intel documents on train) and you have the hideous mess 
that currently is facing us.

Matthew

Matthew