Phil Hendren
Win VIP tickets
"Unusable on the black market” - that's what the Identity and Passport Service said when it had to admit that 3,000 blank passports and the van carrying them had been stolen in Oldham last week. The online information security discussion groups burst into laughter at yet another minister making statements of certainty about the impossibility of cracking a government system.
The security of the new e-passport, sold as foolproof against identity theft, was this week shown by a Times investigation to be easily breached. A computer researcher cloned the microchips on two British e-passports and - to drill the point home about the weakness of the system - then implanted digital images of Osama bin Laden and a suicide bomber. It's not the first time that the security of e-passports has been compromised. Almost two years ago a German security expert attacked the “secure chip” by injecting a malicious code into it so that when the passport was scanned it crashed the scanning device
In the corporate world, too, there are just as many serious lapses of security. A number of months ago, the US retailers such as T. J. Maxx were targeted by the biggest single hacking operation in history, which resulted in 40 million credit and debit card numbers being compromised. This was made possible by a complete failure on the part of the retailers to protect the wireless networks that transmit their customers payment data. They might as well have written their customers' card numbers and PIN on a postcard and sent it to Visa in the mail.
We should not only be angry with government departments or businesses that fail to protect our data from fraudsters and criminals, but also at ourselves for the blind confidence we have put in technology's ability to provide that mythical thing called “total security”. It is a cliché to say that we as a society have sleepwalked into something, but when it comes to the security of our data we have not just walked, we've rushed headlong into an online world where we instinctively trust everything.
We have also given our trust far too readily because computers have been made “easy” for us. For instance, we trust those little icons that show a padlock while we browse the web. Or put too much confidence in the “firewall” that tells us how many hackers it has stopped.
But we never learn. The Government has been examining the possibility of introducing a quality mark for software designed to filter internet sites to protect children while they are online. But it would be only a matter of time before the first newspaper story about a child being groomed by a paedophile appears, complete with quotes from a distraught parent saying: “We bought a government-approved product and it didn't work.”
Instead of parents taking an active interest in protecting the online lives of their children, many will opt for the false security of a little logo. We have become infantilised by technology. Instead of trying to get to grips with information technology, we simply defer to the experts, and then we wonder why we are annoyed when things fail.
The truth is that there is no system that cannot be hacked. If a human being can create a security system, then another human being will be ingenious enough to find a way in, or around it. That's why Jeff Richards, the security expert, made his two laws of data security so simple: (1) Don't buy a computer; (2) If you do buy a computer, don't turn it on.
This is not meant to frighten people away from using computers: it is meant to inject a modicum of common sense into our approach to the security of our information and what we should expect of each other in relation to all of our data.
In the personal arena we need to be more aware of whom we give our data to, why we give them that data and what we should do if we think our data has been compromised. When, for example, your computer begins to act strangely as if it has a mind of its own, then assume the worst and change the password for those online shopping websites you use - this is something that should be done regularly anyway. It may sound bleak, but we must start to trust others less and ourselves more when it comes to our data. We must start to remember that it is ours and we have as much responsibility over it as those guardians we give permission to store it.
Our attitude towards security is stuck in the 20th century of the “eyes only” paper documents: the greater use of technology should run side by side with an ever greater awareness of security.
Government ministers, civil servants, corporate bodies and individuals too should have the words of Eugene H. Spafford, a professor of computer science and leading security expert, drilled into them. “The only system that is truly secure is one that is switched off and unplugged, locked in a titanium safe, buried in a concrete vault on the bottom of the sea and surrounded by very highly paid armed guards. Even then I wouldn't bet on it.”
Phil Hendren is a Unix systems administrator. He blogs at dizzythinks.net
Win a luxury weekend to Newcastle and its neighbour Gateshead, find out more here
Risk, resilience and embracing new technology
Industry sectors news at a glance. Interactive heatmap, video and podcast
Discover the power of collective thinking. Submit a solution and be in with a chance to win a Media Hub Home Entertainment System
The inside track on current trends in the charity, not for profit and social enterprise sectors
Everything the Business Traveller needs to know to make a better trip
Make the most of the summer and enter our fabulous photographic competition, you could win a £5000 holiday
Corsica is an island of beauty and contrast, an ideal holiday destination
Enjoy further reading from Travel to Fashion, Business to Sport, discover more
Shortcuts to help you find sections and articles
The clever way to lease a new car is with Car leasing made simple™
2009
per month on 36-month
Personal Contract Hire (PCH)
2008
42850
Car Insurance
£23,093 - £56,211
The Office for National Statistics
Newport, South Wales
£60,000
The Environment Agency
Bristol
Up to £90K
Boots
Midlands
OTE £85k
Credit Protection Association
Nationwide Opportunities
Completely London
Luxury Condo's in Manhattan with NYC views
The best new homes in Wimbledon?
Nationwide
Fabulous Cruise And Cruise & Stay Offers Including Virgin Atlantic Flights Prices Start From Only £699pp!
Last Minute Cruise And Cruise & Stay Offers. Med From £499pp, Caribbean From £699pp!
5 star quality at a 3 star price.
8 fabulous Canadian cities ...you won’t find cheaper
Contact our advertising team for advertising and sponsorship in Times Online, The Times and The Sunday Times, or place your advertisement.
Times Online Services: Dating | Jobs | Property Search | Used Cars | Holidays | Births, Marriages, Deaths | Subscriptions | E-paper
News International associated websites: Globrix Property Search | Property Finder | Milkround
Copyright 2009 Times Newspapers Ltd.
This service is provided on Times Newspapers' standard Terms and Conditions. Please read our Privacy Policy.To inquire about a licence to reproduce material from Times Online, The Times or The Sunday Times, click here.This website is published by a member of the News International Group. News International Limited, 1 Virginia St, London E98 1XY, is the holding company for the News International group and is registered in England No 81701. VAT number GB 243 8054 69.
Stop using Windows / Internet Exlorer. Get a Mac, set its firewall to "stealth" and use file vault and a secure password generator - it would take the entire resources of the FBI about a week to hack it (unless you're Bin Laden that's never going to happen). Browse with Firefox and use common sense.
Alastair, Alicante, Spain
A couple of years 'mortgage' fraud,was happening in Canada and the US. Hackers got into bank systems. People had their homes 'bought' out from under them. It was up to those, duped to prove otherwise. Even a piece of paper indicating the mortgage was paid in full, was not sufficient! OK now I hope!
Michael Sullivan, Toronto, Canada
Buy a Mac.
Zeon, Galveston, USA
Quite : the problem with the socialists' ID card is not the card ; it's the database. Absolutely no system connected to a network cannot be broken ... eventually.
In an environment in which misguided people place trust in technology, no security is better than any.
Pericles, Tewkesbury, England
*sigh*
Many of these comments sound like my father-in-law.
Of course computers can be made simple - but then they don't do much. If you want a general-purpose machine, it WILL be complicated.
Complexity means it most likely will have flaws, and flaws can be exploited.
THAT is the reality
Richard, Leighton Buzzard, UK
Computers are bought as white goods by the majority of users. The manufacturers have sought to make people believe that computers are not complicated and easy to use. They are not. Computers are hideously complex the fact is gets hidden behind a pretty picture on the screen doesn't make it go away.
Olaf, Dundee,
Typical piece by a computer nerd - any ordinary person who dares to think that a piece of technology might be easy to use is accused of having been "infantalised".
When will the IT industry learn that users, i.e. the people that buy their goods and services, want stuff that just works?
Chris Rodger, London,
If there was a 100% system that was cost effective; the film and recording industry would be using it. A human has design it another human can break it. The only criteria, is it worthwhile,but there are hackers who do it ,just for the buzz.
A Walton, Leicester, England
Phil Hendren's statement (a) "Instead of trying to get to grips with information technology, we simply defer to the experts"
contradicts
his statement (b) "The truth is that there is no system that cannot be hacked."
Pianiss Imo, Greenbrae,
Oh! grow up the lot of you and stop writing this drivel. The computer IS now the real world like it or not - get to learn to live with it NOW with all it's blemishes. Perhaps try and give it a top speed of 8 MPH and a man with a red flag. There is nothing perfect. Get real.
Victor M., Chelmsford, Essex.,
(1) Don't buy a computer; (2) If you do buy a computer, don't turn it on. Yes, but there really isn't much danger provided that you obey (3) Don't connect it to the internet.
Thomas Goodey, Cuxton-upon-Medway, England