Phil Hendren
Subscribe to The Times and The Sunday Times
"Unusable on the black market” - that's what the Identity and Passport Service said when it had to admit that 3,000 blank passports and the van carrying them had been stolen in Oldham last week. The online information security discussion groups burst into laughter at yet another minister making statements of certainty about the impossibility of cracking a government system.
The security of the new e-passport, sold as foolproof against identity theft, was this week shown by a Times investigation to be easily breached. A computer researcher cloned the microchips on two British e-passports and - to drill the point home about the weakness of the system - then implanted digital images of Osama bin Laden and a suicide bomber. It's not the first time that the security of e-passports has been compromised. Almost two years ago a German security expert attacked the “secure chip” by injecting a malicious code into it so that when the passport was scanned it crashed the scanning device
In the corporate world, too, there are just as many serious lapses of security. A number of months ago, the US retailers such as T. J. Maxx were targeted by the biggest single hacking operation in history, which resulted in 40 million credit and debit card numbers being compromised. This was made possible by a complete failure on the part of the retailers to protect the wireless networks that transmit their customers payment data. They might as well have written their customers' card numbers and PIN on a postcard and sent it to Visa in the mail.
We should not only be angry with government departments or businesses that fail to protect our data from fraudsters and criminals, but also at ourselves for the blind confidence we have put in technology's ability to provide that mythical thing called “total security”. It is a cliché to say that we as a society have sleepwalked into something, but when it comes to the security of our data we have not just walked, we've rushed headlong into an online world where we instinctively trust everything.
We have also given our trust far too readily because computers have been made “easy” for us. For instance, we trust those little icons that show a padlock while we browse the web. Or put too much confidence in the “firewall” that tells us how many hackers it has stopped.
But we never learn. The Government has been examining the possibility of introducing a quality mark for software designed to filter internet sites to protect children while they are online. But it would be only a matter of time before the first newspaper story about a child being groomed by a paedophile appears, complete with quotes from a distraught parent saying: “We bought a government-approved product and it didn't work.”
Instead of parents taking an active interest in protecting the online lives of their children, many will opt for the false security of a little logo. We have become infantilised by technology. Instead of trying to get to grips with information technology, we simply defer to the experts, and then we wonder why we are annoyed when things fail.
The truth is that there is no system that cannot be hacked. If a human being can create a security system, then another human being will be ingenious enough to find a way in, or around it. That's why Jeff Richards, the security expert, made his two laws of data security so simple: (1) Don't buy a computer; (2) If you do buy a computer, don't turn it on.
This is not meant to frighten people away from using computers: it is meant to inject a modicum of common sense into our approach to the security of our information and what we should expect of each other in relation to all of our data.
In the personal arena we need to be more aware of whom we give our data to, why we give them that data and what we should do if we think our data has been compromised. When, for example, your computer begins to act strangely as if it has a mind of its own, then assume the worst and change the password for those online shopping websites you use - this is something that should be done regularly anyway. It may sound bleak, but we must start to trust others less and ourselves more when it comes to our data. We must start to remember that it is ours and we have as much responsibility over it as those guardians we give permission to store it.
Our attitude towards security is stuck in the 20th century of the “eyes only” paper documents: the greater use of technology should run side by side with an ever greater awareness of security.
Government ministers, civil servants, corporate bodies and individuals too should have the words of Eugene H. Spafford, a professor of computer science and leading security expert, drilled into them. “The only system that is truly secure is one that is switched off and unplugged, locked in a titanium safe, buried in a concrete vault on the bottom of the sea and surrounded by very highly paid armed guards. Even then I wouldn't bet on it.”
Phil Hendren is a Unix systems administrator. He blogs at dizzythinks.net
Read the training tips and advice that helped our London Triathletes
Enjoy screenings of all the classic films you love, plus take advantage of two-for-one tickets
Times Online's new TV show helps you make the right decisions for your pet
Read our exclusive 100 Years of Fleming and Bond interactive timeline, packed with original Times articles and reviews
The latest travel news plus the best hotels and gadgets for business travellers
Shortcuts to help you find sections and articles


Why good girls pay good money for bad-girl baubles

Search The Times Births, Marriages & Deaths
2007
£47,995
2008
£42,945
06/2006
£40,850
Great car insurance deals online
£33,000
Macmillan Cancer Support
Central/South West
£50k
NHS
Nationwide
£
£30k OTE
Meltwater News
Nationwide
circa £70k
Central Office of Information
London
Great Dubai Investment Opportunities
from £89,950
The Finest Luxury Homes In London and the SE
From £995,000
Studios £33K, 1 Beds £60K, 2 beds £79K
Great Investment, River Views
New York Christmas Shopping
Christmas Cruises
From only £995pp
APTs East Coast now from only
£2425pp.
Great travel insurance deals online
Contact our advertising team for advertising and sponsorship in Times Online, The Times and The Sunday Times. Globrix Property Search - find property for sale and rent in the UK. Visit our classified services and find jobs, used cars, property or holidays. Use our dating service, read our births, marriages and deaths announcements, or place your advertisement.
Copyright 2008 Times Newspapers Ltd.
This service is provided on Times Newspapers' standard Terms and Conditions. Please read our Privacy Policy.To inquire about a licence to reproduce material from Times Online, The Times or The Sunday Times, click here.This website is published by a member of the News International Group. News International Limited, 1 Virginia St, London E98 1XY, is the holding company for the News International group and is registered in England No 81701. VAT number GB 243 8054 69.
Stop using Windows / Internet Exlorer. Get a Mac, set its firewall to "stealth" and use file vault and a secure password generator - it would take the entire resources of the FBI about a week to hack it (unless you're Bin Laden that's never going to happen). Browse with Firefox and use common sense.
Alastair, Alicante, Spain
A couple of years 'mortgage' fraud,was happening in Canada and the US. Hackers got into bank systems. People had their homes 'bought' out from under them. It was up to those, duped to prove otherwise. Even a piece of paper indicating the mortgage was paid in full, was not sufficient! OK now I hope!
Michael Sullivan, Toronto, Canada
Buy a Mac.
Zeon, Galveston, USA
Quite : the problem with the socialists' ID card is not the card ; it's the database. Absolutely no system connected to a network cannot be broken ... eventually.
In an environment in which misguided people place trust in technology, no security is better than any.
Pericles, Tewkesbury, England
*sigh*
Many of these comments sound like my father-in-law.
Of course computers can be made simple - but then they don't do much. If you want a general-purpose machine, it WILL be complicated.
Complexity means it most likely will have flaws, and flaws can be exploited.
THAT is the reality
Richard, Leighton Buzzard, UK
Computers are bought as white goods by the majority of users. The manufacturers have sought to make people believe that computers are not complicated and easy to use. They are not. Computers are hideously complex the fact is gets hidden behind a pretty picture on the screen doesn't make it go away.
Olaf, Dundee,
Typical piece by a computer nerd - any ordinary person who dares to think that a piece of technology might be easy to use is accused of having been "infantalised".
When will the IT industry learn that users, i.e. the people that buy their goods and services, want stuff that just works?
Chris Rodger, London,
If there was a 100% system that was cost effective; the film and recording industry would be using it. A human has design it another human can break it. The only criteria, is it worthwhile,but there are hackers who do it ,just for the buzz.
A Walton, Leicester, England
Phil Hendren's statement (a) "Instead of trying to get to grips with information technology, we simply defer to the experts"
contradicts
his statement (b) "The truth is that there is no system that cannot be hacked."
Pianiss Imo, Greenbrae,
Oh! grow up the lot of you and stop writing this drivel. The computer IS now the real world like it or not - get to learn to live with it NOW with all it's blemishes. Perhaps try and give it a top speed of 8 MPH and a man with a red flag. There is nothing perfect. Get real.
Victor M., Chelmsford, Essex.,
(1) Don't buy a computer; (2) If you do buy a computer, don't turn it on. Yes, but there really isn't much danger provided that you obey (3) Don't connect it to the internet.
Thomas Goodey, Cuxton-upon-Medway, England