Madeline Bennett

Privacy breaches put IT chiefs in peril

IT managers for AOL and the Australian government may have had some sleepless nights last month

Written by Madeline Bennett

August wasn’t a good month for promoting the security of personal data, as various big names were hit by problems.

AOL was in the headlines for a breach of data privacy. It inadvertently exposed the search histories of more than 650,000 users, whose data became widely available across the internet. Though AOL stressed that the information did not include personal details, a US newspaper swiftly identified one subscriber by analysing the available search terms.

The situation led to a heated debate over the amount and type of personal data that firms are storing, and should be allowed to retain. Following the debacle, AOL’s chief technology officer and two other staff parted ways with the company.

HSBC also came under the spotlight last month, after Cardiff University researchers announced they had found a way to circumvent the online bank’s log-in system. They said hackers could use keylogging software installed on a third-party PC to collect the log-in data required to access a victim’s bank account within a few attempts. HSBC’s reliance on a numeric-only passcode, and the fact that it doesn’t always change the three digits requested at log-in, made its system vulnerable, the researchers warned.

HSBC argued that such attacks are very unlikely as it would be a laborious process for a hacker to go through to access just one bank account. But as an HSBC customer, I wasn’t particularly surprised by news of the flaw. I’ve used its web banking facility for many years, and have never been required to change my passcode or been advised to update it.

Though HSBC played down the potential for hacking, I’m sure the bank’s customers would prefer to see any potential problem taken very seriously, even if there’s only a slight chance that any one of us would be affected.

It wasn’t only private companies in the news, though, as reports emerged last month that 600 Australian government staff had been routinely searching the national identity card system to look up details of friends and family or possibly to enable identity thefts. Almost 800 security breaches later, police are investigating five employees at the Centrelink government agency, 19 have been sacked and 92 others have resigned.

While HSBC was fortunate that the weakness in its system was exposed before it was exploited, AOL and the Australian government could not brush off their problems so easily.

I’m sure the UK government could learn a few important lessons about the need to secure its planned identity card system to avoid similar problems here. And the situation at AOL will remind IT chiefs that if problems occur, the buck could well rest with them.

Tags:

reader comments

related articles

Internet giants Amazon, Friends Reunited and eBay have come under fire this week over privacy concerns

Web giants accused of privacy violations

Privacy International criticises Amazon, Friends Reunited and eBay 01 Sep 2006

 

Privacy group raps AOL over data leak

Electronic Frontier Foundation asks Federal Trade Commission to investigate 16 Aug 2006

Heads roll over AOL privacy leak

Chief technology officer Maureen Govern steps down 24 Aug 2006

New web surfing privacy tool launches

Browzar allows mobile workers and hot deskers to surf the web in privacy 31 Aug 2006

Stakeholders gear up for e-Crime Congress 2008

Business, government and law enforcement to discuss growing problems 24 Jan 2008

Job hunters exposed to ID theft

Too much information given out on CVs, warns iProfile 23 Oct 2008

Marketing firms routinely losing customer data

Security firms slam cavalier attitude 24 Jun 2008

related whitepapers

today's top stories

Solid as a rock - business continuity in a global manufacturer

From power supply problems in Nigeria to email availability in Stockport, PZ Cussons is prepared for anything 02 Dec 2008

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

IT staff desperate to keep their jobs

Most would work longer hours for less pay 02 Dec 2008

VMware View 3 enhances virtual desktops

Virtual clients now take up less storage space and can be 'checked out' to a laptop 02 Dec 2008

Technology and privacy

Watch part one of a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 01 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

Parcel being packedFeatures

Case study: eSpares and business continuity

Online electricals business has managed to decrease its downtime 02 Dec 2008

Royal Blackburn HospitalFeatures

NHS trust recovers from server overdose

Virtualisation technology breathed new life into East Lancashire's cost-intensive system 02 Dec 2008

Advertisement

Primary Navigation