Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Perimeter

7/18/2008
09:25 AM
50%
50%

Secret Defense Data Lost on UK Government USBs

Yet more government storage shenanigans on the other side of the pond

5:20 PM

By James Rogers, Byte and Switch

The U.K.’s Ministry of Defence (MoD) has admitted that 121 USB sticks, including five containing secret information, have been lost or stolen since 2004, in the British government’s latest embarrassing data breach .

The figures were released in response to an official question from Sarah Teather, a Liberal Democrat Member of Parliament, and are the latest in a string of British government data gaffes. The MoD’s missing USBs follow the loss of two disks containing welfare information on 25 million U.K. citizens, not to mention the loss of a bewildering array of laptops and mobile phones.

“Far from the problem getting better, it seems actually to be getting worse at the moment,” said Teather. “I think that the government has a duty to come clean and say whether or not anyone has been put at risk as a result of this – we need reassuring, for example, that none of our troops have been put at risk.”

The British government’s latest storage snafu comes less than a year after Her Majesty Revenue and Customs (HMRC), which is the U.K’s equivalent of the IRS was at the center of the country’s largest ever data loss.

The U.K.’s latest data loss heaps yet more pressure on Prime Minister Gordon Brown at a time when his government is pushing on with a controversial plan to implement national identity cards.

”The government are going ahead - to build this giant database for ID cards, and to put all this information into one format,” said Teather. “How can they expect us to trust them to keep our personal information safe in their unnecessary and expensive ID card scheme?”

The U.K., or course, is not the only country whose military secrets have been put at risk in a high-profile storage snafu.

Earlier this month, for example, Japan was left reeling from after the theft of a USB drive containing sensitive information on joint military exercises with the U.S. The country’s armed forces also hit the headlines in 2007 after sensitive information concerning the U.S.-built Aegis missile system was discovered on a serviceman’s home PC, resulting in an apology to U.S. defense secretary Robert Gates.

Sweden’s armed forces was also embarrassed earlier this year when a USB drive containing military secrets surfaced in a public library in Stockholm.

Last year, a survey revealed that almost three quarters of organizations house critical data on removable media despite numerous warnings about the security threats posed by the technology.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Byte and Switch's editors directly, send us a message.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
News
FluBot Malware's Rapid Spread May Soon Hit US Phones
Kelly Sheridan, Staff Editor, Dark Reading,  4/28/2021
Slideshows
7 Modern-Day Cybersecurity Realities
Steve Zurier, Contributing Writer,  4/30/2021
Commentary
How to Secure Employees' Home Wi-Fi Networks
Bert Kashyap, CEO and Co-Founder at SecureW2,  4/28/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-31828
PUBLISHED: 2021-05-06
An SSRF issue in Open Distro for Elasticsearch (ODFE) before 1.13.1.0 allows an existing privileged user to enumerate listening services or interact with configured resources via HTTP requests exceeding the Alerting plugin's intended scope.
CVE-2020-18888
PUBLISHED: 2021-05-06
Arbitrary File Deletion vulnerability in puppyCMS v5.1 allows remote malicious attackers to delete the file/folder via /admin/functions.php.
CVE-2020-18890
PUBLISHED: 2021-05-06
Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote malicious user getshell via /admin/functions.php.
CVE-2021-31793
PUBLISHED: 2021-05-06
An issue exists on NightOwl WDB-20-V2 WDB-20-V2_20190314 devices that allows an unauthenticated user to gain access to snapshots and video streams from the doorbell. The binary app offers a web server on port 80 that allows an unauthenticated user to take a snapshot from the doorbell camera via the ...
CVE-2021-31916
PUBLISHED: 2021-05-06
An out-of-bounds (OOB) memory write flaw was found in list_devices in drivers/md/dm-ioctl.c in the Multi-device driver module in the Linux kernel before 5.12. A bound check failure allows an attacker with special user (CAP_SYS_ADMIN) privilege to gain access to out-of-bounds memory leading to a syst...