Live data from Hacker News

LulzSec supposedly claims its biggest coup yet: The entire UK 2011 Census

thenextweb.com

41–50 of 156 posts

Re: LulzSec supposedly claims its biggest coup yet: The entire UK 2011 Census

#41
post #14

They're going to piss a lot of people off if they do this. Like every single UK citizen. Exposing security flaws and embarrassing govt is one thing, but to put un-redacted personal data online is quite another.

If this is true (and it seems it's probably not) then the people to get angry with are the UK government and their contractors Lockheed-Martin. WTF are we using a US-based company for anyway?

Re: LulzSec supposedly claims its biggest coup yet: The entire UK 2011 Census

#42
post #20
post #8

If this is true then I am suing Lockheed Martin under the Data Protection Act.

There's jurisdiction for that?

Why would jurisdiction enter into someone in the UK suing the company that processed the UK census data? Thier data. I don't know if antihero is in the UK, but if they aren't, people in the UK should do it instead. I am disturbed that my data could leak like this.

Re: LulzSec supposedly claims its biggest coup yet: The entire UK 2011 Census

#43
post #41
post #14

They're going to piss a lot of people off if they do this. Like every single UK citizen. Exposing security flaws and embarrassing govt is one thing, but to put un-redacted personal data online is quite another.

If this is true (and it seems it's probably not) then the people to get angry with are the UK government and their contractors Lockheed-Martin. WTF are we using a US-based company for anyway?

Presumably they put it out for tender and got the best package that they could.

Isn't that what we'd expect a Government to do? Tender jobs out to the private sector and choose the provider that offers the best value for money?

It's not as if Lockheed Martin are a particularly insecure or untrustworthy company to hold private data.

Re: LulzSec supposedly claims its biggest coup yet: The entire UK 2011 Census

#44
post #20

Earlier quoted context omitted.

There's jurisdiction for that?

If their servers have been compromised to leak the data, should be. They ran the survey and UK and European data protection law makes data leaks the responsibility of the data holder.

They were one of the first companies to admit that the RSA SecurID exploit compromised them over the past months, too.

Link to story: http://www.networkworld.com/news/2011/052611-lockheed-martin...

Re: LulzSec supposedly claims its biggest coup yet: The entire UK 2011 Census

#45
post #19

I don't like where this is going.

Whats worrying about the apparent proliferation of security breaches like this is that as the attacks get more sophisticated, so do the prevention methods. This could get to the point whereby the skill level required to protect an application or server goes way higher than the skill level of many developers. The result being that independent development is impossible as you would need to hire ever more expensive secu…

More likely that common development tools and frameworks will become much more intrinsically security conscious.

Re: LulzSec supposedly claims its biggest coup yet: The entire UK 2011 Census

#46
post #19

I don't like where this is going.

Whats worrying about the apparent proliferation of security breaches like this is that as the attacks get more sophisticated, so do the prevention methods. This could get to the point whereby the skill level required to protect an application or server goes way higher than the skill level of many developers. The result being that independent development is impossible as you would need to hire ever more expensive secu…

I understand your point (it is potentially true for more than just the security domain of application development) but I think your premise in this case is false. SQLI (XSS, CSRF, ...) attacks are neither sophisticated nor new. SQLI has been known since at least 1998 (Phrack 54).

SQLI protection at least should be abstracted away from the developer's concerns by use of default parametrized queries. Technical difficulty is not the problem here.

Re: LulzSec supposedly claims its biggest coup yet: The entire UK 2011 Census

#47

So what's the worst possible outcome here in terms of the UK government's reactions? Fast-tracked arcane legislation to make security tools illegal like they are in .de ? Broadening the terms of hacking and increasing the legal penalties? If LulzSec aren't trolling the world and they do indeed have these records I would imagine there is going to be one hell of a shitstorm in the coming weeks.

It would be just another excuse to get the Internet ID implemented. MAFIAA has been pushing for Internet ID since years now and a number of politicians are in favour. Must admit that every time I read about the latest Lulsec activity I cannot help but think that MAFIAA is behind all this.

I'd say the opposite will happen. The government will not be able to set up anything which requires a massive secure database for quite a few years. Every time they claim they can set up a secure database, the 2011 census leak will be brought up.

Re: LulzSec supposedly claims its biggest coup yet: The entire UK 2011 Census

#48
post #21
post #9

If true, this will be a massive coup and regardless of how they obtained the records, LulzSec will get all of the significant negative attention they so badly crave. I submitted my census info via the online form and given the amount of detail I included I would be terrified if that info was leaked.

Imagining that the release is true, this will do strange things for pay bargaining. Imagine if you could look up your colleagues before asking for a rise? On the other hand, I don't recall anything really horrific on that form. Enough data to steal my identity and take out a mortgage in my name, yes. Enough to embarrass me? no...

I don't remember salary being requested on the UK census...

Re: LulzSec supposedly claims its biggest coup yet: The entire UK 2011 Census

#50

So what's the worst possible outcome here in terms of the UK government's reactions? Fast-tracked arcane legislation to make security tools illegal like they are in .de ? Broadening the terms of hacking and increasing the legal penalties? If LulzSec aren't trolling the world and they do indeed have these records I would imagine there is going to be one hell of a shitstorm in the coming weeks.

It would be just another excuse to get the Internet ID implemented. MAFIAA has been pushing for Internet ID since years now and a number of politicians are in favour. Must admit that every time I read about the latest Lulsec activity I cannot help but think that MAFIAA is behind all this.

If they will implement the Internet ID in the same way as they implement their current security (assuming the leak is real), then there is no need to worry...
Post reply on HN