This page permanently redirects to gemini://gemini.techrights.org/2023/07/16/gla-security-lapses/.
Gemini version available ♊︎
Posted in Deception, Free/Libre Software, Security at 6:49 pm by Dr. Roy Schestowitz
Summary: Data security and system security at Greater London Authority’s Web site haven’t been good; today we share just a couple of examples which help refute statements issued by Greater London Authority after a scandal that had made it to the mainstream media
MY! It really takes a liar to progress to management. The better the liar, the higher up the role.
As I mentioned the other day, there’s somewhat of a blunder since Friday when the news broke:
=> mentioned the other day | ↺ news broke
Image: London Mayor's Office data breach: Sexual abuse survivor 'appalled' as her personal details may have been accessible online
The following conspicuous statement is worth assessing, as I was working on the sites (various aspects, some microsites too) for 9 years.
Image: GLA security assurance
You would expect them to say that, wouldn’t you?
As I said on Saturday morning, this has deja vu written all over it.
to give one example (there are more):
Image: GLA: Google security alert
Image: GLA security issue
It wasn’t Sirius stuff (and certainly wasn’t me) who configured those terribly buggy forms.
Image: GLA: Drupal access
Image: GLA: Drupal permissions
As lying bosses at Sirius might say, “it doesn’t look good…”
It’s not the fault of Sirius either, at least not in this case.
The worst part of it is, as far as I’m aware GLA never publicly reported or disclosed this incident (sometimes this is legally required upon discovery or within a number of days, including informing those potentially affected, like people with their identity cards uploaded and widely available to the general public).
This isn’t the only such example.
2 years later even malicious scripts/programs could be uploaded. It was only detected after it had happened. Here are some fragments of old messages:
Image: GLA: can uploaded malware
Image: GLA: any file uploaded
This is a penalty for not scanning/sanitising uploads/input.
Why am I publishing these (redacted sensibly)? Because lying is wrong and privacy problems are the problem, speaking about them is not the problem. It is the moral thing to do — to point out it is a repeat offender so to speak. There is an obligation here to debunk false assurances, as this has gone on for years already. █
Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
Permalink > Image: Mail
Send this to a friend
=> Permalink | ↺ Send this to a friend
=> Techrights
➮ Sharing is caring. Content is available under CC-BY-SA.
text/gemini;lang=en-GB
This content has been proxied by September (3851b).