This page permanently redirects to gemini://gemini.techrights.org/2023/07/16/greater-london-authority-data-breach/.
Gemini version available ♊︎
Posted in Security at 12:08 am by Dr. Roy Schestowitz
But this time it became a blunder in the media:
Image: Sex abuse victim's details could be among hundreds revealed by data breach
Summary: Greater London Authority (GLA) does not know how to manage its Web site properly and it’s causing a lot of pain to victims of crimes; maybe it’s time for GLA to assess how it manages its Web site and how it treats victims of crimes, including its own tech staff
MANY are aware by now of GLA because of crimes at Sirius ‘Open Source’, a large GLA contractor. Typically I’d not open my mouth and led this one slide, but GLA does not care about its own IT workers being defrauded (and does not get the police, which it oversees, to actually do something about it), so I’ll say what I know for sure, with witnesses who saw the same.
=> crimes | Sirius ‘Open Source’
“This was noticed and mentioned internally.”
The above article speaks of a permission issue, which in effect enabled access to hostile parties and potentially did a lot of damage. They’ll probably try to paint this as a one-off incident, but I recall several other instances of this, especially with Drupal used incorrectly. Back then we had a chance to correct it before a breach or before unauthorised access was detected. This was noticed and mentioned internally. Back in the days of Mantis for ticketing, not JIRA bloatware.
“More incidents like the above may as well recur.”
What’s the cause of this? Well, it did not help that the company had people with no clue in computers dealing with computer-related tasks, including Sirius management with no suitable qualifications overseeing things. GLA fared not much better and their skilled IT people kept leaving. Maybe they couldn’t stand clueless managers, but maybe it was something else.
More incidents like the above may as well recur. This can continue to happen because of weakly-enforced rules and procedures. When I did deployments to the site I was typically all on my own, testing was limited, and there was no supervision by security-savvy site engineers. It was all very improvised. This won’t improve until or unless there are changes at the top. █
Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
Permalink > Image: Mail
Send this to a friend
=> Permalink | ↺ Send this to a friend
=> Techrights
➮ Sharing is caring. Content is available under CC-BY-SA.
text/gemini;lang=en-GB
This content has been proxied by September (ba2dc).