<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Large Biometric spill in UK in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Large-Biometric-spill-in-UK/m-p/26877#M3369</link>
    <description>I like the Guardian article better, but there still seem to be lots of questions to ask.&lt;BR /&gt;&lt;BR /&gt;A million people (maybe only a million UK citizens?) but more than 28 million&lt;BR /&gt;records?&lt;BR /&gt;&lt;BR /&gt;And, as Forbes points out, this is biometric data: you can't exactly change your&lt;BR /&gt;password. A fairly huge hit impacting the use of biometric data itself. With the&lt;BR /&gt;number of individuals affected by this, you start to get to the point that you have&lt;BR /&gt;to make alternative access control arrangements for a significant section of the&lt;BR /&gt;population ...&lt;BR /&gt;&lt;BR /&gt;And the irony that this was a company that provided security services to police,&lt;BR /&gt;defence agencies, and banks? Who watches the watchers who are watching the&lt;BR /&gt;watchers?&lt;BR /&gt;&lt;BR /&gt;(OK, in this case it seems to be research and possibly not a real breach, but still ...)&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org&lt;BR /&gt;If you want to keep a secret from me, put it inside a Facebook&lt;BR /&gt;event invitation.&lt;BR /&gt;- &lt;A href="https://twitter.com/brittanymooreok/status/567069226104786944" target="_blank"&gt;https://twitter.com/brittanymooreok/status/567069226104786944&lt;/A&gt;&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt;</description>
    <pubDate>Wed, 14 Aug 2019 19:26:02 GMT</pubDate>
    <dc:creator>rslade</dc:creator>
    <dc:date>2019-08-14T19:26:02Z</dc:date>
    <item>
      <title>Large Biometric spill in UK</title>
      <link>https://community.isc2.org/t5/Industry-News/Large-Biometric-spill-in-UK/m-p/26862#M3365</link>
      <description>&lt;P&gt;I'm sure the GDPR police will be all over &lt;A href="https://www.forbes.com/sites/zakdoffman/2019/08/14/new-data-breach-has-exposed-millions-of-fingerprint-and-facial-recognition-records-report/#e9e966046c60" target="_blank" rel="noopener"&gt;this&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interesting comment towards the bottom of the article is the establishment of a system that would lower the number of databases that would house your biometrics.&amp;nbsp; Maybe a digital medical record that also stores our biometrics and can only be accessed with our prior approval?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2019 13:52:58 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Large-Biometric-spill-in-UK/m-p/26862#M3365</guid>
      <dc:creator>Flyslinger2</dc:creator>
      <dc:date>2019-08-14T13:52:58Z</dc:date>
    </item>
    <item>
      <title>Re: Large Biometric spill in UK</title>
      <link>https://community.isc2.org/t5/Industry-News/Large-Biometric-spill-in-UK/m-p/26866#M3366</link>
      <description>&lt;P&gt;Well written article.&amp;nbsp; The best point mentioned, "we need some kind of unified platform where we limit the numbers of parties who actually hold such data, with others accessing those trusted holders on an “as a service” basis."&amp;nbsp; The notion of least privilege and access control never grow old.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2019 14:56:18 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Large-Biometric-spill-in-UK/m-p/26866#M3366</guid>
      <dc:creator>canLG0501</dc:creator>
      <dc:date>2019-08-14T14:56:18Z</dc:date>
    </item>
    <item>
      <title>Re: Large Biometric spill in UK</title>
      <link>https://community.isc2.org/t5/Industry-News/Large-Biometric-spill-in-UK/m-p/26877#M3369</link>
      <description>I like the Guardian article better, but there still seem to be lots of questions to ask.&lt;BR /&gt;&lt;BR /&gt;A million people (maybe only a million UK citizens?) but more than 28 million&lt;BR /&gt;records?&lt;BR /&gt;&lt;BR /&gt;And, as Forbes points out, this is biometric data: you can't exactly change your&lt;BR /&gt;password. A fairly huge hit impacting the use of biometric data itself. With the&lt;BR /&gt;number of individuals affected by this, you start to get to the point that you have&lt;BR /&gt;to make alternative access control arrangements for a significant section of the&lt;BR /&gt;population ...&lt;BR /&gt;&lt;BR /&gt;And the irony that this was a company that provided security services to police,&lt;BR /&gt;defence agencies, and banks? Who watches the watchers who are watching the&lt;BR /&gt;watchers?&lt;BR /&gt;&lt;BR /&gt;(OK, in this case it seems to be research and possibly not a real breach, but still ...)&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org&lt;BR /&gt;If you want to keep a secret from me, put it inside a Facebook&lt;BR /&gt;event invitation.&lt;BR /&gt;- &lt;A href="https://twitter.com/brittanymooreok/status/567069226104786944" target="_blank"&gt;https://twitter.com/brittanymooreok/status/567069226104786944&lt;/A&gt;&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt;</description>
      <pubDate>Wed, 14 Aug 2019 19:26:02 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Large-Biometric-spill-in-UK/m-p/26877#M3369</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-08-14T19:26:02Z</dc:date>
    </item>
    <item>
      <title>Re: Large Biometric spill in UK</title>
      <link>https://community.isc2.org/t5/Industry-News/Large-Biometric-spill-in-UK/m-p/26881#M3370</link>
      <description>&lt;P&gt;Looks like it goes back to the fundamentals as Ross Anderson famously stated to a Select Committee in the UK:&amp;nbsp; &lt;A href="https://publications.parliament.uk/pa/cm201314/cmselect/cmhaff/70/7004.htm" target="_blank"&gt;https://publications.parliament.uk/pa/cm201314/cmselect/cmhaff/70/7004.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"The &lt;STRONG&gt;only way to ensure data does&lt;/STRONG&gt; not &lt;STRONG&gt;leak is not t&lt;/STRONG&gt;o collect it."&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Seems there is a great need for a Trust Network - but exactly who do you trust?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2019 20:17:57 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Large-Biometric-spill-in-UK/m-p/26881#M3370</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2019-08-14T20:17:57Z</dc:date>
    </item>
  </channel>
</rss>

