The ICO reads my blog!

[Link updated as the ICO has moved its blog] On the 25th of April, I wrote GDPR: you're all getting it wrong. On the 9th of May, Steve Wood (the Deputy Commissioner) wrote this: https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2018/05/blog-raising-the-bar-consent-under-gdpr/ See? I may be a voice in the wilderness, but I'm not (always) wrong.

Meltdown, Spectre and other James Bond movie titles

Hoo boy. Here we go again. More silly codenames, more incomprehensible tech gobbledegook, more security flaws, more worry. What does it all mean? I’m not going to give a detailed technical explanation. The best one is here. The very very short version is that processor speeds have run ahead of memory speeds for some time, … Continue reading Meltdown, Spectre and other James Bond movie titles

It’s 2018 and we still can’t get basic things right

I wrote a blog entry five years ago, explaining why using security questions for password resets was a bad idea. (Why “improved” on-line security could compromise your bank account). It's still true, and we're still getting it wrong. Last week saw an American fined about £200k and sent to prison for nine months for hacking … Continue reading It’s 2018 and we still can’t get basic things right

What does it take?

I wasn't going to blog about Carphone Warehouse being fined £400k by the ICO for a breach, because boring-boring-you've-done-this-before, but then I couldn't help myself. Carphone's offence? A data breach. Resulting from poor maintenance of cyber security on an internet-facing webserver. You remember TalkTalk? They were fined £400,000 just over a year ago. For a … Continue reading What does it take?