News: 1710502451

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Cop shop rapped for 'completely avoidable' web form blunder

(2024/03/15)


The London Mayor's Office for Policing and Crime is being rapped by regulators for untidy tech practices that made public the personal data of hundreds of people who filed complaints against the Metropolitan Police Service.

According to the Information Commissioner’s Office, MOPAC made a "completely avoidable" webform error that first took place 17 months ago, exposing information of close to 400 people that had submitted highly sensitive information.

MOPAC, which sets and oversees the strategic direction of the Met, had two forms on its website: one to lodge objections about how the Met had handled the complainant's original grievance; and the second was to contact the help group Victims Commissioner for London.

[1]

The London.gov.uk site is run by the Greater London Authority, which itself is in place to keep checks on the Mayor. Between November 11-14 2022, an unnamed employee of the GLA had meant to permit four colleagues access to data shared via the web forms but instead made both forms open to anyone on the internet.

[2]

[3]

It wasn't until February that MOPAC was informed of the blunder by a member of the public. Upon closer inspection, it realized that users could see "everything that had been submitted via web form, including name, address and reason for submitting compliant," said the ICO.

Due to the subject matter of the information exposed, MOPAC contacted the 394 people involved to let them know their "data had been made available in error," the regulator said. "However, there is no evidence that the data was ever accessed," it added.

[4]

Why the reprimand? MOPAC "acted professionally" throughout the investigation to tell the Met Police complainants about the screw-up. And MOPAC has since taken "remedial steps" including "awareness and training" around "permission forms."

Further recommendations around information governance and data protection training were uttered by the ICO to maintain compliance with the UK GDPR.

"This means highly personal and sensitive information could have been seen publicly," said Anthony Lehman, director for the regulator. "This was a completely avoidable error that has the potential to jeopardise public confidence in the criminal justice system."

[5]

He added: "I am satisfied this was an honest mistake and I'm pleased by the remedial steps taken by MOPAC since the breach, which include providing additional staff training to prevent any repeated incidents.

"However, it is important that public bodies learn from this incident. The public should be able to trust that their sensitive data will be treated with the utmost care, particularly when it comes to crime."

In a statement sent to The Register , a MOPAC spokesperson said:

“The Mayor’s Office for Policing and Crime (MOPAC) and the GLA accept the findings outlined by the Information Commissioner’s Office (ICO).

“Improved training and enhanced data security monitoring have been put in place to address the findings and provide effective mitigation for the security issue(s) which were identified.

“The GLA and MOPAC take the safety and security of www.london.gov.uk very seriously and sincerely regret any concern this issue may have caused.”

[6]UK biometrics boss bows out, bemoaning bureaucratic blunders

[7]Yet another UK public sector data blab, this time info of pregnant women, cancer patients

[8]Home of the world's longest pleasure pier joins public sector leak club

[9]Greater Manchester Police ransomware attack another classic demo of supply chain challenges

[10]Northern Irish cops release 2 men after Terrorism Act arrests linked to data breach

Cops' fingerprints have been all over data gaffes in recent times, whether that be for mixing up [11]two people's data with serious consequences, or [12]leaking data on their own officers , most notably - but not exclusively - in [13]Northern Ireland last year.

Forces in [14]Cumbria , [15]Norfolk, and Suffolk did the same thing of accidentally exposing their own officers' identities online too, but unlike Northern Ireland, those English counties don’t have the same level of sectarian tensions as are present across the Irish Sea. Both serving and recently retired officers in the region say they face continuing threat from paramilitaries, making the accidental publication in August 2023 of surnames and initials of serving officers and civilian staff members, plus a listing of officers' rank or grade, details on their location, and the department in which they work, that much more egregious. ®

Get our [16]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZfR@qrKKzWZPVXzUFf-NhgAAAEs&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZfR@qrKKzWZPVXzUFf-NhgAAAEs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZfR@qrKKzWZPVXzUFf-NhgAAAEs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZfR@qrKKzWZPVXzUFf-NhgAAAEs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZfR@qrKKzWZPVXzUFf-NhgAAAEs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2024/01/30/surveillance_commissioner_final_report/

[7] https://www.theregister.com/2023/12/07/losing_track_yet_yet_another/

[8] https://www.theregister.com/2023/11/06/southend_council_foi_leak/

[9] https://www.theregister.com/2023/09/15/greater_manchester_police_breach_demonstrates/

[10] https://www.theregister.com/2023/09/04/northern_irish_terrorism_arrests/

[11] https://www.theregister.com/2024/03/01/west_midlands_police_data_protection/

[12] https://www.theregister.com/2023/08/29/met_police_data_breach/

[13] https://www.theregister.com/2023/09/04/northern_irish_terrorism_arrests/

[14] https://www.theregister.com/2023/08/14/cumbrian_police_accidentally_published_officer_details_online/

[15] https://www.theregister.com/2023/08/15/norfolk_and_suffolk_police_data_breach/

[16] https://whitepapers.theregister.com/



Checking it twice

Flak

Surely this is exactly the kind of situation where, prior to a service going live or being changed, you would want to ensure there are no unintended consequences.

Re: Checking it twice

cyberdemon

For a complaints logging database? Nah, just use the lowest-bid contractor for that system that we've been forced to implement but don't actually want ...

We used to have a paper-based system called the cylindrical receptacle, but those scrotes in Whitehall said it wasn't sufficient

Why on Earth?

Mike 137

" ensure there are no unintended consequences "

It's much more basic than that. Why was internal access to the data expected to be via the public portal? Surely it's a fundamental that internal and external access are segregated? Or are we once again falling foul of the output of web devs who understand nothing about even basic security? I suspect that the general misunderstanding of "agile" has a lot to do with it, is it's commonly interpreted as "tinker without planning" so nobody actually designs anything -- they just implement on the fly until it "works" and release it.

Re: Why on Earth?

Handlebars

Probably an off the shelf forms product deployed by non technical staff.

Email submission

Bendacious

I see their "effective mitigation for the security issue" is to remove the online forms and instead ask people to email their complaints to ComplaintReviews@mopac.london.gov.uk. Fortunately emails are entirely secure in transit and storage. Plus, forwarding plain-text emails to the group, rather than making the group log in with 2FA to access encrypted database records with full auditing, is much more convenient.

Exposing complainants?

Yorick Hunt

Sounds like it was a design specification. "Want to complain about us? Well eff ewe!"

Re: Exposing complainants?

perkele

In the old days you'd complain about police, allegedly, and the secret report would suddenly not be secret through a nod and a wink and a lift of trousers...

And you might still fall down the stairs sometime in the future.

Doctor Syntax

"However, there is no evidence that the data was ever accessed,"

Absence of evidence is not evidence of absence. Is their any evidence that it wasn't accessed?

perkele

"Why the reprimand? MOPAC "acted professionally" throughout the investigation to tell the Met Police complainants about the screw-up. And MOPAC has since taken "remedial steps" including "awareness and training" around "permission forms.""

Would the Met Police accept that excuse, or even Khan's TFL, if you screw up and do a crime / drive in a wrong street and "act professionally" to deal with their complaint and then let you off? Doubt it.

No mention of people being sacked as if they are so incompetent how can they be left in post? Or be redirected to pick up dog shit/direct traffic as they're obviously not fit for first year CompSci-type jobs if that.

Nice boy, but about as sharp as a sack of wet mice.
-- Foghorn Leghorn