<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>schestowitz.com &#187; Security</title>
	<atom:link href="https://schestowitz.com/Weblog/archives/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>https://schestowitz.com/Weblog</link>
	<description>Reflections on Technology</description>
	<lastBuildDate>Thu, 24 Sep 2026 05:57:14 +0000</lastBuildDate>
	<language>en-US</language>
		<sy:updatePeriod>hourly</sy:updatePeriod>
		<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=3.9.40</generator>
	<item>
		<title>Matthew J Garrett Put secure-boot and shim in Linux and It&#8217;s Breaking Systems Again</title>
		<link>https://schestowitz.com/Weblog/archives/2026/09/12/matthew-j-garrett-put-secure-boot-and-shim-in-linux-and-its-breaking-systems-again/</link>
		<comments>https://schestowitz.com/Weblog/archives/2026/09/12/matthew-j-garrett-put-secure-boot-and-shim-in-linux-and-its-breaking-systems-again/#comments</comments>
		<pubDate>Sat, 12 Sep 2026 16:08:23 +0000</pubDate>
		<dc:creator><![CDATA[Roy Schestowitz]]></dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">https://schestowitz.com/Weblog/?p=9513</guid>
		<description><![CDATA[Crossposted from Techrights Fake security is already breaking systems running GNU/Linux ore complexity means more problems. Newer code means more bugs (e.g. Rust rewrites). Fake security means catastrophe for no actual gain/s. As noted by several sites [1, 2], linking to a bug report, kneeling to Microsoft came at a high cost: TPM? Who asked [&#8230;]]]></description>
				<content:encoded><![CDATA[<p><em><a href="https://techrights.org/n/2026/09/12/Canonical_Has_Withdrawn_Ubuntu_24_04_5_Installer_Due_to_a_Criti.shtml">Crossposted from Techrights</a></em></p>
<p><em><a href="https://techrights.org/wiki/UEFI/">Fake security</a> is already breaking systems running GNU/Linux</em></p>
<p><a href="https://schestowitz.com/Weblog/wp-content/uploads/2026/09/ubuntu-secure-boot.png"><img src="https://schestowitz.com/Weblog/wp-content/uploads/2026/09/ubuntu-secure-boot.png" alt="Ubuntu secure boot" width="520" class="aligncenter size-full wp-image-9514" /></a></p>
<p><img title="M" src="/IMG/Caps/m.png" alt="M" align="left" border="0" hspace="0" vspace="4" />ore complexity means more problems. Newer code means more bugs (e.g. Rust rewrites).</p>
<p>Fake security means catastrophe for no actual gain/s.</p>
<p>As noted by several sites [<a href="https://www.omgubuntu.co.uk/2026/09/ubuntu-pulls-24-04-5-download">1</a>, <a href="https://www.xda-developers.com/canonical-has-pulled-ubuntu-24045s-installer-because-it-blew-up-when-you-tried-an-extended-install/">2</a>], linking to a <a href="https://bugs.launchpad.net/ubuntu/+source/livecd-rootfs/+bug/2167127">bug report</a>, kneeling to Microsoft came at a high cost:</p>
<p><a href="https://schestowitz.com/Weblog/wp-content/uploads/2026/09/tpm-bs.png"><img src="https://schestowitz.com/Weblog/wp-content/uploads/2026/09/tpm-bs.png" alt="enhanced-secure-boot" width="520"  class="aligncenter size-full wp-image-9515" /></a></p>
<p>TPM? Who asked for TPM in Linux? GAFAM? But <a href="https://techrights.org/n/2026/03/11/An_American_War_on_GNU_Linux_Software_Freedom_and_British_Inves.shtml">who am I to even mention the principal culprits</a>? I have degrees in computing, not in genetics. </p>
]]></content:encoded>
			<wfw:commentRss>https://schestowitz.com/Weblog/archives/2026/09/12/matthew-j-garrett-put-secure-boot-and-shim-in-linux-and-its-breaking-systems-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Near the Action at the Stadium</title>
		<link>https://schestowitz.com/Weblog/archives/2026/09/05/near-the-action-at-the-stadium/</link>
		<comments>https://schestowitz.com/Weblog/archives/2026/09/05/near-the-action-at-the-stadium/#comments</comments>
		<pubDate>Sat, 05 Sep 2026 13:34:48 +0000</pubDate>
		<dc:creator><![CDATA[Roy Schestowitz]]></dc:creator>
				<category><![CDATA[Raves]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Sport]]></category>

		<guid isPermaLink="false">https://schestowitz.com/Weblog/?p=9366</guid>
		<description><![CDATA[A perk of living next to major facilities of non-military nature (datacentres [1, 2] are used for military) think I neglected to mention a sort of &#8220;uptime privilege&#8221; this morning. I realised this only later. It&#8217;s a kind of an &#8220;RK&#8221; privilege one can forget about. You take this for granted when you&#8217;re next to [&#8230;]]]></description>
				<content:encoded><![CDATA[<p><em>A perk of living next to major facilities of non-military <b>nature</b> (datacentres [<a href="https://schestowitz.com/Weblog/archives/2026/08/06/map-of-data-centres-in-greater-manchester/">1</a>, <a href="https://schestowitz.com/Weblog/archives/2026/09/04/more-foodfarms-less-datacentres/">2</a>] are used for military)</em></p>
<p><a href="https://schestowitz.com/Weblog/wp-content/uploads/2026/09/haaland.png"><img src="https://schestowitz.com/Weblog/wp-content/uploads/2026/09/haaland.png" alt="Arrivals...." width="520" class="aligncenter size-full wp-image-9367" /></a></p>
<p><img title="I" src="/IMG/Caps/i.png" alt="I" align="left" border="0" hspace="0" vspace="4" /> think I neglected to mention a sort of <em>&#8220;uptime privilege&#8221;</em> <a href="https://techrights.org/n/2026/09/05/You_Can_Run_GNU_Linux_on_a_Desktop_Laptop_for_1_000_Days_Nonsto.shtml">this morning</a>. I realised this only later. It&#8217;s a kind of an &#8220;RK&#8221; privilege one can forget about. You take this for granted when you&#8217;re next to <a href="https://www.mancity.com/matchday/fixtures/mens/2026/premier-league/man-city-v-coventry-5-sept-2026?page=Commentary">international games or actions</a>.</p>
<p>My computers have high uptime records owing to good electricity infrastructure (reliability/uptime/availability); we have a sort of fortune or the mere luck of having very reliable electric grid (near a very large and famous stadium) with persistent connections and decent hardware nearby, fallbacks included, with no natural disasters, not even floods  (we&#8217;re in a slope).</p>
<p>In some parts of the world they have extreme weather this year, including prohibitive costs of living (UK minimum wage a lot higher than the average in Europe), war, conscription, and worse. Here, unlike Ukraine, no shelter time (or risk of being hit by missiles), is expected, so carrying on as usual is almost always possible. Until someone from <a href="https://techrights.org/litigation.shtml">another continent pays $130,000 to drag you down to London</a>. But even then, your computers remain turned on at home.</p>
]]></content:encoded>
			<wfw:commentRss>https://schestowitz.com/Weblog/archives/2026/09/05/near-the-action-at-the-stadium/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Manchester Airport Data Breach</title>
		<link>https://schestowitz.com/Weblog/archives/2026/09/01/manchester-airport-data-breach/</link>
		<comments>https://schestowitz.com/Weblog/archives/2026/09/01/manchester-airport-data-breach/#comments</comments>
		<pubDate>Tue, 01 Sep 2026 20:31:56 +0000</pubDate>
		<dc:creator><![CDATA[Roy Schestowitz]]></dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">https://schestowitz.com/Weblog/?p=9286</guid>
		<description><![CDATA[The data can be used to defraud (e.g. impersonate) people who flew to and from Manchester Airport. Worse yet, it can potentially be leveraged for blackmail. roups of tourists have gathered for the holiday around here, maybe anticipating the start of the football season. They&#8217;re typically quiet and polite people from Europe or east Asia. [&#8230;]]]></description>
				<content:encoded><![CDATA[<p><em>The data <u>can</u> be used to defraud (e.g. impersonate) people who flew to and from Manchester Airport. <b>Worse yet</b>, it can potentially be leveraged for blackmail.</em></p>
<p><img title="G" src="/IMG/Caps/g.png" alt="G" align="left" border="0" hspace="0" vspace="4" />roups of tourists have gathered for the holiday around here, maybe anticipating the start of the football season. They&#8217;re typically quiet and polite people from Europe or east Asia. They choose to come to Manchester, not London, or sometimes both. They shop, stay overnight, and eventually leave to go back home.</p>
<p>Recently there was a data breach in Manchester Airport. Airports keep a lot of personal information about the people who fly and fliers cannot opt out because nobody can board a plane anonymously.</p>
<p>I certainly hope the computer systems at Manchester Airport were properly partitioned and did not use Windows. Every version of Windows has back doors and is a ransomware magnet.</p>
]]></content:encoded>
			<wfw:commentRss>https://schestowitz.com/Weblog/archives/2026/09/01/manchester-airport-data-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8220;DDoS&#8221; is a Very Broad Term</title>
		<link>https://schestowitz.com/Weblog/archives/2026/09/01/ddos-is-a-very-broad-term/</link>
		<comments>https://schestowitz.com/Weblog/archives/2026/09/01/ddos-is-a-very-broad-term/#comments</comments>
		<pubDate>Tue, 01 Sep 2026 14:12:10 +0000</pubDate>
		<dc:creator><![CDATA[Roy Schestowitz]]></dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Web-based]]></category>

		<guid isPermaLink="false">https://schestowitz.com/Weblog/?p=9280</guid>
		<description><![CDATA[To each its own etting a solution to DDoS attacks is not easy because each time the pattern to tackle (without false positives) is a bit different and each incident can be unprecedented in one single site, so there&#8217;s no one-size-fits-all solution. At the moment we combat another wave of nuisance bots and each time [&#8230;]]]></description>
				<content:encoded><![CDATA[<p><em>To each its own</em></p>
<p><img title="G" src="/IMG/Caps/g.png" alt="G" align="left" border="0" hspace="0" vspace="4" />etting a solution to DDoS attacks is not easy because each time the pattern to tackle (without false positives) is a bit different and each incident can be unprecedented in one single site, so there&#8217;s no one-size-fits-all solution.</p>
<p>At the moment we combat another wave of nuisance bots and each time it comes there&#8217;s risk that everyone will be &#8220;away from keyboard&#8221; and therefore it won&#8217;t be detected.</p>
]]></content:encoded>
			<wfw:commentRss>https://schestowitz.com/Weblog/archives/2026/09/01/ddos-is-a-very-broad-term/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyber Attacks and More</title>
		<link>https://schestowitz.com/Weblog/archives/2026/07/02/cyber-attacks-and-more/</link>
		<comments>https://schestowitz.com/Weblog/archives/2026/07/02/cyber-attacks-and-more/#comments</comments>
		<pubDate>Thu, 02 Jul 2026 05:26:38 +0000</pubDate>
		<dc:creator><![CDATA[Roy Schestowitz]]></dc:creator>
				<category><![CDATA[Cyberspace]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">https://schestowitz.com/Weblog/?p=8447</guid>
		<description><![CDATA[here are cyber attacks against our Web sites this week. These attacks take several different forms. These are clearly censorship attempts. We have paper trail to prove that. Any attacks &#8211; no matter their form &#8211; tend to indicate fear. In this case, the fear is that information that we published will be available and [&#8230;]]]></description>
				<content:encoded><![CDATA[<p><a href="https://schestowitz.com/Weblog/wp-content/uploads/2026/07/wormwood-meteor-of-revelation.jpg"><img src="https://schestowitz.com/Weblog/wp-content/uploads/2026/07/wormwood-meteor-of-revelation.jpg" alt="Wormwood Meteor Of Revelation" width="520" class="aligncenter size-full wp-image-8448" /></a></p>
<p><img title="T" src="/IMG/Caps/t.png" alt="T" align="left" border="0" hspace="0" vspace="4" />here are cyber attacks against our Web sites this week. These attacks take <u>several different forms</u>. These are clearly censorship attempts. We have paper trail to prove that.</p>
<p>Any attacks &#8211; no matter their form &#8211; tend to indicate fear. In this case, the fear is that information that we published will be available and remain available for many years to come.</p>
<p>Sustaining attacks is one thing; reporting them is another. What&#8217;s happening is illegal. It will be treated as such.</p>
<p>We&#8217;ll carry on publishing as usual. Curtailing access to information is never a winning strategy for all sorts of reasons. </p>
]]></content:encoded>
			<wfw:commentRss>https://schestowitz.com/Weblog/archives/2026/07/02/cyber-attacks-and-more/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DDoS Attacks: Tux Machines and Techrights Impacted</title>
		<link>https://schestowitz.com/Weblog/archives/2026/06/24/ddos-attacks-again/</link>
		<comments>https://schestowitz.com/Weblog/archives/2026/06/24/ddos-attacks-again/#comments</comments>
		<pubDate>Wed, 24 Jun 2026 21:27:41 +0000</pubDate>
		<dc:creator><![CDATA[Roy Schestowitz]]></dc:creator>
				<category><![CDATA[Cyberspace]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">https://schestowitz.com/Weblog/?p=8426</guid>
		<description><![CDATA[AM not sure who is doing this and why, but the server of Tux Machines is under DDoS attack. It impacts Techrights as well. I wrote about this back in April when it began, then again ~3 weeks later. The Web is so chaotic on so many levels. CDNs are not the solution. Access gatekeeping [&#8230;]]]></description>
				<content:encoded><![CDATA[<p><img title="I" src="/IMG/Caps/i.png" alt="I" align="left" border="0" hspace="0" vspace="4" /> AM not sure who is doing this and why, but the server of <em>Tux Machines</em> is under DDoS attack. It impacts <em>Techrights</em> as well. I wrote about this <a href="http://techrights.org/n/2026/04/30/Then_Come_the_DDoS_Attacks.shtml">back in April when it began</a>, then again <a href="http://news.tuxmachines.org/n/2026/05/21/Tux_Machines_Subjected_to_Cyberattacks.shtml">~3 weeks later</a>.</p>
<p>The Web is so chaotic on so many levels.</p>
<p>CDNs are not the solution. Access gatekeeping with JS is not the solution either, it&#8217;s another new problem.</p>
]]></content:encoded>
			<wfw:commentRss>https://schestowitz.com/Weblog/archives/2026/06/24/ddos-attacks-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>You Can Hate Donald Trump and Object to Electronic Voting Machines at the Same Time</title>
		<link>https://schestowitz.com/Weblog/archives/2023/12/01/schismogenesis/</link>
		<comments>https://schestowitz.com/Weblog/archives/2023/12/01/schismogenesis/#comments</comments>
		<pubDate>Fri, 01 Dec 2023 03:36:19 +0000</pubDate>
		<dc:creator><![CDATA[Roy Schestowitz]]></dc:creator>
				<category><![CDATA[Politics]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">https://schestowitz.com/Weblog/?p=8067</guid>
		<description><![CDATA[Schismogenesis in Bill Gated-funded sites (those machines run Windows with back doors): NEED to clarify upfront I do not believe the 2020 election in the United States was &#8220;stolen&#8221; and I do not support Donald Trump. He disgusts me. The United States is still &#8220;using fraudulent voting machines&#8221; with back doors, a friend has reminded [&#8230;]]]></description>
				<content:encoded><![CDATA[<p><a href="https://en.wikipedia.org/wiki/Schismogenesis">Schismogenesis</a> in <a href="https://www.theguardian.com/us-news/2023/nov/29/arizona-officials-charged-election-2022">Bill Gated-funded sites</a> (those machines run Windows with back doors): </p>
<p><a href="https://schestowitz.com/Weblog/wp-content/uploads/2023/12/straw-man.png"><img src="https://schestowitz.com/Weblog/wp-content/uploads/2023/12/straw-man.png" alt="Schismogenesis" width="520" class="aligncenter size-full wp-image-8068" /></a></p>
<p><img title="I" src="/IMG/Caps/i.png" alt="I" align="left" border="0" hspace="0" vspace="4" /> NEED to clarify upfront I do not believe the 2020 election in the United States was &#8220;stolen&#8221; and I do not support Donald Trump. He disgusts me.</p>
<p>The United States is still &#8220;using fraudulent voting machines&#8221; <a href="http://techrights.org/wiki/Microsoft_and_the_NSA/">with back doors</a>, a friend has reminded me. But the media giants aren&#8217;t talking about and &#8220;associating opposition to fraudulent voting technologies/products with crazies. Other crazies will defend fraudulent voting technologies/products for no other reason than those two crazies are opposed to them&#8230;&#8221;</p>
<p><em>Techrights</em> did at least 2 &#8220;statements&#8221; on this issue [<a href="http://techrights.org/o/2022/10/27/calling-everyone-nazis/">1</a>, <a href="http://techrights.org/o/2023/04/19/fox-news-straw-man/">2</a>] just to clarify voting machines are no good regardless of news sites&#8217; rhetoric.</p>
<p>Quit using opaque electronic voting machines and then lessen the likilohood of armed fanatics storming government buildings in an act of overt insurrection.</p>
]]></content:encoded>
			<wfw:commentRss>https://schestowitz.com/Weblog/archives/2023/12/01/schismogenesis/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Needs to Disappear</title>
		<link>https://schestowitz.com/Weblog/archives/2023/11/28/windows-needs-to-disappear/</link>
		<comments>https://schestowitz.com/Weblog/archives/2023/11/28/windows-needs-to-disappear/#comments</comments>
		<pubDate>Tue, 28 Nov 2023 01:57:15 +0000</pubDate>
		<dc:creator><![CDATA[Roy Schestowitz]]></dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">https://schestowitz.com/Weblog/?p=8054</guid>
		<description><![CDATA[recently wrote about security crises associated with Windows deployments. &#8220;On the topic of Windows,&#8221; a friend told me (citing this one article): &#8220;The writers there (and elsewhere) conflate spending with results. Security is part of the design and not an aftermarket add-on. The latter is a pointless and futile waste of time and money, but [&#8230;]]]></description>
				<content:encoded><![CDATA[<p><img title="I" src="/IMG/Caps/i.png" alt="I" align="left" border="0" hspace="0" vspace="4" /> recently wrote about <a href="https://news.tuxmachines.org/n/2023/11/27/Data_Breaches_and_Windows_TCO.shtml">security crises</a> associated with Windows deployments. &#8220;On the topic of Windows,&#8221; a friend told me (citing <a href="https://www.politico.eu/article/energy-power-europe-grid-is-under-a-cyberattack-deluge-industry-warns/">this one article</a>): &#8220;The writers there (and elsewhere) conflate spending with results.  Security is part of the design and not an aftermarket add-on.  The latter is a pointless and futile waste of time and money, but one which keeps Microsoft market share from bottoming out. [...] the Microsoft way of thinking permeates their design *and* implementation *and* especially their deployment.&#8221;</p>
<p>I still firmly believe that removing most Windows installations out there (ultimately all of them) would considerably improve computer security worldwide. <a href="http://techrights.org/wiki/Microsoft_and_the_NSA/">Microsoft designs things not for security but the very opposite (remote access by the state)</a>. <a href="#top">?</a></p>
]]></content:encoded>
			<wfw:commentRss>https://schestowitz.com/Weblog/archives/2023/11/28/windows-needs-to-disappear/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Forms for Reporting Data Breaches Exist to be Used and for Those Affected to Get Notified</title>
		<link>https://schestowitz.com/Weblog/archives/2023/07/19/forms-for-reporting-data-breaches/</link>
		<comments>https://schestowitz.com/Weblog/archives/2023/07/19/forms-for-reporting-data-breaches/#comments</comments>
		<pubDate>Wed, 19 Jul 2023 05:32:56 +0000</pubDate>
		<dc:creator><![CDATA[Roy Schestowitz]]></dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">https://schestowitz.com/Weblog/?p=7957</guid>
		<description><![CDATA[Summary: One last note on the issue of Greater London Authority (London Municipality); even though forms exist to report security breaches or incidents of data breaches, Greater London Authority never seems to have bothered with this; the culmination of this in the media (a scandal which puts at risk victims of sex crimes) overlooks a [&#8230;]]]></description>
				<content:encoded><![CDATA[<p><em><b>Summary</b>: One last note on the issue of Greater London Authority (London Municipality); even though forms exist to report security breaches or incidents of data breaches, Greater London Authority never seems to have bothered with this; the culmination of this in the media (a scandal which puts at risk victims of sex crimes) overlooks a history of repeat/recurring incidents</em></p>
<p>As far as I&#8217;m aware, this was never reported (to those impacted) except <em>internally</em>.</p>
<p>GLA staff (it wasn&#8217;t the first such issue, nor the last):</p>
<p align="center">
<a href="http://techrights.org/wp-content/uploads/2023/07/drupal-access.png"><img src="http://techrights.org/wp-content/uploads/2023/07/drupal-access.png" alt="GLA: Drupal access" width="480" class="aligncenter size-full wp-image-176671" /></a>
</p>
<p>So what good are such forms?</p>
<p><a href="http://techrights.org/wp-content/uploads/2023/07/gla-form-data-breach-1.png"><img src="http://techrights.org/wp-content/uploads/2023/07/gla-form-data-breach-1.png" alt="GLA form for data breach #1" width="480" class="aligncenter size-full wp-image-176831" /></a></p>
<p><a href="http://techrights.org/wp-content/uploads/2023/07/gla-form-data-breach-2.png"><img src="http://techrights.org/wp-content/uploads/2023/07/gla-form-data-breach-2.png" alt="GLA form for data breach #2" width="480" class="aligncenter size-full wp-image-176832" /></a></p>
]]></content:encoded>
			<wfw:commentRss>https://schestowitz.com/Weblog/archives/2023/07/19/forms-for-reporting-data-breaches/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Greater London Authority Fails to Meet GDPR Rules</title>
		<link>https://schestowitz.com/Weblog/archives/2023/07/17/greater-london-authority-gdpr/</link>
		<comments>https://schestowitz.com/Weblog/archives/2023/07/17/greater-london-authority-gdpr/#comments</comments>
		<pubDate>Mon, 17 Jul 2023 11:44:41 +0000</pubDate>
		<dc:creator><![CDATA[Roy Schestowitz]]></dc:creator>
				<category><![CDATA[Politics]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">https://schestowitz.com/Weblog/?p=7955</guid>
		<description><![CDATA[Data breaches&#8217; handling policies/stance of GLA were not followed when I was there. Here they are in their own words: Meanwhile in the news: Also this past weekend: Summary: This past weekend Greater London Authority’s managers came under fire for mishandling of data (this went on for months!) and it wasn&#8217;t even the first time; [&#8230;]]]></description>
				<content:encoded><![CDATA[<p><a href="https://www.london.gov.uk/who-we-are/what-london-assembly-does/questions-mayor/find-an-answer/data-breaches-0" title="Data breaches">Data breaches&#8217; handling policies/stance of GLA</a> were not followed when I was there. Here they are in their <em>own</em> words:</p>
<p align="center">
 <a href="http://techrights.org/wp-content/uploads/2023/07/gdpr-gla.png"><img src="http://techrights.org/wp-content/uploads/2023/07/gdpr-gla.png" alt="GDPR, GLA, and Data Breaches" width="480" class="aligncenter size-full wp-image-176724" /></a>
</p>
<p> Meanwhile <a href="https://www.standard.co.uk/news/london/mopac-personal-data-breach-mayor-office-policing-crime-met-complaints-b1094424.html" title="Evening Standard: Complaints to Sadiq Khan’s Met police watchdog on public view in ‘data breach’">in the news</a>:</p>
<p align="center">
<a href="http://techrights.org/wp-content/uploads/2023/07/gla-data-scandal.png"><img src="http://techrights.org/wp-content/uploads/2023/07/gla-data-scandal.png" alt="Complaints to Sadiq Khan’s Met police watchdog on public view in ‘data breach’" width="480" class="aligncenter size-full wp-image-176725" /></a>
</p>
<p>Also <a href="https://metro.co.uk/2023/07/15/sexual-abuse-survivor-appalled-after-details-leaked-in-data-breach-19133690/" title="Sexual abuse survivor ‘appalled’ after personal details leaked in data breach">this past weekend</a>:</p>
<p align="center">
<a href="http://techrights.org/wp-content/uploads/2023/07/metro-gla.png"><img src="http://techrights.org/wp-content/uploads/2023/07/metro-gla.png" alt="Metro: Sexual abuse survivor ‘appalled’ after personal details leaked in data breach" width="480" class="aligncenter size-full wp-image-176726" /></a>
</p>
<p><em><b>Summary</b>: This past weekend Greater London Authority’s managers came under fire for mishandling of data (this went on for months!) and it wasn&#8217;t even the first time; usually they keep quiet about such things and hope nobody will notice while IT people &#8212; including <a href="http://techrights.org/wiki/Sirius_Open_Source" title="Sirius Open Source">Sirius &#8216;Open Source&#8217;</a> &#8212; are retroactively &#8216;fixing&#8217; these issues</em></p>
]]></content:encoded>
			<wfw:commentRss>https://schestowitz.com/Weblog/archives/2023/07/17/greater-london-authority-gdpr/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
