{"id":3705,"date":"2020-05-07T06:08:51","date_gmt":"2020-05-07T06:08:51","guid":{"rendered":"https:\/\/crbdirect.org.uk\/?p=3705"},"modified":"2021-03-18T13:17:07","modified_gmt":"2021-03-18T13:17:07","slug":"concern-over-security-flaws-on-government-websites","status":"publish","type":"post","link":"https:\/\/crbdirect.org.uk\/concern-over-security-flaws-on-government-websites\/","title":{"rendered":"Concern over Security Flaws on Government Websites"},"content":{"rendered":"<p>According to an investigation by <a href=\"https:\/\/crbdirect.org.uk\/new-face-recognition-for-uber-drivers\/\">leading technology<\/a> publication New Scientist, a large number of government websites have serious security issues which could put you at risk. The government operates over 3000 different websites under the gov.uk domain name, covering everything from central government departments to smaller district council websites. A team of security experts looked at the government websites and found that 524 have serious flaws which could allow hackers to get into the website and \u201chijack\u201d it.<\/p>\n<p>&nbsp;<\/p>\n<h2>Digital Delivery<\/h2>\n<p>In the past few years, the government has been shifting many previously paper-based systems online. Disclosure and Barring checks, tax credits, Universal Credit, car tax, passports \u2013 all are now online. One of the few government websites which was not found to have security holes was HMRC, which deals with all issues around tax and national insurance.<\/p>\n<p>The security experts who looked at the government systems used a scale of 1 to 10, with 10 being the most vulnerable to attack, to classify government websites. The average vulnerability across the system was 7.5, meaning the website is particularly vulnerable to attack by hackers. Many of the vulnerabilities are related to cookies, the little pieces of information which browsers keep about users. It was found that if hackers could collect the cookie information, they would be able to log into come government portals without knowing the user name or password of the individual concerned.<\/p>\n<p>&nbsp;<\/p>\n<h2>Criminal Records Bureau Website<\/h2>\n<p>One of the government sites which was found to have most vulnerabilities was the Criminal Records Bureau website. This website is now defunct, as the process for criminal records checks is now operated by the Disclosure and Barring Service (DBS). The CRB site redirects users to the DBS website, but has been found to have serious security flaws. The very real risk is that if a hacker manages to breach the security of the former CRB website, they are then free to divert users to another website, take payments and gather all sorts of personal information including <a href=\"https:\/\/crbdirect.org.uk\/criminal-convictions-and-dbs-checks\/\">details of criminal convictions<\/a>.<\/p>\n<p>&nbsp;<\/p>\n<h2>Remember the NHS Hack?<\/h2>\n<p>The government doesn\u2019t seem to have learned the lessons of the 2017 attach by WannaCry, which attacked computers in the <a href=\"https:\/\/crbdirect.org.uk\/nhs-staff-being-forced-to-pay-to-work-with-dbs-checks\/\">NHS<\/a>. Microsoft had identified the vulnerabilities in the system and issued a patch to fix it, but thousands of computers hadn\u2019t been updated. Testing of computers in government departments is down to managers in each department. The problem is that until a website comes under attack, it can be difficult to assess just how vulnerable it is.<\/p>\n<p>&nbsp;<\/p>\n<h2>Concern for Users<\/h2>\n<p>Although there is concern over some NHS websites, there is nothing to suggest that using them is risky, or that people entering their <a href=\"https:\/\/crbdirect.org.uk\/latest-dbs-performance-data\/\">data<\/a> online should be concerned. However, the general rules about safe internet use should be followed even when on government websites. Always use a secure password which uses a combination of letters, numbers and special characters. Never use just one password across a range of sites, and make sure you have up to date anti-virus software on your laptop, tablet or phone.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>According to an investigation by leading technology publication New Scientist, a large number of government websites have serious security issues which could put you at risk. The government operates over 3000 different websites under the gov.uk domain name, covering everything from central government departments to smaller district council websites.<\/p>\n","protected":false},"author":1,"featured_media":3720,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[34],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v19.8 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Concern over Security Flaws on Government Websites<\/title>\n<meta name=\"description\" content=\"According to an investigation by leading technology publication New Scientist, a large number of government websites have serious security issues which could put you at risk.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/crbdirect.org.uk\/concern-over-security-flaws-on-government-websites\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Concern over Security Flaws on Government Websites\" \/>\n<meta property=\"og:description\" content=\"According to an investigation by leading technology publication New Scientist, a large number of government websites have serious security issues which could put you at risk.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/crbdirect.org.uk\/concern-over-security-flaws-on-government-websites\/\" \/>\n<meta property=\"og:site_name\" content=\"CRB Direct\" \/>\n<meta property=\"article:published_time\" content=\"2020-05-07T06:08:51+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-03-18T13:17:07+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/crbdirect.org.uk\/wp-content\/uploads\/2020\/05\/concern-over-security-flaws-on-government-websites.png\" \/>\n\t<meta property=\"og:image:width\" content=\"300\" \/>\n\t<meta property=\"og:image:height\" content=\"200\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"crb-admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"crb-admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/crbdirect.org.uk\/concern-over-security-flaws-on-government-websites\/\",\"url\":\"https:\/\/crbdirect.org.uk\/concern-over-security-flaws-on-government-websites\/\",\"name\":\"Concern over Security Flaws on Government Websites\",\"isPartOf\":{\"@id\":\"https:\/\/crbdirect.org.uk\/#website\"},\"datePublished\":\"2020-05-07T06:08:51+00:00\",\"dateModified\":\"2021-03-18T13:17:07+00:00\",\"author\":{\"@id\":\"https:\/\/crbdirect.org.uk\/#\/schema\/person\/1b45c80f7d9781fe6a7e7148fad45e1f\"},\"description\":\"According to an investigation by leading technology publication New Scientist, a large number of government websites have serious security issues which could put you at risk.\",\"breadcrumb\":{\"@id\":\"https:\/\/crbdirect.org.uk\/concern-over-security-flaws-on-government-websites\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/crbdirect.org.uk\/concern-over-security-flaws-on-government-websites\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/crbdirect.org.uk\/concern-over-security-flaws-on-government-websites\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/crbdirect.org.uk\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Concern over Security Flaws on Government Websites\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/crbdirect.org.uk\/#website\",\"url\":\"https:\/\/crbdirect.org.uk\/\",\"name\":\"CRB Direct\",\"description\":\"\",\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/crbdirect.org.uk\/#\/schema\/person\/1b45c80f7d9781fe6a7e7148fad45e1f\",\"name\":\"crb-admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/crbdirect.org.uk\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/205f4a48ca8f9921f31527a74b849ba1?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/205f4a48ca8f9921f31527a74b849ba1?s=96&d=mm&r=g\",\"caption\":\"crb-admin\"},\"url\":\"https:\/\/crbdirect.org.uk\/author\/crb-admin\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Concern over Security Flaws on Government Websites","description":"According to an investigation by leading technology publication New Scientist, a large number of government websites have serious security issues which could put you at risk.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/crbdirect.org.uk\/concern-over-security-flaws-on-government-websites\/","og_locale":"en_US","og_type":"article","og_title":"Concern over Security Flaws on Government Websites","og_description":"According to an investigation by leading technology publication New Scientist, a large number of government websites have serious security issues which could put you at risk.","og_url":"https:\/\/crbdirect.org.uk\/concern-over-security-flaws-on-government-websites\/","og_site_name":"CRB Direct","article_published_time":"2020-05-07T06:08:51+00:00","article_modified_time":"2021-03-18T13:17:07+00:00","og_image":[{"width":300,"height":200,"url":"https:\/\/crbdirect.org.uk\/wp-content\/uploads\/2020\/05\/concern-over-security-flaws-on-government-websites.png","type":"image\/png"}],"author":"crb-admin","twitter_card":"summary_large_image","twitter_misc":{"Written by":"crb-admin","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/crbdirect.org.uk\/concern-over-security-flaws-on-government-websites\/","url":"https:\/\/crbdirect.org.uk\/concern-over-security-flaws-on-government-websites\/","name":"Concern over Security Flaws on Government Websites","isPartOf":{"@id":"https:\/\/crbdirect.org.uk\/#website"},"datePublished":"2020-05-07T06:08:51+00:00","dateModified":"2021-03-18T13:17:07+00:00","author":{"@id":"https:\/\/crbdirect.org.uk\/#\/schema\/person\/1b45c80f7d9781fe6a7e7148fad45e1f"},"description":"According to an investigation by leading technology publication New Scientist, a large number of government websites have serious security issues which could put you at risk.","breadcrumb":{"@id":"https:\/\/crbdirect.org.uk\/concern-over-security-flaws-on-government-websites\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/crbdirect.org.uk\/concern-over-security-flaws-on-government-websites\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/crbdirect.org.uk\/concern-over-security-flaws-on-government-websites\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/crbdirect.org.uk\/"},{"@type":"ListItem","position":2,"name":"Concern over Security Flaws on Government Websites"}]},{"@type":"WebSite","@id":"https:\/\/crbdirect.org.uk\/#website","url":"https:\/\/crbdirect.org.uk\/","name":"CRB Direct","description":"","inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/crbdirect.org.uk\/#\/schema\/person\/1b45c80f7d9781fe6a7e7148fad45e1f","name":"crb-admin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/crbdirect.org.uk\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/205f4a48ca8f9921f31527a74b849ba1?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/205f4a48ca8f9921f31527a74b849ba1?s=96&d=mm&r=g","caption":"crb-admin"},"url":"https:\/\/crbdirect.org.uk\/author\/crb-admin\/"}]}},"_links":{"self":[{"href":"https:\/\/crbdirect.org.uk\/wp-json\/wp\/v2\/posts\/3705"}],"collection":[{"href":"https:\/\/crbdirect.org.uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/crbdirect.org.uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/crbdirect.org.uk\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/crbdirect.org.uk\/wp-json\/wp\/v2\/comments?post=3705"}],"version-history":[{"count":6,"href":"https:\/\/crbdirect.org.uk\/wp-json\/wp\/v2\/posts\/3705\/revisions"}],"predecessor-version":[{"id":5990,"href":"https:\/\/crbdirect.org.uk\/wp-json\/wp\/v2\/posts\/3705\/revisions\/5990"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/crbdirect.org.uk\/wp-json\/wp\/v2\/media\/3720"}],"wp:attachment":[{"href":"https:\/\/crbdirect.org.uk\/wp-json\/wp\/v2\/media?parent=3705"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/crbdirect.org.uk\/wp-json\/wp\/v2\/categories?post=3705"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/crbdirect.org.uk\/wp-json\/wp\/v2\/tags?post=3705"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}