Simple clear advice in plain English

CEOP fixes security flaw found in its online reporting form

Online form used to report suspicious activity was not encrypted, but the Information Commissioner's Office says people's personal details are now secure

Child Exploitation and Online Protection Centre logo
CEOP locks down security flaw

A serious security flaw found in the Child Exploitation and Online Protection Centre's (CEOP) online reporting procedure has been fixed.

The online form used by members of the public to inform the child protection agency of suspicious activity was not encrypted, meaning people's personal data was vulnerable when being transmitted to CEOP's servers.

The security problem was found by a member of the public in April this year and reported to the Information Commissioner's Office (ICO). The privacy watchdog found that the flaw had existed for several months following the launch of CEOP's new website.

According to the ICO this has now been rectified and the privacy watchdog's acting head of enforcement, Sally Anne Poole said: "Organisations must make sure that any personal data transmitted electronically is adequately protected.

"While there is no evidence to suggest that attempts have been made to access any of the information, it is highly likely that it would have been sensitive in nature and should not have been compromised by insufficient IT security measures.

CEOP chief executive Peter Davies and Trevor Pearce director general of its parent organisation, the Serious Organised Crime Agency (SOCA) have jointly signed an undertaking to ensure that CEOP's website is regularly tested. This will ensure the personal data they process remains secure and potential weaknesses are immediately identified.

CEOP will also introduce recommendations included in a recent Information Security Review and continue to ensure they are followed.

Poole said: "We are pleased that CEOP and SOCA have taken action to make sure that all of the information sent in by members of the public remains secure."

Reader Comments

   

Add your comment

All fields must be completed. Your email address will not be displayed or used to send marketing messages.

All messages will be checked by moderators before appearing on the site.

See our Privacy Policy for more information.

Related articles

fraud45

ICO calls for prison sentences for serious personal data breaches

Courts should have the power to imprison those involved in serious breaches of the Data Protection Act, according to the Information Commissioner

police

ICO reprimands Lancashire Police Authority over data breach

Police authority published private details of an individual's complaint online

CEOP policy chief says police need to understand mindset of child abusers to forge safer web

'The internet is a tool and cannot be tamed', CEOP policy head tells Westminster e-forum

Question & Answer

Q.Can I switch boot drives so that I can work on older...

> Read the answer

Q.Can I open my old genealogy files or have they gone...

> Read the answer

Q.Why are odd patterns appearing on my monitors shortly...

> Read the answer

Best deals on the web

img

Samsung RV520-A07

£356.50- Buy it now

img

Acer Aspire 5750G (LX.RXP02.019)

£399.99- Buy it now

img

Apple MacBook Pro (MD313B/A)

£904.37- Buy it now

Latest issue & subscription deals

Most popular articles

Poll

Are you concerned about viruses that target mobile phones?

Jargon Buster

Computing terms explained in plain English

Bittorrent

A technology for downloading files. Allows even very large files to be downloaded quickly.

Great shopping deals from Computeractive