<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Database State</title>
	<atom:link href="http://www.lightbluetouchpaper.org/2009/03/23/database-state/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.lightbluetouchpaper.org/2009/03/23/database-state/</link>
	<description>Security Research, Computer Laboratory, University of Cambridge</description>
	<lastBuildDate>Fri, 27 Aug 2010 15:36:41 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Ross Anderson</title>
		<link>http://www.lightbluetouchpaper.org/2009/03/23/database-state/comment-page-1/#comment-52619</link>
		<dc:creator>Ross Anderson</dc:creator>
		<pubDate>Fri, 19 Mar 2010 11:32:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=747#comment-52619</guid>
		<description>Our report is &lt;a href=&quot;http://www.badmed.net/bad-medicine-blog/2010/03/database-state.html&quot; rel=&quot;nofollow&quot;&gt;still being sidely cited and discussed&lt;/a&gt; a year after its publication.</description>
		<content:encoded><![CDATA[<p>Our report is <a href="http://www.badmed.net/bad-medicine-blog/2010/03/database-state.html" rel="nofollow">still being sidely cited and discussed</a> a year after its publication.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ross Anderson</title>
		<link>http://www.lightbluetouchpaper.org/2009/03/23/database-state/comment-page-1/#comment-31023</link>
		<dc:creator>Ross Anderson</dc:creator>
		<pubDate>Thu, 30 Apr 2009 11:49:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=747#comment-31023</guid>
		<description>... and a perspective in the &lt;a href=&quot;http://www.newstatesman.com/scitech/2009/05/database-state-government&quot; rel=&quot;nofollow&quot;&gt;New Statesman&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>&#8230; and a perspective in the <a href="http://www.newstatesman.com/scitech/2009/05/database-state-government" rel="nofollow">New Statesman</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ross Anderson</title>
		<link>http://www.lightbluetouchpaper.org/2009/03/23/database-state/comment-page-1/#comment-30965</link>
		<dc:creator>Ross Anderson</dc:creator>
		<pubDate>Mon, 06 Apr 2009 22:19:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=747#comment-30965</guid>
		<description>There has also been a &lt;a
href=&quot;http://www.theyworkforyou.com/lords/?id=2009-03-25a.658.2&amp;s=JOSEPH+ROWNTREE+REFORM+TRUST#g658.3&quot;&gt;debate&lt;/a&gt; in the Lords on the Report.</description>
		<content:encoded><![CDATA[<p>There has also been a <a href="http://www.theyworkforyou.com/lords/?id=2009-03-25a.658.2&#038;s=JOSEPH+ROWNTREE+REFORM+TRUST#g658.3">debate</a> in the Lords on the Report.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ross Anderson</title>
		<link>http://www.lightbluetouchpaper.org/2009/03/23/database-state/comment-page-1/#comment-30948</link>
		<dc:creator>Ross Anderson</dc:creator>
		<pubDate>Wed, 01 Apr 2009 06:51:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=747#comment-30948</guid>
		<description>Beautiful &lt;a href=&quot;http://www.guardian.co.uk/commentisfree/2009/apr/01/jacqui-smith-expenses&quot; rel=&quot;nofollow&quot;&gt;comment&lt;/a&gt; from Simon Jenkins in the Guardian. The Home Secretary who told us that if we have nothing to hide we have nothing to fear is duly embarrassed ...</description>
		<content:encoded><![CDATA[<p>Beautiful <a href="http://www.guardian.co.uk/commentisfree/2009/apr/01/jacqui-smith-expenses" rel="nofollow">comment</a> from Simon Jenkins in the Guardian. The Home Secretary who told us that if we have nothing to hide we have nothing to fear is duly embarrassed &#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: callum</title>
		<link>http://www.lightbluetouchpaper.org/2009/03/23/database-state/comment-page-1/#comment-30923</link>
		<dc:creator>callum</dc:creator>
		<pubDate>Wed, 25 Mar 2009 13:59:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=747#comment-30923</guid>
		<description>here&#039;s another example from today&#039;s press (BBC):

&quot;The parents of a girl who died suddenly have received a school letter demanding she improves her attendance.

Megan Gillan, 15, was found dead in the bedroom of her home in Macclesfield, Cheshire, two months ago.

Her parents say they were &quot;floored&quot; by a Macclesfield High School letter, which threatened to ban Megan from the end of year prom.

The school has apologised for the mistake, which they said was down to an error on the computer database. &quot;


http://news.bbc.co.uk/1/hi/england/manchester/7963081.stm

This article shows up so many flaws in UK Gov database culture.  The fact that a letter was sent out without checking &amp; verification and then _blamed_ on the database!</description>
		<content:encoded><![CDATA[<p>here&#8217;s another example from today&#8217;s press (BBC):</p>
<p>&#8220;The parents of a girl who died suddenly have received a school letter demanding she improves her attendance.</p>
<p>Megan Gillan, 15, was found dead in the bedroom of her home in Macclesfield, Cheshire, two months ago.</p>
<p>Her parents say they were &#8220;floored&#8221; by a Macclesfield High School letter, which threatened to ban Megan from the end of year prom.</p>
<p>The school has apologised for the mistake, which they said was down to an error on the computer database. &#8221;</p>
<p><a href="http://news.bbc.co.uk/1/hi/england/manchester/7963081.stm" rel="nofollow">http://news.bbc.co.uk/1/hi/england/manchester/7963081.stm</a></p>
<p>This article shows up so many flaws in UK Gov database culture.  The fact that a letter was sent out without checking &amp; verification and then _blamed_ on the database!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ludo</title>
		<link>http://www.lightbluetouchpaper.org/2009/03/23/database-state/comment-page-1/#comment-30918</link>
		<dc:creator>Ludo</dc:creator>
		<pubDate>Mon, 23 Mar 2009 21:09:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=747#comment-30918</guid>
		<description>Interesting report. However, not all  conclusions appear to be justified in my opinion, particularly not as regards the section &#039;European databases&#039;. 

I will only comment on the two databases I have sufficient knowledge of: the Schengen Information System and the Prüm Framework.

Staring with the Prüm Framework: First and foremost: this is NOT a database but a system to conduct automated cross-border checks. No data is held on the system, it facilitates comparison of data from different member states.
Second, and equally crucial, the system works on keys that do not contain personal information and a hit-no-hit basis.  For example, with DNA comparison only the numeric profiles (loci) are compared. If and when there is a hit personal information needs to be requested from the other state according via existing procedures, which depending on the member state could entail sending a judicial letter of request. If these procedures in the UK are not privacy compliant than that might be an issue to address. But that has nothing to do with Prüm. It remains therefore unclear to me on what evidence this &#039;red&#039; flag is based.

As regards the Schengen Information System, the report rates it amber because of the projected changes. In my opinion it would have been more accurate to rate the current system first. Especially if on follows the discussion at the European level it is evident that SIS II actually might never be build.

In sum, it is an interesting report but these inaccuracies harm the overall value for me.</description>
		<content:encoded><![CDATA[<p>Interesting report. However, not all  conclusions appear to be justified in my opinion, particularly not as regards the section &#8216;European databases&#8217;. </p>
<p>I will only comment on the two databases I have sufficient knowledge of: the Schengen Information System and the Prüm Framework.</p>
<p>Staring with the Prüm Framework: First and foremost: this is NOT a database but a system to conduct automated cross-border checks. No data is held on the system, it facilitates comparison of data from different member states.<br />
Second, and equally crucial, the system works on keys that do not contain personal information and a hit-no-hit basis.  For example, with DNA comparison only the numeric profiles (loci) are compared. If and when there is a hit personal information needs to be requested from the other state according via existing procedures, which depending on the member state could entail sending a judicial letter of request. If these procedures in the UK are not privacy compliant than that might be an issue to address. But that has nothing to do with Prüm. It remains therefore unclear to me on what evidence this &#8216;red&#8217; flag is based.</p>
<p>As regards the Schengen Information System, the report rates it amber because of the projected changes. In my opinion it would have been more accurate to rate the current system first. Especially if on follows the discussion at the European level it is evident that SIS II actually might never be build.</p>
<p>In sum, it is an interesting report but these inaccuracies harm the overall value for me.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ross Anderson</title>
		<link>http://www.lightbluetouchpaper.org/2009/03/23/database-state/comment-page-1/#comment-30917</link>
		<dc:creator>Ross Anderson</dc:creator>
		<pubDate>Mon, 23 Mar 2009 14:56:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=747#comment-30917</guid>
		<description>... and here&#039;s a &lt;a href=&quot;http://blogs.ft.com/mccartney/&quot; rel=&quot;nofollow&quot;&gt;blog in the FT&lt;/a&gt; that&#039;s written by a doctor in Scotland</description>
		<content:encoded><![CDATA[<p>&#8230; and here&#8217;s a <a href="http://blogs.ft.com/mccartney/" rel="nofollow">blog in the FT</a> that&#8217;s written by a doctor in Scotland</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ross Anderson</title>
		<link>http://www.lightbluetouchpaper.org/2009/03/23/database-state/comment-page-1/#comment-30916</link>
		<dc:creator>Ross Anderson</dc:creator>
		<pubDate>Mon, 23 Mar 2009 13:55:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=747#comment-30916</guid>
		<description>More news coverage in the &lt;a href=&quot;http://www.dailyindia.com/show/303640.php&quot; rel=&quot;nofollow&quot;&gt;Daily India&lt;/a&gt;, the &lt;a href=&quot;http://www.thisislondon.co.uk/standard/article-23665466-details/Government+%27illegal%27+databases+row/article.do&quot; rel=&quot;nofollow&quot;&gt;Standard&lt;/a&gt; and &lt;a href=&quot;http://news.google.co.uk/news?pz=1&amp;ned=uk&amp;ncl=1318683585&amp;topic=n&quot; rel=&quot;nofollow&quot;&gt;elsewhere&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>More news coverage in the <a href="http://www.dailyindia.com/show/303640.php" rel="nofollow">Daily India</a>, the <a href="http://www.thisislondon.co.uk/standard/article-23665466-details/Government+%27illegal%27+databases+row/article.do" rel="nofollow">Standard</a> and <a href="http://news.google.co.uk/news?pz=1&#038;ned=uk&#038;ncl=1318683585&#038;topic=n" rel="nofollow">elsewhere</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James Hughes</title>
		<link>http://www.lightbluetouchpaper.org/2009/03/23/database-state/comment-page-1/#comment-30915</link>
		<dc:creator>James Hughes</dc:creator>
		<pubDate>Mon, 23 Mar 2009 11:36:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=747#comment-30915</guid>
		<description>I heard your interview on R4 this morning. Why is it that politicians always know better than acknowledged experts in the field? Every time? Why are they never told &#039;You are a minister for 5 minutes, I have been an expert in this field for 20 years. Why do you think you know better than me?&#039;

I&#039;m sorry the politico in questions whose named slips my mind, &#039;dissed&#039; this report out of hand (no surprise there) but at least he came off as being a rather slippery character, clutching at straws, and unable to answer any of the real questions put to him.

James</description>
		<content:encoded><![CDATA[<p>I heard your interview on R4 this morning. Why is it that politicians always know better than acknowledged experts in the field? Every time? Why are they never told &#8216;You are a minister for 5 minutes, I have been an expert in this field for 20 years. Why do you think you know better than me?&#8217;</p>
<p>I&#8217;m sorry the politico in questions whose named slips my mind, &#8216;dissed&#8217; this report out of hand (no surprise there) but at least he came off as being a rather slippery character, clutching at straws, and unable to answer any of the real questions put to him.</p>
<p>James</p>
]]></content:encoded>
	</item>
</channel>
</rss>
