This article is from the source 'guardian' and was first published or seen on . It last changed over 40 days ago and won't be checked again for changes.

You can find the current article at its original source at https://www.theguardian.com/politics/2018/sep/29/tory-conference-app-flaw-reveals-private-data-of-senior-mps

The article has changed 12 times. There is an RSS feed of changes available.

Version 3 Version 4
Tory conference app flaw reveals private data of senior MPs Tory conference app flaw reveals private data of senior MPs
(35 minutes later)
A major flaw in the Conservative’s official conference mobile phone application has made the private data of senior party members – including cabinet members – accessible to anyone that logged in as a conference attendee.A major flaw in the Conservative’s official conference mobile phone application has made the private data of senior party members – including cabinet members – accessible to anyone that logged in as a conference attendee.
The data of every person who registered to attend the Tory conference could be viewed, with Boris Johnson, Michael Gove and others among hundreds of diplomats, dignitaries and party members whose personal information was revealed. The data of every person who registered to attend the Tory conference through the app could be viewed, with Boris Johnson, Michael Gove and others among hundreds of diplomats, dignitaries and party members whose personal information was revealed.
Several ministers, including those in roles with top-ranking security clearance, reportedly received prank calls from members of the public.Several ministers, including those in roles with top-ranking security clearance, reportedly received prank calls from members of the public.
The breach enraged senior ministers and one Whitehall source described the error as “fucking ridiculous”. Anger was aimed at Brandon Lewis, the Tory party chairman, whose duties include overseeing the conference.The breach enraged senior ministers and one Whitehall source described the error as “fucking ridiculous”. Anger was aimed at Brandon Lewis, the Tory party chairman, whose duties include overseeing the conference.
A senior Tory said: “Brandon Lewis is telling everyone who will listen that he could be the man to run the country – yet this conference fiasco shows he couldn’t run a bath.”A senior Tory said: “Brandon Lewis is telling everyone who will listen that he could be the man to run the country – yet this conference fiasco shows he couldn’t run a bath.”
Lewis was due to unveil the new app in a speech on Sunday as part of a wider set of measures in an attempt at overhauling “the oldest and most successful political party in the world”.Lewis was due to unveil the new app in a speech on Sunday as part of a wider set of measures in an attempt at overhauling “the oldest and most successful political party in the world”.
The party’s first “interactive” conference app allows rank and file members to provide feedback during cabinet ministers’ speeches, among other functions.The party’s first “interactive” conference app allows rank and file members to provide feedback during cabinet ministers’ speeches, among other functions.
It also contains a list of events taking place at the conference including Rise of Tech Giants and Data Capitalism and a panel discussion on GovTech and the Future of Public Service Delivery.It also contains a list of events taking place at the conference including Rise of Tech Giants and Data Capitalism and a panel discussion on GovTech and the Future of Public Service Delivery.
The Conservative party apologised. It said: “The technical issue has been resolved and the app is now functioning securely. We are investigating the issue further and apologise for any concern caused.” The Conservative party said: “The technical issue has been resolved and the app is now functioning securely. We are investigating the issue further and apologise for any concern caused.”
The Information Commissioner’s Office, the independent authority which upholds data rights in the public interest, said it would be making inquiries about the breach, opening the possibility that the party could be censured and face fines. The watchdog added: “organisations have a legal duty to keep personal data safe and secure”. The Information Commissioner’s Office, the independent authority that upholds data rights in the public interest, said it would be making inquiries about the breach, opening the possibility that the party could be censured and face fines. The watchdog added: “organisations have a legal duty to keep personal data safe and secure”.
Under the EU’s general data protection regulation (GDPR), organisations must notify the ICO within 72 hours of becoming aware of a personal data breach, if it could pose a risk to people’s rights and freedoms.Under the EU’s general data protection regulation (GDPR), organisations must notify the ICO within 72 hours of becoming aware of a personal data breach, if it could pose a risk to people’s rights and freedoms.
Users, once logged into the app, were able to both amend and make the personal details of prominent MPs public. Twitter users claimed Johnson’s picture had been briefly changed to one featuring a pornographic image. Users, once logged into the app, were able to both amend and make the personal details of prominent MPs public. Twitter users claimed Johnson’s picture had been briefly changed to one featuring a pornographic image. Gove’s picture was changed to Rupert Murdoch, his previous employer at the Times.
Gove’s picture was changed to Rupert Murdoch, his previous employer at the Times.
Anyone could log in as any attendee by providing an email with no password. Many MPs had registered with their public parliamentary email addresses, making it simple for any member of the public to access their mobile number.Anyone could log in as any attendee by providing an email with no password. Many MPs had registered with their public parliamentary email addresses, making it simple for any member of the public to access their mobile number.
Commentators said the flaw raised questions over the ability of the government to harness technology to solve issues around the Irish border and customs checks. Commentators said the flaw raised questions over the ability of the government to harness technology to solve issues around the Irish border and customs checks. Labour said that the mishap raised questions around national security and recommended the Tories provide computer training to its members.
Labour said that the mishap raised questions around national security and recommended the Tories provide computer training to its members. “How can we trust this Tory government with our country’s security when they can’t even build a conference app that keeps the data of their members, MPs and others attending safe and secure?” said Jon Trickett, the shadow Cabinet Office minister.
“How can we trust this Tory government with our country’s security when they can’t even build a conference app that keeps the data of their members, MPs and others attending safe and secure?” said John Trickett, the shadow Cabinet Office minister.
“The Conservative party should roll out some basic computer security training to get their house in order.”“The Conservative party should roll out some basic computer security training to get their house in order.”
A Momentum spokesperson criticised the “staggering incompetence” of the Conservative party and cited the success of its own in-house app during the Labour party conference.A Momentum spokesperson criticised the “staggering incompetence” of the Conservative party and cited the success of its own in-house app during the Labour party conference.
“This sums up the Tories, staggeringly incompetent and out of touch with the modern world,” they said. “They can’t even build a basic conference app without a huge data breach, and it’s terrifying that they’re in charge of the tech that runs our hospitals, schools and airports.“This sums up the Tories, staggeringly incompetent and out of touch with the modern world,” they said. “They can’t even build a basic conference app without a huge data breach, and it’s terrifying that they’re in charge of the tech that runs our hospitals, schools and airports.
“Our conference app was built by a team of volunteers for next to no money, and I’m sure they’d be happy to give the Tories a few tips for next year.”“Our conference app was built by a team of volunteers for next to no money, and I’m sure they’d be happy to give the Tories a few tips for next year.”
It's let me login as Boris Johnson, and just straight up given me all the details used for his registration pic.twitter.com/fLNC06azx7It's let me login as Boris Johnson, and just straight up given me all the details used for his registration pic.twitter.com/fLNC06azx7
The Guardian columnist Dawn Foster was among the first to notice the flaw and swiftly raised the alarm on Saturday before the app, created by an Australian firm called Crown Comms, was updated and the login function removed.The Guardian columnist Dawn Foster was among the first to notice the flaw and swiftly raised the alarm on Saturday before the app, created by an Australian firm called Crown Comms, was updated and the login function removed.
The prime minister, Theresa May, refused to respond to questions from reporters about the embarrassing security blunder as she arrived in Birmingham. Theresa May has refused to respond to questions from reporters about the embarrassing security blunder as she arrived in Birmingham.
Theresa May arrives at #CPC18 in Birmingham - faced with shouts of “have you checked out the conference app?” ... the Tories will want a glitch free few days - this data breach is not a good start pic.twitter.com/KLdF37Hrtf It follows the gaffe that unfolded last year during the prime minister’s keynote speech when a comedian managed to get to the front of the stage and pass her a P45, which she accepted.
It follows the gaffe that unfolded last year during May’s keynote speech when a comedian managed to get to the front of the stage and pass her a P45, which she accepted. The set behind her featuring the slogan “Building a county that works for everyone” soon began to fall apart, and she lost her voice, prompting the chancellor, Philip Hammond, to offer her a cough sweet.
The set behind her – featuring the slogan “Building a county that works for everyone” – soon began to disintegrate as she lost her voice, prompting the chancellor, Philip Hammond, to offer her a cough sweet.
Listen / Listen /
Walking the Brexit tightrope at Labour conference – Politics WeeklyWalking the Brexit tightrope at Labour conference – Politics Weekly
Sorry your browser does not support audio - but you can download hereSorry your browser does not support audio - but you can download here
and listen https://flex.acast.com/audio.guim.co.uk/2018/09/26-51111-gdn.pol.180926.podcast.mp3and listen https://flex.acast.com/audio.guim.co.uk/2018/09/26-51111-gdn.pol.180926.podcast.mp3
Sorry your browser does not support audio - but you can download hereSorry your browser does not support audio - but you can download here
and listen https://flex.acast.com/audio.guim.co.uk/2018/09/26-51111-gdn.pol.180926.podcast.mp3and listen https://flex.acast.com/audio.guim.co.uk/2018/09/26-51111-gdn.pol.180926.podcast.mp3
Conservative conference 2018
ConservativesConservatives
PrivacyPrivacy
Data protectionData protection
newsnews
Share on FacebookShare on Facebook
Share on TwitterShare on Twitter
Share via EmailShare via Email
Share on LinkedInShare on LinkedIn
Share on PinterestShare on Pinterest
Share on Google+Share on Google+
Share on WhatsAppShare on WhatsApp
Share on MessengerShare on Messenger
Reuse this contentReuse this content