msi_school Posted September 25, 2018 Posted September 25, 2018 Hi A question that came up in the staff room today, can we send confidential info or passwords in the post? According to the Royal mails web site they delivered 1.2 billion letters last year and lost 500 000 which is 0.04% the penalty for stealing from the mail is 3 - 5 years for a normal person and 3 - 14 for an employee of the mail, which is as serious as the penalties for hacking email and I would assume it is easier to prosecute. We also argued what was easier to intercept snail mail or e mail, and could not come up with a consensus. Mike
MatthewL Posted September 25, 2018 Posted September 25, 2018 If you are sending printed confidential papers in the post then anyone could get their hands on them in theory. Now if you were to send it in electronic form and encrypted/password protected you have take a step to mitigate that risk and then the password should be send by an alternative means. Now if it was the other way around and just sending a password for documents already received that password could relate to 100 things but if you were to put it in such a way that it wasn't a password you have then mitigated a risk there. End of day electronic is more secure, who uses post for such things these days?
mavhc Posted September 25, 2018 Posted September 25, 2018 Only allow TLS connections for email routing, no interception, done
Meldrew Posted September 26, 2018 Posted September 26, 2018 Bear in mind that organisations have been fined by the ICO for sending confidential material that was lost in the post. Not that anyone even knows that the material has been intercepted. There's no guarantee even if you use a signed-for delivery that the item will end up at the recipient. Meldrew
djrscally Posted September 26, 2018 Posted September 26, 2018 End of day electronic is more secure, who uses post for such things these days? Loads of people. Banks, Doctor's surgeries, hospitals, lawyers, councils, the police... Post for sending confidential information is still very much a thing. I mean, every item of post inherently contains information about a person in the form of their address right? It's unavoidable. What matters is whether the levels of risk associated with sending the information in the post are acceptable. You just need to be able to demonstrate that you have assessed that risk and record that fact. Scenarios for example: 1. If the risk of harm if an item of mail goes missing and the scope of the mailshot (i.e. how many people it's about) are both low, it's probably fine. This might be "your son is behaving great lately, we'd love for you to come in to an awards meeting". 2. If the risk of harm if an item of mail goes missing is high, but the scope is very low (maybe detailed behaviour or CP logs about a single student) then it might be fine if you use signed-for or recorded delivery, or a special courier. 3. If it's high-risk data about every kid, you probably need to think of a better way to send the data. If you were going to send passwords I'd be tempted to try and apply some additional protection; for example perhaps instead of sending the actual password the letter might be "Your password is your son/daughter's initials and date of birth" or something like that.
mavhc Posted September 26, 2018 Posted September 26, 2018 (1)A person commits an offence if, without reasonable excuse, he— (a)intentionally delays or opens a postal packet in the course of its transmission by post, or (b)intentionally opens a mail-bag. (2)Subsections (2) to (5) of section 83 apply to subsection (1) above as they apply to subsection (1) of that section. (3)A person commits an offence if, intending to act to a person’s detriment and without reasonable excuse, he opens a postal packet which he knows or reasonably suspects has been incorrectly delivered to him. (4)Subsections (2) and (3) of section 83 (so far as they relate to the opening of postal packets) apply to subsection (3) above as they apply to subsection (1) of that section. (5)A person who commits an offence under subsection (1) or (3) shall be liable on summary conviction to a fine not exceeding level 5 on the standard scale or to imprisonment for a term not exceeding six months or to both.
enjay Posted September 26, 2018 Posted September 26, 2018 I don't think we're disputing mail tampering is a crime. So is hacking, but if information is leaked through hack, the company can still be liable. We have seen companies fined for losing information sent in the post before.
mavhc Posted September 26, 2018 Posted September 26, 2018 99% of lost data isn't people hacking or stealing post, it's people with the wrong email address or someone posted it to the wrong house. Thing is post is in an envelope, so there has to be an action to read it, and that action is against the law Nothing similar for email, despite the billions of disclaimers attached to emails for no reason. Solution: actually deploy real encryption so 1. you must specify the security level of an email when you write it, identifying the individuals it concerns, 2. you can then only send that email to people on the list that can receive that security level for those individuals, 3. which is proved by the recipients specific public key
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now