How the scrapped ID card database will be destroyed
bbc.co.uk
bbc.co.uk
Seems to me that this is where the compromise will be. Asking "workers" to "provide file locations of extracted data"? What's the chance that some locations will be missed? And why do they not already have a registry of all locations where private data is copied?
Also, it's far easier to compromise a computer (do it remotely over the internet) then some piece of card scanning hardware (more likely to need physical access).
But, in another twist, the document also reveals that not all identity data will be destroyed - some will be kept for the purposes of investigating fraud.
And of course we trust all of these people to get it right and for nothing to slip through the cracks. The threat is as much about what happened in the past as what happens now. What guarantees are there that some employee didn't make their own copy of the data and take it offsite? What about backups?
As for guarantees, there are no more than there would be that someone at Google hasn't done that, but what HMG does have is a fairly strong vetting standard, that these people will be under.
And none of this theatre can rectify historic breaches.
This is basically poisoning the wells and salting the fields.
Next week we're going to hear that they are taking down all the CCTV cameras!