Privacy regulator warns MPs over shared passwords
- Published
The UK's data privacy regulator has cautioned MPs about sharing work computer passwords.
It follows tweets by three Conservative Party MPs over the weekend claiming that they had provided their staff with access to their login details.
Sharing passwords is not a breach of the UK's Data Protection Act.
But the law says that "appropriate" security measures concerning personal data must be in place and that those with access must be properly vetted.
"We're aware of reports that MPs share logins and passwords and are making enquiries of the relevant parliamentary authorities," the Information Commissioner's Office said in a tweet of its own.
"We would remind MPs and others of their obligations under the Data Protection Act to keep personal data secure."
It added a link to a guide outlining the types of safety measures that should be enforced, external.
Left unlocked
The issue was raised by Nadine Dorries - the member of parliament for mid-Bedfordshire - who posted on Saturday evening that her team logged into her computer using her login details "everyday".
Allow Twitter content?
This article contains content provided by Twitter. We ask for your permission before anything is loaded, as they may be using cookies and other technologies. You may want to read Twitter’s cookie policy, external and privacy policy, external before accepting. To view this content choose ‘accept and continue’.
She had made the point in order to cast doubt over claims that First Secretary of State Damian Green must have been responsible for viewing pornography allegedly found on his computer. The minister denies the accusation, but has faced calls to resign.
Nick Boles - MP for Grantham and Stamford - followed up saying that he had shared his password with his four members of his staff, so they could deal with letters and emails from constituents.
Allow Twitter content?
This article contains content provided by Twitter. We ask for your permission before anything is loaded, as they may be using cookies and other technologies. You may want to read Twitter’s cookie policy, external and privacy policy, external before accepting. To view this content choose ‘accept and continue’.
And Will Quince - who represents Colchester - said that he had given his login to his office manager, adding that he did not always lock his machine to allow other team members access.
Allow Twitter content?
This article contains content provided by Twitter. We ask for your permission before anything is loaded, as they may be using cookies and other technologies. You may want to read Twitter’s cookie policy, external and privacy policy, external before accepting. To view this content choose ‘accept and continue’.
The House of Commons Staff Handbook explicitly states that its employees must not share, external their passwords, but the rule does not appear to cover logins of the MPs themselves.
Even so, some politicians have stressed that they do keep their details private.
Allow Twitter content?
This article contains content provided by Twitter. We ask for your permission before anything is loaded, as they may be using cookies and other technologies. You may want to read Twitter’s cookie policy, external and privacy policy, external before accepting. To view this content choose ‘accept and continue’.
Allow Twitter content?
This article contains content provided by Twitter. We ask for your permission before anything is loaded, as they may be using cookies and other technologies. You may want to read Twitter’s cookie policy, external and privacy policy, external before accepting. To view this content choose ‘accept and continue’.
Security experts have expressed concern about the suggestion that password-sharing is commonplace among MPs and their staff.
Troy Hunt blogged about a variety of alternative ways, external to share access to emails and other documents without providing full access to a computer's contents.
And the consultant Graham Cluley suggested, external: "it should worry us all if the very people who are tasked with legislating on internet privacy and security issues are proving to be so utterly clueless".
- Published3 December 2017
- Published4 December 2017