<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: More thoughts on the IBTS data breach</title>
	<atom:link href="http://obriend.info/2008/02/21/more-thoughts-on-the-ibts-data-breach/feed/" rel="self" type="application/rss+xml" />
	<link>http://obriend.info/2008/02/21/more-thoughts-on-the-ibts-data-breach/</link>
	<description>Daragh O Brien on Information Quality Management &#38; other issues</description>
	<pubDate>Fri, 09 Jan 2009 21:32:39 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: Fitz</title>
		<link>http://obriend.info/2008/02/21/more-thoughts-on-the-ibts-data-breach/#comment-22337</link>
		<dc:creator>Fitz</dc:creator>
		<pubDate>Wed, 27 Feb 2008 11:38:37 +0000</pubDate>
		<guid isPermaLink="false">http://obriend.info/2008/02/21/more-thoughts-on-the-ibts-data-breach/#comment-22337</guid>
		<description>So. I didn't edit it much. Here is what I am sending to the IBTS Chief Executive and Data Protection Commissioner. Feel free to re-use any or part of this. I'm not an expert in data encyrption, law or software development. I do work for a software multinational and have limited knowledge of the software development process. I do have Project Management experience and qualifications. I am not a journalist and have no connection to any media organization. 
======================================
Mr. Andrew Kelly
Chief Executive
Irish Blood Transfusion Service
National Blood Centre
James’s Street
Dublin 8

Cc:  Mr Billy Hawkes,
Data Protection Commissioner
Canal House
Station Road
Portarlington
Co. Laois.

Dear Mr. Kelly:
I am writing in response to your letter of February 22nd regarding the theft of a computer on which my personal records were stored.

I have a number of questions to which I require answers. Unfortunately the staff member on the IBTS information line was unable to answer any of the questions. I respectfully request that my questions are not answered by multiple agents of the IBTS including press agents and functional managers and prefer a written response from you directly.

Regarding the use of personal records:
When I submitted my personal records to the IBTS to facilitate donation of blood products I was not informed that these records could be used for software development and/or testing. Have my records been used for any other purpose other than to facilitate donation of blood products at IBTS clinics?  
Why was un-anonymised production data being used for a development/testing activity in contravention to the IBTS’s stated Data Protection policy, Privacy statement and Donor Charter and in breach of section 2 of the Data Protection Act?
Was the use of real data (as opposed to dummy or pseudo data) a requirement of the software development project being undertaken by the NYBC? If not why was real data used? Could this software development project have been completed using anonymous medical data? If not why not?
 
Regarding the transfer and transport of personal records:
Why was the data being transported on a computer laptop? Why was the data not secured onsite at IBTS or NYBC offices?
Who authorized the transfer of the personal records outside of the EU? 
Was the transfer of the personal records strictly in compliance with all data protection laws in the Republic of Ireland and the European Economic Area?  If yes, was this transfer confirmed to be in compliance before or after the transfer took place? 

Regarding the data files (personal records) and encryption of same:
What file format was used to store the data on the CD-ROM? What file format was used to store the data on the laptop?  
What software application was used to encrypt the data? 
When the laptop was stolen was the CD-ROM containing the data stolen also?  
At the time of the theft was the data stored on both the CD-ROM disc and the laptop? 
During the course of the software development work was it necessary to un-encrypt the data? If yes was unencrypted data stored in any place (including cache files or memory page files) on the laptop hard-disc?  
At the time the laptop was stolen were there any unencrypted records stored on the laptop in any format?
If the laptop at any time contained unencrypted data containing personal records was this data deleted? How was it deleted? Was the data wiped from the hard disk of the laptop or was it moved to a ‘recycle bin’ (assuming the Microsoft Windows Operating System was installed on the laptop)?

Paragraph 3 of your letter is unclear. I would like a full explanation of why data was first encrypted on the CD-ROM, transferred to a laptop and then re-encrypted. Are you suggesting that the data was encrypted twice? Are you stating that at no time was the data unencrypted on the laptop? 
 
Regarding the password used for the encrypted data: 
Can the IBTS confirm that the password was not stored in any location on the laptop or in any case/packaging that was stolen with the laptop?  
Is the IBTS satisfied that the password used can withstand a ‘brute force’ or ‘dictionary’ based attack? If yes on what basis does the IBTS form this opinion?
How many people know the password? 
Can the IBTS and/or NYBC confirm that the password was what is commonly known as a ‘strong’ (high-entropy) password that used non-sequential and random ASCII characters not limited to letters and numbers?  
Did the password meet the IBTS and NYBC security policies for passwords?
Was the password a system-created random password or was it created by a person in the IBTS or NYBC?
Is the password unique to the data on the CD-ROM and laptop or it is in use for other data/applications/purposes? 

I remain extremely concerned, despite your assurances to the contrary, that in the future this private data could be made publicly available and cause me to suffer financial loss or loss of reputation. What is the IBTS plan to indemnify people whose personal records were stored on the stolen laptop?

I wish to make an access request under the Data Protection Acts 1988 and 2003 for a copy of any information you keep about me, on computer or in manual form.  I am making this request under section 4 of the Data Protection Acts. 

Thank you for your assistance. I look forward to hearing from you.
Yours sincerely, etc</description>
		<content:encoded><![CDATA[<p>So. I didn&#8217;t edit it much. Here is what I am sending to the IBTS Chief Executive and Data Protection Commissioner. Feel free to re-use any or part of this. I&#8217;m not an expert in data encyrption, law or software development. I do work for a software multinational and have limited knowledge of the software development process. I do have Project Management experience and qualifications. I am not a journalist and have no connection to any media organization.<br />
======================================<br />
Mr. Andrew Kelly<br />
Chief Executive<br />
Irish Blood Transfusion Service<br />
National Blood Centre<br />
James’s Street<br />
Dublin 8</p>
<p>Cc:  Mr Billy Hawkes,<br />
Data Protection Commissioner<br />
Canal House<br />
Station Road<br />
Portarlington<br />
Co. Laois.</p>
<p>Dear Mr. Kelly:<br />
I am writing in response to your letter of February 22nd regarding the theft of a computer on which my personal records were stored.</p>
<p>I have a number of questions to which I require answers. Unfortunately the staff member on the IBTS information line was unable to answer any of the questions. I respectfully request that my questions are not answered by multiple agents of the IBTS including press agents and functional managers and prefer a written response from you directly.</p>
<p>Regarding the use of personal records:<br />
When I submitted my personal records to the IBTS to facilitate donation of blood products I was not informed that these records could be used for software development and/or testing. Have my records been used for any other purpose other than to facilitate donation of blood products at IBTS clinics?<br />
Why was un-anonymised production data being used for a development/testing activity in contravention to the IBTS’s stated Data Protection policy, Privacy statement and Donor Charter and in breach of section 2 of the Data Protection Act?<br />
Was the use of real data (as opposed to dummy or pseudo data) a requirement of the software development project being undertaken by the NYBC? If not why was real data used? Could this software development project have been completed using anonymous medical data? If not why not?</p>
<p>Regarding the transfer and transport of personal records:<br />
Why was the data being transported on a computer laptop? Why was the data not secured onsite at IBTS or NYBC offices?<br />
Who authorized the transfer of the personal records outside of the EU?<br />
Was the transfer of the personal records strictly in compliance with all data protection laws in the Republic of Ireland and the European Economic Area?  If yes, was this transfer confirmed to be in compliance before or after the transfer took place? </p>
<p>Regarding the data files (personal records) and encryption of same:<br />
What file format was used to store the data on the CD-ROM? What file format was used to store the data on the laptop?<br />
What software application was used to encrypt the data?<br />
When the laptop was stolen was the CD-ROM containing the data stolen also?<br />
At the time of the theft was the data stored on both the CD-ROM disc and the laptop?<br />
During the course of the software development work was it necessary to un-encrypt the data? If yes was unencrypted data stored in any place (including cache files or memory page files) on the laptop hard-disc?<br />
At the time the laptop was stolen were there any unencrypted records stored on the laptop in any format?<br />
If the laptop at any time contained unencrypted data containing personal records was this data deleted? How was it deleted? Was the data wiped from the hard disk of the laptop or was it moved to a ‘recycle bin’ (assuming the Microsoft Windows Operating System was installed on the laptop)?</p>
<p>Paragraph 3 of your letter is unclear. I would like a full explanation of why data was first encrypted on the CD-ROM, transferred to a laptop and then re-encrypted. Are you suggesting that the data was encrypted twice? Are you stating that at no time was the data unencrypted on the laptop? </p>
<p>Regarding the password used for the encrypted data:<br />
Can the IBTS confirm that the password was not stored in any location on the laptop or in any case/packaging that was stolen with the laptop?<br />
Is the IBTS satisfied that the password used can withstand a ‘brute force’ or ‘dictionary’ based attack? If yes on what basis does the IBTS form this opinion?<br />
How many people know the password?<br />
Can the IBTS and/or NYBC confirm that the password was what is commonly known as a ‘strong’ (high-entropy) password that used non-sequential and random ASCII characters not limited to letters and numbers?<br />
Did the password meet the IBTS and NYBC security policies for passwords?<br />
Was the password a system-created random password or was it created by a person in the IBTS or NYBC?<br />
Is the password unique to the data on the CD-ROM and laptop or it is in use for other data/applications/purposes? </p>
<p>I remain extremely concerned, despite your assurances to the contrary, that in the future this private data could be made publicly available and cause me to suffer financial loss or loss of reputation. What is the IBTS plan to indemnify people whose personal records were stored on the stolen laptop?</p>
<p>I wish to make an access request under the Data Protection Acts 1988 and 2003 for a copy of any information you keep about me, on computer or in manual form.  I am making this request under section 4 of the Data Protection Acts. </p>
<p>Thank you for your assistance. I look forward to hearing from you.<br />
Yours sincerely, etc</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daragh</title>
		<link>http://obriend.info/2008/02/21/more-thoughts-on-the-ibts-data-breach/#comment-22296</link>
		<dc:creator>Daragh</dc:creator>
		<pubDate>Tue, 26 Feb 2008 23:20:27 +0000</pubDate>
		<guid isPermaLink="false">http://obriend.info/2008/02/21/more-thoughts-on-the-ibts-data-breach/#comment-22296</guid>
		<description>Now, don't loose the run of yourself. You just beat me to the rabble-rousing. ;-) 

I do agree that the only polite response to the letter from the CEO is a letter to the CEO. If you copy it to his new best friend the Data Protection Commissioner it would be even more polite. Sending it registered post to make sure it gets to him would cap the politeness off in a manner that would satisfy the most pernickity of social etiquette gurus.

That would be:

Mr Billy Hawkes,
Data Protection Commissioner
Canal House
Station Road
Portarlington
Co. Laois.</description>
		<content:encoded><![CDATA[<p>Now, don&#8217;t loose the run of yourself. You just beat me to the rabble-rousing. <img src='http://obriend.info/wordpress/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p>I do agree that the only polite response to the letter from the CEO is a letter to the CEO. If you copy it to his new best friend the Data Protection Commissioner it would be even more polite. Sending it registered post to make sure it gets to him would cap the politeness off in a manner that would satisfy the most pernickity of social etiquette gurus.</p>
<p>That would be:</p>
<p>Mr Billy Hawkes,<br />
Data Protection Commissioner<br />
Canal House<br />
Station Road<br />
Portarlington<br />
Co. Laois.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fitz</title>
		<link>http://obriend.info/2008/02/21/more-thoughts-on-the-ibts-data-breach/#comment-22288</link>
		<dc:creator>Fitz</dc:creator>
		<pubDate>Tue, 26 Feb 2008 20:45:00 +0000</pubDate>
		<guid isPermaLink="false">http://obriend.info/2008/02/21/more-thoughts-on-the-ibts-data-breach/#comment-22288</guid>
		<description>I feel almost flattered :-) as per my email I'm going to re-read it and edit if necessary. I'll post a copy here for you to use and will put it on my own blog (which is more of a love-in for my music and family than a blog)

I can be a pedantic git if I want. If the Chief Executive wants to write to me the least I can do is respond. It's only good manners after all . . .</description>
		<content:encoded><![CDATA[<p>I feel almost flattered <img src='http://obriend.info/wordpress/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> as per my email I&#8217;m going to re-read it and edit if necessary. I&#8217;ll post a copy here for you to use and will put it on my own blog (which is more of a love-in for my music and family than a blog)</p>
<p>I can be a pedantic git if I want. If the Chief Executive wants to write to me the least I can do is respond. It&#8217;s only good manners after all . . .</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daragh</title>
		<link>http://obriend.info/2008/02/21/more-thoughts-on-the-ibts-data-breach/#comment-22284</link>
		<dc:creator>Daragh</dc:creator>
		<pubDate>Tue, 26 Feb 2008 19:53:05 +0000</pubDate>
		<guid isPermaLink="false">http://obriend.info/2008/02/21/more-thoughts-on-the-ibts-data-breach/#comment-22284</guid>
		<description>Fitz,

remind me not to contradict you in a pub quiz. You strike me as a person who doesn't get mad but gets even... I feel somewhat out-pedanted.

Would it be OK for me to reformat and publish the text of your letter as a standard form document that any visitor to this site might choose to send to the IBTSB?

Just to save people the hassle and all.

Not for any divilment. I swear. Honest.

(I particularly like the fact that you request manual data as well... it may not have registered with the IBTS that since the 27th of October last that that stuff in the filing cabinets they have also fall under the remit of the DPA...)</description>
		<content:encoded><![CDATA[<p>Fitz,</p>
<p>remind me not to contradict you in a pub quiz. You strike me as a person who doesn&#8217;t get mad but gets even&#8230; I feel somewhat out-pedanted.</p>
<p>Would it be OK for me to reformat and publish the text of your letter as a standard form document that any visitor to this site might choose to send to the IBTSB?</p>
<p>Just to save people the hassle and all.</p>
<p>Not for any divilment. I swear. Honest.</p>
<p>(I particularly like the fact that you request manual data as well&#8230; it may not have registered with the IBTS that since the 27th of October last that that stuff in the filing cabinets they have also fall under the remit of the DPA&#8230;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fitz</title>
		<link>http://obriend.info/2008/02/21/more-thoughts-on-the-ibts-data-breach/#comment-22273</link>
		<dc:creator>Fitz</dc:creator>
		<pubDate>Tue, 26 Feb 2008 16:30:31 +0000</pubDate>
		<guid isPermaLink="false">http://obriend.info/2008/02/21/more-thoughts-on-the-ibts-data-breach/#comment-22273</guid>
		<description>So, I've written a letter. The more I think about this the more pissed off I am. I've written it and I fully expect a half-assed response:
----------------------------

Mr. Andrew Kelly
Chief Executive
Irish Blood Transfusion Service
National Blood Centre
James’s Street
Dublin 8

Dear Mr. Kelly:
I am writing in response to your letter of February 22nd regarding the theft of a computer on which my personal records were stored.
I have a number of questions to which I require answers. Unfortunately the staff member on the IBTS information line was unable to answer any of the questions.
When I submitted my personal records to the IBTS to facilitate donation of blood products I was not informed that these records could be used for software development and/or testing. Have my records been used for any other purpose other than to facilitate donation of blood products at IBTS clinics?  
Why was un-anonymised production data being used for a development/testing activity in contravention to the IBTS’s stated Data Protection policy, Privacy statement and Donor Charter and in breach of section 2 of the Data Protection Act?
Was the use of real data (as opposed to dummy or pseudo data) a requirement of the software development project being undertaken by the NYBC? If not why was real data used? Could this software development project have been completed using anonymous medical data? If not, why not?
Why was the data being transported on a computer laptop? Why was the data not secured onsite at IBTS or NYBC offices?
Who authorized the transfer of the personal records outside of the EU? 
Was the transfer of the personal records strictly in compliance with all data protection laws in the Republic of Ireland and the European Economic Area?  If yes, was this transfer confirmed to be in compliance before or after the transfer took place? 
What file format was used to store the data on the CD-ROM? What file format was used to store the data on the laptop?  
What software application was used to encrypt the data? 
When the laptop was stolen was the CD-ROM containing the data stolen also?  
At the time of the theft was the data stored on both the CD-ROM disc and the laptop? 
During the course of the software development work was it necessary to unencrypt the data? If yes was unencrypted data stored in any place (including cache files or memory page files) on the laptop hard-disc?  
At the time the laptop was stolen were there any unencrypted records stored on the laptop in any format?
If the laptop at any time contained unencrypted data containing personal records was this data deleted? How was it deleted? Was the data wiped from the hard disk of the laptop or was it moved to a ‘recycle bin’ (assuming the Microsoft Windows Operating System was installed on the laptop)?
Paragraph 3 of your letter is unclear. I would like a full explanation of why data was first encrypted on the CD-ROM, transferred to a laptop and then re-encrypted. Are you suggesting that the data was encrypted twice? Are you stating that at no time was the data unencrypted on the laptop?
Regarding the password used for the encrypted data: 
Can the IBTS confirm that the password was not stored in any location on the laptop or in any case/packaging that was stolen with the laptop?  
Is the IBTS satisfied that the password used can withstand a ‘brute force’ or ‘dictionary’ based attack? 
How many people know the password? 
Can the IBTS and/or NYBC confirm that the password was what is commonly known as a ‘strong’ (high-entropy) password that used non-sequential and random ASCII characters not limited to letters and numbers?  
Did the password meet the IBTS and NYBC security policies for passwords?
Was the password a system-created random password or was it created by a person in the IBTS or NYBC?
Is the password unique to the data on the CD-ROM and laptop or it is in use for other data/applications/purposes? 
What is the IBTS plan to indemnify people whose personal records were stored on the stolen laptop? I am concerned, despite your assurances to the contrary, that in the future this private data could be made publicly available and cause me to suffer financial loss or loss of reputation. 
I wish to make an access request under the Data Protection Acts 1988 and 2003 for a copy of any information you keep about me, on computer or in manual form.  I am making this request under section 4 of the Data Protection Acts. 
Thank you for your assistance. I look forward to hearing from you.</description>
		<content:encoded><![CDATA[<p>So, I&#8217;ve written a letter. The more I think about this the more pissed off I am. I&#8217;ve written it and I fully expect a half-assed response:<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p>Mr. Andrew Kelly<br />
Chief Executive<br />
Irish Blood Transfusion Service<br />
National Blood Centre<br />
James’s Street<br />
Dublin 8</p>
<p>Dear Mr. Kelly:<br />
I am writing in response to your letter of February 22nd regarding the theft of a computer on which my personal records were stored.<br />
I have a number of questions to which I require answers. Unfortunately the staff member on the IBTS information line was unable to answer any of the questions.<br />
When I submitted my personal records to the IBTS to facilitate donation of blood products I was not informed that these records could be used for software development and/or testing. Have my records been used for any other purpose other than to facilitate donation of blood products at IBTS clinics?<br />
Why was un-anonymised production data being used for a development/testing activity in contravention to the IBTS’s stated Data Protection policy, Privacy statement and Donor Charter and in breach of section 2 of the Data Protection Act?<br />
Was the use of real data (as opposed to dummy or pseudo data) a requirement of the software development project being undertaken by the NYBC? If not why was real data used? Could this software development project have been completed using anonymous medical data? If not, why not?<br />
Why was the data being transported on a computer laptop? Why was the data not secured onsite at IBTS or NYBC offices?<br />
Who authorized the transfer of the personal records outside of the EU?<br />
Was the transfer of the personal records strictly in compliance with all data protection laws in the Republic of Ireland and the European Economic Area?  If yes, was this transfer confirmed to be in compliance before or after the transfer took place?<br />
What file format was used to store the data on the CD-ROM? What file format was used to store the data on the laptop?<br />
What software application was used to encrypt the data?<br />
When the laptop was stolen was the CD-ROM containing the data stolen also?<br />
At the time of the theft was the data stored on both the CD-ROM disc and the laptop?<br />
During the course of the software development work was it necessary to unencrypt the data? If yes was unencrypted data stored in any place (including cache files or memory page files) on the laptop hard-disc?<br />
At the time the laptop was stolen were there any unencrypted records stored on the laptop in any format?<br />
If the laptop at any time contained unencrypted data containing personal records was this data deleted? How was it deleted? Was the data wiped from the hard disk of the laptop or was it moved to a ‘recycle bin’ (assuming the Microsoft Windows Operating System was installed on the laptop)?<br />
Paragraph 3 of your letter is unclear. I would like a full explanation of why data was first encrypted on the CD-ROM, transferred to a laptop and then re-encrypted. Are you suggesting that the data was encrypted twice? Are you stating that at no time was the data unencrypted on the laptop?<br />
Regarding the password used for the encrypted data:<br />
Can the IBTS confirm that the password was not stored in any location on the laptop or in any case/packaging that was stolen with the laptop?<br />
Is the IBTS satisfied that the password used can withstand a ‘brute force’ or ‘dictionary’ based attack?<br />
How many people know the password?<br />
Can the IBTS and/or NYBC confirm that the password was what is commonly known as a ‘strong’ (high-entropy) password that used non-sequential and random ASCII characters not limited to letters and numbers?<br />
Did the password meet the IBTS and NYBC security policies for passwords?<br />
Was the password a system-created random password or was it created by a person in the IBTS or NYBC?<br />
Is the password unique to the data on the CD-ROM and laptop or it is in use for other data/applications/purposes?<br />
What is the IBTS plan to indemnify people whose personal records were stored on the stolen laptop? I am concerned, despite your assurances to the contrary, that in the future this private data could be made publicly available and cause me to suffer financial loss or loss of reputation.<br />
I wish to make an access request under the Data Protection Acts 1988 and 2003 for a copy of any information you keep about me, on computer or in manual form.  I am making this request under section 4 of the Data Protection Acts.<br />
Thank you for your assistance. I look forward to hearing from you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daragh</title>
		<link>http://obriend.info/2008/02/21/more-thoughts-on-the-ibts-data-breach/#comment-22249</link>
		<dc:creator>Daragh</dc:creator>
		<pubDate>Tue, 26 Feb 2008 09:03:37 +0000</pubDate>
		<guid isPermaLink="false">http://obriend.info/2008/02/21/more-thoughts-on-the-ibts-data-breach/#comment-22249</guid>
		<description>Fitz

I got a letter myself. Which confused me greatly because I didn't give blood at all in the latter half of 2007 (no real excuse - just couldn't prioritise it) and I don't recall having had any blood tests in the latter half of 2007... I tend to be a fairly healthy bunny.

So, assuming that I'm right and my donation records shouldn't have been updated during the period that the IBTSB says they took the data from...

... WHAT THE F**K WAS DATA ABOUT ME DOING IN NYC?

I share your anger. I suggest that you annoy the hell out of them by formally requesting a copy of all data they hold about you. Will only cost about €6.00 and they &lt;em&gt;must&lt;/em&gt; respond within 40 days with data in an intelligble format.

That's what I'll be doing.</description>
		<content:encoded><![CDATA[<p>Fitz</p>
<p>I got a letter myself. Which confused me greatly because I didn&#8217;t give blood at all in the latter half of 2007 (no real excuse - just couldn&#8217;t prioritise it) and I don&#8217;t recall having had any blood tests in the latter half of 2007&#8230; I tend to be a fairly healthy bunny.</p>
<p>So, assuming that I&#8217;m right and my donation records shouldn&#8217;t have been updated during the period that the IBTSB says they took the data from&#8230;</p>
<p>&#8230; WHAT THE F**K WAS DATA ABOUT ME DOING IN NYC?</p>
<p>I share your anger. I suggest that you annoy the hell out of them by formally requesting a copy of all data they hold about you. Will only cost about €6.00 and they <em>must</em> respond within 40 days with data in an intelligble format.</p>
<p>That&#8217;s what I&#8217;ll be doing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fitz</title>
		<link>http://obriend.info/2008/02/21/more-thoughts-on-the-ibts-data-breach/#comment-22217</link>
		<dc:creator>Fitz</dc:creator>
		<pubDate>Tue, 26 Feb 2008 00:07:10 +0000</pubDate>
		<guid isPermaLink="false">http://obriend.info/2008/02/21/more-thoughts-on-the-ibts-data-breach/#comment-22217</guid>
		<description>I received a letter from the IBTS today stating that my details were on the laptop.

Right now I'm extremely angry. I cannot believe the crass stupidity and complete disregard for my privacy.</description>
		<content:encoded><![CDATA[<p>I received a letter from the IBTS today stating that my details were on the laptop.</p>
<p>Right now I&#8217;m extremely angry. I cannot believe the crass stupidity and complete disregard for my privacy.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Simon McGarr</title>
		<link>http://obriend.info/2008/02/21/more-thoughts-on-the-ibts-data-breach/#comment-22059</link>
		<dc:creator>Simon McGarr</dc:creator>
		<pubDate>Thu, 21 Feb 2008 17:14:29 +0000</pubDate>
		<guid isPermaLink="false">http://obriend.info/2008/02/21/more-thoughts-on-the-ibts-data-breach/#comment-22059</guid>
		<description>Daragh, 
Bernard Tyers of DRI raised the same question on last night's Drivetime on RTE Radio. 

The IBTS came back later in the programme with a incomprehensible explanation in a follow up statement. They weren't questioned on it.

I now can't find that explanation to reproduce it on the Drivetime website.</description>
		<content:encoded><![CDATA[<p>Daragh,<br />
Bernard Tyers of DRI raised the same question on last night&#8217;s Drivetime on RTE Radio. </p>
<p>The IBTS came back later in the programme with a incomprehensible explanation in a follow up statement. They weren&#8217;t questioned on it.</p>
<p>I now can&#8217;t find that explanation to reproduce it on the Drivetime website.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
