• Login
  • Register
The Daily Sceptic
No Result
View All Result
  • Articles
  • About
  • Archive
    • ARCHIVE
    • NEWS ROUND-UPS
  • Podcasts
  • Newsletter
  • Premium
  • Donate
  • Log In
The Daily Sceptic
No Result
View All Result

The Vaccine Passport Update to the NHS App Has Created a Honeypot For Hackers

by Toby Young
23 May 2021 11:36 PM

There follows a guest post by Lockdown Sceptics’ technology correspondent about last week’s vaccine passport update to the NHS App which, according to this industry insider, has created a honeypot for hackers.

Back in March I warned that the government had plans to turn the previously unremarkable NHS App into a cyber bully and privacy blabbermouth. Last week, an update appeared that increased the app’s functionality to include a Covid status certificate, but it included a privacy notice that strongly implied it held an unbelievable range of information about us all: “Information relating to the family of the individual and the individual’s lifestyle and social circumstances; Information which relates to the ethnic origin of the individual; Information relating to genetic/biometric details (where processed to uniquely identify an individual) and criminal convictions or alleged criminal behaviour”.

We knew vaccine passports were going to be a threat to our liberties but what this implied was off the scale. It was soon picked up by security experts like Prof Eerke Boiten of De Montfort University who fired off a Twitter thread that got the attention of the Daily Express and Julia Hartley-Brewer’s morning TalkRADIO show.

Remember how the NHS App was going to become our vaccine passport, as of yesterday? It turns out I was massively confused (or misled if you like) about its privacy notice, data controller, etcetera. This is because there are NOW 2 similar features on the app.

— Eerke Boiten (@EerkeBoiten) May 18, 2021

The policy was quickly updated, and you can read the saner version here.

The app’s upgrade has given it a new section: “Share your COVID-19 status.” If you click on it you could be forgiven for thinking you are still within the NHS app, but in fact you are taken to this website which is run by NHSX. It might seem an irrelevant detail, but despite its name NHSX is not the NHS. What is going on here is that one arm of the state is hiding behind the more trusted brand of another arm to get its software into your pocket. That’s sneaky and it does not take much imagination to see how this trick might be repeated in the future, with the NHS App being the conduit for all sorts of intrusive government schemes. What’s more, this is happening in the NHS App, which will be around for as long as the government wants, not in the COVID-19 app which Hancock promised to withdraw when the pandemic was over. This makes the prospect more likely that long after the pandemic is over we will be sharing things like immigration status, outstanding criminal allegations or historic driving convictions alongside our COVID-19 status for any busybody who feels they are doing their bit to keep us all safe.

The implication of this new section being hosted by NHSX is that the data is not being drawn from your GP-held medical record as I speculated in my previous article, but from a single national database, the National Immunisation Management System, previously used to coordinate national flu vaccine programmes, but now also used in the rollout of the Covid jabs. As the NIMS site says:

The demographic details of everyone resident in England or registered with a GP in England are imported into the system from the Primary Care Registration Management Service… Further data such as lists of shielded patients, NHS staff, social care workers, unpaid carers and ethnic category information are also uploaded. This data can then be used for prioritising invitation for flu or COVID-19 vaccination, and for reporting purposes.

That is a lot of very sensitive data in a single central database. It is a high-risk design with a single point of failure, but even worse from a security point of view, it is a honeypot for hackers. Last year, when a similar centralised approach was considered for the COVID-19 app, the E.U. weighed in with a statement saying “data are not to be stored in a centralised database” and this was followed up with a letter from 300 security and privacy researchers from 27 countries repeating the warning. NHSX subsequently changed tack and went with the Apple/Google decentralised model instead. Now, with the NHS App, those lessons are being un-learned. There is a naturally decentralised database available in GP-held records, but it has been shunned – presumably in favour of speed of deployment. And yet there is no public outcry this time, no open letters from security professionals.

We are suffering an ultra-cautious approach when it comes to reopening, but a reckless approach when it comes to privacy. With Covid-related phishing attacks up 15-fold and hackers raking in over £35m in UK Covid-related online scams since the start of the pandemic, the motivation and resources are there to crack these databases. So long as the politicians see privacy as an afterthought, the scammers will be toasting every new version of the app.

Tags: NHS AppVaccine Passports

Donate

We depend on your donations to keep this site going. Please give what you can.

Donate Today

Comment on this Article

You’ll need to set up an account to comment if you don’t already have one. We ask for a minimum donation of £5 if you'd like to make a comment or post in our Forums.

Sign Up
Previous Post

New PHE Study Says AstraZeneca Vaccine is Just 66% Effective. What Happened to “90% in the Over-65s”?

Next Post

Vaccine Safety Update

Subscribe
Login
Notify of
Please log in to comment

To join in with the discussion please make a donation to The Daily Sceptic.

Profanity and abuse will be removed and may lead to a permanent ban.

16 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
Matt Mounsey
Matt Mounsey
4 years ago

The “scammers” and the “hackers” are far less of a concern than the totalitarian one world government that’s making use of this data.

69
0
Brett_McS
Brett_McS
4 years ago

“We are suffering … a reckless approach when it comes to privacy”.

And to experimental vaccines.

56
0
Susan
Susan
4 years ago

Indignation over privacy breach. Silence on vaccines maiming and killing.

51
0
Annie
Annie
4 years ago

I don’t have a smartphone.
They can get stuffed.

45
0
covidiot
covidiot
4 years ago
Reply to  Annie

Sounds like they may already have your data whether you use a smartphone or not.

“The demographic details of everyone resident in England or registered with a GP in England are imported into the system from the Primary Care Registration Management Service… ”

Also suggests my opt out from the NHS sharing any data may have been ignored.

10
0
Hopeless
Hopeless
4 years ago

The security implications of this were one of the points I raised in my comments on the other article about Covid Status certificates. The Irish have very recent experience of a massive hack of a medical database, and other examples abound.

21
0
JohnK
JohnK
4 years ago

The point was well made. There is no intelligent reason to use any such NHS app on a ‘smartphone’, even if one uses them for other reasons (lots of us do not use them at all).

23
0
Hopeless
Hopeless
4 years ago

On this thorny subject, I previously linked the Medconfidential pages concerning Hancock’s download grab of all medical data from GP systems, apparently for sale to various parties. Here is the link again:- https://medconfidential.org/2021/let-us-tell-you-about/

We now find ourselves faced with:-

  • a Covid Status certificate, masquerading behind the apparently innocuous NHS App, but which, run by another arm of the State, has let slip that various other personal/sociological data may also move backwards and forwards under the guise of the NHS App.
  • the NHS Track and Trace app, which despite “assurances” that it will be withdrawn at some post-pandemic point (will there ever be one?), will likely be continued and perhaps its use enforced in some way.
  • the imminent harvesting from GPs of full patient records, possibly for sale to third parties, but probably also to be held centrally by Government for whatever as yet undisclosed purposes. This is in complete defiance of any known medical ethics or patient/doctor confidentiality, although doubtless there will be the usual stuff about “anonymisation” etc. These records will inevitably be accessible to many more persons in Government or quangos, as well as other parties.
  • the establishment of insecure databases, vulnerable to access and misuse by external “bad actors”, who may be from any country on earth, as well as UK people in State or similar employment (perhaps local authorities, education).

All in all, there appears to be a massive increase in the nexus of personal data of all sorts (medical, sociological, lifestyle, financial etc.) gathered and held by the State, without permission of the owner of the data, and with little or no open explanation of the reasons and purposes for the State to do this. The supine and toothless Information Commissioner’s Office, as an arm of Government, is probably complicit and accepting of this.

27
0
chris c
chris c
4 years ago
Reply to  Hopeless

There’s another factor too. When I was permitted to see my GP notes it turned out that there was information that did not apply to me. At worst it was made up, at best it applied to some other patient and got into the wrong file. Also a lot of my notes were missing. Of course there may be another individual who has the rest of my notes. How often does this happen?

7
0
Hopeless
Hopeless
4 years ago
Reply to  chris c

Quite often, I suspect. I’m not sure what or how different practices have loaded old paper records into new computer systems, of which there are several for GPs, but entering those data are a sure-fire way of accidentally getting them into the wrong records. Those are errors, but on the last of the two occasions I have consulted a GP in 30 years, omissions of more recent information, such as being a non-smoker of 20 years standing, were evident.

5
0
sophie123
sophie123
4 years ago

What we actually need is a massive hack and privacy leak. ASAP. Ideally sharing all sorts of unsavoury information about top politicians.

That way people will acknowledge the risk, and stop this farce in its tracks. Fingers crossed hackers are onto it already.

54
0
Less government
Less government
4 years ago
Reply to  sophie123

Best comment of the day

6
0
Milo
Milo
4 years ago
Reply to  sophie123

and leak it all widely!!!

3
0
Ruth Sharpe
Ruth Sharpe
4 years ago

I’ve been reading about NHS Digital & the opt out for it is only a month away. Is this all linked with that?

I’m sorry I don’t know how to copy & paste links, but a good starting point is in the Byline Times. The article is from 19 May and 8s about the government wanting to sell ‘our’ data.

However, I am connecting NHS Digital with this monstrosity.

2
0
Ruth Sharpe
Ruth Sharpe
4 years ago

See FiatLux comment below – I think he’s saying it much better than me!

1
0
Mike Bear
Mike Bear
4 years ago

Lockdown Sceptics you have got your facts wrong!!

The standard NHS App login goes to  https://www.nhsapp.service.nhs.uk/login and leads on to Enter your email address (login.nhs.uk) or https://access.login.nhs.uk/enter-email

The Domain is NHS.UK – when you login to the NHS App and choose to “Share your COVID-19 Status” it takes you to https://covid-status.service.nhsx.nhs.uk/SelectedFlow/

The Domain is again NHS.UK

The Website to which you refer is also https://covid-status.service.nhsx.nhs.uk/   or COVID-19 status – NHS (nhsx.nhs.uk)

The Domain is again NHS.UK

That again leads to Enter your email address (login.nhs.uk) or https://access.login.nhs.uk/enter-email

If you go to WHOIS https://www.nominet.uk/whois/  and search for NHS.UK Domain Name it is shown as:

Registrant type:
UK Government Body

Registrant’s address:
NHS Digital
1 Trevelyan Square
Boar Lane
Leeds
LS1 6AE
GB

Registrar:
NHS Network Addressing Team, NHS Digital

So where the LS article says:

The app’s upgrade has given it a new section: “Share your COVID-19 status.” If you click on it you could be forgiven for thinking you are still within the NHS app, but in fact you are taken to this website which is run by NHSX. It might seem an irrelevant detail, but despite its name NHSX is not the NHS.

 Actually…it is not only still the NHS but is a branch of the same NHS App website!!!

Last edited 4 years ago by Mike Bear
0
0

NEWSLETTER

View today’s newsletter

To receive our latest news in the form of a daily email, enter your details here:

DONATE

PODCAST

The Sceptic | Episode 45: Jack Hadfield on the Anti-Asylum Protests, Alan Miller on the Tyranny of Digital ID and James Graham on the Net Zero Pension Threat

by Richard Eldred
25 July 2025
0

LISTED ARTICLES

  • Most Read
  • Most Commented
  • Editor’s Picks

Gradually, Then Suddenly: The Death Throes of a Regime

25 July 2025
by Dr David McGrogan

Oh-So Biased Public Broadcasting

26 July 2025
by Dr James Allan

News Round-Up

27 July 2025
by Will Jones

The Frightening Cost of Net Zero

26 July 2025
by Paul Homewood

Solar Panel Fault Known a Year Before School Fire

26 July 2025
by Will Jones

Ozzy Osbourne, Oasis of Heavy Metal

34

The Frightening Cost of Net Zero

29

Oh-So Biased Public Broadcasting

17

News Round-Up

12

Solar Panel Fault Known a Year Before School Fire

11

Hate Crime Okay, If Not by a White Man?

27 July 2025
by Laura Perrins

Gas is Dirt Cheap. Only Politicians Make Energy Expensive

27 July 2025
by Ben Pile

Ozzy Osbourne, Oasis of Heavy Metal

26 July 2025
by James Alexander

Oh-So Biased Public Broadcasting

26 July 2025
by Dr James Allan

Is the US Losing the World to China?

26 July 2025
by Noah Carl

POSTS BY DATE

May 2021
M T W T F S S
 12
3456789
10111213141516
17181920212223
24252627282930
31  
« Apr   Jun »

SOCIAL LINKS

Free Speech Union

NEWSLETTER

View today’s newsletter

To receive our latest news in the form of a daily email, enter your details here:

POSTS BY DATE

May 2021
M T W T F S S
 12
3456789
10111213141516
17181920212223
24252627282930
31  
« Apr   Jun »

DONATE

LISTED ARTICLES

  • Most Read
  • Most Commented
  • Editor’s Picks

Gradually, Then Suddenly: The Death Throes of a Regime

25 July 2025
by Dr David McGrogan

Oh-So Biased Public Broadcasting

26 July 2025
by Dr James Allan

News Round-Up

27 July 2025
by Will Jones

The Frightening Cost of Net Zero

26 July 2025
by Paul Homewood

Solar Panel Fault Known a Year Before School Fire

26 July 2025
by Will Jones

Ozzy Osbourne, Oasis of Heavy Metal

34

The Frightening Cost of Net Zero

29

Oh-So Biased Public Broadcasting

17

News Round-Up

12

Solar Panel Fault Known a Year Before School Fire

11

Hate Crime Okay, If Not by a White Man?

27 July 2025
by Laura Perrins

Gas is Dirt Cheap. Only Politicians Make Energy Expensive

27 July 2025
by Ben Pile

Ozzy Osbourne, Oasis of Heavy Metal

26 July 2025
by James Alexander

Oh-So Biased Public Broadcasting

26 July 2025
by Dr James Allan

Is the US Losing the World to China?

26 July 2025
by Noah Carl

SOCIAL LINKS

Free Speech Union
  • Home
  • About us
  • Donate
  • Privacy Policy

Facebook

  • X

Instagram

RSS

Subscribe to our newsletter

© Skeptics Ltd.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Articles
  • About
  • Archive
    • ARCHIVE
    • NEWS ROUND-UPS
  • Podcasts
  • Newsletter
  • Premium
  • Donate
  • Log In

© Skeptics Ltd.

wpDiscuz
You are going to send email to

Move Comment
Perfecty
Do you wish to receive notifications of new articles?
Notifications preferences