What the UK Government gets wrong about QR codes


A leaflet for Childcare with a prominent QR code.

One of my most memorable experiences in the Civil Service1 was discussing link shortening services with a very friendly2 person from the Foreign and Commonwealth Office. I was trying to explain why link shortners like bit.ly and ow.ly weren't sensible for Government use. They didn't seem to particularly care about the privacy implications or the […]

Continue reading →

Are we 'appy about change?


Advert which says "Fancy working with us on the first GOV.UK mobile app? These Android developer roles are exciting..."

Shortly before I left the Civil Service in 2023, I made a complete fool of myself. Someone on Slack was discussing their department's app and I (rather snidely) asked why it was an app rather than a website. After all, one of the seminal blog posts of GDS was about not building apps. In response, […]

Continue reading →

Weeknotes: fin. (So what did I accomplish?)


Photo of Terence presenting. The background has the NCSC logo.

I hate being introspective. But I'm told it's good for me. A few months ago, I handed in my notice to Cabinet Office. And now I'm no longer a Civil Servant. It's hard to sum up those 2,462 days. Every day brought new challenges. I saw my work presented to the highest offices in the […]

Continue reading →

When GOVUK is NSFW


I don't particularly like picking on the security of Government websites. I do it a lot - but I always feel guilty about besmirching the good name of the many talented people who work in the Civil Service. Today's flaw, however, is a particularly basic mistake which simply shouldn't be allowed to happen by any […]

Continue reading →

A Complete List of Every UK Government Domain Name


The GOV.UK logo.

Eight years after I published this blog post, I helped officially release all these domain names as open data! Funny how life works out, eh? Would you like to know every domain name the UK Government had registered? Of course you would! There could be all sorts of interesting tit-bits hidden in there (ProtectAndSurvive.gov.uk? EbolaOutbreak2017.nhs.uk? […]

Continue reading →

How I Got The UK Government To Adopt ODF


Screenshot of a Gov.UK page which says Using Open Document Formats (ODF) in your organisation.

Well, it's not often I get to completely influence the UK Government's approach to open standard. GOV.UK is adopting .ODF as their official document standard! All documentation will be also made available in HTML & PDF. Sweet! Yeah, yeah, so I only played a small part in the (no doubt) hideously complicated process - but […]

Continue reading →

The Unsecured State Part 5 - Abandoned Inquiries


This is part 5 of a series of blog posts looking at the security of the UK Government's web infrastructure. The primary cause of the vulnerabilities I've exposed over this series is abandonment. In a flurry of excitement a website is commissioned and created. Then, as time wears on, people begin to drift away from […]

Continue reading →

The Unsecured State Part 4 - UK Government Websites Spewing Spam


This is part 4 of a series of blog posts looking at the security of the UK Government's web infrastructure. Over the last few days, I've shown that hundreds of websites run by branches of the UK state are in a perilous state of disrepair. There are multiple sites with hugely embarrassing XSS flaws, running […]

Continue reading →

Should GOV.UK Run A Bug Bounty?


Cyber Security is of vital national importance. As the United Kingdom places more of its infrastructure onto the Internet, bugs and glitches go from minor inconveniences to full scale national emergencies. Suppose, for a moment, that a hacker were to interrupt payment processing for banks, or tamper with the UK's water supply, or cut off […]

Continue reading →