Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Exclusive: Crimestoppers anonymous reporting website contains no SSL

by The Gurus
February 12, 2015
in Editor's News
Share on FacebookShare on Twitter

A website designed to allow anonymous crime reporting contains severe security flaws, including a lack of secure transmission of data.
Launched by Crimestoppers, Fearless is described as “a site where you can access non-judgemental information and advice about crime and criminality”. It says that what makes the site different is that it provides a safe place to give information about crime, 100 per cent anonymously.
It says: “Anonymous means you don’t have to give your name, where you live or any personal details. Calls aren’t recorded or traced; we can’t track where online forms are from; you won’t have to give a statement, you don’t have to go to court. Just tell us what you know, not who you are.”
However despite promising the ability to anonymously report crime, IT Security Guru has been informed of major flaws in the website that would allow traffic to be monitored.
Speaking to IT Security Guru, penetration tester Robin Wood pointed at the “Secure Online Form” which is not secure, as there is no certificate on the site. Also on the donate website he said that there is an HTTP link to Crimestoppers, but that then bounces over to the HTTPS version of the site.
Wood also looked at the privacy page, which explained how to clear caches on Firefox 2.0.0.9 and IE7, but had no mention of iPhone, Android or Chrome browsers. “It is as though the page has been written by someone who pulled these from other old sites and dropped them on the page without really understanding what they mean,” he said.
Andrew Barratt, European managing director of Coalfire, told IT Security Guru that it is an example of bad practice somewhere, and that it looks like it has probably just been put together by a small web design company with limited experience.
He said: “For anonymous information to really be captured, someone would have to be snooping on the user – my bigger concern would be that it is likely any evidence/leads submitted would probably be inadmissible in court as it could easily be demonstrated to have been tampered with.”
Wood doubted that if a court would accept evidence from an anonymous person, and also doubted that the court would worry about tampering. “Realistically, the people submitting issues over this and the people they are submitting them about are not going to be to technical, so sniffing and tampering isn’t likely to be an issue,” he said.
Roger Critchell, Crimestoppers director of operations, said in a statement to IT Security Guru that it is aware of a technical issue with the Fearless website, and was making it a priority to rectify this.
He said: “Protecting the identity of those that wish to submit anonymous information to us is paramount, so we can assure you the correct measures are being taken to ensure the website is 100 per cent secure.”
Jon Baines, chair of the National Association of Data Protection Officers (NADPO), told IT Security Guru that he suspected that a section of the public do know that HTTP or the padlock symbol provides a level of security, and would spot its absence in an online commercial transaction.
“But a large section of the public still don’t know that, and, furthermore, a charity like Crimestoppers engenders a level of trust which might mean people would be less alert to a potential lack of security,” he said.
“I do think this is one of the most concerning examples of poor security that I’ve seen. The site looked like it was knocked up as someone’s project ages ago but it was still inviting people to transmit, over what appears to have been a very insecure connection, highly sensitive information.”
In an email to IT Security Guru, a spokesperson for the Information Commissioner’s Office (ICO) confirmed that that it had been made aware of a possible data breach involving the Crimestoppers’ website Fearless. “We will be making enquiries into the circumstances of the alleged breach of the Data Protection Act before deciding what action, if any, needs to be taken,” a spokesperson said.
“The need for secure encryption when handling sensitive personal information was recently highlighted in our IT security report under the chapter on the configuration of SSL and TLS.”

Tags: HTTPSPoliceSSL
ShareTweet
Previous Post

Anthem: company says five employee's credentials phished and used

Next Post

Facebook opens ThreatExchange to share information wider

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol