Reply to post:

TalkTalk attack: 'No legal obligation to encrypt customer bank details', says chief

jonathanb Silver badge

Encryption is only effective if the key is secure. If the system needs access to the data so that customers can view their accounts and change those details they are allowed to change, for example the bank or card they want to use to pay their charges, the billing system can allocate charges to the correct place, and the collection system can collect the money every month, I'm not convinced that encrypting the data would help that much.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Biting the hand that feeds IT © 1998–2021