Live data from Hacker News

Massive data leak in New Zealand government servers

publicaddress.net

31–39 of 39 posts

Re: Massive data leak in New Zealand government servers

#31
post #11

I'm glad so far the government haven't mentioned bringing charges against the author yet. That probably shows you how much I expect from government these days...

That was my first thought, sadly many other governments would never be as close to open as this in all compass directions of the World. So kudos to the NZ goverment upon that aspect.

Re: Massive data leak in New Zealand government servers

#32
post #14

This is easily the biggest databreach that I have ever seen. I sincerely hope no one noticed this before, this has the potential to have a severe impact on so many lives in New Zealand.

Sadly you can imagine less honest user would of found this and not alerted anybody of athourity. The level of security being ustilised is at a level that how many years was it like this as it has been that secure since then sadly.

Many people also may have less respectful governments with regards to being alerted to this and could even end up charging you. Some even have laws against even checking if its is secure as it would be deemed hacking a govermental server. When you have that type of law then you can only imagine at the security in some of the offices. You hope they have good security staff and pentesters. This is clearly not the case with this oversight. It is beyond schoolboy error level even of security.

Still least in other countries they just leave all that data on a USB stick, so in that it is had to guage how much data leaked in comparision to others. But the opertunity is large and covers areas that can and could of caused alot of damage.

Re: Massive data leak in New Zealand government servers

#33
post #30

Earlier quoted context omitted.

The health data base is very well protected from what I know. And access is strictly monitored. If patient notes are viewed by someone who does not need to view them, they face harsh discipline. I recall a case from when I used this database a long time ago. In terms of high profile issues with it, the current eel-in-arse story is going to result in action and this is being done via the systems user tracking. http://…

If they are monitored and if unauthorized access is prevented by "harsh discipline". then they are not protected. Protection is proactive not reactive.

There are always reasons why unauthorized access may be needed (or, to phrase it better: where authorization should be dynamically extended), however. For instance, if a patient arrives in the ED, then a doctor who has never treated them before and normally should not have access to their records, may need to view them. So long as access is audited correctly, then the issues involved are mitigated.

FWIW, "eel case" aside, I know of clinicians being unceremoniously sacked for breaching patient privacy; and I know of NZ hospitals hiring staff to monitor the audit logs on a daily basis. It's a very big deal, and something that a lot of work is put into getting right.

Re: Massive data leak in New Zealand government servers

#34
That is entering the realm of criminal negligence.

This is not a simple data breach, there is stuff in there covering fraud investigations, suicide attempt documentation. This has got to be the most wide-ranging privacy cock-up I have ever heard of

Plus if this was accessible from a kiosk I HIGHLY doubt they properly segment this information internally either

A large number of heads (Including those going up the chain, supervisors, auditors, privacy managers) should roll over this one.

Re: Massive data leak in New Zealand government servers

#35
post #17

Wow, Active Directory Much? There's so many ways to do this correctly using simple groups in AD. Or hell, why do these public kiosks even need to be on the same network?

Why would a public kiosk even be running a consumer OS? They should be running a bare-bones OS with EVERYTHING not necessary to perform their intended functions removed. AND be on their own network. Why are power plant (and other similar) control systems in any way accessible by the internet? Why are credit-card processor internal networks in any way accessible by the internet? Answer: because it's what happens by de…

Because using some bespoke OS costs a fortune and accomplishes nothing.

Windows is more than capable of providing a secure environment for this sort of thing. Wat you're looking at is some shoddy work that was probably done by some contractor years ago.

Re: Massive data leak in New Zealand government servers

#36
post #14

This is easily the biggest databreach that I have ever seen. I sincerely hope no one noticed this before, this has the potential to have a severe impact on so many lives in New Zealand.

It's actually quite scary to read the comments on TFA and see that indeed, people did know about this breach.

Re: Massive data leak in New Zealand government servers

#37
post #8

Having physical access to the network shouldn't (in a better world) result in such an utter compromise. With the ability to plug in devices like the Pwn Plug; your network needs to be moderately resilient to attacks from inside.

Agreed. In fact I would go as far to say that All systems should be deliberately connected to a network physically accessible from the outside world. That way you cannot hide behind the assumption that you have not inadvertently connected.

All security layers have to be based on what you are allowed to do. Cutting abilities in a non-privilege-restriction manner is just asking for people to figure out another way to get through.

Re: Massive data leak in New Zealand government servers

#38
post #16
post #9

Earlier quoted context omitted.

Because we're living in an alternate universe where there's no such thing as VLANs?

True, I we use a MAC Filter at work. If your MAC isn't in a whitelist, then the port get blocked. They took the file sharing a bit too seriously..

Except for MAC filters aren't relevant to this situation at all. Private VLANs, however, are.

A VLAN would keep these computers on their own network, and firewalls could be set up on the network side to prevent this stuff from happening.

A MAC filter would do nothing in this situation, because you are using their computer. Even if you had a MAC filter, these computers would be white-listed anyway.

Re: Massive data leak in New Zealand government servers

#39
post #22

Once it was clear that there was was a leak of confidencial information, he should have taken what was required as minimal evidence (a few screenshots?) and then contacted the Acting Privacy Commissioner. Did he really need to go through files related to Doctors/Radiology, Debt Collectionn, Fraud Investigations, Care and Protection, HCN? Snooping through the servers beyond what was necessary was wrong. The bigger sto…

I thought same thing, but read more and realized it was open for awhile, and no one seem to care. It took the breath of his examples to make everyone shock enough to notice.

The only thing that should be illegal is the way all that information was not secured.

Post reply on HN