These semi-government companies simply does not care about these things...
 
POPI is not in effect yet (but then there are so many exclusion in POPI wrt government, no-one will be accountable). But seeing that House is here and soon Paul is going to stick his head in, the one question I always wanted to ask:

I think last year there was a concourt case where Mail & Guardian was sued to reveal it's sources and the concourt agreed with the SCA decision. So now we know press-freedom in the traditional sense (newspaper), would this then also mean that no subpoena could be issued against MyBB to reveal sources of security leaks (provided that MyBB would challenge a subpoena - or can this not even be done)?
 
No unfortunately not.

However, when it comes to Bombela, I am 100% sure that the act will not apply to them as well. :whistle:

Something tells me that dev company is going to see less business after this. To not have taken the site down immediately after being contacted by MyBB is completely unacceptable.
 
POPI is not in effect yet (but then there are so many exclusion in POPI wrt government, no-one will be accountable). But seeing that House is here and soon Paul is going to stick his head in, the one question I always wanted to ask:

I think last year there was a concourt case where Mail & Guardian was sued to reveal it's sources and the concourt agreed with the SCA decision. So now we know press-freedom in the traditional sense (newspaper), would this then also mean that no subpoena could be issued against MyBB to reveal sources of security leaks (provided that MyBB would challenge a subpoena - or can this not even be done)?

Any court can issue a subpoena against any broadcasting media to reveal their sources if this is being done in the interest of justice. However, they can challenge the request and the judge can make a decision.

The M&G case does not give blanket cover to broadcasting entities to withhold identities of sources. In some circumstances courts may still well compel them to disclose the information.
 
Updated the article with a statement from Errol Braithwaite, executive at the Bombela Concession Company.

Bombela Concession Company said:
We have engaged with the sub-contractors who developed and maintain the site and will revert to you with a full response as soon as it is available. In the interim we have insisted that the site is immediately quarantined with no public access until it's security is fully verified.

At this stage it is still unclear what the exact nature of the problem was and whether the site was the subject of a cyber attack.

We have requested an urgent report on whether anyone’s personal data integrity was in fact compromised. What we do know is that no ones personal data stored on their Gautrain Gold Cards has been compromised or altered in any way.
 
Seeing that MyBB has received information about the leak, it should be fairly easy for Jan to validate if it was OWASP-A4 or not as it is the most obvious mistake any inexperienced developer will make: https://www.owasp.org/index.php/Top_10_2013-A4-Insecure_Direct_Object_References

FWIW: I think the Gautrain is probably the best managed government project so far (all things considered: e-Toll, electricity, health-care)
 
Last edited:
Site is now tango down and with the default Microsoft Information Services (IIS) page.
 
Another excellent article/thread. Nicely done!
 
Updated the article with a statement from Errol Braithwaite, executive at the Bombela Concession Company.

Jan, please ask Errol Braithwaite to clarify the purpose of the GautrainCard.co.za site.

I suspect that GautrainCard.co.za is a site used to apply for a Gautrain Gold Card that is registered in the sense that one's identity is associated with the card and can be replaced if lost or stolen and any funds / remaining trips carried over to the replacement card. Whereas the normal Gautrain Gold card one can purchase at the local Spar etc is not registered and cannot be replaced with the option of carry-over.
 
Top
Sign up to the MyBroadband newsletter
X