No confidential data leaked in website hack, says SAPS

What Kuk....??? There people on this very forum who have been compromised!!!

???

MyBB??? Why don't you respond saying this guy is a liar!!! WTF???


No One Has Ballz anymore!!! Stand up to these pricks and submit your own damn PR!

<cough>

Article said:
Challenged on the clearly private information that was stored in the website’s database that has been made public, SITA general manager Daniel Mashao admitted that it was an oversight on their part.

eNCA, Sapa, and I all challenged their statement, after which SAPS and SITA were willing to go off script.

Which (as a sidenote) is more than many other government agencies are willing to do, in my experience.
 
So there is no way for them to trace false information back to you?

Nope. They don't record anything, specifically so that they can guarantee anonymity. Obviously I have two problems with that: a)False declarations and b)Threats [made by the sender] against the state, etc.
 
That's how they collectively referred to the data during the press conference: "confidential".

The opening line of the article has myBB stating that SAPS specifically used the words "confidential information" yet further down the actual SAPS statements are quoted with the words "criminal information or case information" which lead to some misinterpretation on my part I guess.

Which word would you have preferred we use?

"top secret" :p
 
"Classified" might also have been a better choice, in retrospect.

top secret > classified. Much more dramatic. I have classified information written on my fridge. Top secret stuff stays in my head.
 
Unless the Web server hosted confidential or classified info, which I [should] seriously doubt, then what would a hacker have gained? I would be very surprised, and disturbed, if the SAPS even had a link between systems hosting confidential/classified information and their web-hosting server.
 
Ngubane maintained that the information that was accessed was information that is published usually, or information that is made public on the website in any case.

um, yeah totally...

fine for the saps but not for those 16k people with their info leaked?
 
Here's the full press release for those interested, scanned and OCR'ed from the printed copy they handed out.

Press Release said:
MEDIA STATEMENT MEDIA STATEMENT ISSUED BY THE DIVISIONAL COMMISSIONER OF TECHNOLOGY MANAGEMENT SERVICES, LIEUTENANT GENERAL BONGINKOSI SOLOMON NGUBANE ALLEGED HACKING OF THE WEBSITE OF THE

SAPS At about 10:00 on Tuesday, 21 May 2013, the State information Technology Agency (SITA) informed the SAPS that the website of the SAPS had been breached and that information had been obtained unlawfully.

SITA hosts and manages the website of the SAPS separately from the rest of the corporate systems of the SAPS. For this reason, no criminal information or case information was compromised at all. In fact, the corporate systems of the SAPS are hosted in a building in the Pretoria CBD, while the website of the SAPS is hosted in the data centre of SITA in Centurion. They are, therefore, hosted in completely different buildings with no link between the two.

The SAPS can state that no case information or classified information was compromised as this information resides in the mainframe systems of the SAPS, which is hosted separately from the website.

The SAPS has made a facility available on the website where a person may log a request to be addressed by a specific station or division or merely give a compliment. The person may log the request either with a name and contact detail or anonymously, depending on his/her choice. The persons who submitted their names and contact details made it available in order for a representative of the SAPS to contact them. This list was also available for the people who hacked into the website.

SITA has since addressed the security on the above details.

Furthermore, the information that was accessed was the following;

o Information that is published usually, and
o Names and contact details of divisions and provinces, which is made public on the website in any case.

Hacking the website of the SAPS will always be a matter that the hacker community will strive to achieve and therefore the website of the SAPS and the corporate systems of the SAPS are hosted on completely different networks and therefore no corporate information of the SAPS will be compromised if and when the website is accessed unlawfully.
 
Ty for this. Adding it to my blog :D

Read your blog bout this SAPS debacle earlier. Twas very good.


@Jan, so can you tell us why they said about ID#, Cellphone Number, Home address leaked? This information is surely not published annually
 
Messed UP

They messed up

Never got the CHAMPAGNE Web Site designer guys from the Free State Premiers Office in to do their Web site and backend :whistle: ;)

BTW the Dept of Rural Development was also "hacked"
but
No one is saying much about it -- or what was taken -- or -- what was compromised ?
I do hear though that they are lined up for a complete web makeover and re-design

Maybe someone should look into that ?
 
Top
Sign up to the MyBroadband newsletter
X