Website security flaws in SA: why shoot the messenger?

House, do you see the trend? No one believes you. No one respects you.

Loser. (Or as you would spell it Looser.)
 
Is the guy/gal investigating competent at least?

If you are asking about the CoJ IO, then my impression (based on the 30 minutes I had with my legal team and him during the issuing of the warning statement back in September) that he is well equipped to investigate complex issues. Related to our bidorbuy business we have frequent interactions with the CCU (recent Woza issue as well as another big unpublished issue which will make headlines this year) and I always felt that CCU officers lack the sophisticated equipment "cyber inspectors" should have and despite that seem to be able to do their jobs really well.

It is very evident that the commercial crimes unit seems to be underfunded and understaffed and I have always wondered if this was intentional (i.e. if you provide the CCU with sufficient resources this might lead to more in depth investigations and could compromise government even more - the collapse of the Scorpions?). My impression of the members of the Hawks was always that despite trying to be impartial, they have massive political pressure to investigate (Mdluli / Breytenbach come to mind) but still somewhat need to try and comply with the laws of the country.

I can't repeat what the IO said to us during the meeting, but I have deep respect for the work they do and the challenges they face. I think the same can be said about the NPA. It is unfortunate that both entities have to bend under the political pressure such as from the CoJ, Sanral or ANC.

Since neither the IO or prosecutor has answered phone-calls, emails and even faxes, our legal team will try and pay them a visit tomorrow - should anything of interest surface, I will post an update on MyBB. At the moment there is nothing anyone can or should do. I do ask myself why in situations of gross negligence such as CoJ or Sanral or blatant corruption across government organisations neither the public protector, consumer bodies/watchdogs or industry bodies or at least opposition parties are doing anything about it (it seems they are not even willing to ask questions) - perhaps "it's too much effort"?
 
I do ask myself why in situations of gross negligence such as CoJ or Sanral or blatant corruption across government organisations neither the public protector, consumer bodies/watchdogs or industry bodies or at least opposition parties are doing anything about it (it seems they are not even willing to ask questions) - perhaps "it's too much effort"?

They can't stand the heat. It may be better if they get out of the kitchen, because they cannot make any contribution under these circumstances.
 
And that was exactly what lead to criminal charges being laid and will count as aggravating circumstances if a trial should ever occur.

Take a look what happened with the AT&T hacker who also found a vulnerability and decided to go to the media - http://nakedsecurity.sophos.com/201...-troll-weev-appeals-41-month-prison-sentence/

There is a right way and a wrong way of doing things.

Thula wena!

Security via obscurity is fscked up.

People have a right to know. Companies generally don't a fsck when it comes to customer security. Compare response times for security breaches between open source software and proprietary software for example. MS, Cisco, Oracle etc would rather sue you and try to shut you up for exposing their flaws, it's a really backwards approach to security.
 
And a misquoting a wilful refusal to disclose all material findings in the Weeve matter kicks in
the US courts SPECIFICALLY found that mere URL access did not constitute unauthorized access and conviction could only be secured by persons who had intended to access by circumventing authentication mechanisms - once it is proved that somebody would continuously access a system without authorization the fact that in any given instance there was unknown to the accessor authorization you could secure a conviction.

At least 20 guys simply deposed an affidavit that they were testing the AT&T system for authorization when authorization was declined they did not proceed forward - "looking for an unlocked door" as they called it and the FBI settled and compensated them for the loss of earnings incurred in police questioning.
 
Because the human race has become pathetic pitiful sorry excuses for human beings, crying about every little thing.
Mommy he call me a pig, okay Johnny we will sue his ass. PATHETIC
 
Thula wena!

Security via obscurity is fscked up.

People have a right to know. Companies generally don't a fsck when it comes to customer security. Compare response times for security breaches between open source software and proprietary software for example. MS, Cisco, Oracle etc would rather sue you and try to shut you up for exposing their flaws, it's a really backwards approach to security.

MS is never impressed when flaws are made public. Some flaws have been posted and MS has had to quickly respond to the issue before it was more widely used. Many hackers had used the flaw before it was fixed. MS was pissed, didn't push for a lawsuit though.

Publicly publishing flaws is a double edged sword. It creates urgency and forces the company to take action fast. It also potentially puts other's data at more risk. Note that it is more risk and not creates risk. The fact of the matter is that there are non-public forums where this kind of information is traded as well and if it was posted publicly in one place, it most likely had already been posted in a hacker forum.

What our esteemed government doesn't realise is that by discouraging public action, they are helping the malicious users instead of the standard ones.
 
MS is never impressed when flaws are made public. Some flaws have been posted and MS has had to quickly respond to the issue before it was more widely used. Many hackers had used the flaw before it was fixed. MS was pissed, didn't push for a lawsuit though.

Publicly publishing flaws is a double edged sword. It creates urgency and forces the company to take action fast. It also potentially puts other's data at more risk. Note that it is more risk and not creates risk. The fact of the matter is that there are non-public forums where this kind of information is traded as well and if it was posted publicly in one place, it most likely had already been posted in a hacker forum.

What our esteemed government doesn't realise is that by discouraging public action, they are helping the malicious users instead of the standard ones.

Precisely - companies may not like it when their vulnerabilities are exposed but believe me, they're damned grateful to be made of the aware of the fact.

Repeat after me, "Bad hackers don't tell the world that they've discovered a vulnerability, they steal the data and then sell it and/or cause havoc (PSN, Steam)"

Can the CoJ and SANRAL please get that into their heads. Please.
 
@MagicDude4Eva: If you had to do it over, would you still report the flaw, report it anonymously, or just keep it to yourself?

In other words, what's your advice to someone who finds a security flaw in a public system, and doesn't have the lawyers/time/money to get tangled up in the "hacking conspiracy"?
 
The world is fast heading to a point, where the people in the street will not need or want the politicians anymore. Governments are mostly useless, ignorant, sef serving and stuck in the past.

"A teenager in Australia who thought he was doing a good deed by reporting a security vulnerability in a government website was reported to the police."

http://www.wired.com/threatlevel/2014/01/teen-reported-security-hole/?cid=16836844
 
@MagicDude4Eva: If you had to do it over, would you still report the flaw, report it anonymously, or just keep it to yourself?

In other words, what's your advice to someone who finds a security flaw in a public system, and doesn't have the lawyers/time/money to get tangled up in the "hacking conspiracy"?

Especially having it discussed with my legal team and looking at the chain of events, I would not do anything different. Although a potential court-case will be the result of it, I do think that in the end it has achieved what I had intended - i.e. stop the leak of rate-payer information. The CoJ was already alerted to this issue on the 13th August and then again by myself on the 20th August. If you look at all the events you will notice that CoJ demonstrated sheer arrogance and ignorance and refused to even listen to the issue. The user reporting it on 13th of August never received a response, I received an email response from the CoJ 6 days (!) after my report which read: "Good day value customer, we are aware of that and IT is working on that".

The information exposed was in the public domain since 2012 (for more than 12 months) prior to my discovery (as well as the discovery of another MyBB user before me). I tend to believe that other people might have alerted the CoJ prior to this, but remained quiet due to the fear of facing prosecution.

My legal team and I are of the firm belief that nothing criminal has been done and as such will defend the accusations of the CoJ in a criminal and/or civil matter to ensure that those allegations are cleared up for good. As a municipality, the CoJ has the obligation to provide us rate-payers with the appropriate service (refuse, electricity, water, billing, road infrastructure etc) and the "big shots" in the CoJ tend to forget that they are actually servants of us and only have a job because we pay rates and taxes. As such it is a reasonable expectation from all of us to provide a service with honesty and integrity, which the city officials and their IT service providers have not done to date.

It comes as no surprise that the city is facing it's 4th (!!!!) qualified audit - this means the city has not been able to properly balance it's books and account for money received by rate payers. If you are incapable of managing your finances how do you think anything else will be managed?

So in short, I would not do anything different, as I had exhausted all avenues prior to releasing the information. Unlike CoJ maintained, there was no malicious intent and the information was accessible for years and you can be certain that this information has been sold on for a long time. I also believe that should the CoJ see a court date, that it will not just remain in the magistrate's court, but will result in the ECT being challenged.

Unlike some "law experts" on this forum, we have a fairly good understanding of the ECT act and to date no person was ever convicted based on ECT 86.1 (un-authorised access). House tends to refer to the only ECT case (Douvenga where the accused stole customer data and sold it to the competition) in SA as a precedent, which it is not. The most recent reference is to the Weev case (search for AT&T hacking) who, when properly researched was convicted based on a number of technicalities as part of the CFAA (similar to Aaron Schwarz who eventually committed suicide).

Also, important to note is that FUD is spread about going to prison for ECT 86.1 and to be honest, the maximum charge is no worse than being convicted for drunk driving - so as bleak as some make it out to be, even if the legal system fails you completely and you get convicted across all courts and appeals fail you will in the best case get away with a suspended sentence/fine and in the worst case sit in prison for 3 months.

While my legal defense will eat a deep hole into my savings, I do believe it was the right thing to do. My advice to anyone else: I would continue making it public. Doing it anonymous will not keep you safe from possible malicious/vindictive prosecution - you will see this with Sanral - they will probably issue subpoenas against MyBB, Google (for Youtube and G+) to establish who Moe1 is and perhaps he was good as hiding his true identity, but to be honest as a citizen trying to improve our public service or corporate governance, we should not have to hide out of fear for being prosecuted for trying to highlight and fix an issue.

I am not sure if Moe1 tried to alert Sanral, but from my insights the flaw was already tested beginning of December and it is very possible that Sanral was alerted and aware of it, but similar to CoJ chose to ignore it.

I do think that this country needs a governance body which allows citizens to report issues which are then promptly addressed. We have public protector, CPA and a number of other bodies pretending to be that, but they are incapable to do this - so as a last resort sometimes drastic measures such as going public is necessary.

BTW: It is really unfortunate how amateurish the media reports on incidents like that. Issues like CoJ or Sanral are not of highly complicated technical nature and impossible to explain, but yet, the news media is unable to report in a balanced manner.
 
Great post MD4E!

We need more people like you to inspire us to not fear the FUD, and to do the right thing.
Very inspirational considering how SA is coming apart at the seams and the only thing that will help us through it all is the promotion of basic human good.
 
The simple fact of the matter is that one cannot apply laws selectively.

You cannot be like a bunch of headless chickens running around shouting at government 'protect our data online, protect our data online' and when a law is in place, and someone you know breaks it shout 'Don't charge him, don't charge him, unjust law, unjust law, stupid law, stupid law'...

Sounds like a bunch of *** supporters.....
 
A theoretical question if I may.

Lets say I had an account on the CoJ's site and I discovered that there was a potential security risk, exaclty the same way as it happened recently and listed above.

The difference being is that I access my own personal details without my login and highlight that to the goofballs at CoJ, what are they going to do, open a case against me for hacking my own account or data?
 
Top
Sign up to the MyBroadband newsletter
X