Gordon Campbell | Parliament TV | Parliament Today | Video | Questions Of the Day | Search


Labour alerts Justice Ministry to gaping security hole

Communications and IT Spokesperson


Labour alerts Justice Ministry to gaping security hole in its website
Labour’s Information Technology spokesperson, Clare Curran, has today alerted the Ministry of Justice of a serious security flaw in its website.

The vulnerability leaves the personal and financial details of tens of thousands of New Zealanders potentially exposed, and might allow a malicious person to redirect payments to and from members of the public.

“This is a very serious matter. This is yet another gaping hole in the security of a major government site, with privacy and financial implications for a huge number of people,” says Clare Curran.

The security flaw allows access to Ministry of Justice passwords and databases, via a publicly accessible search engine on its website.

“The Ministry of Justice holds incredibly sensitive data – including information about the victims of crime. The Government has a fundamental duty to protect that information. This flaw, if exploited, could have a devastating effect on thousands of people.

“Earlier today I wrote to the Ministry of Justice, the Minister Judith Collins and the Privacy Commissioner alerting them to the issue, which must be addressed urgently.

“This matter was brought to my attention by a whistle-blower. That person has agreed to help the Ministry of Justice in any way they can to ensure the security flaw is fixed.

“This is the latest in a disturbingly long line of information technology security flaws and privacy breaches. There is clearly a major systemic problem with IT security.

“In the past two years more than 100,000 Kiwis have had their privacy breached by government agencies, including the ACC, MSD, IRD and EQC. This is an issue of public trust and confidence in government systems.

“The National Government needs to treat this matter with the seriousness it deserves, and stop hiding behind human error as an excuse for not protecting people’s private information,” says Clare Curran

Ministry of Justice security flaw Q and A

What is the nature of the security flaw?
The flaw allows access to what appears to be Ministry of Justice databases covering licences and fines. Those databases would likely include the personal details of many victims of crimes.

Access to the page containing passwords for the databases was found via a publicly accessible part of the Ministry of Justice website.

How serious is this vulnerability?
This is a serious flaw. The passwords were contained in a plain text file, and those passwords could be used to access incredibly sensitive information, and could potentially allow someone to alter fines payments and financial records.

The MoJ website is very vulnerable to anyone who is serious about trying to break into it. The MoJ website’s security is nowhere near an acceptable standard.

Potentially how many people’s information is at risk because of this problem?
That is not clear. But the databases in question could include information about people that the Courts have imposed a fine upon, and any victim of crime that is receiving reparations. At the very least the databases also hold the details of those with licences issued by the Ministry of Justice.

How did Clare Curran become aware of the issue?
Clare Curran was contacted by a concerned member of the public, who identified the vulnerability. That person contacted her in the hope that she could help expose the problem and get it fixed.

The whistle-blower did NOT access the Ministry databases, but did view the plain text file that contained the passwords. This confirmed the seriousness and extent of the security issue. This file has been passed on to the Ministry of Justice.

Clare Curran will not be publicly identifying her source, but they have agreed to help the Ministry of Justice to address this problem.

© Scoop Media

Parliament Headlines | Politics Headlines | Regional Headlines



Australia Deportations: English Relaxed On Immigration Centre Conditions

Labour's Annette King: “There have been numerous reports from inside these detention centres on just how bad conditions are... If they were being held in any other foreign jail, I imagine Mr English would be somewhat concerned. More>>


Schools: Achievement-Based Funding Would Be A Disaster

The Education Minister’s speech to the PPTA Conference raising the spectre of achievement data driving a new funding system would be disastrous, says NZEI Te Riu Roa. More>>

  • Video Out-Link - PPTA Annual Conference 2015 on Livestream (Q+A dicussion suggests funding would be directed to less successful schools.)

  • ALSO:

    ECE Report:

    Key In NY: Prime Minister Addresses United Nations

    Prime Minister John Key has addressed the United Nations General Assembly in New York, focusing on a call for action in Syria and on other conflicts, reform of the veto process and on the UN’s Sustainable Development Goals. More>>.


    Gordon Campbell: On The Lack Of Accountability Over Philip Smith

    In New Zealand, accountability is an exotic creature rarely glimpsed at ministerial level, or among senior management. The flight to Rio by the paedophile /murderer Philip John Smith/Traynor is no exception. More>>


    More On Corrections

    Gordon Campbell: On Putin’s Diplomatic Coup Over Syria

    There’s a simple historical precedent for what is occurring in Syria. During WWII, the Allies joined forces with a known butcher and tyrant – Joseph Stalin of the Soviet Union – in order to defeat a greater evil, Nazi Germany… More>>


    Key 'Didn't Know': Brownlee Seeks Pandas In China

    While Defence Minister Gerry Brownlee is in China pushing a taxpayer funded deal to bring two pandas to New Zealand, the country’s military look set to be hit with a pay freeze, Opposition Leader Andrew Little says. More>>


    Scoop Business: GCSB Willing To Extend Cyber-Attack Programme To Local ISPs

    The Government Communications Security Bureau’s ‘Cortex’ cyber-security programme has been successful in helping identify and mitigate a series of cyber attacks since its introduction and an extension to cover local internet service providers is still on the cards... More>>


    Get More From Scoop



    Search Scoop  
    Powered by Vodafone
    NZ independent news