NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business

Juha Saarinen: Security flaw alleged in Census website

Juha Saarinen
By Juha Saarinen
Tech blogger for nzherald.co.nz.·NZ Herald·
24 Apr, 2018 10:00 PM5 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

The issue stems from Stats NZ using a third-party provider, Incapsula, to act as a protective gateway into its network and servers. Photo / Bevan Conley

The issue stems from Stats NZ using a third-party provider, Incapsula, to act as a protective gateway into its network and servers. Photo / Bevan Conley

Juha Saarinen
Opinion by Juha Saarinen
Tech writer for NZ Herald.
Learn more

Despite official assurances that New Zealanders' sensitive personal information given to the mandatory Census 2018 is safe and secure, researchers say they have found a critical flaw in how Statistics NZ set up its website.

This not a data breach, University of Melbourne IT security researchers and cryptographers Drs Vanessa Teague and Chris Culnane told the Herald. There is no suggestion there was unauthorised access to the Census 2018 data, they said.

The issue stems from Stats NZ using a third-party provider, Incapsula, to act as a protective gateway into its network and servers. Incapsula protects other government servers and networks too, such as those belonging to the Government Communications Security Bureau.

Teague and Culnane say that when NZers filled out the Census online, it looked like they were connected to the Stats NZ servers, when they were not.

Instead, people connected to the Incapsula gateway, which a network trace showed is hosted in a data centre in Albany.

Advertisement
Advertise with NZME.
Advertisement
Advertise with NZME.

Connections to Incapsula are done securely through the open standard Transport Layer Security protocol that identifies the server people's computers connect to, and sets up encryption of the data transmitted over the internet. Incapsula operates a TLS proxy, a network device that terminates the connection before it reaches the Stats NZ server, and decrypts the received traffic.

It is done to inspect the traffic so as to remove malicious content such as bots and denial of service attacks.

Once that's done, Incapsula passes on the legitimate traffic to Stats NZ's Census responses collection server.

However, to inspect the traffic, Incapsula decrypts it and the United States-based company is able to see New Zealanders' Census question responses, Teague and Culnane pointed out. Privacy and lack of transparency are at play here.

"The TLS Proxy sees everything that is sent to Stats NZ, and so it has to be fully trusted to keep the data it sees both secure and private," they said. "It gives the false impression that data cannot be read whilst being transmitted to Stats NZ; that data cannot be decrypted by anyone other than Stats NZ; and that the user can be certain they are communicating with Stats NZ," they added.

Discover more

Business

Find out what Facebook knows about you

27 Mar 01:20 AM
Opinion

Juha Saarinen: iPad homes in on school sector

03 Apr 06:51 AM
Sport|rugby

Tech expert: Spark rugby coverage great deal, Sky dead in the water

15 Apr 11:00 PM
Opinion

Juha Saarinen: Getting online rugby ready for kick off

17 Apr 08:29 AM

"Any organisation like Stats NZ has a responsibility to provide accurate and sufficient information about their security so the public can make an informed decision about how they want to interact with government online," Teague and Culnane said.

Stats NZ chief digital officer, Chris Buxton, confirmed the agency uses Incapsula for the Census.

Advertisement
Advertise with NZME.

"Given the national scale of the Census and the experience of our colleagues in Australia during their Census in 2016, Stats NZ made the decision to work with an all-of-government approved supplier that could work at a global scale to block DDOS attacks on the census systems," he said.

Incapsula was not named by Stats NZ, and referred to as "a global web security system" and the provider's ability to decrypt and read the data is not mentioned either.

Incapsula's TLS proxy decrypts all the data sent to it for the Census, as it is required to examine and stop any malicious content that an attacker might try to use to compromise Stats NZ systems, Buxton said.

Adding to the researchers' concerns, Stats NZ's digital key that is required to decrypt the data sent over TLS secured connections is now distributed across Incapsula's global network, Teague and Culnane said.

"Our non-exhaustive search found that servers in Australia, the US, as well as New Zealand, all had the Stats NZ key," they added.

Digital TLS keys are supposed to be protected and should only be kept on the servers that they relate to, the researchers said.

Advertisement
Advertise with NZME.

If keys are leaked, attackers could use them to impersonate Stats NZ servers.

Buxton said that Incapsula can be trusted to hold the digital credentials to unlock the data.

"Incapsula is a government approved, global security provider, trusted to hold and protect the census private TLS key, and use it for the agreed purpose of ensuring that Census data was protected from malicious attack," he added. .

As for the keys being stored on servers overseas, Buxton said most of the Census data traffic was contained in New Zealand and Australia.

In some cases, households would use virtual private networking tunnels via other countries, and their data would have been routed to the closest server to them, he added.

"It was important that our security protection worked at global scale, so that we were able to defend attacks at the point where they originated without compromising our New Zealand internet systems. Having servers in these locations provided this defence," Buxton said.

Advertisement
Advertise with NZME.

The researchers labelled the practice of allowing the keys to be stored on servers outside of New Zealand jurisdiction as a "clear security flaw". They warned the credentials could be used to intercept any encrypted traffic intended for Stats NZ.

Teague and Culnane have reported the flaw to Stats NZ and told the Herald "they acknowledged what we said and appeared to understand the problem."

Buxton said the system for the Census was set up to mitigate a range of risks, including ransomware, malware and DDOS attacks.

Save

    Share this article

Latest from Business

Premium
Business

Court to decide Du Val asset seizure orders

16 Jun 08:07 AM
Premium
Shares

Market close: Tourism Holdings jumps 57.5% on buyout offer

16 Jun 05:55 AM
Premium
Business

Little Island, plant-based ice cream company that raised millions, in liquidation

16 Jun 04:00 AM

Audi offers a sporty spin on city driving with the A3 Sportback and S3 Sportback

sponsored
Advertisement
Advertise with NZME.

Latest from Business

Premium
Court to decide Du Val asset seizure orders

Court to decide Du Val asset seizure orders

16 Jun 08:07 AM

Du Val reportedly owes $306m to investors and creditors, according to PwC.

Premium
Market close: Tourism Holdings jumps 57.5% on buyout offer

Market close: Tourism Holdings jumps 57.5% on buyout offer

16 Jun 05:55 AM
Premium
Little Island, plant-based ice cream company that raised millions, in liquidation

Little Island, plant-based ice cream company that raised millions, in liquidation

16 Jun 04:00 AM
Premium
How worried should we be about economic fallout from the Israel-Iran conflict?

How worried should we be about economic fallout from the Israel-Iran conflict?

16 Jun 03:31 AM
Gold demand soars amid global turmoil
sponsored

Gold demand soars amid global turmoil

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP