NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business

Real cyber-security concerns for virtual Apec

Chris Keall
By Chris Keall
Technology Editor/Senior Business Writer·NZ Herald·
28 Nov, 2020 04:00 PM7 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Dutch journalist Daniel Verlaan (left, in T-shirt) causes mayhem as he gate-crashes a meeting of EU defence ministers earlier this month. Image / Twitter

Dutch journalist Daniel Verlaan (left, in T-shirt) causes mayhem as he gate-crashes a meeting of EU defence ministers earlier this month. Image / Twitter

There's prestige for New Zealand in hosting the first-ever virtual Apec meeting - which will bring together leaders from 21 Pacific rim countries, including China, the US, Singapore, Canada and Australia.

But cybersecurity security expert Daniel Ayers points out that there's also plenty of peril - something he barely needs to highlight after Dutch journalist Daniel Verlaan managed to gatecrash a meeting of EU defence ministers.

That ⁦@danielverlaan⁩ hack of the EU defence ministers' meeting? This is how it looked from the inside. Comedy gold. pic.twitter.com/1qvVYKsDpt

— Michiel van Hulten (@mvanhulten) November 20, 2020

The reporter didn't have to employ any hacking smarts. Rather, he simply spotted the PIN code for the meeting that was inadvertently included in a photo that Dutch Defence Minister Ank Bijleveld posted to Twitter.

Advertisement
Advertise with NZME.

Careful what you’re wishing ;-)
Former Minister of Public Safety in #Greece, also responsible for the Greek Intelligence agency he his password AND username on a post it note. Captured by the photographer of the interview 😂😂😂 pass:12345 user:minister (in 🇬🇷) pic.twitter.com/3u8pgfh9Np

— Sotiris (AiSK) 🇬🇷🇪🇺🇺🇸 🏴󠁧󠁢󠁳󠁣󠁴󠁿 (@skaragiannis) October 9, 2018

Local security expert Daniel Ayers says the Dutch politician's blunder was hardly unique.

A former Greek intelligence minister also apparently posted his user name and password to Twitter, via a Post-It note stuck to the corner of his screen - not that his user-name (minister) or password (12345) required too much cracking.

And during the falsely issued 2018 ballistic missile alert in Hawaii, an official was caught out by the same Post-It problem during a TV interview.

You say that but remember during the Hawaii missile alert they did an interview and there was just a password on a post it note in the back pic.twitter.com/VlbMFVpHxd

— Skeev (@Lord_Izen) January 3, 2019

Meanwhile, international security expert Dr Paul Buchanan says there are a number of scenarios that could, potentially, see China "do a Dutchman" and exploit weak videoconferencing security to make a political statement.

Apec (Asia-Pacific Economic Cooperation) meetings were due to be held in NZ this year, with dozens of lower-level meetings from December 2020 through to its culmination, a meeting of the 21 leaders in Auckland.

Advertisement
Advertise with NZME.

The initial problem was that the planned venue, the new NZ International Convention Centre, had been delayed by construction hold-ups then a catastrophic fire.

But in the new year, that was, of course, overtaken by the coronavirus pandemic.

Discover more

Business

Net closing on Mt Ruapehu hackers

25 Sep 05:32 AM
Business

Covid-19: Survey reveals Kiwis' comfort-level with location-tracking

25 Nov 04:36 AM
Business

Payment page hack cost Kiwi small business $100K - how not to be next

25 Sep 05:45 AM
Business

Ransomware-related death should focus directors' minds on liability - expert

22 Sep 05:52 AM

This year has seen a dramatic increase in cyberattacks, worldwide and in NZ (as Cert NZ figures issued yesterday confirmed).

Earlier, AUT computer science professor Dave Parry told the Herald that could be directly tied to the pandemic. The remote-working boom has opened up security gaps at the same time organised crime was seeing lockdowns diminish its more traditional activity so ramped its cyberattack efforts to compensate.

While Zoom has recently moved to tighten its security, security expert Daniel Ayers points out that recent conference embarrassments have been caused by human error. Photo / File
While Zoom has recently moved to tighten its security, security expert Daniel Ayers points out that recent conference embarrassments have been caused by human error. Photo / File

At the same time, Kordia chief information security officer Hilary Walton said NZ was seen by some as a "soft touch" because we have not kept up with others' cyber-security efforts.

Experts across the Tasman have seen a rise in cyber attacks by "bad state actors," leading to the Morrison government's decision to go on a "war-footing" and apply an extra A$1.4 billion to shoring-up cyber-defences, at the same time that NZ's extra cyber-security spending could be measured in the single-digit millions and a GCSB insider complained to the Herald about our fragmented, multi-agency approach with no clear leadership.

Earlier this year, Cabinet and the Epidemic Response Committee drew flak for using Zoom - the fast-rising videoconferencing platform that was famously user-friendly but also quickly in trouble for a wave of "Zoombombing" (people gatecrashing meetings) and claiming it had full encryption when it did not.

At the time, the GCSB said it could not mandate what video platform cabinet chose to use, only advise that Zoom was only appropriate for discussion of material up to "Restricted" level.

Advertisement
Advertise with NZME.

Earlier this week, the intelligence agency declined to comment on which video conferencing solution would be used for Apec, and its level of confidence in the choice, referring the Herald to the Ministry of Foreign Affairs.

Old school: Prime Minister Jacinda Ardern meets US President Donald Trump with Canadian PM Justin Trudeau and Mexican President Enrique Pena Nieto at Apec in Vietnam in 2017. Photo / via Twitter
Old school: Prime Minister Jacinda Ardern meets US President Donald Trump with Canadian PM Justin Trudeau and Mexican President Enrique Pena Nieto at Apec in Vietnam in 2017. Photo / via Twitter

Cas Carter, communications director for MFAT's Apec unit said: "We are still undergoing final discussions with technology providers and therefore unable provide further details at this time."

She added: "Apec NZ works closely with the government intelligence and communications agencies will continue to do so throughout the hosting year."

"The most significant threats from using a videoconferencing solution are likely to be embarrassment if someone gate-crashes or malware being introduced into computers as a result of installing software to participate," Ayers said.

"I would imagine that Zoom would be considered, I understand it has a better UX for higher numbers of participants. Zoom has improved security in recent months, although from a low baseline."

After Zoom boss Eric Yuan's April mea culpa over security and privacy holes, the chief executive told his company's developers to devote 100 per cent of their efforts over the next three months to tighten up the service.

Zoom finally added full, end-to-end encryption in October, plus the ability to choose a Zoom outside of China if your are paranoid, or simply think you'll get better performance from a Zoom call hosted in the US or Australia.

Image / Herald Graphic
Image / Herald Graphic

That came on top of other measures introduced since April, including guests left in a virtual waiting room by default until the host let them in.

But Ayers said that - especially with such a large event, involving so many people - the risk of human error remains, which is where we came in with the EU incident.

Bad state actor threat

For Buchanan, the potential for a bad state actor to cause trouble persists, regardless of how much Zoom (or Cisco or Microsoft or other video chat providers) tighten security.

"There is always plenty of opportunity for the PRC or other sophisticated cyber-players to wreak havoc on video-conferencing," he told the Herald.

"And if those video conferences are being held on Zoom, then Western security agencies will be concerned about any number of nefarious activities linked to PRC intelligence and hacking units.

"The question, therefore, is not about the opportunity or technological capability to 'do a Dutchman' on the Apec virtual conference but one of motivation."

Dr Paul Buchanan: If Apec is held on Zoom, "Western security agencies will be concerned about any number of nefarious activities linked to PRC intelligence and hacking units." Photo / File
Dr Paul Buchanan: If Apec is held on Zoom, "Western security agencies will be concerned about any number of nefarious activities linked to PRC intelligence and hacking units." Photo / File

What would motivate the PRC to virally disrupt or otherwise interfere with the video-meetings?, the former US State Department analyst and advisor the Pentagon said.

"One reason would be that Apec is going to make some sort of statement or adopt a posture that is perceived as contrary to PRC interests. That seems unlikely but the PRC is very sensitive about things like Hong Kong, the pandemic, South China Sea etc. It would be very unusual for APEC to say anything about such sensitive topics but it is always a (however remote) possibility."

Another reason would be if the PRC is interested in disrupting or otherwise messing with working groups or bilateral aspects of the virtual conference, Buchanan said.

"I am not sure how Apec will conduct its business in a virtual setting but since a lot of the important stuff gets done in side-bars to the main conference proceedings, perhaps there is room for mischief there. But overall, short of some affront, I do not see the PRC wanting to 'Dutch' the conference."

Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Latest from Business

Premium
Shares

Market close: Geopolitical tensions keep NZ market flat, US Fed decision looms

18 Jun 06:09 AM
Premium
Business

Fringe Benefit Tax: Should you be paying it if your business owns a ute?

18 Jun 06:00 AM
New Zealand

'Life-changing': International flights return to Hamilton Airport

18 Jun 05:23 AM

Audi offers a sporty spin on city driving with the A3 Sportback and S3 Sportback

sponsored
Advertisement
Advertise with NZME.

Latest from Business

Premium
Market close: Geopolitical tensions keep NZ market flat, US Fed decision looms

Market close: Geopolitical tensions keep NZ market flat, US Fed decision looms

18 Jun 06:09 AM

The S&P/NZX 50 Index closed down 0.10%, falling to 12,627.32.

Premium
Fringe Benefit Tax: Should you be paying it if your business owns a ute?

Fringe Benefit Tax: Should you be paying it if your business owns a ute?

18 Jun 06:00 AM
'Life-changing': International flights return to Hamilton Airport

'Life-changing': International flights return to Hamilton Airport

18 Jun 05:23 AM
Premium
Liam Dann: 'Brick wall' – why tomorrow’s GDP data won’t tell the real story

Liam Dann: 'Brick wall' – why tomorrow’s GDP data won’t tell the real story

18 Jun 05:17 AM
Gold demand soars amid global turmoil
sponsored

Gold demand soars amid global turmoil

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP