NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / New Zealand

Treasury hacking: The time I hacked WINZ - Keith Ng

Keith Ng
By Keith Ng
Data journalist, NZ Herald·NZ Herald·
31 May, 2019 08:32 PM5 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

In the popular imagination, "hacking" is virtually indistinguishable from magic. In reality, a lot of hacking is laborious, repetitive and mundane.

In the popular imagination, "hacking" is virtually indistinguishable from magic. In reality, a lot of hacking is laborious, repetitive and mundane.

Keith Ng
Opinion by Keith Ng
Data journalist, NZ Herald
Learn more

COMMENT:
How can something as basic as typing into the Treasury search box be hacking? Herald data journalist and WINZ kiosk hacker Keith Ng explains.

I am a rubbish hacker. I am such a rubbish hacker, in fact, that a hacker conference awarded me with a joke prize for my "hack" of the Work & Income kiosks in 2012. This "hack" used the Microsoft Word "open file" window, combined with a few clicks and lot of patience. It resulted in me walking out with a USB drive containing the personal information of vulnerable individuals, including children in state care, from MSD's internal network.

As an award-winning rubbish hacker, let me tell you: Hacking which is lacking in sophistication, even crude to the point of embarrassment, is still hacking.

In the popular imagination, "hacking" is virtually indistinguishable from magic. It's an incomprehensible craft which results in unimaginable havoc. That's why when it's so easily comprehensible – like obtaining Budget files through a browser – we cannot believe it's the same thing.

In reality, a lot of hacking is laborious and repetitive, equivalent to walking down a street trying the door on every house. Hackers do this because they are not magical, they can't breach the unbreachable. But they don't have to, they just have to find something that's easy to breach. Somewhere, there's a server which is misconfigured. Somewhere, there's a person who will click on their malware link. Somewhere, there's a file which is supposed to be locked down, but wasn't. They just have to keep trying.

Advertisement
Advertise with NZME.
Advertisement
Advertise with NZME.
National Party leader Simon Bridges. National released details of this week's Budget before the Government announced it. Photo / Mark Mitchell
National Party leader Simon Bridges. National released details of this week's Budget before the Government announced it. Photo / Mark Mitchell

Imagine if you only saw the last part of the process. Imagine you didn't see the first 200,000 times where the security system blocked access, and you just saw the 200,001st attempt. You would simply see the hacker walk in and succeed at accessing the information. You might think there was no security at all.

In Treasury's case, we can imagine ourselves typing some letters and numbers into the browser. How can something that we do all the time possibly be circumventing security? But we need to wind back, and consider all the times where it didn't work. Those first 2000 attempts that failed is where the real hack took place.

While Treasury Secretary Gabriel Makhlouf tried to make "more than 2000 attempts in 48 hours" seem like a serious attack, it's actually a very low number which signalled it was being done by hand, by someone who was quite a rubbish hacker. But its rubbishness doesn't matter. That it was done through a browser doesn't matter. What makes it hacking is that the Budget documents are clearly not supposed to be available. Even if you didn't know the rules around Budget secrecy, most people would take the hint after failing to obtain the information the first 2000 times.

Advertisement
Advertise with NZME.

This was an intentional effort to get around the access controls. That makes it a hack.

This "open file" window was the tool used to explore MSD's internal networks and to remove sensitive files during the WINZ kiosk hack.
This "open file" window was the tool used to explore MSD's internal networks and to remove sensitive files during the WINZ kiosk hack.

But "hacking" is not the same as "illegal". After my own hack of the WINZ system, journalists and politicians mused about whether I should be prosecuted. The law against unauthorised access of computer systems says it doesn't count "if a person who is authorised to access a computer system accesses that computer system for a purpose other than the one for which that person was given access".

Did that mean I was off the hook? I didn't know, and my lawyer couldn't say for sure either. But if I was charged, at least I had a defence.

I conducted the hack as a journalist to expose the problems with MSD's computer system. It was in the public good because the safety and privacy of very vulnerable people were at stake, and MSD had shown apathy towards information security (it was later revealed that they had a security report alerting them to the exact problem, but they ignored it).

Discover more

Business

Govt sets aside funds for new cyber security strategy

30 May 02:04 AM
Business

'Meagre' cyber-security spend puts goals at risk

30 May 05:00 PM
New Zealand

PM dodges questions on Treasury Budget bungle

30 May 07:14 AM
New Zealand|politics

Budget blunder: Makhlouf hasn't offered resignation – Robertson

30 May 11:23 PM

MSD needed a swift kick to sort it out, and documenting the hack was the only way to detail exactly how bad the problem was and what its consequences were. Some people believed it was unethical, and I understand their position. It was an ethically thorny decision, at best.

This window showed all MSD servers accessible during the WINZ kiosk hack. This was used as proof that their systems were vulnerable.
This window showed all MSD servers accessible during the WINZ kiosk hack. This was used as proof that their systems were vulnerable.

It really was a "hack". It was information which I had no right to. It needed a damn good reason to justify it, and it came with very serious responsibilities to not abuse that information.

I told the Privacy Commissioner and asked for advice. I promised not to release personal details and to destroy the files afterwards. I gave MSD a heads-up so they could shut down all the kiosks before the vulnerability was made public, and provided as much information as possible about what the vulnerability was.

If Simon Bridges just wanted to highlight how insecure Treasury's information system was, why was it necessary to release the content of the hack? If the security of Treasury's information was really so important to him, why didn't he tell Treasury or the public what the problem was?

These are not unreasonable standards to hold ourselves to. If it's good enough for a rubbish hacker like me, it should be good enough for the leader of our opposition.

Save

    Share this article

Latest from New Zealand

New Zealand

‘Rare opportunity’: Wellington’s floating boat cafe up for sale

16 Jun 06:01 AM
New Zealand

'I’m gonna see you burn at the stake': Paramedic bit partner on the nose, then strangled her

16 Jun 06:00 AM
New Zealand

'Loveable rascal': Family, school mourns 6yo boy lost in boat tragedy

16 Jun 05:18 AM

The woman behind NZ’s first PAK’nSAVE

sponsored
Advertisement
Advertise with NZME.

Latest from New Zealand

‘Rare opportunity’: Wellington’s floating boat cafe up for sale

‘Rare opportunity’: Wellington’s floating boat cafe up for sale

16 Jun 06:01 AM

The popular cafe, housed in a 66-year-old tugboat, has an asking price of $220,000.

'I’m gonna see you burn at the stake:' Paramedic bit partner on the nose, then strangled her

'I’m gonna see you burn at the stake:' Paramedic bit partner on the nose, then strangled her

16 Jun 06:00 AM
'Loveable rascal': Family, school mourns 6yo boy lost in boat tragedy

'Loveable rascal': Family, school mourns 6yo boy lost in boat tragedy

16 Jun 05:18 AM
50-year secret unveiled: Gardener who murdered pensioner had killed before

50-year secret unveiled: Gardener who murdered pensioner had killed before

16 Jun 05:01 AM
How one volunteer makes people feel seen
sponsored

How one volunteer makes people feel seen

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP