NZ Herald
  • Home
  • Latest news
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather forecasts

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
    • The Great NZ Road Trip
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
    • Cooking the Books
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • What the Actual
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / New Zealand

Urgent review of Govt computer systems ordered

APNZ
16 Oct, 2012 05:53 AM6 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

An urgent review of publicly-accessible systems operated by State Services has been ordered. File photo / Thinkstock

An urgent review of publicly-accessible systems operated by State Services has been ordered. File photo / Thinkstock

State Services Commissioner Iain Rennie has formally asked the Government Chief Information Officer Colin McDonald to carry out an urgent review of publicly-accessible systems operated by State Services.

Mr Rennie said the Work and Income kiosk security failure had seriously breached any trust New Zealanders had in the Government.

"It is imperative that Government takes the lead to reassure the public and repair the damage that has been done to this trust,'' said Mr Rennie.

He said Mr McDonald will contact all government agencies directly, to seek assurance that their computer systems are robust.

"Mr McDonald will lead public service agencies in evaluating and strengthening their ICT security measures to ensure that there are no systemic faults that could cause additional security issues.''

Advertisement
Advertise with NZME.
Advertisement
Advertise with NZME.

Since the findings of the Privacy Commission report in August on the handling of private material held by ACC, the State Services Commission has been considering a wider role for Mr McDonald across the system.

"The use of technology to further improve access to public services is essential, but this needs to be delivered while ensuring personal information is protected,'' Mr Rennie said.

Disturbing' that security hole not fixed.

Advertisement
Advertise with NZME.

Earlier today, Social Development Minister Paula Bennett said it was disturbing that an IT company identified a major security hole in Work and Income's systems more than a year ago but it had not been fixed.

The Ministry of Social Development revealed this morning that IT company Dimension Data had tested the self-serve kiosks in April last year and identified issues of concern.

Ms Bennett confirmed the report identified the same problem which was revealed this week by blogger Keith Ng, who had easily accessed thousands of copies of invoices with personal details on them through the kiosks.

"What we now need to work out is was [the report] acted on, how was it acted on and obviously it wasn't well enough or we wouldn't be in this situation today.''

Discover more

New Zealand

Too old, Winz tells mum, 42

13 Oct 04:30 PM
New Zealand|politics

MSD lax security exposed

14 Oct 11:45 AM
New Zealand|politics

Blogger unlikely to be prosecuted

15 Oct 12:11 AM
New Zealand|politics

Winz alerted to breach last year

14 Oct 09:13 PM

Ng has handed all his information to the Privacy Commissioner and MSD has contracted Deloittes to investigate the actual breach in question as well as MSD's wider computer security.

Ng was tipped off about the hole by Ira Bailey - an IT analyst who told the Herald he came across it by mistake while he was using a kiosk and was trying to find his USB stick.

He had initially gone to the MSD to warn them of a hole and asked if they had incentive payments for reports of security flaws similar to those offered by Google or Facebook.

Ms Bennett said the issue of Ira Bailey asking about some form of payment in return for the information before he went to Ng was only a "side issue'' and she had bigger problems to deal with.

She said Mr Bailey and Ng had ultimately done the department a favour.

"I feel no ill-feeling towards any of them. At the end of the day, it's not their fault there is such a security flaw in the system and that is quite frankly the responsibility of the ministry. The main issue is that people were able to access information they shouldn't have been able to access.''

Advertisement
Advertise with NZME.

Asked if she believed Mr Bailey had tried to 'blackmail' the Ministry of Social Development in return for his cooperation, she said she believed he was asking for a 'reward.'

"You can take from that what you want to.''

Asked if Mr Bailey's name was leaked to the NZ Herald from within their offices, both Prime Minister John Key and Ms Bennett said not as far as they were aware.

Ms Bennett said the Ministry of Social Development had said the leak had not come from them and she took them at their word.

What Deloittes will look at

Earlier today the Ministry of Social Development's chief executive Brendan Boyle said he wasn't confident that a warning about security flaws 18 months ago was acted on properly.

Advertisement
Advertise with NZME.

Mr Boyle said the ministry received a report from Dimension Data in April last year identifying "flaws" in its system.

"We will be asking Deloittes to determine what we did to follow up this report's recommendations and whether our response was adequate.

"Since yesterday afternoon I have received further information that means I am not confident that we took the right actions in response to Dimension Data's recommendations on security. I will look to the review to provide me with the answers," Mr Boyle said.

"I can confirm that KPMG was not engaged to penetration test our public kiosks. They have, however, been engaged in doing testing on other parts of our system."

Mr Boyle said the ministry's immediate aim was to resolve any security problems and restore public confidence in its systems.

The Deloittes review would happen in two phases.

Advertisement
Advertise with NZME.

The first would deal with the immediate security of its public kiosks. It would look at what happened, how secure information was able to be accessed and how it could be prevented from happening again.

The second phase would involve a broader look at security across all the ministry's IT systems, including policies, governance and culture.

How the flaw was discovered

It has been revealed that Ira Bailey - one of 17 people arrested in the Urewera raids in 2007 - was the first to discover the major privacy flaws in the self-service kiosks.

Mr Bailey, an IT analyst, said he told the ministry last Monday that there was a security issue before he tipped off blogger Keith Ng.

Ng subsequently accessed thousands of documents such as invoices for children's medical care, before blowing the whistle publicly on Sunday night.

Advertisement
Advertise with NZME.

The ministry closed the kiosks and ordered an independent inquiry into the lapse and Ng has handed over all the information he obtained to the Privacy Commissioner.

Mr Boyle said the ministry was first contacted last week by a man who claimed there was a loophole in the system and had asked for a "reward" in return for his co-operation.

The ministry had not acted because the reference was "vague" and the man had not mentioned the kiosks, he said.

Mr Bailey said he had simply asked if the ministry had incentive payments for people who pointed out security breaches.

"I called up on Monday 8th October to say there was a security leak and ask who to talk to. And I also asked was there an incentives scheme about security flaws, which is what Google and Facebook do."

Save

    Share this article

Latest from New Zealand

New Zealand

Watch: Major highway blocked by slip, Auckland flights delayed as intense storm strikes

09 May 08:09 AM
Crime

Man's 11-day crime spree targets police by spitting and threatening to kill staff

09 May 08:00 AM
New Zealand

Auckland War Memorial Museum closed to public after asbestos discovery

09 May 07:49 AM

One tiny baby’s fight to survive

sponsored
Advertisement
Advertise with NZME.

Latest from New Zealand

Watch: Major highway blocked by slip, Auckland flights delayed as intense storm strikes

Watch: Major highway blocked by slip, Auckland flights delayed as intense storm strikes

09 May 08:09 AM

Motorists are being warned to expect hazardous driving conditions.

Man's 11-day crime spree targets police by spitting and threatening to kill staff

Man's 11-day crime spree targets police by spitting and threatening to kill staff

09 May 08:00 AM
Auckland War Memorial Museum closed to public after asbestos discovery

Auckland War Memorial Museum closed to public after asbestos discovery

09 May 07:49 AM
'We've had enough': Red Square protest opposes pay equity changes

'We've had enough': Red Square protest opposes pay equity changes

09 May 07:21 AM
Connected workers are safer workers 
sponsored

Connected workers are safer workers 

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • What the Actual
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven CarGuide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP