Feeds

Oz gov cyber-safety unit loses punters' info IN THE POST

Updated: AUSCERT mislaid DVD of hashed passwords

Choosing a cloud hosting partner with confidence

In an outstanding example of data-loss stupidity, a DVD containing email addresses and encrypted passwords for Australia’s Stay Smart Online Alert service has gone astray in the mail during a handover between contractors.

An e-mail sent to subscribers on 6 July and passed on to The Register by a reader states “the Department has been advised by a former external contractor that a DVD which included information provided by Stay Smart Online Alert Service subscribers was lost in Australia Post’s system, after being posted on 11 April 2012.”

The service is currently being re-developed, apparently by a company called Ladoo since its links exist in the advisory e-mail (more on this below).

The service is managed by the Department of Broadband, Communications and the Digital Economy, which has yet to respond to questions sent by The Register via e-mail during the weekend.

The e-mail also states “The Department has no reason to believe that this information has been found and misused by any third party and we do not believe that there is a privacy risk. We are informing subscribers consistent with a ‘best practice’ approach for privacy matters.

“However, if you have used the same username, memorable phrase and/or password for other websites or services you may wish to consider whether these need to be changed.”

For information, the e-mail suggests users visit the site www.staysmartonline.com.au, but in an ironic twist, the e-mail uses obfuscated links that redirect via ladoo.com.au for the Stay Smart Online Website, user preferences, and the “unsubscribe” link.

As Stay Smart Online states on its Website: “Don't click on links in the message or paste a link from the message into your Web browser.”

The full e-mail is below. The Register has added the Ladoo links where they appear. In case the links are specific to the recipient, The Register has replaced the HTML file names at the end of redirected links. &reg

Update: Since this story was first posted, a reader has alerted El Reg that the prior contractor, which sent the DVD by mail, was AUSCERT, as reported by Fairfax. &reg

6 July 2012

Notification of Subscriber Data Loss

Dear Subscriber

We are writing to notify you that the Department has been advised by a former external contractor that a DVD which included information provided by Stay Smart Online Alert Service subscribers was lost in Australia Posts’ system, after being posted on 11 April 2012.

The external contractor provided the Alert Service on behalf of the Department of Broadband, Communications and the Digital Economy (‘the Department’) from 2008 until 29 April 2012, when its contract with the Department expired. As you may be aware, the Stay Smart Online Alert Service is currently being re-developed by the Department in collaboration with two new contractors.

As part of the expiry of contract handover process, the original contractor advised that it copied its SSO Alert Service subscriber database onto a DVD and, on 11 April 2012, posted this DVD to the Department using Australia Post’s express post service. Unfortunately, this DVD was never received by the Department. The original contractor has informed the Department that information on the missing DVD included subscribers’: usernames; email addresses; memorable phrases; and passwords which are unreadable (as cryptographic hash).

The Department has no reason to believe that this information has been found and misused by any third party and we do not believe that there is a privacy risk. We are informing subscribers consistent with a ‘best practice’ approach for privacy matters.

However, if you have used the same username, memorable phrase and/or password for other websites or services you may wish to consider whether these need to be changed.

For information on password security and other tips and advice on how to be safe and secure online, visit Stay Smart Online website (www.staysmartonline.gov.au). [Link: http://send.ladoo.com.au/ch/38192/1bjbv/1662928/LINK.html]

Regards

Stay Smart Online Team

CONTACT US Email: staysmartonline@dbcde.gov.au [Link: staysmartonline@dbcde.gov.au]

www.staysmartonline.gov.au [Link: http://send.ladoo.com.au/ch/38192/1bjbv/1662783/LINK.html]

You are receiving this message at the address [Removed for privacy reasons]

Click here [Link: http://send.ladoo.com.au/ch/38192/1bjbv/1658692/LINK.html] to update your profile preferences. If you no longer wish to receive the SSO newsletter, you can unsubscribe. [Link: http://send.ladoo.com.au/ch/38192/1bjbv/1656647/LINK.html]

Internet Security Threat Report 2014

More from The Register

next story
FYI: OS X Yosemite's Spotlight tells Apple EVERYTHING you're looking for
It's on by default – didn't you read the small print?
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
Edward who? GCHQ boss dodges Snowden topic during last speech
UK spies would rather 'walk' than do 'mass surveillance'
Microsoft pulls another dodgy patch
Redmond makes a hash of hashing add-on
'LulzSec leader Aush0k' found to be naughty boy not worthy of jail
15 months home detention leaves egg on feds' faces as they grab for more power
China is ALREADY spying on Apple iCloud users, claims watchdog
Attack harvests users' info at iPhone 6 launch
Carders punch holes through Staples
Investigation launched into East Coast stores
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.