ATO e-tax software hit by potential security holes
- 14 September, 2010 07:17
- Comments
The denizens of global security mailing list Bugtraq have started discussing whether the Australian Taxation Office's e-tax 2010 software -- currently being used by millions of Australians to submit their tax returns -- has a security hole in it, due to the way it deals with remote Secure Socket Layer (SSL) certificates.
The breaches were unintentionally discovered when a security expert, known only as Dave B, became fed up with the ATO's restrictions on the use of alternative operating systems other than Windows -- he tried to do a workaround so he didn't have to use Microsoft's platform.
At first Dave B thought that the software did not check the SSL certificate of involved domains and would work if the certificate came from a valid certificate authority. Other tests were made and he found that a "freshly generated" self-signed certificate would be accepted by the software -- so the SSL certificate does not need to be signed by a certificate authority.
e-tax will communicate via the unencrypted http protocol rather than https if told to -- for example, using URL manipulations like such as the Apache mod_rewrite module. e-tax2010 will send the details of the tax request in a Simple Object Access Protocol (SOAP) request.
Securus Global Managing Director Drazen Drazic said he believed the risks were clear and that the whole process was open to attacks such man in the middle (MITM) attacks where an attacker could pull information from the stream between the ATO and the e-tax end user.
"The risks seem to be purely on the client side of things in regards to this advisory," he said. "People need to be careful when accessing. How it’s working based upon the advisory means people could be directed to anywhere with personal information being sent to unauthorised parties. Given the type of information, not a good thing."
For instance if an individual has an SSL certificate for another website, that certificate could then be used to masquerade as the ATO's tax server.
An ATO spokesperson said: "We don't provide comment on security-related matters, however we can assure taxpayers that income tax details submitted by e-tax software is secure."
Last week Dave logged his discovery on security mailing list Bug Traq in a series of logs - each revealed that the security breach was much worse than previously thought. The first bug logged can be viewed below, subsequent bugs logged can be located here and here.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Monday Grok: Will Siri crack the walls of GOOG?
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Phones are distractions during catch-ups
-
Protecting Generation Web
From data privacy to personal safety issues, cyber-bullying, inappropriate content and malware, schools are facing an increasingly difficult task when it comes to allowing young people to spread their online wings without compromising their safety and personal development. The reality that most schools are catering to the needs of mixed age groups and abilities, and it’s easy to understand why a simple stop and block approach won’t work. Learning environments are, by nature, flexible. It stands to reason that the IT resources used in them should be flexible too. Read on. -
Developing an Information Strategy - Strategize, Align, Govern, Execute, and Optimize
An information strategy defines how a company will use the data it collects to achieve a competitive advantage. It is a comprehensive, constantly evolving plan that encompasses five distinct actions. In this white paper we explore how these five vital actions, as well as the technologies that enable and support them, can help organizations develop an effective and broad-reaching information strategy that drives positive change. -
Pathways Business Brochure 2012
Tailored learning and development program for organisations looking to build business acumen within their Key ICT executive. The course curriculum is designed in conjunction with the specific requirements the enrolling organisation.
-
Linux for Dummies Quick Reference, 3rd Edition
-
Sharepoint 2007 and Office Development
-
Illustrator Cs3 Bible
-
Getting Started with Ryan Mcfarland (Rm) Cobol 85 + Compiler 2E
-
Master Data Management & Semantic Modeling Mdm
-
Sharepoint 2007 Collaboration for Dummies®
-
S60 Programming - a Tutorial Guide
-
Microsoft Outlook 2000 Bible
-
Simplified Guide to Structured Cobal Programming 2E








Comments
Post new comment