Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

ATO e-tax software hit by potential security holes

SSL certificates for software questioned

The denizens of global security mailing list Bugtraq have started discussing whether the Australian Taxation Office's e-tax 2010 software -- currently being used by millions of Australians to submit their tax returns -- has a security hole in it, due to the way it deals with remote Secure Socket Layer (SSL) certificates.

The breaches were unintentionally discovered when a security expert, known only as Dave B, became fed up with the ATO's restrictions on the use of alternative operating systems other than Windows -- he tried to do a workaround so he didn't have to use Microsoft's platform.

At first Dave B thought that the software did not check the SSL certificate of involved domains and would work if the certificate came from a valid certificate authority. Other tests were made and he found that a "freshly generated" self-signed certificate would be accepted by the software -- so the SSL certificate does not need to be signed by a certificate authority.

e-tax will communicate via the unencrypted http protocol rather than https if told to -- for example, using URL manipulations like such as the Apache mod_rewrite module. e-tax2010 will send the details of the tax request in a Simple Object Access Protocol (SOAP) request.

Securus Global Managing Director Drazen Drazic said he believed the risks were clear and that the whole process was open to attacks such man in the middle (MITM) attacks where an attacker could pull information from the stream between the ATO and the e-tax end user.

"The risks seem to be purely on the client side of things in regards to this advisory," he said. "People need to be careful when accessing. How it’s working based upon the advisory means people could be directed to anywhere with personal information being sent to unauthorised parties. Given the type of information, not a good thing."

For instance if an individual has an SSL certificate for another website, that certificate could then be used to masquerade as the ATO's tax server.

An ATO spokesperson said: "We don't provide comment on security-related matters, however we can assure taxpayers that income tax details submitted by e-tax software is secure."

Last week Dave logged his discovery on security mailing list Bug Traq in a series of logs - each revealed that the security breach was much worse than previously thought. The first bug logged can be viewed below, subsequent bugs logged can be located here and here.

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: Apache, Australian Taxation Office, Microsoft, Socket

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: Australian Tax Office, e-tax, Secure Socket Layer (SSL), security
Latest Blog Posts
Whitepapers
  • Protecting Generation Web
    From data privacy to personal safety issues, cyber-bullying, inappropriate content and malware, schools are facing an increasingly difficult task when it comes to allowing young people to spread their online wings without compromising their safety and personal development. The reality that most schools are catering to the needs of mixed age groups and abilities, and it’s easy to understand why a simple stop and block approach won’t work. Learning environments are, by nature, flexible. It stands to reason that the IT resources used in them should be flexible too. Read on.
    Learn more »
  • Developing an Information Strategy - Strategize, Align, Govern, Execute, and Optimize
    An information strategy defines how a company will use the data it collects to achieve a competitive advantage. It is a comprehensive, constantly evolving plan that encompasses five distinct actions. In this white paper we explore how these five vital actions, as well as the technologies that enable and support them, can help organizations develop an effective and broad-reaching information strategy that drives positive change.
    Learn more »
  • Pathways Business Brochure 2012
    Tailored learning and development program for organisations looking to build business acumen within their Key ICT executive. The course curriculum is designed in conjunction with the specific requirements the enrolling organisation.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments