PM's office passwords pose security risk
- 29 March, 2011 14:01
- Comments
More than 10 per cent of passwords used in Prime Minister Julia Gillard's department can be easily broken in an hour by hackers using "brute force", a report from the Australian National Audit Office says.
Auditor-General Ian McPhee discovered passwords could be cracked by running a basic generator that found phrases like "Holiday1" were used in place of more complex passwords using a mixture of numbers, symbols and letters.
McPhee looked at four seemingly very different areas of government: Medicare, the office of financial management, prime minister and cabinet and ComSuper.
"These agencies were selected as they represent a general cross-section of agencies and their associated ICT (Information and Communication Technology) systems," he said.
While the problems were not specifically linked with the individual groups, a graph included in the report shows all four groups had more than 10 per cent of "total passwords compromised" by "brute force" attacks.
Similar problems were found across the organisations.
Not only did passwords need to be more complex, but access to web-based email accounts such as Hotmail and GMail needed to be blocked.
Basic software updating was not being done regularly enough, and this left security holes, the audit found.
The failure showed a lack of a "security culture".
The problem of relatively simple passwords is made even worse because some of them provide access to so-called "privileged access accounts".
These accounts allow the user to change the passwords of others, move data, change data and perform other actions with national security implications.
McPhee called for a close look at the risk.
The department of prime minister and cabinet agreed.
"Review of privileged access accounts is regularly undertaken," the department said.
The release of the audit coincided with News Ltd reports that the unclassified network used by cabinet has been hacked, possibly byChinese cyber soldiers.
The Australian Security Intelligence Organisation is said to have begun an investigation.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
- Top 5 Myths of Safe Web Browsing
- There is a HP Printer for everyone
- Businesses are ready for a new approach to IT - Simplify deployment and reduce complexity using systems integrated with expertise
- Best Practices for Secure Enterprise Content Mobility
- Stopping Fake Antivirus: How to Keep Scareware off Your Network
-
Google Jumps Into Social Bookmarks Game
-
NBN build gaining momentum daily: Quigley
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Monday Grok: Will Siri crack the walls of GOOG?
-
Face Time - Interview with John Brennan and Robert DiStefano
-
ALM Buyers Guide: A Practical Guide to Choosing the Right Agile Tools for your Team
This buyer's guide describes the key criteria for application lifecycle management (ALM) solutions for today's high-performance teams. It includes key considerations for enhancing your single- or multi-vendor ALM environment. -
Business Process Management, Service-Oriented Architecture, and Web 2.0: Business Transformation or Train Wreck?
As a result of more and more organisations adopting new technologies and business practices surrounding BPM, SOA, and Web 2.0, fundamental changes have arisen in the way IT and business stakeholders work together. Make this into an opportunity - read on. -
Transforming Your Business by Transforming Your Processes
In this white paper, we build on the “Intelligent Guide to Enterprise BPM: V olume One” in which we described the three entry points where you can begin to build true Enterprise BPM. In this white paper we explain the value of Process T ransformation, the entry point to strategy and design. Successful implementation of Process T ransformation will mean you have successfully documented, standardized, harmonized, managed—as well as analyzed and improved—your business processes. T he next two white papers will detail the other two entry points: Process Automation and Process Intelligence.
-
Cics
-
Google Sketchup and Sketchup Pro 7 Bible
-
Microsoft Works 2000 for Dummies Quick Reference
-
Accredited Symbian Developer Primer - Fundamentals of Symbian OS
-
Storage Area Networks for Dummies
-
Cryptography for Dummies
-
Director 8 and Lingo Bible
-
Mastering Active Directory for Windows Server 2008
-
Excel 2007 Data Analysis for Dummies








Comments
Post new comment