部分属实

评分: 6.0/10

Coalition
C0024

声明内容

“未遵循COVID数字疫苗的网络安全最佳实践。他们没有有效的方式来报告漏洞,更不用说设置漏洞赏金来阻止将漏洞出售给犯罪分子。当政府最终得知其应用程序中存在漏洞时,他们未能及时响应或解决。”
原始来源: Matthew Davis
分析时间: 29 Jan 2026

原始来源

事实核查

###### ### COVIDCOVID COVID 数字证书shù zì zhèng shū shù zì zhèng shū 系统xì tǒng xì tǒng zhōng zhōng de de 漏洞lòu dòng lòu dòng
### Vulnerability in COVID Digital Certificate System
gāi gāi 主张zhǔ zhāng zhǔ zhāng de de 核心hé xīn hé xīn 事实shì shí shì shí 得到dé dào dé dào 实质性shí zhì xìng shí zhì xìng 验证yàn zhèng yàn zhèng
The core facts of the claim are substantially verified.
可信kě xìn kě xìn de de 安全ān quán ān quán 研究员yán jiū yuán yán jiū yuán RichardRichard Richard NelsonNelson Nelson 20212021 2021 nián nián 99 9 yuè yuè 发现fā xiàn fā xiàn le le 澳大利亚ào dà lì yà ào dà lì yà ExpressExpress Express PlusPlus Plus MedicareMedicare Medicare COVIDCOVID COVID -- - 1919 19 数字证书shù zì zhèng shū shù zì zhèng shū 系统xì tǒng xì tǒng zhōng zhōng de de 一个yí gè yí gè 重大zhòng dà zhòng dà 漏洞lòu dòng lòu dòng [[ [ 11 1 ]] ]
Richard Nelson, a credible security researcher, discovered a significant vulnerability in Australia's Express Plus Medicare COVID-19 digital certificate system in September 2021 [1].
NelsonNelson Nelson 发现fā xiàn fā xiàn 通过tōng guò tōng guò 所说suǒ shuō suǒ shuō de de "" " 中间人zhōng jiān rén zhōng jiān rén "" " 漏洞lòu dòng lòu dòng 可以kě yǐ kě yǐ 轻而易举qīng ér yì jǔ qīng ér yì jǔ ràng ràng MedicareMedicare Medicare 应用程序yìng yòng chéng xù yìng yòng chéng xù 显示xiǎn shì xiǎn shì 一个yí gè yí gè 看似kàn shì kàn shì 有效yǒu xiào yǒu xiào de de COVIDCOVID COVID -- - 1919 19 疫苗yì miáo yì miáo 证书zhèng shū zhèng shū [[ [ 22 2 ]] ]
Nelson found it was trivial to make the Medicare app display a valid-looking COVID-19 vaccine certificate through what he describes as a "man-in-the-middle" vulnerability [2].
这一zhè yī zhè yī 发现fā xiàn fā xiàn bèi bèi 包括bāo kuò bāo kuò ABCABC ABC 在内zài nèi zài nèi de de 主流zhǔ liú zhǔ liú 媒体méi tǐ méi tǐ 广泛guǎng fàn guǎng fàn 报道bào dào bào dào [[ [ 33 3 ]] ]
This finding was widely reported by mainstream media, including the ABC [3].
###### ### 缺乏quē fá quē fá 漏洞lòu dòng lòu dòng 披露pī lù pī lù 计划jì huà jì huà
### Lack of Vulnerability Disclosure Program
关于guān yú guān yú 缺乏quē fá quē fá 正式zhèng shì zhèng shì 漏洞lòu dòng lòu dòng 披露pī lù pī lù 计划jì huà jì huà de de 主张zhǔ zhāng zhǔ zhāng 得到dé dào dé dào le le 政府zhèng fǔ zhèng fǔ 声明shēng míng shēng míng de de 证实zhèng shí zhèng shí
The claim about the absence of a formal vulnerability disclosure program is confirmed by government statements.
zài zài 20212021 2021 年底nián dǐ nián dǐ de de 预算yù suàn yù suàn 估算gū suàn gū suàn 听证会tīng zhèng huì tīng zhèng huì shàng shàng dāng dāng LaborLabor Labor 参议员cān yì yuán cān yì yuán jiù jiù 安全漏洞ān quán lòu dòng ān quán lòu dòng xiàng xiàng ServicesServices Services AustraliaAustralia Australia 质询zhì xún zhì xún shí shí gāi gāi 机构jī gòu jī gòu 明确míng què míng què 表示biǎo shì biǎo shì "" " 目前mù qián mù qián 没有méi yǒu méi yǒu 任何rèn hé rèn hé 漏洞lòu dòng lòu dòng 披露pī lù pī lù 计划jì huà jì huà 没有méi yǒu méi yǒu 任何rèn hé rèn hé 未来wèi lái wèi lái 实施shí shī shí shī 此类cǐ lèi cǐ lèi 计划jì huà jì huà de de 安排ān pái ān pái "" " [[ [ 44 4 ]] ]
During Budget Estimates hearings in late 2021, when grilled by Labor senators about the security vulnerabilities, Services Australia explicitly stated: "There are currently no vulnerability disclosure programs in place nor any future plans to implement such a program for the digital vaccination certificates" [4].
此外cǐ wài cǐ wài 数字shù zì shù zì 转型zhuǎn xíng zhuǎn xíng DTADTA DTA 表示biǎo shì biǎo shì "" " 没有méi yǒu méi yǒu 考虑kǎo lǜ kǎo lǜ 建立jiàn lì jiàn lì 赏金shǎng jīn shǎng jīn 计划jì huà jì huà de de 打算dǎ suàn dǎ suàn "" " [[ [ 55 5 ]] ]
Additionally, the Digital Transformation Agency (DTA) stated it had "no plans to consider establishing bounty programs" [5].
###### ### 报告bào gào bào gào 漏洞lòu dòng lòu dòng de de 困难kùn nán kùn nán
### Difficulty Reporting Vulnerabilities
NelsonNelson Nelson de de 个人经历gè rén jīng lì gè rén jīng lì 证实zhèng shí zhèng shí le le gāi gāi 主张zhǔ zhāng zhǔ zhāng de de 第二dì èr dì èr 部分bù fèn bù fèn
Nelson's personal experience corroborates the second part of the claim.
dāng dāng 发现fā xiàn fā xiàn 漏洞lòu dòng lòu dòng shí shí zài zài 通过tōng guò tōng guò 适当shì dàng shì dàng 渠道qú dào qú dào 报告bào gào bào gào shí shí 面临miàn lín miàn lín 重大zhòng dà zhòng dà 挑战tiǎo zhàn tiǎo zhàn [[ [ 11 1 ]] ]
When he discovered the vulnerability, he faced significant challenges in reporting it through proper channels [1].
尝试cháng shì cháng shì le le 多种duō zhǒng duō zhǒng 报告bào gào bào gào 途径tú jìng tú jìng
He attempted multiple reporting pathways: - Tried calling Services Australia directly but gave up after being placed on hold [1] - Found the Department of Health had a Vulnerability Disclosure Policy, but Express Plus Medicare fell under Services Australia, not Health [1] - Reported it via ReportCyber and the Australian Signals Directorate (ASD), but received no response until days later [1] - Only after publicly tweeting about the vulnerability and being contacted by journalists did Services Australia appear to take action [1]
-- - 尝试cháng shì cháng shì 直接zhí jiē zhí jiē 致电zhì diàn zhì diàn ServicesServices Services AustraliaAustralia Australia dàn dàn zài zài bèi bèi 搁置gē zhì gē zhì hòu hòu 放弃fàng qì fàng qì le le [[ [ 11 1 ]] ]
### Response and Remediation Timeliness
-- - 发现fā xiàn fā xiàn 卫生部wèi shēng bù wèi shēng bù yǒu yǒu 漏洞lòu dòng lòu dòng 披露pī lù pī lù 政策zhèng cè zhèng cè dàn dàn ExpressExpress Express PlusPlus Plus MedicareMedicare Medicare 属于shǔ yú shǔ yú ServicesServices Services AustraliaAustralia Australia ér ér fēi fēi 卫生部wèi shēng bù wèi shēng bù [[ [ 11 1 ]] ]
The evidence supports criticism of response timeliness.
-- - 通过tōng guò tōng guò ReportCyberReportCyber ReportCyber 澳大利亚ào dà lì yà ào dà lì yà 信号xìn hào xìn hào ASDASD ASD 报告bào gào bào gào dàn dàn 直到zhí dào zhí dào 几天jǐ tiān jǐ tiān hòu hòu cái cái 收到shōu dào shōu dào 回复huí fù huí fù [[ [ 11 1 ]] ]
Nelson noted that Services Australia did not reach out to him after he went public via Twitter and media, likely because the issue had become sensitive and the agency wanted to avoid additional press coverage [1].
-- - 只有zhǐ yǒu zhǐ yǒu zài zài 公开gōng kāi gōng kāi zài zài 推特上tuī tè shàng tuī tè shàng 发布fā bù fā bù 漏洞lòu dòng lòu dòng bìng bìng bèi bèi 记者jì zhě jì zhě 联系lián xì lián xì hòu hòu ServicesServices Services AustraliaAustralia Australia 似乎sì hū sì hū cái cái 采取行动cǎi qǔ xíng dòng cǎi qǔ xíng dòng [[ [ 11 1 ]] ]
This demonstrates a reactive rather than proactive approach to vulnerability handling.
###### ### 响应xiǎng yìng xiǎng yìng 修复xiū fù xiū fù de de 及时性jí shí xìng jí shí xìng
However, the sources do not provide explicit evidence of extended remediation timelines after the initial reporting or public disclosure.
证据zhèng jù zhèng jù 支持zhī chí zhī chí duì duì 响应xiǎng yìng xiǎng yìng 及时性jí shí xìng jí shí xìng de de 批评pī píng pī píng
NelsonNelson Nelson 指出zhǐ chū zhǐ chū zài zài 通过tōng guò tōng guò 推特tuī tè tuī tè 媒体méi tǐ méi tǐ 公开gōng kāi gōng kāi hòu hòu ServicesServices Services AustraliaAustralia Australia 并未bìng wèi bìng wèi 联系lián xì lián xì 可能kě néng kě néng 是因为shì yīn wèi shì yīn wèi gāi gāi 问题wèn tí wèn tí 变得biàn dé biàn dé 敏感mǐn gǎn mǐn gǎn gāi gāi 机构jī gòu jī gòu 希望xī wàng xī wàng 避免bì miǎn bì miǎn 额外é wài é wài de de 媒体报道méi tǐ bào dào méi tǐ bào dào [[ [ 11 1 ]] ]
zhè zhè demonstratedemonstrate demonstrate le le 一种yī zhǒng yī zhǒng 被动bèi dòng bèi dòng ér ér fēi fēi 主动zhǔ dòng zhǔ dòng de de 漏洞lòu dòng lòu dòng 处理chǔ lǐ chǔ lǐ 方式fāng shì fāng shì
然而rán ér rán ér 来源lái yuán lái yuán wèi wèi 提供tí gōng tí gōng 关于guān yú guān yú 初次chū cì chū cì 报告bào gào bào gào huò huò 公开gōng kāi gōng kāi 披露pī lù pī lù hòu hòu 延长yán cháng yán cháng 修复xiū fù xiū fù 时间表shí jiān biǎo shí jiān biǎo de de 明确míng què míng què 证据zhèng jù zhèng jù

缺失背景

gāi gāi 主张zhǔ zhāng zhǔ zhāng 需要xū yào xū yào 大量dà liàng dà liàng 额外é wài é wài 背景bèi jǐng bèi jǐng
The claim requires significant additional context: **1.
** * ** * 11 1 .. . 政府zhèng fǔ zhèng fǔ 网络安全wǎng luò ān quán wǎng luò ān quán 框架kuāng jià kuāng jià 存在cún zài cún zài ** * ** * ServicesServices Services AustraliaAustralia Australia 声称shēng chēng shēng chēng 每年měi nián měi nián 进行jìn xíng jìn xíng "" " 多次duō cì duō cì 完整wán zhěng wán zhěng de de 网络wǎng luò wǎng luò 评估píng gū píng gū "" " bìng bìng 表示biǎo shì biǎo shì "" " 澳大利亚ào dà lì yà ào dà lì yà 信号xìn hào xìn hào 澳大利亚ào dà lì yà ào dà lì yà 网络安全wǎng luò ān quán wǎng luò ān quán 中心zhōng xīn zhōng xīn 密切合作mì qiè hé zuò mì qiè hé zuò 关注guān zhù guān zhù 移动yí dòng yí dòng 应用程序yìng yòng chéng xù yìng yòng chéng xù de de 潜在qián zài qián zài 漏洞lòu dòng lòu dòng "" " [[ [ 44 4 ]] ]
Government Cybersecurity Framework Existed:** Services Australia claimed to undertake "full cyber assessments several times a year" and stated it "work[s] closely with the Australian Signals Directorate and Australian Cyber Security Centre on potential vulnerabilities on mobile applications" [4].
zhè zhè 表明biǎo míng biǎo míng 政府zhèng fǔ zhèng fǔ 确实què shí què shí yǒu yǒu 网络安全wǎng luò ān quán wǎng luò ān quán 流程liú chéng liú chéng 尽管jǐn guǎn jǐn guǎn 它们tā men tā men 不足以bù zú yǐ bù zú yǐ 处理chǔ lǐ chǔ lǐ 研究员yán jiū yuán yán jiū yuán 报告bào gào bào gào
This indicates the government did have cybersecurity processes in place, though they were not sufficient for handling researcher reports. **2.
** * ** * 22 2 .. . 某些mǒu xiē mǒu xiē 机构jī gòu jī gòu 已有yǐ yǒu yǐ yǒu 漏洞lòu dòng lòu dòng 披露pī lù pī lù 计划jì huà jì huà ** * ** * 虽然suī rán suī rán ServicesServices Services AustraliaAustralia Australia 缺乏quē fá quē fá VDPVDP VDP dàn dàn 其他qí tā qí tā 澳大利亚政府ào dà lì yà zhèng fǔ ào dà lì yà zhèng fǔ 机构jī gòu jī gòu 实施shí shī shí shī
Some Agencies Had Vulnerability Disclosure Programs:** While Services Australia lacked a VDP, other Australian government agencies had implemented them.
内政部nèi zhèng bù nèi zhèng bù 实施shí shī shí shī 漏洞lòu dòng lòu dòng 披露pī lù pī lù 计划jì huà jì huà [[ [ 66 6 ]] ] 新南威尔士州xīn nán wēi ěr shì zhōu xīn nán wēi ěr shì zhōu 服务局fú wù jú fú wù jú 通过tōng guò tōng guò BugcrowdBugcrowd Bugcrowd 运营yùn yíng yùn yíng 漏洞lòu dòng lòu dòng 赏金shǎng jīn shǎng jīn 计划jì huà jì huà [[ [ 77 7 ]] ]
The Department of Home Affairs had a Vulnerability Disclosure Program in place [6], and Service NSW operated a bug bounty program through Bugcrowd [7].
zhè zhè 表明biǎo míng biǎo míng 机构jī gòu jī gòu 实施shí shī shí shī 一致yí zhì yí zhì ér ér 非全fēi quán fēi quán 政府zhèng fǔ zhèng fǔ 范围fàn wéi fàn wéi de de 政策zhèng cè zhèng cè 失败shī bài shī bài
This suggests inconsistent implementation across agencies rather than a government-wide policy failure. **3.
** * ** * 33 3 .. . 严重性yán zhòng xìng yán zhòng xìng 评估píng gū píng gū ** * ** * ServicesServices Services AustraliaAustralia Australia jiāng jiāng suǒ suǒ 攻击gōng jī gōng jī 描述miáo shù miáo shù wèi wèi "" " 需要xū yào xū yào 大量dà liàng dà liàng 知识zhī shí zhī shí 专长zhuān cháng zhuān cháng "" " [[ [ 44 4 ]] ] 表明biǎo míng biǎo míng 他们tā men tā men 认为rèn wéi rèn wéi 实际shí jì shí jì 风险fēng xiǎn fēng xiǎn 低于dī yú dī yú 理论lǐ lùn lǐ lùn 漏洞lòu dòng lòu dòng 可能kě néng kě néng 暗示àn shì àn shì de de 程度chéng dù chéng dù
Severity Assessment:** Services Australia characterized the required attack as something that "require[s] significant knowledge and expertise" [4], suggesting they viewed the practical risk as lower than the theoretical vulnerability might suggest.
然而rán ér rán ér 这一zhè yī zhè yī 辩护biàn hù biàn hù 力度lì dù lì dù 较弱jiào ruò jiào ruò 无论wú lùn wú lùn 攻击gōng jī gōng jī 复杂程度fù zá chéng dù fù zá chéng dù 如何rú hé rú hé 安全漏洞ān quán lòu dòng ān quán lòu dòng dōu dōu yīng yīng 得到dé dào dé dào 解决jiě jué jiě jué
However, this defense is weak—security vulnerabilities should be addressed regardless of attack complexity. **4.
** * ** * 44 4 .. . 伪造wěi zào wěi zào xìng xìng 篡改cuàn gǎi cuàn gǎi ** * ** * gāi gāi 漏洞lòu dòng lòu dòng 涉及shè jí shè jí ràng ràng 应用程序yìng yòng chéng xù yìng yòng chéng xù 显示xiǎn shì xiǎn shì 虚假xū jiǎ xū jiǎ 证书zhèng shū zhèng shū 客户端kè hù duān kè hù duān 漏洞lòu dòng lòu dòng ér ér fēi fēi 创建chuàng jiàn chuàng jiàn néng néng 通过tōng guò tōng guò hòu hòu duān duān 验证yàn zhèng yàn zhèng de de 伪造wěi zào wěi zào 证书zhèng shū zhèng shū
Forgeability vs.
NelsonNelson Nelson 自己zì jǐ zì jǐ de de 推文tuī wén tuī wén 强调qiáng diào qiáng diào le le 显示xiǎn shì xiǎn shì 漏洞lòu dòng lòu dòng de de 简便性jiǎn biàn xìng jiǎn biàn xìng dàn dàn 有限yǒu xiàn yǒu xiàn 证据zhèng jù zhèng jù 表明biǎo míng biǎo míng 底层dǐ céng dǐ céng 注册表zhù cè biǎo zhù cè biǎo bèi bèi 欺骗qī piàn qī piàn [[ [ 33 3 ]] ]
Tampering:** The vulnerability involved making the app display a false certificate (client-side vulnerability) rather than creating counterfeit certificates that would pass backend validation.
** * ** * 55 5 .. . 推出tuī chū tuī chū 时间shí jiān shí jiān 线xiàn xiàn ** * ** * COVIDCOVID COVID -- - 1919 19 数字证书shù zì zhèng shū shù zì zhèng shū shì shì zài zài 疫情yì qíng yì qíng 期间qī jiān qī jiān de de 20212021 2021 nián nián 中期zhōng qī zhōng qī 相对xiāng duì xiāng duì 仓促cāng cù cāng cù 推出tuī chū tuī chū de de [[ [ 88 8 ]] ]
Nelson's own tweet emphasized the ease of the display vulnerability, but there's limited evidence the underlying registry could be spoofed [3]. **5.
这一zhè yī zhè yī 背景bèi jǐng bèi jǐng 不能bù néng bù néng wèi wèi 安全ān quán ān quán 缺陷quē xiàn quē xiàn 开脱kāi tuō kāi tuō dàn dàn 解释jiě shì jiě shì le le 快速kuài sù kuài sù 部署bù shǔ bù shǔ de de 一些yī xiē yī xiē 压力yā lì yā lì
Timeline of Rollout:** The COVID-19 digital certificate was introduced relatively hastily during pandemic conditions (rolled out in mid-2021) [8].

来源可信度评估

###### ### 原始yuán shǐ yuán shǐ 来源lái yuán lái yuán
### Original Sources
** * ** * RichardRichard Richard NelsonNelson Nelson MediumMedium Medium 文章wén zhāng wén zhāng ** * ** *
**Richard Nelson (Medium article):** - Credible security researcher with demonstrable expertise; his other Medium articles show deep technical knowledge of government security systems (COVIDSafe analysis, Service NSW driver license reverse engineering) [1] - Personal account of attempting responsible disclosure; makes genuine effort to follow proper procedures before going public [1] - Transparent about his frustration and emotional state; acknowledges the difficulty of his position [1] - Appears motivated by public security, not partisan politics; no evidence of political alignment toward Labor [1] **ZDNet (Campbell Kwan article):** - Mainstream technology news outlet with editorial standards [9] - Reports on Budget Estimates proceedings, which are documented public records [4] - Accurately cites the government's own statements; quotes are verifiable [4] - Campbell Kwan is a regular contributor on government technology issues [9] - However, the article emphasizes criticism from Labor senators and doesn't deeply explore government rationale or mitigating context
-- - 具有jù yǒu jù yǒu 证明zhèng míng zhèng míng 专业知识zhuān yè zhī shí zhuān yè zhī shí 可信kě xìn kě xìn 安全ān quán ān quán 研究员yán jiū yuán yán jiū yuán de de 其他qí tā qí tā MediumMedium Medium 文章wén zhāng wén zhāng 显示xiǎn shì xiǎn shì duì duì 政府zhèng fǔ zhèng fǔ 安全ān quán ān quán 系统xì tǒng xì tǒng COVIDSafeCOVIDSafe COVIDSafe 分析fēn xī fēn xī 新南威尔士州xīn nán wēi ěr shì zhōu xīn nán wēi ěr shì zhōu 服务局fú wù jú fú wù jú 驾驶执照jià shǐ zhí zhào jià shǐ zhí zhào 逆向nì xiàng nì xiàng 工程gōng chéng gōng chéng yǒu yǒu 深入shēn rù shēn rù 了解liǎo jiě liǎo jiě de de 技术jì shù jì shù 知识zhī shí zhī shí [[ [ 11 1 ]] ]
### Bias Assessment
-- - 尝试cháng shì cháng shì 负责fù zé fù zé rèn rèn 披露pī lù pī lù de de 个人账户gè rén zhàng hù gè rén zhàng hù zài zài 公开gōng kāi gōng kāi qián qián 真诚zhēn chéng zhēn chéng 努力nǔ lì nǔ lì 遵循zūn xún zūn xún 适当shì dàng shì dàng 程序chéng xù chéng xù [[ [ 11 1 ]] ]
Neither source appears primarily motivated by partisan bias, though the ZDNet article gives prominence to Labor senators' criticisms in a federal Budget Estimates context.
-- - duì duì 自己zì jǐ zì jǐ de de 挫败cuò bài cuò bài gǎn gǎn 情绪qíng xù qíng xù 状态zhuàng tài zhuàng tài 保持bǎo chí bǎo chí 透明tòu míng tòu míng 承认chéng rèn chéng rèn 自己zì jǐ zì jǐ suǒ suǒ chù chù 位置wèi zhì wèi zhì de de 困难kùn nán kùn nán [[ [ 11 1 ]] ]
The sources are factual and verifiable, though they emphasize government failures rather than providing balanced context.
-- - 似乎sì hū sì hū 出于chū yú chū yú 公共安全gōng gòng ān quán gōng gòng ān quán 动机dòng jī dòng jī ér ér fēi fēi 党派dǎng pài dǎng pài 政治zhèng zhì zhèng zhì 没有méi yǒu méi yǒu 证据zhèng jù zhèng jù 表明biǎo míng biǎo míng 倾向qīng xiàng qīng xiàng LaborLabor Labor [[ [ 11 1 ]] ]
This is appropriate for security reporting—the vulnerability was real and the response was inadequate—but the framing is inherently critical rather than neutral.
** * ** * ZDNetZDNet ZDNet CampbellCampbell Campbell KwanKwan Kwan 文章wén zhāng wén zhāng ** * ** *
-- - 具有jù yǒu jù yǒu 编辑biān jí biān jí 标准biāo zhǔn biāo zhǔn de de 主流zhǔ liú zhǔ liú 科技kē jì kē jì 新闻媒体xīn wén méi tǐ xīn wén méi tǐ [[ [ 99 9 ]] ]
-- - 报道bào dào bào dào 预算yù suàn yù suàn 估算gū suàn gū suàn 程序chéng xù chéng xù 这些zhè xiē zhè xiē shì shì 记录在案jì lù zài àn jì lù zài àn de de 公开gōng kāi gōng kāi 记录jì lù jì lù [[ [ 44 4 ]] ]
-- - 准确zhǔn què zhǔn què 引用yǐn yòng yǐn yòng 政府zhèng fǔ zhèng fǔ 自己zì jǐ zì jǐ de de 声明shēng míng shēng míng 引述yǐn shù yǐn shù 可验证kě yàn zhèng kě yàn zhèng [[ [ 44 4 ]] ]
-- - CampbellCampbell Campbell KwanKwan Kwan shì shì 政府zhèng fǔ zhèng fǔ 技术jì shù jì shù 问题wèn tí wèn tí de de 定期dìng qī dìng qī 撰稿人zhuàn gǎo rén zhuàn gǎo rén [[ [ 99 9 ]] ]
-- - 然而rán ér rán ér 文章wén zhāng wén zhāng 强调qiáng diào qiáng diào LaborLabor Labor 参议员cān yì yuán cān yì yuán de de 批评pī píng pī píng 并未bìng wèi bìng wèi 深入探讨shēn rù tàn tǎo shēn rù tàn tǎo 政府zhèng fǔ zhèng fǔ 理由lǐ yóu lǐ yóu huò huò 缓解huǎn jiě huǎn jiě xìng xìng 背景bèi jǐng bèi jǐng
###### ### 偏见piān jiàn piān jiàn 评估píng gū píng gū
两个liǎng gè liǎng gè 来源lái yuán lái yuán 似乎sì hū sì hū dōu dōu 不是bú shì bú shì 主要zhǔ yào zhǔ yào yóu yóu 党派dǎng pài dǎng pài 偏见piān jiàn piān jiàn 驱动qū dòng qū dòng 尽管jǐn guǎn jǐn guǎn ZDNetZDNet ZDNet 文章wén zhāng wén zhāng zài zài 联邦lián bāng lián bāng 预算yù suàn yù suàn 估算gū suàn gū suàn 背景bèi jǐng bèi jǐng xià xià 突出tū chū tū chū LaborLabor Labor 参议员cān yì yuán cān yì yuán de de 批评pī píng pī píng
来源lái yuán lái yuán shì shì 事实性shì shí xìng shì shí xìng 可验证kě yàn zhèng kě yàn zhèng de de 尽管jǐn guǎn jǐn guǎn 它们tā men tā men 强调qiáng diào qiáng diào 政府zhèng fǔ zhèng fǔ 失败shī bài shī bài ér ér fēi fēi 提供tí gōng tí gōng 平衡píng héng píng héng 背景bèi jǐng bèi jǐng
zhè zhè 适合shì hé shì hé 安全ān quán ān quán 报告bào gào bào gào 漏洞lòu dòng lòu dòng shì shì 真实zhēn shí zhēn shí de de 响应xiǎng yìng xiǎng yìng shì shì 充分chōng fèn chōng fèn de de dàn dàn 框架kuāng jià kuāng jià 本质běn zhì běn zhì shàng shàng shì shì 批评性pī píng xìng pī píng xìng de de ér ér fēi fēi 中立zhōng lì zhōng lì de de
⚖️

工党对比

** * ** * LaborLabor Labor de de 数字shù zì shù zì 健康jiàn kāng jiàn kāng 系统xì tǒng xì tǒng 是否shì fǒu shì fǒu 存在cún zài cún zài 重大zhòng dà zhòng dà 网络安全wǎng luò ān quán wǎng luò ān quán 问题wèn tí wèn tí
**Did Labor have significant cybersecurity issues with digital health systems?** Search conducted: "Labor government Australian digital health system cybersecurity privacy breach MyHealth Records" Labor's handling of the My Health Record system shows relevant precedent.
** * ** *
The My Health Record was introduced by the Labor government in 2012 and became highly controversial [10].
搜索sōu suǒ sōu suǒ 查询chá xún chá xún "" " LaborLabor Labor 政府zhèng fǔ zhèng fǔ 澳大利亚ào dà lì yà ào dà lì yà 数字shù zì shù zì 健康jiàn kāng jiàn kāng 系统xì tǒng xì tǒng 网络安全wǎng luò ān quán wǎng luò ān quán 隐私yǐn sī yǐn sī 泄露xiè lòu xiè lòu MyHealthMyHealth MyHealth RecordsRecords Records "" "
The system faced significant privacy concerns, leading Labor itself to call for a suspension of the rollout when the Coalition expanded it [11].
LaborLabor Labor duì duì MyMy My HealthHealth Health RecordRecord Record 系统xì tǒng xì tǒng de de 处理chǔ lǐ chǔ lǐ 显示xiǎn shì xiǎn shì le le 相关xiāng guān xiāng guān 先例xiān lì xiān lì
The Privacy Commissioner raised concerns, and there was substantial public backlash [10].
MyMy My HealthHealth Health RecordRecord Record 20122012 2012 nián nián yóu yóu LaborLabor Labor 政府zhèng fǔ zhèng fǔ 推出tuī chū tuī chū bìng bìng 引发yǐn fā yǐn fā 高度gāo dù gāo dù 争议zhēng yì zhēng yì [[ [ 1010 10 ]] ]
While this represents a broader policy failure (flawed design from the start) rather than a cybersecurity vulnerability disclosure issue specifically, it demonstrates that Labor governments have also struggled with digital health system security and public trust in similar areas. **Comparable Cybersecurity Incident:** There is no evidence of Labor government digital health systems facing similar cybersecurity vulnerability disclosure policy gaps during their period in government (2007-2013).
gāi gāi 系统xì tǒng xì tǒng 面临miàn lín miàn lín 重大zhòng dà zhòng dà 隐私yǐn sī yǐn sī 问题wèn tí wèn tí 导致dǎo zhì dǎo zhì LaborLabor Labor 自己zì jǐ zì jǐ zài zài 联盟党lián méng dǎng lián méng dǎng 扩展kuò zhǎn kuò zhǎn shí shí 呼吁hū yù hū yù 暂停zàn tíng zàn tíng 推出tuī chū tuī chū [[ [ 1111 11 ]] ]
However, the broader theme of inadequate digital security governance appears to be a systemic Australian government issue across parties rather than unique to the Coalition.
隐私yǐn sī yǐn sī 专员zhuān yuán zhuān yuán 提出tí chū tí chū 担忧dān yōu dān yōu 公众gōng zhòng gōng zhòng 强烈qiáng liè qiáng liè 反对fǎn duì fǎn duì [[ [ 1010 10 ]] ]
虽然suī rán suī rán zhè zhè 代表dài biǎo dài biǎo gèng gèng 广泛guǎng fàn guǎng fàn de de 政策zhèng cè zhèng cè 失败shī bài shī bài cóng cóng 开始kāi shǐ kāi shǐ jiù jiù yǒu yǒu 缺陷quē xiàn quē xiàn de de 设计shè jì shè jì ér ér fēi fēi 具体jù tǐ jù tǐ de de 网络安全wǎng luò ān quán wǎng luò ān quán 漏洞lòu dòng lòu dòng 披露pī lù pī lù 问题wèn tí wèn tí dàn dàn 表明biǎo míng biǎo míng LaborLabor Labor 政府zhèng fǔ zhèng fǔ zài zài 数字shù zì shù zì 健康jiàn kāng jiàn kāng 系统安全xì tǒng ān quán xì tǒng ān quán 公众gōng zhòng gōng zhòng 信任xìn rèn xìn rèn 方面fāng miàn fāng miàn céng céng zài zài 类似lèi sì lèi sì 领域lǐng yù lǐng yù 挣扎zhēng zhá zhēng zhá
** * ** * 可比kě bǐ kě bǐ 网络安全wǎng luò ān quán wǎng luò ān quán 事件shì jiàn shì jiàn ** * ** * 没有méi yǒu méi yǒu 证据zhèng jù zhèng jù 表明biǎo míng biǎo míng LaborLabor Labor 政府zhèng fǔ zhèng fǔ 数字shù zì shù zì 健康jiàn kāng jiàn kāng 系统xì tǒng xì tǒng zài zài 执政zhí zhèng zhí zhèng 期间qī jiān qī jiān 20072007 2007 -- - 20132013 2013 nián nián 面临miàn lín miàn lín 类似lèi sì lèi sì de de 网络安全wǎng luò ān quán wǎng luò ān quán 漏洞lòu dòng lòu dòng 披露pī lù pī lù 政策zhèng cè zhèng cè 缺口quē kǒu quē kǒu
然而rán ér rán ér 充分chōng fèn chōng fèn de de 数字shù zì shù zì 安全ān quán ān quán 治理zhì lǐ zhì lǐ 这一zhè yī zhè yī gèng gèng 广泛guǎng fàn guǎng fàn de de 主题zhǔ tí zhǔ tí 似乎sì hū sì hū shì shì 跨越kuà yuè kuà yuè 党派dǎng pài dǎng pài de de 系统性xì tǒng xìng xì tǒng xìng 澳大利亚政府ào dà lì yà zhèng fǔ ào dà lì yà zhèng fǔ 问题wèn tí wèn tí ér ér fēi fēi 联盟党lián méng dǎng lián méng dǎng 独有dú yǒu dú yǒu
🌐

平衡视角

** * ** * 政府zhèng fǔ zhèng fǔ 立场lì chǎng lì chǎng ** * ** *
**Government's Position:** Services Australia maintained that the COVID-19 digital certificate system included multiple security layers and that the vulnerability discovered required "significant knowledge and expertise" to exploit [4].
ServicesServices Services AustraliaAustralia Australia 坚称jiān chēng jiān chēng COVIDCOVID COVID -- - 1919 19 数字证书shù zì zhèng shū shù zì zhèng shū 系统xì tǒng xì tǒng 包含bāo hán bāo hán 多层duō céng duō céng 安全ān quán ān quán 发现fā xiàn fā xiàn de de 漏洞lòu dòng lòu dòng 需要xū yào xū yào "" " 大量dà liàng dà liàng 知识zhī shí zhī shí 专长zhuān cháng zhuān cháng "" " 才能cái néng cái néng 利用lì yòng lì yòng [[ [ 44 4 ]] ]
The agency emphasized it was cooperating with the Australian Signals Directorate and conducting regular cyber assessments [4].
gāi gāi 机构jī gòu jī gòu 强调qiáng diào qiáng diào 正在zhèng zài zhèng zài 澳大利亚ào dà lì yà ào dà lì yà 信号xìn hào xìn hào 合作hé zuò hé zuò bìng bìng 进行jìn xíng jìn xíng 定期dìng qī dìng qī 网络wǎng luò wǎng luò 评估píng gū píng gū [[ [ 44 4 ]] ]
The government's perspective was that while the vulnerability should be addressed, it was not a critical failure requiring immediate overhaul of the entire system. **Security Expert Perspective:** Richard Nelson's position is well-reasoned from a security governance standpoint: even if a vulnerability requires expertise to exploit, proper channels for responsible disclosure should exist.
政府zhèng fǔ zhèng fǔ de de 观点guān diǎn guān diǎn shì shì 虽然suī rán suī rán 应该yīng gāi yīng gāi 解决jiě jué jiě jué gāi gāi 漏洞lòu dòng lòu dòng dàn dàn 不是bú shì bú shì 需要xū yào xū yào 立即lì jí lì jí 彻底chè dǐ chè dǐ 改革gǎi gé gǎi gé 整个zhěng gè zhěng gè 系统xì tǒng xì tǒng de de 关键guān jiàn guān jiàn 失败shī bài shī bài
He argues this is standard industry practice and that the absence of such channels is what forced him to make the issue public [1].
** * ** * 安全ān quán ān quán 专家zhuān jiā zhuān jiā 观点guān diǎn guān diǎn ** * ** *
This is a legitimate concern about institutional security maturity, not just about the existence of any single vulnerability. **Systemic Issue vs.
cóng cóng 安全ān quán ān quán 治理zhì lǐ zhì lǐ 角度jiǎo dù jiǎo dù 来看lái kàn lái kàn RichardRichard Richard NelsonNelson Nelson de de 立场lì chǎng lì chǎng shì shì 合理hé lǐ hé lǐ de de 即使jí shǐ jí shǐ 漏洞lòu dòng lòu dòng 需要xū yào xū yào 专业知识zhuān yè zhī shí zhuān yè zhī shí 才能cái néng cái néng 利用lì yòng lì yòng 应该yīng gāi yīng gāi 存在cún zài cún zài 适当shì dàng shì dàng de de 负责fù zé fù zé rèn rèn 披露pī lù pī lù 渠道qú dào qú dào
Malicious Intent:** The evidence suggests this was primarily a systemic governance failure (lack of formal processes) rather than negligence or malicious intent.
认为rèn wéi rèn wéi 这是zhè shì zhè shì 标准biāo zhǔn biāo zhǔn 行业háng yè háng yè 实践shí jiàn shí jiàn 缺乏quē fá quē fá 此类cǐ lèi cǐ lèi 渠道qú dào qú dào 迫使pò shǐ pò shǐ 公开gōng kāi gōng kāi 问题wèn tí wèn tí [[ [ 11 1 ]] ]
Services Australia demonstrated awareness of security concerns and was conducting assessments [4].
zhè zhè shì shì duì duì 机构jī gòu jī gòu 安全ān quán ān quán 成熟度chéng shú dù chéng shú dù de de 合理hé lǐ hé lǐ 担忧dān yōu dān yōu 不仅仅bù jǐn jǐn bù jǐn jǐn shì shì 关于guān yú guān yú 任何rèn hé rèn hé 单一dān yī dān yī 漏洞lòu dòng lòu dòng de de 存在cún zài cún zài
The failure was in not having established, well-publicized, responsive channels for researchers to report vulnerabilities—a process issue rather than a technical issue. **Industry Practice Context:** Vulnerability disclosure programs (VDPs) and bug bounties have become industry standard practice across major tech companies and, increasingly, government agencies.
** * ** * 系统性xì tǒng xìng xì tǒng xìng 问题wèn tí wèn tí 恶意è yì è yì 意图yì tú yì tú ** * ** *
The ASD and Cyber.gov.au have published guidance on implementing VDPs [12].
证据zhèng jù zhèng jù 表明biǎo míng biǎo míng zhè zhè 主要zhǔ yào zhǔ yào shì shì 系统性xì tǒng xìng xì tǒng xìng 治理zhì lǐ zhì lǐ 失败shī bài shī bài 缺乏quē fá quē fá 正式zhèng shì zhèng shì 流程liú chéng liú chéng ér ér fēi fēi 疏忽shū hū shū hū huò huò 恶意è yì è yì 意图yì tú yì tú
By 2021, the absence of a formal VDP for a public-facing COVID safety system was notably behind current best practices, though it wasn't unique to Australia or the Coalition government at that time. **Key context:** The vulnerability disclosure issue is genuinely problematic and represents a failure to follow established cybersecurity best practices.
ServicesServices Services AustraliaAustralia Australia 表现biǎo xiàn biǎo xiàn 出对chū duì chū duì 安全ān quán ān quán 问题wèn tí wèn tí de de 意识yì shí yì shí bìng bìng 进行jìn xíng jìn xíng 评估píng gū píng gū [[ [ 44 4 ]] ]
However, it's not clear this was unique to the Coalition's COVID response or that Labor governments would necessarily have handled it differently—the My Health Record case shows digital health system governance has been challenging across parties.
失败shī bài shī bài 在于zài yú zài yú 没有méi yǒu méi yǒu 建立jiàn lì jiàn lì 公开gōng kāi gōng kāi 响应xiǎng yìng xiǎng yìng 迅速xùn sù xùn sù de de 渠道qú dào qú dào gōng gōng 研究员yán jiū yuán yán jiū yuán 报告bào gào bào gào 漏洞lòu dòng lòu dòng 这是zhè shì zhè shì 一个yí gè yí gè 流程liú chéng liú chéng 问题wèn tí wèn tí ér ér 非技术fēi jì shù fēi jì shù 问题wèn tí wèn tí
** * ** * 行业háng yè háng yè 实践shí jiàn shí jiàn 背景bèi jǐng bèi jǐng ** * ** *
漏洞lòu dòng lòu dòng 披露pī lù pī lù 计划jì huà jì huà VDPVDP VDP 漏洞lòu dòng lòu dòng 赏金shǎng jīn shǎng jīn 成为chéng wéi chéng wéi 主要zhǔ yào zhǔ yào 科技kē jì kē jì 公司gōng sī gōng sī 越来越yuè lái yuè yuè lái yuè duō duō 政府zhèng fǔ zhèng fǔ 机构jī gòu jī gòu de de 标准biāo zhǔn biāo zhǔn 行业háng yè háng yè 实践shí jiàn shí jiàn
ASDASD ASD CyberCyber Cyber .. . govgov gov .. . auau au 发布fā bù fā bù 实施shí shī shí shī VDPVDP VDP de de 指南zhǐ nán zhǐ nán [[ [ 1212 12 ]] ]
dào dào 20212021 2021 nián nián 面向miàn xiàng miàn xiàng 公众gōng zhòng gōng zhòng de de COVIDCOVID COVID 安全ān quán ān quán 系统xì tǒng xì tǒng 缺乏quē fá quē fá 正式zhèng shì zhèng shì VDPVDP VDP 明显míng xiǎn míng xiǎn 落后luò hòu luò hòu 当前dāng qián dāng qián 最佳zuì jiā zuì jiā 实践shí jiàn shí jiàn 尽管jǐn guǎn jǐn guǎn zhè zhè 并非bìng fēi bìng fēi 澳大利亚ào dà lì yà ào dà lì yà huò huò 当时dāng shí dāng shí 联盟党lián méng dǎng lián méng dǎng 政府zhèng fǔ zhèng fǔ 独有dú yǒu dú yǒu
** * ** * 关键guān jiàn guān jiàn 背景bèi jǐng bèi jǐng ** * ** * 漏洞lòu dòng lòu dòng 披露pī lù pī lù 问题wèn tí wèn tí 确实què shí què shí 存在cún zài cún zài 问题wèn tí wèn tí 代表dài biǎo dài biǎo 未能wèi néng wèi néng 遵循zūn xún zūn xún 建立jiàn lì jiàn lì de de 网络安全wǎng luò ān quán wǎng luò ān quán 最佳zuì jiā zuì jiā 实践shí jiàn shí jiàn
然而rán ér rán ér shàng shàng 清楚qīng chǔ qīng chǔ zhè zhè 是否是shì fǒu shì shì fǒu shì 联盟党lián méng dǎng lián méng dǎng COVIDCOVID COVID 应对yìng duì yìng duì 独有dú yǒu dú yǒu de de 或者huò zhě huò zhě LaborLabor Labor 政府zhèng fǔ zhèng fǔ 是否shì fǒu shì fǒu 会以huì yǐ huì yǐ 不同bù tóng bù tóng 方式fāng shì fāng shì 处理chǔ lǐ chǔ lǐ MyMy My HealthHealth Health RecordRecord Record 案例àn lì àn lì 显示xiǎn shì xiǎn shì 数字shù zì shù zì 健康jiàn kāng jiàn kāng 系统xì tǒng xì tǒng 治理zhì lǐ zhì lǐ duì duì 两党liǎng dǎng liǎng dǎng dōu dōu 一直yì zhí yì zhí 具有jù yǒu jù yǒu 挑战性tiǎo zhàn xìng tiǎo zhàn xìng

部分属实

6.0

/ 10

关于guān yú guān yú ServicesServices Services AustraliaAustralia Australia 缺乏quē fá quē fá 漏洞lòu dòng lòu dòng 披露pī lù pī lù 计划jì huà jì huà 以及yǐ jí yǐ jí 报告bào gào bào gào 漏洞lòu dòng lòu dòng 困难kùn nán kùn nán de de 具体jù tǐ jù tǐ 事实性shì shí xìng shì shí xìng 主张zhǔ zhāng zhǔ zhāng shì shì ** * ** * 准确zhǔn què zhǔn què qiě qiě 经验jīng yàn jīng yàn zhèng zhèng de de ** * ** *
The specific factual claims about Services Australia's lack of a vulnerability disclosure program and the difficulty in reporting vulnerabilities are **accurate and verified**.
然而rán ér rán ér gèng gèng 广泛guǎng fàn guǎng fàn de de 主张zhǔ zhāng zhǔ zhāng 需要xū yào xū yào 限定xiàn dìng xiàn dìng
However, the broader claim requires qualification: 1. ✅ **TRUE:** Services Australia had no vulnerability disclosure program and explicitly stated no plans to implement one [4] 2. ✅ **TRUE:** Reporting vulnerabilities was unnecessarily difficult and no effective process existed [1] 3. ✅ **TRUE:** Response was slow and only accelerated after public disclosure [1] 4. ⚠️ **PARTIALLY TRUE:** Claims about "not following cybersecurity best practice" are valid, but government was conducting cyber assessments and working with ASD; the failure was specifically in public vulnerability disclosure processes, not all cybersecurity practices [4] 5. ⚠️ **MISLEADING FRAMING:** The claim's implication that this was uniquely egregious Coalition-era mismanagement is not well-supported.
11 1 .. . ** * ** * 正确zhèng què zhèng què ** * ** * ServicesServices Services AustraliaAustralia Australia 没有méi yǒu méi yǒu 漏洞lòu dòng lòu dòng 披露pī lù pī lù 计划jì huà jì huà bìng bìng 明确míng què míng què 表示biǎo shì biǎo shì 没有méi yǒu méi yǒu 实施shí shī shí shī 计划jì huà jì huà [[ [ 44 4 ]] ]
Labor government digital health projects (My Health Record) faced similar governance and security trust issues [10, 11] 6. ⚠️ **CONTEXT MISSING:** During pandemic conditions in 2021, rapid deployment of public health infrastructure sometimes competed with security maturity; this doesn't excuse the failure but provides context The verdict is that the core facts are sound, the criticism is legitimate, but the framing overstates uniqueness or severity without acknowledging comparable issues in Labor's digital health governance.
22 2 .. . ** * ** * 正确zhèng què zhèng què ** * ** * 报告bào gào bào gào 漏洞lòu dòng lòu dòng 不必要bù bì yào bù bì yào 困难kùn nán kùn nán 没有méi yǒu méi yǒu 有效yǒu xiào yǒu xiào 流程liú chéng liú chéng [[ [ 11 1 ]] ]
33 3 .. . ** * ** * 正确zhèng què zhèng què ** * ** * 响应xiǎng yìng xiǎng yìng 缓慢huǎn màn huǎn màn jǐn jǐn zài zài 公开gōng kāi gōng kāi 披露pī lù pī lù hòu hòu cái cái 加速jiā sù jiā sù [[ [ 11 1 ]] ]
44 4 .. . ** * ** * 部分bù fèn bù fèn 正确zhèng què zhèng què ** * ** * 关于guān yú guān yú "" " wèi wèi 遵循zūn xún zūn xún 网络安全wǎng luò ān quán wǎng luò ān quán 最佳zuì jiā zuì jiā 实践shí jiàn shí jiàn "" " de de 主张zhǔ zhāng zhǔ zhāng shì shì 有效yǒu xiào yǒu xiào de de dàn dàn 政府zhèng fǔ zhèng fǔ 确实què shí què shí zài zài 进行jìn xíng jìn xíng 网络wǎng luò wǎng luò 评估píng gū píng gū bìng bìng ASDASD ASD 合作hé zuò hé zuò 失败shī bài shī bài specificallyspecifically specifically 在于zài yú zài yú 公开gōng kāi gōng kāi 漏洞lòu dòng lòu dòng 披露pī lù pī lù 流程liú chéng liú chéng ér ér fēi fēi 所有suǒ yǒu suǒ yǒu 网络安全wǎng luò ān quán wǎng luò ān quán 实践shí jiàn shí jiàn [[ [ 44 4 ]] ]
55 5 .. . ** * ** * 误导性wù dǎo xìng wù dǎo xìng 框架kuāng jià kuāng jià ** * ** * gāi gāi 主张zhǔ zhāng zhǔ zhāng 暗示àn shì àn shì 这是zhè shì zhè shì 联盟党lián méng dǎng lián méng dǎng 时代shí dài shí dài uniquelyuniquely uniquely 恶劣è liè è liè de de 管理guǎn lǐ guǎn lǐ 不善bù shàn bù shàn 这一zhè yī zhè yī 说法shuō fǎ shuō fǎ 没有méi yǒu méi yǒu 得到dé dào dé dào 充分chōng fèn chōng fèn 支持zhī chí zhī chí
LaborLabor Labor 政府zhèng fǔ zhèng fǔ 数字shù zì shù zì 健康jiàn kāng jiàn kāng 项目xiàng mù xiàng mù MyMy My HealthHealth Health RecordRecord Record 面临miàn lín miàn lín 类似lèi sì lèi sì de de 治理zhì lǐ zhì lǐ 安全ān quán ān quán 信任xìn rèn xìn rèn 问题wèn tí wèn tí [[ [ 1010 10 ,, , 1111 11 ]] ]
66 6 .. . ** * ** * 背景bèi jǐng bèi jǐng 缺失quē shī quē shī ** * ** * 20212021 2021 nián nián 疫情yì qíng yì qíng 期间qī jiān qī jiān 公共卫生gōng gòng wèi shēng gōng gòng wèi shēng 基础设施jī chǔ shè shī jī chǔ shè shī de de 快速kuài sù kuài sù 部署bù shǔ bù shǔ 有时yǒu shí yǒu shí 安全ān quán ān quán 成熟度chéng shú dù chéng shú dù 竞争jìng zhēng jìng zhēng zhè zhè 不能bù néng bù néng wèi wèi 失败shī bài shī bài 开脱kāi tuō kāi tuō dàn dàn 提供tí gōng tí gōng le le 背景bèi jǐng bèi jǐng
裁决cái jué cái jué shì shì 核心hé xīn hé xīn 事实shì shí shì shí 可靠kě kào kě kào 批评pī píng pī píng 合理hé lǐ hé lǐ dàn dàn 框架kuāng jià kuāng jià zài zài 没有méi yǒu méi yǒu 承认chéng rèn chéng rèn LaborLabor Labor 数字shù zì shù zì 健康jiàn kāng jiàn kāng 治理zhì lǐ zhì lǐ zhōng zhōng 类似lèi sì lèi sì 问题wèn tí wèn tí de de 情况qíng kuàng qíng kuàng xià xià 夸大kuā dà kuā dà le le 独特性dú tè xìng dú tè xìng huò huò 严重性yán zhòng xìng yán zhòng xìng

📚 来源与引用 (11)

  1. 1
    The need for an Australian Government Vulnerability Disclosure Policy - Richard Nelson, Medium

    The need for an Australian Government Vulnerability Disclosure Policy - Richard Nelson, Medium

    Recently, I found a weakness in the Express Plus Medicare application’s COVID-19 digital certificate:

    Medium
  2. 2
    COVID-19 vaccination certificates at risk of forgery after discovery of - ABC News

    COVID-19 vaccination certificates at risk of forgery after discovery of - ABC News

    The federal government's COVID-19 vaccine certificate can be forged using a widely known technique to bypass the protections, a member of the public has found.

    Abc Net
  3. 3
    Services Australia brushes off vulnerability concerns in COVID-19 digital certificates - ZDNet, Campbell Kwan

    Services Australia brushes off vulnerability concerns in COVID-19 digital certificates - ZDNet, Campbell Kwan

    There are no vulnerability disclosure programs in place nor any future plans to implement such a thing for Australia's COVID-19 digital certificate.

    ZDNET
  4. 4
    Vulnerability Disclosure Program - Department of Home Affairs

    Vulnerability Disclosure Program - Department of Home Affairs

    Home Affairs brings together Australia's federal law enforcement, national and transport security, criminal justice, emergency management, multicultural affairs, settlement services and immigration and border-related functions, working together to keep Australia safe.

    Department of Home Affairs Website
  5. 5
    Service NSW Vulnerability Disclosure Program via Bugcrowd

    Service NSW Vulnerability Disclosure Program via Bugcrowd

    Learn more about Service NSW’s Vulnerability Disclosure engagement powered by Bugcrowd, the leader in crowdsourced security solutions.

    Bugcrowd
  6. 6
    Service NSW official page

    Service NSW official page

    Service NSW welcomes vulnerability reports that help us to provide safe and secure services to our customers.

    Service NSW
  7. 7
    ZDNet Editorial Standards and contributor information

    ZDNet Editorial Standards and contributor information

    Discover ZDNET's editorial mission, how we evaluate products and our commitment to transparency about our business practices.

    ZDNET
  8. 8
    sciencedirect.com

    Privacy concerns of the Australian My Health Record: Implications for patient autonomy and consent - Science Direct

    Sciencedirect

  9. 9
    dailytelegraph.com.au

    My Health Record: privacy concern sparks calls from Labor to suspend rollout - Daily Telegraph

    Dailytelegraph Com

  10. 10
    cyber.gov.au

    Vulnerability Disclosure Programs explained - Cyber.gov.au

    Cyber Gov

  11. 11
    asd.gov.au

    ASD Responsible Release Principles

    Asd Gov

评分方法

1-3: 不实

事实错误或恶意捏造。

4-6: 部分属实

有一定真实性,但缺乏背景或有所偏颇。

7-9: 基本属实

仅有微小的技术性或措辞问题。

10: 准确

完全经过验证且客观公正。

方法论: 评分通过交叉参照政府官方记录、独立事实核查机构和原始文件确定。