部分属实

评分: 6.0/10

Coalition
C0024

声明内容

“未遵循COVID数字疫苗的网络安全最佳实践。他们没有有效的方式来报告漏洞,更不用说设置漏洞赏金来阻止将漏洞出售给犯罪分子。当政府最终得知其应用程序中存在漏洞时,他们未能及时响应或解决。”
原始来源: Matthew Davis
分析时间: 29 Jan 2026

原始来源

✅ 事实核查

###### ### COVIDCOVID COVID 数字证书shù zì zhèng shū shù zì zhèng shū 系统xì tǒng xì tǒng 中zhōng zhōng 的de de 漏洞lòu dòng lòu dòng
### Vulnerability in COVID Digital Certificate System
该gāi gāi 主张zhǔ zhāng zhǔ zhāng 的de de 核心hé xīn hé xīn 事实shì shí shì shí 得到dé dào dé dào 实质性shí zhì xìng shí zhì xìng 验证yàn zhèng yàn zhèng 。。 。
The core facts of the claim are substantially verified.
可信kě xìn kě xìn 的de de 安全ān quán ān quán 研究员yán jiū yuán yán jiū yuán RichardRichard Richard NelsonNelson Nelson 于yú yú 20212021 2021 年nián nián 99 9 月yuè yuè 发现fā xiàn fā xiàn 了le le 澳大利亚ào dà lì yà ào dà lì yà ExpressExpress Express PlusPlus Plus MedicareMedicare Medicare COVIDCOVID COVID -- - 1919 19 数字证书shù zì zhèng shū shù zì zhèng shū 系统xì tǒng xì tǒng 中zhōng zhōng 的de de 一个yí gè yí gè 重大zhòng dà zhòng dà 漏洞lòu dòng lòu dòng [[ [ 11 1 ]] ] 。。 。
Richard Nelson, a credible security researcher, discovered a significant vulnerability in Australia's Express Plus Medicare COVID-19 digital certificate system in September 2021 [1].
NelsonNelson Nelson 发现fā xiàn fā xiàn ,, , 通过tōng guò tōng guò 他tā tā 所说suǒ shuō suǒ shuō 的de de "" " 中间人zhōng jiān rén zhōng jiān rén "" " 漏洞lòu dòng lòu dòng ,, , 可以kě yǐ kě yǐ 轻而易举qīng ér yì jǔ qīng ér yì jǔ 地dì dì 让ràng ràng MedicareMedicare Medicare 应用程序yìng yòng chéng xù yìng yòng chéng xù 显示xiǎn shì xiǎn shì 一个yí gè yí gè 看似kàn shì kàn shì 有效yǒu xiào yǒu xiào 的de de COVIDCOVID COVID -- - 1919 19 疫苗yì miáo yì miáo 证书zhèng shū zhèng shū [[ [ 22 2 ]] ] 。。 。
Nelson found it was trivial to make the Medicare app display a valid-looking COVID-19 vaccine certificate through what he describes as a "man-in-the-middle" vulnerability [2].
这一zhè yī zhè yī 发现fā xiàn fā xiàn 被bèi bèi 包括bāo kuò bāo kuò ABCABC ABC 在内zài nèi zài nèi 的de de 主流zhǔ liú zhǔ liú 媒体méi tǐ méi tǐ 广泛guǎng fàn guǎng fàn 报道bào dào bào dào [[ [ 33 3 ]] ] 。。 。
This finding was widely reported by mainstream media, including the ABC [3].
###### ### 缺乏quē fá quē fá 漏洞lòu dòng lòu dòng 披露pī lù pī lù 计划jì huà jì huà
### Lack of Vulnerability Disclosure Program
关于guān yú guān yú 缺乏quē fá quē fá 正式zhèng shì zhèng shì 漏洞lòu dòng lòu dòng 披露pī lù pī lù 计划jì huà jì huà 的de de 主张zhǔ zhāng zhǔ zhāng 得到dé dào dé dào 了le le 政府zhèng fǔ zhèng fǔ 声明shēng míng shēng míng 的de de 证实zhèng shí zhèng shí 。。 。
The claim about the absence of a formal vulnerability disclosure program is confirmed by government statements.
在zài zài 20212021 2021 年底nián dǐ nián dǐ 的de de 预算yù suàn yù suàn 估算gū suàn gū suàn 听证会tīng zhèng huì tīng zhèng huì 上shàng shàng ,, , 当dāng dāng LaborLabor Labor 参议员cān yì yuán cān yì yuán 就jiù jiù 安全漏洞ān quán lòu dòng ān quán lòu dòng 向xiàng xiàng ServicesServices Services AustraliaAustralia Australia 质询zhì xún zhì xún 时shí shí ,, , 该gāi gāi 机构jī gòu jī gòu 明确míng què míng què 表示biǎo shì biǎo shì :: : "" " 目前mù qián mù qián 没有méi yǒu méi yǒu 任何rèn hé rèn hé 漏洞lòu dòng lòu dòng 披露pī lù pī lù 计划jì huà jì huà ,, , 也yě yě 没有méi yǒu méi yǒu 任何rèn hé rèn hé 未来wèi lái wèi lái 实施shí shī shí shī 此类cǐ lèi cǐ lèi 计划jì huà jì huà 的de de 安排ān pái ān pái "" " [[ [ 44 4 ]] ] 。。 。
During Budget Estimates hearings in late 2021, when grilled by Labor senators about the security vulnerabilities, Services Australia explicitly stated: "There are currently no vulnerability disclosure programs in place nor any future plans to implement such a program for the digital vaccination certificates" [4].
此外cǐ wài cǐ wài ,, , 数字shù zì shù zì 转型zhuǎn xíng zhuǎn xíng 局jú jú (( ( DTADTA DTA )) ) 表示biǎo shì biǎo shì "" " 没有méi yǒu méi yǒu 考虑kǎo lǜ kǎo lǜ 建立jiàn lì jiàn lì 赏金shǎng jīn shǎng jīn 计划jì huà jì huà 的de de 打算dǎ suàn dǎ suàn "" " [[ [ 55 5 ]] ] 。。 。
Additionally, the Digital Transformation Agency (DTA) stated it had "no plans to consider establishing bounty programs" [5].
###### ### 报告bào gào bào gào 漏洞lòu dòng lòu dòng 的de de 困难kùn nán kùn nán
### Difficulty Reporting Vulnerabilities
NelsonNelson Nelson 的de de 个人经历gè rén jīng lì gè rén jīng lì 证实zhèng shí zhèng shí 了le le 该gāi gāi 主张zhǔ zhāng zhǔ zhāng 的de de 第二dì èr dì èr 部分bù fèn bù fèn 。。 。
Nelson's personal experience corroborates the second part of the claim.
当dāng dāng 他tā tā 发现fā xiàn fā xiàn 漏洞lòu dòng lòu dòng 时shí shí ,, , 他tā tā 在zài zài 通过tōng guò tōng guò 适当shì dàng shì dàng 渠道qú dào qú dào 报告bào gào bào gào 时shí shí 面临miàn lín miàn lín 重大zhòng dà zhòng dà 挑战tiǎo zhàn tiǎo zhàn [[ [ 11 1 ]] ] 。。 。
When he discovered the vulnerability, he faced significant challenges in reporting it through proper channels [1].
他tā tā 尝试cháng shì cháng shì 了le le 多种duō zhǒng duō zhǒng 报告bào gào bào gào 途径tú jìng tú jìng :: :
He attempted multiple reporting pathways: - Tried calling Services Australia directly but gave up after being placed on hold [1] - Found the Department of Health had a Vulnerability Disclosure Policy, but Express Plus Medicare fell under Services Australia, not Health [1] - Reported it via ReportCyber and the Australian Signals Directorate (ASD), but received no response until days later [1] - Only after publicly tweeting about the vulnerability and being contacted by journalists did Services Australia appear to take action [1]
-- - 尝试cháng shì cháng shì 直接zhí jiē zhí jiē 致电zhì diàn zhì diàn ServicesServices Services AustraliaAustralia Australia ,, , 但dàn dàn 在zài zài 被bèi bèi 搁置gē zhì gē zhì 后hòu hòu 放弃fàng qì fàng qì 了le le [[ [ 11 1 ]] ]
### Response and Remediation Timeliness
-- - 发现fā xiàn fā xiàn 卫生部wèi shēng bù wèi shēng bù 有yǒu yǒu 漏洞lòu dòng lòu dòng 披露pī lù pī lù 政策zhèng cè zhèng cè ,, , 但dàn dàn ExpressExpress Express PlusPlus Plus MedicareMedicare Medicare 属于shǔ yú shǔ yú ServicesServices Services AustraliaAustralia Australia ,, , 而ér ér 非fēi fēi 卫生部wèi shēng bù wèi shēng bù [[ [ 11 1 ]] ]
The evidence supports criticism of response timeliness.
-- - 通过tōng guò tōng guò ReportCyberReportCyber ReportCyber 和hé hé 澳大利亚ào dà lì yà ào dà lì yà 信号xìn hào xìn hào 局jú jú (( ( ASDASD ASD )) ) 报告bào gào bào gào ,, , 但dàn dàn 直到zhí dào zhí dào 几天jǐ tiān jǐ tiān 后hòu hòu 才cái cái 收到shōu dào shōu dào 回复huí fù huí fù [[ [ 11 1 ]] ]
Nelson noted that Services Australia did not reach out to him after he went public via Twitter and media, likely because the issue had become sensitive and the agency wanted to avoid additional press coverage [1].
-- - 只有zhǐ yǒu zhǐ yǒu 在zài zài 公开gōng kāi gōng kāi 在zài zài 推特上tuī tè shàng tuī tè shàng 发布fā bù fā bù 漏洞lòu dòng lòu dòng 并bìng bìng 被bèi bèi 记者jì zhě jì zhě 联系lián xì lián xì 后hòu hòu ,, , ServicesServices Services AustraliaAustralia Australia 似乎sì hū sì hū 才cái cái 采取行动cǎi qǔ xíng dòng cǎi qǔ xíng dòng [[ [ 11 1 ]] ]
This demonstrates a reactive rather than proactive approach to vulnerability handling.
###### ### 响应xiǎng yìng xiǎng yìng 和hé hé 修复xiū fù xiū fù 的de de 及时性jí shí xìng jí shí xìng
However, the sources do not provide explicit evidence of extended remediation timelines after the initial reporting or public disclosure.
证据zhèng jù zhèng jù 支持zhī chí zhī chí 对duì duì 响应xiǎng yìng xiǎng yìng 及时性jí shí xìng jí shí xìng 的de de 批评pī píng pī píng 。。 。
NelsonNelson Nelson 指出zhǐ chū zhǐ chū ,, , 在zài zài 他tā tā 通过tōng guò tōng guò 推特tuī tè tuī tè 和hé hé 媒体méi tǐ méi tǐ 公开gōng kāi gōng kāi 后hòu hòu ,, , ServicesServices Services AustraliaAustralia Australia 并未bìng wèi bìng wèi 与yǔ yǔ 他tā tā 联系lián xì lián xì ,, , 可能kě néng kě néng 是因为shì yīn wèi shì yīn wèi 该gāi gāi 问题wèn tí wèn tí 已yǐ yǐ 变得biàn dé biàn dé 敏感mǐn gǎn mǐn gǎn ,, , 该gāi gāi 机构jī gòu jī gòu 希望xī wàng xī wàng 避免bì miǎn bì miǎn 额外é wài é wài 的de de 媒体报道méi tǐ bào dào méi tǐ bào dào [[ [ 11 1 ]] ] 。。 。
这zhè zhè demonstratedemonstrate demonstrate 了le le 一种yī zhǒng yī zhǒng 被动bèi dòng bèi dòng 而ér ér 非fēi fēi 主动zhǔ dòng zhǔ dòng 的de de 漏洞lòu dòng lòu dòng 处理chǔ lǐ chǔ lǐ 方式fāng shì fāng shì 。。 。
然而rán ér rán ér ,, , 来源lái yuán lái yuán 未wèi wèi 提供tí gōng tí gōng 关于guān yú guān yú 初次chū cì chū cì 报告bào gào bào gào 或huò huò 公开gōng kāi gōng kāi 披露pī lù pī lù 后hòu hòu 延长yán cháng yán cháng 修复xiū fù xiū fù 时间表shí jiān biǎo shí jiān biǎo 的de de 明确míng què míng què 证据zhèng jù zhèng jù 。。 。

缺失背景

该gāi gāi 主张zhǔ zhāng zhǔ zhāng 需要xū yào xū yào 大量dà liàng dà liàng 额外é wài é wài 背景bèi jǐng bèi jǐng :: :
The claim requires significant additional context: **1.
** * ** * 11 1 .. . 政府zhèng fǔ zhèng fǔ 网络安全wǎng luò ān quán wǎng luò ān quán 框架kuāng jià kuāng jià 存在cún zài cún zài :: : ** * ** * ServicesServices Services AustraliaAustralia Australia 声称shēng chēng shēng chēng 每年měi nián měi nián 进行jìn xíng jìn xíng "" " 多次duō cì duō cì 完整wán zhěng wán zhěng 的de de 网络wǎng luò wǎng luò 评估píng gū píng gū "" " ,, , 并bìng bìng 表示biǎo shì biǎo shì "" " 与yǔ yǔ 澳大利亚ào dà lì yà ào dà lì yà 信号xìn hào xìn hào 局jú jú 和hé hé 澳大利亚ào dà lì yà ào dà lì yà 网络安全wǎng luò ān quán wǎng luò ān quán 中心zhōng xīn zhōng xīn 密切合作mì qiè hé zuò mì qiè hé zuò ,, , 关注guān zhù guān zhù 移动yí dòng yí dòng 应用程序yìng yòng chéng xù yìng yòng chéng xù 的de de 潜在qián zài qián zài 漏洞lòu dòng lòu dòng "" " [[ [ 44 4 ]] ] 。。 。
Government Cybersecurity Framework Existed:** Services Australia claimed to undertake "full cyber assessments several times a year" and stated it "work[s] closely with the Australian Signals Directorate and Australian Cyber Security Centre on potential vulnerabilities on mobile applications" [4].
这zhè zhè 表明biǎo míng biǎo míng 政府zhèng fǔ zhèng fǔ 确实què shí què shí 有yǒu yǒu 网络安全wǎng luò ān quán wǎng luò ān quán 流程liú chéng liú chéng ,, , 尽管jǐn guǎn jǐn guǎn 它们tā men tā men 不足以bù zú yǐ bù zú yǐ 处理chǔ lǐ chǔ lǐ 研究员yán jiū yuán yán jiū yuán 报告bào gào bào gào 。。 。
This indicates the government did have cybersecurity processes in place, though they were not sufficient for handling researcher reports. **2.
** * ** * 22 2 .. . 某些mǒu xiē mǒu xiē 机构jī gòu jī gòu 已有yǐ yǒu yǐ yǒu 漏洞lòu dòng lòu dòng 披露pī lù pī lù 计划jì huà jì huà :: : ** * ** * 虽然suī rán suī rán ServicesServices Services AustraliaAustralia Australia 缺乏quē fá quē fá VDPVDP VDP ,, , 但dàn dàn 其他qí tā qí tā 澳大利亚政府ào dà lì yà zhèng fǔ ào dà lì yà zhèng fǔ 机构jī gòu jī gòu 已yǐ yǐ 实施shí shī shí shī 。。 。
Some Agencies Had Vulnerability Disclosure Programs:** While Services Australia lacked a VDP, other Australian government agencies had implemented them.
内政部nèi zhèng bù nèi zhèng bù 已yǐ yǐ 实施shí shī shí shī 漏洞lòu dòng lòu dòng 披露pī lù pī lù 计划jì huà jì huà [[ [ 66 6 ]] ] ,, , 新南威尔士州xīn nán wēi ěr shì zhōu xīn nán wēi ěr shì zhōu 服务局fú wù jú fú wù jú 通过tōng guò tōng guò BugcrowdBugcrowd Bugcrowd 运营yùn yíng yùn yíng 漏洞lòu dòng lòu dòng 赏金shǎng jīn shǎng jīn 计划jì huà jì huà [[ [ 77 7 ]] ] 。。 。
The Department of Home Affairs had a Vulnerability Disclosure Program in place [6], and Service NSW operated a bug bounty program through Bugcrowd [7].
这zhè zhè 表明biǎo míng biǎo míng 各gè gè 机构jī gòu jī gòu 实施shí shī shí shī 不bù bù 一致yí zhì yí zhì ,, , 而ér ér 非全fēi quán fēi quán 政府zhèng fǔ zhèng fǔ 范围fàn wéi fàn wéi 的de de 政策zhèng cè zhèng cè 失败shī bài shī bài 。。 。
This suggests inconsistent implementation across agencies rather than a government-wide policy failure. **3.
** * ** * 33 3 .. . 严重性yán zhòng xìng yán zhòng xìng 评估píng gū píng gū :: : ** * ** * ServicesServices Services AustraliaAustralia Australia 将jiāng jiāng 所suǒ suǒ 需xū xū 攻击gōng jī gōng jī 描述miáo shù miáo shù 为wèi wèi "" " 需要xū yào xū yào 大量dà liàng dà liàng 知识zhī shí zhī shí 和hé hé 专长zhuān cháng zhuān cháng "" " [[ [ 44 4 ]] ] ,, , 表明biǎo míng biǎo míng 他们tā men tā men 认为rèn wéi rèn wéi 实际shí jì shí jì 风险fēng xiǎn fēng xiǎn 低于dī yú dī yú 理论lǐ lùn lǐ lùn 漏洞lòu dòng lòu dòng 可能kě néng kě néng 暗示àn shì àn shì 的de de 程度chéng dù chéng dù 。。 。
Severity Assessment:** Services Australia characterized the required attack as something that "require[s] significant knowledge and expertise" [4], suggesting they viewed the practical risk as lower than the theoretical vulnerability might suggest.
然而rán ér rán ér ,, , 这一zhè yī zhè yī 辩护biàn hù biàn hù 力度lì dù lì dù 较弱jiào ruò jiào ruò —— — —— — 无论wú lùn wú lùn 攻击gōng jī gōng jī 复杂程度fù zá chéng dù fù zá chéng dù 如何rú hé rú hé ,, , 安全漏洞ān quán lòu dòng ān quán lòu dòng 都dōu dōu 应yīng yīng 得到dé dào dé dào 解决jiě jué jiě jué 。。 。
However, this defense is weak—security vulnerabilities should be addressed regardless of attack complexity. **4.
** * ** * 44 4 .. . 可kě kě 伪造wěi zào wěi zào 性xìng xìng 与yǔ yǔ 篡改cuàn gǎi cuàn gǎi :: : ** * ** * 该gāi gāi 漏洞lòu dòng lòu dòng 涉及shè jí shè jí 让ràng ràng 应用程序yìng yòng chéng xù yìng yòng chéng xù 显示xiǎn shì xiǎn shì 虚假xū jiǎ xū jiǎ 证书zhèng shū zhèng shū (( ( 客户端kè hù duān kè hù duān 漏洞lòu dòng lòu dòng )) ) ,, , 而ér ér 非fēi fēi 创建chuàng jiàn chuàng jiàn 能néng néng 通过tōng guò tōng guò 后hòu hòu 端duān duān 验证yàn zhèng yàn zhèng 的de de 伪造wěi zào wěi zào 证书zhèng shū zhèng shū 。。 。
Forgeability vs.
NelsonNelson Nelson 自己zì jǐ zì jǐ 的de de 推文tuī wén tuī wén 强调qiáng diào qiáng diào 了le le 显示xiǎn shì xiǎn shì 漏洞lòu dòng lòu dòng 的de de 简便性jiǎn biàn xìng jiǎn biàn xìng ,, , 但dàn dàn 有限yǒu xiàn yǒu xiàn 证据zhèng jù zhèng jù 表明biǎo míng biǎo míng 底层dǐ céng dǐ céng 注册表zhù cè biǎo zhù cè biǎo 可kě kě 被bèi bèi 欺骗qī piàn qī piàn [[ [ 33 3 ]] ] 。。 。
Tampering:** The vulnerability involved making the app display a false certificate (client-side vulnerability) rather than creating counterfeit certificates that would pass backend validation.
** * ** * 55 5 .. . 推出tuī chū tuī chū 时间shí jiān shí jiān 线xiàn xiàn :: : ** * ** * COVIDCOVID COVID -- - 1919 19 数字证书shù zì zhèng shū shù zì zhèng shū 是shì shì 在zài zài 疫情yì qíng yì qíng 期间qī jiān qī jiān 的de de 20212021 2021 年nián nián 中期zhōng qī zhōng qī 相对xiāng duì xiāng duì 仓促cāng cù cāng cù 推出tuī chū tuī chū 的de de [[ [ 88 8 ]] ] 。。 。
Nelson's own tweet emphasized the ease of the display vulnerability, but there's limited evidence the underlying registry could be spoofed [3]. **5.
这一zhè yī zhè yī 背景bèi jǐng bèi jǐng 不能bù néng bù néng 为wèi wèi 安全ān quán ān quán 缺陷quē xiàn quē xiàn 开脱kāi tuō kāi tuō ,, , 但dàn dàn 解释jiě shì jiě shì 了le le 快速kuài sù kuài sù 部署bù shǔ bù shǔ 的de de 一些yī xiē yī xiē 压力yā lì yā lì 。。 。
Timeline of Rollout:** The COVID-19 digital certificate was introduced relatively hastily during pandemic conditions (rolled out in mid-2021) [8].

来源可信度评估

###### ### 原始yuán shǐ yuán shǐ 来源lái yuán lái yuán
### Original Sources
** * ** * RichardRichard Richard NelsonNelson Nelson (( ( MediumMedium Medium 文章wén zhāng wén zhāng )) ) :: : ** * ** *
**Richard Nelson (Medium article):** - Credible security researcher with demonstrable expertise; his other Medium articles show deep technical knowledge of government security systems (COVIDSafe analysis, Service NSW driver license reverse engineering) [1] - Personal account of attempting responsible disclosure; makes genuine effort to follow proper procedures before going public [1] - Transparent about his frustration and emotional state; acknowledges the difficulty of his position [1] - Appears motivated by public security, not partisan politics; no evidence of political alignment toward Labor [1] **ZDNet (Campbell Kwan article):** - Mainstream technology news outlet with editorial standards [9] - Reports on Budget Estimates proceedings, which are documented public records [4] - Accurately cites the government's own statements; quotes are verifiable [4] - Campbell Kwan is a regular contributor on government technology issues [9] - However, the article emphasizes criticism from Labor senators and doesn't deeply explore government rationale or mitigating context
-- - 具有jù yǒu jù yǒu 可kě kě 证明zhèng míng zhèng míng 专业知识zhuān yè zhī shí zhuān yè zhī shí 可信kě xìn kě xìn 安全ān quán ān quán 研究员yán jiū yuán yán jiū yuán ;; ; 他tā tā 的de de 其他qí tā qí tā MediumMedium Medium 文章wén zhāng wén zhāng 显示xiǎn shì xiǎn shì 对duì duì 政府zhèng fǔ zhèng fǔ 安全ān quán ān quán 系统xì tǒng xì tǒng (( ( COVIDSafeCOVIDSafe COVIDSafe 分析fēn xī fēn xī 、、 、 新南威尔士州xīn nán wēi ěr shì zhōu xīn nán wēi ěr shì zhōu 服务局fú wù jú fú wù jú 驾驶执照jià shǐ zhí zhào jià shǐ zhí zhào 逆向nì xiàng nì xiàng 工程gōng chéng gōng chéng )) ) 有yǒu yǒu 深入shēn rù shēn rù 了解liǎo jiě liǎo jiě 的de de 技术jì shù jì shù 知识zhī shí zhī shí [[ [ 11 1 ]] ]
### Bias Assessment
-- - 尝试cháng shì cháng shì 负责fù zé fù zé 任rèn rèn 披露pī lù pī lù 的de de 个人账户gè rén zhàng hù gè rén zhàng hù ;; ; 在zài zài 公开gōng kāi gōng kāi 前qián qián 真诚zhēn chéng zhēn chéng 努力nǔ lì nǔ lì 遵循zūn xún zūn xún 适当shì dàng shì dàng 程序chéng xù chéng xù [[ [ 11 1 ]] ]
Neither source appears primarily motivated by partisan bias, though the ZDNet article gives prominence to Labor senators' criticisms in a federal Budget Estimates context.
-- - 对duì duì 自己zì jǐ zì jǐ 的de de 挫败cuò bài cuò bài 感gǎn gǎn 和hé hé 情绪qíng xù qíng xù 状态zhuàng tài zhuàng tài 保持bǎo chí bǎo chí 透明tòu míng tòu míng ;; ; 承认chéng rèn chéng rèn 自己zì jǐ zì jǐ 所suǒ suǒ 处chù chù 位置wèi zhì wèi zhì 的de de 困难kùn nán kùn nán [[ [ 11 1 ]] ]
The sources are factual and verifiable, though they emphasize government failures rather than providing balanced context.
-- - 似乎sì hū sì hū 出于chū yú chū yú 公共安全gōng gòng ān quán gōng gòng ān quán 动机dòng jī dòng jī ,, , 而ér ér 非fēi fēi 党派dǎng pài dǎng pài 政治zhèng zhì zhèng zhì ;; ; 没有méi yǒu méi yǒu 证据zhèng jù zhèng jù 表明biǎo míng biǎo míng 其qí qí 倾向qīng xiàng qīng xiàng 于yú yú LaborLabor Labor [[ [ 11 1 ]] ]
This is appropriate for security reporting—the vulnerability was real and the response was inadequate—but the framing is inherently critical rather than neutral.
** * ** * ZDNetZDNet ZDNet (( ( CampbellCampbell Campbell KwanKwan Kwan 文章wén zhāng wén zhāng )) ) :: : ** * ** *
-- - 具有jù yǒu jù yǒu 编辑biān jí biān jí 标准biāo zhǔn biāo zhǔn 的de de 主流zhǔ liú zhǔ liú 科技kē jì kē jì 新闻媒体xīn wén méi tǐ xīn wén méi tǐ [[ [ 99 9 ]] ]
-- - 报道bào dào bào dào 预算yù suàn yù suàn 估算gū suàn gū suàn 程序chéng xù chéng xù ,, , 这些zhè xiē zhè xiē 是shì shì 记录在案jì lù zài àn jì lù zài àn 的de de 公开gōng kāi gōng kāi 记录jì lù jì lù [[ [ 44 4 ]] ]
-- - 准确zhǔn què zhǔn què 引用yǐn yòng yǐn yòng 政府zhèng fǔ zhèng fǔ 自己zì jǐ zì jǐ 的de de 声明shēng míng shēng míng ;; ; 引述yǐn shù yǐn shù 可验证kě yàn zhèng kě yàn zhèng [[ [ 44 4 ]] ]
-- - CampbellCampbell Campbell KwanKwan Kwan 是shì shì 政府zhèng fǔ zhèng fǔ 技术jì shù jì shù 问题wèn tí wèn tí 的de de 定期dìng qī dìng qī 撰稿人zhuàn gǎo rén zhuàn gǎo rén [[ [ 99 9 ]] ]
-- - 然而rán ér rán ér ,, , 文章wén zhāng wén zhāng 强调qiáng diào qiáng diào LaborLabor Labor 参议员cān yì yuán cān yì yuán 的de de 批评pī píng pī píng ,, , 并未bìng wèi bìng wèi 深入探讨shēn rù tàn tǎo shēn rù tàn tǎo 政府zhèng fǔ zhèng fǔ 理由lǐ yóu lǐ yóu 或huò huò 缓解huǎn jiě huǎn jiě 性xìng xìng 背景bèi jǐng bèi jǐng
###### ### 偏见piān jiàn piān jiàn 评估píng gū píng gū
两个liǎng gè liǎng gè 来源lái yuán lái yuán 似乎sì hū sì hū 都dōu dōu 不是bú shì bú shì 主要zhǔ yào zhǔ yào 由yóu yóu 党派dǎng pài dǎng pài 偏见piān jiàn piān jiàn 驱动qū dòng qū dòng ,, , 尽管jǐn guǎn jǐn guǎn ZDNetZDNet ZDNet 文章wén zhāng wén zhāng 在zài zài 联邦lián bāng lián bāng 预算yù suàn yù suàn 估算gū suàn gū suàn 背景bèi jǐng bèi jǐng 下xià xià 突出tū chū tū chū LaborLabor Labor 参议员cān yì yuán cān yì yuán 的de de 批评pī píng pī píng 。。 。
来源lái yuán lái yuán 是shì shì 事实性shì shí xìng shì shí xìng 和hé hé 可验证kě yàn zhèng kě yàn zhèng 的de de ,, , 尽管jǐn guǎn jǐn guǎn 它们tā men tā men 强调qiáng diào qiáng diào 政府zhèng fǔ zhèng fǔ 失败shī bài shī bài 而ér ér 非fēi fēi 提供tí gōng tí gōng 平衡píng héng píng héng 背景bèi jǐng bèi jǐng 。。 。
这zhè zhè 适合shì hé shì hé 安全ān quán ān quán 报告bào gào bào gào —— — —— — 漏洞lòu dòng lòu dòng 是shì shì 真实zhēn shí zhēn shí 的de de ,, , 响应xiǎng yìng xiǎng yìng 是shì shì 不bù bù 充分chōng fèn chōng fèn 的de de —— — —— — 但dàn dàn 框架kuāng jià kuāng jià 本质běn zhì běn zhì 上shàng shàng 是shì shì 批评性pī píng xìng pī píng xìng 的de de 而ér ér 非fēi fēi 中立zhōng lì zhōng lì 的de de 。。 。
⚖️

工党对比

** * ** * LaborLabor Labor 的de de 数字shù zì shù zì 健康jiàn kāng jiàn kāng 系统xì tǒng xì tǒng 是否shì fǒu shì fǒu 存在cún zài cún zài 重大zhòng dà zhòng dà 网络安全wǎng luò ān quán wǎng luò ān quán 问题wèn tí wèn tí ?? ?
**Did Labor have significant cybersecurity issues with digital health systems?** Search conducted: "Labor government Australian digital health system cybersecurity privacy breach MyHealth Records" Labor's handling of the My Health Record system shows relevant precedent.
** * ** *
The My Health Record was introduced by the Labor government in 2012 and became highly controversial [10].
搜索sōu suǒ sōu suǒ 查询chá xún chá xún :: : "" " LaborLabor Labor 政府zhèng fǔ zhèng fǔ 澳大利亚ào dà lì yà ào dà lì yà 数字shù zì shù zì 健康jiàn kāng jiàn kāng 系统xì tǒng xì tǒng 网络安全wǎng luò ān quán wǎng luò ān quán 隐私yǐn sī yǐn sī 泄露xiè lòu xiè lòu MyHealthMyHealth MyHealth RecordsRecords Records "" "
The system faced significant privacy concerns, leading Labor itself to call for a suspension of the rollout when the Coalition expanded it [11].
LaborLabor Labor 对duì duì MyMy My HealthHealth Health RecordRecord Record 系统xì tǒng xì tǒng 的de de 处理chǔ lǐ chǔ lǐ 显示xiǎn shì xiǎn shì 了le le 相关xiāng guān xiāng guān 先例xiān lì xiān lì 。。 。
The Privacy Commissioner raised concerns, and there was substantial public backlash [10].
MyMy My HealthHealth Health RecordRecord Record 于yú yú 20122012 2012 年nián nián 由yóu yóu LaborLabor Labor 政府zhèng fǔ zhèng fǔ 推出tuī chū tuī chū ,, , 并bìng bìng 引发yǐn fā yǐn fā 高度gāo dù gāo dù 争议zhēng yì zhēng yì [[ [ 1010 10 ]] ] 。。 。
While this represents a broader policy failure (flawed design from the start) rather than a cybersecurity vulnerability disclosure issue specifically, it demonstrates that Labor governments have also struggled with digital health system security and public trust in similar areas. **Comparable Cybersecurity Incident:** There is no evidence of Labor government digital health systems facing similar cybersecurity vulnerability disclosure policy gaps during their period in government (2007-2013).
该gāi gāi 系统xì tǒng xì tǒng 面临miàn lín miàn lín 重大zhòng dà zhòng dà 隐私yǐn sī yǐn sī 问题wèn tí wèn tí ,, , 导致dǎo zhì dǎo zhì LaborLabor Labor 自己zì jǐ zì jǐ 在zài zài 联盟党lián méng dǎng lián méng dǎng 扩展kuò zhǎn kuò zhǎn 时shí shí 呼吁hū yù hū yù 暂停zàn tíng zàn tíng 推出tuī chū tuī chū [[ [ 1111 11 ]] ] 。。 。
However, the broader theme of inadequate digital security governance appears to be a systemic Australian government issue across parties rather than unique to the Coalition.
隐私yǐn sī yǐn sī 专员zhuān yuán zhuān yuán 提出tí chū tí chū 担忧dān yōu dān yōu ,, , 公众gōng zhòng gōng zhòng 强烈qiáng liè qiáng liè 反对fǎn duì fǎn duì [[ [ 1010 10 ]] ] 。。 。
虽然suī rán suī rán 这zhè zhè 代表dài biǎo dài biǎo 更gèng gèng 广泛guǎng fàn guǎng fàn 的de de 政策zhèng cè zhèng cè 失败shī bài shī bài (( ( 从cóng cóng 一yī yī 开始kāi shǐ kāi shǐ 就jiù jiù 有yǒu yǒu 缺陷quē xiàn quē xiàn 的de de 设计shè jì shè jì )) ) ,, , 而ér ér 非fēi fēi 具体jù tǐ jù tǐ 的de de 网络安全wǎng luò ān quán wǎng luò ān quán 漏洞lòu dòng lòu dòng 披露pī lù pī lù 问题wèn tí wèn tí ,, , 但dàn dàn 它tā tā 表明biǎo míng biǎo míng LaborLabor Labor 政府zhèng fǔ zhèng fǔ 在zài zài 数字shù zì shù zì 健康jiàn kāng jiàn kāng 系统安全xì tǒng ān quán xì tǒng ān quán 和hé hé 公众gōng zhòng gōng zhòng 信任xìn rèn xìn rèn 方面fāng miàn fāng miàn 也yě yě 曾céng céng 在zài zài 类似lèi sì lèi sì 领域lǐng yù lǐng yù 挣扎zhēng zhá zhēng zhá 。。 。
** * ** * 可比kě bǐ kě bǐ 网络安全wǎng luò ān quán wǎng luò ān quán 事件shì jiàn shì jiàn :: : ** * ** * 没有méi yǒu méi yǒu 证据zhèng jù zhèng jù 表明biǎo míng biǎo míng LaborLabor Labor 政府zhèng fǔ zhèng fǔ 数字shù zì shù zì 健康jiàn kāng jiàn kāng 系统xì tǒng xì tǒng 在zài zài 执政zhí zhèng zhí zhèng 期间qī jiān qī jiān (( ( 20072007 2007 -- - 20132013 2013 年nián nián )) ) 面临miàn lín miàn lín 类似lèi sì lèi sì 的de de 网络安全wǎng luò ān quán wǎng luò ān quán 漏洞lòu dòng lòu dòng 披露pī lù pī lù 政策zhèng cè zhèng cè 缺口quē kǒu quē kǒu 。。 。
然而rán ér rán ér ,, , 不bù bù 充分chōng fèn chōng fèn 的de de 数字shù zì shù zì 安全ān quán ān quán 治理zhì lǐ zhì lǐ 这一zhè yī zhè yī 更gèng gèng 广泛guǎng fàn guǎng fàn 的de de 主题zhǔ tí zhǔ tí 似乎sì hū sì hū 是shì shì 跨越kuà yuè kuà yuè 党派dǎng pài dǎng pài 的de de 系统性xì tǒng xìng xì tǒng xìng 澳大利亚政府ào dà lì yà zhèng fǔ ào dà lì yà zhèng fǔ 问题wèn tí wèn tí ,, , 而ér ér 非fēi fēi 联盟党lián méng dǎng lián méng dǎng 独有dú yǒu dú yǒu 。。 。
🌐

平衡视角

** * ** * 政府zhèng fǔ zhèng fǔ 立场lì chǎng lì chǎng :: : ** * ** *
**Government's Position:** Services Australia maintained that the COVID-19 digital certificate system included multiple security layers and that the vulnerability discovered required "significant knowledge and expertise" to exploit [4].
ServicesServices Services AustraliaAustralia Australia 坚称jiān chēng jiān chēng COVIDCOVID COVID -- - 1919 19 数字证书shù zì zhèng shū shù zì zhèng shū 系统xì tǒng xì tǒng 包含bāo hán bāo hán 多层duō céng duō céng 安全ān quán ān quán ,, , 发现fā xiàn fā xiàn 的de de 漏洞lòu dòng lòu dòng 需要xū yào xū yào "" " 大量dà liàng dà liàng 知识zhī shí zhī shí 和hé hé 专长zhuān cháng zhuān cháng "" " 才能cái néng cái néng 利用lì yòng lì yòng [[ [ 44 4 ]] ] 。。 。
The agency emphasized it was cooperating with the Australian Signals Directorate and conducting regular cyber assessments [4].
该gāi gāi 机构jī gòu jī gòu 强调qiáng diào qiáng diào 正在zhèng zài zhèng zài 与yǔ yǔ 澳大利亚ào dà lì yà ào dà lì yà 信号xìn hào xìn hào 局jú jú 合作hé zuò hé zuò 并bìng bìng 进行jìn xíng jìn xíng 定期dìng qī dìng qī 网络wǎng luò wǎng luò 评估píng gū píng gū [[ [ 44 4 ]] ] 。。 。
The government's perspective was that while the vulnerability should be addressed, it was not a critical failure requiring immediate overhaul of the entire system. **Security Expert Perspective:** Richard Nelson's position is well-reasoned from a security governance standpoint: even if a vulnerability requires expertise to exploit, proper channels for responsible disclosure should exist.
政府zhèng fǔ zhèng fǔ 的de de 观点guān diǎn guān diǎn 是shì shì ,, , 虽然suī rán suī rán 应该yīng gāi yīng gāi 解决jiě jué jiě jué 该gāi gāi 漏洞lòu dòng lòu dòng ,, , 但dàn dàn 它tā tā 不是bú shì bú shì 需要xū yào xū yào 立即lì jí lì jí 彻底chè dǐ chè dǐ 改革gǎi gé gǎi gé 整个zhěng gè zhěng gè 系统xì tǒng xì tǒng 的de de 关键guān jiàn guān jiàn 失败shī bài shī bài 。。 。
He argues this is standard industry practice and that the absence of such channels is what forced him to make the issue public [1].
** * ** * 安全ān quán ān quán 专家zhuān jiā zhuān jiā 观点guān diǎn guān diǎn :: : ** * ** *
This is a legitimate concern about institutional security maturity, not just about the existence of any single vulnerability. **Systemic Issue vs.
从cóng cóng 安全ān quán ān quán 治理zhì lǐ zhì lǐ 角度jiǎo dù jiǎo dù 来看lái kàn lái kàn ,, , RichardRichard Richard NelsonNelson Nelson 的de de 立场lì chǎng lì chǎng 是shì shì 合理hé lǐ hé lǐ 的de de :: : 即使jí shǐ jí shǐ 漏洞lòu dòng lòu dòng 需要xū yào xū yào 专业知识zhuān yè zhī shí zhuān yè zhī shí 才能cái néng cái néng 利用lì yòng lì yòng ,, , 也yě yě 应该yīng gāi yīng gāi 存在cún zài cún zài 适当shì dàng shì dàng 的de de 负责fù zé fù zé 任rèn rèn 披露pī lù pī lù 渠道qú dào qú dào 。。 。
Malicious Intent:** The evidence suggests this was primarily a systemic governance failure (lack of formal processes) rather than negligence or malicious intent.
他tā tā 认为rèn wéi rèn wéi 这是zhè shì zhè shì 标准biāo zhǔn biāo zhǔn 行业háng yè háng yè 实践shí jiàn shí jiàn ,, , 缺乏quē fá quē fá 此类cǐ lèi cǐ lèi 渠道qú dào qú dào 迫使pò shǐ pò shǐ 他tā tā 公开gōng kāi gōng kāi 问题wèn tí wèn tí [[ [ 11 1 ]] ] 。。 。
Services Australia demonstrated awareness of security concerns and was conducting assessments [4].
这zhè zhè 是shì shì 对duì duì 机构jī gòu jī gòu 安全ān quán ān quán 成熟度chéng shú dù chéng shú dù 的de de 合理hé lǐ hé lǐ 担忧dān yōu dān yōu ,, , 不仅仅bù jǐn jǐn bù jǐn jǐn 是shì shì 关于guān yú guān yú 任何rèn hé rèn hé 单一dān yī dān yī 漏洞lòu dòng lòu dòng 的de de 存在cún zài cún zài 。。 。
The failure was in not having established, well-publicized, responsive channels for researchers to report vulnerabilities—a process issue rather than a technical issue. **Industry Practice Context:** Vulnerability disclosure programs (VDPs) and bug bounties have become industry standard practice across major tech companies and, increasingly, government agencies.
** * ** * 系统性xì tǒng xìng xì tǒng xìng 问题wèn tí wèn tí 与yǔ yǔ 恶意è yì è yì 意图yì tú yì tú :: : ** * ** *
The ASD and Cyber.gov.au have published guidance on implementing VDPs [12].
证据zhèng jù zhèng jù 表明biǎo míng biǎo míng 这zhè zhè 主要zhǔ yào zhǔ yào 是shì shì 系统性xì tǒng xìng xì tǒng xìng 治理zhì lǐ zhì lǐ 失败shī bài shī bài (( ( 缺乏quē fá quē fá 正式zhèng shì zhèng shì 流程liú chéng liú chéng )) ) ,, , 而ér ér 非fēi fēi 疏忽shū hū shū hū 或huò huò 恶意è yì è yì 意图yì tú yì tú 。。 。
By 2021, the absence of a formal VDP for a public-facing COVID safety system was notably behind current best practices, though it wasn't unique to Australia or the Coalition government at that time. **Key context:** The vulnerability disclosure issue is genuinely problematic and represents a failure to follow established cybersecurity best practices.
ServicesServices Services AustraliaAustralia Australia 表现biǎo xiàn biǎo xiàn 出对chū duì chū duì 安全ān quán ān quán 问题wèn tí wèn tí 的de de 意识yì shí yì shí 并bìng bìng 进行jìn xíng jìn xíng 评估píng gū píng gū [[ [ 44 4 ]] ] 。。 。
However, it's not clear this was unique to the Coalition's COVID response or that Labor governments would necessarily have handled it differently—the My Health Record case shows digital health system governance has been challenging across parties.
失败shī bài shī bài 在于zài yú zài yú 没有méi yǒu méi yǒu 建立jiàn lì jiàn lì 公开gōng kāi gōng kāi 、、 、 响应xiǎng yìng xiǎng yìng 迅速xùn sù xùn sù 的de de 渠道qú dào qú dào 供gōng gōng 研究员yán jiū yuán yán jiū yuán 报告bào gào bào gào 漏洞lòu dòng lòu dòng —— — —— — 这是zhè shì zhè shì 一个yí gè yí gè 流程liú chéng liú chéng 问题wèn tí wèn tí 而ér ér 非技术fēi jì shù fēi jì shù 问题wèn tí wèn tí 。。 。
** * ** * 行业háng yè háng yè 实践shí jiàn shí jiàn 背景bèi jǐng bèi jǐng :: : ** * ** *
漏洞lòu dòng lòu dòng 披露pī lù pī lù 计划jì huà jì huà (( ( VDPVDP VDP )) ) 和hé hé 漏洞lòu dòng lòu dòng 赏金shǎng jīn shǎng jīn 已yǐ yǐ 成为chéng wéi chéng wéi 主要zhǔ yào zhǔ yào 科技kē jì kē jì 公司gōng sī gōng sī 和hé hé 越来越yuè lái yuè yuè lái yuè 多duō duō 政府zhèng fǔ zhèng fǔ 机构jī gòu jī gòu 的de de 标准biāo zhǔn biāo zhǔn 行业háng yè háng yè 实践shí jiàn shí jiàn 。。 。
ASDASD ASD 和hé hé CyberCyber Cyber .. . govgov gov .. . auau au 已yǐ yǐ 发布fā bù fā bù 实施shí shī shí shī VDPVDP VDP 的de de 指南zhǐ nán zhǐ nán [[ [ 1212 12 ]] ] 。。 。
到dào dào 20212021 2021 年nián nián ,, , 面向miàn xiàng miàn xiàng 公众gōng zhòng gōng zhòng 的de de COVIDCOVID COVID 安全ān quán ān quán 系统xì tǒng xì tǒng 缺乏quē fá quē fá 正式zhèng shì zhèng shì VDPVDP VDP 明显míng xiǎn míng xiǎn 落后luò hòu luò hòu 于yú yú 当前dāng qián dāng qián 最佳zuì jiā zuì jiā 实践shí jiàn shí jiàn ,, , 尽管jǐn guǎn jǐn guǎn 这zhè zhè 并非bìng fēi bìng fēi 澳大利亚ào dà lì yà ào dà lì yà 或huò huò 当时dāng shí dāng shí 联盟党lián méng dǎng lián méng dǎng 政府zhèng fǔ zhèng fǔ 独有dú yǒu dú yǒu 。。 。
** * ** * 关键guān jiàn guān jiàn 背景bèi jǐng bèi jǐng :: : ** * ** * 漏洞lòu dòng lòu dòng 披露pī lù pī lù 问题wèn tí wèn tí 确实què shí què shí 存在cún zài cún zài 问题wèn tí wèn tí ,, , 代表dài biǎo dài biǎo 未能wèi néng wèi néng 遵循zūn xún zūn xún 已yǐ yǐ 建立jiàn lì jiàn lì 的de de 网络安全wǎng luò ān quán wǎng luò ān quán 最佳zuì jiā zuì jiā 实践shí jiàn shí jiàn 。。 。
然而rán ér rán ér ,, , 尚shàng shàng 不bù bù 清楚qīng chǔ qīng chǔ 这zhè zhè 是否是shì fǒu shì shì fǒu shì 联盟党lián méng dǎng lián méng dǎng COVIDCOVID COVID 应对yìng duì yìng duì 独有dú yǒu dú yǒu 的de de ,, , 或者huò zhě huò zhě LaborLabor Labor 政府zhèng fǔ zhèng fǔ 是否shì fǒu shì fǒu 会以huì yǐ huì yǐ 不同bù tóng bù tóng 方式fāng shì fāng shì 处理chǔ lǐ chǔ lǐ —— — —— — MyMy My HealthHealth Health RecordRecord Record 案例àn lì àn lì 显示xiǎn shì xiǎn shì 数字shù zì shù zì 健康jiàn kāng jiàn kāng 系统xì tǒng xì tǒng 治理zhì lǐ zhì lǐ 对duì duì 两党liǎng dǎng liǎng dǎng 都dōu dōu 一直yì zhí yì zhí 具有jù yǒu jù yǒu 挑战性tiǎo zhàn xìng tiǎo zhàn xìng 。。 。

部分属实

6.0

/ 10

关于guān yú guān yú ServicesServices Services AustraliaAustralia Australia 缺乏quē fá quē fá 漏洞lòu dòng lòu dòng 披露pī lù pī lù 计划jì huà jì huà 以及yǐ jí yǐ jí 报告bào gào bào gào 漏洞lòu dòng lòu dòng 困难kùn nán kùn nán 的de de 具体jù tǐ jù tǐ 事实性shì shí xìng shì shí xìng 主张zhǔ zhāng zhǔ zhāng 是shì shì ** * ** * 准确zhǔn què zhǔn què 且qiě qiě 经验jīng yàn jīng yàn 证zhèng zhèng 的de de ** * ** * 。。 。
The specific factual claims about Services Australia's lack of a vulnerability disclosure program and the difficulty in reporting vulnerabilities are **accurate and verified**.
然而rán ér rán ér ,, , 更gèng gèng 广泛guǎng fàn guǎng fàn 的de de 主张zhǔ zhāng zhǔ zhāng 需要xū yào xū yào 限定xiàn dìng xiàn dìng :: :
However, the broader claim requires qualification: 1. ✅ **TRUE:** Services Australia had no vulnerability disclosure program and explicitly stated no plans to implement one [4] 2. ✅ **TRUE:** Reporting vulnerabilities was unnecessarily difficult and no effective process existed [1] 3. ✅ **TRUE:** Response was slow and only accelerated after public disclosure [1] 4. ⚠️ **PARTIALLY TRUE:** Claims about "not following cybersecurity best practice" are valid, but government was conducting cyber assessments and working with ASD; the failure was specifically in public vulnerability disclosure processes, not all cybersecurity practices [4] 5. ⚠️ **MISLEADING FRAMING:** The claim's implication that this was uniquely egregious Coalition-era mismanagement is not well-supported.
11 1 .. . ✅✅ ✅ ** * ** * 正确zhèng què zhèng què :: : ** * ** * ServicesServices Services AustraliaAustralia Australia 没有méi yǒu méi yǒu 漏洞lòu dòng lòu dòng 披露pī lù pī lù 计划jì huà jì huà ,, , 并bìng bìng 明确míng què míng què 表示biǎo shì biǎo shì 没有méi yǒu méi yǒu 实施shí shī shí shī 计划jì huà jì huà [[ [ 44 4 ]] ]
Labor government digital health projects (My Health Record) faced similar governance and security trust issues [10, 11] 6. ⚠️ **CONTEXT MISSING:** During pandemic conditions in 2021, rapid deployment of public health infrastructure sometimes competed with security maturity; this doesn't excuse the failure but provides context The verdict is that the core facts are sound, the criticism is legitimate, but the framing overstates uniqueness or severity without acknowledging comparable issues in Labor's digital health governance.
22 2 .. . ✅✅ ✅ ** * ** * 正确zhèng què zhèng què :: : ** * ** * 报告bào gào bào gào 漏洞lòu dòng lòu dòng 不必要bù bì yào bù bì yào 地dì dì 困难kùn nán kùn nán ,, , 没有méi yǒu méi yǒu 有效yǒu xiào yǒu xiào 流程liú chéng liú chéng [[ [ 11 1 ]] ]
33 3 .. . ✅✅ ✅ ** * ** * 正确zhèng què zhèng què :: : ** * ** * 响应xiǎng yìng xiǎng yìng 缓慢huǎn màn huǎn màn ,, , 仅jǐn jǐn 在zài zài 公开gōng kāi gōng kāi 披露pī lù pī lù 后hòu hòu 才cái cái 加速jiā sù jiā sù [[ [ 11 1 ]] ]
44 4 .. . ⚠⚠ ⚠ ️️ ️ ** * ** * 部分bù fèn bù fèn 正确zhèng què zhèng què :: : ** * ** * 关于guān yú guān yú "" " 未wèi wèi 遵循zūn xún zūn xún 网络安全wǎng luò ān quán wǎng luò ān quán 最佳zuì jiā zuì jiā 实践shí jiàn shí jiàn "" " 的de de 主张zhǔ zhāng zhǔ zhāng 是shì shì 有效yǒu xiào yǒu xiào 的de de ,, , 但dàn dàn 政府zhèng fǔ zhèng fǔ 确实què shí què shí 在zài zài 进行jìn xíng jìn xíng 网络wǎng luò wǎng luò 评估píng gū píng gū 并bìng bìng 与yǔ yǔ ASDASD ASD 合作hé zuò hé zuò ;; ; 失败shī bài shī bài specificallyspecifically specifically 在于zài yú zài yú 公开gōng kāi gōng kāi 漏洞lòu dòng lòu dòng 披露pī lù pī lù 流程liú chéng liú chéng ,, , 而ér ér 非fēi fēi 所有suǒ yǒu suǒ yǒu 网络安全wǎng luò ān quán wǎng luò ān quán 实践shí jiàn shí jiàn [[ [ 44 4 ]] ]
55 5 .. . ⚠⚠ ⚠ ️️ ️ ** * ** * 误导性wù dǎo xìng wù dǎo xìng 框架kuāng jià kuāng jià :: : ** * ** * 该gāi gāi 主张zhǔ zhāng zhǔ zhāng 暗示àn shì àn shì 这是zhè shì zhè shì 联盟党lián méng dǎng lián méng dǎng 时代shí dài shí dài uniquelyuniquely uniquely 恶劣è liè è liè 的de de 管理guǎn lǐ guǎn lǐ 不善bù shàn bù shàn ,, , 这一zhè yī zhè yī 说法shuō fǎ shuō fǎ 没有méi yǒu méi yǒu 得到dé dào dé dào 充分chōng fèn chōng fèn 支持zhī chí zhī chí 。。 。
LaborLabor Labor 政府zhèng fǔ zhèng fǔ 数字shù zì shù zì 健康jiàn kāng jiàn kāng 项目xiàng mù xiàng mù (( ( MyMy My HealthHealth Health RecordRecord Record )) ) 面临miàn lín miàn lín 类似lèi sì lèi sì 的de de 治理zhì lǐ zhì lǐ 和hé hé 安全ān quán ān quán 信任xìn rèn xìn rèn 问题wèn tí wèn tí [[ [ 1010 10 ,, , 1111 11 ]] ]
66 6 .. . ⚠⚠ ⚠ ️️ ️ ** * ** * 背景bèi jǐng bèi jǐng 缺失quē shī quē shī :: : ** * ** * 20212021 2021 年nián nián 疫情yì qíng yì qíng 期间qī jiān qī jiān ,, , 公共卫生gōng gòng wèi shēng gōng gòng wèi shēng 基础设施jī chǔ shè shī jī chǔ shè shī 的de de 快速kuài sù kuài sù 部署bù shǔ bù shǔ 有时yǒu shí yǒu shí 与yǔ yǔ 安全ān quán ān quán 成熟度chéng shú dù chéng shú dù 竞争jìng zhēng jìng zhēng ;; ; 这zhè zhè 不能bù néng bù néng 为wèi wèi 失败shī bài shī bài 开脱kāi tuō kāi tuō ,, , 但dàn dàn 提供tí gōng tí gōng 了le le 背景bèi jǐng bèi jǐng
裁决cái jué cái jué 是shì shì 核心hé xīn hé xīn 事实shì shí shì shí 可靠kě kào kě kào ,, , 批评pī píng pī píng 合理hé lǐ hé lǐ ,, , 但dàn dàn 框架kuāng jià kuāng jià 在zài zài 没有méi yǒu méi yǒu 承认chéng rèn chéng rèn LaborLabor Labor 数字shù zì shù zì 健康jiàn kāng jiàn kāng 治理zhì lǐ zhì lǐ 中zhōng zhōng 类似lèi sì lèi sì 问题wèn tí wèn tí 的de de 情况qíng kuàng qíng kuàng 下xià xià 夸大kuā dà kuā dà 了le le 独特性dú tè xìng dú tè xìng 或huò huò 严重性yán zhòng xìng yán zhòng xìng 。。 。

📚 来源与引用 (11)

  1. 1
    The need for an Australian Government Vulnerability Disclosure Policy - Richard Nelson, Medium

    The need for an Australian Government Vulnerability Disclosure Policy - Richard Nelson, Medium

    Recently, I found a weakness in the Express Plus Medicare application’s COVID-19 digital certificate:

    Medium
  2. 2
    COVID-19 vaccination certificates at risk of forgery after discovery of - ABC News

    COVID-19 vaccination certificates at risk of forgery after discovery of - ABC News

    The federal government's COVID-19 vaccine certificate can be forged using a widely known technique to bypass the protections, a member of the public has found.

    Abc Net
  3. 3
    Services Australia brushes off vulnerability concerns in COVID-19 digital certificates - ZDNet, Campbell Kwan

    Services Australia brushes off vulnerability concerns in COVID-19 digital certificates - ZDNet, Campbell Kwan

    There are no vulnerability disclosure programs in place nor any future plans to implement such a thing for Australia's COVID-19 digital certificate.

    ZDNET
  4. 4
    Vulnerability Disclosure Program - Department of Home Affairs

    Vulnerability Disclosure Program - Department of Home Affairs

    Home Affairs brings together Australia's federal law enforcement, national and transport security, criminal justice, emergency management, multicultural affairs, settlement services and immigration and border-related functions, working together to keep Australia safe.

    Department of Home Affairs Website
  5. 5
    Service NSW Vulnerability Disclosure Program via Bugcrowd

    Service NSW Vulnerability Disclosure Program via Bugcrowd

    Learn more about Service NSW’s Vulnerability Disclosure engagement powered by Bugcrowd, the leader in crowdsourced security solutions.

    Bugcrowd
  6. 6
    Service NSW official page

    Service NSW official page

    Service NSW welcomes vulnerability reports that help us to provide safe and secure services to our customers.

    Service NSW
  7. 7
    ZDNet Editorial Standards and contributor information

    ZDNet Editorial Standards and contributor information

    Discover ZDNET's editorial mission, how we evaluate products and our commitment to transparency about our business practices.

    ZDNET
  8. 8
    sciencedirect.com

    Privacy concerns of the Australian My Health Record: Implications for patient autonomy and consent - Science Direct

    Sciencedirect

  9. 9
    dailytelegraph.com.au

    My Health Record: privacy concern sparks calls from Labor to suspend rollout - Daily Telegraph

    Dailytelegraph Com

  10. 10
    cyber.gov.au

    Vulnerability Disclosure Programs explained - Cyber.gov.au

    Cyber Gov

  11. 11
    asd.gov.au

    ASD Responsible Release Principles

    Asd Gov

评分方法

1-3: 不实

事实错误或恶意捏造。

4-6: 部分属实

有一定真实性,但缺乏背景或有所偏颇。

7-9: 基本属实

仅有微小的技术性或措辞问题。

10: 准确

完全经过验证且客观公正。

方法论: 评分通过交叉参照政府官方记录、独立事实核查机构和原始文件确定。