属实

评分: 7.0/10

Coalition
C0161

声明内容

“选择忽视且不修复myGovID的安全漏洞,该漏洞之所以产生是因为所选的认证协议是定制的,不符合标准规范。”
原始来源: Matthew Davis
分析时间: 29 Jan 2026

原始来源

事实核查

###### ### myGovIDmyGovID myGovID 安全漏洞ān quán lòu dòng ān quán lòu dòng -- - 代码dài mǎ dài mǎ zhòng zhòng fàng fàng 攻击gōng jī gōng jī
### myGovID Security Vulnerability - Code Replay Attack
gāi gāi 陈述chén shù chén shù 引用yǐn yòng yǐn yòng le le myGovIDmyGovID myGovID zhōng zhōng 发现fā xiàn fā xiàn de de 真实zhēn shí zhēn shí 安全漏洞ān quán lòu dòng ān quán lòu dòng
The claim references a real security vulnerability identified in myGovID.
20242024 2024 nián nián 88 8 yuè yuè 安全ān quán ān quán 研究yán jiū yán jiū 人员rén yuán rén yuán BenBen Ben FrengleyFrengley Frengley 墨尔本大学mò ěr běn dà xué mò ěr běn dà xué VanessaVanessa Vanessa TeagueTeague Teague ThinkingThinking Thinking CybersecurityCybersecurity Cybersecurity 首席shǒu xí shǒu xí 执行官zhí xíng guān zhí xíng guān 澳大利亚ào dà lì yà ào dà lì yà 国立大学guó lì dà xué guó lì dà xué 兼职jiān zhí jiān zhí 教授jiào shòu jiào shòu 发现fā xiàn fā xiàn le le myGovIDmyGovID myGovID 认证rèn zhèng rèn zhèng 系统xì tǒng xì tǒng zhōng zhōng de de 关键guān jiàn guān jiàn 漏洞lòu dòng lòu dòng [[ [ 11 1 ]] ]
In August 2024, security researchers Ben Frengley (University of Melbourne) and Vanessa Teague (CEO of Thinking Cybersecurity, ANU adjunct professor) discovered a critical vulnerability in myGovID's authentication system [1].
gāi gāi 漏洞lòu dòng lòu dòng shì shì 一种yī zhǒng yī zhǒng ** * ** * 代码dài mǎ dài mǎ zhòng zhòng fàng fàng 攻击gōng jī gōng jī ** * ** * 利用lì yòng lì yòng le le 一个yí gè yí gè 根本性gēn běn xìng gēn běn xìng de de 设计shè jì shè jì 缺陷quē xiàn quē xiàn
The vulnerability is a **code replay attack** that exploits a fundamental design flaw.
攻击者gōng jī zhě gōng jī zhě 可以kě yǐ kě yǐ 建立jiàn lì jiàn lì 一个yí gè yí gè 虚假xū jiǎ xū jiǎ 网站wǎng zhàn wǎng zhàn bìng bìng 捕获bǔ huò bǔ huò 用户yòng hù yòng hù de de 电子邮件diàn zi yóu jiàn diàn zi yóu jiàn 地址dì zhǐ dì zhǐ
An attacker can set up a fake website and capture a user's email address.
dāng dāng 攻击者gōng jī zhě gōng jī zhě 使用shǐ yòng shǐ yòng 受害者shòu hài zhě shòu hài zhě de de 电子邮件diàn zi yóu jiàn diàn zi yóu jiàn 地址dì zhǐ dì zhǐ zài zài 合法hé fǎ hé fǎ de de 政府zhèng fǔ zhèng fǔ 门户网站mén hù wǎng zhàn mén hù wǎng zhàn 发起fā qǐ fā qǐ 认证rèn zhèng rèn zhèng shí shí 门户网站mén hù wǎng zhàn mén hù wǎng zhàn huì huì 显示xiǎn shì xiǎn shì 一个yí gè yí gè 44 4 位数wèi shù wèi shù de de PINPIN PIN
When the attacker initiates authentication at a legitimate government portal using the victim's email, the portal displays a 4-digit PIN.
攻击者gōng jī zhě gōng jī zhě 通过tōng guò tōng guò 虚假xū jiǎ xū jiǎ 网站wǎng zhàn wǎng zhàn jiāng jiāng PINPIN PIN 传递chuán dì chuán dì gěi gěi 受害者shòu hài zhě shòu hài zhě dāng dāng 受害者shòu hài zhě shòu hài zhě zài zài myGovIDmyGovID myGovID 应用程序yìng yòng chéng xù yìng yòng chéng xù zhōng zhōng 输入shū rù shū rù shí shí 他们tā men tā men zài zài 不知情bù zhī qíng bù zhī qíng de de 情况qíng kuàng qíng kuàng xià xià 授予shòu yǔ shòu yǔ le le 攻击者gōng jī zhě gōng jī zhě duì duì 合法政府hé fǎ zhèng fǔ hé fǎ zhèng fǔ 账户zhàng hù zhàng hù de de 完全wán quán wán quán 访问fǎng wèn fǎng wèn 权限quán xiàn quán xiàn
The attacker relays this PIN to the victim through the fake site, and when the victim enters it into their myGovID app, they unknowingly grant the attacker full access to legitimate government accounts.
一个yí gè yí gè 关键guān jiàn guān jiàn de de 设计shè jì shè jì 弱点ruò diǎn ruò diǎn shì shì myGovIDmyGovID myGovID 应用程序yìng yòng chéng xù yìng yòng chéng xù ** * ** * wèi wèi 显示xiǎn shì xiǎn shì 请求qǐng qiú qǐng qiú 认证rèn zhèng rèn zhèng de de shì shì 哪个nǎ ge nǎ ge 组织zǔ zhī zǔ zhī ** * ** * [[ [ 22 2 ]] ]
A critical design weakness is that the myGovID app provides **no indication of which organization is requesting authentication** [2].
研究yán jiū yán jiū 人员rén yuán rén yuán 20242024 2024 nián nián 88 8 yuè yuè 1919 19 日向rì xiàng rì xiàng 澳大利亚ào dà lì yà ào dà lì yà 信号xìn hào xìn hào ASDASD ASD 报告bào gào bào gào le le 漏洞lòu dòng lòu dòng [[ [ 33 3 ]] ]
The researchers reported this vulnerability to the Australian Signals Directorate (ASD) on August 19, 2024 [3].
根据gēn jù gēn jù 行业háng yè háng yè 最佳zuì jiā zuì jiā 实践shí jiàn shí jiàn 他们tā men tā men 提出tí chū tí chū le le 9090 90 tiān tiān de de 负责fù zé fù zé rèn rèn 披露pī lù pī lù 以便yǐ biàn yǐ biàn 政府zhèng fǔ zhèng fǔ yǒu yǒu 时间shí jiān shí jiān zài zài 公开gōng kāi gōng kāi 披露pī lù pī lù qián qián 开发kāi fā kāi fā 实施shí shī shí shī 修复xiū fù xiū fù 方案fāng àn fāng àn [[ [ 11 1 ]] ]
According to industry best practice, they proposed a 90-day responsible disclosure period to allow the government time to develop and implement a fix before public disclosure [1].
###### ### 政府zhèng fǔ zhèng fǔ 回应huí yìng huí yìng 拒绝jù jué jù jué 修复xiū fù xiū fù
### Government's Response: Refusal to Fix
20242024 2024 nián nián 99 9 yuè yuè 1818 18 澳大利亚ào dà lì yà ào dà lì yà 税务局shuì wù jú shuì wù jú ATOATO ATO 研究yán jiū yán jiū 人员rén yuán rén yuán 会面huì miàn huì miàn bìng bìng 明确míng què míng què 表示biǎo shì biǎo shì ** * ** * "" " 打算dǎ suàn dǎ suàn 更改gēng gǎi gēng gǎi 协议xié yì xié yì "" " ** * ** * [[ [ 33 3 ]] ]
On September 18, 2024, the Australian Taxation Office (ATO) met with the researchers and explicitly stated it **"did not intend to change the protocol"** [3].
zhè zhè 意味着yì wèi zhe yì wèi zhe 政府zhèng fǔ zhèng fǔ 拒绝jù jué jù jué 修复xiū fù xiū fù gāi gāi 漏洞lòu dòng lòu dòng
This means the government declined to remediate the vulnerability.
此外cǐ wài cǐ wài ATOATO ATO jiāng jiāng gāi gāi 漏洞lòu dòng lòu dòng 定性dìng xìng dìng xìng wèi wèi "" " gèng gèng 像是xiàng shì xiàng shì 公众gōng zhòng gōng zhòng 意识yì shí yì shí 问题wèn tí wèn tí "" " ér ér fēi fēi 需要xū yào xū yào 更改gēng gǎi gēng gǎi 协议xié yì xié yì de de 技术jì shù jì shù 缺陷quē xiàn quē xiàn [[ [ 33 3 ]] ]
Additionally, the ATO characterized the vulnerability as "more of a public awareness issue" rather than a technical flaw requiring protocol changes [3].
ATOATO ATO hái hái 发表声明fā biǎo shēng míng fā biǎo shēng míng chēng chēng myGovIDmyGovID myGovID "" " 任何rèn hé rèn hé 凭证píng zhèng píng zhèng dōu dōu gèng gèng 安全ān quán ān quán "" " duì duì 研究yán jiū yán jiū 人员rén yuán rén yuán de de 担忧dān yōu dān yōu 不予bù yǔ bù yǔ 理会lǐ huì lǐ huì [[ [ 44 4 ]] ]
The ATO also issued statements claiming myGovID was "more secure than any credential," dismissing researcher concerns [4].
zài zài 政府zhèng fǔ zhèng fǔ 拒绝jù jué jù jué 修复xiū fù xiū fù 漏洞lòu dòng lòu dòng hòu hòu 研究yán jiū yán jiū 人员rén yuán rén yuán 20242024 2024 nián nián 99 9 yuè yuè 2121 21 公开gōng kāi gōng kāi 披露pī lù pī lù 尽管jǐn guǎn jǐn guǎn céng céng 提议tí yì tí yì 负责fù zé fù zé rèn rèn 披露pī lù pī lù dàn dàn réng réng 公布gōng bù gōng bù le le 他们tā men tā men de de 发现fā xiàn fā xiàn [[ [ 22 2 ]] ]
After the government refused to fix the vulnerability, the researchers went public on September 21, 2024 - publishing their findings despite having proposed a responsible disclosure period [2].
安全ān quán ān quán 研究yán jiū yán jiū 人员rén yuán rén yuán 明确míng què míng què 警告jǐng gào jǐng gào 公众gōng zhòng gōng zhòng zài zài 登录dēng lù dēng lù 漏洞lòu dòng lòu dòng 修复xiū fù xiū fù 之前zhī qián zhī qián 不要bú yào bú yào 使用shǐ yòng shǐ yòng myGovIDmyGovID myGovID [[ [ 11 1 ]] ]
The security researchers explicitly warned the public not to use myGovID until the login flaw was fixed [1].
###### ### 监察jiān chá jiān chá 专员zhuān yuán zhuān yuán de de 支持zhī chí zhī chí 证据zhèng jù zhèng jù
### Supporting Evidence from Ombudsman
20242024 2024 nián nián 88 8 yuè yuè 澳大利亚ào dà lì yà ào dà lì yà 监察jiān chá jiān chá 专员zhuān yuán zhuān yuán 发布fā bù fā bù le le 保障bǎo zhàng bǎo zhàng myGovmyGov myGov 安全ān quán ān quán 报告bào gào bào gào 其中qí zhōng qí zhōng 指出zhǐ chū zhǐ chū le le myGovmyGov myGov // / myGovIDmyGovID myGovID 系统xì tǒng xì tǒng zhōng zhōng de de 多项duō xiàng duō xiàng 安全ān quán ān quán 缺陷quē xiàn quē xiàn 包括bāo kuò bāo kuò 身份验证shēn fèn yàn zhèng shēn fèn yàn zhèng 标准biāo zhǔn biāo zhǔn 一致yí zhì yí zhì duì duì wèi wèi 授权shòu quán shòu quán 账户zhàng hù zhàng hù 关联guān lián guān lián de de 安全控制ān quán kòng zhì ān quán kòng zhì 有限yǒu xiàn yǒu xiàn 以及yǐ jí yǐ jí 诈骗者zhà piàn zhě zhà piàn zhě 重定向zhòng dìng xiàng zhòng dìng xiàng 养老金yǎng lǎo jīn yǎng lǎo jīn 支付zhī fù zhī fù 提交tí jiāo tí jiāo 虚假xū jiǎ xū jiǎ 福利fú lì fú lì 申请shēn qǐng shēn qǐng de de 实例shí lì shí lì [[ [ 55 5 ]] ]
In August 2024, the Australian Ombudsman published the "Keeping myGov Secure" report, which identified multiple security deficiencies in myGov/myGovID systems, including inconsistent proof-of-identity standards, limited security controls for unauthorized account linking, and instances of fraudsters redirecting pension payments and submitting false benefit claims [5].
澳大利亚ào dà lì yà ào dà lì yà 服务部fú wù bù fú wù bù 20242024 2024 nián nián 77 7 yuè yuè 下旬xià xún xià xún 同意tóng yì tóng yì le le 这些zhè xiē zhè xiē 建议jiàn yì jiàn yì dàn dàn jiāng jiāng 实施shí shī shí shī 推迟tuī chí tuī chí dào dào 20252025 2025 年初nián chū nián chū 表明biǎo míng biǎo míng duì duì 紧急jǐn jí jǐn jí 安全ān quán ān quán 问题wèn tí wèn tí wèi wèi 立即lì jí lì jí 采取行动cǎi qǔ xíng dòng cǎi qǔ xíng dòng [[ [ 55 5 ]] ]
Services Australia agreed to these recommendations in late July 2024 but deferred implementation to early 2025, indicating no immediate action was taken on urgent security matters [5].

缺失背景

###### ### 11 1 .. . "" " 定制dìng zhì dìng zhì "" " 认证rèn zhèng rèn zhèng 协议xié yì xié yì 属实shǔ shí shǔ shí
### 1. The "Bespoke" Authentication Protocol is Accurate
gāi gāi 陈述chén shù chén shù 准确zhǔn què zhǔn què jiāng jiāng myGovIDmyGovID myGovID de de 认证rèn zhèng rèn zhèng 协议xié yì xié yì 描述miáo shù miáo shù wèi wèi fēi fēi 标准协议biāo zhǔn xié yì biāo zhǔn xié yì
The claim accurately characterizes myGovID's authentication protocol as non-standard. myGovID uses the **Trusted Digital Identity Framework (TDIF)**, which is a proprietary, bespoke system specific to Australia - not OpenID Connect, OAuth 2.0, or other internationally recognized standards [6].
myGovIDmyGovID myGovID 使用shǐ yòng shǐ yòng ** * ** * 可信kě xìn kě xìn 数字shù zì shù zì 身份shēn fèn shēn fèn 框架kuāng jià kuāng jià TDIFTDIF TDIF ** * ** * 这是zhè shì zhè shì 一个yí gè yí gè 专有zhuān yǒu zhuān yǒu de de 定制dìng zhì dìng zhì de de 系统xì tǒng xì tǒng jǐn jǐn zài zài 澳大利亚ào dà lì yà ào dà lì yà 使用shǐ yòng shǐ yòng ér ér fēi fēi OpenIDOpenID OpenID ConnectConnect Connect OAuthOAuth OAuth 2.02.0 2.0 huò huò 其他qí tā qí tā 国际guó jì guó jì 认可rèn kě rèn kě de de 标准biāo zhǔn biāo zhǔn [[ [ 66 6 ]] ]
Security researchers have recommended that the TDIF framework be deprecated and replaced with standard protocols like OpenID Connect [2].
安全ān quán ān quán 研究yán jiū yán jiū 人员rén yuán rén yuán 建议jiàn yì jiàn yì 应弃yīng qì yīng qì yòng yòng TDIFTDIF TDIF 框架kuāng jià kuāng jià 改用gǎi yòng gǎi yòng OpenIDOpenID OpenID ConnectConnect Connect děng děng 标准协议biāo zhǔn xié yì biāo zhǔn xié yì [[ [ 22 2 ]] ]
### 2. Protocol Design vs. Implementation Issues
###### ### 22 2 .. . 协议xié yì xié yì 设计shè jì shè jì 问题wèn tí wèn tí vsvs vs 实施shí shī shí shī 问题wèn tí wèn tí
While the vulnerability exists, there is a technical distinction worth noting: the fundamental flaw appears to stem from the protocol's design (the lack of context about who is requesting authentication in the myGovID app), not necessarily implementation errors.
虽然suī rán suī rán 漏洞lòu dòng lòu dòng 确实què shí què shí 存在cún zài cún zài dàn dàn yǒu yǒu 一个yí gè yí gè 技术jì shù jì shù 区别qū bié qū bié 值得注意zhí de zhù yì zhí de zhù yì 根本性gēn běn xìng gēn běn xìng 缺陷quē xiàn quē xiàn 似乎sì hū sì hū 源于yuán yú yuán yú 协议xié yì xié yì 设计shè jì shè jì myGovIDmyGovID myGovID 应用程序yìng yòng chéng xù yìng yòng chéng xù 缺乏quē fá quē fá 关于guān yú guān yú shuí shuí zài zài 请求qǐng qiú qǐng qiú 认证rèn zhèng rèn zhèng de de 上下文shàng xià wén shàng xià wén 信息xìn xī xìn xī ér ér fēi fēi 必然bì rán bì rán de de 实施shí shī shí shī 错误cuò wù cuò wù
However, this distinction does not diminish the validity of the claim - a flawed protocol design is still a flaw that requires fixing.
然而rán ér rán ér 这一zhè yī zhè yī 区别qū bié qū bié bìng bìng 削弱xuē ruò xuē ruò gāi gāi 陈述chén shù chén shù de de 有效性yǒu xiào xìng yǒu xiào xìng 存在cún zài cún zài 缺陷quē xiàn quē xiàn de de 协议xié yì xié yì 设计shè jì shè jì 仍然réng rán réng rán shì shì 缺陷quē xiàn quē xiàn 需要xū yào xū yào 修复xiū fù xiū fù
### 3. Timeline and Context
###### ### 33 3 .. . 时间shí jiān shí jiān 线xiàn xiàn 背景bèi jǐng bèi jǐng
The vulnerability discovery occurred late in the Coalition government's tenure.
漏洞lòu dòng lòu dòng 发现fā xiàn fā xiàn CoalitionCoalition Coalition 政府zhèng fǔ zhèng fǔ 任期rèn qī rèn qī 即将jí jiāng jí jiāng 结束jié shù jié shù shí shí
The Coalition was voted out of office in May 2022.
CoalitionCoalition Coalition 20222022 2022 nián nián 55 5 yuè yuè 落选luò xuǎn luò xuǎn
The vulnerability was discovered in August 2024 by the Albanese Labor government.
gāi gāi 漏洞lòu dòng lòu dòng 20242024 2024 nián nián 88 8 yuè yuè yóu yóu AlbaneseAlbanese Albanese LaborLabor Labor 政府zhèng fǔ zhèng fǔ 执政zhí zhèng zhí zhèng 期间qī jiān qī jiān bèi bèi 发现fā xiàn fā xiàn
This means: - The Coalition government (2013-2022) would not have made the September 2024 decision to refuse remediation - The current (Labor) government inherited myGovID and made the decision not to change the protocol [3] However, the claim may be referring to the Coalition government's original decision to develop and deploy myGovID using a bespoke, non-standard protocol rather than established industry standards - which would have been a decision made during the Coalition's time in office (2013-2022).
zhè zhè 意味着yì wèi zhe yì wèi zhe
-- - CoalitionCoalition Coalition 政府zhèng fǔ zhèng fǔ 20132013 2013 -- - 20222022 2022 不会bú huì bú huì zài zài 20242024 2024 nián nián 99 9 yuè yuè 做出zuò chū zuò chū 拒绝jù jué jù jué 修复xiū fù xiū fù de de 决定jué dìng jué dìng
-- - 现任xiàn rèn xiàn rèn LaborLabor Labor 政府zhèng fǔ zhèng fǔ 继承jì chéng jì chéng le le myGovIDmyGovID myGovID bìng bìng 决定jué dìng jué dìng 更改gēng gǎi gēng gǎi 协议xié yì xié yì [[ [ 33 3 ]] ]
然而rán ér rán ér gāi gāi 陈述chén shù chén shù 可能kě néng kě néng zhǐ zhǐ de de shì shì CoalitionCoalition Coalition 政府zhèng fǔ zhèng fǔ 最初zuì chū zuì chū 决定jué dìng jué dìng 使用shǐ yòng shǐ yòng 定制dìng zhì dìng zhì de de fēi fēi 标准协议biāo zhǔn xié yì biāo zhǔn xié yì ér ér fēi fēi 既定jì dìng jì dìng 行业标准háng yè biāo zhǔn háng yè biāo zhǔn 开发kāi fā kāi fā 部署bù shǔ bù shǔ myGovIDmyGovID myGovID 这是zhè shì zhè shì CoalitionCoalition Coalition 执政zhí zhèng zhí zhèng 期间qī jiān qī jiān 20132013 2013 -- - 20222022 2022 做出zuò chū zuò chū de de 决定jué dìng jué dìng

来源可信度评估

###### ### 原始yuán shǐ yuán shǐ 来源lái yuán lái yuán ThinkingThinking Thinking CybersecurityCybersecurity Cybersecurity
### Original Source: Thinking Cybersecurity
提供tí gōng tí gōng de de 原始yuán shǐ yuán shǐ 来源lái yuán lái yuán ThinkingThinking Thinking CybersecurityCybersecurity Cybersecurity shì shì yóu yóu VanessaVanessa Vanessa TeagueTeague Teague 领导lǐng dǎo lǐng dǎo de de 组织zǔ zhī zǔ zhī shì shì 发现fā xiàn fā xiàn gāi gāi 漏洞lòu dòng lòu dòng de de 研究yán jiū yán jiū 人员rén yuán rén yuán 之一zhī yī zhī yī
The original source provided (Thinking Cybersecurity) is an organization led by Vanessa Teague, one of the researchers who discovered the vulnerability.
zhè zhè 形成xíng chéng xíng chéng le le 关于guān yú guān yú 漏洞lòu dòng lòu dòng 本身běn shēn běn shēn de de 直接zhí jiē zhí jiē 来源lái yuán lái yuán
This creates a direct source on the vulnerability itself.
VanessaVanessa Vanessa TeagueTeague Teague shì shì
Vanessa Teague is: - An ANU adjunct professor and security researcher - A credible academic voice in cybersecurity - Has published peer-reviewed work on electoral security and digital systems [7] However, as one of the researchers reporting on their own finding, there is inherent bias in favor of emphasizing the vulnerability's severity.
-- - 澳大利亚ào dà lì yà ào dà lì yà 国立大学guó lì dà xué guó lì dà xué 兼职jiān zhí jiān zhí 教授jiào shòu jiào shòu 安全ān quán ān quán 研究yán jiū yán jiū 人员rén yuán rén yuán
### Primary Sources on This Issue
-- - 网络安全wǎng luò ān quán wǎng luò ān quán 领域lǐng yù lǐng yù 可信kě xìn kě xìn de de 学术xué shù xué shù 声音shēng yīn shēng yīn
The most reliable sources are: - **Technology news outlets** (iTnews, InnovationAus): Mainstream Australian tech journalism covering the vulnerability discovery and government response [1][3] - **Government sources** (Ombudsman report, ATO statements): Official documentation of security concerns and government positions [4][5] - **Security research** (Thinking Cybersecurity, researchers' technical documentation): Academic and professional security analysis [2] The claim is well-supported by mainstream technology journalism and government reports, not primarily dependent on a single partisan source.
-- - 发表fā biǎo fā biǎo guò guò 关于guān yú guān yú 选举xuǎn jǔ xuǎn jǔ 安全ān quán ān quán 数字shù zì shù zì 系统xì tǒng xì tǒng de de 同行tóng háng tóng háng 评审píng shěn píng shěn 研究yán jiū yán jiū [[ [ 77 7 ]] ]
然而rán ér rán ér 作为zuò wéi zuò wéi 报告bào gào bào gào 自己zì jǐ zì jǐ 发现fā xiàn fā xiàn de de 研究yán jiū yán jiū 人员rén yuán rén yuán 之一zhī yī zhī yī 存在cún zài cún zài 强调qiáng diào qiáng diào 漏洞lòu dòng lòu dòng 严重性yán zhòng xìng yán zhòng xìng de de 固有gù yǒu gù yǒu 偏见piān jiàn piān jiàn
###### ### gāi gāi 问题wèn tí wèn tí de de 主要zhǔ yào zhǔ yào 信息xìn xī xìn xī 来源lái yuán lái yuán
zuì zuì 可靠kě kào kě kào de de 来源lái yuán lái yuán 包括bāo kuò bāo kuò
-- - ** * ** * 科技kē jì kē jì 新闻媒体xīn wén méi tǐ xīn wén méi tǐ ** * ** * iTnewsiTnews iTnews InnovationAusInnovationAus InnovationAus 报道bào dào bào dào 漏洞lòu dòng lòu dòng 发现fā xiàn fā xiàn 政府zhèng fǔ zhèng fǔ 回应huí yìng huí yìng de de 澳大利亚ào dà lì yà ào dà lì yà 主流zhǔ liú zhǔ liú 科技kē jì kē jì 新闻xīn wén xīn wén [[ [ 11 1 ]] ] [[ [ 33 3 ]] ]
-- - ** * ** * 政府zhèng fǔ zhèng fǔ 来源lái yuán lái yuán ** * ** * 监察jiān chá jiān chá 专员zhuān yuán zhuān yuán 报告bào gào bào gào ATOATO ATO 声明shēng míng shēng míng 关于guān yú guān yú 安全ān quán ān quán 担忧dān yōu dān yōu 政府zhèng fǔ zhèng fǔ 立场lì chǎng lì chǎng de de 官方guān fāng guān fāng 文件wén jiàn wén jiàn [[ [ 44 4 ]] ] [[ [ 55 5 ]] ]
-- - ** * ** * 安全ān quán ān quán 研究yán jiū yán jiū ** * ** * ThinkingThinking Thinking CybersecurityCybersecurity Cybersecurity 研究yán jiū yán jiū 人员rén yuán rén yuán de de 技术jì shù jì shù 文档wén dàng wén dàng 学术xué shù xué shù 专业zhuān yè zhuān yè 安全ān quán ān quán 分析fēn xī fēn xī [[ [ 22 2 ]] ]
gāi gāi 陈述chén shù chén shù yǒu yǒu 主流zhǔ liú zhǔ liú 科技kē jì kē jì 新闻xīn wén xīn wén 政府zhèng fǔ zhèng fǔ 报告bào gào bào gào de de 良好liáng hǎo liáng hǎo 支持zhī chí zhī chí 完全wán quán wán quán 依赖于yī lài yú yī lài yú 单一dān yī dān yī 党派dǎng pài dǎng pài 来源lái yuán lái yuán
⚖️

工党对比

###### ### LaborLabor Labor 是否shì fǒu shì fǒu 采用cǎi yòng cǎi yòng le le 类似lèi sì lèi sì de de 定制dìng zhì dìng zhì 认证rèn zhèng rèn zhèng 方法fāng fǎ fāng fǎ
### Did Labor Adopt Similar Bespoke Authentication Approaches?
LaborLabor Labor zài zài myGovIDmyGovID myGovID 开发kāi fā kāi fā 期间qī jiān qī jiān 并未bìng wèi bìng wèi 执政zhí zhèng zhí zhèng CoalitionCoalition Coalition 执政zhí zhèng zhí zhèng 期为qī wèi qī wèi 20132013 2013 -- - 20222022 2022
Labor was not in government when myGovID was developed (Coalition governed 2013-2022).
LaborLabor Labor 政府zhèng fǔ zhèng fǔ 20222022 2022 nián nián 55 5 yuè yuè 上任shàng rèn shàng rèn shí shí 继承jì chéng jì chéng le le myGovIDmyGovID myGovID 系统xì tǒng xì tǒng
The Labor government inherited the myGovID system when they took office in May 2022. **However**, the more relevant comparison is: **How did Labor respond to the discovered vulnerability?** As noted above, the decision to "not intend to change the protocol" in September 2024 was made by the **Labor government's ATO**, not the Coalition.
** * ** * 然而rán ér rán ér ** * ** * gèng gèng 相关xiāng guān xiāng guān de de 比较bǐ jiào bǐ jiào shì shì ** * ** * LaborLabor Labor 如何rú hé rú hé 应对yìng duì yìng duì 发现fā xiàn fā xiàn de de 漏洞lòu dòng lòu dòng
This indicates both governments (Coalition for original development, Labor for response to the discovered vulnerability) made questionable cybersecurity decisions regarding myGovID.
** * ** *
### Labor's Approach to Digital Identity
如上所述rú shàng suǒ shù rú shàng suǒ shù 20242024 2024 nián nián 99 9 yuè yuè "" " 打算dǎ suàn dǎ suàn 更改gēng gǎi gēng gǎi 协议xié yì xié yì "" " de de 决定jué dìng jué dìng shì shì yóu yóu ** * ** * LaborLabor Labor 政府zhèng fǔ zhèng fǔ de de ATOATO ATO ** * ** * 做出zuò chū zuò chū de de ér ér fēi fēi CoalitionCoalition Coalition
Labor has pursued continued development of myGovID (rebranded as "myID" in November 2024) under a digital identity scheme.
zhè zhè 表明biǎo míng biǎo míng 两届liǎng jiè liǎng jiè 政府zhèng fǔ zhèng fǔ CoalitionCoalition Coalition 负责fù zé fù zé 原始yuán shǐ yuán shǐ 开发kāi fā kāi fā LaborLabor Labor 负责fù zé fù zé 应对yìng duì yìng duì 发现fā xiàn fā xiàn de de 漏洞lòu dòng lòu dòng zài zài myGovIDmyGovID myGovID 网络安全wǎng luò ān quán wǎng luò ān quán 方面fāng miàn fāng miàn dōu dōu 存在cún zài cún zài 令人lìng rén lìng rén 质疑zhì yí zhì yí de de 决策jué cè jué cè
Labor has not abandoned the bespoke TDIF framework but instead continued operating within it [8].
###### ### LaborLabor Labor de de 数字shù zì shù zì 身份shēn fèn shēn fèn 方法fāng fǎ fāng fǎ
This suggests Labor may bear some responsibility for not addressing the architectural vulnerability once it was discovered under their watch.
LaborLabor Labor zài zài 数字shù zì shù zì 身份shēn fèn shēn fèn 计划jì huà jì huà xià xià 继续jì xù jì xù 开发kāi fā kāi fā myGovIDmyGovID myGovID 20242024 2024 nián nián 1111 11 yuè yuè 重新命名chóng xīn mìng míng chóng xīn mìng míng wèi wèi "" " myIDmyID myID "" "
LaborLabor Labor 并未bìng wèi bìng wèi 放弃fàng qì fàng qì 定制dìng zhì dìng zhì de de TDIFTDIF TDIF 框架kuāng jià kuāng jià 而是ér shì ér shì 继续jì xù jì xù zài zài 框架kuāng jià kuāng jià nèi nèi 运行yùn xíng yùn xíng [[ [ 88 8 ]] ]
zhè zhè 表明biǎo míng biǎo míng LaborLabor Labor 可能kě néng kě néng duì duì 发现fā xiàn fā xiàn de de 架构jià gòu jià gòu 漏洞lòu dòng lòu dòng 承担chéng dān chéng dān 一定yí dìng yí dìng 责任zé rèn zé rèn 因为yīn wèi yīn wèi gāi gāi 漏洞lòu dòng lòu dòng shì shì zài zài 他们tā men tā men 执政zhí zhèng zhí zhèng 期间qī jiān qī jiān bèi bèi 发现fā xiàn fā xiàn de de
** * ** * 来源lái yuán lái yuán ** * ** *
-- - [[ [ 66 6 ]] ] httpshttps https :: : // / // / architecturearchitecture architecture .. . digitaldigital digital .. . govgov gov .. . auau au // / mygovidmygovid mygovid
-- - [[ [ 88 8 ]] ] httpshttps https :: : // / // / wwwwww www .. . atoato ato .. . govgov gov .. . auau au // / generalgeneral general // / onlineonline online -- - servicesservices services // / myidmyid myid
🌐

平衡视角

###### ### CoalitionCoalition Coalition de de 设计shè jì shè jì 决策jué cè jué cè 20132013 2013 -- - 20222022 2022
### The Coalition's Design Decision (2013-2022)
dāng dāng CoalitionCoalition Coalition 政府zhèng fǔ zhèng fǔ 决定jué dìng jué dìng 使用shǐ yòng shǐ yòng 专有zhuān yǒu zhuān yǒu de de 定制dìng zhì dìng zhì 认证rèn zhèng rèn zhèng 协议xié yì xié yì TDIFTDIF TDIF ér ér fēi fēi 采用cǎi yòng cǎi yòng 国际guó jì guó jì 认可rèn kě rèn kě de de 标准协议biāo zhǔn xié yì biāo zhǔn xié yì OpenIDOpenID OpenID ConnectConnect Connect lái lái 开发kāi fā kāi fā myGovIDmyGovID myGovID shí shí zhè zhè 代表dài biǎo dài biǎo le le 一个yí gè yí gè 值得zhí de zhí de 质疑zhì yí zhì yí de de 架构jià gòu jià gòu 决策jué cè jué cè
When the Coalition government decided to develop myGovID using a proprietary, bespoke authentication protocol (TDIF) rather than adopting internationally standard protocols like OpenID Connect, this represented a questionable architectural decision.
做出zuò chū zuò chū 这一zhè yī zhè yī 选择xuǎn zé xuǎn zé de de 可能kě néng kě néng 原因yuán yīn yuán yīn 包括bāo kuò bāo kuò
The reasons for this choice were likely: - Desire for a uniquely Australian solution tailored to specific government needs - Potential national sovereignty concerns (not relying on international standards) - Perceived control over the system's security and operations However, security experts argue that bespoke authentication systems are inherently riskier because they: - Have limited external security review compared to widely-used standards - Don't benefit from years of community vulnerability discovery and patching - Increase the chance of design flaws like the one discovered in 2024 [2] **Standard security practice is to use proven, widely-audited protocols unless there is a compelling reason not to.**
-- - 希望xī wàng xī wàng 获得huò dé huò dé 针对zhēn duì zhēn duì 特定tè dìng tè dìng 政府zhèng fǔ zhèng fǔ 需求量xū qiú liàng xū qiú liàng shēn shēn 定制dìng zhì dìng zhì de de 独特dú tè dú tè 澳大利亚ào dà lì yà ào dà lì yà 解决方案jiě jué fāng àn jiě jué fāng àn
### The Government's Response to the Discovered Vulnerability
-- - 潜在qián zài qián zài de de 国家主权guó jiā zhǔ quán guó jiā zhǔ quán 担忧dān yōu dān yōu 依赖yī lài yī lài 国际标准guó jì biāo zhǔn guó jì biāo zhǔn
More problematic than the original design choice was the response when the vulnerability was discovered: **During Coalition government (2013-2022):** - The Coalition would have deployed and operated myGovID but the vulnerability wasn't discovered until 2024 (after their loss of office) **During Labor government (September 2024 onward):** - The ATO explicitly refused to fix the known vulnerability, stating they "did not intend to change the protocol" - The government dismissed it as a "public awareness issue" rather than a technical design flaw - No remediation timeline or plan was announced - The system continued to operate with the known vulnerability
-- - duì duì 系统安全xì tǒng ān quán xì tǒng ān quán 运营yùn yíng yùn yíng de de 感知gǎn zhī gǎn zhī 控制kòng zhì kòng zhì
### Expert and Institutional Perspectives
然而rán ér rán ér 安全ān quán ān quán 专家zhuān jiā zhuān jiā 认为rèn wéi rèn wéi 定制dìng zhì dìng zhì 认证rèn zhèng rèn zhèng 系统xì tǒng xì tǒng 本质běn zhì běn zhì shàng shàng 风险fēng xiǎn fēng xiǎn 更高gèng gāo gèng gāo 因为yīn wèi yīn wèi
The Ombudsman's report reinforces that myGov/myGovID security is inadequate, with the government only agreeing to address deficiencies in 2025 [5].
-- - 广泛guǎng fàn guǎng fàn 使用shǐ yòng shǐ yòng de de 标准biāo zhǔn biāo zhǔn 相比xiāng bǐ xiāng bǐ 外部wài bù wài bù 安全ān quán ān quán 审查shěn chá shěn chá 有限yǒu xiàn yǒu xiàn
The timing suggests this was reactive rather than proactive security governance.
-- - 无法wú fǎ wú fǎ 受益shòu yì shòu yì 多年duō nián duō nián 社区shè qū shè qū 漏洞lòu dòng lòu dòng 发现fā xiàn fā xiàn 修补xiū bǔ xiū bǔ de de 成果chéng guǒ chéng guǒ
### Comparative Government Practice
-- - 增加zēng jiā zēng jiā le le 设计shè jì shè jì 缺陷quē xiàn quē xiàn de de 可能性kě néng xìng kě néng xìng 20242024 2024 nián nián 发现fā xiàn fā xiàn de de 缺陷quē xiàn quē xiàn [[ [ 22 2 ]] ]
Ignoring known security vulnerabilities in authentication systems is not standard practice across responsible governments.
** * ** * 标准biāo zhǔn biāo zhǔn 安全ān quán ān quán 实践shí jiàn shí jiàn shì shì 使用shǐ yòng shǐ yòng 经过jīng guò jīng guò 验证yàn zhèng yàn zhèng de de 广泛guǎng fàn guǎng fàn 审计shěn jì shěn jì de de 协议xié yì xié yì 除非chú fēi chú fēi yǒu yǒu 令人信服lìng rén xìn fú lìng rén xìn fú de de 理由lǐ yóu lǐ yóu 这样zhè yàng zhè yàng zuò zuò
The standard industry approach is: 1.
** * ** *
Acknowledge the vulnerability 2.
###### ### 政府zhèng fǔ zhèng fǔ duì duì 发现fā xiàn fā xiàn 漏洞lòu dòng lòu dòng de de 回应huí yìng huí yìng
Develop a remediation plan 3.
原始yuán shǐ yuán shǐ 设计shè jì shè jì 选择xuǎn zé xuǎn zé gèng gèng 令人担忧lìng rén dān yōu lìng rén dān yōu de de shì shì 发现fā xiàn fā xiàn 漏洞lòu dòng lòu dòng hòu hòu de de 回应huí yìng huí yìng
Implement the fix within a reasonable timeframe 4.
** * ** * CoalitionCoalition Coalition 政府zhèng fǔ zhèng fǔ 期间qī jiān qī jiān 20132013 2013 -- - 20222022 2022 ** * ** *
Publicly communicate the resolution The Australian government's response (refusing to fix the protocol design flaw) falls short of these standards. **Key context:** Neither the Coalition nor Labor has demonstrated strong cybersecurity governance regarding myGovID.
-- - CoalitionCoalition Coalition 部署bù shǔ bù shǔ 运营yùn yíng yùn yíng le le myGovIDmyGovID myGovID dàn dàn 直到zhí dào zhí dào 20242024 2024 nián nián 他们tā men tā men 败选后bài xuǎn hòu bài xuǎn hòu cái cái bèi bèi 发现fā xiàn fā xiàn gāi gāi 漏洞lòu dòng lòu dòng
The Coalition created a system using non-standard protocols, and Labor (which inherited it) refused to fix it when vulnerabilities were discovered.
** * ** * LaborLabor Labor 政府zhèng fǔ zhèng fǔ 期间qī jiān qī jiān 20242024 2024 nián nián 99 9 yuè yuè ** * ** *
Both decisions appear driven by bureaucratic inertia and unwillingness to acknowledge systemic architectural failures.
-- - ATOATO ATO 明确míng què míng què 拒绝jù jué jù jué 修复xiū fù xiū fù 已知yǐ zhī yǐ zhī de de 漏洞lòu dòng lòu dòng 声明shēng míng shēng míng 他们tā men tā men "" " 打算dǎ suàn dǎ suàn 更改gēng gǎi gēng gǎi 协议xié yì xié yì "" "
-- - 政府zhèng fǔ zhèng fǔ jiāng jiāng 视为shì wèi shì wèi "" " 公众gōng zhòng gōng zhòng 意识yì shí yì shí 问题wèn tí wèn tí "" " ér ér 非技术fēi jì shù fēi jì shù 设计shè jì shè jì 缺陷quē xiàn quē xiàn
-- - wèi wèi 宣布xuān bù xuān bù 修复xiū fù xiū fù 时间表shí jiān biǎo shí jiān biǎo huò huò 计划jì huà jì huà
-- - 系统xì tǒng xì tǒng zài zài 已知yǐ zhī yǐ zhī 漏洞lòu dòng lòu dòng 存在cún zài cún zài de de 情况qíng kuàng qíng kuàng xià xià 继续jì xù jì xù 运行yùn xíng yùn xíng
###### ### 专家zhuān jiā zhuān jiā 机构jī gòu jī gòu 观点guān diǎn guān diǎn
监察jiān chá jiān chá 专员zhuān yuán zhuān yuán de de 报告bào gào bào gào 进一步jìn yí bù jìn yí bù 证实zhèng shí zhèng shí myGovmyGov myGov // / myGovIDmyGovID myGovID 安全ān quán ān quán 不足bù zú bù zú 政府zhèng fǔ zhèng fǔ jǐn jǐn 同意tóng yì tóng yì zài zài 20252025 2025 nián nián 解决jiě jué jiě jué 缺陷quē xiàn quē xiàn [[ [ 55 5 ]] ]
时间shí jiān shí jiān 安排ān pái ān pái 表明biǎo míng biǎo míng 这是zhè shì zhè shì 被动bèi dòng bèi dòng de de ér ér fēi fēi 主动zhǔ dòng zhǔ dòng de de 安全ān quán ān quán 治理zhì lǐ zhì lǐ
###### ### 比较bǐ jiào bǐ jiào 政府zhèng fǔ zhèng fǔ 实践shí jiàn shí jiàn
忽视hū shì hū shì 认证rèn zhèng rèn zhèng 系统xì tǒng xì tǒng zhōng zhōng de de 已知yǐ zhī yǐ zhī 安全漏洞ān quán lòu dòng ān quán lòu dòng 并非bìng fēi bìng fēi 负责fù zé fù zé rèn rèn 政府zhèng fǔ zhèng fǔ de de 标准biāo zhǔn biāo zhǔn 做法zuò fǎ zuò fǎ
标准biāo zhǔn biāo zhǔn 行业háng yè háng yè 做法zuò fǎ zuò fǎ shì shì
11 1 .. . 承认chéng rèn chéng rèn 漏洞lòu dòng lòu dòng
22 2 .. . 制定zhì dìng zhì dìng 修复xiū fù xiū fù 计划jì huà jì huà
33 3 .. . zài zài 合理hé lǐ hé lǐ 时间shí jiān shí jiān nèi nèi 实施shí shī shí shī 修复xiū fù xiū fù
44 4 .. . 公开gōng kāi gōng kāi 沟通gōu tōng gōu tōng 解决方案jiě jué fāng àn jiě jué fāng àn
澳大利亚政府ào dà lì yà zhèng fǔ ào dà lì yà zhèng fǔ de de 回应huí yìng huí yìng 拒绝jù jué jù jué 修复xiū fù xiū fù 协议xié yì xié yì 设计shè jì shè jì 缺陷quē xiàn quē xiàn wèi wèi 达到dá dào dá dào 这些zhè xiē zhè xiē 标准biāo zhǔn biāo zhǔn
** * ** * 关键guān jiàn guān jiàn 背景bèi jǐng bèi jǐng ** * ** * CoalitionCoalition Coalition LaborLabor Labor zài zài myGovIDmyGovID myGovID 网络安全wǎng luò ān quán wǎng luò ān quán 治理zhì lǐ zhì lǐ 方面fāng miàn fāng miàn dōu dōu 表现biǎo xiàn biǎo xiàn 不佳bù jiā bù jiā
CoalitionCoalition Coalition 创建chuàng jiàn chuàng jiàn le le 使用shǐ yòng shǐ yòng fēi fēi 标准协议biāo zhǔn xié yì biāo zhǔn xié yì de de 系统xì tǒng xì tǒng LaborLabor Labor 继承jì chéng jì chéng gāi gāi 系统xì tǒng xì tǒng zài zài 发现fā xiàn fā xiàn 漏洞lòu dòng lòu dòng shí shí 拒绝jù jué jù jué 修复xiū fù xiū fù
两次liǎng cì liǎng cì 决策jué cè jué cè 似乎sì hū sì hū dōu dōu shì shì yóu yóu 官僚guān liáo guān liáo 惯性guàn xìng guàn xìng 不愿bù yuàn bù yuàn 承认chéng rèn chéng rèn 系统性xì tǒng xìng xì tǒng xìng 架构jià gòu jià gòu 失败shī bài shī bài suǒ suǒ 驱动qū dòng qū dòng

属实

7.0

/ 10

gāi gāi 陈述chén shù chén shù 关于guān yú guān yú myGovIDmyGovID myGovID 漏洞lòu dòng lòu dòng 政府zhèng fǔ zhèng fǔ 拒绝jù jué jù jué 修复xiū fù xiū fù de de 事实shì shí shì shí shì shì 准确zhǔn què zhǔn què de de
The claim is factually accurate regarding the myGovID vulnerability and the government's refusal to fix it.
然而rán ér rán ér yǒu yǒu 一个yí gè yí gè 重要zhòng yào zhòng yào de de ** * ** * 时间shí jiān shí jiān 澄清chéng qīng chéng qīng ** * ** * 拒绝jù jué jù jué 修复xiū fù xiū fù de de 决定jué dìng jué dìng shì shì yóu yóu ** * ** * 20242024 2024 nián nián 99 9 yuè yuè de de LaborLabor Labor 政府zhèng fǔ zhèng fǔ ** * ** * 做出zuò chū zuò chū de de ér ér fēi fēi CoalitionCoalition Coalition 政府zhèng fǔ zhèng fǔ
However, there is an important **temporal clarification**: The decision to refuse remediation was made by the **Labor government in September 2024**, not the Coalition government.
CoalitionCoalition Coalition 20132013 2013 -- - 20222022 2022 做出zuò chū zuò chū le le 使用shǐ yòng shǐ yòng 定制dìng zhì dìng zhì fēi fēi 标准协议biāo zhǔn xié yì biāo zhǔn xié yì de de 原始yuán shǐ yuán shǐ 决定jué dìng jué dìng 这是zhè shì zhè shì 导致dǎo zhì dǎo zhì gāi gāi 漏洞lòu dòng lòu dòng de de 架构jià gòu jià gòu 选择xuǎn zé xuǎn zé
The Coalition (2013-2022) made the original decision to use a bespoke, non-standard protocol, which was the architectural choice that enabled this vulnerability.
gāi gāi 陈述chén shù chén shù 可以kě yǐ kě yǐ yǒu yǒu 两种liǎng zhǒng liǎng zhǒng 理解lǐ jiě lǐ jiě 方式fāng shì fāng shì
The claim could be interpreted two ways: 1. **If referring to original protocol design (Coalition era 2013-2022):** TRUE - The Coalition chose a bespoke protocol over proven standards 2. **If referring to the 2024 refusal to fix the discovered vulnerability:** TRUE but made by Labor government, not Coalition The statement "Chose to ignore and not fix" most naturally reads as referring to the refusal to remediate after discovery (September 2024), which was a Labor government decision, though the underlying architectural choice was made by the Coalition.
11 1 .. . ** * ** * 如果rú guǒ rú guǒ zhǐ zhǐ de de shì shì 原始yuán shǐ yuán shǐ 协议xié yì xié yì 设计shè jì shè jì CoalitionCoalition Coalition 时代shí dài shí dài 20132013 2013 -- - 20222022 2022 ** * ** * 属实shǔ shí shǔ shí CoalitionCoalition Coalition 选择xuǎn zé xuǎn zé le le 定制dìng zhì dìng zhì 协议xié yì xié yì ér ér fēi fēi 经过jīng guò jīng guò 验证yàn zhèng yàn zhèng de de 标准biāo zhǔn biāo zhǔn
22 2 .. . ** * ** * 如果rú guǒ rú guǒ zhǐ zhǐ de de shì shì 20242024 2024 nián nián 拒绝jù jué jù jué 修复xiū fù xiū fù 发现fā xiàn fā xiàn 漏洞lòu dòng lòu dòng ** * ** * 属实shǔ shí shǔ shí 但是dàn shì dàn shì yóu yóu LaborLabor Labor 政府zhèng fǔ zhèng fǔ 做出zuò chū zuò chū ér ér fēi fēi CoalitionCoalition Coalition
"" " 选择xuǎn zé xuǎn zé 忽视hū shì hū shì qiě qiě 修复xiū fù xiū fù "" " 这一zhè yī zhè yī 表述biǎo shù biǎo shù zuì zuì 自然zì rán zì rán 理解lǐ jiě lǐ jiě wèi wèi zhǐ zhǐ 发现fā xiàn fā xiàn hòu hòu de de 拒绝jù jué jù jué 修复xiū fù xiū fù 20242024 2024 nián nián 99 9 yuè yuè 这是zhè shì zhè shì LaborLabor Labor 政府zhèng fǔ zhèng fǔ de de 决定jué dìng jué dìng 尽管jǐn guǎn jǐn guǎn 底层dǐ céng dǐ céng 架构jià gòu jià gòu 选择xuǎn zé xuǎn zé shì shì yóu yóu CoalitionCoalition Coalition 做出zuò chū zuò chū de de

📚 来源与引用 (8)

  1. 1
    itnews.com.au

    itnews.com.au

    ATO declines to change protocol.

    iTnews
  2. 2
    thinkingcybersecurity.com

    thinkingcybersecurity.com

    Thinkingcybersecurity

  3. 3
    innovationaus.com

    innovationaus.com

    Innovationaus

  4. 4
    accountantsdaily.com.au

    accountantsdaily.com.au

    From security concerns to clashes with workplace policies, the transition to myGovID has caused a few headaches within the profession, but the ATO believes worries are misplaced.

    Accountantsdaily Com
  5. 5
    PDF

    Keeping myGov Secure

    Ombudsman Gov • PDF Document
  6. 6
    architecture.digital.gov.au

    architecture.digital.gov.au

    Architecture Digital Gov

  7. 7
    cecs.anu.edu.au

    cecs.anu.edu.au

    Cecs Anu Edu

  8. 8
    ato.gov.au

    ato.gov.au

    Ato Gov

评分方法

1-3: 不实

事实错误或恶意捏造。

4-6: 部分属实

有一定真实性,但缺乏背景或有所偏颇。

7-9: 基本属实

仅有微小的技术性或措辞问题。

10: 准确

完全经过验证且客观公正。

方法论: 评分通过交叉参照政府官方记录、独立事实核查机构和原始文件确定。