属实

评分: 7.0/10

Coalition
C0161

声明内容

“选择忽视且不修复myGovID的安全漏洞,该漏洞之所以产生是因为所选的认证协议是定制的,不符合标准规范。”
原始来源: Matthew Davis
分析时间: 29 Jan 2026

原始来源

✅ 事实核查

###### ### myGovIDmyGovID myGovID 安全漏洞ān quán lòu dòng ān quán lòu dòng -- - 代码dài mǎ dài mǎ 重zhòng zhòng 放fàng fàng 攻击gōng jī gōng jī
### myGovID Security Vulnerability - Code Replay Attack
该gāi gāi 陈述chén shù chén shù 引用yǐn yòng yǐn yòng 了le le myGovIDmyGovID myGovID 中zhōng zhōng 发现fā xiàn fā xiàn 的de de 真实zhēn shí zhēn shí 安全漏洞ān quán lòu dòng ān quán lòu dòng 。。 。
The claim references a real security vulnerability identified in myGovID.
20242024 2024 年nián nián 88 8 月yuè yuè ,, , 安全ān quán ān quán 研究yán jiū yán jiū 人员rén yuán rén yuán BenBen Ben FrengleyFrengley Frengley (( ( 墨尔本大学mò ěr běn dà xué mò ěr běn dà xué )) ) 和hé hé VanessaVanessa Vanessa TeagueTeague Teague (( ( ThinkingThinking Thinking CybersecurityCybersecurity Cybersecurity 首席shǒu xí shǒu xí 执行官zhí xíng guān zhí xíng guān ,, , 澳大利亚ào dà lì yà ào dà lì yà 国立大学guó lì dà xué guó lì dà xué 兼职jiān zhí jiān zhí 教授jiào shòu jiào shòu )) ) 发现fā xiàn fā xiàn 了le le myGovIDmyGovID myGovID 认证rèn zhèng rèn zhèng 系统xì tǒng xì tǒng 中zhōng zhōng 的de de 关键guān jiàn guān jiàn 漏洞lòu dòng lòu dòng [[ [ 11 1 ]] ] 。。 。
In August 2024, security researchers Ben Frengley (University of Melbourne) and Vanessa Teague (CEO of Thinking Cybersecurity, ANU adjunct professor) discovered a critical vulnerability in myGovID's authentication system [1].
该gāi gāi 漏洞lòu dòng lòu dòng 是shì shì 一种yī zhǒng yī zhǒng ** * ** * 代码dài mǎ dài mǎ 重zhòng zhòng 放fàng fàng 攻击gōng jī gōng jī ** * ** * ,, , 利用lì yòng lì yòng 了le le 一个yí gè yí gè 根本性gēn běn xìng gēn běn xìng 的de de 设计shè jì shè jì 缺陷quē xiàn quē xiàn 。。 。
The vulnerability is a **code replay attack** that exploits a fundamental design flaw.
攻击者gōng jī zhě gōng jī zhě 可以kě yǐ kě yǐ 建立jiàn lì jiàn lì 一个yí gè yí gè 虚假xū jiǎ xū jiǎ 网站wǎng zhàn wǎng zhàn 并bìng bìng 捕获bǔ huò bǔ huò 用户yòng hù yòng hù 的de de 电子邮件diàn zi yóu jiàn diàn zi yóu jiàn 地址dì zhǐ dì zhǐ 。。 。
An attacker can set up a fake website and capture a user's email address.
当dāng dāng 攻击者gōng jī zhě gōng jī zhě 使用shǐ yòng shǐ yòng 受害者shòu hài zhě shòu hài zhě 的de de 电子邮件diàn zi yóu jiàn diàn zi yóu jiàn 地址dì zhǐ dì zhǐ 在zài zài 合法hé fǎ hé fǎ 的de de 政府zhèng fǔ zhèng fǔ 门户网站mén hù wǎng zhàn mén hù wǎng zhàn 发起fā qǐ fā qǐ 认证rèn zhèng rèn zhèng 时shí shí ,, , 门户网站mén hù wǎng zhàn mén hù wǎng zhàn 会huì huì 显示xiǎn shì xiǎn shì 一个yí gè yí gè 44 4 位数wèi shù wèi shù 的de de PINPIN PIN 码mǎ mǎ 。。 。
When the attacker initiates authentication at a legitimate government portal using the victim's email, the portal displays a 4-digit PIN.
攻击者gōng jī zhě gōng jī zhě 通过tōng guò tōng guò 虚假xū jiǎ xū jiǎ 网站wǎng zhàn wǎng zhàn 将jiāng jiāng 此cǐ cǐ PINPIN PIN 码mǎ mǎ 传递chuán dì chuán dì 给gěi gěi 受害者shòu hài zhě shòu hài zhě ,, , 当dāng dāng 受害者shòu hài zhě shòu hài zhě 在zài zài myGovIDmyGovID myGovID 应用程序yìng yòng chéng xù yìng yòng chéng xù 中zhōng zhōng 输入shū rù shū rù 时shí shí ,, , 他们tā men tā men 在zài zài 不知情bù zhī qíng bù zhī qíng 的de de 情况qíng kuàng qíng kuàng 下xià xià 授予shòu yǔ shòu yǔ 了le le 攻击者gōng jī zhě gōng jī zhě 对duì duì 其qí qí 合法政府hé fǎ zhèng fǔ hé fǎ zhèng fǔ 账户zhàng hù zhàng hù 的de de 完全wán quán wán quán 访问fǎng wèn fǎng wèn 权限quán xiàn quán xiàn 。。 。
The attacker relays this PIN to the victim through the fake site, and when the victim enters it into their myGovID app, they unknowingly grant the attacker full access to legitimate government accounts.
一个yí gè yí gè 关键guān jiàn guān jiàn 的de de 设计shè jì shè jì 弱点ruò diǎn ruò diǎn 是shì shì myGovIDmyGovID myGovID 应用程序yìng yòng chéng xù yìng yòng chéng xù ** * ** * 未wèi wèi 显示xiǎn shì xiǎn shì 请求qǐng qiú qǐng qiú 认证rèn zhèng rèn zhèng 的de de 是shì shì 哪个nǎ ge nǎ ge 组织zǔ zhī zǔ zhī ** * ** * [[ [ 22 2 ]] ] 。。 。
A critical design weakness is that the myGovID app provides **no indication of which organization is requesting authentication** [2].
研究yán jiū yán jiū 人员rén yuán rén yuán 于yú yú 20242024 2024 年nián nián 88 8 月yuè yuè 1919 19 日向rì xiàng rì xiàng 澳大利亚ào dà lì yà ào dà lì yà 信号xìn hào xìn hào 局jú jú (( ( ASDASD ASD )) ) 报告bào gào bào gào 了le le 此cǐ cǐ 漏洞lòu dòng lòu dòng [[ [ 33 3 ]] ] 。。 。
The researchers reported this vulnerability to the Australian Signals Directorate (ASD) on August 19, 2024 [3].
根据gēn jù gēn jù 行业háng yè háng yè 最佳zuì jiā zuì jiā 实践shí jiàn shí jiàn ,, , 他们tā men tā men 提出tí chū tí chū 了le le 9090 90 天tiān tiān 的de de 负责fù zé fù zé 任rèn rèn 披露pī lù pī lù 期qī qī ,, , 以便yǐ biàn yǐ biàn 政府zhèng fǔ zhèng fǔ 有yǒu yǒu 时间shí jiān shí jiān 在zài zài 公开gōng kāi gōng kāi 披露pī lù pī lù 前qián qián 开发kāi fā kāi fā 和hé hé 实施shí shī shí shī 修复xiū fù xiū fù 方案fāng àn fāng àn [[ [ 11 1 ]] ] 。。 。
According to industry best practice, they proposed a 90-day responsible disclosure period to allow the government time to develop and implement a fix before public disclosure [1].
###### ### 政府zhèng fǔ zhèng fǔ 回应huí yìng huí yìng :: : 拒绝jù jué jù jué 修复xiū fù xiū fù
### Government's Response: Refusal to Fix
20242024 2024 年nián nián 99 9 月yuè yuè 1818 18 日rì rì ,, , 澳大利亚ào dà lì yà ào dà lì yà 税务局shuì wù jú shuì wù jú (( ( ATOATO ATO )) ) 与yǔ yǔ 研究yán jiū yán jiū 人员rén yuán rén yuán 会面huì miàn huì miàn ,, , 并bìng bìng 明确míng què míng què 表示biǎo shì biǎo shì ** * ** * "" " 不bù bù 打算dǎ suàn dǎ suàn 更改gēng gǎi gēng gǎi 协议xié yì xié yì "" " ** * ** * [[ [ 33 3 ]] ] 。。 。
On September 18, 2024, the Australian Taxation Office (ATO) met with the researchers and explicitly stated it **"did not intend to change the protocol"** [3].
这zhè zhè 意味着yì wèi zhe yì wèi zhe 政府zhèng fǔ zhèng fǔ 拒绝jù jué jù jué 修复xiū fù xiū fù 该gāi gāi 漏洞lòu dòng lòu dòng 。。 。
This means the government declined to remediate the vulnerability.
此外cǐ wài cǐ wài ,, , ATOATO ATO 将jiāng jiāng 该gāi gāi 漏洞lòu dòng lòu dòng 定性dìng xìng dìng xìng 为wèi wèi "" " 更gèng gèng 像是xiàng shì xiàng shì 公众gōng zhòng gōng zhòng 意识yì shí yì shí 问题wèn tí wèn tí "" " ,, , 而ér ér 非fēi fēi 需要xū yào xū yào 更改gēng gǎi gēng gǎi 协议xié yì xié yì 的de de 技术jì shù jì shù 缺陷quē xiàn quē xiàn [[ [ 33 3 ]] ] 。。 。
Additionally, the ATO characterized the vulnerability as "more of a public awareness issue" rather than a technical flaw requiring protocol changes [3].
ATOATO ATO 还hái hái 发表声明fā biǎo shēng míng fā biǎo shēng míng 称chēng chēng myGovIDmyGovID myGovID "" " 比bǐ bǐ 任何rèn hé rèn hé 凭证píng zhèng píng zhèng 都dōu dōu 更gèng gèng 安全ān quán ān quán "" " ,, , 对duì duì 研究yán jiū yán jiū 人员rén yuán rén yuán 的de de 担忧dān yōu dān yōu 不予bù yǔ bù yǔ 理会lǐ huì lǐ huì [[ [ 44 4 ]] ] 。。 。
The ATO also issued statements claiming myGovID was "more secure than any credential," dismissing researcher concerns [4].
在zài zài 政府zhèng fǔ zhèng fǔ 拒绝jù jué jù jué 修复xiū fù xiū fù 漏洞lòu dòng lòu dòng 后hòu hòu ,, , 研究yán jiū yán jiū 人员rén yuán rén yuán 于yú yú 20242024 2024 年nián nián 99 9 月yuè yuè 2121 21 日rì rì 公开gōng kāi gōng kāi 披露pī lù pī lù —— — —— — 尽管jǐn guǎn jǐn guǎn 曾céng céng 提议tí yì tí yì 负责fù zé fù zé 任rèn rèn 披露pī lù pī lù 期qī qī ,, , 但dàn dàn 仍réng réng 公布gōng bù gōng bù 了le le 他们tā men tā men 的de de 发现fā xiàn fā xiàn [[ [ 22 2 ]] ] 。。 。
After the government refused to fix the vulnerability, the researchers went public on September 21, 2024 - publishing their findings despite having proposed a responsible disclosure period [2].
安全ān quán ān quán 研究yán jiū yán jiū 人员rén yuán rén yuán 明确míng què míng què 警告jǐng gào jǐng gào 公众gōng zhòng gōng zhòng 在zài zài 登录dēng lù dēng lù 漏洞lòu dòng lòu dòng 修复xiū fù xiū fù 之前zhī qián zhī qián 不要bú yào bú yào 使用shǐ yòng shǐ yòng myGovIDmyGovID myGovID [[ [ 11 1 ]] ] 。。 。
The security researchers explicitly warned the public not to use myGovID until the login flaw was fixed [1].
###### ### 监察jiān chá jiān chá 专员zhuān yuán zhuān yuán 的de de 支持zhī chí zhī chí 证据zhèng jù zhèng jù
### Supporting Evidence from Ombudsman
20242024 2024 年nián nián 88 8 月yuè yuè ,, , 澳大利亚ào dà lì yà ào dà lì yà 监察jiān chá jiān chá 专员zhuān yuán zhuān yuán 发布fā bù fā bù 了le le 《《 《 保障bǎo zhàng bǎo zhàng myGovmyGov myGov 安全ān quán ān quán 》》 》 报告bào gào bào gào ,, , 其中qí zhōng qí zhōng 指出zhǐ chū zhǐ chū 了le le myGovmyGov myGov // / myGovIDmyGovID myGovID 系统xì tǒng xì tǒng 中zhōng zhōng 的de de 多项duō xiàng duō xiàng 安全ān quán ān quán 缺陷quē xiàn quē xiàn ,, , 包括bāo kuò bāo kuò 身份验证shēn fèn yàn zhèng shēn fèn yàn zhèng 标准biāo zhǔn biāo zhǔn 不bù bù 一致yí zhì yí zhì 、、 、 对duì duì 未wèi wèi 授权shòu quán shòu quán 账户zhàng hù zhàng hù 关联guān lián guān lián 的de de 安全控制ān quán kòng zhì ān quán kòng zhì 有限yǒu xiàn yǒu xiàn ,, , 以及yǐ jí yǐ jí 诈骗者zhà piàn zhě zhà piàn zhě 重定向zhòng dìng xiàng zhòng dìng xiàng 养老金yǎng lǎo jīn yǎng lǎo jīn 支付zhī fù zhī fù 和hé hé 提交tí jiāo tí jiāo 虚假xū jiǎ xū jiǎ 福利fú lì fú lì 申请shēn qǐng shēn qǐng 的de de 实例shí lì shí lì [[ [ 55 5 ]] ] 。。 。
In August 2024, the Australian Ombudsman published the "Keeping myGov Secure" report, which identified multiple security deficiencies in myGov/myGovID systems, including inconsistent proof-of-identity standards, limited security controls for unauthorized account linking, and instances of fraudsters redirecting pension payments and submitting false benefit claims [5].
澳大利亚ào dà lì yà ào dà lì yà 服务部fú wù bù fú wù bù 于yú yú 20242024 2024 年nián nián 77 7 月yuè yuè 下旬xià xún xià xún 同意tóng yì tóng yì 了le le 这些zhè xiē zhè xiē 建议jiàn yì jiàn yì ,, , 但dàn dàn 将jiāng jiāng 实施shí shī shí shī 推迟tuī chí tuī chí 到dào dào 20252025 2025 年初nián chū nián chū ,, , 表明biǎo míng biǎo míng 对duì duì 紧急jǐn jí jǐn jí 安全ān quán ān quán 问题wèn tí wèn tí 未wèi wèi 立即lì jí lì jí 采取行动cǎi qǔ xíng dòng cǎi qǔ xíng dòng [[ [ 55 5 ]] ] 。。 。
Services Australia agreed to these recommendations in late July 2024 but deferred implementation to early 2025, indicating no immediate action was taken on urgent security matters [5].

缺失背景

###### ### 11 1 .. . "" " 定制dìng zhì dìng zhì "" " 认证rèn zhèng rèn zhèng 协议xié yì xié yì 属实shǔ shí shǔ shí
### 1. The "Bespoke" Authentication Protocol is Accurate
该gāi gāi 陈述chén shù chén shù 准确zhǔn què zhǔn què 地dì dì 将jiāng jiāng myGovIDmyGovID myGovID 的de de 认证rèn zhèng rèn zhèng 协议xié yì xié yì 描述miáo shù miáo shù 为wèi wèi 非fēi fēi 标准协议biāo zhǔn xié yì biāo zhǔn xié yì 。。 。
The claim accurately characterizes myGovID's authentication protocol as non-standard. myGovID uses the **Trusted Digital Identity Framework (TDIF)**, which is a proprietary, bespoke system specific to Australia - not OpenID Connect, OAuth 2.0, or other internationally recognized standards [6].
myGovIDmyGovID myGovID 使用shǐ yòng shǐ yòng ** * ** * 可信kě xìn kě xìn 数字shù zì shù zì 身份shēn fèn shēn fèn 框架kuāng jià kuāng jià (( ( TDIFTDIF TDIF )) ) ** * ** * ,, , 这是zhè shì zhè shì 一个yí gè yí gè 专有zhuān yǒu zhuān yǒu 的de de 、、 、 定制dìng zhì dìng zhì 的de de 系统xì tǒng xì tǒng ,, , 仅jǐn jǐn 在zài zài 澳大利亚ào dà lì yà ào dà lì yà 使用shǐ yòng shǐ yòng —— — —— — 而ér ér 非fēi fēi OpenIDOpenID OpenID ConnectConnect Connect 、、 、 OAuthOAuth OAuth 2.02.0 2.0 或huò huò 其他qí tā qí tā 国际guó jì guó jì 认可rèn kě rèn kě 的de de 标准biāo zhǔn biāo zhǔn [[ [ 66 6 ]] ] 。。 。
Security researchers have recommended that the TDIF framework be deprecated and replaced with standard protocols like OpenID Connect [2].
安全ān quán ān quán 研究yán jiū yán jiū 人员rén yuán rén yuán 建议jiàn yì jiàn yì 应弃yīng qì yīng qì 用yòng yòng TDIFTDIF TDIF 框架kuāng jià kuāng jià ,, , 改用gǎi yòng gǎi yòng OpenIDOpenID OpenID ConnectConnect Connect 等děng děng 标准协议biāo zhǔn xié yì biāo zhǔn xié yì [[ [ 22 2 ]] ] 。。 。
### 2. Protocol Design vs. Implementation Issues
###### ### 22 2 .. . 协议xié yì xié yì 设计shè jì shè jì 问题wèn tí wèn tí vsvs vs 实施shí shī shí shī 问题wèn tí wèn tí
While the vulnerability exists, there is a technical distinction worth noting: the fundamental flaw appears to stem from the protocol's design (the lack of context about who is requesting authentication in the myGovID app), not necessarily implementation errors.
虽然suī rán suī rán 漏洞lòu dòng lòu dòng 确实què shí què shí 存在cún zài cún zài ,, , 但dàn dàn 有yǒu yǒu 一个yí gè yí gè 技术jì shù jì shù 区别qū bié qū bié 值得注意zhí de zhù yì zhí de zhù yì :: : 根本性gēn běn xìng gēn běn xìng 缺陷quē xiàn quē xiàn 似乎sì hū sì hū 源于yuán yú yuán yú 协议xié yì xié yì 设计shè jì shè jì (( ( myGovIDmyGovID myGovID 应用程序yìng yòng chéng xù yìng yòng chéng xù 缺乏quē fá quē fá 关于guān yú guān yú 谁shuí shuí 在zài zài 请求qǐng qiú qǐng qiú 认证rèn zhèng rèn zhèng 的de de 上下文shàng xià wén shàng xià wén 信息xìn xī xìn xī )) ) ,, , 而ér ér 非fēi fēi 必然bì rán bì rán 的de de 实施shí shī shí shī 错误cuò wù cuò wù 。。 。
However, this distinction does not diminish the validity of the claim - a flawed protocol design is still a flaw that requires fixing.
然而rán ér rán ér ,, , 这一zhè yī zhè yī 区别qū bié qū bié 并bìng bìng 不bù bù 削弱xuē ruò xuē ruò 该gāi gāi 陈述chén shù chén shù 的de de 有效性yǒu xiào xìng yǒu xiào xìng —— — —— — 存在cún zài cún zài 缺陷quē xiàn quē xiàn 的de de 协议xié yì xié yì 设计shè jì shè jì 仍然réng rán réng rán 是shì shì 缺陷quē xiàn quē xiàn ,, , 需要xū yào xū yào 修复xiū fù xiū fù 。。 。
### 3. Timeline and Context
###### ### 33 3 .. . 时间shí jiān shí jiān 线xiàn xiàn 和hé hé 背景bèi jǐng bèi jǐng
The vulnerability discovery occurred late in the Coalition government's tenure.
漏洞lòu dòng lòu dòng 发现fā xiàn fā xiàn 于yú yú CoalitionCoalition Coalition 政府zhèng fǔ zhèng fǔ 任期rèn qī rèn qī 即将jí jiāng jí jiāng 结束jié shù jié shù 时shí shí 。。 。
The Coalition was voted out of office in May 2022.
CoalitionCoalition Coalition 于yú yú 20222022 2022 年nián nián 55 5 月yuè yuè 落选luò xuǎn luò xuǎn 。。 。
The vulnerability was discovered in August 2024 by the Albanese Labor government.
该gāi gāi 漏洞lòu dòng lòu dòng 于yú yú 20242024 2024 年nián nián 88 8 月yuè yuè 由yóu yóu AlbaneseAlbanese Albanese LaborLabor Labor 政府zhèng fǔ zhèng fǔ 执政zhí zhèng zhí zhèng 期间qī jiān qī jiān 被bèi bèi 发现fā xiàn fā xiàn 。。 。
This means: - The Coalition government (2013-2022) would not have made the September 2024 decision to refuse remediation - The current (Labor) government inherited myGovID and made the decision not to change the protocol [3] However, the claim may be referring to the Coalition government's original decision to develop and deploy myGovID using a bespoke, non-standard protocol rather than established industry standards - which would have been a decision made during the Coalition's time in office (2013-2022).
这zhè zhè 意味着yì wèi zhe yì wèi zhe :: :
-- - CoalitionCoalition Coalition 政府zhèng fǔ zhèng fǔ (( ( 20132013 2013 -- - 20222022 2022 )) ) 不会bú huì bú huì 在zài zài 20242024 2024 年nián nián 99 9 月yuè yuè 做出zuò chū zuò chū 拒绝jù jué jù jué 修复xiū fù xiū fù 的de de 决定jué dìng jué dìng
-- - 现任xiàn rèn xiàn rèn (( ( LaborLabor Labor )) ) 政府zhèng fǔ zhèng fǔ 继承jì chéng jì chéng 了le le myGovIDmyGovID myGovID ,, , 并bìng bìng 决定jué dìng jué dìng 不bù bù 更改gēng gǎi gēng gǎi 协议xié yì xié yì [[ [ 33 3 ]] ]
然而rán ér rán ér ,, , 该gāi gāi 陈述chén shù chén shù 可能kě néng kě néng 指zhǐ zhǐ 的de de 是shì shì CoalitionCoalition Coalition 政府zhèng fǔ zhèng fǔ 最初zuì chū zuì chū 决定jué dìng jué dìng 使用shǐ yòng shǐ yòng 定制dìng zhì dìng zhì 的de de 非fēi fēi 标准协议biāo zhǔn xié yì biāo zhǔn xié yì 而ér ér 非fēi fēi 既定jì dìng jì dìng 行业标准háng yè biāo zhǔn háng yè biāo zhǔn 开发kāi fā kāi fā 和hé hé 部署bù shǔ bù shǔ myGovIDmyGovID myGovID —— — —— — 这是zhè shì zhè shì CoalitionCoalition Coalition 执政zhí zhèng zhí zhèng 期间qī jiān qī jiān (( ( 20132013 2013 -- - 20222022 2022 )) ) 做出zuò chū zuò chū 的de de 决定jué dìng jué dìng 。。 。

来源可信度评估

###### ### 原始yuán shǐ yuán shǐ 来源lái yuán lái yuán :: : ThinkingThinking Thinking CybersecurityCybersecurity Cybersecurity
### Original Source: Thinking Cybersecurity
提供tí gōng tí gōng 的de de 原始yuán shǐ yuán shǐ 来源lái yuán lái yuán (( ( ThinkingThinking Thinking CybersecurityCybersecurity Cybersecurity )) ) 是shì shì 由yóu yóu VanessaVanessa Vanessa TeagueTeague Teague 领导lǐng dǎo lǐng dǎo 的de de 组织zǔ zhī zǔ zhī ,, , 她tā tā 是shì shì 发现fā xiàn fā xiàn 该gāi gāi 漏洞lòu dòng lòu dòng 的de de 研究yán jiū yán jiū 人员rén yuán rén yuán 之一zhī yī zhī yī 。。 。
The original source provided (Thinking Cybersecurity) is an organization led by Vanessa Teague, one of the researchers who discovered the vulnerability.
这zhè zhè 形成xíng chéng xíng chéng 了le le 关于guān yú guān yú 漏洞lòu dòng lòu dòng 本身běn shēn běn shēn 的de de 直接zhí jiē zhí jiē 来源lái yuán lái yuán 。。 。
This creates a direct source on the vulnerability itself.
VanessaVanessa Vanessa TeagueTeague Teague 是shì shì :: :
Vanessa Teague is: - An ANU adjunct professor and security researcher - A credible academic voice in cybersecurity - Has published peer-reviewed work on electoral security and digital systems [7] However, as one of the researchers reporting on their own finding, there is inherent bias in favor of emphasizing the vulnerability's severity.
-- - 澳大利亚ào dà lì yà ào dà lì yà 国立大学guó lì dà xué guó lì dà xué 兼职jiān zhí jiān zhí 教授jiào shòu jiào shòu 和hé hé 安全ān quán ān quán 研究yán jiū yán jiū 人员rén yuán rén yuán
### Primary Sources on This Issue
-- - 网络安全wǎng luò ān quán wǎng luò ān quán 领域lǐng yù lǐng yù 可信kě xìn kě xìn 的de de 学术xué shù xué shù 声音shēng yīn shēng yīn
The most reliable sources are: - **Technology news outlets** (iTnews, InnovationAus): Mainstream Australian tech journalism covering the vulnerability discovery and government response [1][3] - **Government sources** (Ombudsman report, ATO statements): Official documentation of security concerns and government positions [4][5] - **Security research** (Thinking Cybersecurity, researchers' technical documentation): Academic and professional security analysis [2] The claim is well-supported by mainstream technology journalism and government reports, not primarily dependent on a single partisan source.
-- - 发表fā biǎo fā biǎo 过guò guò 关于guān yú guān yú 选举xuǎn jǔ xuǎn jǔ 安全ān quán ān quán 和hé hé 数字shù zì shù zì 系统xì tǒng xì tǒng 的de de 同行tóng háng tóng háng 评审píng shěn píng shěn 研究yán jiū yán jiū [[ [ 77 7 ]] ]
然而rán ér rán ér ,, , 作为zuò wéi zuò wéi 报告bào gào bào gào 自己zì jǐ zì jǐ 发现fā xiàn fā xiàn 的de de 研究yán jiū yán jiū 人员rén yuán rén yuán 之一zhī yī zhī yī ,, , 存在cún zài cún zài 强调qiáng diào qiáng diào 漏洞lòu dòng lòu dòng 严重性yán zhòng xìng yán zhòng xìng 的de de 固有gù yǒu gù yǒu 偏见piān jiàn piān jiàn 。。 。
###### ### 该gāi gāi 问题wèn tí wèn tí 的de de 主要zhǔ yào zhǔ yào 信息xìn xī xìn xī 来源lái yuán lái yuán
最zuì zuì 可靠kě kào kě kào 的de de 来源lái yuán lái yuán 包括bāo kuò bāo kuò :: :
-- - ** * ** * 科技kē jì kē jì 新闻媒体xīn wén méi tǐ xīn wén méi tǐ ** * ** * (( ( iTnewsiTnews iTnews 、、 、 InnovationAusInnovationAus InnovationAus )) ) :: : 报道bào dào bào dào 漏洞lòu dòng lòu dòng 发现fā xiàn fā xiàn 和hé hé 政府zhèng fǔ zhèng fǔ 回应huí yìng huí yìng 的de de 澳大利亚ào dà lì yà ào dà lì yà 主流zhǔ liú zhǔ liú 科技kē jì kē jì 新闻xīn wén xīn wén [[ [ 11 1 ]] ] [[ [ 33 3 ]] ]
-- - ** * ** * 政府zhèng fǔ zhèng fǔ 来源lái yuán lái yuán ** * ** * (( ( 监察jiān chá jiān chá 专员zhuān yuán zhuān yuán 报告bào gào bào gào 、、 、 ATOATO ATO 声明shēng míng shēng míng )) ) :: : 关于guān yú guān yú 安全ān quán ān quán 担忧dān yōu dān yōu 和hé hé 政府zhèng fǔ zhèng fǔ 立场lì chǎng lì chǎng 的de de 官方guān fāng guān fāng 文件wén jiàn wén jiàn [[ [ 44 4 ]] ] [[ [ 55 5 ]] ]
-- - ** * ** * 安全ān quán ān quán 研究yán jiū yán jiū ** * ** * (( ( ThinkingThinking Thinking CybersecurityCybersecurity Cybersecurity 、、 、 研究yán jiū yán jiū 人员rén yuán rén yuán 的de de 技术jì shù jì shù 文档wén dàng wén dàng )) ) :: : 学术xué shù xué shù 和hé hé 专业zhuān yè zhuān yè 安全ān quán ān quán 分析fēn xī fēn xī [[ [ 22 2 ]] ]
该gāi gāi 陈述chén shù chén shù 有yǒu yǒu 主流zhǔ liú zhǔ liú 科技kē jì kē jì 新闻xīn wén xīn wén 和hé hé 政府zhèng fǔ zhèng fǔ 报告bào gào bào gào 的de de 良好liáng hǎo liáng hǎo 支持zhī chí zhī chí ,, , 不bù bù 完全wán quán wán quán 依赖于yī lài yú yī lài yú 单一dān yī dān yī 党派dǎng pài dǎng pài 来源lái yuán lái yuán 。。 。
⚖️

工党对比

###### ### LaborLabor Labor 是否shì fǒu shì fǒu 采用cǎi yòng cǎi yòng 了le le 类似lèi sì lèi sì 的de de 定制dìng zhì dìng zhì 认证rèn zhèng rèn zhèng 方法fāng fǎ fāng fǎ ?? ?
### Did Labor Adopt Similar Bespoke Authentication Approaches?
LaborLabor Labor 在zài zài myGovIDmyGovID myGovID 开发kāi fā kāi fā 期间qī jiān qī jiān 并未bìng wèi bìng wèi 执政zhí zhèng zhí zhèng (( ( CoalitionCoalition Coalition 执政zhí zhèng zhí zhèng 期为qī wèi qī wèi 20132013 2013 -- - 20222022 2022 )) ) 。。 。
Labor was not in government when myGovID was developed (Coalition governed 2013-2022).
LaborLabor Labor 政府zhèng fǔ zhèng fǔ 于yú yú 20222022 2022 年nián nián 55 5 月yuè yuè 上任shàng rèn shàng rèn 时shí shí 继承jì chéng jì chéng 了le le myGovIDmyGovID myGovID 系统xì tǒng xì tǒng 。。 。
The Labor government inherited the myGovID system when they took office in May 2022. **However**, the more relevant comparison is: **How did Labor respond to the discovered vulnerability?** As noted above, the decision to "not intend to change the protocol" in September 2024 was made by the **Labor government's ATO**, not the Coalition.
** * ** * 然而rán ér rán ér ** * ** * ,, , 更gèng gèng 相关xiāng guān xiāng guān 的de de 比较bǐ jiào bǐ jiào 是shì shì :: : ** * ** * LaborLabor Labor 如何rú hé rú hé 应对yìng duì yìng duì 发现fā xiàn fā xiàn 的de de 漏洞lòu dòng lòu dòng ?? ?
This indicates both governments (Coalition for original development, Labor for response to the discovered vulnerability) made questionable cybersecurity decisions regarding myGovID.
** * ** *
### Labor's Approach to Digital Identity
如上所述rú shàng suǒ shù rú shàng suǒ shù ,, , 20242024 2024 年nián nián 99 9 月yuè yuè "" " 不bù bù 打算dǎ suàn dǎ suàn 更改gēng gǎi gēng gǎi 协议xié yì xié yì "" " 的de de 决定jué dìng jué dìng 是shì shì 由yóu yóu ** * ** * LaborLabor Labor 政府zhèng fǔ zhèng fǔ 的de de ATOATO ATO ** * ** * 做出zuò chū zuò chū 的de de ,, , 而ér ér 非fēi fēi CoalitionCoalition Coalition 。。 。
Labor has pursued continued development of myGovID (rebranded as "myID" in November 2024) under a digital identity scheme.
这zhè zhè 表明biǎo míng biǎo míng 两届liǎng jiè liǎng jiè 政府zhèng fǔ zhèng fǔ (( ( CoalitionCoalition Coalition 负责fù zé fù zé 原始yuán shǐ yuán shǐ 开发kāi fā kāi fā ,, , LaborLabor Labor 负责fù zé fù zé 应对yìng duì yìng duì 发现fā xiàn fā xiàn 的de de 漏洞lòu dòng lòu dòng )) ) 在zài zài myGovIDmyGovID myGovID 网络安全wǎng luò ān quán wǎng luò ān quán 方面fāng miàn fāng miàn 都dōu dōu 存在cún zài cún zài 令人lìng rén lìng rén 质疑zhì yí zhì yí 的de de 决策jué cè jué cè 。。 。
Labor has not abandoned the bespoke TDIF framework but instead continued operating within it [8].
###### ### LaborLabor Labor 的de de 数字shù zì shù zì 身份shēn fèn shēn fèn 方法fāng fǎ fāng fǎ
This suggests Labor may bear some responsibility for not addressing the architectural vulnerability once it was discovered under their watch.
LaborLabor Labor 在zài zài 数字shù zì shù zì 身份shēn fèn shēn fèn 计划jì huà jì huà 下xià xià 继续jì xù jì xù 开发kāi fā kāi fā myGovIDmyGovID myGovID (( ( 于yú yú 20242024 2024 年nián nián 1111 11 月yuè yuè 重新命名chóng xīn mìng míng chóng xīn mìng míng 为wèi wèi "" " myIDmyID myID "" " )) ) 。。 。
LaborLabor Labor 并未bìng wèi bìng wèi 放弃fàng qì fàng qì 定制dìng zhì dìng zhì 的de de TDIFTDIF TDIF 框架kuāng jià kuāng jià ,, , 而是ér shì ér shì 继续jì xù jì xù 在zài zài 其qí qí 框架kuāng jià kuāng jià 内nèi nèi 运行yùn xíng yùn xíng [[ [ 88 8 ]] ] 。。 。
这zhè zhè 表明biǎo míng biǎo míng LaborLabor Labor 可能kě néng kě néng 对duì duì 发现fā xiàn fā xiàn 的de de 架构jià gòu jià gòu 漏洞lòu dòng lòu dòng 承担chéng dān chéng dān 一定yí dìng yí dìng 责任zé rèn zé rèn ,, , 因为yīn wèi yīn wèi 该gāi gāi 漏洞lòu dòng lòu dòng 是shì shì 在zài zài 他们tā men tā men 执政zhí zhèng zhí zhèng 期间qī jiān qī jiān 被bèi bèi 发现fā xiàn fā xiàn 的de de 。。 。
** * ** * 来源lái yuán lái yuán :: : ** * ** *
-- - [[ [ 66 6 ]] ] httpshttps https :: : // / // / architecturearchitecture architecture .. . digitaldigital digital .. . govgov gov .. . auau au // / mygovidmygovid mygovid
-- - [[ [ 88 8 ]] ] httpshttps https :: : // / // / wwwwww www .. . atoato ato .. . govgov gov .. . auau au // / generalgeneral general // / onlineonline online -- - servicesservices services // / myidmyid myid
🌐

平衡视角

###### ### CoalitionCoalition Coalition 的de de 设计shè jì shè jì 决策jué cè jué cè (( ( 20132013 2013 -- - 20222022 2022 )) )
### The Coalition's Design Decision (2013-2022)
当dāng dāng CoalitionCoalition Coalition 政府zhèng fǔ zhèng fǔ 决定jué dìng jué dìng 使用shǐ yòng shǐ yòng 专有zhuān yǒu zhuān yǒu 的de de 定制dìng zhì dìng zhì 认证rèn zhèng rèn zhèng 协议xié yì xié yì (( ( TDIFTDIF TDIF )) ) 而ér ér 非fēi fēi 采用cǎi yòng cǎi yòng 国际guó jì guó jì 认可rèn kě rèn kě 的de de 标准协议biāo zhǔn xié yì biāo zhǔn xié yì 如rú rú OpenIDOpenID OpenID ConnectConnect Connect 来lái lái 开发kāi fā kāi fā myGovIDmyGovID myGovID 时shí shí ,, , 这zhè zhè 代表dài biǎo dài biǎo 了le le 一个yí gè yí gè 值得zhí de zhí de 质疑zhì yí zhì yí 的de de 架构jià gòu jià gòu 决策jué cè jué cè 。。 。
When the Coalition government decided to develop myGovID using a proprietary, bespoke authentication protocol (TDIF) rather than adopting internationally standard protocols like OpenID Connect, this represented a questionable architectural decision.
做出zuò chū zuò chū 这一zhè yī zhè yī 选择xuǎn zé xuǎn zé 的de de 可能kě néng kě néng 原因yuán yīn yuán yīn 包括bāo kuò bāo kuò :: :
The reasons for this choice were likely: - Desire for a uniquely Australian solution tailored to specific government needs - Potential national sovereignty concerns (not relying on international standards) - Perceived control over the system's security and operations However, security experts argue that bespoke authentication systems are inherently riskier because they: - Have limited external security review compared to widely-used standards - Don't benefit from years of community vulnerability discovery and patching - Increase the chance of design flaws like the one discovered in 2024 [2] **Standard security practice is to use proven, widely-audited protocols unless there is a compelling reason not to.**
-- - 希望xī wàng xī wàng 获得huò dé huò dé 针对zhēn duì zhēn duì 特定tè dìng tè dìng 政府zhèng fǔ zhèng fǔ 需求量xū qiú liàng xū qiú liàng 身shēn shēn 定制dìng zhì dìng zhì 的de de 独特dú tè dú tè 澳大利亚ào dà lì yà ào dà lì yà 解决方案jiě jué fāng àn jiě jué fāng àn
### The Government's Response to the Discovered Vulnerability
-- - 潜在qián zài qián zài 的de de 国家主权guó jiā zhǔ quán guó jiā zhǔ quán 担忧dān yōu dān yōu (( ( 不bù bù 依赖yī lài yī lài 国际标准guó jì biāo zhǔn guó jì biāo zhǔn )) )
More problematic than the original design choice was the response when the vulnerability was discovered: **During Coalition government (2013-2022):** - The Coalition would have deployed and operated myGovID but the vulnerability wasn't discovered until 2024 (after their loss of office) **During Labor government (September 2024 onward):** - The ATO explicitly refused to fix the known vulnerability, stating they "did not intend to change the protocol" - The government dismissed it as a "public awareness issue" rather than a technical design flaw - No remediation timeline or plan was announced - The system continued to operate with the known vulnerability
-- - 对duì duì 系统安全xì tǒng ān quán xì tǒng ān quán 和hé hé 运营yùn yíng yùn yíng 的de de 感知gǎn zhī gǎn zhī 控制kòng zhì kòng zhì
### Expert and Institutional Perspectives
然而rán ér rán ér ,, , 安全ān quán ān quán 专家zhuān jiā zhuān jiā 认为rèn wéi rèn wéi ,, , 定制dìng zhì dìng zhì 认证rèn zhèng rèn zhèng 系统xì tǒng xì tǒng 本质běn zhì běn zhì 上shàng shàng 风险fēng xiǎn fēng xiǎn 更高gèng gāo gèng gāo ,, , 因为yīn wèi yīn wèi :: :
The Ombudsman's report reinforces that myGov/myGovID security is inadequate, with the government only agreeing to address deficiencies in 2025 [5].
-- - 与yǔ yǔ 广泛guǎng fàn guǎng fàn 使用shǐ yòng shǐ yòng 的de de 标准biāo zhǔn biāo zhǔn 相比xiāng bǐ xiāng bǐ ,, , 外部wài bù wài bù 安全ān quán ān quán 审查shěn chá shěn chá 有限yǒu xiàn yǒu xiàn
The timing suggests this was reactive rather than proactive security governance.
-- - 无法wú fǎ wú fǎ 受益shòu yì shòu yì 于yú yú 多年duō nián duō nián 社区shè qū shè qū 漏洞lòu dòng lòu dòng 发现fā xiàn fā xiàn 和hé hé 修补xiū bǔ xiū bǔ 的de de 成果chéng guǒ chéng guǒ
### Comparative Government Practice
-- - 增加zēng jiā zēng jiā 了le le 设计shè jì shè jì 缺陷quē xiàn quē xiàn 的de de 可能性kě néng xìng kě néng xìng ,, , 如rú rú 20242024 2024 年nián nián 发现fā xiàn fā xiàn 的de de 缺陷quē xiàn quē xiàn [[ [ 22 2 ]] ]
Ignoring known security vulnerabilities in authentication systems is not standard practice across responsible governments.
** * ** * 标准biāo zhǔn biāo zhǔn 安全ān quán ān quán 实践shí jiàn shí jiàn 是shì shì 使用shǐ yòng shǐ yòng 经过jīng guò jīng guò 验证yàn zhèng yàn zhèng 的de de 、、 、 广泛guǎng fàn guǎng fàn 审计shěn jì shěn jì 的de de 协议xié yì xié yì ,, , 除非chú fēi chú fēi 有yǒu yǒu 令人信服lìng rén xìn fú lìng rén xìn fú 的de de 理由lǐ yóu lǐ yóu 不bù bù 这样zhè yàng zhè yàng 做zuò zuò 。。 。
The standard industry approach is: 1.
** * ** *
Acknowledge the vulnerability 2.
###### ### 政府zhèng fǔ zhèng fǔ 对duì duì 发现fā xiàn fā xiàn 漏洞lòu dòng lòu dòng 的de de 回应huí yìng huí yìng
Develop a remediation plan 3.
比bǐ bǐ 原始yuán shǐ yuán shǐ 设计shè jì shè jì 选择xuǎn zé xuǎn zé 更gèng gèng 令人担忧lìng rén dān yōu lìng rén dān yōu 的de de 是shì shì 发现fā xiàn fā xiàn 漏洞lòu dòng lòu dòng 后hòu hòu 的de de 回应huí yìng huí yìng :: :
Implement the fix within a reasonable timeframe 4.
** * ** * CoalitionCoalition Coalition 政府zhèng fǔ zhèng fǔ 期间qī jiān qī jiān (( ( 20132013 2013 -- - 20222022 2022 )) ) :: : ** * ** *
Publicly communicate the resolution The Australian government's response (refusing to fix the protocol design flaw) falls short of these standards. **Key context:** Neither the Coalition nor Labor has demonstrated strong cybersecurity governance regarding myGovID.
-- - CoalitionCoalition Coalition 部署bù shǔ bù shǔ 和hé hé 运营yùn yíng yùn yíng 了le le myGovIDmyGovID myGovID ,, , 但dàn dàn 直到zhí dào zhí dào 20242024 2024 年nián nián (( ( 他们tā men tā men 败选后bài xuǎn hòu bài xuǎn hòu )) ) 才cái cái 被bèi bèi 发现fā xiàn fā xiàn 该gāi gāi 漏洞lòu dòng lòu dòng
The Coalition created a system using non-standard protocols, and Labor (which inherited it) refused to fix it when vulnerabilities were discovered.
** * ** * LaborLabor Labor 政府zhèng fǔ zhèng fǔ 期间qī jiān qī jiān (( ( 20242024 2024 年nián nián 99 9 月yuè yuè 起qǐ qǐ )) ) :: : ** * ** *
Both decisions appear driven by bureaucratic inertia and unwillingness to acknowledge systemic architectural failures.
-- - ATOATO ATO 明确míng què míng què 拒绝jù jué jù jué 修复xiū fù xiū fù 已知yǐ zhī yǐ zhī 的de de 漏洞lòu dòng lòu dòng ,, , 声明shēng míng shēng míng 他们tā men tā men "" " 不bù bù 打算dǎ suàn dǎ suàn 更改gēng gǎi gēng gǎi 协议xié yì xié yì "" "
-- - 政府zhèng fǔ zhèng fǔ 将jiāng jiāng 其qí qí 视为shì wèi shì wèi "" " 公众gōng zhòng gōng zhòng 意识yì shí yì shí 问题wèn tí wèn tí "" " 而ér ér 非技术fēi jì shù fēi jì shù 设计shè jì shè jì 缺陷quē xiàn quē xiàn
-- - 未wèi wèi 宣布xuān bù xuān bù 修复xiū fù xiū fù 时间表shí jiān biǎo shí jiān biǎo 或huò huò 计划jì huà jì huà
-- - 系统xì tǒng xì tǒng 在zài zài 已知yǐ zhī yǐ zhī 漏洞lòu dòng lòu dòng 存在cún zài cún zài 的de de 情况qíng kuàng qíng kuàng 下xià xià 继续jì xù jì xù 运行yùn xíng yùn xíng
###### ### 专家zhuān jiā zhuān jiā 和hé hé 机构jī gòu jī gòu 观点guān diǎn guān diǎn
监察jiān chá jiān chá 专员zhuān yuán zhuān yuán 的de de 报告bào gào bào gào 进一步jìn yí bù jìn yí bù 证实zhèng shí zhèng shí myGovmyGov myGov // / myGovIDmyGovID myGovID 安全ān quán ān quán 不足bù zú bù zú ,, , 政府zhèng fǔ zhèng fǔ 仅jǐn jǐn 同意tóng yì tóng yì 在zài zài 20252025 2025 年nián nián 解决jiě jué jiě jué 缺陷quē xiàn quē xiàn [[ [ 55 5 ]] ] 。。 。
时间shí jiān shí jiān 安排ān pái ān pái 表明biǎo míng biǎo míng 这是zhè shì zhè shì 被动bèi dòng bèi dòng 的de de 而ér ér 非fēi fēi 主动zhǔ dòng zhǔ dòng 的de de 安全ān quán ān quán 治理zhì lǐ zhì lǐ 。。 。
###### ### 比较bǐ jiào bǐ jiào 政府zhèng fǔ zhèng fǔ 实践shí jiàn shí jiàn
忽视hū shì hū shì 认证rèn zhèng rèn zhèng 系统xì tǒng xì tǒng 中zhōng zhōng 的de de 已知yǐ zhī yǐ zhī 安全漏洞ān quán lòu dòng ān quán lòu dòng 并非bìng fēi bìng fēi 负责fù zé fù zé 任rèn rèn 政府zhèng fǔ zhèng fǔ 的de de 标准biāo zhǔn biāo zhǔn 做法zuò fǎ zuò fǎ 。。 。
标准biāo zhǔn biāo zhǔn 行业háng yè háng yè 做法zuò fǎ zuò fǎ 是shì shì :: :
11 1 .. . 承认chéng rèn chéng rèn 漏洞lòu dòng lòu dòng
22 2 .. . 制定zhì dìng zhì dìng 修复xiū fù xiū fù 计划jì huà jì huà
33 3 .. . 在zài zài 合理hé lǐ hé lǐ 时间shí jiān shí jiān 内nèi nèi 实施shí shī shí shī 修复xiū fù xiū fù
44 4 .. . 公开gōng kāi gōng kāi 沟通gōu tōng gōu tōng 解决方案jiě jué fāng àn jiě jué fāng àn
澳大利亚政府ào dà lì yà zhèng fǔ ào dà lì yà zhèng fǔ 的de de 回应huí yìng huí yìng (( ( 拒绝jù jué jù jué 修复xiū fù xiū fù 协议xié yì xié yì 设计shè jì shè jì 缺陷quē xiàn quē xiàn )) ) 未wèi wèi 达到dá dào dá dào 这些zhè xiē zhè xiē 标准biāo zhǔn biāo zhǔn 。。 。
** * ** * 关键guān jiàn guān jiàn 背景bèi jǐng bèi jǐng :: : ** * ** * CoalitionCoalition Coalition 和hé hé LaborLabor Labor 在zài zài myGovIDmyGovID myGovID 网络安全wǎng luò ān quán wǎng luò ān quán 治理zhì lǐ zhì lǐ 方面fāng miàn fāng miàn 都dōu dōu 表现biǎo xiàn biǎo xiàn 不佳bù jiā bù jiā 。。 。
CoalitionCoalition Coalition 创建chuàng jiàn chuàng jiàn 了le le 使用shǐ yòng shǐ yòng 非fēi fēi 标准协议biāo zhǔn xié yì biāo zhǔn xié yì 的de de 系统xì tǒng xì tǒng ,, , LaborLabor Labor (( ( 继承jì chéng jì chéng 该gāi gāi 系统xì tǒng xì tǒng )) ) 在zài zài 发现fā xiàn fā xiàn 漏洞lòu dòng lòu dòng 时shí shí 拒绝jù jué jù jué 修复xiū fù xiū fù 。。 。
两次liǎng cì liǎng cì 决策jué cè jué cè 似乎sì hū sì hū 都dōu dōu 是shì shì 由yóu yóu 官僚guān liáo guān liáo 惯性guàn xìng guàn xìng 和hé hé 不愿bù yuàn bù yuàn 承认chéng rèn chéng rèn 系统性xì tǒng xìng xì tǒng xìng 架构jià gòu jià gòu 失败shī bài shī bài 所suǒ suǒ 驱动qū dòng qū dòng 。。 。

属实

7.0

/ 10

该gāi gāi 陈述chén shù chén shù 关于guān yú guān yú myGovIDmyGovID myGovID 漏洞lòu dòng lòu dòng 和hé hé 政府zhèng fǔ zhèng fǔ 拒绝jù jué jù jué 修复xiū fù xiū fù 的de de 事实shì shí shì shí 是shì shì 准确zhǔn què zhǔn què 的de de 。。 。
The claim is factually accurate regarding the myGovID vulnerability and the government's refusal to fix it.
然而rán ér rán ér ,, , 有yǒu yǒu 一个yí gè yí gè 重要zhòng yào zhòng yào 的de de ** * ** * 时间shí jiān shí jiān 澄清chéng qīng chéng qīng ** * ** * :: : 拒绝jù jué jù jué 修复xiū fù xiū fù 的de de 决定jué dìng jué dìng 是shì shì 由yóu yóu ** * ** * 20242024 2024 年nián nián 99 9 月yuè yuè 的de de LaborLabor Labor 政府zhèng fǔ zhèng fǔ ** * ** * 做出zuò chū zuò chū 的de de ,, , 而ér ér 非fēi fēi CoalitionCoalition Coalition 政府zhèng fǔ zhèng fǔ 。。 。
However, there is an important **temporal clarification**: The decision to refuse remediation was made by the **Labor government in September 2024**, not the Coalition government.
CoalitionCoalition Coalition (( ( 20132013 2013 -- - 20222022 2022 )) ) 做出zuò chū zuò chū 了le le 使用shǐ yòng shǐ yòng 定制dìng zhì dìng zhì 非fēi fēi 标准协议biāo zhǔn xié yì biāo zhǔn xié yì 的de de 原始yuán shǐ yuán shǐ 决定jué dìng jué dìng ,, , 这是zhè shì zhè shì 导致dǎo zhì dǎo zhì 该gāi gāi 漏洞lòu dòng lòu dòng 的de de 架构jià gòu jià gòu 选择xuǎn zé xuǎn zé 。。 。
The Coalition (2013-2022) made the original decision to use a bespoke, non-standard protocol, which was the architectural choice that enabled this vulnerability.
该gāi gāi 陈述chén shù chén shù 可以kě yǐ kě yǐ 有yǒu yǒu 两种liǎng zhǒng liǎng zhǒng 理解lǐ jiě lǐ jiě 方式fāng shì fāng shì :: :
The claim could be interpreted two ways: 1. **If referring to original protocol design (Coalition era 2013-2022):** TRUE - The Coalition chose a bespoke protocol over proven standards 2. **If referring to the 2024 refusal to fix the discovered vulnerability:** TRUE but made by Labor government, not Coalition The statement "Chose to ignore and not fix" most naturally reads as referring to the refusal to remediate after discovery (September 2024), which was a Labor government decision, though the underlying architectural choice was made by the Coalition.
11 1 .. . ** * ** * 如果rú guǒ rú guǒ 指zhǐ zhǐ 的de de 是shì shì 原始yuán shǐ yuán shǐ 协议xié yì xié yì 设计shè jì shè jì (( ( CoalitionCoalition Coalition 时代shí dài shí dài 20132013 2013 -- - 20222022 2022 )) ) :: : ** * ** * 属实shǔ shí shǔ shí —— — —— — CoalitionCoalition Coalition 选择xuǎn zé xuǎn zé 了le le 定制dìng zhì dìng zhì 协议xié yì xié yì 而ér ér 非fēi fēi 经过jīng guò jīng guò 验证yàn zhèng yàn zhèng 的de de 标准biāo zhǔn biāo zhǔn
22 2 .. . ** * ** * 如果rú guǒ rú guǒ 指zhǐ zhǐ 的de de 是shì shì 20242024 2024 年nián nián 拒绝jù jué jù jué 修复xiū fù xiū fù 已yǐ yǐ 发现fā xiàn fā xiàn 漏洞lòu dòng lòu dòng :: : ** * ** * 属实shǔ shí shǔ shí ,, , 但是dàn shì dàn shì 由yóu yóu LaborLabor Labor 政府zhèng fǔ zhèng fǔ 做出zuò chū zuò chū ,, , 而ér ér 非fēi fēi CoalitionCoalition Coalition
"" " 选择xuǎn zé xuǎn zé 忽视hū shì hū shì 且qiě qiě 不bù bù 修复xiū fù xiū fù "" " 这一zhè yī zhè yī 表述biǎo shù biǎo shù 最zuì zuì 自然zì rán zì rán 地dì dì 理解lǐ jiě lǐ jiě 为wèi wèi 指zhǐ zhǐ 发现fā xiàn fā xiàn 后hòu hòu 的de de 拒绝jù jué jù jué 修复xiū fù xiū fù (( ( 20242024 2024 年nián nián 99 9 月yuè yuè )) ) ,, , 这是zhè shì zhè shì LaborLabor Labor 政府zhèng fǔ zhèng fǔ 的de de 决定jué dìng jué dìng ,, , 尽管jǐn guǎn jǐn guǎn 底层dǐ céng dǐ céng 架构jià gòu jià gòu 选择xuǎn zé xuǎn zé 是shì shì 由yóu yóu CoalitionCoalition Coalition 做出zuò chū zuò chū 的de de 。。 。

📚 来源与引用 (8)

  1. 1
    itnews.com.au

    itnews.com.au

    ATO declines to change protocol.

    iTnews
  2. 2
    thinkingcybersecurity.com

    thinkingcybersecurity.com

    Thinkingcybersecurity

  3. 3
    innovationaus.com

    innovationaus.com

    Innovationaus

  4. 4
    accountantsdaily.com.au

    accountantsdaily.com.au

    From security concerns to clashes with workplace policies, the transition to myGovID has caused a few headaches within the profession, but the ATO believes worries are misplaced.

    Accountantsdaily Com
  5. 5
    PDF

    Keeping myGov Secure

    Ombudsman Gov • PDF Document
  6. 6
    architecture.digital.gov.au

    architecture.digital.gov.au

    Architecture Digital Gov

  7. 7
    cecs.anu.edu.au

    cecs.anu.edu.au

    Cecs Anu Edu

  8. 8
    ato.gov.au

    ato.gov.au

    Ato Gov

评分方法

1-3: 不实

事实错误或恶意捏造。

4-6: 部分属实

有一定真实性,但缺乏背景或有所偏颇。

7-9: 基本属实

仅有微小的技术性或措辞问题。

10: 准确

完全经过验证且客观公正。

方法论: 评分通过交叉参照政府官方记录、独立事实核查机构和原始文件确定。