真實

評分: 7.0/10

Coalition
C0161

主張

“選擇忽視且不修復 myGovID 的安全漏洞,該漏洞的產生是因為所選擇的驗證協議為客製化設計,不符合標準實務。”
原始來源: Matthew Davis
分析日期: 29 Jan 2026

原始來源

✅ 事實查核

###### ### myGovIDmyGovID myGovID 安全漏洞ㄢ ㄑㄩㄢˊ ㄌㄡˋ ㄉㄨㄥˋ ān quán lòu dòng -- - 驗證碼ㄧㄢˋ ㄓㄥˋ ㄇㄚˇ yàn zhèng mǎ 重送ㄓㄨㄥˋ ㄙㄨㄥˋ zhòng sòng 攻擊ㄍㄨㄥ ㄐㄧ gōng jī
### myGovID Security Vulnerability - Code Replay Attack
該主張ㄍㄞ ㄓㄨˇ ㄓㄤ gāi zhǔ zhāng 提及ㄊㄧˊ ㄐㄧˊ tí jí myGovIDmyGovID myGovID 存在ㄘㄨㄣˊ ㄗㄞˋ cún zài 的ㄉㄜ˙ de 真實ㄓㄣ ㄕˊ zhēn shí 安全漏洞ㄢ ㄑㄩㄢˊ ㄌㄡˋ ㄉㄨㄥˋ ān quán lòu dòng 。。 。
The claim references a real security vulnerability identified in myGovID.
20242024 2024 年ㄋㄧㄢˊ nián 88 8 月ㄩㄝˋ yuè ,, , 墨爾本ㄇㄛˋ ㄦˇ ㄅㄣˇ mò ěr běn 大學ㄉㄚˋ ㄒㄩㄝˊ dà xué 的ㄉㄜ˙ de BenBen Ben FrengleyFrengley Frengley 與ㄩˇ yǔ ThinkingThinking Thinking CybersecurityCybersecurity Cybersecurity 執行長ㄓˊ ㄒㄧㄥˊ ㄓㄤˇ zhí xíng zhǎng 、、 、 澳洲ㄠˋ ㄓㄡ ào zhōu 國立ㄍㄨㄛˊ ㄌㄧˋ guó lì 大學ㄉㄚˋ ㄒㄩㄝˊ dà xué 兼任ㄐㄧㄢ ㄖㄣˋ jiān rèn 教授ㄐㄧㄠˋ ㄕㄡˋ jiào shòu VanessaVanessa Vanessa TeagueTeague Teague 發現ㄈㄚ ㄒㄧㄢˋ fā xiàn myGovIDmyGovID myGovID 驗證ㄧㄢˋ ㄓㄥˋ yàn zhèng 系統ㄒㄧˋ ㄊㄨㄥˇ xì tǒng 存在ㄘㄨㄣˊ ㄗㄞˋ cún zài 重大ㄓㄨㄥˋ ㄉㄚˋ zhòng dà 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng [[ [ 11 1 ]] ] 。。 。
In August 2024, security researchers Ben Frengley (University of Melbourne) and Vanessa Teague (CEO of Thinking Cybersecurity, ANU adjunct professor) discovered a critical vulnerability in myGovID's authentication system [1].
此ㄘˇ cǐ 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 為ㄨㄟˋ wèi ** * ** * 驗證碼ㄧㄢˋ ㄓㄥˋ ㄇㄚˇ yàn zhèng mǎ 重送ㄓㄨㄥˋ ㄙㄨㄥˋ zhòng sòng 攻擊ㄍㄨㄥ ㄐㄧ gōng jī ** * ** * ,, , 利用ㄌㄧˋ ㄩㄥˋ lì yòng 基本ㄐㄧ ㄅㄣˇ jī běn 設計ㄕㄜˋ ㄐㄧˋ shè jì 缺陷ㄑㄩㄝ ㄒㄧㄢˋ quē xiàn 運作ㄩㄣˋ ㄗㄨㄛˋ yùn zuò 。。 。
The vulnerability is a **code replay attack** that exploits a fundamental design flaw.
攻擊者ㄍㄨㄥ ㄐㄧ ㄓㄜˇ gōng jī zhě 可ㄎㄜˇ kě 建立ㄐㄧㄢˋ ㄌㄧˋ jiàn lì 假網ㄐㄧㄚˇ ㄨㄤˇ jiǎ wǎng 站ㄓㄢˋ zhàn 並擷ㄅㄧㄥˋ ㄒㄧㄝˊ bìng xié 取ㄑㄩˇ qǔ 使用者ㄕˇ ㄩㄥˋ ㄓㄜˇ shǐ yòng zhě 電子ㄉㄧㄢˋ ㄗ˙ diàn zi 郵件ㄧㄡˊ ㄐㄧㄢˋ yóu jiàn 地址ㄉㄧˋ ㄓˇ dì zhǐ 。。 。
An attacker can set up a fake website and capture a user's email address.
當攻ㄉㄤ ㄍㄨㄥ dāng gōng 擊者ㄐㄧ ㄓㄜˇ jī zhě 使用ㄕˇ ㄩㄥˋ shǐ yòng 受害者ㄕㄡˋ ㄏㄞˋ ㄓㄜˇ shòu hài zhě 電子ㄉㄧㄢˋ ㄗ˙ diàn zi 郵件ㄧㄡˊ ㄐㄧㄢˋ yóu jiàn 在ㄗㄞˋ zài 合法政府ㄏㄜˊ ㄈㄚˇ ㄓㄥˋ ㄈㄨˇ hé fǎ zhèng fǔ 入口ㄖㄨˋ ㄎㄡˇ rù kǒu 網站ㄨㄤˇ ㄓㄢˋ wǎng zhàn 啟動驗ㄑㄧˇ ㄉㄨㄥˋ ㄧㄢˋ qǐ dòng yàn 證時ㄓㄥˋ ㄕˊ zhèng shí ,, , 入口ㄖㄨˋ ㄎㄡˇ rù kǒu 網站ㄨㄤˇ ㄓㄢˋ wǎng zhàn 會ㄏㄨㄟˋ huì 顯示ㄒㄧㄢˇ ㄕˋ xiǎn shì 44 4 位數ㄨㄟˋ ㄕㄨˋ wèi shù PINPIN PIN 碼ㄇㄚˇ mǎ 。。 。
When the attacker initiates authentication at a legitimate government portal using the victim's email, the portal displays a 4-digit PIN.
攻擊者ㄍㄨㄥ ㄐㄧ ㄓㄜˇ gōng jī zhě 透過ㄊㄡˋ ㄍㄨㄛˋ tòu guò 假網ㄐㄧㄚˇ ㄨㄤˇ jiǎ wǎng 站ㄓㄢˋ zhàn 將此ㄐㄧㄤ ㄘˇ jiāng cǐ PINPIN PIN 碼轉ㄇㄚˇ ㄓㄨㄢˇ mǎ zhuǎn 傳給ㄔㄨㄢˊ ㄍㄟˇ chuán gěi 受害者ㄕㄡˋ ㄏㄞˋ ㄓㄜˇ shòu hài zhě ,, , 當ㄉㄤ dāng 受害者ㄕㄡˋ ㄏㄞˋ ㄓㄜˇ shòu hài zhě 在ㄗㄞˋ zài myGovIDmyGovID myGovID 應用ㄧㄥ ㄩㄥˋ yīng yòng 程式ㄔㄥˊ ㄕˋ chéng shì 中輸入ㄓㄨㄥ ㄕㄨ ㄖㄨˋ zhōng shū rù 時ㄕˊ shí ,, , 便會ㄅㄧㄢˋ ㄏㄨㄟˋ biàn huì 在ㄗㄞˋ zài 不知情ㄅㄨˋ ㄓ ㄑㄧㄥˊ bù zhī qíng 的ㄉㄜ˙ de 情況ㄑㄧㄥˊ ㄎㄨㄤˋ qíng kuàng 下ㄒㄧㄚˋ xià 授予ㄕㄡˋ ㄩˇ shòu yǔ 攻擊者ㄍㄨㄥ ㄐㄧ ㄓㄜˇ gōng jī zhě 完整ㄨㄢˊ ㄓㄥˇ wán zhěng 存取ㄘㄨㄣˊ ㄑㄩˇ cún qǔ 合法政府ㄏㄜˊ ㄈㄚˇ ㄓㄥˋ ㄈㄨˇ hé fǎ zhèng fǔ 帳戶ㄓㄤˋ ㄏㄨˋ zhàng hù 的ㄉㄜ˙ de 權限ㄑㄩㄢˊ ㄒㄧㄢˋ quán xiàn 。。 。
The attacker relays this PIN to the victim through the fake site, and when the victim enters it into their myGovID app, they unknowingly grant the attacker full access to legitimate government accounts.
一個ㄧ ㄍㄜˋ yī gè 關鍵ㄍㄨㄢ ㄐㄧㄢˋ guān jiàn 的ㄉㄜ˙ de 設計ㄕㄜˋ ㄐㄧˋ shè jì 弱點ㄖㄨㄛˋ ㄉㄧㄢˇ ruò diǎn 是ㄕˋ shì myGovIDmyGovID myGovID 應用ㄧㄥ ㄩㄥˋ yīng yòng 程式ㄔㄥˊ ㄕˋ chéng shì ** * ** * 完全ㄨㄢˊ ㄑㄩㄢˊ wán quán 不ㄅㄨˋ bù 顯示ㄒㄧㄢˇ ㄕˋ xiǎn shì 是ㄕˋ shì 哪個ㄋㄚˇ ㄍㄜˋ nǎ gè 機構ㄐㄧ ㄍㄡˋ jī gòu 正在ㄓㄥˋ ㄗㄞˋ zhèng zài 要求ㄧㄠ ㄑㄧㄡˊ yāo qiú 驗證ㄧㄢˋ ㄓㄥˋ yàn zhèng ** * ** * [[ [ 22 2 ]] ] 。。 。
A critical design weakness is that the myGovID app provides **no indication of which organization is requesting authentication** [2].
研究ㄧㄢˊ ㄐㄧㄡ yán jiū 人員ㄖㄣˊ ㄩㄢˊ rén yuán 於ㄩˊ yú 20242024 2024 年ㄋㄧㄢˊ nián 88 8 月ㄩㄝˋ yuè 1919 19 日向ㄖˋ ㄒㄧㄤˋ rì xiàng 澳洲ㄠˋ ㄓㄡ ào zhōu 信號局ㄒㄧㄣˋ ㄏㄠˋ ㄐㄩˊ xìn hào jú (( ( ASDASD ASD )) ) 通報ㄊㄨㄥ ㄅㄠˋ tōng bào 此ㄘˇ cǐ 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng [[ [ 33 3 ]] ] 。。 。
The researchers reported this vulnerability to the Australian Signals Directorate (ASD) on August 19, 2024 [3].
依據業界ㄧ ㄐㄩˋ ㄧㄝˋ ㄐㄧㄝˋ yī jù yè jiè 最佳ㄗㄨㄟˋ ㄐㄧㄚ zuì jiā 實務ㄕˊ ㄨˋ shí wù ,, , 他們ㄊㄚ ㄇㄣ˙ tā men 提出ㄊㄧˊ ㄔㄨ tí chū 9090 90 天ㄊㄧㄢ tiān 的ㄉㄜ˙ de 負責任ㄈㄨˋ ㄗㄜˊ ㄖㄣˋ fù zé rèn 揭露ㄐㄧㄝ ㄌㄨˋ jiē lù 期ㄑㄧ qī ,, , 讓ㄖㄤˋ ràng 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 有ㄧㄡˇ yǒu 時間ㄕˊ ㄐㄧㄢ shí jiān 在ㄗㄞˋ zài 公開ㄍㄨㄥ ㄎㄞ gōng kāi 揭露ㄐㄧㄝ ㄌㄨˋ jiē lù 前開ㄑㄧㄢˊ ㄎㄞ qián kāi 發並ㄈㄚ ㄅㄧㄥˋ fā bìng 實施ㄕˊ ㄕ shí shī 修ㄒㄧㄡ xiū 復ㄈㄨˋ fù 方案ㄈㄤ ㄢˋ fāng àn [[ [ 11 1 ]] ] 。。 。
According to industry best practice, they proposed a 90-day responsible disclosure period to allow the government time to develop and implement a fix before public disclosure [1].
###### ### 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 回應ㄏㄨㄟˊ ㄧㄥ huí yīng :: : 拒絕ㄐㄩˋ ㄐㄩㄝˊ jù jué 修ㄒㄧㄡ xiū 復ㄈㄨˋ fù
### Government's Response: Refusal to Fix
20242024 2024 年ㄋㄧㄢˊ nián 99 9 月ㄩㄝˋ yuè 1818 18 日ㄖˋ rì ,, , 澳洲ㄠˋ ㄓㄡ ào zhōu 稅務局ㄕㄨㄟˋ ㄨˋ ㄐㄩˊ shuì wù jú (( ( ATOATO ATO )) ) 與ㄩˇ yǔ 研究ㄧㄢˊ ㄐㄧㄡ yán jiū 人員會面ㄖㄣˊ ㄩㄢˊ ㄏㄨㄟˋ ㄇㄧㄢˋ rén yuán huì miàn ,, , 並明確ㄅㄧㄥˋ ㄇㄧㄥˊ ㄑㄩㄝˋ bìng míng què 表示ㄅㄧㄠˇ ㄕˋ biǎo shì ** * ** * 「「 「 不ㄅㄨˋ bù 打算ㄉㄚˇ ㄙㄨㄢˋ dǎ suàn 變ㄅㄧㄢˋ biàn 更ㄍㄥˋ gèng 協議ㄒㄧㄝˊ ㄧˋ xié yì 」」 」 ** * ** * [[ [ 33 3 ]] ] 。。 。
On September 18, 2024, the Australian Taxation Office (ATO) met with the researchers and explicitly stated it **"did not intend to change the protocol"** [3].
這ㄓㄜˋ zhè 代表ㄉㄞˋ ㄅㄧㄠˇ dài biǎo 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 拒絕ㄐㄩˋ ㄐㄩㄝˊ jù jué 修補此ㄒㄧㄡ ㄅㄨˇ ㄘˇ xiū bǔ cǐ 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 。。 。
This means the government declined to remediate the vulnerability.
此外ㄘˇ ㄨㄞˋ cǐ wài ,, , ATOATO ATO 將此ㄐㄧㄤ ㄘˇ jiāng cǐ 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 定性ㄉㄧㄥˋ ㄒㄧㄥˋ dìng xìng 為ㄨㄟˋ wèi 「「 「 比較ㄅㄧˇ ㄐㄧㄠˋ bǐ jiào 像是ㄒㄧㄤˋ ㄕˋ xiàng shì 公眾ㄍㄨㄥ ㄓㄨㄥˋ gōng zhòng 認知ㄖㄣˋ ㄓ rèn zhī 問題ㄨㄣˋ ㄊㄧˊ wèn tí 」」 」 而ㄦˊ ér 非ㄈㄟ fēi 需要ㄒㄩ ㄧㄠˋ xū yào 變ㄅㄧㄢˋ biàn 更ㄍㄥˋ gèng 協議ㄒㄧㄝˊ ㄧˋ xié yì 的ㄉㄜ˙ de 技術ㄐㄧˋ ㄕㄨˋ jì shù 缺陷ㄑㄩㄝ ㄒㄧㄢˋ quē xiàn [[ [ 33 3 ]] ] 。。 。
Additionally, the ATO characterized the vulnerability as "more of a public awareness issue" rather than a technical flaw requiring protocol changes [3].
ATOATO ATO 還發表聲ㄏㄞˊ ㄈㄚ ㄅㄧㄠˇ ㄕㄥ hái fā biǎo shēng 明宣稱ㄇㄧㄥˊ ㄒㄩㄢ ㄔㄥ míng xuān chēng myGovIDmyGovID myGovID 「「 「 比ㄅㄧˇ bǐ 任何ㄖㄣˋ ㄏㄜˊ rèn hé 憑證ㄆㄧㄥˊ ㄓㄥˋ píng zhèng 都ㄉㄡ dōu 更ㄍㄥˋ gèng 安全ㄢ ㄑㄩㄢˊ ān quán 」」 」 ,, , 對ㄉㄨㄟˋ duì 研究ㄧㄢˊ ㄐㄧㄡ yán jiū 人員ㄖㄣˊ ㄩㄢˊ rén yuán 的ㄉㄜ˙ de 疑慮ㄧˊ ㄌㄩˋ yí lǜ 不予ㄅㄨˋ ㄩˇ bù yǔ 理會ㄌㄧˇ ㄏㄨㄟˋ lǐ huì [[ [ 44 4 ]] ] 。。 。
The ATO also issued statements claiming myGovID was "more secure than any credential," dismissing researcher concerns [4].
在ㄗㄞˋ zài 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 拒絕ㄐㄩˋ ㄐㄩㄝˊ jù jué 修ㄒㄧㄡ xiū 復ㄈㄨˋ fù 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 後ㄏㄡˋ hòu ,, , 研究ㄧㄢˊ ㄐㄧㄡ yán jiū 人員ㄖㄣˊ ㄩㄢˊ rén yuán 於ㄩˊ yú 20242024 2024 年ㄋㄧㄢˊ nián 99 9 月ㄩㄝˋ yuè 2121 21 日公ㄖˋ ㄍㄨㄥ rì gōng 開ㄎㄞ kāi 揭露ㄐㄧㄝ ㄌㄨˋ jiē lù —— — —— — 在ㄗㄞˋ zài 提出ㄊㄧˊ ㄔㄨ tí chū 負責任ㄈㄨˋ ㄗㄜˊ ㄖㄣˋ fù zé rèn 揭露ㄐㄧㄝ ㄌㄨˋ jiē lù 期ㄑㄧ qī 的ㄉㄜ˙ de 情況ㄑㄧㄥˊ ㄎㄨㄤˋ qíng kuàng 下ㄒㄧㄚˋ xià 仍ㄖㄥˊ réng 發布ㄈㄚ ㄅㄨˋ fā bù 了ㄌㄜ˙ le 他們ㄊㄚ ㄇㄣ˙ tā men 的ㄉㄜ˙ de 發現ㄈㄚ ㄒㄧㄢˋ fā xiàn [[ [ 22 2 ]] ] 。。 。
After the government refused to fix the vulnerability, the researchers went public on September 21, 2024 - publishing their findings despite having proposed a responsible disclosure period [2].
資安ㄗ ㄢ zī ān 研究ㄧㄢˊ ㄐㄧㄡ yán jiū 人員明確ㄖㄣˊ ㄩㄢˊ ㄇㄧㄥˊ ㄑㄩㄝˋ rén yuán míng què 警告ㄐㄧㄥˇ ㄍㄠˋ jǐng gào 大眾ㄉㄚˋ ㄓㄨㄥˋ dà zhòng 在ㄗㄞˋ zài 登入ㄉㄥ ㄖㄨˋ dēng rù 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 修ㄒㄧㄡ xiū 復ㄈㄨˋ fù 前ㄑㄧㄢˊ qián 不要ㄅㄨˊ ㄧㄠˋ bú yào 使用ㄕˇ ㄩㄥˋ shǐ yòng myGovIDmyGovID myGovID [[ [ 11 1 ]] ] 。。 。
The security researchers explicitly warned the public not to use myGovID until the login flaw was fixed [1].
###### ### 監察使ㄐㄧㄢ ㄔㄚˊ ㄕˇ jiān chá shǐ 的ㄉㄜ˙ de 佐證ㄗㄨㄛˇ ㄓㄥˋ zuǒ zhèng
### Supporting Evidence from Ombudsman
20242024 2024 年ㄋㄧㄢˊ nián 88 8 月ㄩㄝˋ yuè ,, , 澳洲ㄠˋ ㄓㄡ ào zhōu 監察使ㄐㄧㄢ ㄔㄚˊ ㄕˇ jiān chá shǐ 發布ㄈㄚ ㄅㄨˋ fā bù 「「 「 確保ㄑㄩㄝˋ ㄅㄠˇ què bǎo myGovmyGov myGov 安全ㄢ ㄑㄩㄢˊ ān quán 」」 」 報告ㄅㄠˋ ㄍㄠˋ bào gào ,, , 指出ㄓˇ ㄔㄨ zhǐ chū myGovmyGov myGov // / myGovIDmyGovID myGovID 系統ㄒㄧˋ ㄊㄨㄥˇ xì tǒng 存在ㄘㄨㄣˊ ㄗㄞˋ cún zài 多項ㄉㄨㄛ ㄒㄧㄤˋ duō xiàng 安全ㄢ ㄑㄩㄢˊ ān quán 缺陷ㄑㄩㄝ ㄒㄧㄢˋ quē xiàn ,, , 包括ㄅㄠ ㄎㄨㄛˋ bāo kuò 不ㄅㄨˋ bù 一致ㄧˊ ㄓˋ yí zhì 的ㄉㄜ˙ de 身分ㄕㄣ ㄈㄣˋ shēn fèn 驗證ㄧㄢˋ ㄓㄥˋ yàn zhèng 標準ㄅㄧㄠ ㄓㄨㄣˇ biāo zhǔn 、、 、 對ㄉㄨㄟˋ duì 未經ㄨㄟˋ ㄐㄧㄥ wèi jīng 授權ㄕㄡˋ ㄑㄩㄢˊ shòu quán 帳戶ㄓㄤˋ ㄏㄨˋ zhàng hù 連結ㄌㄧㄢˊ ㄐㄧㄝˊ lián jié 的ㄉㄜ˙ de 有限ㄧㄡˇ ㄒㄧㄢˋ yǒu xiàn 安全ㄢ ㄑㄩㄢˊ ān quán 管控ㄍㄨㄢˇ ㄎㄨㄥˋ guǎn kòng ,, , 以及ㄧˇ ㄐㄧˊ yǐ jí 詐ㄓㄚˋ zhà 騙者將ㄆㄧㄢˋ ㄓㄜˇ ㄐㄧㄤ piàn zhě jiāng 退休金ㄊㄨㄟˋ ㄒㄧㄡ ㄐㄧㄣ tuì xiū jīn 轉移ㄓㄨㄢˇ ㄧˊ zhuǎn yí 和ㄏㄜˊ hé 提交ㄊㄧˊ ㄐㄧㄠ tí jiāo 虛假ㄒㄩ ㄐㄧㄚˇ xū jiǎ 福利ㄈㄨˊ ㄌㄧˋ fú lì 申請ㄕㄣ ㄑㄧㄥˇ shēn qǐng 的ㄉㄜ˙ de 實例ㄕˊ ㄌㄧˋ shí lì [[ [ 55 5 ]] ] 。。 。
In August 2024, the Australian Ombudsman published the "Keeping myGov Secure" report, which identified multiple security deficiencies in myGov/myGovID systems, including inconsistent proof-of-identity standards, limited security controls for unauthorized account linking, and instances of fraudsters redirecting pension payments and submitting false benefit claims [5].
澳洲ㄠˋ ㄓㄡ ào zhōu 服務部ㄈㄨˊ ㄨˋ ㄅㄨˋ fú wù bù 於ㄩˊ yú 20242024 2024 年ㄋㄧㄢˊ nián 77 7 月底ㄩㄝˋ ㄉㄧˇ yuè dǐ 同意ㄊㄨㄥˊ ㄧˋ tóng yì 這些ㄓㄜˋ ㄒㄧㄝ zhè xiē 建議ㄐㄧㄢˋ ㄧˋ jiàn yì ,, , 但將ㄉㄢˋ ㄐㄧㄤ dàn jiāng 實施ㄕˊ ㄕ shí shī 時間ㄕˊ ㄐㄧㄢ shí jiān 推遲ㄊㄨㄟ ㄔˊ tuī chí 至ㄓˋ zhì 20252025 2025 年初ㄋㄧㄢˊ ㄔㄨ nián chū ,, , 顯示ㄒㄧㄢˇ ㄕˋ xiǎn shì 對ㄉㄨㄟˋ duì 緊急ㄐㄧㄣˇ ㄐㄧˊ jǐn jí 安全ㄢ ㄑㄩㄢˊ ān quán 事項ㄕˋ ㄒㄧㄤˋ shì xiàng 未ㄨㄟˋ wèi 採取ㄘㄞˇ ㄑㄩˇ cǎi qǔ 立即ㄌㄧˋ ㄐㄧˊ lì jí 行動ㄒㄧㄥˊ ㄉㄨㄥˋ xíng dòng [[ [ 55 5 ]] ] 。。 。
Services Australia agreed to these recommendations in late July 2024 but deferred implementation to early 2025, indicating no immediate action was taken on urgent security matters [5].

缺失的脈絡

###### ### 11 1 .. . 「「 「 客ㄎㄜˋ kè 製ㄓˋ zhì 化ㄏㄨㄚˋ huà 」」 」 驗證ㄧㄢˋ ㄓㄥˋ yàn zhèng 協議ㄒㄧㄝˊ ㄧˋ xié yì 的ㄉㄜ˙ de 說ㄕㄨㄛ shuō 法正確ㄈㄚˇ ㄓㄥˋ ㄑㄩㄝˋ fǎ zhèng què
### 1. The "Bespoke" Authentication Protocol is Accurate
該主張ㄍㄞ ㄓㄨˇ ㄓㄤ gāi zhǔ zhāng 準確ㄓㄨㄣˇ ㄑㄩㄝˋ zhǔn què 地將ㄉㄧˋ ㄐㄧㄤ dì jiāng myGovIDmyGovID myGovID 的ㄉㄜ˙ de 驗證ㄧㄢˋ ㄓㄥˋ yàn zhèng 協議ㄒㄧㄝˊ ㄧˋ xié yì 描述ㄇㄧㄠˊ ㄕㄨˋ miáo shù 為ㄨㄟˋ wèi 非ㄈㄟ fēi 標準ㄅㄧㄠ ㄓㄨㄣˇ biāo zhǔn 協議ㄒㄧㄝˊ ㄧˋ xié yì 。。 。
The claim accurately characterizes myGovID's authentication protocol as non-standard. myGovID uses the **Trusted Digital Identity Framework (TDIF)**, which is a proprietary, bespoke system specific to Australia - not OpenID Connect, OAuth 2.0, or other internationally recognized standards [6].
myGovIDmyGovID myGovID 使用ㄕˇ ㄩㄥˋ shǐ yòng ** * ** * 可信ㄎㄜˇ ㄒㄧㄣˋ kě xìn 數位ㄕㄨˋ ㄨㄟˋ shù wèi 身分ㄕㄣ ㄈㄣˋ shēn fèn 框架ㄎㄨㄤ ㄐㄧㄚˋ kuāng jià (( ( TDIFTDIF TDIF )) ) ** * ** * ,, , 這是ㄓㄜˋ ㄕˋ zhè shì 澳洲ㄠˋ ㄓㄡ ào zhōu 專屬ㄓㄨㄢ ㄕㄨˇ zhuān shǔ 的ㄉㄜ˙ de 客ㄎㄜˋ kè 製ㄓˋ zhì 化ㄏㄨㄚˋ huà 系ㄒㄧˋ xì 統ㄊㄨㄥˇ tǒng —— — —— — 而ㄦˊ ér 非ㄈㄟ fēi OpenIDOpenID OpenID ConnectConnect Connect 、、 、 OAuthOAuth OAuth 2.02.0 2.0 或ㄏㄨㄛˋ huò 其他ㄑㄧˊ ㄊㄚ qí tā 國際認ㄍㄨㄛˊ ㄐㄧˋ ㄖㄣˋ guó jì rèn 可ㄎㄜˇ kě 的ㄉㄜ˙ de 標準ㄅㄧㄠ ㄓㄨㄣˇ biāo zhǔn [[ [ 66 6 ]] ] 。。 。
Security researchers have recommended that the TDIF framework be deprecated and replaced with standard protocols like OpenID Connect [2].
資安ㄗ ㄢ zī ān 研究ㄧㄢˊ ㄐㄧㄡ yán jiū 人員建議ㄖㄣˊ ㄩㄢˊ ㄐㄧㄢˋ ㄧˋ rén yuán jiàn yì 應ㄧㄥ yīng 廢除ㄈㄟˋ ㄔㄨˊ fèi chú TDIFTDIF TDIF 框架ㄎㄨㄤ ㄐㄧㄚˋ kuāng jià ,, , 改採ㄍㄞˇ ㄘㄞˇ gǎi cǎi OpenIDOpenID OpenID ConnectConnect Connect 等ㄉㄥˇ děng 標準ㄅㄧㄠ ㄓㄨㄣˇ biāo zhǔn 協議ㄒㄧㄝˊ ㄧˋ xié yì [[ [ 22 2 ]] ] 。。 。
### 2. Protocol Design vs. Implementation Issues
###### ### 22 2 .. . 協議ㄒㄧㄝˊ ㄧˋ xié yì 設計ㄕㄜˋ ㄐㄧˋ shè jì 與ㄩˇ yǔ 實作ㄕˊ ㄗㄨㄛˋ shí zuò 問題ㄨㄣˋ ㄊㄧˊ wèn tí 的ㄉㄜ˙ de 區別ㄑㄩ ㄅㄧㄝˊ qū bié
While the vulnerability exists, there is a technical distinction worth noting: the fundamental flaw appears to stem from the protocol's design (the lack of context about who is requesting authentication in the myGovID app), not necessarily implementation errors.
雖然ㄙㄨㄟ ㄖㄢˊ suī rán 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 確實ㄑㄩㄝˋ ㄕˊ què shí 存在ㄘㄨㄣˊ ㄗㄞˋ cún zài ,, , 但ㄉㄢˋ dàn 有ㄧㄡˇ yǒu 一個ㄧ ㄍㄜˋ yī gè 技術區ㄐㄧˋ ㄕㄨˋ ㄑㄩ jì shù qū 別ㄅㄧㄝˊ bié 值得注意ㄓˊ ㄉㄜ˙ ㄓㄨˋ ㄧˋ zhí de zhù yì :: : 基本ㄐㄧ ㄅㄣˇ jī běn 缺陷ㄑㄩㄝ ㄒㄧㄢˋ quē xiàn 似乎ㄙˋ ㄏㄨ sì hū 源自ㄩㄢˊ ㄗˋ yuán zì 協議ㄒㄧㄝˊ ㄧˋ xié yì 設計ㄕㄜˋ ㄐㄧˋ shè jì (( ( myGovIDmyGovID myGovID 應用ㄧㄥ ㄩㄥˋ yīng yòng 程式ㄔㄥˊ ㄕˋ chéng shì 缺乏ㄑㄩㄝ ㄈㄚˊ quē fá 關於ㄍㄨㄢ ㄩˊ guān yú 誰ㄕㄨㄟˊ shuí 正在ㄓㄥˋ ㄗㄞˋ zhèng zài 要求ㄧㄠ ㄑㄧㄡˊ yāo qiú 驗證ㄧㄢˋ ㄓㄥˋ yàn zhèng 的ㄉㄜ˙ de 上下文ㄕㄤˋ ㄒㄧㄚˋ ㄨㄣˊ shàng xià wén 資訊ㄗ ㄒㄩㄣˋ zī xùn )) ) ,, , 而ㄦˊ ér 不ㄅㄨˋ bù 一定ㄧˊ ㄉㄧㄥˋ yí dìng 是ㄕˋ shì 實作ㄕˊ ㄗㄨㄛˋ shí zuò 錯誤ㄘㄨㄛˋ ㄨˋ cuò wù 。。 。
However, this distinction does not diminish the validity of the claim - a flawed protocol design is still a flaw that requires fixing.
然而ㄖㄢˊ ㄦˊ rán ér ,, , 這個ㄓㄜˋ ㄍㄜˋ zhè gè 區別ㄑㄩ ㄅㄧㄝˊ qū bié 並不減ㄅㄧㄥˋ ㄅㄨˋ ㄐㄧㄢˇ bìng bù jiǎn 損該ㄙㄨㄣˇ ㄍㄞ sǔn gāi 主張ㄓㄨˇ ㄓㄤ zhǔ zhāng 的ㄉㄜ˙ de 有效性ㄧㄡˇ ㄒㄧㄠˋ ㄒㄧㄥˋ yǒu xiào xìng —— — —— — 有ㄧㄡˇ yǒu 缺陷ㄑㄩㄝ ㄒㄧㄢˋ quē xiàn 的ㄉㄜ˙ de 協議ㄒㄧㄝˊ ㄧˋ xié yì 設計ㄕㄜˋ ㄐㄧˋ shè jì 仍然ㄖㄥˊ ㄖㄢˊ réng rán 是ㄕˋ shì 缺陷ㄑㄩㄝ ㄒㄧㄢˋ quē xiàn ,, , 需要ㄒㄩ ㄧㄠˋ xū yào 修ㄒㄧㄡ xiū 復ㄈㄨˋ fù 。。 。
### 3. Timeline and Context
###### ### 33 3 .. . 時間軸ㄕˊ ㄐㄧㄢ ㄓㄡˊ shí jiān zhóu 與ㄩˇ yǔ 背景ㄅㄟˋ ㄐㄧㄥˇ bèi jǐng
The vulnerability discovery occurred late in the Coalition government's tenure.
漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 發現ㄈㄚ ㄒㄧㄢˋ fā xiàn 時機ㄕˊ ㄐㄧ shí jī 接近ㄐㄧㄝ ㄐㄧㄣˋ jiē jìn CoalitionCoalition Coalition 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 任期ㄖㄣˋ ㄑㄧ rèn qī 尾聲ㄨㄟˇ ㄕㄥ wěi shēng 。。 。
The Coalition was voted out of office in May 2022.
CoalitionCoalition Coalition 於ㄩˊ yú 20222022 2022 年ㄋㄧㄢˊ nián 55 5 月ㄩㄝˋ yuè 卸任ㄒㄧㄝˋ ㄖㄣˋ xiè rèn 。。 。
The vulnerability was discovered in August 2024 by the Albanese Labor government.
漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 於ㄩˊ yú 20242024 2024 年ㄋㄧㄢˊ nián 88 8 月ㄩㄝˋ yuè 由ㄧㄡˊ yóu AlbaneseAlbanese Albanese 領導ㄌㄧㄥˇ ㄉㄠˇ lǐng dǎo 的ㄉㄜ˙ de LaborLabor Labor 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 時期ㄕˊ ㄑㄧ shí qī 發現ㄈㄚ ㄒㄧㄢˋ fā xiàn 。。 。
This means: - The Coalition government (2013-2022) would not have made the September 2024 decision to refuse remediation - The current (Labor) government inherited myGovID and made the decision not to change the protocol [3] However, the claim may be referring to the Coalition government's original decision to develop and deploy myGovID using a bespoke, non-standard protocol rather than established industry standards - which would have been a decision made during the Coalition's time in office (2013-2022).
這ㄓㄜˋ zhè 意味著ㄧˋ ㄨㄟˋ ㄓㄨˋ yì wèi zhù :: :
-- - CoalitionCoalition Coalition 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ (( ( 20132013 2013 -- - 20222022 2022 )) ) 不ㄅㄨˋ bù 可能ㄎㄜˇ ㄋㄥˊ kě néng 做出ㄗㄨㄛˋ ㄔㄨ zuò chū 20242024 2024 年ㄋㄧㄢˊ nián 99 9 月ㄩㄝˋ yuè 拒絕ㄐㄩˋ ㄐㄩㄝˊ jù jué 修ㄒㄧㄡ xiū 復ㄈㄨˋ fù 的ㄉㄜ˙ de 決定ㄐㄩㄝˊ ㄉㄧㄥˋ jué dìng
-- - 現任ㄒㄧㄢˋ ㄖㄣˋ xiàn rèn (( ( LaborLabor Labor )) ) 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 繼承ㄐㄧˋ ㄔㄥˊ jì chéng 了ㄌㄜ˙ le myGovIDmyGovID myGovID ,, , 並ㄅㄧㄥˋ bìng 做出ㄗㄨㄛˋ ㄔㄨ zuò chū 不變ㄅㄨˋ ㄅㄧㄢˋ bù biàn 更ㄍㄥˋ gèng 協議ㄒㄧㄝˊ ㄧˋ xié yì 的ㄉㄜ˙ de 決定ㄐㄩㄝˊ ㄉㄧㄥˋ jué dìng [[ [ 33 3 ]] ]
然而ㄖㄢˊ ㄦˊ rán ér ,, , 該主張ㄍㄞ ㄓㄨˇ ㄓㄤ gāi zhǔ zhāng 可能ㄎㄜˇ ㄋㄥˊ kě néng 是ㄕˋ shì 指ㄓˇ zhǐ CoalitionCoalition Coalition 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 最初ㄗㄨㄟˋ ㄔㄨ zuì chū 決定ㄐㄩㄝˊ ㄉㄧㄥˋ jué dìng 使用ㄕˇ ㄩㄥˋ shǐ yòng 客ㄎㄜˋ kè 製ㄓˋ zhì 化ㄏㄨㄚˋ huà 、、 、 非標ㄈㄟ ㄅㄧㄠ fēi biāo 準協議ㄓㄨㄣˇ ㄒㄧㄝˊ ㄧˋ zhǔn xié yì 而ㄦˊ ér 非業界ㄈㄟ ㄧㄝˋ ㄐㄧㄝˋ fēi yè jiè 既定ㄐㄧˋ ㄉㄧㄥˋ jì dìng 標準ㄅㄧㄠ ㄓㄨㄣˇ biāo zhǔn 來ㄌㄞˊ lái 開發ㄎㄞ ㄈㄚ kāi fā 和ㄏㄜˊ hé 部署ㄅㄨˋ ㄕㄨˇ bù shǔ myGovIDmyGovID myGovID —— — —— — 這應ㄓㄜˋ ㄧㄥ zhè yīng 是ㄕˋ shì CoalitionCoalition Coalition 執政期ㄓˊ ㄓㄥˋ ㄑㄧ zhí zhèng qī 間ㄐㄧㄢ jiān (( ( 20132013 2013 -- - 20222022 2022 )) ) 所ㄙㄨㄛˇ suǒ 做ㄗㄨㄛˋ zuò 的ㄉㄜ˙ de 決定ㄐㄩㄝˊ ㄉㄧㄥˋ jué dìng 。。 。

來源可信度評估

###### ### 原始ㄩㄢˊ ㄕˇ yuán shǐ 來源ㄌㄞˊ ㄩㄢˊ lái yuán :: : ThinkingThinking Thinking CybersecurityCybersecurity Cybersecurity
### Original Source: Thinking Cybersecurity
提供ㄊㄧˊ ㄍㄨㄥ tí gōng 的ㄉㄜ˙ de 原始ㄩㄢˊ ㄕˇ yuán shǐ 來源ㄌㄞˊ ㄩㄢˊ lái yuán (( ( ThinkingThinking Thinking CybersecurityCybersecurity Cybersecurity )) ) 是ㄕˋ shì 由ㄧㄡˊ yóu VanessaVanessa Vanessa TeagueTeague Teague 領導ㄌㄧㄥˇ ㄉㄠˇ lǐng dǎo 的ㄉㄜ˙ de 機構ㄐㄧ ㄍㄡˋ jī gòu ,, , 她ㄊㄚ tā 是ㄕˋ shì 發現ㄈㄚ ㄒㄧㄢˋ fā xiàn 該ㄍㄞ gāi 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 的ㄉㄜ˙ de 研究ㄧㄢˊ ㄐㄧㄡ yán jiū 人員ㄖㄣˊ ㄩㄢˊ rén yuán 之一ㄓ ㄧ zhī yī 。。 。
The original source provided (Thinking Cybersecurity) is an organization led by Vanessa Teague, one of the researchers who discovered the vulnerability.
這創造ㄓㄜˋ ㄔㄨㄤˋ ㄗㄠˋ zhè chuàng zào 了關ㄌㄜ˙ ㄍㄨㄢ le guān 於ㄩˊ yú 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 本身ㄅㄣˇ ㄕㄣ běn shēn 的ㄉㄜ˙ de 直接ㄓˊ ㄐㄧㄝ zhí jiē 來源ㄌㄞˊ ㄩㄢˊ lái yuán 。。 。
This creates a direct source on the vulnerability itself.
VanessaVanessa Vanessa TeagueTeague Teague 具備ㄐㄩˋ ㄅㄟˋ jù bèi :: :
Vanessa Teague is: - An ANU adjunct professor and security researcher - A credible academic voice in cybersecurity - Has published peer-reviewed work on electoral security and digital systems [7] However, as one of the researchers reporting on their own finding, there is inherent bias in favor of emphasizing the vulnerability's severity.
-- - 澳洲ㄠˋ ㄓㄡ ào zhōu 國立ㄍㄨㄛˊ ㄌㄧˋ guó lì 大學ㄉㄚˋ ㄒㄩㄝˊ dà xué 兼任ㄐㄧㄢ ㄖㄣˋ jiān rèn 教授ㄐㄧㄠˋ ㄕㄡˋ jiào shòu 及ㄐㄧˊ jí 資安ㄗ ㄢ zī ān 研究ㄧㄢˊ ㄐㄧㄡ yán jiū 人員ㄖㄣˊ ㄩㄢˊ rén yuán 身份ㄕㄣ ㄈㄣˋ shēn fèn
### Primary Sources on This Issue
-- - 網路ㄨㄤˇ ㄌㄨˋ wǎng lù 安全ㄢ ㄑㄩㄢˊ ān quán 領域ㄌㄧㄥˇ ㄩˋ lǐng yù 可信ㄎㄜˇ ㄒㄧㄣˋ kě xìn 賴的ㄌㄞˋ ㄉㄜ˙ lài de 學術ㄒㄩㄝˊ ㄕㄨˋ xué shù 聲音ㄕㄥ ㄧㄣ shēng yīn
The most reliable sources are: - **Technology news outlets** (iTnews, InnovationAus): Mainstream Australian tech journalism covering the vulnerability discovery and government response [1][3] - **Government sources** (Ombudsman report, ATO statements): Official documentation of security concerns and government positions [4][5] - **Security research** (Thinking Cybersecurity, researchers' technical documentation): Academic and professional security analysis [2] The claim is well-supported by mainstream technology journalism and government reports, not primarily dependent on a single partisan source.
-- - 曾ㄘㄥˊ céng 發表關ㄈㄚ ㄅㄧㄠˇ ㄍㄨㄢ fā biǎo guān 於ㄩˊ yú 選舉ㄒㄩㄢˇ ㄐㄩˇ xuǎn jǔ 安全ㄢ ㄑㄩㄢˊ ān quán 與ㄩˇ yǔ 數位ㄕㄨˋ ㄨㄟˋ shù wèi 系統ㄒㄧˋ ㄊㄨㄥˇ xì tǒng 的ㄉㄜ˙ de 同儕ㄊㄨㄥˊ ㄔㄞˊ tóng chái 審查ㄕㄣˇ ㄔㄚˊ shěn chá 研究ㄧㄢˊ ㄐㄧㄡ yán jiū [[ [ 77 7 ]] ]
然而ㄖㄢˊ ㄦˊ rán ér ,, , 作為ㄗㄨㄛˋ ㄨㄟˋ zuò wèi 報告ㄅㄠˋ ㄍㄠˋ bào gào 自身ㄗˋ ㄕㄣ zì shēn 發現ㄈㄚ ㄒㄧㄢˋ fā xiàn 的ㄉㄜ˙ de 研究ㄧㄢˊ ㄐㄧㄡ yán jiū 人員ㄖㄣˊ ㄩㄢˊ rén yuán 之一ㄓ ㄧ zhī yī ,, , 存在ㄘㄨㄣˊ ㄗㄞˋ cún zài 強調ㄑㄧㄤˊ ㄉㄧㄠˋ qiáng diào 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 嚴重性ㄧㄢˊ ㄓㄨㄥˋ ㄒㄧㄥˋ yán zhòng xìng 的ㄉㄜ˙ de 固有ㄍㄨˋ ㄧㄡˇ gù yǒu 偏見ㄆㄧㄢ ㄐㄧㄢˋ piān jiàn 。。 。
###### ### 此議題ㄘˇ ㄧˋ ㄊㄧˊ cǐ yì tí 的ㄉㄜ˙ de 主要ㄓㄨˇ ㄧㄠˋ zhǔ yào 來源ㄌㄞˊ ㄩㄢˊ lái yuán
最ㄗㄨㄟˋ zuì 可靠ㄎㄜˇ ㄎㄠˋ kě kào 的ㄉㄜ˙ de 來源ㄌㄞˊ ㄩㄢˊ lái yuán 包括ㄅㄠ ㄎㄨㄛˋ bāo kuò :: :
-- - ** * ** * 科技ㄎㄜ ㄐㄧˋ kē jì 新聞ㄒㄧㄣ ㄨㄣˊ xīn wén 媒體ㄇㄟˊ ㄊㄧˇ méi tǐ ** * ** * (( ( iTnewsiTnews iTnews 、、 、 InnovationAusInnovationAus InnovationAus )) ) :: : 報導ㄅㄠˋ ㄉㄠˇ bào dǎo 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 發現ㄈㄚ ㄒㄧㄢˋ fā xiàn 與ㄩˇ yǔ 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 回應ㄏㄨㄟˊ ㄧㄥ huí yīng 的ㄉㄜ˙ de 澳洲ㄠˋ ㄓㄡ ào zhōu 主流ㄓㄨˇ ㄌㄧㄡˊ zhǔ liú 科技ㄎㄜ ㄐㄧˋ kē jì 新聞ㄒㄧㄣ ㄨㄣˊ xīn wén [[ [ 11 1 ]] ] [[ [ 33 3 ]] ]
-- - ** * ** * 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 來源ㄌㄞˊ ㄩㄢˊ lái yuán ** * ** * (( ( 監察使ㄐㄧㄢ ㄔㄚˊ ㄕˇ jiān chá shǐ 報告ㄅㄠˋ ㄍㄠˋ bào gào 、、 、 ATOATO ATO 聲明ㄕㄥ ㄇㄧㄥˊ shēng míng )) ) :: : 安全ㄢ ㄑㄩㄢˊ ān quán 疑慮ㄧˊ ㄌㄩˋ yí lǜ 與ㄩˇ yǔ 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 立場ㄌㄧˋ ㄔㄤˇ lì chǎng 的ㄉㄜ˙ de 官方ㄍㄨㄢ ㄈㄤ guān fāng 文件ㄨㄣˊ ㄐㄧㄢˋ wén jiàn [[ [ 44 4 ]] ] [[ [ 55 5 ]] ]
-- - ** * ** * 資安ㄗ ㄢ zī ān 研究ㄧㄢˊ ㄐㄧㄡ yán jiū ** * ** * (( ( ThinkingThinking Thinking CybersecurityCybersecurity Cybersecurity 、、 、 研究ㄧㄢˊ ㄐㄧㄡ yán jiū 人員技術ㄖㄣˊ ㄩㄢˊ ㄐㄧˋ ㄕㄨˋ rén yuán jì shù 文件ㄨㄣˊ ㄐㄧㄢˋ wén jiàn )) ) :: : 學術ㄒㄩㄝˊ ㄕㄨˋ xué shù 與ㄩˇ yǔ 專業ㄓㄨㄢ ㄧㄝˋ zhuān yè 資安ㄗ ㄢ zī ān 分析ㄈㄣ ㄒㄧ fēn xī [[ [ 22 2 ]] ]
該主張ㄍㄞ ㄓㄨˇ ㄓㄤ gāi zhǔ zhāng 獲得ㄏㄨㄛˋ ㄉㄜˊ huò dé 主流ㄓㄨˇ ㄌㄧㄡˊ zhǔ liú 科技ㄎㄜ ㄐㄧˋ kē jì 新聞ㄒㄧㄣ ㄨㄣˊ xīn wén 與ㄩˇ yǔ 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 報告ㄅㄠˋ ㄍㄠˋ bào gào 的ㄉㄜ˙ de 充分ㄔㄨㄥ ㄈㄣˋ chōng fèn 支持ㄓ ㄔˊ zhī chí ,, , 而ㄦˊ ér 非ㄈㄟ fēi 主要ㄓㄨˇ ㄧㄠˋ zhǔ yào 依賴ㄧ ㄌㄞˋ yī lài 單一黨ㄉㄢ ㄧ ㄉㄤˇ dān yī dǎng 派ㄆㄞˋ pài 來源ㄌㄞˊ ㄩㄢˊ lái yuán 。。 。
⚖️

Labor 比較

###### ### LaborLabor Labor 是否ㄕˋ ㄈㄡˇ shì fǒu 採用類ㄘㄞˇ ㄩㄥˋ ㄌㄟˋ cǎi yòng lèi 似的ㄕˋ ㄉㄜ˙ shì de 客ㄎㄜˋ kè 製ㄓˋ zhì 化ㄏㄨㄚˋ huà 驗ㄧㄢˋ yàn 證ㄓㄥˋ zhèng 方式ㄈㄤ ㄕˋ fāng shì ?? ?
### Did Labor Adopt Similar Bespoke Authentication Approaches?
LaborLabor Labor 在ㄗㄞˋ zài myGovIDmyGovID myGovID 開發時ㄎㄞ ㄈㄚ ㄕˊ kāi fā shí 並未ㄅㄧㄥˋ ㄨㄟˋ bìng wèi 執政ㄓˊ ㄓㄥˋ zhí zhèng (( ( CoalitionCoalition Coalition 執政ㄓˊ ㄓㄥˋ zhí zhèng 於ㄩˊ yú 20132013 2013 -- - 20222022 2022 )) ) 。。 。
Labor was not in government when myGovID was developed (Coalition governed 2013-2022).
LaborLabor Labor 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 於ㄩˊ yú 20222022 2022 年ㄋㄧㄢˊ nián 55 5 月ㄩㄝˋ yuè 上任ㄕㄤˋ ㄖㄣˋ shàng rèn 時繼承ㄕˊ ㄐㄧˋ ㄔㄥˊ shí jì chéng 了ㄌㄜ˙ le myGovIDmyGovID myGovID 系統ㄒㄧˋ ㄊㄨㄥˇ xì tǒng 。。 。
The Labor government inherited the myGovID system when they took office in May 2022. **However**, the more relevant comparison is: **How did Labor respond to the discovered vulnerability?** As noted above, the decision to "not intend to change the protocol" in September 2024 was made by the **Labor government's ATO**, not the Coalition.
** * ** * 然而ㄖㄢˊ ㄦˊ rán ér ** * ** * ,, , 更具ㄍㄥˋ ㄐㄩˋ gèng jù 相關性ㄒㄧㄤ ㄍㄨㄢ ㄒㄧㄥˋ xiāng guān xìng 的ㄉㄜ˙ de 比ㄅㄧˇ bǐ 較ㄐㄧㄠˋ jiào 是ㄕˋ shì :: : ** * ** * LaborLabor Labor 如何ㄖㄨˊ ㄏㄜˊ rú hé 回應ㄏㄨㄟˊ ㄧㄥ huí yīng 已ㄧˇ yǐ 發現ㄈㄚ ㄒㄧㄢˋ fā xiàn 的ㄉㄜ˙ de 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng ?? ?
This indicates both governments (Coalition for original development, Labor for response to the discovered vulnerability) made questionable cybersecurity decisions regarding myGovID.
** * ** *
### Labor's Approach to Digital Identity
如上所述ㄖㄨˊ ㄕㄤˋ ㄙㄨㄛˇ ㄕㄨˋ rú shàng suǒ shù ,, , 20242024 2024 年ㄋㄧㄢˊ nián 99 9 月ㄩㄝˋ yuè 「「 「 不ㄅㄨˋ bù 打算ㄉㄚˇ ㄙㄨㄢˋ dǎ suàn 變ㄅㄧㄢˋ biàn 更ㄍㄥˋ gèng 協議ㄒㄧㄝˊ ㄧˋ xié yì 」」 」 的ㄉㄜ˙ de 決定ㄐㄩㄝˊ ㄉㄧㄥˋ jué dìng 是ㄕˋ shì 由ㄧㄡˊ yóu ** * ** * LaborLabor Labor 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 的ㄉㄜ˙ de ATOATO ATO ** * ** * 做出ㄗㄨㄛˋ ㄔㄨ zuò chū ,, , 而ㄦˊ ér 非ㄈㄟ fēi CoalitionCoalition Coalition 。。 。
Labor has pursued continued development of myGovID (rebranded as "myID" in November 2024) under a digital identity scheme.
這顯示ㄓㄜˋ ㄒㄧㄢˇ ㄕˋ zhè xiǎn shì 兩個ㄌㄧㄤˇ ㄍㄜˋ liǎng gè 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ (( ( CoalitionCoalition Coalition 負責ㄈㄨˋ ㄗㄜˊ fù zé 最初ㄗㄨㄟˋ ㄔㄨ zuì chū 開發ㄎㄞ ㄈㄚ kāi fā ,, , LaborLabor Labor 負責ㄈㄨˋ ㄗㄜˊ fù zé 對ㄉㄨㄟˋ duì 已ㄧˇ yǐ 發現ㄈㄚ ㄒㄧㄢˋ fā xiàn 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 的ㄉㄜ˙ de 回應ㄏㄨㄟˊ ㄧㄥ huí yīng )) ) 在ㄗㄞˋ zài myGovIDmyGovID myGovID 的ㄉㄜ˙ de 資安ㄗ ㄢ zī ān 決策ㄐㄩㄝˊ ㄘㄜˋ jué cè 上ㄕㄤˋ shàng 都ㄉㄡ dōu 有ㄧㄡˇ yǒu 可議ㄎㄜˇ ㄧˋ kě yì 之處ㄓ ㄔㄨˋ zhī chù 。。 。
Labor has not abandoned the bespoke TDIF framework but instead continued operating within it [8].
###### ### LaborLabor Labor 的ㄉㄜ˙ de 數位ㄕㄨˋ ㄨㄟˋ shù wèi 身分ㄕㄣ ㄈㄣˋ shēn fèn 政策ㄓㄥˋ ㄘㄜˋ zhèng cè 方針ㄈㄤ ㄓㄣ fāng zhēn
This suggests Labor may bear some responsibility for not addressing the architectural vulnerability once it was discovered under their watch.
LaborLabor Labor 持續ㄔˊ ㄒㄩˋ chí xù 推動ㄊㄨㄟ ㄉㄨㄥˋ tuī dòng myGovIDmyGovID myGovID 的ㄉㄜ˙ de 開發ㄎㄞ ㄈㄚ kāi fā (( ( 於ㄩˊ yú 20242024 2024 年ㄋㄧㄢˊ nián 1111 11 月ㄩㄝˋ yuè 重新命名ㄔㄨㄥˊ ㄒㄧㄣ ㄇㄧㄥˋ ㄇㄧㄥˊ chóng xīn mìng míng 為ㄨㄟˋ wèi 「「 「 myIDmyID myID 」」 」 )) ) ,, , 納入ㄋㄚˋ ㄖㄨˋ nà rù 數位ㄕㄨˋ ㄨㄟˋ shù wèi 身分ㄕㄣ ㄈㄣˋ shēn fèn 計畫ㄐㄧˋ ㄏㄨㄚˋ jì huà 。。 。
LaborLabor Labor 並未放棄ㄅㄧㄥˋ ㄨㄟˋ ㄈㄤˋ ㄑㄧˋ bìng wèi fàng qì 客ㄎㄜˋ kè 製ㄓˋ zhì 化ㄏㄨㄚˋ huà 的ㄉㄜ˙ de TDIFTDIF TDIF 框架ㄎㄨㄤ ㄐㄧㄚˋ kuāng jià ,, , 而是ㄦˊ ㄕˋ ér shì 繼續ㄐㄧˋ ㄒㄩˋ jì xù 在ㄗㄞˋ zài 該ㄍㄞ gāi 框架ㄎㄨㄤ ㄐㄧㄚˋ kuāng jià 內運作ㄋㄟˋ ㄩㄣˋ ㄗㄨㄛˋ nèi yùn zuò [[ [ 88 8 ]] ] 。。 。
這顯示ㄓㄜˋ ㄒㄧㄢˇ ㄕˋ zhè xiǎn shì LaborLabor Labor 在ㄗㄞˋ zài 發現ㄈㄚ ㄒㄧㄢˋ fā xiàn 架構ㄐㄧㄚˋ ㄍㄡˋ jià gòu 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 後ㄏㄡˋ hòu 可能ㄎㄜˇ ㄋㄥˊ kě néng 也ㄧㄝˇ yě 負有ㄈㄨˋ ㄧㄡˇ fù yǒu 未ㄨㄟˋ wèi 處理ㄔㄨˋ ㄌㄧˇ chù lǐ 的ㄉㄜ˙ de 責任ㄗㄜˊ ㄖㄣˋ zé rèn 。。 。
🌐

平衡觀點

###### ### CoalitionCoalition Coalition 的ㄉㄜ˙ de 設計ㄕㄜˋ ㄐㄧˋ shè jì 決定ㄐㄩㄝˊ ㄉㄧㄥˋ jué dìng (( ( 20132013 2013 -- - 20222022 2022 )) )
### The Coalition's Design Decision (2013-2022)
當ㄉㄤ dāng CoalitionCoalition Coalition 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 決定ㄐㄩㄝˊ ㄉㄧㄥˋ jué dìng 使用ㄕˇ ㄩㄥˋ shǐ yòng 專屬ㄓㄨㄢ ㄕㄨˇ zhuān shǔ 客ㄎㄜˋ kè 製ㄓˋ zhì 化ㄏㄨㄚˋ huà 驗ㄧㄢˋ yàn 證ㄓㄥˋ zhèng 協ㄒㄧㄝˊ xié 議ㄧˋ yì (( ( TDIFTDIF TDIF )) ) 而ㄦˊ ér 非ㄈㄟ fēi 採用ㄘㄞˇ ㄩㄥˋ cǎi yòng OpenIDOpenID OpenID ConnectConnect Connect 等ㄉㄥˇ děng 國際ㄍㄨㄛˊ ㄐㄧˋ guó jì 標準ㄅㄧㄠ ㄓㄨㄣˇ biāo zhǔn 協議ㄒㄧㄝˊ ㄧˋ xié yì 來ㄌㄞˊ lái 開發ㄎㄞ ㄈㄚ kāi fā myGovIDmyGovID myGovID 時ㄕˊ shí ,, , 這ㄓㄜˋ zhè 代表ㄉㄞˋ ㄅㄧㄠˇ dài biǎo 一個ㄧ ㄍㄜˋ yī gè 有ㄧㄡˇ yǒu 疑慮ㄧˊ ㄌㄩˋ yí lǜ 的ㄉㄜ˙ de 架構ㄐㄧㄚˋ ㄍㄡˋ jià gòu 決定ㄐㄩㄝˊ ㄉㄧㄥˋ jué dìng 。。 。
When the Coalition government decided to develop myGovID using a proprietary, bespoke authentication protocol (TDIF) rather than adopting internationally standard protocols like OpenID Connect, this represented a questionable architectural decision.
選擇ㄒㄩㄢˇ ㄗㄜˊ xuǎn zé 此ㄘˇ cǐ 方案ㄈㄤ ㄢˋ fāng àn 的ㄉㄜ˙ de 可能ㄎㄜˇ ㄋㄥˊ kě néng 原因ㄩㄢˊ ㄧㄣ yuán yīn 包括ㄅㄠ ㄎㄨㄛˋ bāo kuò :: :
The reasons for this choice were likely: - Desire for a uniquely Australian solution tailored to specific government needs - Potential national sovereignty concerns (not relying on international standards) - Perceived control over the system's security and operations However, security experts argue that bespoke authentication systems are inherently riskier because they: - Have limited external security review compared to widely-used standards - Don't benefit from years of community vulnerability discovery and patching - Increase the chance of design flaws like the one discovered in 2024 [2] **Standard security practice is to use proven, widely-audited protocols unless there is a compelling reason not to.**
-- - 希望ㄒㄧ ㄨㄤˋ xī wàng 打造ㄉㄚˇ ㄗㄠˋ dǎ zào 獨特ㄉㄨˊ ㄊㄜˋ dú tè 符合ㄈㄨˊ ㄏㄜˊ fú hé 澳洲ㄠˋ ㄓㄡ ào zhōu 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 特定ㄊㄜˋ ㄉㄧㄥˋ tè dìng 需求ㄒㄩ ㄑㄧㄡˊ xū qiú 的ㄉㄜ˙ de 解決ㄐㄧㄝˇ ㄐㄩㄝˊ jiě jué 方案ㄈㄤ ㄢˋ fāng àn
### The Government's Response to the Discovered Vulnerability
-- - 潛在ㄑㄧㄢˊ ㄗㄞˋ qián zài 的國ㄉㄜ˙ ㄍㄨㄛˊ de guó 家主ㄐㄧㄚ ㄓㄨˇ jiā zhǔ 權ㄑㄩㄢˊ quán 考量ㄎㄠˇ ㄌㄧㄤˊ kǎo liáng (( ( 不依ㄅㄨˋ ㄧ bù yī 賴國際ㄌㄞˋ ㄍㄨㄛˊ ㄐㄧˋ lài guó jì 標準ㄅㄧㄠ ㄓㄨㄣˇ biāo zhǔn )) )
More problematic than the original design choice was the response when the vulnerability was discovered: **During Coalition government (2013-2022):** - The Coalition would have deployed and operated myGovID but the vulnerability wasn't discovered until 2024 (after their loss of office) **During Labor government (September 2024 onward):** - The ATO explicitly refused to fix the known vulnerability, stating they "did not intend to change the protocol" - The government dismissed it as a "public awareness issue" rather than a technical design flaw - No remediation timeline or plan was announced - The system continued to operate with the known vulnerability
-- - 認為ㄖㄣˋ ㄨㄟˋ rèn wèi 能ㄋㄥˊ néng 掌控ㄓㄤˇ ㄎㄨㄥˋ zhǎng kòng 系統ㄒㄧˋ ㄊㄨㄥˇ xì tǒng 安全ㄢ ㄑㄩㄢˊ ān quán 與ㄩˇ yǔ 運作ㄩㄣˋ ㄗㄨㄛˋ yùn zuò
### Expert and Institutional Perspectives
然而ㄖㄢˊ ㄦˊ rán ér ,, , 資安ㄗ ㄢ zī ān 專家ㄓㄨㄢ ㄐㄧㄚ zhuān jiā 認為ㄖㄣˋ ㄨㄟˋ rèn wèi 客ㄎㄜˋ kè 製ㄓˋ zhì 化ㄏㄨㄚˋ huà 驗ㄧㄢˋ yàn 證ㄓㄥˋ zhèng 系ㄒㄧˋ xì 統ㄊㄨㄥˇ tǒng 本ㄅㄣˇ běn 質ㄓˋ zhì 上ㄕㄤˋ shàng 風ㄈㄥ fēng 險ㄒㄧㄢˇ xiǎn 更ㄍㄥˋ gèng 高ㄍㄠ gāo ,, , 因為ㄧㄣ ㄨㄟˋ yīn wèi :: :
The Ombudsman's report reinforces that myGov/myGovID security is inadequate, with the government only agreeing to address deficiencies in 2025 [5].
-- - 與ㄩˇ yǔ 廣泛ㄍㄨㄤˇ ㄈㄢˋ guǎng fàn 使用ㄕˇ ㄩㄥˋ shǐ yòng 的ㄉㄜ˙ de 標準ㄅㄧㄠ ㄓㄨㄣˇ biāo zhǔn 相比ㄒㄧㄤ ㄅㄧˇ xiāng bǐ ,, , 外部ㄨㄞˋ ㄅㄨˋ wài bù 安全ㄢ ㄑㄩㄢˊ ān quán 審查ㄕㄣˇ ㄔㄚˊ shěn chá 有限ㄧㄡˇ ㄒㄧㄢˋ yǒu xiàn
The timing suggests this was reactive rather than proactive security governance.
-- - 無法ㄨˊ ㄈㄚˇ wú fǎ 受益ㄕㄡˋ ㄧˋ shòu yì 於ㄩˊ yú 多年ㄉㄨㄛ ㄋㄧㄢˊ duō nián 社群ㄕㄜˋ ㄑㄩㄣˊ shè qún 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 發現ㄈㄚ ㄒㄧㄢˋ fā xiàn 與ㄩˇ yǔ 修補ㄒㄧㄡ ㄅㄨˇ xiū bǔ 的ㄉㄜ˙ de 經驗ㄐㄧㄥ ㄧㄢˋ jīng yàn
### Comparative Government Practice
-- - 增加ㄗㄥ ㄐㄧㄚ zēng jiā 如ㄖㄨˊ rú 20242024 2024 年ㄋㄧㄢˊ nián 發現ㄈㄚ ㄒㄧㄢˋ fā xiàn 的ㄉㄜ˙ de 設計ㄕㄜˋ ㄐㄧˋ shè jì 缺陷ㄑㄩㄝ ㄒㄧㄢˋ quē xiàn 機率ㄐㄧ ㄌㄩˋ jī lǜ [[ [ 22 2 ]] ]
Ignoring known security vulnerabilities in authentication systems is not standard practice across responsible governments.
** * ** * 標準ㄅㄧㄠ ㄓㄨㄣˇ biāo zhǔn 資安實務ㄗ ㄢ ㄕˊ ㄨˋ zī ān shí wù 是ㄕˋ shì 使用ㄕˇ ㄩㄥˋ shǐ yòng 經過ㄐㄧㄥ ㄍㄨㄛˋ jīng guò 驗證ㄧㄢˋ ㄓㄥˋ yàn zhèng 、、 、 廣泛ㄍㄨㄤˇ ㄈㄢˋ guǎng fàn 審查ㄕㄣˇ ㄔㄚˊ shěn chá 的ㄉㄜ˙ de 協議ㄒㄧㄝˊ ㄧˋ xié yì ,, , 除非ㄔㄨˊ ㄈㄟ chú fēi 有ㄧㄡˇ yǒu 令人信服ㄌㄧㄥˋ ㄖㄣˊ ㄒㄧㄣˋ ㄈㄨˊ lìng rén xìn fú 的ㄉㄜ˙ de 理由ㄌㄧˇ ㄧㄡˊ lǐ yóu 不ㄅㄨˋ bù 這麼ㄓㄜˋ ㄇㄜ˙ zhè me 做ㄗㄨㄛˋ zuò 。。 。
The standard industry approach is: 1.
** * ** *
Acknowledge the vulnerability 2.
###### ### 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 對ㄉㄨㄟˋ duì 已ㄧˇ yǐ 發現ㄈㄚ ㄒㄧㄢˋ fā xiàn 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 的ㄉㄜ˙ de 回應ㄏㄨㄟˊ ㄧㄥ huí yīng
Develop a remediation plan 3.
比ㄅㄧˇ bǐ 最初ㄗㄨㄟˋ ㄔㄨ zuì chū 設計ㄕㄜˋ ㄐㄧˋ shè jì 選擇ㄒㄩㄢˇ ㄗㄜˊ xuǎn zé 更ㄍㄥˋ gèng 有ㄧㄡˇ yǒu 問題ㄨㄣˋ ㄊㄧˊ wèn tí 的ㄉㄜ˙ de 是ㄕˋ shì 發現ㄈㄚ ㄒㄧㄢˋ fā xiàn 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 後ㄏㄡˋ hòu 的ㄉㄜ˙ de 回應ㄏㄨㄟˊ ㄧㄥ huí yīng :: :
Implement the fix within a reasonable timeframe 4.
** * ** * CoalitionCoalition Coalition 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 時期ㄕˊ ㄑㄧ shí qī (( ( 20132013 2013 -- - 20222022 2022 )) ) :: : ** * ** *
Publicly communicate the resolution The Australian government's response (refusing to fix the protocol design flaw) falls short of these standards. **Key context:** Neither the Coalition nor Labor has demonstrated strong cybersecurity governance regarding myGovID.
-- - CoalitionCoalition Coalition 部署ㄅㄨˋ ㄕㄨˇ bù shǔ 並運作ㄅㄧㄥˋ ㄩㄣˋ ㄗㄨㄛˋ bìng yùn zuò myGovIDmyGovID myGovID ,, , 但ㄉㄢˋ dàn 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 直到ㄓˊ ㄉㄠˋ zhí dào 20242024 2024 年ㄋㄧㄢˊ nián 才ㄘㄞˊ cái 發現ㄈㄚ ㄒㄧㄢˋ fā xiàn (( ( 在ㄗㄞˋ zài 他們ㄊㄚ ㄇㄣ˙ tā men 卸任ㄒㄧㄝˋ ㄖㄣˋ xiè rèn 後ㄏㄡˋ hòu )) )
The Coalition created a system using non-standard protocols, and Labor (which inherited it) refused to fix it when vulnerabilities were discovered.
** * ** * LaborLabor Labor 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 時期ㄕˊ ㄑㄧ shí qī (( ( 20242024 2024 年ㄋㄧㄢˊ nián 99 9 月ㄩㄝˋ yuè 起ㄑㄧˇ qǐ )) ) :: : ** * ** *
Both decisions appear driven by bureaucratic inertia and unwillingness to acknowledge systemic architectural failures.
-- - ATOATO ATO 明確ㄇㄧㄥˊ ㄑㄩㄝˋ míng què 拒絕ㄐㄩˋ ㄐㄩㄝˊ jù jué 修ㄒㄧㄡ xiū 復ㄈㄨˋ fù 已知ㄧˇ ㄓ yǐ zhī 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng ,, , 表示ㄅㄧㄠˇ ㄕˋ biǎo shì 他們ㄊㄚ ㄇㄣ˙ tā men 「「 「 不ㄅㄨˋ bù 打算ㄉㄚˇ ㄙㄨㄢˋ dǎ suàn 變ㄅㄧㄢˋ biàn 更ㄍㄥˋ gèng 協議ㄒㄧㄝˊ ㄧˋ xié yì 」」 」
-- - 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 將其視ㄐㄧㄤ ㄑㄧˊ ㄕˋ jiāng qí shì 為ㄨㄟˋ wèi 「「 「 公眾ㄍㄨㄥ ㄓㄨㄥˋ gōng zhòng 認知ㄖㄣˋ ㄓ rèn zhī 問題ㄨㄣˋ ㄊㄧˊ wèn tí 」」 」 而ㄦˊ ér 非技術ㄈㄟ ㄐㄧˋ ㄕㄨˋ fēi jì shù 設計ㄕㄜˋ ㄐㄧˋ shè jì 缺陷ㄑㄩㄝ ㄒㄧㄢˋ quē xiàn
-- - 未ㄨㄟˋ wèi 公布ㄍㄨㄥ ㄅㄨˋ gōng bù 修ㄒㄧㄡ xiū 復ㄈㄨˋ fù 時間ㄕˊ ㄐㄧㄢ shí jiān 表ㄅㄧㄠˇ biǎo 或ㄏㄨㄛˋ huò 計畫ㄐㄧˋ ㄏㄨㄚˋ jì huà
-- - 系統ㄒㄧˋ ㄊㄨㄥˇ xì tǒng 在ㄗㄞˋ zài 已知ㄧˇ ㄓ yǐ zhī 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 存在ㄘㄨㄣˊ ㄗㄞˋ cún zài 的ㄉㄜ˙ de 情況ㄑㄧㄥˊ ㄎㄨㄤˋ qíng kuàng 下ㄒㄧㄚˋ xià 繼續ㄐㄧˋ ㄒㄩˋ jì xù 運作ㄩㄣˋ ㄗㄨㄛˋ yùn zuò
###### ### 專家ㄓㄨㄢ ㄐㄧㄚ zhuān jiā 與ㄩˇ yǔ 機構ㄐㄧ ㄍㄡˋ jī gòu 觀點ㄍㄨㄢ ㄉㄧㄢˇ guān diǎn
監察使ㄐㄧㄢ ㄔㄚˊ ㄕˇ jiān chá shǐ 的ㄉㄜ˙ de 報告ㄅㄠˋ ㄍㄠˋ bào gào 強化ㄑㄧㄤˊ ㄏㄨㄚˋ qiáng huà 指出ㄓˇ ㄔㄨ zhǐ chū myGovmyGov myGov // / myGovIDmyGovID myGovID 安全性ㄢ ㄑㄩㄢˊ ㄒㄧㄥˋ ān quán xìng 不足ㄅㄨˋ ㄗㄨˊ bù zú ,, , 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 僅ㄐㄧㄣˇ jǐn 同意ㄊㄨㄥˊ ㄧˋ tóng yì 於ㄩˊ yú 20252025 2025 年ㄋㄧㄢˊ nián 處理ㄔㄨˋ ㄌㄧˇ chù lǐ 這些ㄓㄜˋ ㄒㄧㄝ zhè xiē 缺陷ㄑㄩㄝ ㄒㄧㄢˋ quē xiàn [[ [ 55 5 ]] ] 。。 。
時間點ㄕˊ ㄐㄧㄢ ㄉㄧㄢˇ shí jiān diǎn 顯示ㄒㄧㄢˇ ㄕˋ xiǎn shì 這是ㄓㄜˋ ㄕˋ zhè shì 反應式ㄈㄢˇ ㄧㄥ ㄕˋ fǎn yīng shì 而ㄦˊ ér 非主動式ㄈㄟ ㄓㄨˇ ㄉㄨㄥˋ ㄕˋ fēi zhǔ dòng shì 的ㄉㄜ˙ de 安全ㄢ ㄑㄩㄢˊ ān quán 治理ㄓˋ ㄌㄧˇ zhì lǐ 。。 。
###### ### 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 實務比ㄕˊ ㄨˋ ㄅㄧˇ shí wù bǐ 較ㄐㄧㄠˋ jiào
忽視ㄏㄨ ㄕˋ hū shì 已知ㄧˇ ㄓ yǐ zhī 的ㄉㄜ˙ de 驗證ㄧㄢˋ ㄓㄥˋ yàn zhèng 系統ㄒㄧˋ ㄊㄨㄥˇ xì tǒng 安全漏洞ㄢ ㄑㄩㄢˊ ㄌㄡˋ ㄉㄨㄥˋ ān quán lòu dòng 並非ㄅㄧㄥˋ ㄈㄟ bìng fēi 負責任ㄈㄨˋ ㄗㄜˊ ㄖㄣˋ fù zé rèn 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 的ㄉㄜ˙ de 標準ㄅㄧㄠ ㄓㄨㄣˇ biāo zhǔn 實務ㄕˊ ㄨˋ shí wù 。。 。
標準ㄅㄧㄠ ㄓㄨㄣˇ biāo zhǔn 業界ㄧㄝˋ ㄐㄧㄝˋ yè jiè 作法ㄗㄨㄛˋ ㄈㄚˇ zuò fǎ 是ㄕˋ shì :: :
11 1 .. . 承認ㄔㄥˊ ㄖㄣˋ chéng rèn 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 存在ㄘㄨㄣˊ ㄗㄞˋ cún zài
22 2 .. . 制定ㄓˋ ㄉㄧㄥˋ zhì dìng 修ㄒㄧㄡ xiū 復ㄈㄨˋ fù 計畫ㄐㄧˋ ㄏㄨㄚˋ jì huà
33 3 .. . 在ㄗㄞˋ zài 合理ㄏㄜˊ ㄌㄧˇ hé lǐ 時間ㄕˊ ㄐㄧㄢ shí jiān 內ㄋㄟˋ nèi 實施ㄕˊ ㄕ shí shī 修ㄒㄧㄡ xiū 復ㄈㄨˋ fù
44 4 .. . 公開溝ㄍㄨㄥ ㄎㄞ ㄍㄡ gōng kāi gōu 通解ㄊㄨㄥ ㄐㄧㄝˇ tōng jiě 決ㄐㄩㄝˊ jué 方案ㄈㄤ ㄢˋ fāng àn
澳洲ㄠˋ ㄓㄡ ào zhōu 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 的ㄉㄜ˙ de 回應ㄏㄨㄟˊ ㄧㄥ huí yīng (( ( 拒絕ㄐㄩˋ ㄐㄩㄝˊ jù jué 修ㄒㄧㄡ xiū 復ㄈㄨˋ fù 協議ㄒㄧㄝˊ ㄧˋ xié yì 設計ㄕㄜˋ ㄐㄧˋ shè jì 缺陷ㄑㄩㄝ ㄒㄧㄢˋ quē xiàn )) ) 未達ㄨㄟˋ ㄉㄚˊ wèi dá 這些ㄓㄜˋ ㄒㄧㄝ zhè xiē 標準ㄅㄧㄠ ㄓㄨㄣˇ biāo zhǔn 。。 。
** * ** * 重要ㄓㄨㄥˋ ㄧㄠˋ zhòng yào 背景ㄅㄟˋ ㄐㄧㄥˇ bèi jǐng :: : ** * ** * CoalitionCoalition Coalition 與ㄩˇ yǔ LaborLabor Labor 在ㄗㄞˋ zài myGovIDmyGovID myGovID 的ㄉㄜ˙ de 資安ㄗ ㄢ zī ān 治理ㄓˋ ㄌㄧˇ zhì lǐ 上ㄕㄤˋ shàng 都ㄉㄡ dōu 未展ㄨㄟˋ ㄓㄢˇ wèi zhǎn 現強ㄒㄧㄢˋ ㄑㄧㄤˊ xiàn qiáng 有力ㄧㄡˇ ㄌㄧˋ yǒu lì 的ㄉㄜ˙ de 表現ㄅㄧㄠˇ ㄒㄧㄢˋ biǎo xiàn 。。 。
CoalitionCoalition Coalition 使用ㄕˇ ㄩㄥˋ shǐ yòng 非標ㄈㄟ ㄅㄧㄠ fēi biāo 準協議ㄓㄨㄣˇ ㄒㄧㄝˊ ㄧˋ zhǔn xié yì 創建系統ㄔㄨㄤˋ ㄐㄧㄢˋ ㄒㄧˋ ㄊㄨㄥˇ chuàng jiàn xì tǒng ,, , 而ㄦˊ ér LaborLabor Labor (( ( 繼承該ㄐㄧˋ ㄔㄥˊ ㄍㄞ jì chéng gāi 系統ㄒㄧˋ ㄊㄨㄥˇ xì tǒng )) ) 在ㄗㄞˋ zài 發現ㄈㄚ ㄒㄧㄢˋ fā xiàn 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 時拒ㄕˊ ㄐㄩˋ shí jù 絕修ㄐㄩㄝˊ ㄒㄧㄡ jué xiū 復ㄈㄨˋ fù 。。 。
兩個ㄌㄧㄤˇ ㄍㄜˋ liǎng gè 決定ㄐㄩㄝˊ ㄉㄧㄥˋ jué dìng 似乎ㄙˋ ㄏㄨ sì hū 都ㄉㄡ dōu 源ㄩㄢˊ yuán 於ㄩˊ yú 官僚ㄍㄨㄢ ㄌㄧㄠˊ guān liáo 惰性ㄉㄨㄛˋ ㄒㄧㄥˋ duò xìng 以及ㄧˇ ㄐㄧˊ yǐ jí 不願ㄅㄨˋ ㄩㄢˋ bù yuàn 承ㄔㄥˊ chéng 認系ㄖㄣˋ ㄒㄧˋ rèn xì 統性ㄊㄨㄥˇ ㄒㄧㄥˋ tǒng xìng 架構ㄐㄧㄚˋ ㄍㄡˋ jià gòu 失敗ㄕ ㄅㄞˋ shī bài 。。 。

真實

7.0

/ 10

該主ㄍㄞ ㄓㄨˇ gāi zhǔ 張關ㄓㄤ ㄍㄨㄢ zhāng guān 於ㄩˊ yú myGovIDmyGovID myGovID 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 及ㄐㄧˊ jí 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 拒絕ㄐㄩˋ ㄐㄩㄝˊ jù jué 修ㄒㄧㄡ xiū 復ㄈㄨˋ fù 的ㄉㄜ˙ de 事實ㄕˋ ㄕˊ shì shí 描述ㄇㄧㄠˊ ㄕㄨˋ miáo shù 準確ㄓㄨㄣˇ ㄑㄩㄝˋ zhǔn què 。。 。
The claim is factually accurate regarding the myGovID vulnerability and the government's refusal to fix it.
然而ㄖㄢˊ ㄦˊ rán ér ,, , 有ㄧㄡˇ yǒu 一個ㄧ ㄍㄜˋ yī gè 重要ㄓㄨㄥˋ ㄧㄠˋ zhòng yào 的ㄉㄜ˙ de ** * ** * 時間ㄕˊ ㄐㄧㄢ shí jiān 澄清ㄔㄥˊ ㄑㄧㄥ chéng qīng ** * ** * :: : 拒絕ㄐㄩˋ ㄐㄩㄝˊ jù jué 修ㄒㄧㄡ xiū 復ㄈㄨˋ fù 的ㄉㄜ˙ de 決定ㄐㄩㄝˊ ㄉㄧㄥˋ jué dìng 是ㄕˋ shì 由ㄧㄡˊ yóu ** * ** * 20242024 2024 年ㄋㄧㄢˊ nián 99 9 月ㄩㄝˋ yuè 的ㄉㄜ˙ de LaborLabor Labor 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ ** * ** * 做出ㄗㄨㄛˋ ㄔㄨ zuò chū ,, , 而ㄦˊ ér 非ㄈㄟ fēi CoalitionCoalition Coalition 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 。。 。
However, there is an important **temporal clarification**: The decision to refuse remediation was made by the **Labor government in September 2024**, not the Coalition government.
CoalitionCoalition Coalition (( ( 20132013 2013 -- - 20222022 2022 )) ) 做出ㄗㄨㄛˋ ㄔㄨ zuò chū 最初ㄗㄨㄟˋ ㄔㄨ zuì chū 使用ㄕˇ ㄩㄥˋ shǐ yòng 客ㄎㄜˋ kè 製ㄓˋ zhì 化ㄏㄨㄚˋ huà 、、 、 非標ㄈㄟ ㄅㄧㄠ fēi biāo 準協議ㄓㄨㄣˇ ㄒㄧㄝˊ ㄧˋ zhǔn xié yì 的ㄉㄜ˙ de 決定ㄐㄩㄝˊ ㄉㄧㄥˋ jué dìng ,, , 這個ㄓㄜˋ ㄍㄜˋ zhè gè 架構ㄐㄧㄚˋ ㄍㄡˋ jià gòu 選擇ㄒㄩㄢˇ ㄗㄜˊ xuǎn zé 才ㄘㄞˊ cái 導致ㄉㄠˇ ㄓˋ dǎo zhì 了ㄌㄜ˙ le 此ㄘˇ cǐ 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 。。 。
The Coalition (2013-2022) made the original decision to use a bespoke, non-standard protocol, which was the architectural choice that enabled this vulnerability.
該主張ㄍㄞ ㄓㄨˇ ㄓㄤ gāi zhǔ zhāng 可以ㄎㄜˇ ㄧˇ kě yǐ 有ㄧㄡˇ yǒu 兩種ㄌㄧㄤˇ ㄓㄨㄥˇ liǎng zhǒng 解讀ㄐㄧㄝˇ ㄉㄨˊ jiě dú 方式ㄈㄤ ㄕˋ fāng shì :: :
The claim could be interpreted two ways: 1. **If referring to original protocol design (Coalition era 2013-2022):** TRUE - The Coalition chose a bespoke protocol over proven standards 2. **If referring to the 2024 refusal to fix the discovered vulnerability:** TRUE but made by Labor government, not Coalition The statement "Chose to ignore and not fix" most naturally reads as referring to the refusal to remediate after discovery (September 2024), which was a Labor government decision, though the underlying architectural choice was made by the Coalition.
11 1 .. . ** * ** * 若指ㄖㄨㄛˋ ㄓˇ ruò zhǐ 最初ㄗㄨㄟˋ ㄔㄨ zuì chū 協議ㄒㄧㄝˊ ㄧˋ xié yì 設計ㄕㄜˋ ㄐㄧˋ shè jì (( ( CoalitionCoalition Coalition 時期ㄕˊ ㄑㄧ shí qī 20132013 2013 -- - 20222022 2022 )) ) :: : ** * ** * TRUETRUE TRUE -- - CoalitionCoalition Coalition 選擇ㄒㄩㄢˇ ㄗㄜˊ xuǎn zé 客ㄎㄜˋ kè 製ㄓˋ zhì 化ㄏㄨㄚˋ huà 協ㄒㄧㄝˊ xié 議ㄧˋ yì 而ㄦˊ ér 非ㄈㄟ fēi 成熟ㄔㄥˊ ㄕㄨˊ chéng shú 標準ㄅㄧㄠ ㄓㄨㄣˇ biāo zhǔn
22 2 .. . ** * ** * 若指ㄖㄨㄛˋ ㄓˇ ruò zhǐ 20242024 2024 年ㄋㄧㄢˊ nián 拒絕ㄐㄩˋ ㄐㄩㄝˊ jù jué 修ㄒㄧㄡ xiū 復ㄈㄨˋ fù 已ㄧˇ yǐ 發現ㄈㄚ ㄒㄧㄢˋ fā xiàn 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng :: : ** * ** * TRUETRUE TRUE 但ㄉㄢˋ dàn 由ㄧㄡˊ yóu LaborLabor Labor 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 做出ㄗㄨㄛˋ ㄔㄨ zuò chū ,, , 而ㄦˊ ér 非ㄈㄟ fēi CoalitionCoalition Coalition
「「 「 選擇ㄒㄩㄢˇ ㄗㄜˊ xuǎn zé 忽視且ㄏㄨ ㄕˋ ㄑㄧㄝˇ hū shì qiě 不修ㄅㄨˋ ㄒㄧㄡ bù xiū 復ㄈㄨˋ fù 」」 」 這句ㄓㄜˋ ㄐㄩˋ zhè jù 話ㄏㄨㄚˋ huà 最ㄗㄨㄟˋ zuì 自然ㄗˋ ㄖㄢˊ zì rán 地解讀ㄉㄧˋ ㄐㄧㄝˇ ㄉㄨˊ dì jiě dú 為ㄨㄟˋ wèi 指發ㄓˇ ㄈㄚ zhǐ fā 現後拒ㄒㄧㄢˋ ㄏㄡˋ ㄐㄩˋ xiàn hòu jù 絕修ㄐㄩㄝˊ ㄒㄧㄡ jué xiū 復ㄈㄨˋ fù (( ( 20242024 2024 年ㄋㄧㄢˊ nián 99 9 月ㄩㄝˋ yuè )) ) ,, , 這是ㄓㄜˋ ㄕˋ zhè shì LaborLabor Labor 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 的ㄉㄜ˙ de 決定ㄐㄩㄝˊ ㄉㄧㄥˋ jué dìng ,, , 但底ㄉㄢˋ ㄉㄧˇ dàn dǐ 層架構ㄘㄥˊ ㄐㄧㄚˋ ㄍㄡˋ céng jià gòu 選擇ㄒㄩㄢˇ ㄗㄜˊ xuǎn zé 是ㄕˋ shì 由ㄧㄡˊ yóu CoalitionCoalition Coalition 做出ㄗㄨㄛˋ ㄔㄨ zuò chū 。。 。

📚 來源與引用 (8)

  1. 1
    itnews.com.au

    itnews.com.au

    ATO declines to change protocol.

    iTnews
  2. 2
    thinkingcybersecurity.com

    thinkingcybersecurity.com

    Thinkingcybersecurity

  3. 3
    innovationaus.com

    innovationaus.com

    Innovationaus

  4. 4
    accountantsdaily.com.au

    accountantsdaily.com.au

    From security concerns to clashes with workplace policies, the transition to myGovID has caused a few headaches within the profession, but the ATO believes worries are misplaced.

    Accountantsdaily Com
  5. 5
    PDF

    Keeping myGov Secure

    Ombudsman Gov • PDF Document
  6. 6
    architecture.digital.gov.au

    architecture.digital.gov.au

    Architecture Digital Gov

  7. 7
    cecs.anu.edu.au

    cecs.anu.edu.au

    Cecs Anu Edu

  8. 8
    ato.gov.au

    ato.gov.au

    Ato Gov

評分量表方法論

1-3: 虛假

事實不正確或惡意捏造。

4-6: 部分

有部分真實性,但缺乏或扭曲了背景。

7-9: 大致屬實

微小的技術性問題或措辭問題。

10: 準確

完美驗證且在情境上公正。

方法論: 評分通過交叉比對官方政府記錄、獨立事實查核組織和原始來源文件來確定。