真實

評分: 8.5/10

Coalition
C0195

主張

“在部署 COVIDSafe 應用程式時忽視了安全最佳實踐,選擇不執行漏洞賞金計畫,且儘管曾承諾卻未即時公開原始碼,導致多個漏洞被研究人員發現的時間遠遠晚於應有的時機。”
原始來源: Matthew Davis

原始來源

✅ 事實查核

澳洲ㄠˋ ㄓㄡ ào zhōu 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 在ㄗㄞˋ zài COVIDSafeCOVIDSafe COVIDSafe 應用ㄧㄥ ㄩㄥˋ yīng yòng 程式ㄔㄥˊ ㄕˋ chéng shì 上ㄕㄤˋ shàng 忽視ㄏㄨ ㄕˋ hū shì 安全ㄢ ㄑㄩㄢˊ ān quán 最佳ㄗㄨㄟˋ ㄐㄧㄚ zuì jiā 實踐ㄕˊ ㄐㄧㄢˋ shí jiàn 的ㄉㄜ˙ de 聲稱ㄕㄥ ㄔㄥ shēng chēng ** * ** * 基本ㄐㄧ ㄅㄣˇ jī běn 屬實ㄕㄨˇ ㄕˊ shǔ shí ** * ** * ,, , 但ㄉㄢˋ dàn 需要ㄒㄩ ㄧㄠˋ xū yào 在ㄗㄞˋ zài 時間點ㄕˊ ㄐㄧㄢ ㄉㄧㄢˇ shí jiān diǎn 和ㄏㄜˊ hé 背景ㄅㄟˋ ㄐㄧㄥˇ bèi jǐng 上ㄕㄤˋ shàng 進行ㄐㄧㄣˋ ㄒㄧㄥˊ jìn xíng 重要ㄓㄨㄥˋ ㄧㄠˋ zhòng yào 澄清ㄔㄥˊ ㄑㄧㄥ chéng qīng 。。 。
The claim that the Australian government ignored security best practices with the COVIDSafe app is **substantially accurate**, though it requires important clarification regarding timing and context. **Delayed Response to Vulnerabilities:** Within hours of COVIDSafe's release on April 26, 2020, security researcher Jim Mussared discovered multiple privacy issues in the Android version by 1:19am on April 27 [1].
** * ** * 對ㄉㄨㄟˋ duì 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 的ㄉㄜ˙ de 延遲ㄧㄢˊ ㄔˊ yán chí 回應ㄏㄨㄟˊ ㄧㄥ huí yīng :: : ** * ** * COVIDSafeCOVIDSafe COVIDSafe 於ㄩˊ yú 20202020 2020 年ㄋㄧㄢˊ nián 44 4 月ㄩㄝˋ yuè 2626 26 日ㄖˋ rì 發布後數ㄈㄚ ㄅㄨˋ ㄏㄡˋ ㄕㄨˋ fā bù hòu shù 小時ㄒㄧㄠˇ ㄕˊ xiǎo shí 內ㄋㄟˋ nèi ,, , 安全ㄢ ㄑㄩㄢˊ ān quán 研究ㄧㄢˊ ㄐㄧㄡ yán jiū 人員ㄖㄣˊ ㄩㄢˊ rén yuán JimJim Jim MussaredMussared Mussared 即ㄐㄧˊ jí 在ㄗㄞˋ zài 44 4 月ㄩㄝˋ yuè 2727 27 日ㄖˋ rì 凌晨ㄌㄧㄥˊ ㄔㄣˊ líng chén 11 1 :: : 1919 19 發現ㄈㄚ ㄒㄧㄢˋ fā xiàn AndroidAndroid Android 版本ㄅㄢˇ ㄅㄣˇ bǎn běn 存在ㄘㄨㄣˊ ㄗㄞˋ cún zài 多個ㄉㄨㄛ ㄍㄜˋ duō gè 隱私ㄧㄣˇ ㄙ yǐn sī 問題ㄨㄣˋ ㄊㄧˊ wèn tí [[ [ 11 1 ]] ] 。。 。
He detailed these vulnerabilities in a comprehensive report and emailed the Department of Health, Digital Transformation Agency (DTA), Australian Signals Directorate (ASD), and the Australian Cyber Security Centre (ACSC) on April 27-28 [1].
他ㄊㄚ tā 在ㄗㄞˋ zài 一份ㄧ ㄈㄣˋ yī fèn 詳盡ㄒㄧㄤˊ ㄐㄧㄣˇ xiáng jǐn 的ㄉㄜ˙ de 報告ㄅㄠˋ ㄍㄠˋ bào gào 中ㄓㄨㄥ zhōng 記錄ㄐㄧˋ ㄌㄨˋ jì lù 了ㄌㄜ˙ le 這些ㄓㄜˋ ㄒㄧㄝ zhè xiē 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng ,, , 並ㄅㄧㄥˋ bìng 於ㄩˊ yú 44 4 月ㄩㄝˋ yuè 2727 27 至ㄓˋ zhì 2828 28 日發ㄖˋ ㄈㄚ rì fā 送ㄙㄨㄥˋ sòng 電子ㄉㄧㄢˋ ㄗ˙ diàn zi 郵件ㄧㄡˊ ㄐㄧㄢˋ yóu jiàn 給衛ㄍㄟˇ ㄨㄟˋ gěi wèi 生部ㄕㄥ ㄅㄨˋ shēng bù 、、 、 數位ㄕㄨˋ ㄨㄟˋ shù wèi 轉型ㄓㄨㄢˇ ㄒㄧㄥˊ zhuǎn xíng 局ㄐㄩˊ jú (( ( DTADTA DTA )) ) 、、 、 澳洲ㄠˋ ㄓㄡ ào zhōu 信號局ㄒㄧㄣˋ ㄏㄠˋ ㄐㄩˊ xìn hào jú (( ( ASDASD ASD )) ) 及ㄐㄧˊ jí 澳洲ㄠˋ ㄓㄡ ào zhōu 網路ㄨㄤˇ ㄌㄨˋ wǎng lù 安全ㄢ ㄑㄩㄢˊ ān quán 中心ㄓㄨㄥ ㄒㄧㄣ zhōng xīn (( ( ACSCACSC ACSC )) ) [[ [ 11 1 ]] ] 。。 。
However, Mussared only received a single-line response from the DTA a week later on May 5, and this response came only after media began making inquiries [1].
然而ㄖㄢˊ ㄦˊ rán ér ,, , MussaredMussared Mussared 直到ㄓˊ ㄉㄠˋ zhí dào 一週ㄧ ㄓㄡ yī zhōu 後ㄏㄡˋ hòu 的ㄉㄜ˙ de 55 5 月ㄩㄝˋ yuè 55 5 日才ㄖˋ ㄘㄞˊ rì cái 收到ㄕㄡ ㄉㄠˋ shōu dào DTADTA DTA 僅有ㄐㄧㄣˇ ㄧㄡˇ jǐn yǒu 一行ㄧ ㄒㄧㄥˊ yī xíng 的ㄉㄜ˙ de 回覆ㄏㄨㄟˊ ㄈㄨˋ huí fù ,, , 且ㄑㄧㄝˇ qiě 這次ㄓㄜˋ ㄘˋ zhè cì 回覆ㄏㄨㄟˊ ㄈㄨˋ huí fù 是ㄕˋ shì 在ㄗㄞˋ zài 媒體ㄇㄟˊ ㄊㄧˇ méi tǐ 開始詢ㄎㄞ ㄕˇ ㄒㄩㄣˊ kāi shǐ xún 問後才ㄨㄣˋ ㄏㄡˋ ㄘㄞˊ wèn hòu cái 發出ㄈㄚ ㄔㄨ fā chū 的ㄉㄜ˙ de [[ [ 11 1 ]] ] 。。 。
In comparison, Mussared confirmed that he was able to reach Singapore's team (which developed TraceTogether, the app Australia modeled COVIDSafe on) within hours and had some issues fixed by them [1]. **No Formal Bug Bounty Program:** The government did not establish a formal bug bounty program for COVIDSafe.
相比之下ㄒㄧㄤ ㄅㄧˇ ㄓ ㄒㄧㄚˋ xiāng bǐ zhī xià ,, , MussaredMussared Mussared 確認ㄑㄩㄝˋ ㄖㄣˋ què rèn 他ㄊㄚ tā 能ㄋㄥˊ néng 在ㄗㄞˋ zài 數小時ㄕㄨˋ ㄒㄧㄠˇ ㄕˊ shù xiǎo shí 內ㄋㄟˋ nèi 聯ㄌㄧㄢˊ lián 繫ㄒㄧˋ xì 到ㄉㄠˋ dào 新加坡ㄒㄧㄣ ㄐㄧㄚ ㄆㄛ xīn jiā pō 團隊ㄊㄨㄢˊ ㄉㄨㄟˋ tuán duì (( ( 該團隊ㄍㄞ ㄊㄨㄢˊ ㄉㄨㄟˋ gāi tuán duì 開發ㄎㄞ ㄈㄚ kāi fā 了ㄌㄜ˙ le 澳洲ㄠˋ ㄓㄡ ào zhōu COVIDSafeCOVIDSafe COVIDSafe 所ㄙㄨㄛˇ suǒ 參考ㄘㄢ ㄎㄠˇ cān kǎo 的ㄉㄜ˙ de TraceTogetherTraceTogether TraceTogether 應用ㄧㄥ ㄩㄥˋ yīng yòng 程式ㄔㄥˊ ㄕˋ chéng shì )) ) ,, , 且ㄑㄧㄝˇ qiě 對方ㄉㄨㄟˋ ㄈㄤ duì fāng 已修ㄧˇ ㄒㄧㄡ yǐ xiū 復ㄈㄨˋ fù 部分ㄅㄨˋ ㄈㄣˋ bù fèn 問題ㄨㄣˋ ㄊㄧˊ wèn tí [[ [ 11 1 ]] ] 。。 。
According to cybersecurity experts quoted in authoritative sources, "the best practices would be a formal disclosure program and a bug bounty program, and a commitment to getting the bugs fixed" [1].
** * ** * 未ㄨㄟˋ wèi 設立ㄕㄜˋ ㄌㄧˋ shè lì 正式ㄓㄥˋ ㄕˋ zhèng shì 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 賞金計畫ㄕㄤˇ ㄐㄧㄣ ㄐㄧˋ ㄏㄨㄚˋ shǎng jīn jì huà :: : ** * ** * 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 未為ㄨㄟˋ ㄨㄟˋ wèi wèi COVIDSafeCOVIDSafe COVIDSafe 建立ㄐㄧㄢˋ ㄌㄧˋ jiàn lì 正式ㄓㄥˋ ㄕˋ zhèng shì 的ㄉㄜ˙ de 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 賞金計畫ㄕㄤˇ ㄐㄧㄣ ㄐㄧˋ ㄏㄨㄚˋ shǎng jīn jì huà 。。 。
This represents a significant departure from best practices.
根據權ㄍㄣ ㄐㄩˋ ㄑㄩㄢˊ gēn jù quán 威來源ㄨㄟ ㄌㄞˊ ㄩㄢˊ wēi lái yuán 引述ㄧㄣˇ ㄕㄨˋ yǐn shù 的ㄉㄜ˙ de 網路ㄨㄤˇ ㄌㄨˋ wǎng lù 安全ㄢ ㄑㄩㄢˊ ān quán 專家ㄓㄨㄢ ㄐㄧㄚ zhuān jiā 表示ㄅㄧㄠˇ ㄕˋ biǎo shì ,, , 「「 「 最佳ㄗㄨㄟˋ ㄐㄧㄚ zuì jiā 實踐ㄕˊ ㄐㄧㄢˋ shí jiàn 應ㄧㄥ yīng 包括ㄅㄠ ㄎㄨㄛˋ bāo kuò 正式ㄓㄥˋ ㄕˋ zhèng shì 的ㄉㄜ˙ de 披露ㄆㄧ ㄌㄨˋ pī lù 計畫ㄐㄧˋ ㄏㄨㄚˋ jì huà 和ㄏㄜˊ hé 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 賞金計畫ㄕㄤˇ ㄐㄧㄣ ㄐㄧˋ ㄏㄨㄚˋ shǎng jīn jì huà ,, , 以及ㄧˇ ㄐㄧˊ yǐ jí 修ㄒㄧㄡ xiū 復ㄈㄨˋ fù 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 的ㄉㄜ˙ de 承諾ㄔㄥˊ ㄋㄨㄛˋ chéng nuò 」」 」 [[ [ 11 1 ]] ] 。。 。
For comparison, the UK government's approach to its NHS COVID-19 app included more structured vulnerability disclosure processes [1]. **Delayed Source Code Publication:** While Australia eventually released source code (app code was published on April 28, 2020), there were significant delays and transparency issues [1].
這與ㄓㄜˋ ㄩˇ zhè yǔ 最佳ㄗㄨㄟˋ ㄐㄧㄚ zuì jiā 實踐ㄕˊ ㄐㄧㄢˋ shí jiàn 存在ㄘㄨㄣˊ ㄗㄞˋ cún zài 顯著ㄒㄧㄢˇ ㄓㄨˋ xiǎn zhù 偏差ㄆㄧㄢ ㄔㄚ piān chā 。。 。
Cryptographer Dr.
相比之下ㄒㄧㄤ ㄅㄧˇ ㄓ ㄒㄧㄚˋ xiāng bǐ zhī xià ,, , 英國ㄧㄥ ㄍㄨㄛˊ yīng guó 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 對ㄉㄨㄟˋ duì 其ㄑㄧˊ qí NHSNHS NHS COVIDCOVID COVID -- - 1919 19 應用ㄧㄥ ㄩㄥˋ yīng yòng 程式ㄔㄥˊ ㄕˋ chéng shì 的ㄉㄜ˙ de 做法ㄗㄨㄛˋ ㄈㄚˇ zuò fǎ 包含ㄅㄠ ㄏㄢˊ bāo hán 了ㄌㄜ˙ le 更ㄍㄥˋ gèng 有ㄧㄡˇ yǒu 結構ㄐㄧㄝˊ ㄍㄡˋ jié gòu 的ㄉㄜ˙ de 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 披露ㄆㄧ ㄌㄨˋ pī lù 流程ㄌㄧㄡˊ ㄔㄥˊ liú chéng [[ [ 11 1 ]] ] 。。 。
Vanessa Teague noted that "Singapore released app and server code weeks ago" while "Aus & the UK released app code, and no server code, within the last 24 hours" [1].
** * ** * 原始ㄩㄢˊ ㄕˇ yuán shǐ 碼發布ㄇㄚˇ ㄈㄚ ㄅㄨˋ mǎ fā bù 的ㄉㄜ˙ de 延遲ㄧㄢˊ ㄔˊ yán chí :: : ** * ** * 雖然ㄙㄨㄟ ㄖㄢˊ suī rán 澳洲ㄠˋ ㄓㄡ ào zhōu 最終ㄗㄨㄟˋ ㄓㄨㄥ zuì zhōng 公開ㄍㄨㄥ ㄎㄞ gōng kāi 了ㄌㄜ˙ le 原始ㄩㄢˊ ㄕˇ yuán shǐ 碼ㄇㄚˇ mǎ (( ( 應用ㄧㄥ ㄩㄥˋ yīng yòng 程式ㄔㄥˊ ㄕˋ chéng shì 碼ㄇㄚˇ mǎ 於ㄩˊ yú 20202020 2020 年ㄋㄧㄢˊ nián 44 4 月ㄩㄝˋ yuè 2828 28 日ㄖˋ rì 發布ㄈㄚ ㄅㄨˋ fā bù )) ) ,, , 但ㄉㄢˋ dàn 存在ㄘㄨㄣˊ ㄗㄞˋ cún zài 顯著ㄒㄧㄢˇ ㄓㄨˋ xiǎn zhù 的ㄉㄜ˙ de 延遲ㄧㄢˊ ㄔˊ yán chí 和ㄏㄜˊ hé 透明度ㄊㄡˋ ㄇㄧㄥˊ ㄉㄨˋ tòu míng dù 問題ㄨㄣˋ ㄊㄧˊ wèn tí [[ [ 11 1 ]] ] 。。 。
Critically, Australia only released application code—not the server code where "the server does all the crypto" [1].
密碼學ㄇㄧˋ ㄇㄚˇ ㄒㄩㄝˊ mì mǎ xué 專家ㄓㄨㄢ ㄐㄧㄚ zhuān jiā VanessaVanessa Vanessa TeagueTeague Teague 博士ㄅㄛˊ ㄕˋ bó shì 指出ㄓˇ ㄔㄨ zhǐ chū ,, , 「「 「 新加坡ㄒㄧㄣ ㄐㄧㄚ ㄆㄛ xīn jiā pō 於ㄩˊ yú 數週前ㄕㄨˋ ㄓㄡ ㄑㄧㄢˊ shù zhōu qián 已ㄧˇ yǐ 發布ㄈㄚ ㄅㄨˋ fā bù 應用ㄧㄥ ㄩㄥˋ yīng yòng 程式ㄔㄥˊ ㄕˋ chéng shì 和ㄏㄜˊ hé 伺服器ㄘˋ ㄈㄨˊ ㄑㄧˋ cì fú qì 程式ㄔㄥˊ ㄕˋ chéng shì 碼ㄇㄚˇ mǎ 」」 」 ,, , 而ㄦˊ ér 「「 「 澳洲ㄠˋ ㄓㄡ ào zhōu 在ㄗㄞˋ zài 過去ㄍㄨㄛˋ ㄑㄩˋ guò qù 2424 24 小時ㄒㄧㄠˇ ㄕˊ xiǎo shí 內ㄋㄟˋ nèi 才ㄘㄞˊ cái 發布ㄈㄚ ㄅㄨˋ fā bù 應用ㄧㄥ ㄩㄥˋ yīng yòng 程式ㄔㄥˊ ㄕˋ chéng shì 碼ㄇㄚˇ mǎ ,, , 未ㄨㄟˋ wèi 發布ㄈㄚ ㄅㄨˋ fā bù 伺服器ㄘˋ ㄈㄨˊ ㄑㄧˋ cì fú qì 程式ㄔㄥˊ ㄕˋ chéng shì 碼ㄇㄚˇ mǎ 」」 」 [[ [ 11 1 ]] ] 。。 。
The government also failed to publish whitepapers explaining the cryptographic design and security assumptions, unlike Singapore and the UK [1]. **Multiple Vulnerabilities Discovered Over Time:** Researchers identified at least four major vulnerabilities in COVIDSafe that were discovered at different times throughout 2020 [2]: - A bug in how COVIDSafe reads Bluetooth messages on iPhones, causing some encrypted messages to be garbled [2] - CVE-2020-14292: A vulnerability allowing long-term tracking of Android devices [2] - CVE-2020-12856: A flaw affecting Android versions 1.0.17 and earlier, allowing attackers to bond silently with Android phones [2] - A critical concurrency flaw in encryption code (versions 1.0.18 to 1.0.27) where a single Cipher instance was shared across threads without synchronization [2] These were not all discovered simultaneously, but rather identified as researchers examined the code over weeks and months [2]. **Lack of Engagement with Research Community:** The government did not adequately engage with researchers raising concerns.
關鍵ㄍㄨㄢ ㄐㄧㄢˋ guān jiàn 問題ㄨㄣˋ ㄊㄧˊ wèn tí 在ㄗㄞˋ zài 於ㄩˊ yú ,, , 澳洲ㄠˋ ㄓㄡ ào zhōu 僅發布ㄐㄧㄣˇ ㄈㄚ ㄅㄨˋ jǐn fā bù 了ㄌㄜ˙ le 應用ㄧㄥ ㄩㄥˋ yīng yòng 程式ㄔㄥˊ ㄕˋ chéng shì 碼ㄇㄚˇ mǎ —— — —— — 而ㄦˊ ér 非ㄈㄟ fēi 「「 「 執行ㄓˊ ㄒㄧㄥˊ zhí xíng 所有ㄙㄨㄛˇ ㄧㄡˇ suǒ yǒu 加密ㄐㄧㄚ ㄇㄧˋ jiā mì 運算ㄩㄣˋ ㄙㄨㄢˋ yùn suàn 的ㄉㄜ˙ de 伺服器ㄘˋ ㄈㄨˊ ㄑㄧˋ cì fú qì 」」 」 程式ㄔㄥˊ ㄕˋ chéng shì 碼ㄇㄚˇ mǎ [[ [ 11 1 ]] ] 。。 。
Dr.
政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 也ㄧㄝˇ yě 未ㄨㄟˋ wèi 發布ㄈㄚ ㄅㄨˋ fā bù 說明ㄕㄨㄛ ㄇㄧㄥˊ shuō míng 加密ㄐㄧㄚ ㄇㄧˋ jiā mì 設計ㄕㄜˋ ㄐㄧˋ shè jì 和ㄏㄜˊ hé 安全ㄢ ㄑㄩㄢˊ ān quán 假設ㄐㄧㄚˇ ㄕㄜˋ jiǎ shè 的ㄉㄜ˙ de 技術ㄐㄧˋ ㄕㄨˋ jì shù 白皮ㄅㄞˊ ㄆㄧˊ bái pí 書ㄕㄨ shū ,, , 這與ㄓㄜˋ ㄩˇ zhè yǔ 新加坡ㄒㄧㄣ ㄐㄧㄚ ㄆㄛ xīn jiā pō 和ㄏㄜˊ hé 英國ㄧㄥ ㄍㄨㄛˊ yīng guó 的ㄉㄜ˙ de 做法ㄗㄨㄛˋ ㄈㄚˇ zuò fǎ 不同ㄅㄨˋ ㄊㄨㄥˊ bù tóng [[ [ 11 1 ]] ] 。。 。
Vanessa Teague and colleagues reported problems with the application, but communication was difficult [1].
** * ** * 隨時間ㄙㄨㄟˊ ㄕˊ ㄐㄧㄢ suí shí jiān 發現ㄈㄚ ㄒㄧㄢˋ fā xiàn 的ㄉㄜ˙ de 多個ㄉㄨㄛ ㄍㄜˋ duō gè 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng :: : ** * ** * 研究ㄧㄢˊ ㄐㄧㄡ yán jiū 人員ㄖㄣˊ ㄩㄢˊ rén yuán 發現ㄈㄚ ㄒㄧㄢˋ fā xiàn COVIDSafeCOVIDSafe COVIDSafe 至少ㄓˋ ㄕㄠˇ zhì shǎo 存在ㄘㄨㄣˊ ㄗㄞˋ cún zài 四個ㄙˋ ㄍㄜˋ sì gè 重大ㄓㄨㄥˋ ㄉㄚˋ zhòng dà 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng ,, , 這些ㄓㄜˋ ㄒㄧㄝ zhè xiē 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 於ㄩˊ yú 20202020 2020 年間ㄋㄧㄢˊ ㄐㄧㄢ nián jiān 不同ㄅㄨˋ ㄊㄨㄥˊ bù tóng 時間點ㄕˊ ㄐㄧㄢ ㄉㄧㄢˇ shí jiān diǎn 被ㄅㄟˋ bèi 發現ㄈㄚ ㄒㄧㄢˋ fā xiàn [[ [ 22 2 ]] ] :: :
The Australian Digital Transformation Agency only published an email address where researchers "could provide feedback" rather than establishing a formal, responsive vulnerability disclosure program [1].
-- - COVIDSafeCOVIDSafe COVIDSafe 在ㄗㄞˋ zài iPhoneiPhone iPhone 上ㄕㄤˋ shàng 讀取ㄉㄨˊ ㄑㄩˇ dú qǔ 藍牙訊息ㄌㄢˊ ㄧㄚˊ ㄒㄩㄣˋ ㄒㄧ lán yá xùn xī 的ㄉㄜ˙ de 方式ㄈㄤ ㄕˋ fāng shì 存在ㄘㄨㄣˊ ㄗㄞˋ cún zài 錯誤ㄘㄨㄛˋ ㄨˋ cuò wù ,, , 導致ㄉㄠˇ ㄓˋ dǎo zhì 部分ㄅㄨˋ ㄈㄣˋ bù fèn 加密ㄐㄧㄚ ㄇㄧˋ jiā mì 訊息ㄒㄩㄣˋ ㄒㄧ xùn xī 出現ㄔㄨ ㄒㄧㄢˋ chū xiàn 亂碼ㄌㄨㄢˋ ㄇㄚˇ luàn mǎ [[ [ 22 2 ]] ]
-- - CVECVE CVE -- - 20202020 2020 -- - 1429214292 14292 :: : 允許ㄩㄣˇ ㄒㄩˇ yǔn xǔ 長ㄓㄤˇ zhǎng 期ㄑㄧ qī 追ㄓㄨㄟ zhuī 蹤ㄗㄨㄥ zōng AndroidAndroid Android 裝置ㄓㄨㄤ ㄓˋ zhuāng zhì 的ㄉㄜ˙ de 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng [[ [ 22 2 ]] ]
-- - CVECVE CVE -- - 20202020 2020 -- - 1285612856 12856 :: : 影響ㄧㄥˇ ㄒㄧㄤˇ yǐng xiǎng AndroidAndroid Android 1.01.0 1.0 .. . 1717 17 及ㄐㄧˊ jí 更ㄍㄥˋ gèng 早ㄗㄠˇ zǎo 版本ㄅㄢˇ ㄅㄣˇ bǎn běn 的ㄉㄜ˙ de 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng ,, , 允許ㄩㄣˇ ㄒㄩˇ yǔn xǔ 攻擊者ㄍㄨㄥ ㄐㄧ ㄓㄜˇ gōng jī zhě 與ㄩˇ yǔ AndroidAndroid Android 手機ㄕㄡˇ ㄐㄧ shǒu jī 靜默配ㄐㄧㄥˋ ㄇㄛˋ ㄆㄟˋ jìng mò pèi 對ㄉㄨㄟˋ duì [[ [ 22 2 ]] ]
-- - 加密ㄐㄧㄚ ㄇㄧˋ jiā mì 程式ㄔㄥˊ ㄕˋ chéng shì 碼中ㄇㄚˇ ㄓㄨㄥ mǎ zhōng 的ㄉㄜ˙ de 重大ㄓㄨㄥˋ ㄉㄚˋ zhòng dà 並發ㄅㄧㄥˋ ㄈㄚ bìng fā 缺陷ㄑㄩㄝ ㄒㄧㄢˋ quē xiàn (( ( 1.01.0 1.0 .. . 1818 18 至ㄓˋ zhì 1.01.0 1.0 .. . 2727 27 版本ㄅㄢˇ ㄅㄣˇ bǎn běn )) ) :: : 單一ㄉㄢ ㄧ dān yī CipherCipher Cipher 實例ㄕˊ ㄌㄧˋ shí lì 在ㄗㄞˋ zài 未ㄨㄟˋ wèi 同步ㄊㄨㄥˊ ㄅㄨˋ tóng bù 的ㄉㄜ˙ de 情況ㄑㄧㄥˊ ㄎㄨㄤˋ qíng kuàng 下ㄒㄧㄚˋ xià 被ㄅㄟˋ bèi 跨ㄎㄨㄚˋ kuà 執行緒ㄓˊ ㄒㄧㄥˊ ㄒㄩˋ zhí xíng xù 共用ㄍㄨㄥˋ ㄩㄥˋ gòng yòng [[ [ 22 2 ]] ]
這些ㄓㄜˋ ㄒㄧㄝ zhè xiē 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 並ㄅㄧㄥˋ bìng 非同ㄈㄟ ㄊㄨㄥˊ fēi tóng 時ㄕˊ shí 被ㄅㄟˋ bèi 發現ㄈㄚ ㄒㄧㄢˋ fā xiàn ,, , 而是ㄦˊ ㄕˋ ér shì 研究ㄧㄢˊ ㄐㄧㄡ yán jiū 人員ㄖㄣˊ ㄩㄢˊ rén yuán 在ㄗㄞˋ zài 數週ㄕㄨˋ ㄓㄡ shù zhōu 和ㄏㄜˊ hé 數月ㄕㄨˋ ㄩㄝˋ shù yuè 內ㄋㄟˋ nèi 檢視ㄐㄧㄢˇ ㄕˋ jiǎn shì 程式ㄔㄥˊ ㄕˋ chéng shì 碼時ㄇㄚˇ ㄕˊ mǎ shí 陸續識ㄌㄨˋ ㄒㄩˋ ㄕˊ lù xù shí 別出ㄅㄧㄝˊ ㄔㄨ bié chū 的ㄉㄜ˙ de [[ [ 22 2 ]] ] 。。 。
** * ** * 與ㄩˇ yǔ 研究ㄧㄢˊ ㄐㄧㄡ yán jiū 社群ㄕㄜˋ ㄑㄩㄣˊ shè qún 的ㄉㄜ˙ de 互動ㄏㄨˋ ㄉㄨㄥˋ hù dòng 不足ㄅㄨˋ ㄗㄨˊ bù zú :: : ** * ** * 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 未ㄨㄟˋ wèi 充分ㄔㄨㄥ ㄈㄣˋ chōng fèn 與ㄩˇ yǔ 提出ㄊㄧˊ ㄔㄨ tí chū 疑慮ㄧˊ ㄌㄩˋ yí lǜ 的ㄉㄜ˙ de 研究ㄧㄢˊ ㄐㄧㄡ yán jiū 人員ㄖㄣˊ ㄩㄢˊ rén yuán 互動ㄏㄨˋ ㄉㄨㄥˋ hù dòng 。。 。
VanessaVanessa Vanessa TeagueTeague Teague 博士ㄅㄛˊ ㄕˋ bó shì 及其ㄐㄧˊ ㄑㄧˊ jí qí 同事ㄊㄨㄥˊ ㄕˋ tóng shì 回報ㄏㄨㄟˊ ㄅㄠˋ huí bào 了ㄌㄜ˙ le 應用ㄧㄥ ㄩㄥˋ yīng yòng 程式ㄔㄥˊ ㄕˋ chéng shì 的ㄉㄜ˙ de 問題ㄨㄣˋ ㄊㄧˊ wèn tí ,, , 但ㄉㄢˋ dàn 溝通ㄍㄡ ㄊㄨㄥ gōu tōng 困難ㄎㄨㄣˋ ㄋㄢˊ kùn nán [[ [ 11 1 ]] ] 。。 。
澳洲ㄠˋ ㄓㄡ ào zhōu 數位ㄕㄨˋ ㄨㄟˋ shù wèi 轉型ㄓㄨㄢˇ ㄒㄧㄥˊ zhuǎn xíng 局僅ㄐㄩˊ ㄐㄧㄣˇ jú jǐn 發布ㄈㄚ ㄅㄨˋ fā bù 了ㄌㄜ˙ le 一個ㄧ ㄍㄜˋ yī gè 電子ㄉㄧㄢˋ ㄗ˙ diàn zi 郵件ㄧㄡˊ ㄐㄧㄢˋ yóu jiàn 地址ㄉㄧˋ ㄓˇ dì zhǐ 供ㄍㄨㄥ gōng 研究ㄧㄢˊ ㄐㄧㄡ yán jiū 人員ㄖㄣˊ ㄩㄢˊ rén yuán 「「 「 提供ㄊㄧˊ ㄍㄨㄥ tí gōng 反饋ㄈㄢˇ ㄎㄨㄟˋ fǎn kuì 」」 」 ,, , 而ㄦˊ ér 非ㄈㄟ fēi 建立ㄐㄧㄢˋ ㄌㄧˋ jiàn lì 正式ㄓㄥˋ ㄕˋ zhèng shì 、、 、 具回ㄐㄩˋ ㄏㄨㄟˊ jù huí 應性ㄧㄥ ㄒㄧㄥˋ yīng xìng 的ㄉㄜ˙ de 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 披露ㄆㄧ ㄌㄨˋ pī lù 計畫ㄐㄧˋ ㄏㄨㄚˋ jì huà [[ [ 11 1 ]] ] 。。 。

缺失的脈絡

然而ㄖㄢˊ ㄦˊ rán ér ,, , 該聲ㄍㄞ ㄕㄥ gāi shēng 稱ㄔㄥ chēng 需要ㄒㄩ ㄧㄠˋ xū yào 重要ㄓㄨㄥˋ ㄧㄠˋ zhòng yào 的ㄉㄜ˙ de 背景ㄅㄟˋ ㄐㄧㄥˇ bèi jǐng 資訊來ㄗ ㄒㄩㄣˋ ㄌㄞˊ zī xùn lái 協助ㄒㄧㄝˊ ㄓㄨˋ xié zhù 理解ㄌㄧˇ ㄐㄧㄝˇ lǐ jiě :: :
However, the claim requires significant context that affects interpretation: **Rushed Timeline and Pandemic Response:** The COVIDSafe app was developed in response to an urgent pandemic crisis and was released quickly [3].
** * ** * 倉促ㄘㄤ ㄘㄨˋ cāng cù 的ㄉㄜ˙ de 時間ㄕˊ ㄐㄧㄢ shí jiān 表ㄅㄧㄠˇ biǎo 和ㄏㄜˊ hé 疫情ㄧˋ ㄑㄧㄥˊ yì qíng 應對ㄧㄥ ㄉㄨㄟˋ yīng duì :: : ** * ** * COVIDSafeCOVIDSafe COVIDSafe 應用ㄧㄥ ㄩㄥˋ yīng yòng 程式ㄔㄥˊ ㄕˋ chéng shì 是ㄕˋ shì 為ㄨㄟˋ wèi 了ㄌㄜ˙ le 應ㄧㄥ yīng 對ㄉㄨㄟˋ duì 緊急ㄐㄧㄣˇ ㄐㄧˊ jǐn jí 的ㄉㄜ˙ de 疫情ㄧˋ ㄑㄧㄥˊ yì qíng 危機ㄨㄟ ㄐㄧ wēi jī 而ㄦˊ ér 開發ㄎㄞ ㄈㄚ kāi fā 的ㄉㄜ˙ de ,, , 且ㄑㄧㄝˇ qiě 快速ㄎㄨㄞˋ ㄙㄨˋ kuài sù 發布ㄈㄚ ㄅㄨˋ fā bù [[ [ 33 3 ]] ] 。。 。
The government was developing technology at an unprecedented pace during a public health emergency.
政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 在ㄗㄞˋ zài 公共ㄍㄨㄥ ㄍㄨㄥˋ gōng gòng 衛生ㄨㄟˋ ㄕㄥ wèi shēng 緊ㄐㄧㄣˇ jǐn 急情ㄐㄧˊ ㄑㄧㄥˊ jí qíng 況下ㄎㄨㄤˋ ㄒㄧㄚˋ kuàng xià 以ㄧˇ yǐ 前所未有ㄑㄧㄢˊ ㄙㄨㄛˇ ㄨㄟˋ ㄧㄡˇ qián suǒ wèi yǒu 的ㄉㄜ˙ de 速度ㄙㄨˋ ㄉㄨˋ sù dù 開發ㄎㄞ ㄈㄚ kāi fā 技術ㄐㄧˋ ㄕㄨˋ jì shù 。。 。
While this explains the urgency, it does not excuse the failure to implement industry-standard security practices—in fact, it makes them more important, not less [3]. **Government Accountability vs.
雖然ㄙㄨㄟ ㄖㄢˊ suī rán 這解釋ㄓㄜˋ ㄐㄧㄝˇ ㄕˋ zhè jiě shì 了ㄌㄜ˙ le 緊ㄐㄧㄣˇ jǐn 迫性ㄆㄛˋ ㄒㄧㄥˋ pò xìng ,, , 但ㄉㄢˋ dàn 無法作ㄨˊ ㄈㄚˇ ㄗㄨㄛˋ wú fǎ zuò 為ㄨㄟˋ wèi 未ㄨㄟˋ wèi 實施ㄕˊ ㄕ shí shī 產業ㄔㄢˇ ㄧㄝˋ chǎn yè 標準ㄅㄧㄠ ㄓㄨㄣˇ biāo zhǔn 安全ㄢ ㄑㄩㄢˊ ān quán 實踐ㄕˊ ㄐㄧㄢˋ shí jiàn 的ㄉㄜ˙ de 藉口ㄐㄧㄝˋ ㄎㄡˇ jiè kǒu —— — —— — 事實ㄕˋ ㄕˊ shì shí 上ㄕㄤˋ shàng ,, , 這使ㄓㄜˋ ㄕˇ zhè shǐ 安全ㄢ ㄑㄩㄢˊ ān quán 實踐ㄕˊ ㄐㄧㄢˋ shí jiàn 變得ㄅㄧㄢˋ ㄉㄜˊ biàn dé 更加ㄍㄥˋ ㄐㄧㄚ gèng jiā 重要ㄓㄨㄥˋ ㄧㄠˋ zhòng yào ,, , 而ㄦˊ ér 非ㄈㄟ fēi 較ㄐㄧㄠˋ jiào 不ㄅㄨˋ bù 重要ㄓㄨㄥˋ ㄧㄠˋ zhòng yào [[ [ 33 3 ]] ] 。。 。
Comparative Analysis:** The government did eventually respond to some issues.
** * ** * 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 責任ㄗㄜˊ ㄖㄣˋ zé rèn 與ㄩˇ yǔ 比ㄅㄧˇ bǐ 較ㄐㄧㄠˋ jiào 分析ㄈㄣ ㄒㄧ fēn xī :: : ** * ** * 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 最終ㄗㄨㄟˋ ㄓㄨㄥ zuì zhōng 對ㄉㄨㄟˋ duì 部分ㄅㄨˋ ㄈㄣˋ bù fèn 問題ㄨㄣˋ ㄊㄧˊ wèn tí 做出ㄗㄨㄛˋ ㄔㄨ zuò chū 了ㄌㄜ˙ le 回應ㄏㄨㄟˊ ㄧㄥ huí yīng 。。 。
After the research community identified vulnerabilities, the DTA and Australian Signals Directorate did patch the encryption concurrency flaw, which researchers thanked them for addressing [2].
在ㄗㄞˋ zài 研究ㄧㄢˊ ㄐㄧㄡ yán jiū 社群ㄕㄜˋ ㄑㄩㄣˊ shè qún 識別ㄕˊ ㄅㄧㄝˊ shí bié 出ㄔㄨ chū 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 後ㄏㄡˋ hòu ,, , DTADTA DTA 和澳洲ㄏㄜˊ ㄠˋ ㄓㄡ hé ào zhōu 信號ㄒㄧㄣˋ ㄏㄠˋ xìn hào 局確ㄐㄩˊ ㄑㄩㄝˋ jú què 實修ㄕˊ ㄒㄧㄡ shí xiū 補ㄅㄨˇ bǔ 了ㄌㄜ˙ le 加密ㄐㄧㄚ ㄇㄧˋ jiā mì 並發ㄅㄧㄥˋ ㄈㄚ bìng fā 缺陷ㄑㄩㄝ ㄒㄧㄢˋ quē xiàn ,, , 研究ㄧㄢˊ ㄐㄧㄡ yán jiū 人員ㄖㄣˊ ㄩㄢˊ rén yuán 對ㄉㄨㄟˋ duì 此ㄘˇ cǐ 表示ㄅㄧㄠˇ ㄕˋ biǎo shì 感謝ㄍㄢˇ ㄒㄧㄝˋ gǎn xiè [[ [ 22 2 ]] ] 。。 。
However, the government's initial failure to establish proactive vulnerability disclosure mechanisms meant fixes came reactively rather than systematically. **Comparison to International Standards:** Singapore's contact tracing app (TraceTogether), which Australia modeled COVIDSafe after, demonstrated that faster vulnerability disclosure and more transparent security practices were feasible even in a pandemic context.
然而ㄖㄢˊ ㄦˊ rán ér ,, , 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 最初ㄗㄨㄟˋ ㄔㄨ zuì chū 未能ㄨㄟˋ ㄋㄥˊ wèi néng 建立ㄐㄧㄢˋ ㄌㄧˋ jiàn lì 主動ㄓㄨˇ ㄉㄨㄥˋ zhǔ dòng 的ㄉㄜ˙ de 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 披露ㄆㄧ ㄌㄨˋ pī lù 機制ㄐㄧ ㄓˋ jī zhì ,, , 意味著ㄧˋ ㄨㄟˋ ㄓㄨˋ yì wèi zhù 修ㄒㄧㄡ xiū 復ㄈㄨˋ fù 是ㄕˋ shì 被ㄅㄟˋ bèi 動ㄉㄨㄥˋ dòng 的ㄉㄜ˙ de 而ㄦˊ ér 非系ㄈㄟ ㄒㄧˋ fēi xì 統性ㄊㄨㄥˇ ㄒㄧㄥˋ tǒng xìng 的ㄉㄜ˙ de 。。 。
Similarly, the UK's approach, while not perfect, was significantly more transparent with whitepaper documentation and faster engagement with researchers [1]. **Scale of Impact:** While COVIDSafe's security issues were real, the app ultimately failed to deliver epidemiological value.
** * ** * 與ㄩˇ yǔ 國際ㄍㄨㄛˊ ㄐㄧˋ guó jì 標準ㄅㄧㄠ ㄓㄨㄣˇ biāo zhǔn 的ㄉㄜ˙ de 比ㄅㄧˇ bǐ 較ㄐㄧㄠˋ jiào :: : ** * ** * 澳洲ㄠˋ ㄓㄡ ào zhōu 所ㄙㄨㄛˇ suǒ 參考ㄘㄢ ㄎㄠˇ cān kǎo 的ㄉㄜ˙ de 新加坡ㄒㄧㄣ ㄐㄧㄚ ㄆㄛ xīn jiā pō 接觸ㄐㄧㄝ ㄔㄨˋ jiē chù 者ㄓㄜˇ zhě 追ㄓㄨㄟ zhuī 蹤ㄗㄨㄥ zōng 應ㄧㄥ yīng 用ㄩㄥˋ yòng 程式ㄔㄥˊ ㄕˋ chéng shì (( ( TraceTogetherTraceTogether TraceTogether )) ) 證明ㄓㄥˋ ㄇㄧㄥˊ zhèng míng ,, , 即使ㄐㄧˊ ㄕˇ jí shǐ 在ㄗㄞˋ zài 疫情ㄧˋ ㄑㄧㄥˊ yì qíng 背景ㄅㄟˋ ㄐㄧㄥˇ bèi jǐng 下ㄒㄧㄚˋ xià ,, , 更快ㄍㄥˋ ㄎㄨㄞˋ gèng kuài 的ㄉㄜ˙ de 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 披露ㄆㄧ ㄌㄨˋ pī lù 和ㄏㄜˊ hé 更ㄍㄥˋ gèng 透明ㄊㄡˋ ㄇㄧㄥˊ tòu míng 的ㄉㄜ˙ de 安全ㄢ ㄑㄩㄢˊ ān quán 實踐ㄕˊ ㄐㄧㄢˋ shí jiàn 也ㄧㄝˇ yě 是ㄕˋ shì 可行ㄎㄜˇ ㄒㄧㄥˊ kě xíng 的ㄉㄜ˙ de 。。 。
A confidential government report by independent consultants found that "the utilisation of COVIDSafe...resulted in high transaction costs for state contact tracing teams and produced few benefits" [3].
同樣ㄊㄨㄥˊ ㄧㄤˋ tóng yàng 地ㄉㄧˋ dì ,, , 英國ㄧㄥ ㄍㄨㄛˊ yīng guó 的ㄉㄜ˙ de 做法ㄗㄨㄛˋ ㄈㄚˇ zuò fǎ 雖非ㄙㄨㄟ ㄈㄟ suī fēi 完美ㄨㄢˊ ㄇㄟˇ wán měi ,, , 但ㄉㄢˋ dàn 在ㄗㄞˋ zài 技術ㄐㄧˋ ㄕㄨˋ jì shù 白皮ㄅㄞˊ ㄆㄧˊ bái pí 書ㄕㄨ shū 文件ㄨㄣˊ ㄐㄧㄢˋ wén jiàn 和ㄏㄜˊ hé 與ㄩˇ yǔ 研究ㄧㄢˊ ㄐㄧㄡ yán jiū 人員ㄖㄣˊ ㄩㄢˊ rén yuán 的ㄉㄜ˙ de 更ㄍㄥˋ gèng 快ㄎㄨㄞˋ kuài 互動ㄏㄨˋ ㄉㄨㄥˋ hù dòng 方面ㄈㄤ ㄇㄧㄢˋ fāng miàn 顯著ㄒㄧㄢˇ ㄓㄨˋ xiǎn zhù 更ㄍㄥˋ gèng 為ㄨㄟˋ wèi 透明ㄊㄡˋ ㄇㄧㄥˊ tòu míng [[ [ 11 1 ]] ] 。。 。
By the time the app was decommissioned, it had discovered only two positive cases and 17 close-contacts during its entire period of activity [3].
** * ** * 影響ㄧㄥˇ ㄒㄧㄤˇ yǐng xiǎng 規模ㄍㄨㄟ ㄇㄛˊ guī mó :: : ** * ** * 雖然ㄙㄨㄟ ㄖㄢˊ suī rán COVIDSafeCOVIDSafe COVIDSafe 的ㄉㄜ˙ de 安全ㄢ ㄑㄩㄢˊ ān quán 問題ㄨㄣˋ ㄊㄧˊ wèn tí 是ㄕˋ shì 真實ㄓㄣ ㄕˊ zhēn shí 存在ㄘㄨㄣˊ ㄗㄞˋ cún zài 的ㄉㄜ˙ de ,, , 但ㄉㄢˋ dàn 該ㄍㄞ gāi 應用ㄧㄥ ㄩㄥˋ yīng yòng 程式ㄔㄥˊ ㄕˋ chéng shì 最終ㄗㄨㄟˋ ㄓㄨㄥ zuì zhōng 未能ㄨㄟˋ ㄋㄥˊ wèi néng 提供ㄊㄧˊ ㄍㄨㄥ tí gōng 流行病ㄌㄧㄡˊ ㄒㄧㄥˊ ㄅㄧㄥˋ liú xíng bìng 學價值ㄒㄩㄝˊ ㄐㄧㄚˋ ㄓˊ xué jià zhí 。。 。
The security vulnerabilities, therefore, occurred in an application that was already fundamentally ineffective for its stated purpose.
一份ㄧ ㄈㄣˋ yī fèn 由ㄧㄡˊ yóu 獨立ㄉㄨˊ ㄌㄧˋ dú lì 顧問ㄍㄨˋ ㄨㄣˋ gù wèn 撰ㄓㄨㄢˋ zhuàn 寫ㄒㄧㄝˇ xiě 的ㄉㄜ˙ de 機密ㄐㄧ ㄇㄧˋ jī mì 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 報告ㄅㄠˋ ㄍㄠˋ bào gào 發現ㄈㄚ ㄒㄧㄢˋ fā xiàn ,, , 「「 「 COVIDSafeCOVIDSafe COVIDSafe 的ㄉㄜ˙ de 使用ㄕˇ ㄩㄥˋ shǐ yòng …… … …… … 為州級ㄨㄟˋ ㄓㄡ ㄐㄧˊ wèi zhōu jí 接觸ㄐㄧㄝ ㄔㄨˋ jiē chù 追ㄓㄨㄟ zhuī 蹤ㄗㄨㄥ zōng 團ㄊㄨㄢˊ tuán 隊ㄉㄨㄟˋ duì 帶ㄉㄞˋ dài 來ㄌㄞˊ lái 了ㄌㄜ˙ le 高昂ㄍㄠ ㄤˊ gāo áng 的ㄉㄜ˙ de 交易成本ㄐㄧㄠ ㄧˋ ㄔㄥˊ ㄅㄣˇ jiāo yì chéng běn ,, , 卻產生ㄑㄩㄝˋ ㄔㄢˇ ㄕㄥ què chǎn shēng 了ㄌㄜ˙ le 極少ㄐㄧˊ ㄕㄠˇ jí shǎo 的ㄉㄜ˙ de 效益ㄒㄧㄠˋ ㄧˋ xiào yì 」」 」 [[ [ 33 3 ]] ] 。。 。
到ㄉㄠˋ dào 該ㄍㄞ gāi 應用ㄧㄥ ㄩㄥˋ yīng yòng 程式ㄔㄥˊ ㄕˋ chéng shì 停用ㄊㄧㄥˊ ㄩㄥˋ tíng yòng 時ㄕˊ shí ,, , 在ㄗㄞˋ zài 其ㄑㄧˊ qí 整個ㄓㄥˇ ㄍㄜˋ zhěng gè 活動期ㄏㄨㄛˊ ㄉㄨㄥˋ ㄑㄧ huó dòng qī 間僅ㄐㄧㄢ ㄐㄧㄣˇ jiān jǐn 發現ㄈㄚ ㄒㄧㄢˋ fā xiàn 了ㄌㄜ˙ le 兩個ㄌㄧㄤˇ ㄍㄜˋ liǎng gè 確診ㄑㄩㄝˋ ㄓㄣˇ què zhěn 病例ㄅㄧㄥˋ ㄌㄧˋ bìng lì 和ㄏㄜˊ hé 1717 17 名ㄇㄧㄥˊ míng 密切ㄇㄧˋ ㄑㄧㄝˋ mì qiè 接觸者ㄐㄧㄝ ㄔㄨˋ ㄓㄜˇ jiē chù zhě [[ [ 33 3 ]] ] 。。 。
因此ㄧㄣ ㄘˇ yīn cǐ ,, , 安全漏洞ㄢ ㄑㄩㄢˊ ㄌㄡˋ ㄉㄨㄥˋ ān quán lòu dòng 發生ㄈㄚ ㄕㄥ fā shēng 在ㄗㄞˋ zài 一個ㄧ ㄍㄜˋ yī gè 對ㄉㄨㄟˋ duì 其ㄑㄧˊ qí 既定ㄐㄧˋ ㄉㄧㄥˋ jì dìng 目的ㄇㄨˋ ㄉㄧˋ mù dì 已ㄧˇ yǐ 根本ㄍㄣ ㄅㄣˇ gēn běn 無效ㄨˊ ㄒㄧㄠˋ wú xiào 的ㄉㄜ˙ de 應用ㄧㄥ ㄩㄥˋ yīng yòng 程式ㄔㄥˊ ㄕˋ chéng shì 上ㄕㄤˋ shàng 。。 。

來源可信度評估

提供ㄊㄧˊ ㄍㄨㄥ tí gōng 的ㄉㄜ˙ de 原始ㄩㄢˊ ㄕˇ yuán shǐ 來源ㄌㄞˊ ㄩㄢˊ lái yuán 是ㄕˋ shì 可信ㄎㄜˇ ㄒㄧㄣˋ kě xìn 且ㄑㄧㄝˇ qiě 記錄ㄐㄧˋ ㄌㄨˋ jì lù 完整ㄨㄢˊ ㄓㄥˇ wán zhěng 的ㄉㄜ˙ de :: :
The original sources provided are credible and well-documented: **ZDNET Article [1]:** ZDNET is a mainstream technology publication owned by Ziff Davis Media and is widely recognized as a credible source for technology reporting.
** * ** * ZDNETZDNET ZDNET 文章ㄨㄣˊ ㄓㄤ wén zhāng [[ [ 11 1 ]] ] :: : ** * ** * ZDNETZDNET ZDNET 是ㄕˋ shì ZiffZiff Ziff DavisDavis Davis MediaMedia Media 旗下ㄑㄧˊ ㄒㄧㄚˋ qí xià 的ㄉㄜ˙ de 主流ㄓㄨˇ ㄌㄧㄡˊ zhǔ liú 科技ㄎㄜ ㄐㄧˋ kē jì 出版物ㄔㄨ ㄅㄢˇ ㄨˋ chū bǎn wù ,, , 被ㄅㄟˋ bèi 廣泛ㄍㄨㄤˇ ㄈㄢˋ guǎng fàn 認可為ㄖㄣˋ ㄎㄜˇ ㄨㄟˋ rèn kě wèi 科技ㄎㄜ ㄐㄧˋ kē jì 報導ㄅㄠˋ ㄉㄠˇ bào dǎo 的ㄉㄜ˙ de 可信ㄎㄜˇ ㄒㄧㄣˋ kě xìn 來源ㄌㄞˊ ㄩㄢˊ lái yuán 。。 。
The article by Stilgherrian, a noted technology journalist, is based on direct reporting from Jim Mussared (a security researcher) and Dr.
該文ㄍㄞ ㄨㄣˊ gāi wén 由ㄧㄡˊ yóu 著名ㄓㄨˋ ㄇㄧㄥˊ zhù míng 科技ㄎㄜ ㄐㄧˋ kē jì 記者ㄐㄧˋ ㄓㄜˇ jì zhě StilgherrianStilgherrian Stilgherrian 撰寫ㄓㄨㄢˋ ㄒㄧㄝˇ zhuàn xiě ,, , 基ㄐㄧ jī 於ㄩˊ yú 對ㄉㄨㄟˋ duì 安全ㄢ ㄑㄩㄢˊ ān quán 研究ㄧㄢˊ ㄐㄧㄡ yán jiū 人員ㄖㄣˊ ㄩㄢˊ rén yuán JimJim Jim MussaredMussared Mussared 和備ㄏㄜˊ ㄅㄟˋ hé bèi 受ㄕㄡˋ shòu 尊敬ㄗㄨㄣ ㄐㄧㄥˋ zūn jìng 的ㄉㄜ˙ de 密碼學ㄇㄧˋ ㄇㄚˇ ㄒㄩㄝˊ mì mǎ xué 專家ㄓㄨㄢ ㄐㄧㄚ zhuān jiā VanessaVanessa Vanessa TeagueTeague Teague 博士ㄅㄛˊ ㄕˋ bó shì 的ㄉㄜ˙ de 直接ㄓˊ ㄐㄧㄝ zhí jiē 報導ㄅㄠˋ ㄉㄠˇ bào dǎo 。。 。
Vanessa Teague (a respected cryptographer).
該ㄍㄞ gāi 文章ㄨㄣˊ ㄓㄤ wén zhāng 以事ㄧˇ ㄕˋ yǐ shì 實為ㄕˊ ㄨㄟˋ shí wèi 基礎ㄐㄧ ㄔㄨˇ jī chǔ 並有ㄅㄧㄥˋ ㄧㄡˇ bìng yǒu 文件ㄨㄣˊ ㄐㄧㄢˋ wén jiàn 記錄ㄐㄧˋ ㄌㄨˋ jì lù [[ [ 11 1 ]] ] 。。 。
The article is fact-based and documented [1]. **ITNews Article [2]:** ITNews.com.au is an Australian technology news publication with a solid reputation for accurate reporting.
** * ** * ITNewsITNews ITNews 文章ㄨㄣˊ ㄓㄤ wén zhāng [[ [ 22 2 ]] ] :: : ** * ** * ITNewsITNews ITNews .. . comcom com .. . auau au 是ㄕˋ shì 澳洲ㄠˋ ㄓㄡ ào zhōu 科技ㄎㄜ ㄐㄧˋ kē jì 新聞ㄒㄧㄣ ㄨㄣˊ xīn wén 出版物ㄔㄨ ㄅㄢˇ ㄨˋ chū bǎn wù ,, , 以ㄧˇ yǐ 準確ㄓㄨㄣˇ ㄑㄩㄝˋ zhǔn què 報導ㄅㄠˋ ㄉㄠˇ bào dǎo 著稱ㄓㄨˋ ㄔㄥ zhù chēng 。。 。
The article documents vulnerabilities identified by multiple respected researchers (Chris Culnane, Ben Frengley, Eleanor McMurtry, Jim Mussared, Yaakov Smith, Vanessa Teague, and Alwen Tiu) and is based on their detailed GitHub documentation [2]. **GitHub Documentation [3]:** The GitHub repository maintained by Vanessa Teague and others contains technical analysis and timeline documentation.
該ㄍㄞ gāi 文章ㄨㄣˊ ㄓㄤ wén zhāng 記錄ㄐㄧˋ ㄌㄨˋ jì lù 了ㄌㄜ˙ le 多位ㄉㄨㄛ ㄨㄟˋ duō wèi 受ㄕㄡˋ shòu 尊敬ㄗㄨㄣ ㄐㄧㄥˋ zūn jìng 的ㄉㄜ˙ de 研究ㄧㄢˊ ㄐㄧㄡ yán jiū 人員ㄖㄣˊ ㄩㄢˊ rén yuán (( ( ChrisChris Chris CulnaneCulnane Culnane 、、 、 BenBen Ben FrengleyFrengley Frengley 、、 、 EleanorEleanor Eleanor McMurtryMcMurtry McMurtry 、、 、 JimJim Jim MussaredMussared Mussared 、、 、 YaakovYaakov Yaakov SmithSmith Smith 、、 、 VanessaVanessa Vanessa TeagueTeague Teague 和ㄏㄜˊ hé AlwenAlwen Alwen TiuTiu Tiu )) ) 識別ㄕˊ ㄅㄧㄝˊ shí bié 的ㄉㄜ˙ de 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng ,, , 並基ㄅㄧㄥˋ ㄐㄧ bìng jī 於ㄩˊ yú 他們ㄊㄚ ㄇㄣ˙ tā men 詳細ㄒㄧㄤˊ ㄒㄧˋ xiáng xì 的ㄉㄜ˙ de GitHubGitHub GitHub 文件ㄨㄣˊ ㄐㄧㄢˋ wén jiàn [[ [ 22 2 ]] ] 。。 。
This is a primary source authored by security researchers themselves and is highly credible for understanding what was discovered and when [3].
** * ** * GitHubGitHub GitHub 文件ㄨㄣˊ ㄐㄧㄢˋ wén jiàn [[ [ 33 3 ]] ] :: : ** * ** * VanessaVanessa Vanessa TeagueTeague Teague 等ㄉㄥˇ děng 人維護ㄖㄣˊ ㄨㄟˊ ㄏㄨˋ rén wéi hù 的ㄉㄜ˙ de GitHubGitHub GitHub 儲存庫ㄔㄨˇ ㄘㄨㄣˊ ㄎㄨˋ chǔ cún kù 包含ㄅㄠ ㄏㄢˊ bāo hán 技術ㄐㄧˋ ㄕㄨˋ jì shù 分析ㄈㄣ ㄒㄧ fēn xī 和ㄏㄜˊ hé 時間ㄕˊ ㄐㄧㄢ shí jiān 線ㄒㄧㄢˋ xiàn 文件ㄨㄣˊ ㄐㄧㄢˋ wén jiàn 。。 。
These sources are not partisan advocacy; they are factual reporting by respected technology journalists and cryptography experts documenting security issues in a government application.
這是ㄓㄜˋ ㄕˋ zhè shì 由ㄧㄡˊ yóu 安全ㄢ ㄑㄩㄢˊ ān quán 研究ㄧㄢˊ ㄐㄧㄡ yán jiū 人員ㄖㄣˊ ㄩㄢˊ rén yuán 本人ㄅㄣˇ ㄖㄣˊ běn rén 撰寫ㄓㄨㄢˋ ㄒㄧㄝˇ zhuàn xiě 的ㄉㄜ˙ de 主要ㄓㄨˇ ㄧㄠˋ zhǔ yào 來源ㄌㄞˊ ㄩㄢˊ lái yuán ,, , 對ㄉㄨㄟˋ duì 於ㄩˊ yú 理解ㄌㄧˇ ㄐㄧㄝˇ lǐ jiě 發現ㄈㄚ ㄒㄧㄢˋ fā xiàn 的ㄉㄜ˙ de 內容ㄋㄟˋ ㄖㄨㄥˊ nèi róng 和ㄏㄜˊ hé 時間ㄕˊ ㄐㄧㄢ shí jiān 極具ㄐㄧˊ ㄐㄩˋ jí jù 可信度ㄎㄜˇ ㄒㄧㄣˋ ㄉㄨˋ kě xìn dù [[ [ 33 3 ]] ] 。。 。
這些ㄓㄜˋ ㄒㄧㄝ zhè xiē 來源ㄌㄞˊ ㄩㄢˊ lái yuán 並非ㄅㄧㄥˋ ㄈㄟ bìng fēi 黨ㄉㄤˇ dǎng 派ㄆㄞˋ pài 倡導ㄔㄤˋ ㄉㄠˇ chàng dǎo ;; ; 它們ㄊㄚ ㄇㄣ˙ tā men 是ㄕˋ shì 備受ㄅㄟˋ ㄕㄡˋ bèi shòu 尊敬ㄗㄨㄣ ㄐㄧㄥˋ zūn jìng 的ㄉㄜ˙ de 科技ㄎㄜ ㄐㄧˋ kē jì 記者ㄐㄧˋ ㄓㄜˇ jì zhě 和ㄏㄜˊ hé 密碼學ㄇㄧˋ ㄇㄚˇ ㄒㄩㄝˊ mì mǎ xué 專家ㄓㄨㄢ ㄐㄧㄚ zhuān jiā 記錄ㄐㄧˋ ㄌㄨˋ jì lù 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 應用ㄧㄥ ㄩㄥˋ yīng yòng 程式ㄔㄥˊ ㄕˋ chéng shì 安全ㄢ ㄑㄩㄢˊ ān quán 問題ㄨㄣˋ ㄊㄧˊ wèn tí 的ㄉㄜ˙ de 事實ㄕˋ ㄕˊ shì shí 報導ㄅㄠˋ ㄉㄠˇ bào dǎo 。。 。
⚖️

Labor 比較

** * ** * 工黨ㄍㄨㄥ ㄉㄤˇ gōng dǎng 在ㄗㄞˋ zài 技術ㄐㄧˋ ㄕㄨˋ jì shù 安全ㄢ ㄑㄩㄢˊ ān quán 實踐ㄕˊ ㄐㄧㄢˋ shí jiàn 方面ㄈㄤ ㄇㄧㄢˋ fāng miàn 是否ㄕˋ ㄈㄡˇ shì fǒu 做ㄗㄨㄛˋ zuò 過類ㄍㄨㄛˋ ㄌㄟˋ guò lèi 似的ㄕˋ ㄉㄜ˙ shì de 事情ㄕˋ ㄑㄧㄥˊ shì qíng ?? ?
**Did Labor do something similar with technology security practices?** This question is somewhat difficult to assess directly because Labor was not in power during the COVID-19 pandemic (the Coalition governed 2013-2022, while Labor won the 2022 election).
** * ** *
However, some relevant historical context exists: **Prior Labor Government Technology Initiatives:** During Labor's 2007-2013 period in government, it pursued various technology initiatives with mixed results, including the National Broadband Network (NBN).
這個ㄓㄜˋ ㄍㄜˋ zhè gè 問題ㄨㄣˋ ㄊㄧˊ wèn tí 較ㄐㄧㄠˋ jiào 難ㄋㄢˊ nán 直接ㄓˊ ㄐㄧㄝ zhí jiē 評估ㄆㄧㄥˊ ㄍㄨ píng gū ,, , 因為ㄧㄣ ㄨㄟˋ yīn wèi 工黨ㄍㄨㄥ ㄉㄤˇ gōng dǎng 在ㄗㄞˋ zài COVIDCOVID COVID -- - 1919 19 疫情ㄧˋ ㄑㄧㄥˊ yì qíng 期間ㄑㄧ ㄐㄧㄢ qī jiān 並未ㄅㄧㄥˋ ㄨㄟˋ bìng wèi 執政ㄓˊ ㄓㄥˋ zhí zhèng (( ( 聯盟ㄌㄧㄢˊ ㄇㄥˊ lián méng 黨ㄉㄤˇ dǎng 執政期ㄓˊ ㄓㄥˋ ㄑㄧ zhí zhèng qī 為ㄨㄟˋ wèi 20132013 2013 -- - 20222022 2022 年ㄋㄧㄢˊ nián ,, , 而ㄦˊ ér 工黨ㄍㄨㄥ ㄉㄤˇ gōng dǎng 在ㄗㄞˋ zài 20222022 2022 年大選ㄋㄧㄢˊ ㄉㄚˋ ㄒㄩㄢˇ nián dà xuǎn 中ㄓㄨㄥ zhōng 獲勝ㄏㄨㄛˋ ㄕㄥˋ huò shèng )) ) 。。 。
The NBN project faced criticism for cost overruns and implementation challenges, but these were more related to project management and infrastructure deployment rather than security practices in specific applications [4]. **Proposed Opposition Cyber Security Policies:** During the pandemic, Labor's Shadow Assistant Cyber Security Minister Tim Watts pointed to the UK's model of a "central vulnerability disclosure platform" operated by HackerOne as a better approach [1].
然而ㄖㄢˊ ㄦˊ rán ér ,, , 存在ㄘㄨㄣˊ ㄗㄞˋ cún zài 一些ㄧ ㄒㄧㄝ yī xiē 相關ㄒㄧㄤ ㄍㄨㄢ xiāng guān 的ㄉㄜ˙ de 歷史ㄌㄧˋ ㄕˇ lì shǐ 背景ㄅㄟˋ ㄐㄧㄥˇ bèi jǐng :: :
Labor was proposing such measures as policy, suggesting the opposition recognized that the Coalition's approach was deficient [1].
** * ** * 先前ㄒㄧㄢ ㄑㄧㄢˊ xiān qián 工黨ㄍㄨㄥ ㄉㄤˇ gōng dǎng 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 的ㄉㄜ˙ de 技術ㄐㄧˋ ㄕㄨˋ jì shù 計畫ㄐㄧˋ ㄏㄨㄚˋ jì huà :: : ** * ** * 在ㄗㄞˋ zài 工黨ㄍㄨㄥ ㄉㄤˇ gōng dǎng 20072007 2007 -- - 20132013 2013 年ㄋㄧㄢˊ nián 執政期ㄓˊ ㄓㄥˋ ㄑㄧ zhí zhèng qī 間ㄐㄧㄢ jiān ,, , 推行ㄊㄨㄟ ㄒㄧㄥˊ tuī xíng 了ㄌㄜ˙ le 多項ㄉㄨㄛ ㄒㄧㄤˋ duō xiàng 技術ㄐㄧˋ ㄕㄨˋ jì shù 計畫ㄐㄧˋ ㄏㄨㄚˋ jì huà ,, , 成果ㄔㄥˊ ㄍㄨㄛˇ chéng guǒ 參差ㄘㄢ ㄔㄚˋ cān chà 不齊ㄅㄨˋ ㄑㄧˊ bù qí ,, , 包括ㄅㄠ ㄎㄨㄛˋ bāo kuò 國家ㄍㄨㄛˊ ㄐㄧㄚ guó jiā 寬頻ㄎㄨㄢ ㄆㄧㄣˊ kuān pín 網路ㄨㄤˇ ㄌㄨˋ wǎng lù (( ( NBNNBN NBN )) ) 。。 。
This implies Labor would likely have implemented better practices, but this is a proposed alternative rather than a demonstrated track record. **Government-Wide Security Culture:** There is no evidence that Labor under Albanese government (2022-present) has implemented fundamentally different security practices for critical applications.
NBNNBN NBN 計畫ㄐㄧˋ ㄏㄨㄚˋ jì huà 因ㄧㄣ yīn 成本ㄔㄥˊ ㄅㄣˇ chéng běn 超支ㄔㄠ ㄓ chāo zhī 和ㄏㄜˊ hé 執行ㄓˊ ㄒㄧㄥˊ zhí xíng 挑戰ㄊㄧㄠ ㄓㄢˋ tiāo zhàn 而ㄦˊ ér 受到ㄕㄡˋ ㄉㄠˋ shòu dào 批評ㄆㄧ ㄆㄧㄥˊ pī píng ,, , 但ㄉㄢˋ dàn 這些ㄓㄜˋ ㄒㄧㄝ zhè xiē 問題ㄨㄣˋ ㄊㄧˊ wèn tí 更ㄍㄥˋ gèng 多ㄉㄨㄛ duō 與ㄩˇ yǔ 專案ㄓㄨㄢ ㄢˋ zhuān àn 管理ㄍㄨㄢˇ ㄌㄧˇ guǎn lǐ 和ㄏㄜˊ hé 基礎ㄐㄧ ㄔㄨˇ jī chǔ 設施ㄕㄜˋ ㄕ shè shī 部署ㄅㄨˋ ㄕㄨˇ bù shǔ 相關ㄒㄧㄤ ㄍㄨㄢ xiāng guān ,, , 而ㄦˊ ér 非ㄈㄟ fēi 特定ㄊㄜˋ ㄉㄧㄥˋ tè dìng 應用ㄧㄥ ㄩㄥˋ yīng yòng 程式ㄔㄥˊ ㄕˋ chéng shì 的ㄉㄜ˙ de 安全ㄢ ㄑㄩㄢˊ ān quán 實踐ㄕˊ ㄐㄧㄢˋ shí jiàn [[ [ 44 4 ]] ] 。。 。
The issue appears to be more systemic across Australian government rather than partisan.
** * ** * 提出ㄊㄧˊ ㄔㄨ tí chū 的ㄉㄜ˙ de 反ㄈㄢˇ fǎn 對ㄉㄨㄟˋ duì 黨ㄉㄤˇ dǎng 網路ㄨㄤˇ ㄌㄨˋ wǎng lù 安全ㄢ ㄑㄩㄢˊ ān quán 政策ㄓㄥˋ ㄘㄜˋ zhèng cè :: : ** * ** * 疫情ㄧˋ ㄑㄧㄥˊ yì qíng 期間ㄑㄧ ㄐㄧㄢ qī jiān ,, , 工黨ㄍㄨㄥ ㄉㄤˇ gōng dǎng 影子ㄧㄥˇ ㄗ˙ yǐng zi 助理ㄓㄨˋ ㄌㄧˇ zhù lǐ 網路ㄨㄤˇ ㄌㄨˋ wǎng lù 安全部ㄢ ㄑㄩㄢˊ ㄅㄨˋ ān quán bù 長ㄓㄤˇ zhǎng TimTim Tim WattsWatts Watts 指出ㄓˇ ㄔㄨ zhǐ chū ,, , 英國ㄧㄥ ㄍㄨㄛˊ yīng guó 由ㄧㄡˊ yóu HackerOneHackerOne HackerOne 營運ㄧㄥˊ ㄩㄣˋ yíng yùn 的ㄉㄜ˙ de 「「 「 集中式ㄐㄧˊ ㄓㄨㄥ ㄕˋ jí zhōng shì 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 披露ㄆㄧ ㄌㄨˋ pī lù 平台ㄆㄧㄥˊ ㄊㄞˊ píng tái 」」 」 是ㄕˋ shì 更好ㄍㄥˋ ㄏㄠˇ gèng hǎo 的ㄉㄜ˙ de 做法ㄗㄨㄛˋ ㄈㄚˇ zuò fǎ [[ [ 11 1 ]] ] 。。 。
工黨ㄍㄨㄥ ㄉㄤˇ gōng dǎng 曾ㄘㄥˊ céng 提出ㄊㄧˊ ㄔㄨ tí chū 此類ㄘˇ ㄌㄟˋ cǐ lèi 措施ㄘㄨㄛˋ ㄕ cuò shī 作為ㄗㄨㄛˋ ㄨㄟˋ zuò wèi 政策ㄓㄥˋ ㄘㄜˋ zhèng cè ,, , 暗示ㄢˋ ㄕˋ àn shì 反對ㄈㄢˇ ㄉㄨㄟˋ fǎn duì 黨ㄉㄤˇ dǎng 認為ㄖㄣˋ ㄨㄟˋ rèn wèi 聯盟ㄌㄧㄢˊ ㄇㄥˊ lián méng 黨ㄉㄤˇ dǎng 的ㄉㄜ˙ de 做法ㄗㄨㄛˋ ㄈㄚˇ zuò fǎ 存在ㄘㄨㄣˊ ㄗㄞˋ cún zài 缺陷ㄑㄩㄝ ㄒㄧㄢˋ quē xiàn [[ [ 11 1 ]] ] 。。 。
這ㄓㄜˋ zhè 暗示ㄢˋ ㄕˋ àn shì 工黨ㄍㄨㄥ ㄉㄤˇ gōng dǎng 可能ㄎㄜˇ ㄋㄥˊ kě néng 會ㄏㄨㄟˋ huì 實施ㄕˊ ㄕ shí shī 更好ㄍㄥˋ ㄏㄠˇ gèng hǎo 的ㄉㄜ˙ de 實踐ㄕˊ ㄐㄧㄢˋ shí jiàn ,, , 但ㄉㄢˋ dàn 這是ㄓㄜˋ ㄕˋ zhè shì 提出ㄊㄧˊ ㄔㄨ tí chū 的ㄉㄜ˙ de 替代ㄊㄧˋ ㄉㄞˋ tì dài 方案ㄈㄤ ㄢˋ fāng àn 而ㄦˊ ér 非ㄈㄟ fēi 實際ㄕˊ ㄐㄧˋ shí jì 的ㄉㄜ˙ de 往績ㄨㄤˇ ㄐㄧ wǎng jī 記錄ㄐㄧˋ ㄌㄨˋ jì lù 。。 。
** * ** * 全ㄑㄩㄢˊ quán 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 範圍ㄈㄢˋ ㄨㄟˊ fàn wéi 的ㄉㄜ˙ de 安全ㄢ ㄑㄩㄢˊ ān quán 文化ㄨㄣˊ ㄏㄨㄚˋ wén huà :: : ** * ** * 沒有ㄇㄟˊ ㄧㄡˇ méi yǒu 證據ㄓㄥˋ ㄐㄩˋ zhèng jù 顯示ㄒㄧㄢˇ ㄕˋ xiǎn shì AlbaneseAlbanese Albanese 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 領導ㄌㄧㄥˇ ㄉㄠˇ lǐng dǎo 下ㄒㄧㄚˋ xià 的ㄉㄜ˙ de 工黨ㄍㄨㄥ ㄉㄤˇ gōng dǎng (( ( 20222022 2022 年ㄋㄧㄢˊ nián 至今ㄓˋ ㄐㄧㄣ zhì jīn )) ) 為ㄨㄟˋ wèi 關鍵ㄍㄨㄢ ㄐㄧㄢˋ guān jiàn 應用ㄧㄥ ㄩㄥˋ yīng yòng 程式ㄔㄥˊ ㄕˋ chéng shì 實施ㄕˊ ㄕ shí shī 了ㄌㄜ˙ le 根本ㄍㄣ ㄅㄣˇ gēn běn 不同ㄅㄨˋ ㄊㄨㄥˊ bù tóng 的ㄉㄜ˙ de 安全ㄢ ㄑㄩㄢˊ ān quán 實踐ㄕˊ ㄐㄧㄢˋ shí jiàn 。。 。
這個ㄓㄜˋ ㄍㄜˋ zhè gè 問題ㄨㄣˋ ㄊㄧˊ wèn tí 在ㄗㄞˋ zài 澳洲ㄠˋ ㄓㄡ ào zhōu 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 中ㄓㄨㄥ zhōng 似乎ㄙˋ ㄏㄨ sì hū 更具ㄍㄥˋ ㄐㄩˋ gèng jù 系統性ㄒㄧˋ ㄊㄨㄥˇ ㄒㄧㄥˋ xì tǒng xìng ,, , 而ㄦˊ ér 非黨ㄈㄟ ㄉㄤˇ fēi dǎng 派ㄆㄞˋ pài 之分ㄓ ㄈㄣ zhī fēn 。。 。
🌐

平衡觀點

** * ** * 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 的ㄉㄜ˙ de 立場ㄌㄧˋ ㄔㄤˇ lì chǎng :: : ** * ** * DTADTA DTA 在ㄗㄞˋ zài 疫情ㄧˋ ㄑㄧㄥˊ yì qíng 期間ㄑㄧ ㄐㄧㄢ qī jiān 承受ㄔㄥˊ ㄕㄡˋ chéng shòu 著ㄓㄨˋ zhù 非凡ㄈㄟ ㄈㄢˊ fēi fán 的ㄉㄜ˙ de 時間ㄕˊ ㄐㄧㄢ shí jiān 壓力ㄧㄚ ㄌㄧˋ yā lì 。。 。
**The Government's Position:** The DTA acted under extraordinary time pressure during a pandemic.
建立ㄐㄧㄢˋ ㄌㄧˋ jiàn lì 正式ㄓㄥˋ ㄕˋ zhèng shì 的ㄉㄜ˙ de 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 賞金計畫ㄕㄤˇ ㄐㄧㄣ ㄐㄧˋ ㄏㄨㄚˋ shǎng jīn jì huà 和ㄏㄜˊ hé 發布ㄈㄚ ㄅㄨˋ fā bù 全面ㄑㄩㄢˊ ㄇㄧㄢˋ quán miàn 的ㄉㄜ˙ de 安全ㄢ ㄑㄩㄢˊ ān quán 文件ㄨㄣˊ ㄐㄧㄢˋ wén jiàn 通常ㄊㄨㄥ ㄔㄤˊ tōng cháng 需要ㄒㄩ ㄧㄠˋ xū yào 數週ㄕㄨˋ ㄓㄡ shù zhōu 或數ㄏㄨㄛˋ ㄕㄨˋ huò shù 月ㄩㄝˋ yuè 的ㄉㄜ˙ de 流程ㄌㄧㄡˊ ㄔㄥˊ liú chéng 。。 。
Establishing formal bug bounty programs and publishing comprehensive security documentation requires processes that typically take weeks or months.
政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 優ㄧㄡ yōu 先考ㄒㄧㄢ ㄎㄠˇ xiān kǎo 慮ㄌㄩˋ lǜ 快速ㄎㄨㄞˋ ㄙㄨˋ kuài sù 部署ㄅㄨˋ ㄕㄨˇ bù shǔ ,, , 而ㄦˊ ér 非ㄈㄟ fēi 在ㄗㄞˋ zài 理想ㄌㄧˇ ㄒㄧㄤˇ lǐ xiǎng 情況ㄑㄧㄥˊ ㄎㄨㄤˋ qíng kuàng 下應ㄒㄧㄚˋ ㄧㄥ xià yīng 有ㄧㄡˇ yǒu 的ㄉㄜ˙ de 分層ㄈㄣ ㄘㄥˊ fēn céng 安全ㄢ ㄑㄩㄢˊ ān quán 實踐ㄕˊ ㄐㄧㄢˋ shí jiàn 。。 。
The government prioritized rapid deployment over the layered security practices that would have been ideal under normal circumstances. **However, This Does Not Excuse the Approach:** International comparison shows that transparent security practices are not incompatible with rapid deployment.
** * ** * 然而ㄖㄢˊ ㄦˊ rán ér ,, , 這並ㄓㄜˋ ㄅㄧㄥˋ zhè bìng 不能ㄅㄨˋ ㄋㄥˊ bù néng 為ㄨㄟˋ wèi 其ㄑㄧˊ qí 做法ㄗㄨㄛˋ ㄈㄚˇ zuò fǎ 開脫ㄎㄞ ㄊㄨㄛ kāi tuō :: : ** * ** * 國際ㄍㄨㄛˊ ㄐㄧˋ guó jì 比較ㄅㄧˇ ㄐㄧㄠˋ bǐ jiào 顯示ㄒㄧㄢˇ ㄕˋ xiǎn shì ,, , 透明ㄊㄡˋ ㄇㄧㄥˊ tòu míng 的ㄉㄜ˙ de 安全ㄢ ㄑㄩㄢˊ ān quán 實踐ㄕˊ ㄐㄧㄢˋ shí jiàn 與ㄩˇ yǔ 快速ㄎㄨㄞˋ ㄙㄨˋ kuài sù 部署ㄅㄨˋ ㄕㄨˇ bù shǔ 並非ㄅㄧㄥˋ ㄈㄟ bìng fēi 互斥ㄏㄨˋ ㄔˋ hù chì 。。 。
Singapore and the UK both released more comprehensive documentation and established faster communication channels with researchers, even during the same pandemic emergency [1].
新加坡ㄒㄧㄣ ㄐㄧㄚ ㄆㄛ xīn jiā pō 和ㄏㄜˊ hé 英國ㄧㄥ ㄍㄨㄛˊ yīng guó 都ㄉㄡ dōu 發布ㄈㄚ ㄅㄨˋ fā bù 了ㄌㄜ˙ le 更ㄍㄥˋ gèng 全面ㄑㄩㄢˊ ㄇㄧㄢˋ quán miàn 的ㄉㄜ˙ de 文件ㄨㄣˊ ㄐㄧㄢˋ wén jiàn ,, , 並與ㄅㄧㄥˋ ㄩˇ bìng yǔ 研究ㄧㄢˊ ㄐㄧㄡ yán jiū 人員ㄖㄣˊ ㄩㄢˊ rén yuán 建立ㄐㄧㄢˋ ㄌㄧˋ jiàn lì 了ㄌㄜ˙ le 更ㄍㄥˋ gèng 快ㄎㄨㄞˋ kuài 的ㄉㄜ˙ de 溝通ㄍㄡ ㄊㄨㄥ gōu tōng 管道ㄍㄨㄢˇ ㄉㄠˋ guǎn dào ,, , 即使ㄐㄧˊ ㄕˇ jí shǐ 在ㄗㄞˋ zài 相同ㄒㄧㄤ ㄊㄨㄥˊ xiāng tóng 的ㄉㄜ˙ de 疫情ㄧˋ ㄑㄧㄥˊ yì qíng 緊ㄐㄧㄣˇ jǐn 急情ㄐㄧˊ ㄑㄧㄥˊ jí qíng 況下ㄎㄨㄤˋ ㄒㄧㄚˋ kuàng xià 也ㄧㄝˇ yě 是ㄕˋ shì 如此ㄖㄨˊ ㄘˇ rú cǐ [[ [ 11 1 ]] ] 。。 。
The "it was urgent" explanation provides context but does not justify abandoning industry-standard security practices entirely. **The Broader Systemic Issue:** The academic analysis of Australia's COVID technology ecosystem suggests this was part of a broader problem: "Australia's choice to advertise and design visual indicators of security—e.g., a 'green tick' for check ins—persistently came at the cost of strong cryptographic protections" [3].
「「 「 當時ㄉㄤ ㄕˊ dāng shí 很ㄏㄣˇ hěn 緊急ㄐㄧㄣˇ ㄐㄧˊ jǐn jí 」」 」 的ㄉㄜ˙ de 解釋ㄐㄧㄝˇ ㄕˋ jiě shì 提供ㄊㄧˊ ㄍㄨㄥ tí gōng 了ㄌㄜ˙ le 背景ㄅㄟˋ ㄐㄧㄥˇ bèi jǐng ,, , 但ㄉㄢˋ dàn 不能ㄅㄨˋ ㄋㄥˊ bù néng 作為ㄗㄨㄛˋ ㄨㄟˋ zuò wèi 完全ㄨㄢˊ ㄑㄩㄢˊ wán quán 放棄ㄈㄤˋ ㄑㄧˋ fàng qì 產業ㄔㄢˇ ㄧㄝˋ chǎn yè 標準ㄅㄧㄠ ㄓㄨㄣˇ biāo zhǔn 安全ㄢ ㄑㄩㄢˊ ān quán 實踐ㄕˊ ㄐㄧㄢˋ shí jiàn 的ㄉㄜ˙ de 藉口ㄐㄧㄝˋ ㄎㄡˇ jiè kǒu 。。 。
This represents not just a matter of timeline pressure but a fundamental philosophical difference in approaching security. **Key Distinction:** Choosing security best practices is not a luxury add-on; it's foundational.
** * ** * 更廣泛ㄍㄥˋ ㄍㄨㄤˇ ㄈㄢˋ gèng guǎng fàn 的ㄉㄜ˙ de 系ㄒㄧˋ xì 統性ㄊㄨㄥˇ ㄒㄧㄥˋ tǒng xìng 問題ㄨㄣˋ ㄊㄧˊ wèn tí :: : ** * ** * 對ㄉㄨㄟˋ duì 澳洲ㄠˋ ㄓㄡ ào zhōu COVIDCOVID COVID 技術ㄐㄧˋ ㄕㄨˋ jì shù 生態ㄕㄥ ㄊㄞˋ shēng tài 系統ㄒㄧˋ ㄊㄨㄥˇ xì tǒng 的ㄉㄜ˙ de 學術ㄒㄩㄝˊ ㄕㄨˋ xué shù 分析表明ㄈㄣ ㄒㄧ ㄅㄧㄠˇ ㄇㄧㄥˊ fēn xī biǎo míng ,, , 這是ㄓㄜˋ ㄕˋ zhè shì 更ㄍㄥˋ gèng 廣泛ㄍㄨㄤˇ ㄈㄢˋ guǎng fàn 問題ㄨㄣˋ ㄊㄧˊ wèn tí 的ㄉㄜ˙ de 一部分ㄧ ㄅㄨˋ ㄈㄣˋ yī bù fèn :: : 「「 「 澳洲ㄠˋ ㄓㄡ ào zhōu 選擇ㄒㄩㄢˇ ㄗㄜˊ xuǎn zé 宣傳ㄒㄩㄢ ㄔㄨㄢˊ xuān chuán 和ㄏㄜˊ hé 設計ㄕㄜˋ ㄐㄧˋ shè jì 安全ㄢ ㄑㄩㄢˊ ān quán 視覺ㄕˋ ㄐㄩㄝˊ shì jué 指標ㄓˇ ㄅㄧㄠ zhǐ biāo —— — —— — 例如ㄌㄧˋ ㄖㄨˊ lì rú 簽到ㄑㄧㄢ ㄉㄠˋ qiān dào 時ㄕˊ shí 的ㄉㄜ˙ de 『『 『 綠色ㄌㄩˋ ㄙㄜˋ lǜ sè 勾號ㄍㄡ ㄏㄠˋ gōu hào 』』 』 —— — —— — 卻始ㄑㄩㄝˋ ㄕˇ què shǐ 終以ㄓㄨㄥ ㄧˇ zhōng yǐ 犧牲ㄒㄧ ㄕㄥ xī shēng 強大ㄑㄧㄤˊ ㄉㄚˋ qiáng dà 的ㄉㄜ˙ de 加密ㄐㄧㄚ ㄇㄧˋ jiā mì 保護ㄅㄠˇ ㄏㄨˋ bǎo hù 為代價ㄨㄟˋ ㄉㄞˋ ㄐㄧㄚˋ wèi dài jià 」」 」 [[ [ 33 3 ]] ] 。。 。
The government's failure to implement formal vulnerability disclosure, publish complete code, or establish bug bounty programs meant that: - Security issues were discovered by external researchers and reported to unresponsive government agencies - Fixes were implemented reactively rather than proactively - The government didn't benefit from crowdsourced security auditing - Public trust was eroded by poor security practices
這不僅ㄓㄜˋ ㄅㄨˋ ㄐㄧㄣˇ zhè bù jǐn 是ㄕˋ shì 時間ㄕˊ ㄐㄧㄢ shí jiān 壓力ㄧㄚ ㄌㄧˋ yā lì 的ㄉㄜ˙ de 問題ㄨㄣˋ ㄊㄧˊ wèn tí ,, , 更是ㄍㄥˋ ㄕˋ gèng shì 處理ㄔㄨˋ ㄌㄧˇ chù lǐ 安全ㄢ ㄑㄩㄢˊ ān quán 問題ㄨㄣˋ ㄊㄧˊ wèn tí 時ㄕˊ shí 根本ㄍㄣ ㄅㄣˇ gēn běn 哲學ㄓㄜˊ ㄒㄩㄝˊ zhé xué 差異ㄔㄚˋ ㄧˋ chà yì 的ㄉㄜ˙ de 體現ㄊㄧˇ ㄒㄧㄢˋ tǐ xiàn 。。 。
** * ** * 關鍵ㄍㄨㄢ ㄐㄧㄢˋ guān jiàn 區別ㄑㄩ ㄅㄧㄝˊ qū bié :: : ** * ** * 選擇ㄒㄩㄢˇ ㄗㄜˊ xuǎn zé 安全ㄢ ㄑㄩㄢˊ ān quán 最佳ㄗㄨㄟˋ ㄐㄧㄚ zuì jiā 實踐ㄕˊ ㄐㄧㄢˋ shí jiàn 並非ㄅㄧㄥˋ ㄈㄟ bìng fēi 奢侈ㄕㄜ ㄔˇ shē chǐ 的ㄉㄜ˙ de 附加ㄈㄨˋ ㄐㄧㄚ fù jiā 功能ㄍㄨㄥ ㄋㄥˊ gōng néng ;; ; 它ㄊㄚ tā 是ㄕˋ shì 基礎ㄐㄧ ㄔㄨˇ jī chǔ 性ㄒㄧㄥˋ xìng 的ㄉㄜ˙ de 。。 。
政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 未能ㄨㄟˋ ㄋㄥˊ wèi néng 實施ㄕˊ ㄕ shí shī 正式ㄓㄥˋ ㄕˋ zhèng shì 的ㄉㄜ˙ de 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 披露ㄆㄧ ㄌㄨˋ pī lù 、、 、 發布ㄈㄚ ㄅㄨˋ fā bù 完整ㄨㄢˊ ㄓㄥˇ wán zhěng 的ㄉㄜ˙ de 程式ㄔㄥˊ ㄕˋ chéng shì 碼ㄇㄚˇ mǎ ,, , 或ㄏㄨㄛˋ huò 建立ㄐㄧㄢˋ ㄌㄧˋ jiàn lì 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 賞金計畫ㄕㄤˇ ㄐㄧㄣ ㄐㄧˋ ㄏㄨㄚˋ shǎng jīn jì huà ,, , 意味著ㄧˋ ㄨㄟˋ ㄓㄨˋ yì wèi zhù :: :
-- - 安全ㄢ ㄑㄩㄢˊ ān quán 問題ㄨㄣˋ ㄊㄧˊ wèn tí 由ㄧㄡˊ yóu 外部ㄨㄞˋ ㄅㄨˋ wài bù 研究ㄧㄢˊ ㄐㄧㄡ yán jiū 人員ㄖㄣˊ ㄩㄢˊ rén yuán 發現ㄈㄚ ㄒㄧㄢˋ fā xiàn 並回ㄅㄧㄥˋ ㄏㄨㄟˊ bìng huí 報給ㄅㄠˋ ㄍㄟˇ bào gěi 回應ㄏㄨㄟˊ ㄧㄥ huí yīng 不積極ㄅㄨˋ ㄐㄧ ㄐㄧˊ bù jī jí 的ㄉㄜ˙ de 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 機構ㄐㄧ ㄍㄡˋ jī gòu
-- - 修ㄒㄧㄡ xiū 復ㄈㄨˋ fù 是ㄕˋ shì 被ㄅㄟˋ bèi 動ㄉㄨㄥˋ dòng 的ㄉㄜ˙ de 而ㄦˊ ér 非主動ㄈㄟ ㄓㄨˇ ㄉㄨㄥˋ fēi zhǔ dòng 的ㄉㄜ˙ de
-- - 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 無法ㄨˊ ㄈㄚˇ wú fǎ 受益ㄕㄡˋ ㄧˋ shòu yì 於ㄩˊ yú 群眾ㄑㄩㄣˊ ㄓㄨㄥˋ qún zhòng 外包ㄨㄞˋ ㄅㄠ wài bāo 的ㄉㄜ˙ de 安全ㄢ ㄑㄩㄢˊ ān quán 審計ㄕㄣˇ ㄐㄧˋ shěn jì
-- - 公眾ㄍㄨㄥ ㄓㄨㄥˋ gōng zhòng 信任ㄒㄧㄣˋ ㄖㄣˋ xìn rèn 因ㄧㄣ yīn 不良ㄅㄨˋ ㄌㄧㄤˊ bù liáng 的ㄉㄜ˙ de 安全ㄢ ㄑㄩㄢˊ ān quán 實踐ㄕˊ ㄐㄧㄢˋ shí jiàn 而ㄦˊ ér 受到ㄕㄡˋ ㄉㄠˋ shòu dào 侵蝕ㄑㄧㄣ ㄕˊ qīn shí

真實

8.5

/ 10

聯盟ㄌㄧㄢˊ ㄇㄥˊ lián méng 黨ㄉㄤˇ dǎng 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 在ㄗㄞˋ zài 部署ㄅㄨˋ ㄕㄨˇ bù shǔ COVIDSafeCOVIDSafe COVIDSafe 應用ㄧㄥ ㄩㄥˋ yīng yòng 程式ㄔㄥˊ ㄕˋ chéng shì 時確ㄕˊ ㄑㄩㄝˋ shí què 實忽視ㄕˊ ㄏㄨ ㄕˋ shí hū shì 了ㄌㄜ˙ le 安全ㄢ ㄑㄩㄢˊ ān quán 最佳ㄗㄨㄟˋ ㄐㄧㄚ zuì jiā 實踐ㄕˊ ㄐㄧㄢˋ shí jiàn 。。 。
The Coalition government did ignore security best practices when deploying the COVIDSafe app.
政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 選擇ㄒㄩㄢˇ ㄗㄜˊ xuǎn zé 不ㄅㄨˋ bù 建立ㄐㄧㄢˋ ㄌㄧˋ jiàn lì 正式ㄓㄥˋ ㄕˋ zhèng shì 的ㄉㄜ˙ de 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 賞金計畫ㄕㄤˇ ㄐㄧㄣ ㄐㄧˋ ㄏㄨㄚˋ shǎng jīn jì huà [[ [ 11 1 ]] ] ,, , 未即ㄨㄟˋ ㄐㄧˊ wèi jí 時ㄕˊ shí 發布ㄈㄚ ㄅㄨˋ fā bù 完整ㄨㄢˊ ㄓㄥˇ wán zhěng 的ㄉㄜ˙ de 原始ㄩㄢˊ ㄕˇ yuán shǐ 碼ㄇㄚˇ mǎ (( ( 僅發布ㄐㄧㄣˇ ㄈㄚ ㄅㄨˋ jǐn fā bù 應用ㄧㄥ ㄩㄥˋ yīng yòng 程式ㄔㄥˊ ㄕˋ chéng shì 碼ㄇㄚˇ mǎ ,, , 未ㄨㄟˋ wèi 發布ㄈㄚ ㄅㄨˋ fā bù 伺服器ㄘˋ ㄈㄨˊ ㄑㄧˋ cì fú qì 程式ㄔㄥˊ ㄕˋ chéng shì 碼ㄇㄚˇ mǎ )) ) [[ [ 11 1 ]] ] ,, , 且ㄑㄧㄝˇ qiě 未能ㄨㄟˋ ㄋㄥˊ wèi néng 建立ㄐㄧㄢˋ ㄌㄧˋ jiàn lì 具回ㄐㄩˋ ㄏㄨㄟˊ jù huí 應性ㄧㄥ ㄒㄧㄥˋ yīng xìng 的ㄉㄜ˙ de 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng 披露ㄆㄧ ㄌㄨˋ pī lù 流程ㄌㄧㄡˊ ㄔㄥˊ liú chéng [[ [ 11 1 ]] ] 。。 。
The government chose not to establish a formal bug bounty program [1], did not promptly publish complete source code (only app code, not server code) [1], and failed to establish responsive vulnerability disclosure processes [1].
這些ㄓㄜˋ ㄒㄧㄝ zhè xiē 漏洞ㄌㄡˋ ㄉㄨㄥˋ lòu dòng —— — —— — 包括ㄅㄠ ㄎㄨㄛˋ bāo kuò CVECVE CVE -- - 20202020 2020 -- - 1429214292 14292 、、 、 CVECVE CVE -- - 20202020 2020 -- - 1285612856 12856 、、 、 藍牙訊息ㄌㄢˊ ㄧㄚˊ ㄒㄩㄣˋ ㄒㄧ lán yá xùn xī 亂碼ㄌㄨㄢˋ ㄇㄚˇ luàn mǎ 以及ㄧˇ ㄐㄧˊ yǐ jí 加密ㄐㄧㄚ ㄇㄧˋ jiā mì 並發ㄅㄧㄥˋ ㄈㄚ bìng fā 缺陷ㄑㄩㄝ ㄒㄧㄢˋ quē xiàn —— — —— — 是ㄕˋ shì 由ㄧㄡˊ yóu 研究ㄧㄢˊ ㄐㄧㄡ yán jiū 人員ㄖㄣˊ ㄩㄢˊ rén yuán 隨時間ㄙㄨㄟˊ ㄕˊ ㄐㄧㄢ suí shí jiān 發現ㄈㄚ ㄒㄧㄢˋ fā xiàn 並回ㄅㄧㄥˋ ㄏㄨㄟˊ bìng huí 報給ㄅㄠˋ ㄍㄟˇ bào gěi 回應ㄏㄨㄟˊ ㄧㄥ huí yīng 不積極ㄅㄨˋ ㄐㄧ ㄐㄧˊ bù jī jí 的ㄉㄜ˙ de 政府ㄓㄥˋ ㄈㄨˇ zhèng fǔ 機構ㄐㄧ ㄍㄡˋ jī gòu 的ㄉㄜ˙ de [[ [ 11 1 ]] ] [[ [ 22 2 ]] ] 。。 。
These vulnerabilities—including CVE-2020-14292, CVE-2020-12856, Bluetooth message garbling, and encryption concurrency flaws—were discovered by researchers over time and reported to an unresponsive government apparatus [1][2].
國際ㄍㄨㄛˊ ㄐㄧˋ guó jì 比ㄅㄧˇ bǐ 較ㄐㄧㄠˋ jiào (( ( 新加坡ㄒㄧㄣ ㄐㄧㄚ ㄆㄛ xīn jiā pō 、、 、 英國ㄧㄥ ㄍㄨㄛˊ yīng guó )) ) 證明ㄓㄥˋ ㄇㄧㄥˊ zhèng míng 這些ㄓㄜˋ ㄒㄧㄝ zhè xiē 是ㄕˋ shì 選擇ㄒㄩㄢˇ ㄗㄜˊ xuǎn zé 上ㄕㄤˋ shàng 的ㄉㄜ˙ de 失誤ㄕ ㄨˋ shī wù ,, , 而ㄦˊ ér 非ㄈㄟ fēi 必要性ㄅㄧˋ ㄧㄠˋ ㄒㄧㄥˋ bì yào xìng [[ [ 11 1 ]] ] [[ [ 33 3 ]] ] 。。 。
International comparisons (Singapore, UK) demonstrate these were failures of choice, not necessity [1][3].

📚 來源與引用 (6)

  1. 1
    zdnet.com

    zdnet.com

    Best practice would suggest that making source code available and responding quickly to reported vulnerabilities is a given for government apps, but not yet in Australia.

    ZDNET
  2. 2
    itwire.com

    itwire.com

    A number of researchers have detailed four major vulnerabilities in the Australian Government's COVIDSafe application for the iPhone and Android systems, and advised users to upgrade at once. The main patches issued were to fix: A bug in the way COVIDSafe reads Bluetooth messages on iPhones. Thi...

    Researchers outline flaws in COVIDSafe app, urge users to upgrade
  3. 3
    arxiv.org

    arxiv.org

    Arxiv

  4. 4
    PDF

    report on the operation and effectiveness of covidsafe and the national covidsafe data store 0

    Health Gov • PDF Document
  5. 5
    ncbi.nlm.nih.gov

    ncbi.nlm.nih.gov

    Timely and effective contact tracing is an essential public health measure for curbing the transmission of COVID-19. App-based contact tracing has the potential to optimize the resources of overstretched public health departments. However, its ...

    PubMed Central (PMC)
  6. 6
    pmc.ncbi.nlm.nih.gov

    pmc.ncbi.nlm.nih.gov

    The global and national response to the COVID-19 pandemic has been inadequate due to a collective lack of preparation and a shortage of available tools for responding to a large-scale pandemic. By applying lessons learned to create better ...

    PubMed Central (PMC)

評分量表方法論

1-3: 虛假

事實不正確或惡意捏造。

4-6: 部分

有部分真實性,但缺乏或扭曲了背景。

7-9: 大致屬實

微小的技術性問題或措辭問題。

10: 準確

完美驗證且在情境上公正。

方法論: 評分通過交叉比對官方政府記錄、獨立事實查核組織和原始來源文件來確定。