<?xml version="1.0" encoding="UTF-8"?>




<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
	<channel>
		<title>Public Address | Cafe | OnPoint: #WTFMSD: &quot;Damning&quot;</title>
		<link>https://publicaddress.net/system/cafe/</link>
		<atom:link rel="self" href="https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/rss/" type="application/rss+xml"/>
		
		<description><![CDATA[A talking shop where we put the questions and our community illuminates the issues.]]></description>
			<language>en-us</language>
			<copyright>Copyright (c) 2026 Public Address</copyright>
			

		
			<item>
				<title>Tim Michie</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=277601#post277601</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=277601#post277601</guid>
				<description><![CDATA[
						<a href="http://www.radionz.co.nz/national/programmes/ninetonoon/audio/2541063/brendan-boyle.asx" target="_blank" rel="noopener noreferrer">Brendan Boyle, the head of NZ's largest government department addresses concerns about information systems security</a>.
					]]></description>
				<pubDate>Mon, 10 Dec 2012 10:39:57 +1300</pubDate>
			</item>
		
			<item>
				<title>Sacha</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274352#post274352</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274352#post274352</guid>
				<description><![CDATA[
						<p><q>But they're still quite certain there's been no privacy breach</q></p><p>Bennett repeated that claim to Parliament in <a href="http://www.parliament.nz/en-NZ/PB/Business/QOA/2/f/3/00HOH_OralQuestions-List-of-questions-for-oral-answer.htm" target="_blank" rel="noopener noreferrer">Question Time</a> today when asked (in a Supplementary to Q5) about the comment on this thread by someone other than Keith or Ira about also having accessed the network through the kiosk flaw.</p>
					]]></description>
				<pubDate>Tue, 06 Nov 2012 14:57:40 +1300</pubDate>
			</item>
		
			<item>
				<title>TracyMac</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274350#post274350</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274350#post274350</guid>
				<description><![CDATA[
						<p>Yup, I'm still keen on wielding the good-old <em>carefully-selected</em> cc when necessary. People don't grump at you if you don't default to the scattershot approach.</p><p>As long as someone in your management chain or the organisation's Security group is included, you're covered. Especially in these days of email journalling and…</p>
					]]></description>
				<pubDate>Tue, 06 Nov 2012 14:30:25 +1300</pubDate>
			</item>
		
			<item>
				<title>BenWilson</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274178#post274178</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274178#post274178</guid>
				<description><![CDATA[
						<p><q>But they're still quite certain there's been no privacy breach.</q></p><p>I thought they just had no evidence of it. It's on the public if they can't tell the difference between "No evidence of x" and "Evidence of no x". Ironically, since the term "conspiracy theory" came into existence, there's been…</p>
					]]></description>
				<pubDate>Sun, 04 Nov 2012 17:23:54 +1300</pubDate>
			</item>
		
			<item>
				<title>Matthew Poole</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274176#post274176</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274176#post274176</guid>
				<description><![CDATA[
						<p><a href="http://www.nzherald.co.nz/politics/news/article.cfm?c_id=280&amp;objectid=10844736" target="_blank" rel="noopener noreferrer">In today's news</a>:<q><br />Computer terminals used for <strong>13 years</strong> by job seekers at Work and Income offices had the same security flaw as the self-service kiosks at the centre of the major privacy breach at Winz.<br /></q></p><p>But they're still quite certain there's been no privacy breach.</p>
					]]></description>
				<pubDate>Sun, 04 Nov 2012 16:17:49 +1300</pubDate>
			</item>
		
			<item>
				<title>Marc C</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274150#post274150</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274150#post274150</guid>
				<description><![CDATA[
						John &ndash; You are soo right! The same is happening at ACC. There was all this fuss about the privacy leaks, and Pullar going into a meeting with management to negotiate a settlement, while telling them she was sent sensitive info about so many hundreds or more other clients. Heads…
					]]></description>
				<pubDate>Sat, 03 Nov 2012 22:23:15 +1300</pubDate>
			</item>
		
			<item>
				<title>Marc C</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274147#post274147</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274147#post274147</guid>
				<description><![CDATA[
						<p>Welcome to "Ringfenced MSD" and "Ringfenced WINZ"! </p><p>This is a hugely sick joke and scandal what is going on. So 4 junior staff members are to blame for it all, for supposed "sloppiness"? How many did warn them (MSD) over the last 2 years, and who was in charge? How…</p>
					]]></description>
				<pubDate>Sat, 03 Nov 2012 22:12:24 +1300</pubDate>
			</item>
		
			<item>
				<title>Keith Ng</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274123#post274123</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274123#post274123</guid>
				<description><![CDATA[
						<p><q> the traditional approach would have been to send a memo or email cc'd to everyone the sender can think of. This might well provide effective blame transference. But that's unfashionable nowadays.</q></p><p>Ass-covering CCing never goes out of fashion. In fact, I imagine lawyers for the four people under the gun…</p>
					]]></description>
				<pubDate>Sat, 03 Nov 2012 15:04:29 +1300</pubDate>
			</item>
		
			<item>
				<title>Keith Ng</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274121#post274121</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274121#post274121</guid>
				<description><![CDATA[
						<p><q>That looks pretty damned searchable to me, if one had a spot of inside info.</q></p><p>Those file names were from the case files server logs. The case file server itself was inaccessible. Most of my grabs were from the invoice server, which was unsorted and unnamed.</p>
					]]></description>
				<pubDate>Sat, 03 Nov 2012 14:35:26 +1300</pubDate>
			</item>
		
			<item>
				<title>Sacha</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274114#post274114</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274114#post274114</guid>
				<description><![CDATA[
						Putting in place and overseeing project risk and escalation processes is not the job of those at the bottom. Poor governance is a big problem throughout NZ organisations.
					]]></description>
				<pubDate>Sat, 03 Nov 2012 12:41:21 +1300</pubDate>
			</item>
		
			<item>
				<title>BenWilson</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274112#post274112</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274112#post274112</guid>
				<description><![CDATA[
						<p><q>What if "they" aren't as incompetent as you suspect, and they do indeed detect that you have more data than you admitted...</q></p><p>The pile of legal doo-doo would be roughly the same as the pile involved in taking the documents that actually were sensitive, by the thousands. If they were…</p>
					]]></description>
				<pubDate>Sat, 03 Nov 2012 12:25:19 +1300</pubDate>
			</item>
		
			<item>
				<title>Rich of Observationz</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274107#post274107</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274107#post274107</guid>
				<description><![CDATA[
						<p>There are a bunch of ways something could be escalated:<br />&ndash; at an extreme, a bearded, scrofulous sysadmin (for it would be he) could have entered a senior managers office and screamed at the person until he took steps to rectify the problem<br />&ndash; at another extreme, managers could have…</p>
					]]></description>
				<pubDate>Sat, 03 Nov 2012 11:31:48 +1300</pubDate>
			</item>
		
			<item>
				<title>FletcherB</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274105#post274105</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274105#post274105</guid>
				<description><![CDATA[
						<p>Ben,</p><p>What if "they" aren't as incompetent as you suspect, and they do indeed detect that you have more data than you admitted...</p><p>Then you could be in a pile of legal doo-doo...</p>
					]]></description>
				<pubDate>Sat, 03 Nov 2012 11:00:02 +1300</pubDate>
			</item>
		
			<item>
				<title>BenWilson</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274092#post274092</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274092#post274092</guid>
				<description><![CDATA[
						<p><q>except oneself, grasshopper</q></p><p>Sure, although from a personal ethical point of view, you'd know:<br />1) The data was harmless<br />2) You had already seen it<br />3) You did not intend to use it, because of 1) and 2), for any other purpose than establishing whether incompetence was followed by cover…</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 22:32:34 +1300</pubDate>
			</item>
		
			<item>
				<title>Karen Adams</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274091#post274091</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274091#post274091</guid>
				<description><![CDATA[
						But they do not if you include all paperwork submitted by beneficiaries.  Seems to me that would be vaguely classified as a record.  They have policies about what they scan in so not everything is kept (and hard copies are not always kept either).
					]]></description>
				<pubDate>Fri, 02 Nov 2012 22:27:22 +1300</pubDate>
			</item>
		
			<item>
				<title>Sacha</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274090#post274090</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274090#post274090</guid>
				<description><![CDATA[
						<p><q>no one would ever know</q></p><p>except oneself, grasshopper</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 22:12:36 +1300</pubDate>
			</item>
		
			<item>
				<title>BenWilson</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274089#post274089</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274089#post274089</guid>
				<description><![CDATA[
						<p><q>rather different ethical/legal implications</q></p><p>Yup, technically. Practically, no one would ever know. If you decided to let them know, you could tell them that you only kept MD5s of the data for proof of existence purposes. You could even do exactly that, if you were a stickler.</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 22:03:36 +1300</pubDate>
			</item>
		
			<item>
				<title>Matthew Poole</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274088#post274088</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274088#post274088</guid>
				<description><![CDATA[
						<p><q> It’s more likely that the online records are backed up with the system data, rather than the reason for the backup of the system data</q></p><p>Which is what I was trying to say. They <em>have</em> to backup anything vaguely classified as records, and they have to backup systems. Since logs…</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 21:52:56 +1300</pubDate>
			</item>
		
			<item>
				<title>Sacha</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274087#post274087</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274087#post274087</guid>
				<description><![CDATA[
						<p><q>keep </q></p><p>rather different ethical/legal implications</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 21:42:01 +1300</pubDate>
			</item>
		
			<item>
				<title>BenWilson</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274086#post274086</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274086#post274086</guid>
				<description><![CDATA[
						<p><q>Yes (I think).</q></p><p>Next time (:-)) keep a hold-off set of unimportant/irrelevant data that you don't tell them you ever got. Then you can check whether they are lying about being able to detect what you took.  Two scoops for the price of one.</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 21:38:20 +1300</pubDate>
			</item>
		
			<item>
				<title>nzlemming</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274084#post274084</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274084#post274084</guid>
				<description><![CDATA[
						I retract and withdraw. Lovely Wife advises that system logs <strong>are</strong> considered records on the basis that they act as metadata for the actual content. How things have changed.
					]]></description>
				<pubDate>Fri, 02 Nov 2012 21:03:38 +1300</pubDate>
			</item>
		
			<item>
				<title>Ds</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274083#post274083</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274083#post274083</guid>
				<description><![CDATA[
						<p>TV3<br />Read more: <a href="http://www.3news.co.nz/Junior-staff-blamed-for-WINZ-privacy-breach/tabid/1607/articleID/275225/Default.aspx#ixzz2B2wNIMlq" target="_blank" rel="noopener noreferrer">http://www.3news.co.nz/Junior-staff-blamed-for-WINZ-privacy-breach/tabid/1607/articleID/275225/Default.aspx#ixzz2B2wNIMlq</a></p><p>A report on the breach released today blames staff at the ministry, and says they should have told senior managers.</p><p>But senior management would have known about the security check. <br />Why would the senior manager NOT ask, hey what did the security report say.<br />Systems seemed…</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 20:05:46 +1300</pubDate>
			</item>
		
			<item>
				<title>nzlemming</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274082#post274082</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274082#post274082</guid>
				<description><![CDATA[
						<q>I wouldn't consider them to be public records, but my observation was more that it's generally easier to have a single backup retention policy for the entire organisational network than to split things up based on information servers vs management servers. The logs are very likely to be backed up…</q>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 19:41:37 +1300</pubDate>
			</item>
		
			<item>
				<title>Matthew Poole</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274080#post274080</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274080#post274080</guid>
				<description><![CDATA[
						<q>In practice, do all departments keep all network log files as if they’re records under the Public Records Act? They probably should for certain kinds of information able to be logged, but short of being prompted to think about it, I could imagine a situation where IT staff aren’t thinking…</q>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 19:20:01 +1300</pubDate>
			</item>
		
			<item>
				<title>Russell Brown</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274078#post274078</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274078#post274078</guid>
				<description><![CDATA[
						<p><q>What’s been outlined above, if it’s accurate, is that low level people received DD’s report, which highlighted the problem. It was not then escalated properly.</p><p>If that’s accurate…</p><p>It will somewhat turn on what ‘escalated properly’ means.</q></p><p>This is interesting in the context of this week's Media3 discussion of whistleblowing.…</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 18:27:12 +1300</pubDate>
			</item>
		
			<item>
				<title>izogi</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274077#post274077</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274077#post274077</guid>
				<description><![CDATA[
						<p><q>The requirements of the Public Records Act 2005 make it certain that there will be long-term backups available, and network logs take up so little space when compressed that trying to keep them out is just not worth the effort.</q></p><p>In practice, do all departments keep all network log files…</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 17:37:06 +1300</pubDate>
			</item>
		
			<item>
				<title>Kyle Matthews</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274074#post274074</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274074#post274074</guid>
				<description><![CDATA[
						<q>But if you are trying to find low-level scapegoats for sacking, then I’m sure they would argue that the existence of a document with a statement that “non-separation of networks was an urgent issue” circulated to appropriate levels of management equates to communication. Management would in turn argue that it…</q>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 16:47:49 +1300</pubDate>
			</item>
		
			<item>
				<title>Matthew Poole</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274073#post274073</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274073#post274073</guid>
				<description><![CDATA[
						OK. I've skimmed the Deloitte report with some degree of thoroughness. I think it is reasonable to conclude that there was no mass transfer of data in the same manner was was done by Keith, based on what's in the report. The requirements of the Public Records Act 2005 make…
					]]></description>
				<pubDate>Fri, 02 Nov 2012 16:42:56 +1300</pubDate>
			</item>
		
			<item>
				<title>Matthew Poole</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274072#post274072</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274072#post274072</guid>
				<description><![CDATA[
						<p><q>It is impossible to look for anything.</q></p><p>Orly? From <a href="http://publicaddress.net/onpoint/msds-leaky-servers/" target="_blank" rel="noopener noreferrer">the original post</a>:<br /><q><br /><em>And then there were file server logs. Normally, they aren’t that exciting. Except that WINZ name their files quite well. For example:</p><p>    s:SharedDatawi_witesWaikatoHAMFraud Investigations[Name of investigator][Name of WINZ client] 23 Jun 2011 Case 640026-10.WMA</em><br /></q><br />That looks pretty damned…</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 16:32:57 +1300</pubDate>
			</item>
		
			<item>
				<title>Matthew Poole</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274070#post274070</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274070#post274070</guid>
				<description><![CDATA[
						<p><q><br /><em>Did they identify your downloads? And from that, which files you accessed?</em></p><p>Yes (I think).</q></p><p>I certainly see in the report that they saw your accessing the servers, and the transfer of data. I don't get from there to an audit trail of what you accessed, were they to be…</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 16:30:33 +1300</pubDate>
			</item>
		
			<item>
				<title>Keith Ng</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274067#post274067</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274067#post274067</guid>
				<description><![CDATA[
						<p><q>That would certainly get you mass-downloads. But it wouldn't e.g. spot a debt-collector using a kiosk to access information on a few people they were looking for.</q></p><p>Can't. They were scanned PDFs with no metadata and sequential file names. It is impossible to look for anything. Scouring for personal information…</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 16:08:46 +1300</pubDate>
			</item>
		
			<item>
				<title>Keith Ng</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274064#post274064</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274064#post274064</guid>
				<description><![CDATA[
						<p><q>Did they identify your downloads? And from that, which files you accessed?</q></p><p>Yes (I think).</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 16:03:31 +1300</pubDate>
			</item>
		
			<item>
				<title>Rich of Observationz</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274062#post274062</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274062#post274062</guid>
				<description><![CDATA[
						<p>Obviously the process didn't work. </p><p>But if you are trying to find low-level scapegoats for sacking, then I'm sure they would argue that the existence of a document with a statement that "non-separation of networks was an urgent issue" circulated to appropriate levels of management equates to communication. Management would…</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 15:57:45 +1300</pubDate>
			</item>
		
			<item>
				<title>Hamish</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274060#post274060</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274060#post274060</guid>
				<description><![CDATA[
						While network logs might help detect the sort of mass extract that you're talking about, there is no way you could claim that it's evidence of a "low risk" to security. For all we know, people have been popping in and out of the back end for years, establishing a…
					]]></description>
				<pubDate>Fri, 02 Nov 2012 15:49:54 +1300</pubDate>
			</item>
		
			<item>
				<title>Dave Marks</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274055#post274055</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274055#post274055</guid>
				<description><![CDATA[
						<p>Based on my reading of the review report I think you are correct. You really have to question how thorough that review was.</p><p>&ndash; <strong>The Logs</strong> &ndash; How far back in time do the logs go? The reviewer used the logs to find out what information was accessed from the…</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 15:19:54 +1300</pubDate>
			</item>
		
			<item>
				<title>nzlemming</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274049#post274049</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274049#post274049</guid>
				<description><![CDATA[
						<p><q>Never attribute to cost/benefit analysis that which is adequately explained by stupidity.</q></p><p>Word.</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 14:39:26 +1300</pubDate>
			</item>
		
			<item>
				<title>James George</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274046#post274046</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274046#post274046</guid>
				<description><![CDATA[
						<p>I stand corrected Mr Ng, but if you are right that there was only one large unprotected and unaudited national network, rather than hundreds of smaller localised sub-networks, the decision to eschew both auditing and security controls defies belief.<br />Even back in the early 90's when big departments moved from…</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 14:16:32 +1300</pubDate>
			</item>
		
			<item>
				<title>Kyle Matthews</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274045#post274045</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274045#post274045</guid>
				<description><![CDATA[
						<q>I would imagine that they reported it, or were aware it had been reported, by making an entry in the project risk register, on the meeting minutes, or, if using Agile, in crayon on a piece of brightly coloured paper stuck to the wall of the meeting room, which will…</q>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 14:15:53 +1300</pubDate>
			</item>
		
			<item>
				<title>Sacha</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274042#post274042</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274042#post274042</guid>
				<description><![CDATA[
						Not a formal economic analysis. And stupidity, yes. Report mentions project management defects and inadequate approach to risk.
					]]></description>
				<pubDate>Fri, 02 Nov 2012 14:03:24 +1300</pubDate>
			</item>
		
			<item>
				<title>Martin Lindberg</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274041#post274041</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274041#post274041</guid>
				<description><![CDATA[
						<p><q>Some person or group has made a decision about the cost/benefit of acting on concerns raised.</q></p><p>Never attribute to cost/benefit analysis that which is adequately explained by stupidity.</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 14:01:16 +1300</pubDate>
			</item>
		
			<item>
				<title>Sacha</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274039#post274039</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274039#post274039</guid>
				<description><![CDATA[
						The full report is interesting reading.
					]]></description>
				<pubDate>Fri, 02 Nov 2012 13:51:49 +1300</pubDate>
			</item>
		
			<item>
				<title>Idiot Savant</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274037#post274037</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274037#post274037</guid>
				<description><![CDATA[
						<q>My understanding is that there's no audit trail to determine *who* accessed information, but that there *were* network logs. Boyle talked about not finding any "download patterns" &ndash; i.e. People leeching large volumes of data, like I did. That seems like a reasonable way to detect intrusion, unless it was…</q>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 13:39:51 +1300</pubDate>
			</item>
		
			<item>
				<title>nzlemming</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274035#post274035</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274035#post274035</guid>
				<description><![CDATA[
						<p><q> Boyle talked about not finding any "download patterns" &ndash; i.e. People leeching large volumes of data, like I did.</q></p><p>Did they identify your downloads? And from that, which files you accessed? If not, then they know precisely nothing about what anyone else may or may not have done.</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 13:32:21 +1300</pubDate>
			</item>
		
			<item>
				<title>Sacha</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274034#post274034</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274034#post274034</guid>
				<description><![CDATA[
						<p><q>Management would have then failed to understand it and ignored it.</q></p><p>I'd expect any review to have looked at the paper trail about this. Some person or group has made a decision about the cost/benefit of acting on concerns raised.</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 13:25:50 +1300</pubDate>
			</item>
		
			<item>
				<title>Rich of Observationz</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274033#post274033</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274033#post274033</guid>
				<description><![CDATA[
						I would imagine that they reported it, or were aware it had been reported, by making an entry in the project risk register, on the meeting minutes, or, if using Agile, in crayon on a piece of brightly coloured paper stuck to the wall of the meeting room, which will…
					]]></description>
				<pubDate>Fri, 02 Nov 2012 13:22:59 +1300</pubDate>
			</item>
		
			<item>
				<title>Keith Ng</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274030#post274030</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274030#post274030</guid>
				<description><![CDATA[
						<p><q>Every Winz regional office (do they still call them that?) would have had their own local area network which was compromised to varying extents depending on what that regional office chose to make available on its LAN.</q></p><p>My understanding is that all the computers were connected on a single, national,…</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 13:16:57 +1300</pubDate>
			</item>
		
			<item>
				<title>Keith Ng</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274029#post274029</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274029#post274029</guid>
				<description><![CDATA[
						<p><q>The Deloittes report makes it clear that there's no auditing or logging. So their claim that there were no other breaches is pulled from their arse. I wonder how much they got paid for that?</q></p><p>My understanding is that there's no audit trail to determine *who* accessed information, but that…</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 13:15:38 +1300</pubDate>
			</item>
		
			<item>
				<title>BenWilson</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274028#post274028</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274028#post274028</guid>
				<description><![CDATA[
						<p><q> I wonder how much they got paid for that?</q></p><p>My bet is that it's a lot more than Keith or Ira did, and they actually found and reported the bloody problem.</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 13:12:48 +1300</pubDate>
			</item>
		
			<item>
				<title>Kyle Matthews</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274027#post274027</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274027#post274027</guid>
				<description><![CDATA[
						<p><q>And you can map network resources through the printer dialogue (let me know if I’m wrong about this).</q></p><p>No you're right, at least in Windows 7. Go to print, click find printer, up pops an explorer window, right click on your computer and map away. Not very intuitive however, if…</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 13:12:03 +1300</pubDate>
			</item>
		
			<item>
				<title>BenWilson</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274026#post274026</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274026#post274026</guid>
				<description><![CDATA[
						<p>BTW, good on you, Keith, for trying to find out how Bailey was outed to Sleazy Slater. And good luck.</p><p>I love how "no evidence of other breaches" can be used in this context to actually appear as a positive. There's no evidence because there is no possible way to…</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 13:10:16 +1300</pubDate>
			</item>
		
			<item>
				<title>Sacha</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274025#post274025</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274025#post274025</guid>
				<description><![CDATA[
						<p><q>It's like AirNZ still operating Zeppelins.</q></p><p>you clearly haven't met their reservations mainframe. :)</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 13:09:27 +1300</pubDate>
			</item>
		
			<item>
				<title>Martin Lindberg</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274024#post274024</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274024#post274024</guid>
				<description><![CDATA[
						<p><q> or has some kind of security hole.</p><p>(Example: I was in the bank the other day. To calculate mortgage repayments, they use CICS.</q></p><p>I dare you to find a security hole in CICS ;-)</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 12:58:28 +1300</pubDate>
			</item>
		
			<item>
				<title>James George</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274023#post274023</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274023#post274023</guid>
				<description><![CDATA[
						Sorry to 'daisy chain' but all sorts of ideas are flicking up, not least of which is that we thought at first this was an Active Directory issue.  An Active Directory is the method of setting tasks, access and privileges in networks that feature windows server technology, but it may…
					]]></description>
				<pubDate>Fri, 02 Nov 2012 12:55:22 +1300</pubDate>
			</item>
		
			<item>
				<title>Lucy Stewart</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274022#post274022</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274022#post274022</guid>
				<description><![CDATA[
						<p><q>It is a failure of management if the staff below do not feel it is possible or appropriate to pass information of this kind upwards.</p><p>It is simply poor leadership.</q></p><p>It's also a failure of procedure. Good security protocols should not allow urgent security breaches to not be passed up…</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 12:54:55 +1300</pubDate>
			</item>
		
			<item>
				<title>nzlemming</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274021#post274021</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274021#post274021</guid>
				<description><![CDATA[
						<p><q>The original description of the problem sounds exactly like being able to map network drives and seeing the names of all the computers on the network. And you can map network resources through the printer dialogue (let me know if I'm wrong about this).</q></p><p>I think your take is correct.…</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 12:54:32 +1300</pubDate>
			</item>
		
			<item>
				<title>Rich of Observationz</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274018#post274018</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274018#post274018</guid>
				<description><![CDATA[
						<p>Anyways, I'm of the view that this kind of issue could happen in just about every organisation* I've ever dealt with or heard of, especially, but not exclusively, in New Zealand.</p><p>The financiers (whether government or private owners) don't want to spend money. The management don't want to understand "techy…</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 12:50:07 +1300</pubDate>
			</item>
		
			<item>
				<title>James George</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274016#post274016</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274016#post274016</guid>
				<description><![CDATA[
						<p>@izogi Yeah even the herald report pretty much admitted that the only breaches the report considered were those of Bailey &amp; Ng, with a passing reference to the 'consumer advocate' who warned them last year.<br />Every Winz regional office (do they still call them that?) would have had their own local…</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 12:45:21 +1300</pubDate>
			</item>
		
			<item>
				<title>Roger Lacey</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274015#post274015</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274015#post274015</guid>
				<description><![CDATA[
						<p><q>“In the meantime I can confirm that at this stage four employment investigations are being undertaken by an independent barrister."</q><br />Are they going to fire the whole IT department?</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 12:44:55 +1300</pubDate>
			</item>
		
			<item>
				<title>Idiot Savant</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274014#post274014</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274014#post274014</guid>
				<description><![CDATA[
						The Deloittes report makes it clear that there's no auditing or logging.  So their claim that there were no other breaches is pulled from their arse.  I wonder how much they got paid for that?
					]]></description>
				<pubDate>Fri, 02 Nov 2012 12:37:42 +1300</pubDate>
			</item>
		
			<item>
				<title>James George</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274013#post274013</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274013#post274013</guid>
				<description><![CDATA[
						<p>Easy solution Mr Ng, be like winz and play it down.  See Deloittes only recommend kicking a few junior IT staff out of their expensive to obtain (if as yet unpaid for) careers.<br />The poor fuckers who will cop the shellacking will have chosen to ignore the security warnings not…</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 12:36:47 +1300</pubDate>
			</item>
		
			<item>
				<title>izogi</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274012#post274012</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274012#post274012</guid>
				<description><![CDATA[
						<p><q>From MSD behind that NBR link and on Scoop: <em>"Investigations have determined that there is no evidence that the Kiosk breach went beyond that of Keith Ng and his associate Ira Bailey."</em></q></p><p>Am I correct in assuming that this statement only addresses the specific breach by Keith and Ira, and…</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 12:33:25 +1300</pubDate>
			</item>
		
			<item>
				<title>Rich of Observationz</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274008#post274008</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274008#post274008</guid>
				<description><![CDATA[
						I'm not sure where the root of this idea lies, but wonder that Deloittes might have picked up if there was actually any compromise of production Active Directory files and the like. I'm suspecting it's a bit of a red herring.
					]]></description>
				<pubDate>Fri, 02 Nov 2012 12:28:43 +1300</pubDate>
			</item>
		
			<item>
				<title>Keith Ng</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274007#post274007</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274007#post274007</guid>
				<description><![CDATA[
						<p><q>The report focuses on privacy when the bigger whole of government issue is the potential cascade of security breaches. The analysis of this seems to be entirely missing.</q></p><p>It's true. Not a conspiracy though &ndash; I just don't know what the story is. With the invoices, I can tell you…</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 12:22:24 +1300</pubDate>
			</item>
		
			<item>
				<title>Sacha</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274002#post274002</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274002#post274002</guid>
				<description><![CDATA[
						<p><q>unfortunately everyone is focusing on the privacy breaches</q></p><p>exactly as intended. #spin</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 12:13:39 +1300</pubDate>
			</item>
		
			<item>
				<title>John Holley</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274001#post274001</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274001#post274001</guid>
				<description><![CDATA[
						<p>The report focuses on privacy when the bigger whole of government issue is the potential cascade of security breaches.  The analysis of this seems to be entirely missing.</p><p>The MSD network was wide open for months and to assume that other people (domestic and foreign) did not gather material or…</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 12:11:43 +1300</pubDate>
			</item>
		
			<item>
				<title>Hebe</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274000#post274000</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=274000#post274000</guid>
				<description><![CDATA[
						Manners! Mr Boyle seems to have forgotten to say thank you to Keith and Ira. he at least owes them a good dinner on the Winz entertainment account: if they hadn’t pursued the story the potential for his own job being threatened would have been huge.As it is, I can…
					]]></description>
				<pubDate>Fri, 02 Nov 2012 12:09:14 +1300</pubDate>
			</item>
		
			<item>
				<title>Bart Janssen</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=273998#post273998</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=273998#post273998</guid>
				<description><![CDATA[
						<p><q>But he did make clear that the decisions didn’t get escalated properly</q></p><p>It is a failure of management if the staff below do not feel it is possible or appropriate to pass information of this kind upwards.</p><p>It is simply poor leadership.</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 11:59:17 +1300</pubDate>
			</item>
		
			<item>
				<title>Sacha</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=273996#post273996</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=273996#post273996</guid>
				<description><![CDATA[
						The <a href="http://www.scoop.co.nz/stories/PO1211/S00024/msd-releases-independent-report-into-it-security-breach.htm" target="_blank" rel="noopener noreferrer">MSD media release</a> (and another link to the full report at bottom).
					]]></description>
				<pubDate>Fri, 02 Nov 2012 11:51:58 +1300</pubDate>
			</item>
		
			<item>
				<title>Public Address</title>
				<link>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=273995#post273995</link>
				<guid>https://publicaddress.net/system/cafe/onpoint-wtfmsd-damning/?p=273995#post273995</guid>
				<description><![CDATA[
						<p>Discussion from blog post.</p>
					]]></description>
				<pubDate>Fri, 02 Nov 2012 11:51:58 +1300</pubDate>
			</item>
		
	</channel>
</rss>
