ATO's Windows bias reveals possible hole

update The denizens of global security mailing list Bugtraq have started discussing whether the Australian Taxation Office's (ATO) e-tax 2010 software, which is currently being used by millions of Australians to submit their tax returns, has a security hole in it due to the way it deals with remote Secure Socket Layer (SSL) certificates.

The breaches were unintentionally discovered when a security expert, known only as Dave B, became fed up with the ATO's restrictions on the use of alternative operating systems other than Windows. He tried to do a workaround so he didn't have to use Microsoft's platform.

At first Dave thought that the software did not check the SSL certificate of involved domains and would work if the certificate came from a valid certificate authority. Other tests were made and he found that a "freshly generated" self-signed certificate would be accepted by the software: the SSL certificate does not need to be signed by a certificate authority.

E-tax communicates via the unencrypted Hypertext Transfer Protocol (http) rather than Hypertext Transfer Protocol Secure (https) if told to by, for example, using URL manipulations such as the Apache mod_rewrite module. E-tax 2010 sends the details of the tax request in a Simple Object Access Protocol (SOAP) request.

"We don't provide comment on security-related matters; however, we can assure taxpayers that income tax details submitted by e-tax software is secure," the ATO said in response to queries on the matter.

Securus Global managing director Drazen Drazic said that he believed the risks were clear and that the whole process was open to incursions such as man-in-the-middle (MITM) attacks, where an attacker could pull information from the stream between the ATO and the e-tax end user.

"The risks seem to be purely on the client side of things in regards to this advisory," he said. "People need to be careful when accessing. How it's working based upon the advisory means people could be directed to anywhere with personal information being sent to unauthorised parties. Given the type of information, not a good thing."

For instance, if an individual has an SSL certificate for another website that certificate could then be used to masquerade as the ATO's tax server. The ATO was contacted last Thursday for comment but has not yet responded to the issue at the time of publication.

Last week Dave logged his discovery on Bugtraq in a series of logs. Each revealed that the security breach was much worse than previously thought. The first bug logged can be viewed here, subsequent bugs logged can be located here and here.

Updated at 5:30pm, 13 September 2010: included comment from ATO.

Talkback

What's this got to do with Windows? Poorly written/designed software can be written on any platform.

That's like saying it's Apple's fault for insecure Adobe software, so using Apple's OS is dangerous.

PachangaPachanga September 14th, 2010
Report offensive content Reply (0) (0)

It's got nothing to do with Windows, more to do with the ATO's bias towards Windows. If the ATO had of released Linux and OSX software this bug might not have been found. It was in the effort to port this software to a new OS that this bug was found.

I bet the e-tax software is far from secure. I'm sure if hackers wanted to they could quite easily intercept your tax details. This is probably not something security researcher would want to bring to light though due to the sensitive nature of it (and maybe, as I would, fear of retribution from the ATO itself, the next 20 years of my life being audited sound like enough discouragement to me to not disclose security issues).

moonheadmoonhead September 14th, 2010
Report offensive content Reply (0) (0)

Regardless, Windows is not to blame for ATO's poorly written software. E-Tax is an outdated software that has been maintained by ATO. There are bound to be issues with it. This is nothing to do with the operating system itself.

Besides, there is nothing wrong with ATO bias towards Windows software. The majority of its users are using Windows software. Almost all accountants use Windows software. ATO is just catering to the majority.

fred9999fred9999 September 14th, 2010
Report offensive content Reply (0) (0)
Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

Tech Blueprint

ZDNet Australia Live

First off, Bitcoin is not a virus. Second off, the only way to generate Bitcoins, is by using a Bitcoin miner. More information on this h...

4 minutes ago by rizowski on ABC's Bitcoin miner tackled in minutes

Vic councils tender for VMware partner - ZDNet Australia: Vic councils tender for VMware partnerZDNet Australia#... http://t.co/V9rukN7Q

Cybercrime golden age over in two years?
http://t.co/qdeIhHXP #techwd #Tech_ar #reversing

US, Australia team up on #cybersecurity http://t.co/AKDgHpmB

Microsoft's So.cl network launched amid Facebook press http://t.co/MkUizROL

Students create "v'ideo parties" with MSFT new social service http://t.co/uH9ffvLa

RT @zdnetaustralia: Melbourne City Council pulls parking fine cameras. Turns out Melbournites park too close together: http://t.co/pqbJbeJy

Vic councils tender for VMware partner - ZDNet Australia http://t.co/eTTZFXVG #australia #technews

@Microsoft So.cl combines search and social media, designed to aid students networking and sharing information ZDNet http://t.co/zQW8Zecr

Google's Chrome vs. Microsoft's IE: How's that halo effect? http://t.co/xz2YGQMU

When an operating system is sold it should not launch until an approved security service is purchased online with a list of approved supp...

46 minutes ago by Kevin Cobley on National Botnet Network coming: Earthwave

Windows Phone: Photography the key to its success? http://t.co/14swIy1J

National Botnet Network coming: Earthwave http://t.co/BsCUwtGW via @zdnetaustralia

Windows Phone: Photography the key to its success? http://t.co/CBVdS9f7

RT @MicrosoftNZCRM: Great article on ZDNet - Microsoft #Dynamics #CRM saves email-drowned Australian Power and Gas http://t.co/51PgGxkW #msdyncrm #crm2011 ^pb

RT @MicrosoftNZCRM: Great article on ZDNet - Microsoft #Dynamics #CRM saves email-drowned Australian Power and Gas http://t.co/51PgGxkW #msdyncrm #crm2011 ^pb

Windows Phone: Photography the key to its success?: I tend to do a bit of digital photography when I go on trips... http://t.co/lAYofzgi

CASE STUDY: using #msdyncrm to cope with growing number of client comms http://t.co/qA1SxZLO #personalinjury #legaluk #solicitors #lawyers

Windows Phone: Photography the key to its success? - ZDNet (blog): ZDNet (blog)Windows Phone: Photography the ke... http://t.co/HPArdCe0

One of Windows Server 2012's secret weapons: Hyper-V Replica http://t.co/F8nJ7xK6

“@ZDNet: One of Windows Server 2012's secret weapons: Hyper-V Replica http://t.co/oAE1ifmp”....a DR solution, that is for the little guys.

TechnologyOne keeps profits growing: http://t.co/A7J5uDlT

“@btviewpoint: #Cybercrime golden age over in two years? - #Security - #News - http://t.co/ZEmny2dI

“@ZDNet: Can Windows 8 tablet be priced low enough to compete with iPad, Kindle Fire? http://t.co/b7n4Wb7C” .....unlikely, and disappointing

#Cybercrime golden age over in two years? - #Security - #News - http://t.co/Mvc37WAr

RT @MicrosoftNZCRM: Great article on ZDNet - Microsoft #Dynamics #CRM saves email-drowned Australian Power and Gas http://t.co/51PgGxkW #msdyncrm #crm2011 ^pb

United States, Australia team up on cybersecurity http://t.co/41IYTcDx

$50m to Medicare locals for eHealth http://t.co/VM5ts5lf

RT @adrianbritton: Goodbye Friending #Facebook: We only part to meet again http://t.co/gXZEKtEE #socialmedia

RT @stilgherrian: RT: Me at @zdnetaustralia: "NSA, FBI split on comms intercepts" http://t.co/Y32rF8Gz #AusCERT

Microsoft admits Vista was 'cheesy' http://t.co/Yd6fSLyx

We Are Specialty Supply Miu Miu Handbags, Miu Miu Pocketbook, Miu Miu Sunglasses And So On. Miu Miu Car-boot sale Online Strapping Reduct...

4 hours ago by ExedegamEmodo on Reservoir blogs: Fan fakes Tarantino diary

RT @stilgherrian: RT: Me at @zdnetaustralia: "NSA, FBI split on comms intercepts" http://t.co/Y32rF8Gz #AusCERT

RT: Me at @zdnetaustralia: "NSA, FBI split on comms intercepts" http://t.co/Y32rF8Gz #AusCERT

RT @stilgherrian: RT: Me at @zdnetaustralia: "NSA, FBI split on comms intercepts" http://t.co/Y32rF8Gz #AusCERT

4 hours ago by forporoExpoxy on Reservoir blogs: Fan fakes Tarantino diary

Goods Shopping Location Diminish Of Japan's Largest Overseas Train Brands. Coach Outlet Recover 89% Off.We Entertain Stuffed Items Such A...

4 hours ago by MentIdott on Reservoir blogs: Fan fakes Tarantino diary

Our Stow away Tender Exercise Bags Of The Cheapest Quotation, 50-75% OFF. Secured Shipping To Japan. Detailed Inferior Instructor Handbag...

4 hours ago by Hieffiftsoinc on Reservoir blogs: Fan fakes Tarantino diary

http://t.co/gNQkl0gd

1963年ナイキの創業者フィル・ナイトが訪日、オニツカ(現アシックス)の経営陣を訪問。 最新の機...

4 hours ago by Scafthapthinc on Reservoir blogs: Fan fakes Tarantino diary

4 hours ago by antaftilk on Reservoir blogs: Fan fakes Tarantino diary

Our Aggregate Wholesale Trainer Bags Of The Cheapest Consequence, 50-75% OFF. Self-indulgent Shipping To Japan. Exquisite Worthless Drill...

5 hours ago by meltygypent on Reservoir blogs: Fan fakes Tarantino diary

Celine belongings,Celine case,purse Celine,CELINE Celine is synonymous with je sais quoi and faultlessness prevalent since founding in 19...

5 hours ago by dendyBymNTedo on Reservoir blogs: Fan fakes Tarantino diary

Global mobile phone sales take a hit; Nokia yields to Apple, Samsung http://t.co/95pDxClp

5 hours ago by Fedaupdat on Reservoir blogs: Fan fakes Tarantino diary

Global mobile phone sales take a hit; Nokia yields to Apple, Samsung - ZDNet (blog): Global mobile phone sales t... http://t.co/GtLqWFz1

Admits? Don't fall for their marketing. Vista was beautiful. Microsoft has a history of trashing their older OSes.

6 hours ago by anonymuos on Microsoft admits Vista was 'cheesy'

Gotta agree. For our Burnie, Tas. internet, we have a 1.5MB download speed adls connection through exetel using testra copper line. ADS...

6 hours ago by brozza on Broadband Speedtest

Well the message certainly is clear. Never do anything because something might happen. Seriously it seems to me "Earthwave" just want to...

8 hours ago by Hubert Cumberdale on National Botnet Network coming: Earthwave

you really think it's going to be such a grim future? looking at South Korea, Japan, even Czech Republic - I haven't seen either emit mo...

10 hours ago by romant on National Botnet Network coming: Earthwave

No... they'll just blame the NBN for that too ;-)

10 hours ago by Beta on National Botnet Network coming: Earthwave

It seems that some of the people who set up ACCAN (not staff members) took the view that it would somehow be against their view of 'consu...

11 hours ago by socrates on ACCAN gets govt tick amid industry criticism

Don't laugh, Mr Turnbull is dumb enough to try and use this against the NBN. I'm sure the noallitions magical FTTN will be impervious to ...

11 hours ago by Jingles on National Botnet Network coming: Earthwave

OMG, the sky will fall if we get NBN - it must be cancelled immediately! Sorry; was just channelling Malcolm Turnbull there for a moment...

11 hours ago by socrates on National Botnet Network coming: Earthwave

Thats just stupid.. what else is the NBN going to get blamed for? People die crossing the road, are you going to ban cars or police it b...

12 hours ago by fibretech on National Botnet Network coming: Earthwave

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar