Code replay attack on the myGovID Scheme
thinkingcybersecurity.com
thinkingcybersecurity.com
Thank god we don't have electronic voting.
I suppose they 'hinted' which is what you do in all good threats. In general, the government in Australia is fairly hostile to cryptographers and security researchers that find problems with governmental projects.
It may not be good but there's no suggestion there they were pressuring the place to fire her.
For what it's worth, here's the letter: https://www.righttoknow.org.au/request/6092/response/16930/a...
I think what's most evident and bizarre is they act like there's actually significant research going on here: the researchers in question just pointed out how easy something was, basically (see https://pursuit.unimelb.edu.au/articles/the-simple-process-o...), and the university got this letter in response.
See https://twitter.com/VTeagueAus/status/1235067612318449664 with the indication the reason she resigned was entirely due to all of this plus some other stuff.
Fair point if you want to still argue they didn't directly have to fire her, I'll walk that back a bit and say that that was pre-empted and we lack the counterfactual of what the Department of Health would have actually done in terms of pressure had she continued.
Also
> We notified the Australian Government of this problem, and were told by the Australian Tax Office that they do not intend to make the recommended changes to their protocol. [1]
Aust Govt breaks multiple web-security 101 rules, bears no cost nor responsibility for it, and the cherry on top: they refuse to do anything about it.
App-based OTP and push seems like a reasonable middle ground, short of supplying everyone with FIDO keys. It’s still better than SMS or email - or no second factor at all.
I’m fairly sure the app does require you to enter a password after a set period or reboot - exactly like apple’s iCloud implementation (which IMO, is pretty good, or at least good enough for most individuals’ use cases).
Things are getting a bit confused lately though, as some models require that factors can’t exist on the same device, and there’s questions around keeping physical (‘have’)factors separated for different accounts and functions.
>Responsible disclosure history
>This problem was disclosed on 19th August 2020 to the Australian Signals Directorate, with an indicative expectation of a 90-day disclosure period. ASD communicated it to the ATO. At a meeting on 18th September 2020, ATO told us they did not intend to change the protocol, at which point we immediately informed them that we would make a warning to users public on Monday 21st September.
https://web.archive.org/web/20200101000000*/https://www.thin...
News article about it, in Swedish: https://www.svd.se/a/yvMvle/skatteverket-utfardar-bank-id-va...
https://geeko.lesoir.be/2022/06/28/les-belges-pourront-obten...
https://tweakers.net/nieuws/198482/belgische-overheid-werkt-... (in dutch)
easy when you don't need to spend your own money!
Kind of funny the govt shipped the feature even with the spam risk and our more commercially oriented competitor product didn’t. You’d Hope they would be raising the bar for security not lowering it.
In fact, Google has a very similar 2FA option where you can simply press a Yes/No on a mobile device you are already signed into, in order to authenticate another device. None of the this PIN stuff is going to do much to reduce the odds of phishing.
These are documents that most people carry around in their wallet. Just gaining access for a few seconds to someone's wallet and take a couple photos to these documents, is all you need to impersonate this person through myGovId.
There are even night clubs where they make a copy of your driver licence as a requirement for entry.
In addition, as usual with any software system related to the Australian Governement, MyGovId simply does not work very well. For example, mine stopped receiving the 4-digit verification codes after an Android upgrade. After countless hours of resetting the application, re-entering the identity data, etc. I had to end up using my wife's phone.
Maybee I overread anything, but in general a Man-in-the-Middle is everytime possible when the user is not able to check if his communication partner is trustworthy.
The 'Analysis of impact' only bespokes the probability, but not what can happen and what besides of vandalism can be done with a login. And which goal a attacker could have that is valuable enough to justify the effort. Maybee nothing?
The mitigations beside 'Short term - for users' are all reading for me like bullshit. Displaying the URL in the App will not change anything, when the user didn't understand what he see in the browser, why should he understand it in the app? Clearly, with a private/public key infrastructure, this could be fixed, but unrolling a thing expensive like this is questionable for a simple Man-in-the-Middle attack with this little impact.
Spelling out the very simple flaw is a means of underlining how poor this system is.
Which impact can happen on Amazon, eBay, Steam? An attacker can steal your account and some hundreds of dollar of your money.
Steam does, Amazon I don't think so (just a pay via Amazon button I think)
The current scheme apparently does not make it very obvious that you're being phished.
https://krebsonsecurity.com/2018/07/google-security-keys-neu...
Use WebAuthn. It is technically possible that your users are like "Well, the nice man needed my unique physical authenticator, so he sent a bike courier and I handed it over" but in practice that doesn't happen.
> In the short term, the easy mitigation is to update the (phone) app to tell users where they're logging into. https://www.youtube.com/watch?v=TgPdVbUbtBM&t=4m25s