<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Brad Heap &#187; Security</title>
	<atom:link href="http://www.bradheap.id.au/blog/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.bradheap.id.au/blog</link>
	<description>One kiwi&#039;s news and views on politics, science, computers, god, religion, and other ramblings from Sydney, Australia</description>
	<lastBuildDate>Thu, 02 Feb 2012 08:11:01 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Sydney Domestic Security Meltdown – The Day Paranoia Reigned</title>
		<link>http://www.bradheap.id.au/blog/2011/04/sydney-domestic-security-meltdown-%e2%80%93-the-day-paranoia-reigned/</link>
		<comments>http://www.bradheap.id.au/blog/2011/04/sydney-domestic-security-meltdown-%e2%80%93-the-day-paranoia-reigned/#comments</comments>
		<pubDate>Wed, 20 Apr 2011 00:27:03 +0000</pubDate>
		<dc:creator>Brad Heap</dc:creator>
				<category><![CDATA[Australia]]></category>
		<category><![CDATA[Comment and Opinion]]></category>
		<category><![CDATA[News & Current Events]]></category>
		<category><![CDATA[Flying]]></category>
		<category><![CDATA[Safety]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Travel]]></category>

		<guid isPermaLink="false">http://www.bradheap.id.au/blog/?p=4411</guid>
		<description><![CDATA[About 3.30pm yesterday one of the security scanners at Sydney&#8217;s Domestic Terminal lost power resulting in 16 passengers passing through security without being correctly screened. Out of the many thousands of passengers who pass through Sydney Domestic every day this &#8230; <a href="http://www.bradheap.id.au/blog/2011/04/sydney-domestic-security-meltdown-%e2%80%93-the-day-paranoia-reigned/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>About 3.30pm yesterday one of the <a href="http://www.smh.com.au/travel/travel-incidents/thousands-stranded-in-sydney-after-airport-security-breach-20110420-1dnrr.html" target="_blank">security scanners at Sydney&#8217;s Domestic Terminal lost power</a> resulting in 16 passengers passing through security without being correctly screened. Out of the many thousands of passengers who pass through Sydney Domestic every day this is a very minor problem.</p>
<p>However, the paranoia that has strangled the airline industry since the September 11 attacks saw what was a minor security machine malfunction turn into a farce that affected flights and travellers across Australia. All passengers in the terminal, and on flights that were still boarding at Sydney Domestic were forced to leave the air-side area of the terminal and planes landing at the airport were made to queue for hours on the tarmac until every passenger was re-screened.</p>
<p>In other words the failure to correctly screen 16 passengers resulted in thousands of people being stuffed about by overbearing and unnecessary security regulations which see public freedom curtailed in the name of fighting an invisible and mostly physiological enemy.</p>
<p>This paranoia and curtailing of public freedom has sees us live in a society where you are many times more likely to be killed in a plane accident than a terrorist attack. Yet in the United States<a href="http://en.wikipedia.org/wiki/Transportation_Security_Administration" target="_blank"> $8.1 billion is spent on the TSA</a> to enforce <a href="http://dailypaul.com/149217/video-tsa-molesting-3-year-old-child" target="_blank"><del>compulsory child molestation</del></a> air-line security while only <a href="http://en.wikipedia.org/wiki/National_Transportation_Safety_Board" target="_blank">$77 million is spent on investigating airline accidents</a>.</p>
<p>It is all a bit ridiculous isn&#8217;t it? Which reminds me of this infographic:</p>
<p><img class="aligncenter" src="http://www.boingboing.net/200912301009.jpg" alt="Terrorist Attack Infographic" /></p>
<p>My hope is one day we will wake to the realisation that the biggest threat to our safety and freedom is not a few men who live in dusty caves in the middle-east but instead our own governments curtailing our freedoms in a manner akin to that of Orwell&#8217;s 1984.
<div class="social4i" style="height:29px;">
<div class="social4in" style="height:29px;float: left;">
<div class="socialicons s4twitter" style="float:left;margin-right: 10px;background:url(&quot;http://goo.gl/zjqd1&quot;) no-repeat;"><a href="http://twitter.com/share" data-url="http://www.bradheap.id.au/blog/2011/04/sydney-domestic-security-meltdown-%e2%80%93-the-day-paranoia-reigned/" data-counturl="http://www.bradheap.id.au/blog/2011/04/sydney-domestic-security-meltdown-%e2%80%93-the-day-paranoia-reigned/" data-text="Sydney Domestic Security Meltdown – The Day Paranoia Reigned" class="twitter-share-button" data-count="horizontal" data-via=""></a></div>
<div class="socialicons s4fblike" style="float:left;margin-right: 10px;">
<div id="fb-root"></div>
<p><fb:like href="http%3A%2F%2Fwww.bradheap.id.au%2Fblog%2F2011%2F04%2Fsydney-domestic-security-meltdown-%25e2%2580%2593-the-day-paranoia-reigned%2F" send="false" layout="button_count" width="100" height="21" show_faces="false" font=""></fb:like></div>
<div class="socialicons s4plusone" style="float:left;margin-right: 10px;"><g:plusone size="medium" href="http://www.bradheap.id.au/blog/2011/04/sydney-domestic-security-meltdown-%e2%80%93-the-day-paranoia-reigned/" count="true"></g:plusone></div>
</div>
<div style="clear:both"></div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.bradheap.id.au/blog/2011/04/sydney-domestic-security-meltdown-%e2%80%93-the-day-paranoia-reigned/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Auckland City Council&#8217;s Carparking Machines were hacked not skimmed</title>
		<link>http://www.bradheap.id.au/blog/2009/11/auckland-city-councils-carparking-machines-we-hacked-not-skimmed/</link>
		<comments>http://www.bradheap.id.au/blog/2009/11/auckland-city-councils-carparking-machines-we-hacked-not-skimmed/#comments</comments>
		<pubDate>Wed, 25 Nov 2009 22:34:09 +0000</pubDate>
		<dc:creator>Brad Heap</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[News & Current Events]]></category>
		<category><![CDATA[Auckland City Council]]></category>
		<category><![CDATA[Credit Cards]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.brad.net.nz/blog/?p=2139</guid>
		<description><![CDATA[Breaking news seems to be coming form the Twitterverse this morning. It appears that the Auckland City Council&#8217;s parking machines were storing the credit card numbers of all cards entered into the machines and the database storing this data has &#8230; <a href="http://www.bradheap.id.au/blog/2009/11/auckland-city-councils-carparking-machines-we-hacked-not-skimmed/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Breaking news seems to be coming form the Twitterverse this morning.</p>
<p>It appears that the Auckland City Council&#8217;s parking machines were storing the credit card numbers of all cards entered into the machines and the database storing this data has been hacked.</p>
<p>There is a discussion going on here at Public Address: <a href="http://publicaddress.net/system/topic,2226,hard-news-a-bigger-breach.sm" target="_blank">http://publicaddress.net/system/topic,2226,hard-news-a-bigger-breach.sm</a></p>
<p>There is no reason why after the transaction was processed for the council to store the credit card numbers unless they were using them as a form of tracking of people using the carpark, if this is the case they still should have never stored the credit card numbers, at a minimum a hash sum of the number would have worked. There appears to be much more to come on this story.</p>
<p>Update:</p>
<p>This just in from Mr A. Source:</p>
<blockquote><p>Auckland City&#8217;s PCI certification is under serious review which will compromise their ability to carry out any credit card transactions. This will also potentially impact the new Auckland Council. Basically, internal systems at Auckland City have been compromised.</p></blockquote>
<p><a href="http://publicaddress.net/system/topic,2226,hard-news-a-bigger-breach.sm?p=142117#post142117" target="_blank">http://publicaddress.net/system/topic,2226,hard-news-a-bigger-breach.sm?p=142117#post142117</a>
<div class="social4i" style="height:29px;">
<div class="social4in" style="height:29px;float: left;">
<div class="socialicons s4twitter" style="float:left;margin-right: 10px;background:url(&quot;http://goo.gl/zjqd1&quot;) no-repeat;"><a href="http://twitter.com/share" data-url="http://www.bradheap.id.au/blog/2009/11/auckland-city-councils-carparking-machines-we-hacked-not-skimmed/" data-counturl="http://www.bradheap.id.au/blog/2009/11/auckland-city-councils-carparking-machines-we-hacked-not-skimmed/" data-text="Auckland City Council&#8217;s Carparking Machines were hacked not skimmed" class="twitter-share-button" data-count="horizontal" data-via=""></a></div>
<div class="socialicons s4fblike" style="float:left;margin-right: 10px;">
<div id="fb-root"></div>
<p><fb:like href="http%3A%2F%2Fwww.bradheap.id.au%2Fblog%2F2009%2F11%2Fauckland-city-councils-carparking-machines-we-hacked-not-skimmed%2F" send="false" layout="button_count" width="100" height="21" show_faces="false" font=""></fb:like></div>
<div class="socialicons s4plusone" style="float:left;margin-right: 10px;"><g:plusone size="medium" href="http://www.bradheap.id.au/blog/2009/11/auckland-city-councils-carparking-machines-we-hacked-not-skimmed/" count="true"></g:plusone></div>
</div>
<div style="clear:both"></div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.bradheap.id.au/blog/2009/11/auckland-city-councils-carparking-machines-we-hacked-not-skimmed/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The ongoing Toll Road Website Saga</title>
		<link>http://www.bradheap.id.au/blog/2009/01/the-ongoing-toll-road-website-saga/</link>
		<comments>http://www.bradheap.id.au/blog/2009/01/the-ongoing-toll-road-website-saga/#comments</comments>
		<pubDate>Thu, 08 Jan 2009 07:56:44 +0000</pubDate>
		<dc:creator>Brad Heap</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[New Zealand]]></category>
		<category><![CDATA[News & Current Events]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[NZTA]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Roads]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.brad.net.nz/blog/?p=909</guid>
		<description><![CDATA[And today&#8217;s other top story. NZTA was told in mid December they had security issues but did nothing. http://www.nzherald.co.nz/technology/news/article.cfm?c_id=5&#38;objectid=10550914]]></description>
			<content:encoded><![CDATA[<p>And today&#8217;s other top story.</p>
<p>NZTA was told in mid December they had security issues but did nothing.</p>
<p><a href="http://www.nzherald.co.nz/technology/news/article.cfm?c_id=5&amp;objectid=10550914" target="_blank">http://www.nzherald.co.nz/technology/news/article.cfm?c_id=5&amp;objectid=10550914</a>
<div class="social4i" style="height:29px;">
<div class="social4in" style="height:29px;float: left;">
<div class="socialicons s4twitter" style="float:left;margin-right: 10px;background:url(&quot;http://goo.gl/zjqd1&quot;) no-repeat;"><a href="http://twitter.com/share" data-url="http://www.bradheap.id.au/blog/2009/01/the-ongoing-toll-road-website-saga/" data-counturl="http://www.bradheap.id.au/blog/2009/01/the-ongoing-toll-road-website-saga/" data-text="The ongoing Toll Road Website Saga" class="twitter-share-button" data-count="horizontal" data-via=""></a></div>
<div class="socialicons s4fblike" style="float:left;margin-right: 10px;">
<div id="fb-root"></div>
<p><fb:like href="http%3A%2F%2Fwww.bradheap.id.au%2Fblog%2F2009%2F01%2Fthe-ongoing-toll-road-website-saga%2F" send="false" layout="button_count" width="100" height="21" show_faces="false" font=""></fb:like></div>
<div class="socialicons s4plusone" style="float:left;margin-right: 10px;"><g:plusone size="medium" href="http://www.bradheap.id.au/blog/2009/01/the-ongoing-toll-road-website-saga/" count="true"></g:plusone></div>
</div>
<div style="clear:both"></div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.bradheap.id.au/blog/2009/01/the-ongoing-toll-road-website-saga/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Does the NZTA even know what HTTPS is?</title>
		<link>http://www.bradheap.id.au/blog/2009/01/does-the-nzta-even-know-what-https-is/</link>
		<comments>http://www.bradheap.id.au/blog/2009/01/does-the-nzta-even-know-what-https-is/#comments</comments>
		<pubDate>Wed, 07 Jan 2009 06:59:29 +0000</pubDate>
		<dc:creator>Brad Heap</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[New Zealand]]></category>
		<category><![CDATA[News & Current Events]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[NZTA]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Roads]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.brad.net.nz/blog/?p=900</guid>
		<description><![CDATA[I have been laughing over the last few days as the New Zealand Transport Authority has become more red faced over the massive security hole in their toll road payment system. On January 25 the Silverdale to Puhoi motorway extension &#8230; <a href="http://www.bradheap.id.au/blog/2009/01/does-the-nzta-even-know-what-https-is/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I have been laughing over the last few days as the New Zealand Transport Authority has become more red faced over the massive security hole in their toll road payment system.</p>
<p>On January 25 the Silverdale to Puhoi motorway extension will open, however to drive on it you will need to pay tolls, and for the last two months or so the NZTA have been advertising the www.tollroad.govt.nz website heavily so regulary uses of the new road can set up accounts.</p>
<p>On Monday a computer user realised that the website was not encrypting credit card information which means that anyone who knows anything about packet snifting or the like could intercept peoples credit card details as they used the website.</p>
<p>Now first and foremost this should never happen. Not on any ecommerce site, let alone a government website. Ecommerce programing 101 would surely teach you that first you must always encrypt data through using SSL and HTTPS not plain HTTP.</p>
<p>But what was more funny is that the red faced NZTA denied that there was anything wrong with the site! Refusing to take it offline or stop processing accounts.</p>
<p>That was until today when with egg on their face they took down the site for maintenance and admitted they stuffed up. Time to get new programmers one thinks.</p>
<p>Read more here:</p>
<p><a href="http://www.nzherald.co.nz/connect/news/article.cfm?c_id=1501833&amp;objectid=10550614" target="_blank">http://www.nzherald.co.nz/connect/news/article.cfm?c_id=1501833&amp;objectid=10550614</a></p>
<p>and</p>
<p><a href="http://www.nzherald.co.nz/nz/news/article.cfm?c_id=1&amp;objectid=10550744" target="_blank">http://www.nzherald.co.nz/nz/news/article.cfm?c_id=1&amp;objectid=10550744</a></p>
<p><img src="http://www.metservice.co.nz/phpads/adimage.php?filename=760x120.gif&#038;contenttype=gif"/>
<div class="social4i" style="height:29px;">
<div class="social4in" style="height:29px;float: left;">
<div class="socialicons s4twitter" style="float:left;margin-right: 10px;background:url(&quot;http://goo.gl/zjqd1&quot;) no-repeat;"><a href="http://twitter.com/share" data-url="http://www.bradheap.id.au/blog/2009/01/does-the-nzta-even-know-what-https-is/" data-counturl="http://www.bradheap.id.au/blog/2009/01/does-the-nzta-even-know-what-https-is/" data-text="Does the NZTA even know what HTTPS is?" class="twitter-share-button" data-count="horizontal" data-via=""></a></div>
<div class="socialicons s4fblike" style="float:left;margin-right: 10px;">
<div id="fb-root"></div>
<p><fb:like href="http%3A%2F%2Fwww.bradheap.id.au%2Fblog%2F2009%2F01%2Fdoes-the-nzta-even-know-what-https-is%2F" send="false" layout="button_count" width="100" height="21" show_faces="false" font=""></fb:like></div>
<div class="socialicons s4plusone" style="float:left;margin-right: 10px;"><g:plusone size="medium" href="http://www.bradheap.id.au/blog/2009/01/does-the-nzta-even-know-what-https-is/" count="true"></g:plusone></div>
</div>
<div style="clear:both"></div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.bradheap.id.au/blog/2009/01/does-the-nzta-even-know-what-https-is/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

