Colby Cosh: MLA's reward for exposing insecure Alberta health site? A possible $200K fine

  • 📰 nationalpost
  • ⏱ Reading Time:
  • 48 sec. here
  • 2 min. at publisher
  • 📊 Quality Score:
  • News: 23%
  • Publisher: 80%

Health Health Headlines News

Health Health Latest News,Health Health Headlines

Removed from the NDP caucus during an investigation, Thomas Dang may not be allowed to stand in next year\u0027s provincial election

Someone had noticed that the site was not guarded by a CAPTCHA test that would prevent automated “brute forcing” of the site using a computer-generated barrage of birthdates and Alberta health insurance numbers.

The government’s COVID-records site did have a barrier to repeated lookups from the same IP address, but overcoming that by obfuscating your IP is a hacking task much less difficult than writing a script for brute-forcing. Dang decided to execute a principled “white-hat hack” of the site to prove that it was creating a terrible information-security risk for the Alberta public, and he chose the birthdate of Premier Jason Kenney for the test.

On Friday, RCMP cybersecurity specialists announced that Dang would be summoned and charged with a violation of the Alberta Health Information Act. He faces a possible fine of up to $200,000 and has not decided how he will plea. He continues to point out, as he did when his hack came to light last year, that the government of Alberta completely lacks any semblance of a bug-bounty or “vulnerability disclosure” scheme that would give white-hat hackers incentives to help stop up security holes.

 

Thank you for your comment. Your comment will be published after being reviewed.
Please try again later.
We have summarized this news so that you can read it quickly. If you are interested in the news, you can read the full text here. Read more:

 /  🏆 10. in HEALTH

Health Health Latest News, Health Health Headlines

Similar News:You can also read news stories similar to this one that we have collected from other news sources.

Colby Cosh: MLA's reward for exposing insecure Alberta health site? A possible $200K fineRemoved from the NDP caucus during an investigation, Thomas Dang may not be allowed to stand in next year\u0027s provincial election What is the deal with conservatives having people charged for exposing bad website security they're responsible for? It's a pattern that keeps repeating.
Source: nationalpost - 🏆 10. / 80 Read more »

Colby Cosh: MLA's reward for exposing insecure Alberta health site? A possible $200K fineRemoved from the NDP caucus during an investigation, Thomas Dang may not be allowed to stand in next year\u0027s provincial election What is the deal with conservatives having people charged for exposing bad website security they're responsible for? It's a pattern that keeps repeating.
Source: nationalpost - 🏆 10. / 80 Read more »