Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


Ge0rge

2052 posts

Uber Geek

Trusted
Lifetime subscriber

#261534 2-Dec-2019 15:24
Send private message

https://i.stuff.co.nz/national/politics/117596483/privacy-breach-has-police-shut-down-gun-buyback-website

Police have shut down the firearm buyback registration platform after the details of over 37,000 owners have potentially been made publicly available.

Info includes licence details, their firearms, addresses, bank details and phone numbers.

Scary for those who have done the right thing and registered their details and firearms.

View this topic in a long page with up to 500 replies per page Create new topic
 1 | 2
Oblivian
7296 posts

Uber Geek

ID Verified

  #2364926 2-Dec-2019 15:36
Send private message

I know a few gunslingers starting to stand out (abusing 'system', and government incompetence and so on and so on - almost falling into stereotypes they are hard against/fight to say they are not). Naturally they've all jumped on this as more fuel to that fire.

 

Guess someone will have to answer as why the info wasn't segregated off. Would have had a red target painted on it and be a matter of time given that there would be groups targeting it for a way in. Especially with the early campaigns with US influence from early on. And of course the scheme just had another boost last week on US tv with the tonight show NZ PM spot.




nathan
5695 posts

Uber Geek
Inactive user


  #2364937 2-Dec-2019 15:57
Send private message

It’s not controversial to say it’s incompetence.

Some may say the buyback is a smokescreen to divert attention away from the negligence of the firearms officer that issued the person a license, 5 weeks after arriving in NZ, with no friends or family.


Ge0rge

2052 posts

Uber Geek

Trusted
Lifetime subscriber

  #2364939 2-Dec-2019 15:59
Send private message

That would be a politics discussion and not really appropriate for a discussion about the data breach.



Zeon
3916 posts

Uber Geek

Trusted

  #2364967 2-Dec-2019 16:56
Send private message

Not at all surprising. Was seemeingly good politics to have a rushed process about the new legislation and yet another failure as a result. Further bad downstream effects for political theatre.....





Speedtest 2019-10-14


  #2364993 2-Dec-2019 18:10
Send private message

Our overseas vendor, yada yada yada.

 

Why the hell are they not using locally sourced experience. 

 

Yup complete incompetence especially around something like this. 





Ding Ding Ding Ding Ding : Ice cream man , Ice cream man


dt

dt
1152 posts

Uber Geek
Inactive user


  #2365004 2-Dec-2019 18:13
Send private message

was surprised to see how quickly this had already made international headlines, RT published it earlier in the afternoon 

 

 

 

 


nathan
5695 posts

Uber Geek
Inactive user


  #2365011 2-Dec-2019 18:18
Send private message

dt:

was surprised to see how quickly this had already made international headlines, RT published it earlier in the afternoon 


 


 



Russia propaganda loves to create divisions, highlight US 2nd Ammendment issues, gun control blah blah

 
 
 

Cloud spending continues to surge globally, but most organisations haven’t made the changes necessary to maximise the value and cost-efficiency benefits of their cloud investments. Download the whitepaper From Overspend to Advantage now.
Ge0rge

2052 posts

Uber Geek

Trusted
Lifetime subscriber

  #2365015 2-Dec-2019 18:28
Send private message

Nash has claimed that only one person viewed the data.

Colfo claim it was sent screen shots of the data from several of it's members.

I don't want to call anyone a liar, but I'm struggling to see how they can both be telling the truth...

tdgeek
29740 posts

Uber Geek

Trusted
Lifetime subscriber

  #2365019 2-Dec-2019 18:33
Send private message

Is it the Govt job to secure the data? Its the IT guys job. Govt certainly owns the breach but I doubt Twyford looks after it :-)

 

This incompetence is very common. Probably all of the flagship global Tech companies have been breached, what's happens to them?


loceff13
1065 posts

Uber Geek


  #2365026 2-Dec-2019 18:44
Send private message

It's a shame the person who discovered it attempted to make it political(involving colfo) and possibly exposed others to danger rather than disclosing it to the right people then going public after it was resolved.


Handle9
11386 posts

Uber Geek

Trusted
Lifetime subscriber

  #2365027 2-Dec-2019 18:45
Send private message

JaseNZ:

Our overseas vendor, yada yada yada.


Why the hell are they not using locally sourced experience. 


Yup complete incompetence especially around something like this. 



What does an overseas vendor have to do with competence? There are plenty of Muppets in NZ

  #2365167 2-Dec-2019 20:09
Send private message

Handle9:
JaseNZ:

 

Our overseas vendor, yada yada yada.

 

 

 

Why the hell are they not using locally sourced experience. 

 

 

 

Yup complete incompetence especially around something like this. 

 



What does an overseas vendor have to do with competence? There are plenty of Muppets in NZ

 

Absolutely but the government might as well pay our own muppets 😀. 





Ding Ding Ding Ding Ding : Ice cream man , Ice cream man


hio77
12999 posts

Uber Geek

ID Verified
Trusted
Lizard Networks

  #2365168 2-Dec-2019 20:17
Send private message

JaseNZ:

 

Handle9:
JaseNZ:

 

Our overseas vendor, yada yada yada.

 

 

 

Why the hell are they not using locally sourced experience. 

 

 

 

Yup complete incompetence especially around something like this. 

 



What does an overseas vendor have to do with competence? There are plenty of Muppets in NZ

 

Absolutely but the government might as well pay our own muppets 😀. 

 

 

Would not surprise me if there was a project manager or finance person pushing for the cheapest fastest solution.

 

 

 

One of the risks you make when you try to go hard and fast is well, it can get messy...





#include <std_disclaimer>

 

Any comments made are personal opinion and do not reflect directly on the position my current or past employers may have.

 

 


Oblivian
7296 posts

Uber Geek

ID Verified

  #2365170 2-Dec-2019 20:36
Send private message

 

We can confirm that a dealer with legitimate access to the online notification platform for the firearm buy-back programme has been able to view details of firearms owners.

 

We were notified of the error this morning when the dealer contacted us.

 

Upon being notified all efforts were made to immediately shut down access to the platform.

 

 

We have been able to identify the error back to an update made by our vendor last week which provided dealers a higher level of access to the notifications database.

 

The update was not authorised by Police.

 

Our investigations have shown only one dealer login has accessed the system since the update.

 

We believe this was an isolated incident and made possible due to human error.

 

The vendor for the online notification platform is German based global software company SAP.

 

The firearms buy-back programme is continuing and we will be using a manual process to manage the return of prohibited firearms.

 

The online notification platform will remain offline until we can be reassured by our vendor that the platform is secure.

 

We take the privacy of the public information we hold seriously and we will undertake our own additional checks to ensure the system is secure before the online notification platform is re-established.

 

We have advised the Office of the Privacy Commissioner and we are working to identify and then notify those whose information has been accessed.

 

——

 

Statement from SAP spokesperson:

 

SAP can confirm it was notified of a security breach to the New Zealand Police gun buy back system this morning.

 

The security breach indicated that a single dealer user had accessed information not intended to its user profile.

 

As soon as the full details of this incident were understood, all user profiles on the system, except for SAP consultants investigating, were locked, and remain so.

 

As part of new features intended for the platform, security profiles were to be updated to allow certain users to be able to create citizens records.

 

A new security profile was incorrectly provisioned to a group of 66 dealer users due to human error by SAP.

 

We unreservedly apologise to New Zealand Police and the citizens of New Zealand for this error.

 

The security of our customers and their data is of absolute priority to us.

 

A full internal investigation is already underway within SAP.

 

We continue to work with and offer our full resources to New Zealand Police to ensure the system is fully secure and up and running again as soon as possible.

 


boosacnoodle
963 posts

Ultimate Geek


  #2365244 3-Dec-2019 00:22
Send private message

I'm just wondering how much the SAP bill will be by the end of all of this.


 1 | 2
View this topic in a long page with up to 500 replies per page Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.