09. Data Privacy and Sovereignty

Current Events: GitLab RCE

Any user with a login could remotely execute code through the GitHub import feature.

Patched in 15.3.1/15.2.3/15.1.5

Communication:

Current Events: Optus Hack

2nd largest telecommunications company in Australia. 5 million drivers’ license/passports stolen.

Broken access control: faulty API which allowed the attacker to dump a large amount of data.

Initially released 10K entries as proof and requested million dollar ransom; apparently changed their mind and deleted the data.

Data Privacy

NZ Data Privacy Act 2020:

NZ Google Street View Wi-Fi collection (2010):

EU GDPR:

digital.govt.nz on GDPR:

While the GDPR imposes additional obligations on agencies, and provides additional privacy rights to EU residents, an agency is likely to comply with most of its obligations under the GDPR if it complies with the Privacy Act.

No…

Web Usability Standard 1.3

ISO 27000:

NZ Information Security Manual:

OWASP Secure Code Review Guide V2:

OWASP Secure Coding Practices Quick Reference Guide V2:

Secure Code Review Best Practices:

Penetration testing on live systems:

Māori Data Sovereignty:

Patriot Act (9/11), CLOUD Act (2018):

China National Intelligence Law:

Local legal agreements can prevent data transfer:

VPNs vs Tor: