Wednesday, June 15, 2011

WhaleLeaks; the continuing saga

Cameron "WhaleOil" Slater's discover of a Labour Party computer server with no security precautions now has a name - WhaleLeaks. We reckon that is very fitting, especially given the way that the Left back-slapped and high-fived itself after the theft of Don Brash's e-mails, WikiLeaks revelations, and most recently, the theft of e-mails from Sarah Palin.

And the furore over WhaleLeaks isn't going to die away any time soon; the man himself has a new instalment this morning which is very sobering reading for anyone who gave personal details to the Labour Party with the expectation that their privacy would be protected. It's pretty clear that Labour has failed dismally in its duty of care - check this out:

Labour have gone all in on their attacks on me and my alleged pup­pet mas­ters in National. They for­got though that Trevor Mal­lard mounted a months worth of attacks on me for being in the pocket of Don Brash and ACT. So it is clear they are not “on mes­sage” as they say in the beltway.

After I posted my video that showed how easy it was to obtain data from their wide open site the IT com­mu­nity unan­i­mously deliv­ered their ver­dict that Labour and no one else was to blame for their woe­ful breach of people’s privacy.

Com­menters at Kiwiblog and other sites quickly realised what I did long ago and that was that Google and other bots had archived Labour’s open site exten­sively. All their data is still in the cache and will be for quite some time.


Oh dear. Keeping Stock gets visits from Google bots every day. That's why, when you comment, that you have to use a randon anti-spam word. Even when we were temporarily retired from blogging in late 2009, we were having comments left on the blog, even though there was no fresh contact; it was the work of bots.

And for those who reckon that Slater has acted illegally, he blogs:

Their credit card provider admin details were:

Flo2Cash_Donate\”;s:9:\“user_name\”;s:8:\“nzlabour\”;s:8:\“password\”;N;s:9:\“signature\”;N;s:8:\“url_site\”;s:63:\

https://secure.flo2cash.co.nz/donations/labourparty/donate.aspx\”;s:7:\“url_api\”;N;s:9:\“url_recur\”;s:63:\

https://secure.flo2cash.co.nz/donations/labourparty/donate.aspx\”

This shows the appalling lack of secu­rity not only for the donor and mem­ber­ship details but also with regard to user­names and pass­words for other secure areas.

I never accessed those areas, to do so would have been ille­gal. But given that their sys­tems were open and exposed long enough that Google and 9 other bots were able to cache the entire direc­tory sys­tem there is a good chance that Russ­ian or Niger­ian scam­sters also were able to obtain access to the data­base and credit card pro­cess­ing passs­words that Labour left exposed. Chris Flatt can­not give any assur­ances that their donor details includ­ing credit cards were safe and secure.

I know that Labour have been warned about the details of this post so pre­sum­ably their IT mup­pets have now changed these details.


This is entirely Labour's problem. Had there not been a story in the Herald on Sunday four days ago, and had Cam Slater not started a series of blog posts, there would still be huge holes in Labour's website security, and they would be unaware of them. It was only the revelations of Sunday which ramg alarm bells at Labour Party HQ.


We're not experts in this area; indeed, we are technical neanderthals. But surely, more could have been expected from one of New Zealand's largest political parties. It is going to be interesting to see how this pans out, and we reckon that the Privacy Commissioner is going to be asking Chris Flatt and Moira Coatsworth some searching questions as to why their website security was so woefully inadequate.

The Labour Party head honchos and those who blog supporting Labour need to stop shooting at the messenger, Cam Slater, and look a bit closer to home. This is wholly Labour's problem, and if they can't run a website, it begs a question that we needn't even ask.

38 comments:

Anonymous said...
This comment has been removed by a blog administrator.
Inventory2 said...

Penny; your post was irrelevant to the subject, hence its deletion.

Jacqueline said...

This whole thing has me scratching my head.

Unlike with the theft of Don Brash's emails, there doesn't appear to be anything all that exciting, or scandalous found in the "Whaleleaks..."

A list of 18,000 names and donors is hardly nail biting stuff. I have always been under the impression that political parties had to make where their donations come from public anyway.

I don't understand the excitement over all of this.

alex Masterley said...

It is about security of personal information including personal details, credit card details and other ephemera.
If the Lbour party can't do the basics correctly (and most SME's who engage in e transactions manage to successfully) then how can they properly govern a country.

robertguyton said...

Jacqueline - there is none.
Right wing bloggers are whipping froth from water and that water is in the bottom of a tea cup and they'd have us believe it's a storm.
So pale, this beat-up, so insipid.
As weak as whale piss :-)

Inventory2 said...

How you wish that was the case Robert. It is highly likely that the NZLP is going to be put through the wringer by the Office of the Privacy Commissioner, and they had better hope that there have been NO malicious attempts to use credit card passwords, as they may well have a financial liability; and it's all down to slack processes.

robertguyton said...

Quote of the day:

"Cameron Slater claimed to have all sorts of “top secret political information” that he was going to “release”. In the end all that appeared was a boring set of meeting minutes that was about as politically explosive as play dough."

Inventory2 said...

Be patient Robert; you should know that you don't dump all the juicy stuff at once...

Moist von Lipwig said...

Woooosh..........


That was the sound the point made going over your head Robert.

Inventory2 said...

Do you condone the personal attacks on Slater that have been made by both bloggers and commenters at The Standard Robert? Just wondering ..

Anonymous said...

A list of 18,000 names and donors is hardly nail biting stuff. I

18,000 names of whom say 15,000 will be public servants or state employees

loaded salary of 100K, that's 1.5 BILLION dollars in savings right there.

Now thing: say you're a school principal, or a departmental deputy general manager, and you have to choose whom you're going to keep and whom you're going to fire when the next round of the cuts come through.

Well gee - if you're not checking those lists then you can bet on one thing: you'll be out on your ear because the National & ACT research units sure will be.

This is a a great precursor to one of the biggest - and most overdue - clean out of bureaucrats and state "servants" since the 1990s!

Tinman said...

The Labour Party head honchos and those who blog supporting Labour need to stop shooting at the messenger, Cam Slater

No, I'm all for shooting Slater no matter who does it.

NZ's style of government needs a credible opposition.

Labour are proving they can't provide this so we're left with the reds and the racists.

God defend New Zealand!

Jeremy Harris said...

This really has been the most fun.

Watching the nincompoops at the The Standard try and blame National and WO for the one sided ineptitude of the NZLP, actually has been hurting my sides with laughter.

Adolf Fiinkensein said...

Of course, way down there in Invercargill where rational thought is subsumed by the bitter foggy cold, they regards instituionalised theft by the Labour party from the taxpayer as 'nothing at all scandalous.'

Did someone shuk open your skulls and flick your brains into a pottle with the other oysters, Robert and Jacqueline? They'd be indistinguishable apart from the sour taste.

Is Jacqueline female incarnation of RG? Looks like it.

Inventory2 said...

Riverton Adolf, not Invercargill; that's where Robert hails from.

And don't be too hard on Jacqueline; she has far more going for her than the fella from down south!

robertguyton said...

Adolf - slagging Jacqueline off with comments about her brains being indistinguishable from oysters and sour to boot, is just plain rude and ignorant. Jacqueline's views are valid and she has every right to express them here. In fact, her opinions seem a great deal more clearly constructed than your own. If this is the way you speak to females, and the evidence says it is, then you ought to be ashamed of yourself.
Inv2 - I'm ver disappointed in you for allowing the sort of mysoginist crap that Adolf is presenting here, to appear on your blog. It reflects very badly on you and on the ignorant Adolf. I'm sure that any other female readers you might have, feel similarly disgusted.
If you don't address the issue of Adolf macho bad manners and ignorant comments, I'm sure your female (and any male) readers who value fairness and manners will show their disapproval by leaving Keeping Stock to the block headed and the chauvanistic, and go elsewhere for their reading.

Anonymous said...

Sarah Palin's emails weren't stolen. They were made available under a freedom of information request and distributed by the state of Alaska.

Inventory2 said...

Very Sir Galahad-like Robert; contrasts nicely with your sniping a while back at the female members of the Key household.

And as you well know, I seldom delete comments. If they are in any way offensive, it's better that they stay there, where readers can make their own judgments rather than needing you to be their moral guardian, and telling them what to think.

Oh; still waiting to hear whether or not you condone the personal attacks against Mr Slater by the bloggers and commenters at The Standard; the wait is killing me!

Anonymous said...

Robertguyton, why are you trying to accuse Adolf of sexism? Adolf made no gender-based criticism. It was an equal-opportunity insult; your brain was compared to an oyster too. With your response you proved him correct.

robertguyton said...

Anonymous (brave soul).
Yes. Adolf made offensive comments to a woman and particularly one who didn't deserve to be insulted.
And I said mysogonist and chauvanist.
Can't you read?

Inv2 - do I support those attacking Slater for his poor mental health? Of course not, are you mad?
Seriously, no.

Anonymous said...

yep, as a female reader I have no idea what Robert is on about.

Jacqueline said...

I can take an insult or two - they say more about Adolf than they do about me.

I understand that the lapse in internet security is a bit embarrassing for Labour - but I have to agree with Robert's quote of the day.

I am either completely missing something regarding the information that has been released so far, and the information that it is rumoured that Slater has - and that wooooosh sound just went right over my head, as well - or people are making a big fuss about not much at all.

I think if i was a Labour Party Member i would be pretty happy that the most scandalous thing someone who accessed the websites could find - was a list of supporters.

There must be more to this...than Labour having a security lapse and a list of supporters.

robertguyton said...

Jacqueline shouldn't have to 'take an insult or two' here on Inv2's blog from Adolf or anyone else. Though she's to polite and forgiving to call for it, I will. Adolf should apologise. So should Inv2, for allowing such attacks.

Inventory2 said...

Your cheek astounds me Robert; you're asking for apologies here when you spout vitriol on your blog. You're an expert in telling everyone else what to do; how about you live up to the standards you require of others?

robertguyton said...

Inv2 - you claim I have slighted the women in the Key household - I say you've once again, misunderstood. Max is Key's son for goodness sake!!

jabba said...

Sir Bob, you don't brew your own rhubarb wine by any chance that you drink in copious amounts as that would explain a lot of what you post.
and I'm a facebook friend of JS so would never say anything bad to her. I can see how she See's WO's revelations as being unexciting which 1,000's of other would agree BUT he really has found a pot of gold that shows Labour, or confirms what a useless inept lot they are on all levels

Moist von Lipwig said...

"BUT he really has found a pot of gold that shows Labour, or confirms what a useless inept lot they are on all levels."

Take note Robert and Jacqueline.
Thanks to jabba.
The point has landed.

Jacqueline said...

I never stated that i hadn't missed a point.

I still though - have no idea what that point is, that is so exciting or scandalous.

Maybe you lot get excited easier than i do. O well.

robertguyton said...

Facebook friends jabba?

Golly!

You are such a polite fellow. Perhaps you could teach Adolf how to talk respectfully to a woman. Inv2 won't do it.

Inventory2 said...

And maybe you should be eternally grateful that you're not a political tragic like the rest of us Jackie!

robertguyton said...

And Moist as well, old Jabs. He's treating Jacqueline like she's a foolish girl as well.
What is it with the blokes on this blog?
Inv2? Can you shed some light on this misogyny?

Jacqueline said...

What Adolf said was pathetic, rude, uncalled for, and really did nothing more than detract from the point he was trying to make.

It's not nice when people feel the need to be rude like that, but Inv2 knows me well enough to know that it wouldn't really bother me.

Far worse than that has been said to and about me ;) Roll with the punches - or get knocked out.

Anyway - i look forward to the exciting, and scandalous release of some exciting, and scandalous information.

Til then i will just sit here - scratching my head.

robertguyton said...

At 12:00 Inventory2 said...

Penny; your post was irrelevant to the subject, hence its deletion.

Then at 5:25 ON THE SAME THREAD
Inv2 said...

And as you well know, I seldom delete comments.

Oh Lordy! Protect me from the deluded!
And lookee here! The deleted comment WAS BY A WOMAN!!!

robertguyton said...

Kia kaha Jacqueline.

Inventory2 said...

Rob; Penny's post was barely readable, and was nothing more than promotion of her rather out-there views on conspiracy in the halls of power in Auckland. It had nothing to do with WhaleLeaks, nothing to do with the Labour Party, and nothing to do with anything I have blogged about this year. She was warned yesterday, and chose to ignore the warning. Her gender is irrelevant to the deletion.

Right; bedtime. The alarm is set for 4.45am tomorrow, and I need my beauty sleep!

Ian Guy said...

Blubber face makes some serious allegations, but if you use his same methods you could make the same allegations about National. He seems to think that because a domain is registered by someone from parliament then money must have been used from parliament for that purpose. There are more domains in the National server registered by parliament than Labour have.

Inventory2 said...

@ Penny; that's better; posts here are seldom deleted, and if you are prepared to stick to the subject WITHOUT all the templated autobiographical stuff, your views are welcome. Gender, religion and hair colour have nothing to do with it :)

jabba said...

I treated JS badly .. what drugs are you on Sir Bob .. you really are a wanker.
mmmm, jabs, that's what Boomer, or is it Bomber, called me once when he didn't agree with about something. I will wear the name like a badge of honor