Dan Lacey (@danlacey)
Posted
0 replies · 3 reposts · 7 likes
Here are the answers to questions 4 and 5 of my recent OIA re: the 2020 NZ Election. There's a bit more to this one, but also they withheld process documentation and results for the penetration testing, which is what I really wanted - although I think their reasons for doing so are fair. The first time I read this answer I thought it sounded quite robust, but when I read it a second and third time I realised it actually sounds quite general... and what's really important is how good the testing is, the skill level of the person performing it, and the quality of the setup of all the things they have listed. Otherwise it's just a list. If it's an average IT guy setting it up and a top foreign hacker trying to penetrate the system, then I know who my money would be on from what I've seen so far. It might be worth some follow-up questions to dig further on a few things (although they may not give more information), such as "firewalls" - we know of one firewall within Microsoft Defender... do they also use another? Or does this mean firewalls as in there is one on each PC, or something else. Here's the link from the response: https://www.gcsb.govt.nz/publications/the-nz-information-security-manual/ If anyone has any insights or ideas for follow-up questions, then please let me know.