News
Gauteng says e-panic button secure after students find exposed user data
University students found exposed user data in Gauteng’s e-panic button app. The province says no personal information was compromised and patches were applied.
University students analysing Gauteng’s e-panic button app found an unauthenticated database that exposed user details, but the province’s e-government department says steps have been taken and that no citizens’ personal information was compromised.
What happened
According to The Citizen, university computer science students discovered the flaws while analysing the e-panic button app’s code last week. One of the students, Joel Cedras, reported that he was easily able to access personal information of users.
“None of the information we found was encrypted,” Cedras told SABC News, as quoted by The Citizen.
Scale of the system
The Citizen reported that the department revealed the platform’s usage since launch, noting 288 307 active users registered on the e-panic button system, who had logged 114 414 emergency call-outs, resulting in the reporting of 59 394 crimes.
Government response
According to The Citizen, the e-government department said it had “identified an attempted security breach” and described it as involving “a highly specialised organisation with advanced cybersecurity expertise and capabilities in vulnerability identification and security testing.”
The department told The Citizen that its technical teams had implemented corrective measures promptly and stated that “no citizens’ personal information was compromised as a result of the incident.”
Political reaction
The Citizen reported that the DA said it would report the matter to the Information Regulator and demanded that the department appear before the e-government portfolio committee to explain.
What the students said
According to The Citizen, Joel Cedras said he was conducting a static analysis of the app’s code when he noticed the database storing user information was unauthenticated and accessible. Cedras told the broadcaster that the privacy policy claimed data was encrypted, but he could see user addresses, ID numbers, licence plate numbers, contact details and details of crimes reported by users, as reported by The Citizen.
Next steps cited by the department
The department, as cited by The Citizen, said it had patched the digital holes in the app and that tighter cybersecurity protocols would be implemented in future.
Follow Joburg ETC on Facebook, Twitter, TikTok and Instagram
For more News in Johannesburg, visit joburgetc.com
Source: citizen.co.za
