Modern Australian
Men's Weekly

.

Security flaws in Microsoft email software raise questions over Australia's cybersecurity approach

  • Written by Carsten Rudolph, Associate professor, Monash University
Security flaws in Microsoft email software raise questions over Australia's cybersecurity approach

On March 2, 2021, Microsoft published information about four critical vulnerabilities in its widely used Exchange email server software that are being actively exploited. It also released security updates for all versions of Exchange back to 2010.

Microsoft has told cybersecurity expert Brian Krebs it was notified of the vulnerabilities in “early January”. The Australian Cyber Security Centre has also issued a notice on the vulnerabilities.

The situation has been widely reported in the general media as well as specialist cybersecurity sites, but often inaccurately. But the situation also highlights a contradiction in government cybersecurity policy.

When governments find flaws in widely used software, they may not publish the details in order to build up their own offensive cybersecurity capabilities, i.e. the ability to target computers and networks for spying, manipulation and disruption. Operations like this often rely on exploiting vulnerabilities in commercial software — thus leaving their own citizens vulnerable to attack as a consequence.

What happened?

Microsoft has issued patches to fix the vulnerabilities and provided advice on how to respond if systems have already been affected.

These vulnerabilities can be really damaging for anybody running their own Exchange mail server. Attackers can run any code on the server and fully compromise a business’s email, allowing them to impersonate anybody in the business. They could also read all email stored on the server and potentially compromise more systems within the businesses’ network.

Who was affected?

It’s important to clear up exactly who the vulnerabilities affected: anybody running their own instance of Exchange, and the risk was higher if web access was turned on.

An ABC/Reuters report said:

All of those affected appear to run Web versions of email client Outlook and host them on their own machines, instead of relying on cloud providers.

But using a cloud-hosted version of Exchange wouldn’t necessarily solve the problem, as the vulnerabilities still exist. What’s more, larger enterprises will most probably still choose or be required by regulation to also run a local Exchange server that can be exploited in the same way.

Read more: 5 ways the COVID-19 pandemic has forever changed cybersecurity

Another open issue with moving mail servers to the cloud is that it also gives the provider access to all unencrypted emails by default. End-to-end encryption would increase security, but this is not currently standard practice.

Questions for Microsoft

As vulnerabilities existed in versions of the software released as long ago as 2010, we can assume more skilled attackers have already used them. This raises a fundamental question about the quality of the software, which Microsoft has been developing since 1996. Why did Microsoft not spot these vulnerabilities earlier?

Another question: if Microsoft knew about the vulnerabilities in early January, why did it take two months to alert its customers?

Questions for cybersecurity policy

We also need to consider the bigger picture of how we deal with vulnerabilities in software that builds the backbone of our computer and network infrastructure. Obviously, these vulnerabilities would have been a great offensive cybersecurity tool for any number of actors.

There is a basic conflict between building offensive cybersecurity capabilities and protecting our own businesses and citizens.

Imagine you are tasked with building offensive cybersecurity capabilities. You discover these vulnerabilities in Microsoft Exchange. Would you alert the vendor, Microsoft in this case, to make sure they are fixed as soon as possible, or would you keep them secret to not to lose your great new cyber weapon? Secretly having access to an organisation’s email could be very valuable for law enforcement or intelligence agencies.

Read more: The SolarWinds hack was all but inevitable – why national cyber defense is a 'wicked' problem and what can be done about it

Australia’s Cyber Security Strategy 2020 does not address the contradiction between establishing offensive cybersecurity capabilities and protecting Australians from cybersecurity vulnerabilities.

The establishment of offensive cybersecurity capabilities is explicitly mentioned in the strategy. In contrast, the detection of vulnerabilities with the goal of mitigation is not a clear goal.

Nor is openness about existing vulnerabilities — which would empower Australian citizens to react to them — part of the strategy. Australia has the expertise across the public sector, private sector and civil society to have this important dialogue on how to best protect Australian citizens and businesses.

Authors: Carsten Rudolph, Associate professor, Monash University

Read more https://theconversation.com/security-flaws-in-microsoft-email-software-raise-questions-over-australias-cybersecurity-approach-156864

The Cost of Converting a Shipping Container into a Liveable Space

Container conversions often require more planning and labour than expected Early costs include foundations, framing, and structural reinforceme...

Marriage Celebrant for Modern Lovers Who Want Something Different

Many couples today feel pressure to follow the same wedding traditions their parents or grandparents did. They might sit through long ceremonies that ...

Why Everyone’s Signing Up for Fitstop’s 6-Week Challenge (Again)

Hint: It’s not just for the gains. Somewhere between the endless TikTok fitness hacks and the unrealistic “30-day shred” promises, we forgot ...

The Mental & Financial Benefits of Minimalist Caravan Travel

Minimalist caravan travel has grown in popularity, not just for its practical appeal but also for the sense of freedom it brings. With the rise of c...

Sydney Property Lawyers: Your Complete Guide to Smooth Transactions

Navigating the Sydney property market can feel like traversing a minefield, can't it? The process, laden with legal jargon and complex procedures, o...

Electrician Perth: Your Go-To Guide for Home Electrical Safety

When it comes to keeping your home safe and sound, electricity is something you simply can't afford to ignore. Faulty wiring, outdated switchboards...

Why More Homes and Businesses Are Choosing an Electric Sliding Door

Convenience, aesthetics, and technology often go hand in hand when it comes to architectural choices. One solution that delivers all three is the el...

Real Estate Rubbish Removal That Keeps Properties Market-Ready

When it comes to real estate, presentation is everything. Whether it’s a property for rent or sale, first impressions count. Cluttered backyards, ...

Real Estate Rubbish Removal That Keeps Properties Market-Ready

When it comes to real estate, presentation is everything. Whether it’s a property for rent or sale, first impressions count. Cluttered backyards, ...

Ironman 4x4: Building Complete Suspension Systems for Australia

The name Ironman 4x4 resonates throughout Australia's 4WD community, particularly when discussing Ironman suspension solutions. This Australian bran...

Pontoon Boats - The New Must-Have for Luxe Canal Homes

If you are living on a canal in Australia, you are already living the dream. But living near the water without a boat is like owning a horse without...

Perth Airport Transfers: Choosing the Right Service

Touching down in a new city can be exciting, but let's be honest, it can also be a bit stressful. After a long flight, the last thing you want to wo...

How to Save Smart: Cheapest Travel Insurance for Schengen Visa without Cutting Corners

Picture this: you’ve found a last-minute flight to Milan, your hotel booking comes with breakfast and a rooftop view, and your itinerary is ready ...

Keeping Lone and Remote Workers Safe: Employer Duties and Practical Solutions

In Australia, thousands of employees work alone, in remote locations, or in direct contact with the public every day. While these roles are critical...

How Your General Dentist Supports Your Smile Over a Lifetime

A healthy grin is more than just a desirable feature; it reflects overall health, well-being, and self-esteem. Our oral health needs evolve from chi...

A Brighter Smile in Sydney: Expert Cosmetic Dentists and Veneers Solutions

A confident smile can open doors, boost your self-esteem, and leave a lasting impression. In Sydney, more people than ever are turning to cosmetic den...

How To Keep Vase Flowers Fresh Through Australia’s Coldest Months

Winter flowers develop slowly, which gives them stronger structure and longer vase life Heat from indoor environments is the biggest threat to th...

Artificial Intelligence is Powering the Growth of Australian Telehealth Services

Many Australians have traditionally experienced difficulties in accessing timely and quality healthcare, especially those who live in rural or remot...