AusCERT loses passwords to Govt service
The Australian Computer Emergency Response Team (AusCERT) has conceded losing a DVD containing the usernames and passwords of subscribers to the Federal Government's Stay Smart Online Alert Service in the mail.
AusCERT sent the disc — containing usernames, email addresses, passwords and recovery phrases — through Australia Post on April 11 but it was never received as intended by the Department of Broadband, Communications and the Digital Economy.
The department alerted affected subscribers late last week but assured the passwords were "unreadable" due to a cryptographic hash. However, neither AusCERT or the department were able to say what encryption hash was used to secure the records. Weak encryption algorithms, such as MD5, can be easily defeated, placing subscriber details at risk.