Modern Australian
Men's Weekly

.

Security flaws in Microsoft email software raise questions over Australia's cybersecurity approach

  • Written by Carsten Rudolph, Associate professor, Monash University
Security flaws in Microsoft email software raise questions over Australia's cybersecurity approach

On March 2, 2021, Microsoft published information about four critical vulnerabilities in its widely used Exchange email server software that are being actively exploited. It also released security updates for all versions of Exchange back to 2010.

Microsoft has told cybersecurity expert Brian Krebs it was notified of the vulnerabilities in “early January”. The Australian Cyber Security Centre has also issued a notice on the vulnerabilities.

The situation has been widely reported in the general media as well as specialist cybersecurity sites, but often inaccurately. But the situation also highlights a contradiction in government cybersecurity policy.

When governments find flaws in widely used software, they may not publish the details in order to build up their own offensive cybersecurity capabilities, i.e. the ability to target computers and networks for spying, manipulation and disruption. Operations like this often rely on exploiting vulnerabilities in commercial software — thus leaving their own citizens vulnerable to attack as a consequence.

What happened?

Microsoft has issued patches to fix the vulnerabilities and provided advice on how to respond if systems have already been affected.

These vulnerabilities can be really damaging for anybody running their own Exchange mail server. Attackers can run any code on the server and fully compromise a business’s email, allowing them to impersonate anybody in the business. They could also read all email stored on the server and potentially compromise more systems within the businesses’ network.

Who was affected?

It’s important to clear up exactly who the vulnerabilities affected: anybody running their own instance of Exchange, and the risk was higher if web access was turned on.

An ABC/Reuters report said:

All of those affected appear to run Web versions of email client Outlook and host them on their own machines, instead of relying on cloud providers.

But using a cloud-hosted version of Exchange wouldn’t necessarily solve the problem, as the vulnerabilities still exist. What’s more, larger enterprises will most probably still choose or be required by regulation to also run a local Exchange server that can be exploited in the same way.

Read more: 5 ways the COVID-19 pandemic has forever changed cybersecurity

Another open issue with moving mail servers to the cloud is that it also gives the provider access to all unencrypted emails by default. End-to-end encryption would increase security, but this is not currently standard practice.

Questions for Microsoft

As vulnerabilities existed in versions of the software released as long ago as 2010, we can assume more skilled attackers have already used them. This raises a fundamental question about the quality of the software, which Microsoft has been developing since 1996. Why did Microsoft not spot these vulnerabilities earlier?

Another question: if Microsoft knew about the vulnerabilities in early January, why did it take two months to alert its customers?

Questions for cybersecurity policy

We also need to consider the bigger picture of how we deal with vulnerabilities in software that builds the backbone of our computer and network infrastructure. Obviously, these vulnerabilities would have been a great offensive cybersecurity tool for any number of actors.

There is a basic conflict between building offensive cybersecurity capabilities and protecting our own businesses and citizens.

Imagine you are tasked with building offensive cybersecurity capabilities. You discover these vulnerabilities in Microsoft Exchange. Would you alert the vendor, Microsoft in this case, to make sure they are fixed as soon as possible, or would you keep them secret to not to lose your great new cyber weapon? Secretly having access to an organisation’s email could be very valuable for law enforcement or intelligence agencies.

Read more: The SolarWinds hack was all but inevitable – why national cyber defense is a 'wicked' problem and what can be done about it

Australia’s Cyber Security Strategy 2020 does not address the contradiction between establishing offensive cybersecurity capabilities and protecting Australians from cybersecurity vulnerabilities.

The establishment of offensive cybersecurity capabilities is explicitly mentioned in the strategy. In contrast, the detection of vulnerabilities with the goal of mitigation is not a clear goal.

Nor is openness about existing vulnerabilities — which would empower Australian citizens to react to them — part of the strategy. Australia has the expertise across the public sector, private sector and civil society to have this important dialogue on how to best protect Australian citizens and businesses.

Authors: Carsten Rudolph, Associate professor, Monash University

Read more https://theconversation.com/security-flaws-in-microsoft-email-software-raise-questions-over-australias-cybersecurity-approach-156864

WooCommerce Website Designer: Building High-Performance Online Stores That Drive Sales

A WooCommerce website designer plays a crucial role in helping businesses create high-performing, visually appealing, and conversion-focused online...

The Importance of Dogging Courses in Australia: How to Get Your Dogman Ticket

In Australia’s construction, mining, and industrial sectors, safety and technical competence are essential for any worker handling heavy loads and l...

Beyond the Hype: Why Breitling Speaks to the Modern Watch Collector

There’s a point every collector reaches when the chase for the latest release gives way to a deeper appreciation for quality. The thrill of new mode...

Elevate your Perth workspace: Sleek tech with managed IT Services

In today's fast-paced business environment, having a reliable and efficient IT infrastructure is no longer a luxury, it's a necessity. For businesse...

7 Ways a Luxury Australian Cruise Transforms Your Travel Expectations

Dreaming of your next holiday? Forget the crowded tourist traps and consider something truly special: a luxury australian cruise. More than just a ...

How Polycarbonate Became the Backbone of Modern Australian Design

The design landscape in Australia has been audacious, innovative and climate-conscious at all times. Design in this area is all about striking a balan...

Affordable Invisalign in Bangkok Why Australians Are Choosing Thailand

More Australians are investing in Invisalign to straighten their teeth, but the treatment in Australia can cost thousands of dollars and often takes m...

Designing a Tranquil Oasis in Your Backyard

Nothing beats a warm summer evening spent in a gorgeous backyard. The backyard is the perfect space to unwind and spend some of the most magical momen...

How a Well-Designed Gym Can Improve Your Performance

Have you ever entered a gym that just feels off and couldn’t focus on your workout? Maybe it’s the layout that was weird, or the lack of natural l...

Wellness Checkups at Work: Key to Employee Happiness and Higher Output

Employee wellness programs are reshaping how companies think about productivity and satisfaction. When people feel healthy, they perform better, sta...

Experience the Elegance of Plantation Shutter Blinds: Enhance Your Décor Today

When it comes to elevating your home’s interior, few window treatments combine sophistication and practicality as effortlessly as plantation shutter...

Common Questions Women Are Afraid to Ask Their Gynaecologist (and Honest Answers)

Visiting your gynaecologist isn’t always easy. Even though reproductive and sexual health are essential parts of overall wellbeing, many women fee...

Designing Homes for Coastal Climates – How to Handle Salt, Humidity, and Strong Winds in Building Materials

Living by the ocean is a dream for many Australians, offering breathtaking views, refreshing sea breezes, and a relaxed lifestyle that’s hard to b...

This OT Week, Australia’s occupational therapists are done staying quiet

Occupational Therapy Week is typically a time to celebrate the difference occupational therapists make in people’s lives. But this year, many sa...

Melbourne EMDR Clinic Sees Growing Interest in Patients with Depression

Depression is a common mental health condition affecting around 1 in 7 Australians. It is typically diagnosed when an individual has experienced a p...

Proactive approaches to mental wellbeing

Life gets busy quickly. For many adults, each week is a constant mix of work commitments, raising kids, managing a household, settling bills, catching...

The Power of Giving Back: How Volunteering Shapes Your Mindset

To say the least, volunteering can maximally change the way you see the world. Period. When you step into someone else’s shoes, even for a few hours...

How to Level Up Your Workouts with Simple Home Equipment

Working out at home has reached the peak of its popularity. Whether you’re short on time or simply prefer the comfort of your own space, home traini...