The Gauteng Department of e-Government has issued a statement regarding the security failures of its e-Panic Button app, following a report by GroundUp. The department claims that an attempted data breach was carried out by a "highly specialised organisation with advanced expertise in cybersecurity testing". MEC for e-Government Bonginkosi Dhlamini stated that the incident was swiftly identified and resolved without compromising any citizens' personal information.
GroundUp has responded to the Gauteng government's statement, clarifying that they are not a "highly specialised" cybersecurity organisation. The report was conducted by journalist Joel Cedras, who is also a part-time software developer, using standard and open-source tools. Cedras discovered that the app's database was open, with crime reports, names, phone numbers, GPS coordinates, and location histories of users accessible to anyone.
The Gauteng government's statement appears to be a response to GroundUp's report, which revealed that the e-Panic Button app had significant security vulnerabilities. The app, developed by Evolve Value Added Services, was found to have an open database that exposed sensitive user information. The developers have since confirmed that the issues have been addressed and have thanked GroundUp for bringing the matter to their attention.
GroundUp's report highlighted the ease with which the security vulnerabilities were discovered, stating that it was not an "attempted" breach, but rather a straightforward access of publicly available information. The organisation has expressed concern that the Gauteng government's IT systems are plagued with bad design and security vulnerabilities, which can be exploited by malicious actors.
The e-Panic Button app was implemented at a reportedly outrageous cost of R131-million, with the aim of addressing the loss of public confidence in the emergency 10111 number. However, GroundUp has questioned the effectiveness of the app, citing its parallel system that competes with private sector panic button apps and requires ongoing maintenance.
GroundUp has run several exposés on IT incompetence in state IT systems, highlighting the vulnerability of these systems to security breaches. The organisation has stated that it will report IT vulnerabilities in large companies and government departments that are grossly incompetent, but will not report every vulnerability found, especially in small companies with limited resources.
The Gauteng government has not responded to GroundUp's allegations, despite multiple attempts by the organisation to engage with them. The department's technical teams allegedly engaged with the developers to address the identified vulnerabilities, but no direct response has been received from the Gauteng government.
Key points
- The Gauteng government's e-Panic Button app was found to have significant security vulnerabilities, exposing sensitive user information.
- GroundUp has clarified that they are not a "highly specialised" cybersecurity organisation, but rather journalists who discovered the vulnerabilities using standard tools.
- The e-Panic Button app was implemented at a cost of R131-million, with concerns raised about its effectiveness and the Gauteng government's IT competence.