為達最佳瀏覽效果,建議使用 Chrome、Firefox 或 Microsoft Edge 的瀏覽器。

請至Edge官網下載 請至FireFox官網下載 請至Google官網下載
晴時多雲

限制級
您即將進入之新聞內容 需滿18歲 方可瀏覽。
根據「電腦網路內容分級處理辦法」修正條文第六條第三款規定,已於網站首頁或各該限制級網頁,依台灣網站分級推廣基金會規定作標示。 台灣網站分級推廣基金會(TICRF)網站:http://www.ticrf.org.tw

《TAIPEI TIMES 焦點》 Most government apps ‘vulnerable’

2017/05/08 03:00

SECURITY: The most common issues relate to data storage and software vulnerability, among others. Apps that fail to meet the deadline for improvement will be pulled

By Lo Tien-pin and Jonathan Chin / Staff reporter, with staff writer

The Executive Yuan yesterday said 98 government-made applications render their users highly vulnerable to hacking, adding that it would pull the apps from circulation if improvements are not made by the middle of the month.

Only 20 apps out of a total of 144 made by the Executive Yuan’s subordinate agencies passed all tests conducted by its evaluators, an Executive Yuan inventory report to the Legislative Yuan Internal Administration Committee said.

Of the remaining apps, 23 were found to have four to six vulnerabilities and 101 have one to three vulnerabilities, the report said.

The 98 apps that failed the tests pose a “high informational security risk” and the National Development Council last month instructed agencies to improve them before the middle of this month.

Those that fail to meet the deadline are to be pulled, Executive Yuan sources said.

The apps that posed a low risk should be improved before the end of July, sources added.

Apps with six vulnerabilities include the following: Tienkena’s Attack (進擊的鐵克納) by the National Science and Technology Museum, Mobile Water Manager (行動水管家) by Taiwan Water Corp (台灣自來水), Taiwan Railways eTicket (台鐵e訂通) by the Taiwan Railways Administration, Foreign Workers’ Little Assistant (外籍勞工小幫手) by the Workforce Development Agency and Accounting Mobile Go (統計隨身GO) by the Directorate-General of Budget, Accounting and Statistics.

During the budget review for this fiscal year, lawmakers on the Internal Administration Committee passed a resolution that said the Executive Yuan must review its apps for potential vulnerabilities that could compromise state secrets or users’ privacy or financial information.

According to the executive’s report, information security evaluations were conducted on the 144 apps that are available for download by 73 of its agencies.

The evaluations were performed according to the Industrial Bureau’s “guidelines for evaluating basic informational security of mobile applications,” it said, adding that the apps were tested on 10 to 16 protocols, including on their management of sensitive data, connection security and the validity of digital certificates.

The most common security issues were related to storage of sensitive data, vulnerabilities in software, invalid certificates for servers and others, the report said.

The National Development Council is to draft new standards for information security, which all future government-made apps must meet before distribution, the Executive Yuan said.

In addition, the Industrial Bureau is to incorporate informational security evaluation services into contracting guidelines for all agencies, it said.

新聞來源:TAIPEI TIMES

不用抽 不用搶 現在用APP看新聞 保證天天中獎  點我下載APP  按我看活動辦法

焦點今日熱門

2024巴黎奧運

看更多!請加入自由時報粉絲團

網友回應

載入中
此網頁已閒置超過5分鐘,請點擊透明黑底或右下角 X 鈕。