• 0 Posts
  • 3 Comments
Joined 12 days ago
cake
Cake day: January 5th, 2026

help-circle
  • I don’t have any insider information so I’m just spitballing here :D but I have worked in health IT field before and I’m not even a little surprised that bugs like these exist - and have been exploited.

    Poor authorisation handling bug is quite common. Authentication is largely a solved problem what with OAuth (not that a lot of NZ health IT providers use it… sigh) but each software developer still has to solve the problem of authorisation. And it’s just all too easy to forget that random IDs are not secure and are not even random.