Gauteng government thinks we are hackers. We are not
Response to e-Panic button security vulnerabilities is misleading
The Gauteng Department of e-Government recently issued a statement addressing security concerns regarding its e-Panic Button app. According to the department, they recently detected and resolved an attempted data breach involving a highly specialized organization with advanced cybersecurity testing expertise. However, this claim has been disputed by GroundUp, a journalism organization.
GroundUp's Joel Cedras, a journalist and part-time software developer, accessed the app and discovered that the personal information of users was openly accessible. Cedras did not employ any advanced tools; rather, he simply downloaded the app and examined its database. The database was open, and all the necessary tools for accessing the data were standard, open-source software.
The developers of the app, Evolve Value Added Services, acknowledged the issue and confirmed that they had addressed the problems. They appreciated GroundUp's responsible reporting and praised the journalist's decision to prioritize public protection. The article reveals that personal information such as crime reports, names, phone numbers, GPS coordinates, and location histories were readily available in the app's database, despite the privacy policy claiming data obfuscation.
This failure to adequately protect user data highlights the government's IT incompetence and raises concerns about the allocation of multi-million-rand contracts to companies with insufficient experience and technical expertise.
Written by urgent.news from GroundUp's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.