logo
Police warned over shifting information to Microsoft cloud services

Police warned over shifting information to Microsoft cloud services

RNZ News27-04-2025
Sensitive police information is being moved from police stations to off-site at Microsoft's 'cloud' of computer servers. File photo.
Photo:
123rf
Police have been warned that shifting their information to the cloud could have "severe detrimental impacts" if they are not careful.
The shift to Microsoft cloud services has started in Wellington.
But a privacy impact assessment says if staff accidentally let someone into the data, the consequences could be "death of individuals, extensive injury and hospitalisation".
It lists ways to make it safer.
The tech upgrade changes how vast amounts of restricted, sensitive information is handled, from on-site at police stations using 2013 Microsoft technology, to off-site at Microsoft's 'cloud' of computer servers.
The data can identify individuals.
"Should this become compromised, there could be severe detrimental impacts on the wellness and safety of individuals, as well as the reputation of the NZ police 'brand' and erosion of trust from the public and government," said the May 2022 assessment, newly released to RNZ under the Official Information Act.
"The information that will be stored, processed and transmitted by the service has been classified as up to RESTRICTED, and will include sensitive and personal information. Compromise of information classified RESTRICTED would likely impact NZ police's reputation and operation."
It detailed several risks arising from the upgrade against each of the 12 Privacy Act principles - one severe 'red' one, and several 'orange'. It also listed 31 measures police should take.
"This assessment identified that the proposed use of Office 365 service exposes NZ police to a Very High level of privacy risk. It identifies a total of 12 privacy risks for NZ police through the expected use of the service, one of which was rated as Very High and eight which are rated as High," it said.
"If the privacy risks highlighted in this report are not managed to an appropriate level, NZ police is exposed to privacy threats that may result in Very High health & safety impacts and reputational damage."
But if the controls were taken, then the upgrade would be "within its risk appetite".
It is not clear how many of these measures police were now instituting at the trial stage of the upgrade. "The technical delivery of this work has been relatively smooth, with the products and processes working well," NZ police told RNZ.
The assessment report listed a dozen different laws police and Microsoft must comply with.
It noted Microsoft and Spark will run the new system for police, and that this was another point of risk.
One risk was that a foreign government or law enforcement agency could ask Microsoft for New Zealand police data. The US has a Cloud Act that allows for this to happen, though it is not known if the power has been exercised as it does not have to declare it.
The cloud upgrade has been on the cards for years but police have hit roadblocks on the tech front, including from [last year's public sector funding cuts,
RNZ has reported
.
The cloud privacy assessment was started in 2019, but a trial only began in September in Wellington.
Just five out of 32 workgroups in Wellington district have gone live so far.
"The initiative is continuing to fine-tune the framework," police said in the OIA response last week.
A 2022 security risk assessment of the move said Microsoft and its cloud datacentres had an "extensive security toolset" and "layers of defence-in-depth".
The cloud upgrade is part of moves to try to relieve what reports have called "unsustainable" pressure on frontline officers as well as to conform to Privacy Commissioner orders to stop the police illegally taking and storing photos of young people. They amassed tens of thousands illegally up till 2020,
as RNZ exposed
.
It is in line with successive governments' push for all agencies to shift to cloud services, which has proved a boon for Microsoft, Amazon and Google, and an incentive for the former two US tech giants to build new datacentres in this country.
A second police tech upgrade - to digital notebooks from paper notebooks at the front line in 2023 - aimed to add photo handling features this year.
An assessment of this, also released under the OIA, also found a "high" risk, but that this was more easily managed. It laid out 41 measures to take.
Police did not formally consult the Privacy Commissioner about either the Digital Notebooks and Microsoft moves, though privacy and security risk assessments were run on both, they told RNZ in the OIA.
They have had no reports done on how the seven-month-old Wellington pilot was going, but would at the end, they said.
The cloud work was being done largely in-house, with just one contractor hired for $288,000.
Sign up for Ngā Pitopito Kōrero,
a daily newsletter curated by our editors and delivered straight to your inbox every weekday.
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Tech firms say deals for power give new life to nuclear plants at risk of going offline
Tech firms say deals for power give new life to nuclear plants at risk of going offline

NZ Herald

timea day ago

  • NZ Herald

Tech firms say deals for power give new life to nuclear plants at risk of going offline

Meta signed a 20-year agreement for the power flowing from a large legacy reactor in Illinois. Microsoft struck a deal to restart a reactor next to the one at Pennsylvania's Three Mile Island plant that was closed in 1979 by a partial meltdown. And Amazon last month in the same state locked up power from a 42-year-old nuclear plant down the Susquehanna River. Tech companies are scouring the nation for other geriatric nuclear plants to power their AI dreams, according to interviews with nuclear industry officials and company earnings calls. Their interest is focused on the roughly two dozen operating plants in unregulated markets, which are in many cases free to sell power to the highest bidder. They make up about half of the 54 plants still operating in the US. The tech firms say the deals give new life to plants at risk of going offline or that have already been shut down. Contracts that lock in rates for decades are attractive to plant operators, and the electricity flows without directly generating new carbon emissions. Critics say Silicon Valley's nuclear spree will make it more likely that consumers will face electricity rate hikes or shortages in coming years as the US faces soaring demand for power - driven in part by new data centres. By locking up ageing nuclear plants instead of building new power generation, tech firms could leave communities to fall back on fossil fuels, extending the life of polluting coal and gas plants. A few years ago, nuclear energy struggled to compete with cheaper renewables and natural gas, but all power sources are now in greater demand. Contracts with tech firms can offer nuclear plant operators as much as double the market rate for electricity. Jackson Morris, a director with the environmental advocacy group Natural Resources Defence Council, said tapping nuclear energy allows companies to keep pledges to use carbon-free power, but 'doesn't do anything to solve for the impact they're having on consumers'. 'They're insulating themselves from their own impact,' he said. Amazon, Google, Meta, and Microsoft declined to answer questions about which additional nuclear plants they may be seeking to buy power from, as well as the potential impacts of such purchases on other ratepayers and the environment. Amazon founder Jeff Bezos owns the Washington Post. All of the companies say they mitigate the impact of their energy use on other customers, by working with utilities to shield customers from funding infrastructure that serves only data centres and investing in bringing new clean technologies to the power grid. Tech firms say their data centres will eventually be powered by a new generation of cheaper but more sophisticated nuclear reactors, to be designed with help from AI. However, the technology has been stymied by engineering issues, supply chain challenges and regulatory hurdles. Google and Microsoft are also investing in fusion energy, which is even less proven. Controls, monitors and indicator lights fill the main control room at Three Mile Island last year. Photo / Wesley Lapointe, The Washington Post 'It turns out it is hard to go from all of that fancy new technology on a spreadsheet to an actual piece of infrastructure that isn't run with analogue controls,' said Ted Nordhaus, co-founder of the Breakthrough Institute, a California-based energy think-tank. 'Right now there is not much else to do other than try to squeeze every electron you can out of the existing nuclear fleet.' Chain reaction Energy companies that own nuclear plants are thrilled by the tech industry's recent interest, calling it a springboard for nuclear power's resurgence. New Jersey power company PSEG told investors in February that it is in talks with tech firms about selling large amounts of power directly from its nuclear reactors on what is known as the Artificial Island complex in Delaware Bay. Company chief executive Ralph LaRossa said in April that requests for new power from the utility by data centres has exploded over the past year, jumping 16-fold to 6.4 gigawatts, an amount of electricity that could power several million homes. In Texas, energy company Vistra says it is in talks with tech firms interested in buying energy from the Comanche Peak nuclear plant, near Fort Worth, and possibly others it owns in Ohio and Pennsylvania. 'I think we will see more large deals,' said Dan Eggers, executive vice-president at Constellation Energy, which owns or partially owns 13 nuclear energy complexes across the country. Constellation has already rezoned land next to the Byron Clean Energy Centre, a nuclear plant in Illinois, so tech companies can build data centres there. It is seeking similar changes at the campus of the Calvert Cliffs nuclear plant in Maryland on Chesapeake Bay. The company says it is also contemplating new deals with tech companies for long-term nuclear power contracts in Pennsylvania and New York. Lawmakers and regulators in some communities are concerned data centre nuclear deals could increase costs for other ratepayers and weaken the power grid. Some Maryland lawmakers want to ban Constellation from inviting data centre construction alongside Calvert Cliffs, which produces nearly 40% of the state's electricity. A report from the state's Public Service Commission warns that siphoning energy from the plant away from the power grid for data centres could destabilise the system. The Calvert Cliffs nuclear power plant in Lusby, Maryland, is seen in 2011. Photo / Jonathan Newton, The Washington Post 'In addition to being costly to replace a large nuclear plant, the quality of the generation … would be difficult to replace,' the report says. Unlike solar or wind facilities, nuclear power provides round-the-clock electricity when the plants are operating, in any weather. In many cases, nuclear power that gets redirected to tech companies would be backfilled on the power grid with gas or coal generation. Nuclear industry officials say the solution is not restricting deals, but building more plants. 'It is short sighted to say we will just ignore all this demand over the next few years and tell these companies to get their power somewhere else, when this could set us up for a lot of growth in the industry,' said Benton Arnett, senior director of markets and policy at the Nuclear Energy Institute, an industry group. But even nuclear executives working with tech firms acknowledge that pulling zero emissions nuclear energy away from other customers will have an impact on the climate and can be out of sync with ambitious commitments tech firms have made to reduce their carbon footprint. 'A growing list of people are realising they can't have everything they want,' said Robert Coward, principal officer at MPR Associates, one of the nuclear industry's leading technical services firms. Critical mass The scramble by tech firms to secure more nuclear energy quickly has led Silicon Valley companies to some unexpected places. They include a dormant construction site in South Carolina, where plans to build a Three Mile Island-size nuclear plant were abandoned in 2017, after the developer burned through US$9 billion on a project that struggled with cost overruns and engineering setbacks. Local ratepayers were saddled with the bill. Federal prosecutors in 2020 secured prison sentences for executives involved with the project for lying to investors and ratepayers about its viability. Now, several big tech companies are among those that have expressed interest in bringing the VC Summer nuclear project back to life, according to testimony from officials at utility Santee Cooper, after it invited proposals for restarting the project. A utility spokesperson would not say if there are tech companies among the three or four proposals she said are finalists for a potential deal. Tech firms are also eyeing a revival of Duane Arnold Energy Centre in Iowa, a 1970s vintage nuclear plant majority-owned by NextEra that was mothballed in 2020 after a fierce storm damaged its cooling towers, according to company earnings calls. The repairs were initially deemed too costly, but data centres have shifted the economics of nuclear energy, and NextEra is mulling a reboot to serve the facilities. 'If we continue to see the kind of prices Microsoft is willing to pay for nuclear power from Three Mile Island, these type of deals become a solid economic proposition,' said Carly Davenport, a utilities analyst at Goldman Sachs. She said estimates show the tech company is paying as much as twice the going rate on the open market, and locking in for a 20-year contract. Duane Arnold is one of the last retired plants intact enough to restart. Many of the retired plants in the US have already been dismantled. But tech companies are finding ways to squeeze more juice out of active reactors in the ageing national fleet, pursuing reactor 'uprates' from federal regulators that allow increased output. Nuclear power companies aim to increase the power output of the existing US nuclear fleet by the equivalent of three large new reactors using that tactic. As more deals involving ageing reactors emerge, consumer advocates and environmental groups are growing concerned about the impact on everyday ratepayers and the planet. Amazon reconfigured its deal in Pennsylvania after it was rejected by federal regulators that expressed concern about the effects on consumer electricity bills. The company had proposed routing power from the plant directly to nearby data centres, allowing it to avoid paying usage fees for the electric grid. A caution sign warns of radioactive exposure on the turbine deck at Three Mile Island, which is being renamed Crane Clean Energy Centre. Photo / Wesley Lapointe, The Washington Post The online retailer last month announced a deal with plant owner Talen in which it agreed to pay grid fees, a contract that will effectively lock up a large chunk of existing power generation at a time the Mid-Atlantic power grid desperately needs more energy. The deal is notable because it puts an existing nuclear plant on sound economic footing for another decade of emissions-free power generation, said former federal energy commissioner Allison Clements. However, Amazon is also removing supply from the grid just as demand from AI and other uses such as electric cars and air conditioners is spiking. 'There isn't enough power on the grid,' Clements said, and the increased load forecast by analysts, utilities and grid operators cannot be met by existing power sources. 'There's not enough room on the system.'

Wasp warning: Ruakākā Beach walker warns public after being stung 50 times
Wasp warning: Ruakākā Beach walker warns public after being stung 50 times

NZ Herald

timea day ago

  • NZ Herald

Wasp warning: Ruakākā Beach walker warns public after being stung 50 times

Radewald ran to her car with her dog in tow, managing to bat away the majority of the wasps as she got in her vehicle. She believed she had been stung all over her body about 50 times. The pain was 10 times worse than if she had been stung once, she said. At home, Radewald had a cold shower and tried to calm herself down. 'I felt itchy and in pain all over,' she said. Radewald was amazed the wasps had managed to sting her through two layers of clothing. Radewald used vinegar and other natural ointments to treat the sores, which had since started to heal. 'I got away. I feel okay,' she said. Radewald was unsure what species of wasp had attacked her. The most commonly encountered wasps in Northland are the German wasp and the common wasp. The Asian paper wasp is also widespread in the upper North Island. The German European Wasp is one of the common wasp varieties seen in Northland. Elke Radewald was unsure what species of wasp attacked her. Photo / 123rf She reported the wasps to the Whangārei District Council, which reportedly told her they would follow up. Radewald said a member of the public instead dealt with the wasps themselves. She also posted online to warn others, especially those with children, to take care. Whangārei District Council senior technical officer Spencer Jellyman said the council decided the wasps had most likely been bees as wasps do not usually swarm but bees do. 'Bee swarms move about, so rather than going to the location to find them we decided to monitor for further incidents before investigating further.' Jellyman said council did not receive any more reports about the swarm in the days after the incident, which they usually would if there was an aggressive swarm of bees or wasps near a path. Department of Conservation (DoC) science adviser Eric Edwards said the incident sounded consistent with the behaviour of a disturbed wasps' nest that was possibly concealed. 'These species can become very aggressive when they feel threatened, particularly in late summer and autumn when nest sizes peak. 'However, aggressive behaviour can also occur during warmer winter days if nests are still active.' Phil Tunstall, owner and manager of pest management company Enviropro, said it was possible Radewald's dog may have stood on a wasp nest or disturbed one higher up. He said wasps were hibernating in nests on the ground, in trees or tree trunks at this time of year. 'If you do stand on a nest over winter time they will attack. 'They get very angry very quickly and they go into protect mode.' Tunstall said Enviropro typically got about 50 callouts around February and March, and perhaps one or two in winter. Wasp callouts had been common this summer as it had been reasonably warm, he said. The mild winter had meant the cold wasn't enough to impact a nest, he said. How to prevent bee and wasp stings Health New Zealand Te Whatu Ora information states that calling an exterminator is the best practice for wasps found at home. It also states to take care when eating food outdoors, especially sugary drinks and fish sandwiches, which can attract bees and wasps. Other tips include: Avoid bright-coloured or dark-coloured clothing Avoid perfumes If you're hiking in bush and forest areas, wear hats, long-sleeved shirts and long pants, and light colours. For advice on first aid and treatment of stings, call the National Poisons Centre on 0800 764 766. Brodie Stone covers crime and emergency for the Northern Advocate. She has spent most of her life in Whangārei and is passionate about delving into issues that matter to Northlanders and beyond.

GitHub Copilot users surpass 20 million as AI tools surge in demand
GitHub Copilot users surpass 20 million as AI tools surge in demand

Techday NZ

time2 days ago

  • Techday NZ

GitHub Copilot users surpass 20 million as AI tools surge in demand

GitHub Copilot now reports more than 20 million users and widespread adoption by over 90 percent of the Fortune 100, reflecting growing demand for AI-enhanced development tools across the software industry. The figures, shared as part of Microsoft's Q4 FY25 earnings update, show a significant increase from the previous quarter, where user numbers stood at 15 million. The platform also highlighted that its Copilot Enterprise customer base increased 75 percent quarter-over-quarter. Growth and adoption AI-enabled projects on GitHub have more than doubled over the past year. The GitHub Code Review agent is now used to perform millions of code reviews each month on the platform, indicating sustained engagement from both new and existing users. The release of new features over recent months, including a fully autonomous coding agent, has aimed to expand options for developers to automate routine coding jobs. This tool is designed to allow programmers to assign low- to medium-complexity tasks or issues and monitor their completion through GitHub's pull request system, with comprehensive security measures in place. How the coding agent works Developers can assign an issue to Copilot, either via the web, mobile, or the GitHub CLI, as they would a team member. The agent then initiates a secure development environment using GitHub Actions, applies a retrieval augmented generation method powered by GitHub code search, and pushes progress to a draft pull request. Every action taken by the agent is logged, providing insight into the agent's decision-making process. Additional security controls ensure that any code proposed by the agent must be reviewed and approved before integration. Existing policies such as branch protections remain intact, and any deployment workflows are only triggered after human approval. The autonomous coding agent uses vision models to interpret images attached to issues, such as screenshots or mockups, and can access additional context and data through GitHub's Model Context Protocol (MCP). This allows it to adapt to a variety of coding standards and requirements within different repositories. The Copilot coding agent is opening up doors for human developers to have their own agent-driven team, all working in parallel to amplify their work. We're now able to assign tasks that would typically detract from deeper, more complex work - allowing developers to focus on high-value coding tasks. - James Zabinski, DevEx Lead at EY The Copilot coding agent is available to Copilot Enterprise and Copilot Pro+ customers, with support extended to a range of development environments including Xcode, Eclipse, JetBrains, and Visual Studio from June 2025. Developer feedback The GitHub Copilot coding agent fits into our existing workflow and converts specifications to production code in minutes. This increases our velocity and enables our team to channel their energy toward higher-level creative work. - Alex Devkar, Senior Vice President, Engineering and Analytics, Carvana The new coding agent is designed to respect organisational policies and rulesets. It is limited to interacting only with branches it creates, and any required code reviews or approvals set within a repository remain in effect. Its internet access is also limited to a configurable list of trusted destinations. Company perspective GitHub Copilot has crossed 20 million users – up more than 5 million from last quarter. We're also seeing explosive AI growth on GitHub, with AI projects more than doubling over the past year. And it's all because of grit. It's no secret the market Copilot introduced has heated up. Over the past year, incredible startups and founders have built and scaled great products that found real traction. The true measure of a company is never drawn during its hype wave, but by its resilience when pressure tested. Hubbers across GitHub put their heads down, treated pressure as a privilege, and we innovated. This past year, we shipped over 230 updates to GitHub Copilot – becoming the first multi-model solution at Microsoft, in partnership with Anthropic, Google, and OpenAI. We enabled Copilot Free for millions and introduced the synchronous agent mode in VS Code, all the way to Spark and the coding agent native to GitHub. I could not be more proud of my colleagues. Even with all the constraints we've faced, we proved that a little grit wins the game. - Thomas Dohmke, CEO at GitHub GitHub has stated its intention to continue expanding features to provide developers with increased flexibility and efficiency, promising further updates over the coming months.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store