💥Join UPSC 2027,2028 Mentorship (July Batch) + XFactor Notes & Microthemes PDF

GS Paper: Cyber Security

  • CERT-In exempted from RTI Ambit

    Central Idea

    • The Centre has included the Computer Emergency Response Team (CERT-In) in the list of organizations exempted from the Right to Information Act (RTI), 2005.
    • There are 26 other intelligence and security organisations established by the Central government such as the Intelligence Bureau, Research and Analysis Wing, Directorate of Enforcement, and National Technical Research Organisation that are exempt under RTI.

    About Indian Computer Emergency Response Team (CERT-In)

    Details
    Nodal Agency Part of India’s Ministry of Electronics and Information Technology
    Establishment Formed in 2004 under the Information Technology Act, 2000 Section (70B)
    Inter-agency Coordination Works with NCIIPC (under NTRO and PMO) and NDMA (under Ministry of Home Affairs)
    Functions Monitors cyber-attacks, issues security guidelines, liaises with national cybersecurity bodies
    Recent Activities Hosted ‘Synergy’ exercise in 2022 with international participation
    International Agreements MoUs with UK, Korea, Canada, Australia, Malaysia, Singapore, Japan, Uzbekistan; cooperation with Shanghai Cooperation Organisation
    Notable Incidents Reported Android Jelly Bean flaw (2014), Chrome vulnerabilities (2020), WhatsApp vulnerability (2021); investigated AIIMS cyber-attack (2022)
    Cyberattack Statistics (2021) Faced 11.5 million cyberattack incidents including attacks on infrastructure and government

     


    Back2Basics: Right to Information (RTI) Act

    Enactment June 15, 2005
    Objective Promote transparency and accountability
    Applicability All public authorities at central, state, local levels
    Scope Access to information on matters of public interest, government policies, budgets, etc.
    RTI Application Filed in writing with the concerned public authority
    Response Time Within 30 days (48 hours for life or liberty issues)
    Exemptions Some information exempted to protect national security, privacy, etc.

    Judiciary

    Fees Nominal fee varies based on state and information requested
    First Appellate Authority Filed if dissatisfied with the response
    Second Appeal Filed with the relevant Information Commission
    Whistleblower Protection Safeguards against victimization for exposing corruption
    Impact Promotes transparency, accountability, and good governance

     

  • Pegasus Spyware Saga: Unveiling the Expert Committee’s Findings

    Pegasus

    Central Idea

    • Several prominent opposition leaders recently reported receiving “threat notifications” from Apple regarding a potential state-sponsored spyware attack on their iPhones.
    • This incident has drawn parallels with the Pegasus Spyware Case, which targeted individuals globally, including in India.

    About Pegasus Spyware

    • Functionality: Pegasus, like its name suggests, is a spyware designed to surveil individuals through their smartphones.
    • Covert Installation: It infiltrates a target’s device by enticing them to click on an exploit link, installing the malware without their knowledge or consent.
    • Comprehensive Access: Once installed, Pegasus grants the attacker complete control over the victim’s phone, enabling eavesdropping, data retrieval, and even activation of the camera and microphone.

    What is the Pegasus Spyware Case?

    • Global Revelation: In July 2021, a collaborative global investigative project uncovered the use of Pegasus spyware, developed by NSO Group, an Israeli cybersecurity company, to target mobile phones worldwide, including India.
    • Government Denials: The Indian government denied the allegations and accused the opposition of undermining national security but did not explicitly deny using Pegasus.
    • Supreme Court’s Involvement: On October 27, 2021, the Supreme Court appointed an Expert Committee headed by Justice R V Raveendran to investigate the allegations, considering their public importance and potential violation of citizens’ fundamental rights.
    • Cyber Terrorism: This intrusion constitutes a cyber-terrorism attempt and calls for the application of Section 66(F) of the Information Technology Act 2008 (IT Act) to deal with the perpetrators.

    Expert Committee’s Mandate

    • Terms of Reference: The committee had seven terms of reference, including determining the entity that procured Pegasus, verifying if petitioners were targeted, and assessing the legal basis for using spyware like Pegasus on Indian citizens.
    • Policy Recommendations: It was also tasked with making recommendations on a legal and policy framework for cybersecurity to protect citizens’ privacy.
    • Technical Expertise: The committee comprised technical experts from various fields, including cybersecurity and forensic sciences.

    Key Findings

    • Lack of Conclusive Evidence: On August 25, 2022, the Supreme Court revealed that the expert committee did not find conclusive evidence of Pegasus use in the 29 phones it examined.
    • Government Non-Cooperation: The Centre did not cooperate with the committee, as observed by the panel itself.
    • Malware Discovery: While malware was found in five phones, it could not be definitively linked to Pegasus.
    • Inconclusive Determination: The committee concluded that the limited data available made it inconclusive to determine Pegasus use.
    • National Security Concerns: The committee’s report contained information about malware that could pose threats to national security and private confidential information.

    Implications and Urgent Action

    • Fundamental Right to Privacy: Protecting citizens’ smartphones through technologies like encryption is crucial for national security.
    • Need for Inquiry: Establishing an independent high-level inquiry with credible members and experts can restore confidence and ensure transparency.
    • Global Cooperation: Given the multinational impact of such attacks, coordinated global cooperation is essential for a thorough investigation.
    • Data Sovereignty and Privacy: Citizens’ data sovereignty should encompass their right to privacy, with stringent punishments for privacy violations.

    Conclusion

    • The Pegasus spyware case, which raised significant concerns about citizen privacy and national security, prompted a comprehensive investigation by the Supreme Court-appointed Expert Committee.
    • While the committee did not find conclusive evidence of Pegasus use, it emphasized the potential risks associated with malware and cybersecurity.
    • The case remains open, and further developments may shed light on the extent of surveillance and privacy infringements.
  • What is the ‘SIM Swap Scam’ — and how can you protect yourself?

    sim swap scam

    Central Idea

    • In recent years, the SIM swap scam has emerged as a significant threat to individuals’ financial security.
    • This fraudulent scheme exploits the link between physical SIM cards and banking applications, allowing scammers to gain access to victim’s bank accounts and personal information.

    SIM Swap Scam: An Overview

    • Exploiting Technological Advances: The SIM swap scam capitalizes on the integration of banking applications with phone numbers, enabling the generation of OTPs (One-Time Passwords) and the receipt of critical bank-related messages.
    • Acquiring Personal Data: Scammers begin by collecting victims’ personal details, including phone numbers, bank account information, and addresses, often through phishing or vishing (voice phishing) techniques. Phishing involves sending malware-laden links through emails or messages to steal personal data.
    • Forging Victim Identity: Armed with the stolen data, fraudsters visit a mobile operator’s retail outlet, impersonating the victim with forged ID proof. They falsely report the theft of the victim’s SIM card and/or mobile phone. As a result, they obtain a duplicate SIM card. Notably, fraudsters can secure a duplicate SIM even if the original is still functional. All activation messages and information are directed to the scammer rather than the victim.

    Why do victims receive Missed Calls?

    • Strategic Communication: In contrast to typical scams that involve tricking individuals into divulging OTPs and private data during phone calls, the SIM swap scam operates differently.
    • Distraction Tactic: Fraudsters initiate missed calls to their targets, prompting victims to check their phones and potentially ignore network connectivity issues.
    • SIM Exchange Execution: Perpetrators use these missed calls as a diversion while they execute the SIM swap. Once the SIM is swapped, fraudsters gain control over all calls and messages through the victim’s SIM, allowing them to initiate transactions unnoticed.

    How do scammers withdraw money?

    • Phishing Information: After acquiring personal data through phishing attacks, scammers use this information to access bank portals and generate OTPs required for fund withdrawal.
    • OTP Access: Having control over the victim’s SIM card, fraudsters receive all OTPs, enabling them to authenticate transactions and steal money.
    • Data Sources: Accused individuals purchase data from hackers involved in data breaches or from online portals. Data breaches often involve private companies losing vast amounts of customer data.
    • Example: In April, Rentomojo, an electronics and furniture rental company, reported a data breach, acknowledging unauthorized access to customer data due to a cloud misconfiguration.

    Arrests and Challenges

    • Absence of Arrests: Delhi Police has not made any arrests related to the SIM swap scam. The accused effectively evaded capture by discarding duplicate SIMs and operating from multiple locations.
    • Cryptocurrency Conversion: Stolen funds are often converted into cryptocurrency, making tracking Bitcoin or other cryptocurrency transactions impossible due to encryption.

    Protecting Yourself from SIM Swap Fraud

    • Stay Vigilant: Be cautious of vishing or phishing attacks and avoid clicking on suspicious links or sharing sensitive information.
    • Don’t Ignore Missed Calls: Don’t ignore missed calls or switch off your phone, especially if you receive multiple missed calls. Contact your mobile operator immediately if such activity occurs.
    • Regularly Update Passwords: Change bank account passwords regularly for added security.
    • Set Up Alerts: Register for regular SMS and email alerts for banking transactions to stay informed.
    • Report Fraud: In case of fraud, promptly contact your bank authorities to block your account and prevent further fraud.
  • Dark Pattern Sales by Airlines deemed ‘Cybercrime’

    dark patterns

    Central Idea

    • Due to complaints of deceptive practices by airlines and online travel agents, the Indian Ministry of Civil Aviation has urged IndiGo to fix its website, which a government official termed a Dark Pattern “cybercrime.”

    “Dark Patterns” in Airline Practices

    • Deceptive Techniques: Airlines and online portals have been accused of employing “dark patterns” in their user interfaces, which manipulate consumers into purchasing products they did not intend to buy.
    • Consumer Affairs Secretary’s Stance: The Consumer Affairs Secretary, Rohit Kumar Singh, defines “dark patterns” as tactics nudging consumers into unintended purchases, constituting unfair trading practices and possibly cybercrimes.
    • Pervasive Issue: Approximately 10,000 complaints related to these practices have been lodged with the Ministry via the National Consumers Helpline over the past eight to nine months.

    Manipulating Seat Selection

    • IndiGo’s Practice: IndiGo Airlines, for instance, employs a tactic known as “false urgency,” creating a sense of urgency by implying that consumers must pay an extra fee (₹99 to ₹1,500) for seat selection during booking, portraying all free seats as unavailable.
    • Transparency Issue: Passengers are not adequately informed that they will be auto-assigned free seats if they choose not to pay the extra fee.
    • Obfuscation: The “skip” option, although present, is inconspicuously located, demonstrating “interface interference.”

    Additional Unfair Practices

    • SpiceJet’s Pressure for Insurance: SpiceJet’s website pressures passengers to purchase travel insurance by using alarming phrases like “I will risk my trip” if they opt out, playing on passengers’ fears.
    • “Basket Sneaking” by MakeMyTrip: MakeMyTrip adds a convenience fee when customers reach the payment gateway after booking, a practice known as “basket sneaking.”

    Draft Guidelines and Regulatory Perspective

    • Ministry of Consumer Affairs Guidelines: These dark patterns have been defined in the draft guidelines released by the Ministry of Consumer Affairs in September.
    • DGCA’s Stance: The Directorate General of Civil Aviation (DGCA) permits “unbundling” airfares but emphasizes that these services must be offered on an “opt-in” basis, with clear descriptions without ambiguity.
    • Parliamentary Committee Report: A parliamentary committee report urges transparency in seat-wise airfares, fair pricing mechanisms to ensure reasonable profit margins, and effective grievance redressal mechanisms.

    Conclusion

    • The crackdown on deceptive airline practices by the Indian Ministry of Civil Aviation signifies a push for transparency and fairness in the airline industry.
    • The rise of “dark patterns” and other misleading tactics in online booking processes has raised concerns about consumer exploitation and cybercrimes.
    • As the government takes action to address these issues, passengers may expect a more equitable and transparent air travel experience in the future.

    Tap to read more about:

    India’s Draft Guidelines on Dark Patterns

  • Dawn of Passkeys: A Password-Free Future

    passkey

    Central Idea

    • In 1961, MIT computer science professor Fernando Corbato introduced the world to digital passwords, an innovation designed for research purposes. Little did he know the profound societal impact his creation would eventually wield.

    Why discuss this?

    • Passwords have become nearly synonymous with cybersecurity in the 21st century, albeit with an unsavory connotation.
    • Despite efforts to promote robust password practices, “password” and “123456” continue to dominate the list of common passwords, underscoring the pervasive vulnerability of most accounts.

    Passkeys: Need for Change

    • Ineffectiveness of Passwords: The prevailing authentication method, based on passwords, falls short in ensuring adequate security.
    • Big Tech Solution: In response to this predicament, major tech companies propose a solution – passkeys.

    Understanding Passkeys

    • Web Authentication Standard: Passkeys are a security feature built on the WebAuthentication (WebAuthn) standard.
    • Public-Key Cryptography: Passkeys employ public-key cryptography, a potent technique employing a public key (server-side) and a private key (user-side).
    • Authentication Process: When users log in, a challenge is sent to their device, which utilizes the private key to solve it and respond. The server then validates the response with the public key, all without storing any secrets, enhancing security.

    Getting Started with Passkeys

    • Wide Compatibility: Leading tech companies, including Microsoft, Google, and Apple, have collaborated to make passkeys accessible to most recent phones and PCs.
    • Operating Systems: Passkeys are available on iOS 16+, iPadOS 16+, macOS Ventura, Android 9+, Windows 10, and Windows 11.
    • Web Browsers: Passkeys are supported on popular browsers like Chrome, Edge, Safari, and Firefox.

    Creating and Using Passkeys

    • Account Requirement: Users need an account with a provider supporting passkeys, such as Microsoft, Google, or Apple.
    • Activation Process: To enable passkeys, sign in to a compatible app or website, activate the passkey option, and obtain a unique passkey linked to your account and device.
    • Usage: Passkeys can be used with biometrics (e.g., Touch ID, Face ID), QR codes, or device verification.

    Future of Passwords

    • Inevitable Evolution: While passkeys offer notable advantages over traditional passwords in terms of security and user-friendliness, they still face challenges related to compatibility and user adoption.
    • Industry Push: Notably, Google, Apple, and Microsoft are driving the passkey agenda strongly, suggesting that passwords may eventually become obsolete.

    Conclusion

    • A Security Evolution: The emergence of passkeys as an alternative to traditional passwords marks a significant shift in the realm of cybersecurity.
    • Ongoing Transition: As passkeys gain momentum and garner support from tech giants, they may gradually pave the way for a password-free future, promising enhanced security and user convenience in the digital realm.
  • Inside the Digital World of Cookies

    cookies

    Central Idea

    • In the online world, digital cookies hold a significant role, contributing to personalization and user convenience.
    • These unobtrusive lines of code, quietly stored on devices during website visits, shape the online experiences we encounter.

    Understanding How Cookies Work

    • Cookies as Digital Keys: Think of cookies as keys to an exclusive club. Just as a club bouncer recognizes regular patrons, cookies remember your login details on websites, eliminating the need for constant re-authentication.
    • Enhanced Online Shopping: Websites like Amazon leverage cookies to remember your past interactions, offering tailored product recommendations and an intimate shopping experience.
    • Persistent Shopping Carts: Online shopping carts, fueled by cookies, ensure your selections remain intact even after you leave the site, simplifying the checkout process.
    • Personalized Advertising: Platforms like Facebook and Google utilize cookies to track online behaviour, serving ads aligned with your preferences.

    Types of Cookies

    • Session Cookies: Temporary, session cookies function as post-it notes for websites, existing only in your computer’s memory during your browsing session.
    • Persistent Cookies: Comparable to bookmarks, persistent cookies remain on your device after your browsing session, retaining login information and preferences.
    • Secure Cookies: Sent over encrypted connections, secure cookies are employed for sensitive data like login credentials.
    • Third-Party Cookies: Originating from domains other than the visited site, third-party cookies serve tracking and advertising functions, offering both benefits and potential intrusiveness.

    Multifaceted Uses of Cookies

    • Digital ID Cards: Cookies facilitate user authentication, allowing websites to recognize and keep you logged in.
    • Personalization: They remember your preferences, such as language choices and website themes.
    • Persistent Shopping Carts: Items added online remain accessible upon your return.
    • Analytics Data: Cookies enable website owners to gather valuable data about user interactions for improvements and customization.
    • Targeted Advertising: Advertisers employ cookies to display ads aligning with your interests, enhancing online shopping experiences.

    Challenges Associated with Cookies

    • Privacy Concerns: Cookies can track online behaviour, occasionally infringing upon digital privacy.
    • Security Risks: Inadequately secured cookies may expose personal information to cybercriminals.
    • User Consent Era: Privacy regulations necessitate websites to seek user consent before deploying specific cookie types, resulting in pop-ups and prompts.
    • Third-Party Cookie Debates: Concerns about third-party cookies have led web browsers to limit their usage for user privacy protection.
    • Data Deluge: The multitude of cookies can potentially overwhelm your browser, causing a sluggish web experience.

    Conclusion

    • Complex yet Sweet: Cookies enhance online experiences but also bring privacy and security challenges. As the digital landscape evolves, so will the use and regulation of cookies.
    • Analogous to Real Cookies: Just like warm, gooey chocolate chip cookies, digital cookies add a personalized touch to your online adventures, even if they occasionally leave behind a few crumbs.
  • CERT-IN warns against Akira Ransomware

    akira ransomware

    Central Idea

    • The Computer Emergency Response Team of India (CERT-In) issued a warning about the Akira ransomware, a highly dangerous cyber threat that has been wreaking havoc on corporate networks worldwide.

    What is the Akira Ransomware?

    • Encryption and Data Theft: Akira ransomware encrypts sensitive data on targeted devices and appends the “akira” extension to filenames, making the files inaccessible to users.
    • Shadow Volume Deletion: The ransomware deletes Windows Shadow Volume copies, hindering data recovery options for affected organizations.
    • Ransom Demands: The ransomware operators extort victims by demanding a double ransom for decryption and recovery, threatening to leak sensitive data on their dark web blog if payment is not made.

    Infection and Working Mechanism

    • Spread Methods: Akira ransomware is primarily distributed through spear-phishing emails with malicious attachments, drive-by downloads, and specially crafted web links. It also exploits insecure Remote Desktop connections to infiltrate systems.
    • Selective Encryption: The ransomware avoids encrypting specific system folders to maintain system stability.
    • Negotiation Process: Each victim is given a unique negotiation password to communicate with the ransomware gang via the threat actor’s Tor site.

    Major targets

    • Corporate Networks: Akira ransomware targets corporate networks across various sectors, including education, finance, real estate, manufacturing, and consulting.
    • Data Exfiltration: In addition to encryption, the threat actors steal sensitive corporate data, using it as leverage in their extortion attempts.

    Protective Measures against Akira Ransomware

    • Regular Backups: Maintain up-to-date offline backups to ensure data recovery in case of an attack.
    • System Updates: Regularly update operating systems and networks, and implement virtual patching for legacy systems.
    • Email Authentication: Establish Domain-based Message Authentication, Reporting, and Conformance (DMARC), Domain Keys Identified Mail (DKIM), and Sender Policy Framework (SPF) to prevent email spoofing and spam.
    • Strong Authentication: Enforce strong password policies and multi-factor authentication (MFA) to secure user accounts.
    • Data Encryption: Implement data-at-rest and data-in-transit encryption to protect sensitive information.
    • Attachment Blocking: Block suspicious attachment file types like .exe, .pif, or .url to prevent malicious downloads.
    • Security Audits: Conduct regular security audits, especially for critical networks and database servers, to identify vulnerabilities.
  • CoWIN Data Breach: Data Privacy and Security Concerns in India’s Digitalization Journey

    Data

    Central Idea

    • The recent CoWin data leak has raised significant concerns about data privacy and security in India. While the leak itself is disconcerting, what is more troubling is the government’s response to the issue. Mere assurances that the back-end database is still secure do little to alleviate the concerns of citizens.

    CoWIN Data Breach and Government Denials

    • Data Breach: On June 12, a data breach on the CoWIN platform was reported by the Malayala Manorama and online portal “The Fourth.” Personal details, including vaccination information and identification numbers, were found circulating on the messaging platform Telegram.
    • Government Denials: Despite the mounting evidence of the data breach, the Ministry of Health and Family Welfare and Minister of State, Ministry of Electronics and IT (MEITY), responded with denials. The Ministry of Health and Family Welfare labeled the reports as “mischievous,” while the Minister of State, MEITY, claimed that the sensitive information had emerged from previously stolen data.
    • Press Information Bureau Statement: Later in the day, the PIB issued a statement asserting the complete safety of the Co-WIN portal and its adequate safeguards for data privacy. However, the credibility of this statement was questionable, given the initial denials and the substantial evidence of the breach.
    • Lack of Transparency: The government’s response to the CoWIN data breach exemplifies a recurring pattern of denial and opacity in addressing data breaches in the public sector. Previous incidents, such as the Employees’ Provident Fund Organisation breach and the ransomware attack on AIIMS, have been met with similar denials and lack of transparency.
    • Erosion of Trust: The consistent lack of transparency, coupled with the absence of a National Cyber Security Strategy and data protection laws requiring breach notifications to affected users, has eroded citizens’ trust in the government’s ability to secure their personal information. T

    Articulating Threat Models for Robust Security

    • Adversaries Corrupting Insiders: The threat model assumes that adversaries can corrupt all insiders, including system administrators and personnel with authorized access.
    • Compromised Custody Chains: The threat model includes the possibility of adversaries compromising the custody chains of data, which may involve unauthorized access or tampering with data during its lifecycle.
    • Compromised Hardware and Software: The threat model assumes that adversaries can compromise both hardware and software components, potentially exploiting vulnerabilities in these systems.

    Challenges in Indian Digitalization Initiatives

    • Limited Infrastructure: One of the significant challenges in Indian digitalization initiatives is the limited infrastructure, especially in rural areas. Inadequate internet connectivity, lack of reliable power supply, and limited access to digital devices pose obstacles to the effective implementation of digital services.
    • Digital Divide: India faces a significant digital divide, with a large section of the population having limited or no access to digital technologies. This divide is often along socio-economic lines, with marginalized communities and rural areas facing more significant barriers to digital inclusion.
    • Data Security and Privacy: Ensuring data security and privacy is a persistent challenge in Indian digitalization efforts. Incidents of data breaches, leaks, and unauthorized access to personal information highlight the need for robust data protection frameworks and stringent security measures.
    • Cybersecurity Threats: With the expansion of digital services, the risk of cybersecurity threats such as hacking, phishing, malware attacks, and ransomware has increased. The government and relevant stakeholders need to invest in cybersecurity infrastructure and raise awareness about safe digital practices.
    • Skill Gaps and Digital Literacy: Many individuals, particularly in rural areas, lack the necessary digital skills and literacy to effectively utilize digital services. Bridging the digital skills gap and promoting digital literacy are essential for the successful adoption of digitalization initiatives.
    • Interoperability and Standardization: The lack of interoperability and standardization among different digital systems and platforms hampers the seamless integration of services. It creates complexities in data sharing, collaboration, and the overall user experience.
    • Legal and Regulatory Frameworks: Developing comprehensive and up-to-date legal and regulatory frameworks for digitalization is crucial. It includes laws related to data protection, privacy, electronic signatures, cybercrime, and digital transactions. Ensuring these frameworks are robust and aligned with international best practices is necessary for building trust and confidence in digital services.

    Data

    Consequences of Inadequate Privacy Risk Assessment

    • Data Breaches and Leaks: Inadequate privacy risk assessment can lead to data breaches and leaks, exposing sensitive personal information to unauthorized access. This can result in identity theft, financial fraud, and other forms of misuse of personal data.
    • Privacy Violations: Insufficient assessment of privacy risks can result in privacy violations, where individuals’ personal information is used or disclosed without their consent or in ways that infringe upon their privacy rights. This can erode trust in digital services and undermine individuals’ confidence in sharing their data.
    • Loss of Control over Personal Information: Without proper risk assessment, individuals may lose control over their personal information. This can lead to the unauthorized collection, storage, and use of their data by both private and public entities, potentially exposing them to various risks and harms.
    • Discriminatory Practices: Inadequate privacy risk assessment can contribute to discriminatory practices, where personal data is used to profile individuals based on sensitive attributes such as race, religion, gender, or political beliefs. This can lead to unfair treatment, exclusion, and perpetuation of bias in decision-making processes.
    • Societal Harms: Privacy breaches resulting from inadequate risk assessment can have broader societal impacts. For example, leaked personal information can be exploited for political manipulation, voter profiling, or predatory advertising, potentially influencing elections, public opinions, and individual choices.
    • Erosion of Trust: When privacy risks are not adequately assessed and addressed, it can erode public trust in digital services, government initiatives, and the overall data ecosystem. Lack of trust can hinder the adoption of digital technologies, impede economic growth, and undermine the potential benefits of digitalization.
    • Legal and Regulatory Consequences: Inadequate privacy risk assessment may lead to non-compliance with data protection laws and regulations, potentially resulting in legal consequences, penalties, or lawsuits. Failure to protect individuals’ privacy rights can attract regulatory scrutiny and damage the reputation of organizations or government entities involved.

    Data

    Way ahead: The Need for Standardized Grammar in Security and Privacy Discourse

    • Defining Threat Models: Establishing well-articulated threat models is crucial. This involves identifying potential risks, vulnerabilities, and capabilities of adversaries. It provides a common starting point for discussions and allows stakeholders to align their understanding of security and privacy concerns.
    • Promoting Best Practices: Encourage the adoption of best practices in security and privacy. This includes following internationally recognized standards and frameworks, such as those provided by organizations like the National Institute of Standards and Technology (NIST) or the International Organization for Standardization (ISO).
    • Clear Communication of Security Measures: System designers and administrators should precisely articulate the security measures implemented to address specific threats. It is important to go beyond vague claims of “state-of-the-art best practices” and provide concrete details on how security and privacy issues are being tackled.
    • Publicly Articulating Threat Models: Digital service providers and government agencies should publicly articulate their threat models. By doing so, they demonstrate transparency, foster trust, and allow stakeholders to assess the adequacy of security measures in place.
    • Collaboration and Knowledge Sharing: Encourage collaboration and knowledge sharing among stakeholders involved in security and privacy discourse. This can be done through forums, conferences, and working groups where experts can share experiences, insights, and best practices.
    • Developing Common Terminology: Establish a common terminology and vocabulary for discussing security and privacy concepts. This helps to avoid misunderstandings and ensures that stakeholders are on the same page when discussing security risks and mitigation strategies.
    • Education and Training: Invest in education and training programs to enhance the understanding of security and privacy concepts among professionals, policymakers, and end-users. This includes promoting cybersecurity awareness and digital literacy to empower individuals to make informed decisions about their privacy.
    • Regulatory Frameworks: Develop comprehensive and up-to-date regulatory frameworks that incorporate standardized security and privacy measures. These frameworks should address specific threat models, outline data protection requirements, and establish accountability mechanisms for organizations handling personal data.
    • Independent Audits and Certifications: Encourage independent audits and certifications of digital systems to verify their adherence to standardized security and privacy practices. This helps build trust and provides assurance to users that appropriate measures are in place to protect their data.

    Conclusion

    • India’s digitalization journey has been remarkable in its scale and scope, but there is a pressing need to reinforce it with computer science rigor. Strengthening data security and privacy practices is paramount to ensure public trust and the success of digital public services. With a well-structured approach, India can leverage the benefits of digitalization while safeguarding the privacy and security of its citizens’ data.

    Also read:

    CoWIN Vaccination Data Breached

     

  • CoWIN Vaccination Data Breached

    cowin

    Central Idea

    • Data breach reports: The Health Ministry, on Monday, refuted claims of a data breach of COVID vaccination beneficiaries, stating that such reports were baseless and mischievous in nature.
    • Investigation by CERT-In: The Indian Computer Emergency Response Team (CERT-In) has been asked to investigate the alleged data breach issue and submit a report to ascertain the facts.
    • Assurance of data safety: The Ministry maintains that the CoWIN (Covid Vaccine Intelligence Network) portal is completely safe, equipped with adequate safeguards to protect data privacy.

    About CoWIN

    • Development: CoWIN was developed and is owned and managed by the Ministry of Health.
    • Policy decisions: The Empowered Group on Vaccine Administration (EGVAC), chaired by the former CEO of the National Health Authority, oversees this. It includes members from the Health Ministry and MeitY (Ministry of Electronics and Information Technology).

    Evaluation of Alleged Breach

    • CERT-In review results: The review conducted by CERT-In concludes that there was no direct breach of the CoWIN app or database.
    • Data source of Telegram bot: The data accessed by the Telegram bot was sourced from a separate threat actor database, which contained previously breached or stolen data.
    • No direct breach of CoWIN: The Ministry states that it does not appear that the CoWIN app or database itself was directly breached.

    Clarification on CoWIN Data Access

    • Three methods of data access: The Ministry outlines the three ways in which data can be accessed on the CoWIN portal: user access, vaccinator access, and authorized third-party applications.
    • Data sharing with Telegram bot: The Ministry clarifies that data cannot be shared with the Telegram bot without undergoing the one-time password (OTP) authentication process.
    • Limited data collection: CoWIN only collects the year of birth and does not capture a person’s address.

    Unanswered Questions and API Access

    • Uncertainty regarding recent breaches: The Ministry has not explicitly clarified whether the CoWIN database was breached recently or in the past.
    • Lack of insights on bot accuracy: The Ministry’s statement does not offer insight into the accuracy of the Telegram bot’s retrieval of citizens’ data from the CoWIN database.
    • API access without OTP: The Ministry admits the existence of an API that allows data sharing without OTP, but emphasizes that requests are accepted only from trusted whitelisted APIs.

    Concerns and Aadhaar Data

    • Accuracy of Aadhaar details: The accuracy of displaying Aadhaar numbers corresponding to mobile numbers raises concerns, as the government has never publicly acknowledged any breaches of Aadhaar data.
    • Need for clarity: The Ministry’s statement does not provide clarity on how the Telegram bot accurately displayed Aadhaar numbers.
    • Addressing security concerns: The Ministry should address concerns regarding the security of Aadhaar data and provide transparency on its safety measures.

    Future Steps and Data Governance Policy

    • Empowering CERT-In: The Health Ministry has requested a final report from CERT-In to investigate the alleged data breach incident thoroughly.
    • National Data Governance policy: The Ministry highlights the finalization of the National Data Governance policy, which aims to establish a common framework for data storage, access, and security standards across the government.
    • Awaited response from CERT-In: The Ministry is awaiting a response from CERT-In regarding the issue, which will provide further insights into the nature of the breach.

    Assurance and Previous Leaks

    • Assurances of secure infrastructure: Health authorities maintain that CoWIN has state-of-the-art secure infrastructure and has never experienced a security breach.
    • Dismissal of previous claims: Previous claims of data leaks, such as the ‘Dark Leak Market’ incident, were dismissed by health authorities, emphasizing the safety of citizen data.
    • Security measures in place: CoWIN has implemented security measures such as web application firewall, regular vulnerability assessments, and OTP authentication to ensure the protection of data.

    Implications of this data leak

    • Identity theft risks: The leaked data exposes individuals to the risk of identity theft, as sensitive information can be misused for fraudulent activities.
    • Targeted scams and phishing attacks: With access to personal details, scammers may attempt targeted scams and phishing attacks, leading to financial loss and potential harm to individuals.
    • Loss of trust in government systems: The data breach undermines public trust in the government’s ability to safeguard sensitive information, affecting confidence in the vaccination program and other government initiatives.
    • Reputational damage: The incident could tarnish the reputation of the CoWIN platform and associated government agencies, affecting their credibility in managing sensitive data.
    • Impact on future vaccination drive: Concerns about data security may deter individuals from participating in the vaccination program, slowing down efforts to control the spread of COVID-19.
    • Calls for accountability: The data leak prompts demands for accountability from the responsible government agencies and the implementation of stricter measures to protect citizen data.

    Conclusion

    • The data leak incident related to the CoWIN portal raises serious concerns about the privacy and security of individuals’ personal information.
    • While the Ministry of Health maintains that the CoWIN app and database were not directly breached, the access to sensitive data through a Telegram bot raises questions about the integrity of the system.

     

    Get an IAS/IPS ranker as your 1: 1 personal mentor for UPSC 2024

  • Protecting Critical Information Infrastructure: The Role of the G20

    Central Idea

    • Technology has become pervasive, impacting various aspects of society, including national and foreign policies, governance, service delivery, and warfare. However, this dependence on technology also exposes critical systems to potential disruptions. Safeguarding critical systems is a nation’s responsibility to ensure the continuity of vital services.

    What is critical information infrastructure?

    • Critical information infrastructure refers to the interconnected systems and assets that are essential for the functioning of a nation’s society, economy, and government. It encompasses the hardware, software, networks, data, and communication channels that support vital services and processes.
    • It includes sectors such as transportation, energy, banking and finance, healthcare, telecommunications, water and sanitation, emergency services, and government networks.
    • Protecting critical information infrastructure is crucial to ensure the continuity of services, safeguard sensitive data, and defend against cyber threats, including cyberattacks, data breaches, and other malicious activities.

    Differences in defining critical information infrastructure

    • Criteria for Criticality: Different countries employ distinct criteria to determine the criticality of information infrastructure.
    • For example: One country may consider infrastructure critical if its failure impacts national security, economy, public health, or safety. Another country may define critical infrastructure based on the potential for sustained supply shortages, disruptions to public safety and security, or other significant consequences.
    • Scope of Infrastructure: There may be variations in the scope of infrastructure considered critical. While certain sectors like energy, transportation, banking, and telecommunications are commonly recognized as critical across many countries, there might be differences in identifying sub-sectors or specific enterprises within those sectors. Some countries may include additional sectors like water and sanitation, emergency services, healthcare, or government networks in their definition of critical information infrastructure.
    • Overlapping Criteria: In some cases, the criteria used to identify critical infrastructure may overlap with one another. For instance, ensuring the availability, delivery, or integrity of essential services can encompass vital societal functions, information flow, and communication channels. Harmonizing these overlapping criteria can help establish specific and comprehensive criteria that cater to the needs of all countries.
    • National Context: National priorities and contextual factors also influence the definition of critical information infrastructure. Countries may consider their unique geopolitical situation, existing threats, vulnerabilities, and the potential impact on their economy and citizens. This context-specific approach allows each country to address its specific challenges and ensure the protection of infrastructure crucial to its national well-being.

    Role of the G20 in developing global norms for protecting critical infrastructure

    • Platform for Discussion: The G20 provides a platform for member countries to engage in discussions and exchanges on pressing global issues, including cybersecurity and the protection of critical infrastructure. It brings together policymakers, experts, and stakeholders from various sectors to share insights, experiences, and best practices.
    • Building Consensus: The G20 aims to build consensus among member countries on critical issues related to protecting infrastructure. Through dialogue, negotiations, and diplomatic efforts, the G20 seeks to develop common understandings and principles that can guide international cooperation in safeguarding critical information infrastructure.
    • Initiating Discussions: The G20 has the capacity to initiate discussions on specific topics and themes relevant to critical infrastructure protection. By placing the issue on the G20 agenda, it draws attention to the importance of addressing cybersecurity risks and establishing global norms in this area.
    • Leveraging Economic Influence: The G20 represents around 85 percent of global GDP, over 75 percent of global trade, and a significant portion of the world population. This economic influence provides the G20 with leverage to drive discussions and encourage member countries to prioritize the protection of critical infrastructure.
    • Collaboration with International Organizations: The G20 collaborates with international organizations such as the United Nations (UN), International Telecommunication Union (ITU), and Organization for Economic Cooperation and Development (OECD). This collaboration helps leverage the expertise, resources, and frameworks of these organizations to inform discussions and develop comprehensive approaches to protecting critical infrastructure.
    • Promoting International Stability: The G20 recognizes that protecting critical infrastructure is crucial for international stability and economic cooperation. By advocating for global norms and responsible state behavior, the G20 aims to enhance cybersecurity, prevent disruptions, and promote a secure digital environment for economic activities.
    • Influencing Policy Development: The G20’s discussions and recommendations on critical infrastructure protection can influence policy development at the national and international levels. Member countries may align their policies and frameworks with the norms and principles identified through G20 deliberations, thereby fostering harmonization and cooperation.

    Recommendations to the G20

    • Common Definition and Critical Sectors: The G20 should adopt a phased approach, beginning with establishing a common definition of critical infrastructure. Subsequently, a broader consensus on critical sectors should be built, followed by the formulation of common principles for regulating critical infrastructure. This process will facilitate a global consensus, ensure cooperation among member countries, and guide nations that are in the early stages of regulating critical infrastructure.
    • Common Principles: While formulating common principles for regulating critical infrastructure, the G20 should reaffirm and adopt existing norms as the foundation for future discussions. This includes commitments made in G20 documents like the Hamburg Action Plan and the Buenos Aires Declaration. Furthermore, the G20 can draw from the initiatives of other multilateral groupings, such as the G7, G8, and OECD, that have focused on protecting critical infrastructure.
    • Respecting International Law: The G20 should commit to protecting critical infrastructure and refrain from intentionally damaging it. Member countries should conduct themselves in accordance with international law and uphold responsible state behavior in cyberspace.
    • International Cooperation: G20 countries must enhance cooperation to prevent, mitigate, trace, and investigate cyber incidents targeting critical infrastructure. Sharing information regarding such incidents should be encouraged. Adopting international standards relevant to critical infrastructure will help harmonize approaches to regulation and enforcement, reducing conflicts and improving cooperation.
    • Capacity Building: Investing in research and development and building capacity in emerging technologies such as artificial intelligence (AI), drones, and space is crucial. G20 countries should support low- and middle-income nations in accessing research and technologies. Additionally, countries should respond to requests for assistance from states whose critical infrastructure has been affected, and promote the application of certified security technologies based on international standards.
    • Multistakeholder Approach: A multistakeholder commitment is vital to protecting critical information infrastructure. Governments, technology companies, and civil society groups should collaborate to share and analyze critical infrastructure information, prevent attacks, and respond to damage. Awareness should be raised to ensure stakeholders understand the nature and extent of critical information infrastructure and their respective roles in protecting it.
    • National Laws: G20 countries should incorporate the principles and norms for protecting critical infrastructure into their national laws. This will help create a culture of enforcement and cooperation at both the national and international levels.
    • Institutional Mechanism: Establishing an institutional mechanism for continuous research and the development of new standards for protecting critical infrastructure is essential. Drawing lessons from initiatives like the Christchurch Call, public-private partnerships can play a crucial role in establishing a global order for a safe cyberspace.

    Conclusion

    • The protection of critical information infrastructure is of paramount importance in today’s interconnected world. The G20, with its representation of major economies and commitment to international cooperation, plays a crucial role in developing global norms for safeguarding critical infrastructure. By establishing a common understanding and definition of critical information infrastructure, the G20 can facilitate discussions and build consensus among member countries.

    Get an IAS/IPS ranker as your personal mentor for UPSC 2024 | Schedule your FREE session and get the Prelims prep Toolkit!

    Also read:

    Digital Public Infrastructure (DPI): New Backbone of India’s Economy