💥Join UPSC 2027,2028 Mentorship (August Batch) + XFactor Notes & Microthemes PDF

GS Paper: Cyber Security

  • In cyber attacks, terror has a found a new face

    Recent Cyber Attacks In India 2020

    Central idea

    The article underscores the transformation of terrorism into cyberspace, emphasizing the significance of robust cybersecurity measures in the face of escalating state-sponsored cyberattacks.

    Key Highlights:

    • Mumbai holds the unfortunate title of the most terror-attacked city globally.
    • The November 26, 2008 (26/11) attacks were the most audacious, lasting three days.
    • Intelligence was available before 26/11 attacks, but preventive measures failed.
    • Post-attack, significant changes were made in the police department and security apparatus.

    Key Challenges:

    • Despite reforms, the landscape of terror warfare has shifted to cyberspace.
    • The Russia–Ukraine and Israel–Hamas conflicts demonstrate the growing threat of cyber warfare.
    • State-sponsored cyberattacks against India increased by 278% between March 2021-September 2023.

    Key Terms and Phrases:

    • 26/11 terror attacks, cyberspace, cyber warfare, state-sponsored cyberattacks.

    Key Examples and References:

    • November 26, 2008, terror attacks in Mumbai.
    • Israel-Hamas conflict and the failure of the Iron Dome against cyber threats.
    • 2023 India Threat Landscape Report by Cyfirma.

    Key Facts and Data:

    • State-sponsored cyberattacks on India increased by 278% from March 2021-September 2023.
    • India faced 13.7% of all global cyberattacks.
    • 13.91 lakh cybersecurity incidents in India in 2022.

    Critical Analysis:

    • Cybersecurity is of paramount importance in a highly digitized world.
    • Recent incidents, including Apple’s warning, highlight the urgency for robust cybersecurity measures.
    • The need for nationwide education and training on cyber threats is crucial.

    Way Forward:

    • Urgent investment in robust cybersecurity measures across government, private sector, and individual citizens.
    • Comprehensive education programs, starting in schools, to raise awareness about cyber threats.
    • Adequate training and financial support for government agencies to strengthen cybersecurity.

    In conclusion, the evolving landscape of terrorism emphasizes the shift to cyberspace, demanding urgent and comprehensive cybersecurity measures, education, and training to safeguard against potential online threats like a “cyber 26/11.”

  • CERT-In exempted from RTI Ambit

    Central Idea

    • The Centre has included the Computer Emergency Response Team (CERT-In) in the list of organizations exempted from the Right to Information Act (RTI), 2005.
    • There are 26 other intelligence and security organisations established by the Central government such as the Intelligence Bureau, Research and Analysis Wing, Directorate of Enforcement, and National Technical Research Organisation that are exempt under RTI.

    About Indian Computer Emergency Response Team (CERT-In)

    Details
    Nodal Agency Part of India’s Ministry of Electronics and Information Technology
    Establishment Formed in 2004 under the Information Technology Act, 2000 Section (70B)
    Inter-agency Coordination Works with NCIIPC (under NTRO and PMO) and NDMA (under Ministry of Home Affairs)
    Functions Monitors cyber-attacks, issues security guidelines, liaises with national cybersecurity bodies
    Recent Activities Hosted ‘Synergy’ exercise in 2022 with international participation
    International Agreements MoUs with UK, Korea, Canada, Australia, Malaysia, Singapore, Japan, Uzbekistan; cooperation with Shanghai Cooperation Organisation
    Notable Incidents Reported Android Jelly Bean flaw (2014), Chrome vulnerabilities (2020), WhatsApp vulnerability (2021); investigated AIIMS cyber-attack (2022)
    Cyberattack Statistics (2021) Faced 11.5 million cyberattack incidents including attacks on infrastructure and government

     


    Back2Basics: Right to Information (RTI) Act

    Enactment June 15, 2005
    Objective Promote transparency and accountability
    Applicability All public authorities at central, state, local levels
    Scope Access to information on matters of public interest, government policies, budgets, etc.
    RTI Application Filed in writing with the concerned public authority
    Response Time Within 30 days (48 hours for life or liberty issues)
    Exemptions Some information exempted to protect national security, privacy, etc.

    Judiciary

    Fees Nominal fee varies based on state and information requested
    First Appellate Authority Filed if dissatisfied with the response
    Second Appeal Filed with the relevant Information Commission
    Whistleblower Protection Safeguards against victimization for exposing corruption
    Impact Promotes transparency, accountability, and good governance

     

  • Pegasus Spyware Saga: Unveiling the Expert Committee’s Findings

    Pegasus

    Central Idea

    • Several prominent opposition leaders recently reported receiving “threat notifications” from Apple regarding a potential state-sponsored spyware attack on their iPhones.
    • This incident has drawn parallels with the Pegasus Spyware Case, which targeted individuals globally, including in India.

    About Pegasus Spyware

    • Functionality: Pegasus, like its name suggests, is a spyware designed to surveil individuals through their smartphones.
    • Covert Installation: It infiltrates a target’s device by enticing them to click on an exploit link, installing the malware without their knowledge or consent.
    • Comprehensive Access: Once installed, Pegasus grants the attacker complete control over the victim’s phone, enabling eavesdropping, data retrieval, and even activation of the camera and microphone.

    What is the Pegasus Spyware Case?

    • Global Revelation: In July 2021, a collaborative global investigative project uncovered the use of Pegasus spyware, developed by NSO Group, an Israeli cybersecurity company, to target mobile phones worldwide, including India.
    • Government Denials: The Indian government denied the allegations and accused the opposition of undermining national security but did not explicitly deny using Pegasus.
    • Supreme Court’s Involvement: On October 27, 2021, the Supreme Court appointed an Expert Committee headed by Justice R V Raveendran to investigate the allegations, considering their public importance and potential violation of citizens’ fundamental rights.
    • Cyber Terrorism: This intrusion constitutes a cyber-terrorism attempt and calls for the application of Section 66(F) of the Information Technology Act 2008 (IT Act) to deal with the perpetrators.

    Expert Committee’s Mandate

    • Terms of Reference: The committee had seven terms of reference, including determining the entity that procured Pegasus, verifying if petitioners were targeted, and assessing the legal basis for using spyware like Pegasus on Indian citizens.
    • Policy Recommendations: It was also tasked with making recommendations on a legal and policy framework for cybersecurity to protect citizens’ privacy.
    • Technical Expertise: The committee comprised technical experts from various fields, including cybersecurity and forensic sciences.

    Key Findings

    • Lack of Conclusive Evidence: On August 25, 2022, the Supreme Court revealed that the expert committee did not find conclusive evidence of Pegasus use in the 29 phones it examined.
    • Government Non-Cooperation: The Centre did not cooperate with the committee, as observed by the panel itself.
    • Malware Discovery: While malware was found in five phones, it could not be definitively linked to Pegasus.
    • Inconclusive Determination: The committee concluded that the limited data available made it inconclusive to determine Pegasus use.
    • National Security Concerns: The committee’s report contained information about malware that could pose threats to national security and private confidential information.

    Implications and Urgent Action

    • Fundamental Right to Privacy: Protecting citizens’ smartphones through technologies like encryption is crucial for national security.
    • Need for Inquiry: Establishing an independent high-level inquiry with credible members and experts can restore confidence and ensure transparency.
    • Global Cooperation: Given the multinational impact of such attacks, coordinated global cooperation is essential for a thorough investigation.
    • Data Sovereignty and Privacy: Citizens’ data sovereignty should encompass their right to privacy, with stringent punishments for privacy violations.

    Conclusion

    • The Pegasus spyware case, which raised significant concerns about citizen privacy and national security, prompted a comprehensive investigation by the Supreme Court-appointed Expert Committee.
    • While the committee did not find conclusive evidence of Pegasus use, it emphasized the potential risks associated with malware and cybersecurity.
    • The case remains open, and further developments may shed light on the extent of surveillance and privacy infringements.
  • What is the ‘SIM Swap Scam’ — and how can you protect yourself?

    sim swap scam

    Central Idea

    • In recent years, the SIM swap scam has emerged as a significant threat to individuals’ financial security.
    • This fraudulent scheme exploits the link between physical SIM cards and banking applications, allowing scammers to gain access to victim’s bank accounts and personal information.

    SIM Swap Scam: An Overview

    • Exploiting Technological Advances: The SIM swap scam capitalizes on the integration of banking applications with phone numbers, enabling the generation of OTPs (One-Time Passwords) and the receipt of critical bank-related messages.
    • Acquiring Personal Data: Scammers begin by collecting victims’ personal details, including phone numbers, bank account information, and addresses, often through phishing or vishing (voice phishing) techniques. Phishing involves sending malware-laden links through emails or messages to steal personal data.
    • Forging Victim Identity: Armed with the stolen data, fraudsters visit a mobile operator’s retail outlet, impersonating the victim with forged ID proof. They falsely report the theft of the victim’s SIM card and/or mobile phone. As a result, they obtain a duplicate SIM card. Notably, fraudsters can secure a duplicate SIM even if the original is still functional. All activation messages and information are directed to the scammer rather than the victim.

    Why do victims receive Missed Calls?

    • Strategic Communication: In contrast to typical scams that involve tricking individuals into divulging OTPs and private data during phone calls, the SIM swap scam operates differently.
    • Distraction Tactic: Fraudsters initiate missed calls to their targets, prompting victims to check their phones and potentially ignore network connectivity issues.
    • SIM Exchange Execution: Perpetrators use these missed calls as a diversion while they execute the SIM swap. Once the SIM is swapped, fraudsters gain control over all calls and messages through the victim’s SIM, allowing them to initiate transactions unnoticed.

    How do scammers withdraw money?

    • Phishing Information: After acquiring personal data through phishing attacks, scammers use this information to access bank portals and generate OTPs required for fund withdrawal.
    • OTP Access: Having control over the victim’s SIM card, fraudsters receive all OTPs, enabling them to authenticate transactions and steal money.
    • Data Sources: Accused individuals purchase data from hackers involved in data breaches or from online portals. Data breaches often involve private companies losing vast amounts of customer data.
    • Example: In April, Rentomojo, an electronics and furniture rental company, reported a data breach, acknowledging unauthorized access to customer data due to a cloud misconfiguration.

    Arrests and Challenges

    • Absence of Arrests: Delhi Police has not made any arrests related to the SIM swap scam. The accused effectively evaded capture by discarding duplicate SIMs and operating from multiple locations.
    • Cryptocurrency Conversion: Stolen funds are often converted into cryptocurrency, making tracking Bitcoin or other cryptocurrency transactions impossible due to encryption.

    Protecting Yourself from SIM Swap Fraud

    • Stay Vigilant: Be cautious of vishing or phishing attacks and avoid clicking on suspicious links or sharing sensitive information.
    • Don’t Ignore Missed Calls: Don’t ignore missed calls or switch off your phone, especially if you receive multiple missed calls. Contact your mobile operator immediately if such activity occurs.
    • Regularly Update Passwords: Change bank account passwords regularly for added security.
    • Set Up Alerts: Register for regular SMS and email alerts for banking transactions to stay informed.
    • Report Fraud: In case of fraud, promptly contact your bank authorities to block your account and prevent further fraud.
  • Dark Pattern Sales by Airlines deemed ‘Cybercrime’

    dark patterns

    Central Idea

    • Due to complaints of deceptive practices by airlines and online travel agents, the Indian Ministry of Civil Aviation has urged IndiGo to fix its website, which a government official termed a Dark Pattern “cybercrime.”

    “Dark Patterns” in Airline Practices

    • Deceptive Techniques: Airlines and online portals have been accused of employing “dark patterns” in their user interfaces, which manipulate consumers into purchasing products they did not intend to buy.
    • Consumer Affairs Secretary’s Stance: The Consumer Affairs Secretary, Rohit Kumar Singh, defines “dark patterns” as tactics nudging consumers into unintended purchases, constituting unfair trading practices and possibly cybercrimes.
    • Pervasive Issue: Approximately 10,000 complaints related to these practices have been lodged with the Ministry via the National Consumers Helpline over the past eight to nine months.

    Manipulating Seat Selection

    • IndiGo’s Practice: IndiGo Airlines, for instance, employs a tactic known as “false urgency,” creating a sense of urgency by implying that consumers must pay an extra fee (₹99 to ₹1,500) for seat selection during booking, portraying all free seats as unavailable.
    • Transparency Issue: Passengers are not adequately informed that they will be auto-assigned free seats if they choose not to pay the extra fee.
    • Obfuscation: The “skip” option, although present, is inconspicuously located, demonstrating “interface interference.”

    Additional Unfair Practices

    • SpiceJet’s Pressure for Insurance: SpiceJet’s website pressures passengers to purchase travel insurance by using alarming phrases like “I will risk my trip” if they opt out, playing on passengers’ fears.
    • “Basket Sneaking” by MakeMyTrip: MakeMyTrip adds a convenience fee when customers reach the payment gateway after booking, a practice known as “basket sneaking.”

    Draft Guidelines and Regulatory Perspective

    • Ministry of Consumer Affairs Guidelines: These dark patterns have been defined in the draft guidelines released by the Ministry of Consumer Affairs in September.
    • DGCA’s Stance: The Directorate General of Civil Aviation (DGCA) permits “unbundling” airfares but emphasizes that these services must be offered on an “opt-in” basis, with clear descriptions without ambiguity.
    • Parliamentary Committee Report: A parliamentary committee report urges transparency in seat-wise airfares, fair pricing mechanisms to ensure reasonable profit margins, and effective grievance redressal mechanisms.

    Conclusion

    • The crackdown on deceptive airline practices by the Indian Ministry of Civil Aviation signifies a push for transparency and fairness in the airline industry.
    • The rise of “dark patterns” and other misleading tactics in online booking processes has raised concerns about consumer exploitation and cybercrimes.
    • As the government takes action to address these issues, passengers may expect a more equitable and transparent air travel experience in the future.

    Tap to read more about:

    India’s Draft Guidelines on Dark Patterns

  • Dawn of Passkeys: A Password-Free Future

    passkey

    Central Idea

    • In 1961, MIT computer science professor Fernando Corbato introduced the world to digital passwords, an innovation designed for research purposes. Little did he know the profound societal impact his creation would eventually wield.

    Why discuss this?

    • Passwords have become nearly synonymous with cybersecurity in the 21st century, albeit with an unsavory connotation.
    • Despite efforts to promote robust password practices, “password” and “123456” continue to dominate the list of common passwords, underscoring the pervasive vulnerability of most accounts.

    Passkeys: Need for Change

    • Ineffectiveness of Passwords: The prevailing authentication method, based on passwords, falls short in ensuring adequate security.
    • Big Tech Solution: In response to this predicament, major tech companies propose a solution – passkeys.

    Understanding Passkeys

    • Web Authentication Standard: Passkeys are a security feature built on the WebAuthentication (WebAuthn) standard.
    • Public-Key Cryptography: Passkeys employ public-key cryptography, a potent technique employing a public key (server-side) and a private key (user-side).
    • Authentication Process: When users log in, a challenge is sent to their device, which utilizes the private key to solve it and respond. The server then validates the response with the public key, all without storing any secrets, enhancing security.

    Getting Started with Passkeys

    • Wide Compatibility: Leading tech companies, including Microsoft, Google, and Apple, have collaborated to make passkeys accessible to most recent phones and PCs.
    • Operating Systems: Passkeys are available on iOS 16+, iPadOS 16+, macOS Ventura, Android 9+, Windows 10, and Windows 11.
    • Web Browsers: Passkeys are supported on popular browsers like Chrome, Edge, Safari, and Firefox.

    Creating and Using Passkeys

    • Account Requirement: Users need an account with a provider supporting passkeys, such as Microsoft, Google, or Apple.
    • Activation Process: To enable passkeys, sign in to a compatible app or website, activate the passkey option, and obtain a unique passkey linked to your account and device.
    • Usage: Passkeys can be used with biometrics (e.g., Touch ID, Face ID), QR codes, or device verification.

    Future of Passwords

    • Inevitable Evolution: While passkeys offer notable advantages over traditional passwords in terms of security and user-friendliness, they still face challenges related to compatibility and user adoption.
    • Industry Push: Notably, Google, Apple, and Microsoft are driving the passkey agenda strongly, suggesting that passwords may eventually become obsolete.

    Conclusion

    • A Security Evolution: The emergence of passkeys as an alternative to traditional passwords marks a significant shift in the realm of cybersecurity.
    • Ongoing Transition: As passkeys gain momentum and garner support from tech giants, they may gradually pave the way for a password-free future, promising enhanced security and user convenience in the digital realm.
  • Inside the Digital World of Cookies

    cookies

    Central Idea

    • In the online world, digital cookies hold a significant role, contributing to personalization and user convenience.
    • These unobtrusive lines of code, quietly stored on devices during website visits, shape the online experiences we encounter.

    Understanding How Cookies Work

    • Cookies as Digital Keys: Think of cookies as keys to an exclusive club. Just as a club bouncer recognizes regular patrons, cookies remember your login details on websites, eliminating the need for constant re-authentication.
    • Enhanced Online Shopping: Websites like Amazon leverage cookies to remember your past interactions, offering tailored product recommendations and an intimate shopping experience.
    • Persistent Shopping Carts: Online shopping carts, fueled by cookies, ensure your selections remain intact even after you leave the site, simplifying the checkout process.
    • Personalized Advertising: Platforms like Facebook and Google utilize cookies to track online behaviour, serving ads aligned with your preferences.

    Types of Cookies

    • Session Cookies: Temporary, session cookies function as post-it notes for websites, existing only in your computer’s memory during your browsing session.
    • Persistent Cookies: Comparable to bookmarks, persistent cookies remain on your device after your browsing session, retaining login information and preferences.
    • Secure Cookies: Sent over encrypted connections, secure cookies are employed for sensitive data like login credentials.
    • Third-Party Cookies: Originating from domains other than the visited site, third-party cookies serve tracking and advertising functions, offering both benefits and potential intrusiveness.

    Multifaceted Uses of Cookies

    • Digital ID Cards: Cookies facilitate user authentication, allowing websites to recognize and keep you logged in.
    • Personalization: They remember your preferences, such as language choices and website themes.
    • Persistent Shopping Carts: Items added online remain accessible upon your return.
    • Analytics Data: Cookies enable website owners to gather valuable data about user interactions for improvements and customization.
    • Targeted Advertising: Advertisers employ cookies to display ads aligning with your interests, enhancing online shopping experiences.

    Challenges Associated with Cookies

    • Privacy Concerns: Cookies can track online behaviour, occasionally infringing upon digital privacy.
    • Security Risks: Inadequately secured cookies may expose personal information to cybercriminals.
    • User Consent Era: Privacy regulations necessitate websites to seek user consent before deploying specific cookie types, resulting in pop-ups and prompts.
    • Third-Party Cookie Debates: Concerns about third-party cookies have led web browsers to limit their usage for user privacy protection.
    • Data Deluge: The multitude of cookies can potentially overwhelm your browser, causing a sluggish web experience.

    Conclusion

    • Complex yet Sweet: Cookies enhance online experiences but also bring privacy and security challenges. As the digital landscape evolves, so will the use and regulation of cookies.
    • Analogous to Real Cookies: Just like warm, gooey chocolate chip cookies, digital cookies add a personalized touch to your online adventures, even if they occasionally leave behind a few crumbs.
  • CERT-IN warns against Akira Ransomware

    akira ransomware

    Central Idea

    • The Computer Emergency Response Team of India (CERT-In) issued a warning about the Akira ransomware, a highly dangerous cyber threat that has been wreaking havoc on corporate networks worldwide.

    What is the Akira Ransomware?

    • Encryption and Data Theft: Akira ransomware encrypts sensitive data on targeted devices and appends the “akira” extension to filenames, making the files inaccessible to users.
    • Shadow Volume Deletion: The ransomware deletes Windows Shadow Volume copies, hindering data recovery options for affected organizations.
    • Ransom Demands: The ransomware operators extort victims by demanding a double ransom for decryption and recovery, threatening to leak sensitive data on their dark web blog if payment is not made.

    Infection and Working Mechanism

    • Spread Methods: Akira ransomware is primarily distributed through spear-phishing emails with malicious attachments, drive-by downloads, and specially crafted web links. It also exploits insecure Remote Desktop connections to infiltrate systems.
    • Selective Encryption: The ransomware avoids encrypting specific system folders to maintain system stability.
    • Negotiation Process: Each victim is given a unique negotiation password to communicate with the ransomware gang via the threat actor’s Tor site.

    Major targets

    • Corporate Networks: Akira ransomware targets corporate networks across various sectors, including education, finance, real estate, manufacturing, and consulting.
    • Data Exfiltration: In addition to encryption, the threat actors steal sensitive corporate data, using it as leverage in their extortion attempts.

    Protective Measures against Akira Ransomware

    • Regular Backups: Maintain up-to-date offline backups to ensure data recovery in case of an attack.
    • System Updates: Regularly update operating systems and networks, and implement virtual patching for legacy systems.
    • Email Authentication: Establish Domain-based Message Authentication, Reporting, and Conformance (DMARC), Domain Keys Identified Mail (DKIM), and Sender Policy Framework (SPF) to prevent email spoofing and spam.
    • Strong Authentication: Enforce strong password policies and multi-factor authentication (MFA) to secure user accounts.
    • Data Encryption: Implement data-at-rest and data-in-transit encryption to protect sensitive information.
    • Attachment Blocking: Block suspicious attachment file types like .exe, .pif, or .url to prevent malicious downloads.
    • Security Audits: Conduct regular security audits, especially for critical networks and database servers, to identify vulnerabilities.
  • CoWIN Data Breach: Data Privacy and Security Concerns in India’s Digitalization Journey

    Data

    Central Idea

    • The recent CoWin data leak has raised significant concerns about data privacy and security in India. While the leak itself is disconcerting, what is more troubling is the government’s response to the issue. Mere assurances that the back-end database is still secure do little to alleviate the concerns of citizens.

    CoWIN Data Breach and Government Denials

    • Data Breach: On June 12, a data breach on the CoWIN platform was reported by the Malayala Manorama and online portal “The Fourth.” Personal details, including vaccination information and identification numbers, were found circulating on the messaging platform Telegram.
    • Government Denials: Despite the mounting evidence of the data breach, the Ministry of Health and Family Welfare and Minister of State, Ministry of Electronics and IT (MEITY), responded with denials. The Ministry of Health and Family Welfare labeled the reports as “mischievous,” while the Minister of State, MEITY, claimed that the sensitive information had emerged from previously stolen data.
    • Press Information Bureau Statement: Later in the day, the PIB issued a statement asserting the complete safety of the Co-WIN portal and its adequate safeguards for data privacy. However, the credibility of this statement was questionable, given the initial denials and the substantial evidence of the breach.
    • Lack of Transparency: The government’s response to the CoWIN data breach exemplifies a recurring pattern of denial and opacity in addressing data breaches in the public sector. Previous incidents, such as the Employees’ Provident Fund Organisation breach and the ransomware attack on AIIMS, have been met with similar denials and lack of transparency.
    • Erosion of Trust: The consistent lack of transparency, coupled with the absence of a National Cyber Security Strategy and data protection laws requiring breach notifications to affected users, has eroded citizens’ trust in the government’s ability to secure their personal information. T

    Articulating Threat Models for Robust Security

    • Adversaries Corrupting Insiders: The threat model assumes that adversaries can corrupt all insiders, including system administrators and personnel with authorized access.
    • Compromised Custody Chains: The threat model includes the possibility of adversaries compromising the custody chains of data, which may involve unauthorized access or tampering with data during its lifecycle.
    • Compromised Hardware and Software: The threat model assumes that adversaries can compromise both hardware and software components, potentially exploiting vulnerabilities in these systems.

    Challenges in Indian Digitalization Initiatives

    • Limited Infrastructure: One of the significant challenges in Indian digitalization initiatives is the limited infrastructure, especially in rural areas. Inadequate internet connectivity, lack of reliable power supply, and limited access to digital devices pose obstacles to the effective implementation of digital services.
    • Digital Divide: India faces a significant digital divide, with a large section of the population having limited or no access to digital technologies. This divide is often along socio-economic lines, with marginalized communities and rural areas facing more significant barriers to digital inclusion.
    • Data Security and Privacy: Ensuring data security and privacy is a persistent challenge in Indian digitalization efforts. Incidents of data breaches, leaks, and unauthorized access to personal information highlight the need for robust data protection frameworks and stringent security measures.
    • Cybersecurity Threats: With the expansion of digital services, the risk of cybersecurity threats such as hacking, phishing, malware attacks, and ransomware has increased. The government and relevant stakeholders need to invest in cybersecurity infrastructure and raise awareness about safe digital practices.
    • Skill Gaps and Digital Literacy: Many individuals, particularly in rural areas, lack the necessary digital skills and literacy to effectively utilize digital services. Bridging the digital skills gap and promoting digital literacy are essential for the successful adoption of digitalization initiatives.
    • Interoperability and Standardization: The lack of interoperability and standardization among different digital systems and platforms hampers the seamless integration of services. It creates complexities in data sharing, collaboration, and the overall user experience.
    • Legal and Regulatory Frameworks: Developing comprehensive and up-to-date legal and regulatory frameworks for digitalization is crucial. It includes laws related to data protection, privacy, electronic signatures, cybercrime, and digital transactions. Ensuring these frameworks are robust and aligned with international best practices is necessary for building trust and confidence in digital services.

    Data

    Consequences of Inadequate Privacy Risk Assessment

    • Data Breaches and Leaks: Inadequate privacy risk assessment can lead to data breaches and leaks, exposing sensitive personal information to unauthorized access. This can result in identity theft, financial fraud, and other forms of misuse of personal data.
    • Privacy Violations: Insufficient assessment of privacy risks can result in privacy violations, where individuals’ personal information is used or disclosed without their consent or in ways that infringe upon their privacy rights. This can erode trust in digital services and undermine individuals’ confidence in sharing their data.
    • Loss of Control over Personal Information: Without proper risk assessment, individuals may lose control over their personal information. This can lead to the unauthorized collection, storage, and use of their data by both private and public entities, potentially exposing them to various risks and harms.
    • Discriminatory Practices: Inadequate privacy risk assessment can contribute to discriminatory practices, where personal data is used to profile individuals based on sensitive attributes such as race, religion, gender, or political beliefs. This can lead to unfair treatment, exclusion, and perpetuation of bias in decision-making processes.
    • Societal Harms: Privacy breaches resulting from inadequate risk assessment can have broader societal impacts. For example, leaked personal information can be exploited for political manipulation, voter profiling, or predatory advertising, potentially influencing elections, public opinions, and individual choices.
    • Erosion of Trust: When privacy risks are not adequately assessed and addressed, it can erode public trust in digital services, government initiatives, and the overall data ecosystem. Lack of trust can hinder the adoption of digital technologies, impede economic growth, and undermine the potential benefits of digitalization.
    • Legal and Regulatory Consequences: Inadequate privacy risk assessment may lead to non-compliance with data protection laws and regulations, potentially resulting in legal consequences, penalties, or lawsuits. Failure to protect individuals’ privacy rights can attract regulatory scrutiny and damage the reputation of organizations or government entities involved.

    Data

    Way ahead: The Need for Standardized Grammar in Security and Privacy Discourse

    • Defining Threat Models: Establishing well-articulated threat models is crucial. This involves identifying potential risks, vulnerabilities, and capabilities of adversaries. It provides a common starting point for discussions and allows stakeholders to align their understanding of security and privacy concerns.
    • Promoting Best Practices: Encourage the adoption of best practices in security and privacy. This includes following internationally recognized standards and frameworks, such as those provided by organizations like the National Institute of Standards and Technology (NIST) or the International Organization for Standardization (ISO).
    • Clear Communication of Security Measures: System designers and administrators should precisely articulate the security measures implemented to address specific threats. It is important to go beyond vague claims of “state-of-the-art best practices” and provide concrete details on how security and privacy issues are being tackled.
    • Publicly Articulating Threat Models: Digital service providers and government agencies should publicly articulate their threat models. By doing so, they demonstrate transparency, foster trust, and allow stakeholders to assess the adequacy of security measures in place.
    • Collaboration and Knowledge Sharing: Encourage collaboration and knowledge sharing among stakeholders involved in security and privacy discourse. This can be done through forums, conferences, and working groups where experts can share experiences, insights, and best practices.
    • Developing Common Terminology: Establish a common terminology and vocabulary for discussing security and privacy concepts. This helps to avoid misunderstandings and ensures that stakeholders are on the same page when discussing security risks and mitigation strategies.
    • Education and Training: Invest in education and training programs to enhance the understanding of security and privacy concepts among professionals, policymakers, and end-users. This includes promoting cybersecurity awareness and digital literacy to empower individuals to make informed decisions about their privacy.
    • Regulatory Frameworks: Develop comprehensive and up-to-date regulatory frameworks that incorporate standardized security and privacy measures. These frameworks should address specific threat models, outline data protection requirements, and establish accountability mechanisms for organizations handling personal data.
    • Independent Audits and Certifications: Encourage independent audits and certifications of digital systems to verify their adherence to standardized security and privacy practices. This helps build trust and provides assurance to users that appropriate measures are in place to protect their data.

    Conclusion

    • India’s digitalization journey has been remarkable in its scale and scope, but there is a pressing need to reinforce it with computer science rigor. Strengthening data security and privacy practices is paramount to ensure public trust and the success of digital public services. With a well-structured approach, India can leverage the benefits of digitalization while safeguarding the privacy and security of its citizens’ data.

    Also read:

    CoWIN Vaccination Data Breached

     

  • CoWIN Vaccination Data Breached

    cowin

    Central Idea

    • Data breach reports: The Health Ministry, on Monday, refuted claims of a data breach of COVID vaccination beneficiaries, stating that such reports were baseless and mischievous in nature.
    • Investigation by CERT-In: The Indian Computer Emergency Response Team (CERT-In) has been asked to investigate the alleged data breach issue and submit a report to ascertain the facts.
    • Assurance of data safety: The Ministry maintains that the CoWIN (Covid Vaccine Intelligence Network) portal is completely safe, equipped with adequate safeguards to protect data privacy.

    About CoWIN

    • Development: CoWIN was developed and is owned and managed by the Ministry of Health.
    • Policy decisions: The Empowered Group on Vaccine Administration (EGVAC), chaired by the former CEO of the National Health Authority, oversees this. It includes members from the Health Ministry and MeitY (Ministry of Electronics and Information Technology).

    Evaluation of Alleged Breach

    • CERT-In review results: The review conducted by CERT-In concludes that there was no direct breach of the CoWIN app or database.
    • Data source of Telegram bot: The data accessed by the Telegram bot was sourced from a separate threat actor database, which contained previously breached or stolen data.
    • No direct breach of CoWIN: The Ministry states that it does not appear that the CoWIN app or database itself was directly breached.

    Clarification on CoWIN Data Access

    • Three methods of data access: The Ministry outlines the three ways in which data can be accessed on the CoWIN portal: user access, vaccinator access, and authorized third-party applications.
    • Data sharing with Telegram bot: The Ministry clarifies that data cannot be shared with the Telegram bot without undergoing the one-time password (OTP) authentication process.
    • Limited data collection: CoWIN only collects the year of birth and does not capture a person’s address.

    Unanswered Questions and API Access

    • Uncertainty regarding recent breaches: The Ministry has not explicitly clarified whether the CoWIN database was breached recently or in the past.
    • Lack of insights on bot accuracy: The Ministry’s statement does not offer insight into the accuracy of the Telegram bot’s retrieval of citizens’ data from the CoWIN database.
    • API access without OTP: The Ministry admits the existence of an API that allows data sharing without OTP, but emphasizes that requests are accepted only from trusted whitelisted APIs.

    Concerns and Aadhaar Data

    • Accuracy of Aadhaar details: The accuracy of displaying Aadhaar numbers corresponding to mobile numbers raises concerns, as the government has never publicly acknowledged any breaches of Aadhaar data.
    • Need for clarity: The Ministry’s statement does not provide clarity on how the Telegram bot accurately displayed Aadhaar numbers.
    • Addressing security concerns: The Ministry should address concerns regarding the security of Aadhaar data and provide transparency on its safety measures.

    Future Steps and Data Governance Policy

    • Empowering CERT-In: The Health Ministry has requested a final report from CERT-In to investigate the alleged data breach incident thoroughly.
    • National Data Governance policy: The Ministry highlights the finalization of the National Data Governance policy, which aims to establish a common framework for data storage, access, and security standards across the government.
    • Awaited response from CERT-In: The Ministry is awaiting a response from CERT-In regarding the issue, which will provide further insights into the nature of the breach.

    Assurance and Previous Leaks

    • Assurances of secure infrastructure: Health authorities maintain that CoWIN has state-of-the-art secure infrastructure and has never experienced a security breach.
    • Dismissal of previous claims: Previous claims of data leaks, such as the ‘Dark Leak Market’ incident, were dismissed by health authorities, emphasizing the safety of citizen data.
    • Security measures in place: CoWIN has implemented security measures such as web application firewall, regular vulnerability assessments, and OTP authentication to ensure the protection of data.

    Implications of this data leak

    • Identity theft risks: The leaked data exposes individuals to the risk of identity theft, as sensitive information can be misused for fraudulent activities.
    • Targeted scams and phishing attacks: With access to personal details, scammers may attempt targeted scams and phishing attacks, leading to financial loss and potential harm to individuals.
    • Loss of trust in government systems: The data breach undermines public trust in the government’s ability to safeguard sensitive information, affecting confidence in the vaccination program and other government initiatives.
    • Reputational damage: The incident could tarnish the reputation of the CoWIN platform and associated government agencies, affecting their credibility in managing sensitive data.
    • Impact on future vaccination drive: Concerns about data security may deter individuals from participating in the vaccination program, slowing down efforts to control the spread of COVID-19.
    • Calls for accountability: The data leak prompts demands for accountability from the responsible government agencies and the implementation of stricter measures to protect citizen data.

    Conclusion

    • The data leak incident related to the CoWIN portal raises serious concerns about the privacy and security of individuals’ personal information.
    • While the Ministry of Health maintains that the CoWIN app and database were not directly breached, the access to sensitive data through a Telegram bot raises questions about the integrity of the system.

     

    Get an IAS/IPS ranker as your 1: 1 personal mentor for UPSC 2024