Showing posts with label Current Affairs. Show all posts
Showing posts with label Current Affairs. Show all posts

Tuesday, September 22, 2015

Indian National Encryption Policy

It is interesting to note that the Government of India's Department of Engineering and Information Technology has issued National Encryption Policy for public comment.  And today the first addendum for the same has been issued for the people to refer to.  However, when it comes to the overall policy, it has been left out pretty lopsided. When I say Lopsided, I mean from the subjectiveness & perspective dependence that has been maintained throughout the Policy.

I would not get into those micro level details where the industry's who's who is making some or other comment on the types of services that would be covered and the type of data user as well as business would need to be retained for 90 days.  That's a very low level speculative inference that would differ from person to person and from perspective to perspective. My initial view was same and I also took to twitter for that :)

What my assessment of the Policy is the lacuna that is maintained by not aligning it to the industry standards and not basing it on the prevailing trends.  For that matter, one of the key aspect that I find missing is the way the Committee should have taken cognizance of the "Heart Bleed" as well as "Poodle" vulnerabilities that led to the demise of SSL as an Encryption Standard. It should have been noted that the PCI-Council has declared that SSL is no more a supported standard for encryption and that TLS 1.2 is the deficto standard until next such notification. Indian National Encryption Policy has this void in it to align itself with the latest, thought he vision and mission state so.  The policy goes anywhere else than stay around the vision and mission.

I am surprised to actually read the reference of SSL in the Policy at the time the world is moving to TLS 1.2 and the bigwigs of industry have already moved to the other side of adopting TLS 1.2.  Moreover, TLS 1.3 is already being eyed as it is slated for release by next year. We have already seen the advent of SHA3 earlier this year and the Policy still sticks around to 3DES and RC4. It needs to be noted that RC4 already has been vulnerable to attacks and can be actually be used to get some hand on the information encrypted using the encryption standard (Read - Article on Security Week - Dated March 2015). Moving on to the 3DES, it is not at all considered strong enough to protect the data and when the Target Breach happened, it was identified that 3DES was deployed and there was a lot of scrutiny on that move as to when AES was available why 3DES was used?

So, when the industry is basing their opinion on the micro issues of what to store how to store, where to store and talking about the data security & integrity from a different angle, my real concern is the coverage of obsolete standards and technologies as part of the overall Policy and basing the policy on those obsolete standards and technologies.  I am not sure why the Trade Pundit's or the bloggers in social media have not raised this issue till now.

Certainly, in its current format the Policy itself would be obsolete in not more than 6 months and that would call for next round.  But would DeitY listen to the Gen Next or are we still going to hear from the "Experienced" folks who missed to evaluate the latest and greatest developments??

Would you hear the voice of Young India or would this also go the TRAI way???

Friday, July 5, 2013

Use of Technology for Payment Transactions

The days when we used to make payments with hard cash are long gone.  With the advent of new age technology, Bank cards (Debit/Credit) and the Internet Banking, we all do go for convenience payment sitting in the comfort of our home and / or office.  The payments made in this way are something that can be tracked without dealing with the trouble of paper receipts.  

That's said, it is critically important to review the options before making payments with the use of technology as along with the convenience of making payment, technological advancements have provided the newer ways for attacks and scams.  Initially there were Phishing Attacks where the attacker would host a Dummy Site for the target bank and get the required information and enjoy the proceedings.  As the users started getting smarter and the Banks started implementing tighter security norms and getting the fake sites down, there came the Vishing Attack or where the attacker posing as the genuine Phone Banker or Customer Service Associate tries to extract relevant information including Sensitive Personal Information and PIN/CVV/CVC of the Card being discussed about. In many instances the Customers Do fall pray to such calls and they end up loosing their hard earned money.  Typical Case to be read here - Paying bill online costs man Rs 50,000

Now the main points to be noted while making online payments or while getting on for online transactions  are - 
  1. For making online payments, ensure that you register the organization, to whom you want to make payment, at your Bank's Internet Banking site
  2. If you find it cumbersome to register the Biller at your Bank's site, please ensure that you make the payment from the Official Site of the Biller and also by creating your own Account on that site
  3. Ensure that you DO NOT use any third party website for any online Bill Pay, as they may claim  to facilitate the transaction, but this is NOT always safe
Another aspect that needs to be taken care of is the payment through IVR System of the Biller or the Bank.  It is pretty important to note the following points - 
  1. Never reveal Sensitive Information like CVC/CVV/PIN during an Automated Call or while talking to the Phone Banker or Customer Service Representative
  2. It is critical to note that you never get a Call from either the Bank or the Biller stating to share your sensitive information to enable the payment through Phone Banking or IVR.  A Payment through IVR or Phone can only be initiated when you would call the Bank or the Biller to make such Payments
  3. Please ensure that if anyone claiming to be from the Bank or from the Biller seeks to gain your PIN/CVV/CVC and other information that is generally not sought by Banks / Biller, disengage yourself from the call and raise a written complain with your Bank / Biller through netbanking/biller website. This will trigger a automated response to your mail box.  Do not reply to that address and just wait for an official mail from your bank (delivered in netbanking inbox) and or Biller (delivered at your Registered email address).  
  4. You have a choice to refer the case to the Consumer Forum / RBI / Appellate Tribunal depending on your choice and party involved. When you refer the case to concerned authority you wold need to provide details around the transaction that is being referred, the person's name (if you remember), time you made the call, duration of the call and summary of the call proceedings.  Remember that IVR calls are always recorded and in such a case your claims can be verified at the Bank / Biller's side.
So, to be safe is in your hands and to ensure that you don't fall pray to such cases is totally in your hands.  You need to be really careful for not disclosing the sensitive information to anyone or on any weblink that you may get claiming to be of a bank.

Please ensure to verify the Website address as it would always have some altered information if it would be from the imposter. And the most important thing - if you suspect that your information has been compromised - raise a Red Flag Complain immediately with the Bank.  Bank's Do provide you with all the required help to protect against any fraudulent activity in your account.  In case you know that someone gained your personal information and has misused it, please lodge a written complain with the bank before you head to the Law Enforcing Agency.  A Copy of the Complain raised with Bank always helps you in your case and the Banks then have to ensure that they do cooperate in your case to get you the rightful justice.

However, in the current technological era, the old saying "Better to be Safe than Sorry" as well as "Precaution is Cure" still stand true.  So take due precautions to not let someone defraud you...its your information and you have the right to refusal for imparting the same...

Tuesday, December 18, 2012

New Viruses as reported

The recent developments that hackers are adopting to target the systems are pretty interesting.  The Batchwiper as detected by the Iranian CERT and the Trojan as reported with evade technology are the two recent developments.  The Batch Wiper though can be contained with certain precautionary measures, but the Trojan with evade technology would certainly be something that would create a widespread Havoc.  

With the evade technology the Anti-Virus Firms would need time and research to ensure that the right set of detection & quarantine techniques are used so as not to jeopardize the O/S routines that the Trojans use to evade the AV.

Specifically with the Trojan that is reported and that waits for the left Mouse Click routine to execute the commands is one tricky case.  Certainly, we can't stop using mouse with the fear of the Trojan getting executed.....

Time to look out and dig deeper around these aspects to ensure that the corporate as well as home users are impacted the least.....

Sunday, February 5, 2012

Gadget - The Technology of Enslavement


When we look around ourselves, we find that we are living in the ever evolving world of Gadgets or we can rather say that we are being enslaved by the Gadgets.  So what is a Gadget? Let’s draw a caricature of Gadget with following definition –
“A Gadget is a small device or appliance with a particular functionality that may be considered as a novelty over and above the existing technological products.  They may be scaled down version of the technological products or may be an upscale version, but one thing they surely add to the use is comfort and user friendliness.” Gadgets are often referred as Gizmos also.
When we look at the Gadgets that we have around us, we find them touching every walk of our life; right from the morning alarm to the phones to the driving aids of Bluetooth and to the e-readers all have evolved over past decade or so.  Below we discuss some of the most talked gadgets today
1.       Smartphones – With the features of Alarms, Digital Diaries, Notes, emails, News and Web Surfing, ebooks, chats and messengers, camera etc. they have changed the way the world used to communicate. Add to the new generation of smartphones that have video-calling facility.
2.       E-readers – They have really reduced the millions and zillions of pages in small and thin electronic readers to provide the ease of carrying our favorite books whenever and wherever we go.  Add to that the books available for free and on the subscription based facility to be able to choose from thousands of books in just one thin device, even smaller than our usual text books.
3.       Digital Cameras – Gone are the days when we had to buy the camera, the role and then run around to do the errands of getting the role developed and print.  Now we are in the era where we can simply take the photo and share that with our friends and family across geographies in minutes with just a click.  Well, indeed the new generation of cameras are talking about share on Social networks via a Wi-Fi Connectivity
4.       Tablets – The new generation of Computing Devices that have really submerged the difference between a smartphone and a Laptop/desktop.  Moreover the touchscreen, the camera, the video capture functionality, the e-reader etc are all merged in this one device that provide the facility to connect either through a wi-fi or normal mobile phone network.  Though they are not yet a success in India, but future is still bright for them.
5.       Game Consoles – With the Playstations and Xboxs, the games have entered the living room of the house with the video sensitivity added and the Motion detector helping you imitate the real world. These gaming Consoles have also converged the normal social points to the living rooms by converging the TV and Gym to our living rooms.
So indeed, it is not exaggerating to say, we are becoming the Slaves of Gadgets and Drifting to a world of Monotony.

Thursday, December 23, 2010

Issue of Data Protection & Privacy in India

Just what I had highlighted in the previous two posts about the Government intentions to get access to the Google mails along with the Blackberry and Skype.  Interestingly the news is here -  "Government wants to read your Gmail".  Well pretty Interesting huh!!! Just when we were worried about the Privacy of the previous cases, we get to know the cave in of the defense of Nokia and now Google is in Line.


I am not sure how would the Government ensure the security of the Personal Information associated with the emails et al.  It is well understood that the step is taken in the interest of National Security, but if the Government can't secure the Information collected through the access obtained, I do not see why the Netizens shouldn't Panic?


Its High-time for the Government to create an infrastructure that is Effective, Efficient and Resilient to counter Hacking attempts and at the same time ensure that the Privacy of Information is maintained at the level of "Classified Information" that should be accessible ONLY to the Agency responsible for and is in-charge of the said investigation. 


National Security also includes in its Folds the Security of Its Citizens and Netizens.  We should not be going Draconian Ways to create a scenario where the Individuals and Corporates get back to the traditional means of communication for the Fear Information Compromise by Government Agencies and then Leaking it in the Public Domain....Yeah there has to be some restrains on that side too.....

Tuesday, December 7, 2010

VoIP and the Risk of Data Privacy and Protection

Just finished reading "Encrypted Phone Calls & Skype Security" by a fellow blogger and a technocrat Friend Mukesh Kesharwani. Indeed pretty interesting and well covered stuff no doubts and that is what we expect from Mukesh.

However, when I look in from my Risk and Compliance Corner, the concern of using Skype in Corporate Network still looms large and Rings the Bell in my head... Can't do away with that as for me the Data Privacy and Protection (be it in any form) is primer.

Some of you might have read my previous post on this when I had written about the Blackberry Security and Issue of National Security.  I would reiterate those concerns in the case of Skype Usage also.  For most of the cases, if Skype is used for Corporate purpose, the corporates would try to cut the cost and try and use the retail version of Skype that's available to one and all with access to Internet.  In this case, I am sure that as and when the Security Agencies get access to the Data exchanged on Skype, though the sorts of agreement it now has with Research in Motion (the Company that owns the Blackberry Brand), there would be a High Risk to the Confidential and Business Critical Data that would be shared using Skype and mind it that may include files shared or voice communication.  Certainly if a company is using Skype, it would also use the VOIP facility to ensure that the Cost of Communication stays low.  

I would still suggest to take a step at a time in this arena to ensure that the Corporate Risk related to Data Privacy and Protection does not get High "Particularly when the Country DOES NOT have a Data Protection and Data Privacy Regime".  When I highlighted that risk in my previous blog, certainly there were few high profile cases of Data leak, but now we have the example of Telephone Tapes in which the conversations were taped in by an enforcement agency authorities to investigate some case, but the tapes went to Public Domain and now to the Apex Court.  

I still would be not too happy to hear from the Corporates Adopting Public Domain technologies for handling Corporate Affairs and Exchange Business Critical and/or Business Sensitive information over such channels.  Unless, the Govt comes around with a Data Privacy and Protection Regulation to ensure that the information stays where it is supposed to be and is not leaked out in a domain where it may be utilized in a fashion to cause material damage to the Corporate Affairs or so......

The Risk Remains High till such time....