Live data from Hacker News

Indian Government Breached, Massive Amount of Critical Vulnerabilities

johnjhacking.com

21–30 of 74 posts

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#21
At this point, wouldn't it be easier to design systems as completely open, with all user data exposed?

Then for actual interaction purposes, to rely on biological verification? eg. widespread retina and fingerprint scanning.

As a side effect this would somewhat limit tax evasion - if all tax returns and income were public, as in countries like Norway.

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#23

This smells a bit off: why is there no detail whatsoever on what exactly they breached? The "Indian Government" (central, state, other?) is a sprawling octopus that employs on the order of 50 million people, and there's a world of difference between breaching the public site of the Department of Fertilizers ( https://fert.nic.in/ ) vs getting into the internal systems of the Ministry of External Affairs. The only clu…

I think that Twitter user is just a member. One of the founders is https://twitter.com/johnjhacking who proclaims to have a full time job and be a disabled vet.

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#24

This smells a bit off: why is there no detail whatsoever on what exactly they breached? The "Indian Government" (central, state, other?) is a sprawling octopus that employs on the order of 50 million people, and there's a world of difference between breaching the public site of the Department of Fertilizers ( https://fert.nic.in/ ) vs getting into the internal systems of the Ministry of External Affairs. The only clu…

"Indian government" means central government, not state. Just like "US government" always refers to the federal government.

I would have the same question of the US federal government being breached: which systems, exactly?

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#25
post #14

So in the process of communicating with the Indian Government to resolve the issues responsibly, they announce on Twitter "We Breached The Indian Government!!!". What is wrong with them?

no/less bounties from gov? researcher wants to show off? 10 year old kid who recently wrote some script and has a lot of over confidence? Who knows.

But its a fault of Indian Government too. They hire programmers who are less competent to save budget for salary. And if someone reports some vulnerebility I bet these government police will come after the reporter. And there is no incentives too.

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#26
post #11

> Governments have an obligation to protect the private data of its employees and citizens. In addition, the exposure of proprietary government data can be used for great means of manipulation and for other destructive purposes. Understandable. > While the NCIIPC operates a Responsible Vulnerability Disclosure Program, the recklessness and avoidance of communication represents the complete opposite of a responsible p…

Because responsible disclosure isn’t as cool and being a l337 h4x0r

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#27
post #5

Is there any financial incentive to secure an Indian citizen's data ? In fact, there's more financial incentive to make things leaky, less work needs to be done to peek into your neighbors yard, and the vast (vast, vast) majority of the people cannot give a damn about this. Frankly, I'm surprised they replied with an acknowledgement and tried to fix some vulns. Expect no more changes.

Indian Government Sold Driver Licence Data to 87 Private Companies for Rs 65 Crore - https://www.news18.com/news/auto/government-sold-drivers-lic...

The data is already publicly available via government sites and app store. By making the data public through 3rd parties, government just made it easy for public to access it.

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#28
post #14

So in the process of communicating with the Indian Government to resolve the issues responsibly, they announce on Twitter "We Breached The Indian Government!!!". What is wrong with them?

They don’t fear jail for some reason...why?

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#29

If these guys were Indian pretty sure they would be facing jail time for exposing such vulnerabilities (1) (1) https://www.livemint.com/Opinion/S6Ep52qB9PK1DRLFUbUDBK/The-...

Well. Section 47 is a real delight, a diabolical inversion of the principle of locus standi. Increasingly, there are agencies and laws which say that "you cannot take us to court". As though writing it makes it somehow legal. Reminds me of calvinball.
Post reply on HN