Live data from Hacker News

I could send any text message from Indian government IDs

kmskrishna.me

21–30 of 46 posts

Re: I could send any text message from Indian government IDs

#22
> Essentially, anyone can’t send arbitrary messages using the above-mentioned loophole anymore. TRAI’s new system fixed that loophole. > One can still send any message that fits in the template. But this largely restricts the possibilities of scams and misuse.

Seems to be fixed and that it was fixed during the time he did _nothing_ and just waited. Perhaps there was a responsible disclosure but he didn't said how he did it.

Re: I could send any text message from Indian government IDs

#23

Earlier quoted context omitted.

Brave? Or dumb? Using someone else’s credentials is against the law in most jurisdictions.

Intent tends to matter. I once reported an exposed AWS access key (someone posted it to StackOverflow) to AWS support and they weren't quite sure what to do with it; gave me instructions on how to disable it in the Console, but it wasn't mine. I gave up after a couple rounds and just committed it to Github; their credential monitoring bot disabled it within seconds.

> their credential monitoring bot disabled it within seconds

This is Amazon’s monitoring bot right?

Re: I could send any text message from Indian government IDs

#24
post #20

> You would likely believe it, given the sender ID, wouldn’t you? No. I absolutely don't believe anyone unknown calling me, no matter who he claims to be, or what the CLIP says, unless I can call back to a public number of the institution he claims to represent. CLIP just isn't secure. I choose to risk believing for non-essential things, because security is just not convenient. But banks, government, anything where t…

I absolutely agree with you. I would also do the same. Here I think the author meant not so tech savy normal people.

Re: I could send any text message from Indian government IDs

#25
post #4
post #3

I think the author went way over the line here and should probably retract ASAP for his own well being.

You are totally right. Hope he gets this thread and removes that page for ever (at least the details), he runs a serious risk.

I do not understand, serious risk of what?

Re: I could send any text message from Indian government IDs

#27
post #16

He should use this to tell everybody in India to stay hime, wear masks and stop going to mass worship ceremonies that are causing this devastating covid spike.

See also: mega churches in the US.

Sure, but i’m not sure indian government officials spamming evangelical christians will have much effect? Can this system even mass spam non-indian cell subscribers?

Re: I could send any text message from Indian government IDs

#28
post #4

Earlier quoted context omitted.

You are totally right. Hope he gets this thread and removes that page for ever (at least the details), he runs a serious risk.

I do not understand, serious risk of what?

He lives in India, and he's basically pentesting Indian government websites without permission and boasting about it publicly. They seem to have laws prohibiting that sort of thing: https://www.indiacode.nic.in/bitstream/123456789/1999/3/A200...

Re: I could send any text message from Indian government IDs

#29
post #23

Earlier quoted context omitted.

Intent tends to matter. I once reported an exposed AWS access key (someone posted it to StackOverflow) to AWS support and they weren't quite sure what to do with it; gave me instructions on how to disable it in the Console, but it wasn't mine. I gave up after a couple rounds and just committed it to Github; their credential monitoring bot disabled it within seconds.

> their credential monitoring bot disabled it within seconds This is Amazon’s monitoring bot right?

It’s a GitHub feature: https://docs.github.com/en/code-security/secret-security/abo...
Post reply on HN