Live data from Hacker News

Indian Government Breached, Massive Amount of Critical Vulnerabilities

johnjhacking.com

31–40 of 74 posts

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#31
post #11

> Governments have an obligation to protect the private data of its employees and citizens. In addition, the exposure of proprietary government data can be used for great means of manipulation and for other destructive purposes. Understandable. > While the NCIIPC operates a Responsible Vulnerability Disclosure Program, the recklessness and avoidance of communication represents the complete opposite of a responsible p…

Because responsible disclosure isn’t as cool and being a l337 h4x0r

It also doesn't pay nearly as well with many organizations.

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#32
Everyone seems to assume it is the central government. No one has remarked on this, the following somewhat obvious. One of the screenshots has a heading in Malayalam, saying "Bill Vivarangal" - "Bill details" [1].

Was it some government of Kerala service which was breached? Or is it one of several governments? Or was it only the central government with Malayalam as the language set for the interface?

If it was an Indian hacker, they would know that the language will be a big giveaway, so they would have obscured it. (India has about 15 official languages, and probably about 10 scripts each with 10+ million users [2].) Overall, I cannot dismiss the feeling that it is some script kiddie who attacked some underfunded department, rather than some big deal.

[1] https://johnjhacking.com/uploads/session-chained.png

[2] https://en.wikipedia.org/wiki/Brahmic_scripts

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#33
post #32

Everyone seems to assume it is the central government. No one has remarked on this, the following somewhat obvious. One of the screenshots has a heading in Malayalam, saying "Bill Vivarangal" - "Bill details" [1]. Was it some government of Kerala service which was breached? Or is it one of several governments? Or was it only the central government with Malayalam as the language set for the interface? If it was an Ind…

Tamil kooda irukalam

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#34
post #33
post #32

Everyone seems to assume it is the central government. No one has remarked on this, the following somewhat obvious. One of the screenshots has a heading in Malayalam, saying "Bill Vivarangal" - "Bill details" [1]. Was it some government of Kerala service which was breached? Or is it one of several governments? Or was it only the central government with Malayalam as the language set for the interface? If it was an Ind…

Tamil kooda irukalam

enge?

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#35
post #15
post #7

Earlier quoted context omitted.

What does RS 65 Croer mean?

Crore is equivalent to 10e6. In this case, that would evaluate to 650'000'000 INR.

> 10e6

Under scientific notation, you should strongly prefer to write 1e7. 10e6 is just begging for people to interpret it as 10⁶ rather than 10×10⁶ (10⁷).

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#36
post #5

Is there any financial incentive to secure an Indian citizen's data ? In fact, there's more financial incentive to make things leaky, less work needs to be done to peek into your neighbors yard, and the vast (vast, vast) majority of the people cannot give a damn about this. Frankly, I'm surprised they replied with an acknowledgement and tried to fix some vulns. Expect no more changes.

Indian Government Sold Driver Licence Data to 87 Private Companies for Rs 65 Crore - https://www.news18.com/news/auto/government-sold-drivers-lic...

Calofornia does it sell for 50Mio USD and Florida for 77Mio USD. I guess just everybody sell everything today.

https://www.caranddriver.com/features/a32035408/dmv-selling-...

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#37
post #32

Everyone seems to assume it is the central government. No one has remarked on this, the following somewhat obvious. One of the screenshots has a heading in Malayalam, saying "Bill Vivarangal" - "Bill details" [1]. Was it some government of Kerala service which was breached? Or is it one of several governments? Or was it only the central government with Malayalam as the language set for the interface? If it was an Ind…

https://sakurasamurai.org is newly added domain (suspicious). In India there are some motivated groups try to blame central government for every action. I believe this is a new group and trying the same thing.

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#38
post #32

Everyone seems to assume it is the central government. No one has remarked on this, the following somewhat obvious. One of the screenshots has a heading in Malayalam, saying "Bill Vivarangal" - "Bill details" [1]. Was it some government of Kerala service which was breached? Or is it one of several governments? Or was it only the central government with Malayalam as the language set for the interface? If it was an Ind…

https://sakurasamurai.org is newly added domain (suspicious). In India there are some motivated groups try to blame central government for every action. I believe this is a new group and trying the same thing.

I am not a fan of any government or political party in particular. Just pointing out an obvious fact.

But the newly registered domain is not a red flag per se. That's how experienced groups might also go about covering their tracks.

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#39
If they care, as they claim, about the consequences for the indian public, why did they not disclose this less publicly? They think two weeks is a long time but perhaps the Indian government departments concerned don't immediately have the right sorts of people available to fix all these software problems in two weeks?

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#40
Try reporting something to Indian CERT, its a bureaucratic chore. I tried reporting multiple, still open issues but nothing happened. One exposed PII data at scale, the other one exposed credentials at a critical sector organization. Now I am not reporting it anymore because no one listens.

The key problem is that cyber in government is still very nascent, and security is an afterthought even in policy.

Post reply on HN