Live data from Hacker News

Indian Government Breached, Massive Amount of Critical Vulnerabilities

johnjhacking.com

41–50 of 74 posts

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#41
post #18
post #11

> Governments have an obligation to protect the private data of its employees and citizens. In addition, the exposure of proprietary government data can be used for great means of manipulation and for other destructive purposes. Understandable. > While the NCIIPC operates a Responsible Vulnerability Disclosure Program, the recklessness and avoidance of communication represents the complete opposite of a responsible p…

> Why did they published anything about the vulnerabilities before they were absolutely sure all of those has been mitigated? Because various entities tried to exploit that to defer any publicaton, which lead to things never getting fixed. An entity may not want to fix things, but at some point their users / constituents have a right to know so they can take their own protective measures.

> Because various entities tried to exploit that to defer any publicaton, which lead to things never getting fixed.

Also understandable.

> [...] so they can take their own protective measures.

Little can the ordinary citizen do whose data is at risk of exploitation. All responsibility lies on the government because the citizens do not have any other choice, as it seems to me. What protective measure can someone take who is vulnerable?

With a thorough reading of the article, it is clear that the hackers are aware of what they are doing:

> Once threat actors catch wind of major vulnerabilities against an organization they begin poking on their own, looking for more vectors of attack.

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#42
post #23

This smells a bit off: why is there no detail whatsoever on what exactly they breached? The "Indian Government" (central, state, other?) is a sprawling octopus that employs on the order of 50 million people, and there's a world of difference between breaching the public site of the Department of Fertilizers ( https://fert.nic.in/ ) vs getting into the internal systems of the Ministry of External Affairs. The only clu…

I think that Twitter user is just a member. One of the founders is https://twitter.com/johnjhacking who proclaims to have a full time job and be a disabled vet.

whoever is behind it I find it hard to blame them. As they write on their blog:

>> Governments have an obligation to protect the private data of its employees and citizens. In addition, the exposure of proprietary government data can be used for great means of manipulation and for other destructive purposes. While the NCIIPC operates a Responsible Vulnerability Disclosure Program, the recklessness and avoidance of communication represents the complete opposite of a responsible program. https://johnjhacking.com/blog/indian-government-breached-mas...

Enough has been said by people inside and outside of India about UIDAI / Aadahaar[0][1] and it's many horrible side-effects and risks it creates. This situation that has been created years ago after loud warnings of researchers and citizens who have meanwhile been silenced by the Modi government (who are the real culprits here).

India has done this to its people already years ago, therefore breaches here today are mere symptoms of incompetence (not the cause).

[0] Aadhaar: 'Leak' in world's biggest database worries Indians https://www.bbc.com/news/world-asia-india-42575443

[1] French Hacker transcends Aadhaar UIDAI helpline number to millions of Android phones in India https://www.cybersecurity-insiders.com/french-hacker-transce...

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#43

At this point, wouldn't it be easier to design systems as completely open, with all user data exposed? Then for actual interaction purposes, to rely on biological verification? eg. widespread retina and fingerprint scanning. As a side effect this would somewhat limit tax evasion - if all tax returns and income were public, as in countries like Norway.

> ...eg. widespread retina and fingerprint scanning...

This previous HN discussion [1] about a "Falsehoods programmers believe about Biometrics" article might be relevant. Careful, here be dragons, edge cases still abound the unwary implementer.

[1] https://news.ycombinator.com/item?id=25700026

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#44
post #33
post #32

Everyone seems to assume it is the central government. No one has remarked on this, the following somewhat obvious. One of the screenshots has a heading in Malayalam, saying "Bill Vivarangal" - "Bill details" [1]. Was it some government of Kerala service which was breached? Or is it one of several governments? Or was it only the central government with Malayalam as the language set for the interface? If it was an Ind…

Tamil kooda irukalam

Don't just go by the transliteration in parent comment. If you see the screenshot, it's clearly Malayalam.

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#45

This smells a bit off: why is there no detail whatsoever on what exactly they breached? The "Indian Government" (central, state, other?) is a sprawling octopus that employs on the order of 50 million people, and there's a world of difference between breaching the public site of the Department of Fertilizers ( https://fert.nic.in/ ) vs getting into the internal systems of the Ministry of External Affairs. The only clu…

> Unfortunately, what seemed like a done deal turned out to be quite the unprofessional ride. Any organization knows that fixing breach-worthy vulnerabilities is extremely time sensitive. Once threat actors catch wind of major vulnerabilities against an organization they begin poking on their own, looking for more vectors of attack.

Do you expect them to tell everybody exactly which systems are vulnerable? What is it you're suggesting they do?

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#47
post #15

Earlier quoted context omitted.

Crore is equivalent to 10e6. In this case, that would evaluate to 650'000'000 INR.

> 10e6 Under scientific notation, you should strongly prefer to write 1e7. 10e6 is just begging for people to interpret it as 10⁶ rather than 10×10⁶ (10⁷).

But that's the definition, and every calculator's "engineering" mode shows it exactly like that, too. And usually you learn in middle school how to interpret that.

Here’s a photo with the calculator I used in middle school, showing exactly the specified number:

https://i.k8r.eu/qOUpgg.png

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#48

Earlier quoted context omitted.

"Indian government" means central government, not state. Just like "US government" always refers to the federal government.

In Indian usage, yes, but this appears to have been written by a bunch of American teenagers.

premature attribution is as much a fallacy and problem as ignoring risks that lead to a breach in the first place.

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#49

Earlier quoted context omitted.

"Indian government" means central government, not state. Just like "US government" always refers to the federal government.

In Indian usage, yes, but this appears to have been written by a bunch of American teenagers.

Well, we can't expect every hacker to know what they're looking at...

> Game List

>> GLOBAL THERMONUCLEAR WAR

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#50

This smells a bit off: why is there no detail whatsoever on what exactly they breached? The "Indian Government" (central, state, other?) is a sprawling octopus that employs on the order of 50 million people, and there's a world of difference between breaching the public site of the Department of Fertilizers ( https://fert.nic.in/ ) vs getting into the internal systems of the Ministry of External Affairs. The only clu…

> Unfortunately, what seemed like a done deal turned out to be quite the unprofessional ride. Any organization knows that fixing breach-worthy vulnerabilities is extremely time sensitive. Once threat actors catch wind of major vulnerabilities against an organization they begin poking on their own, looking for more vectors of attack. Do you expect them to tell everybody exactly which systems are vulnerable? What is it…

I believe they are suggesting that the systems be fixed in a timely manner.

That was my read of the article.

Post reply on HN