Live data from Hacker News

Indian Government Breached, Massive Amount of Critical Vulnerabilities

johnjhacking.com

61–70 of 74 posts

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#61
post #60
post #29

Earlier quoted context omitted.

Well. Section 47 is a real delight, a diabolical inversion of the principle of locus standi. Increasingly, there are agencies and laws which say that "you cannot take us to court". As though writing it makes it somehow legal. Reminds me of calvinball.

Sovereign Immunity means you can't sue the government unless given permission by a statute anyway.

This has nothing to do with sovereign immunity. It is just an act. Expectedly, it was struck down by the Supreme Court as unconstitutional. It was just a ludicrous thing to try in the first place.

https://www.timesnownews.com/business-economy/economy/articl...

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#63
post #58

Earlier quoted context omitted.

Curious. I don’t have a traditional calculator to hand, but tools like Rust, Python and Wolfram|Alpha are all turning 10e50 into 1e51. https://en.wikipedia.org/wiki/Scientific_notation#Normalized... agrees with my memory that in normalised form the coefficient should be at least one and less than ten.

And the paragraph below the one you linked... https://en.wikipedia.org/wiki/Scientific_notation#Engineerin... is directly showing exactly the mode I'm using :)

Oh, I get it and see what’s happening. Kinda careless of me to miss it. Thanks for pointing it out.

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#64
post #14

So in the process of communicating with the Indian Government to resolve the issues responsibly, they announce on Twitter "We Breached The Indian Government!!!". What is wrong with them?

no/less bounties from gov? researcher wants to show off? 10 year old kid who recently wrote some script and has a lot of over confidence? Who knows. But its a fault of Indian Government too. They hire programmers who are less competent to save budget for salary. And if someone reports some vulnerebility I bet these government police will come after the reporter. And there is no incentives too.

The same thing happens I believe in almost all developing countries, they don't take security that seriously, all contracts related with technology are awarded to the company, that charge the smallest amount of money and has ties with the public officers at the time, when a researcher detects a bug in their software depending on the entity they either sue the researcher or ignore him, until they are exposed by the public media.

Couple months ago the data of all Venezuelan immigrants got breached the government did nothing until the public media started to talk about it.

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#65

This smells a bit off: why is there no detail whatsoever on what exactly they breached? The "Indian Government" (central, state, other?) is a sprawling octopus that employs on the order of 50 million people, and there's a world of difference between breaching the public site of the Department of Fertilizers ( https://fert.nic.in/ ) vs getting into the internal systems of the Ministry of External Affairs. The only clu…

> Update: the leader of the "Sakura Samurai" appears to be 15 years old, which explains a lot. What does it explain? Anyone who is not familiar with the branches of the Indian government could have omitted specific details of which departments were hacked.

It explains that the whole press release/site down to the branding looks like amateur hour: https://sakurasamurai.pro/

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#67
post #14

So in the process of communicating with the Indian Government to resolve the issues responsibly, they announce on Twitter "We Breached The Indian Government!!!". What is wrong with them?

They don’t fear jail for some reason...why?

I think the article covers that exact question (excerpt below)

Sakura Samurai coordinated with the U.S. DoD Vulnerability Disclosure Program (VDP) to assist in facilitating initial conversations of disclosure. John Jackson spoke with DC3’s Program Manager via email and coordinated on a plan of action

&

Roughly 4 days later, after further communication with the DC3, we felt safe to begin our initial reveal of research on the NCIIPC’s RVDP program.

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#68

Earlier quoted context omitted.

> Update: the leader of the "Sakura Samurai" appears to be 15 years old, which explains a lot. What does it explain? Anyone who is not familiar with the branches of the Indian government could have omitted specific details of which departments were hacked.

It explains that the whole press release/site down to the branding looks like amateur hour: https://sakurasamurai.pro/

Looks like every other text file I've seen from hacking groups over the last 25 years, which is the aesthetic they're going for.

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#69

This manner of disclosure seems rather callous and reaching out on twitter to communicate a discovered vuln smacks of attention seeking. The Indian Government sites are a very wide mix with some where there is active consideration of such criticalities and a huge number created by the local enterprising chap who is no longer involved. Its hardly a surprise that lots of sites are vulnerable. Without some info on the s…

Sorry I might've missed it, where did you see NPCI (the payments body) mentioned? The organization mentioned repeatedly in the post is NCIIPC.

Re: Indian Government Breached, Massive Amount of Critical Vulnerabilities

#70
post #41
post #18

Earlier quoted context omitted.

> Why did they published anything about the vulnerabilities before they were absolutely sure all of those has been mitigated? Because various entities tried to exploit that to defer any publicaton, which lead to things never getting fixed. An entity may not want to fix things, but at some point their users / constituents have a right to know so they can take their own protective measures.

> Because various entities tried to exploit that to defer any publicaton, which lead to things never getting fixed. Also understandable. > [...] so they can take their own protective measures. Little can the ordinary citizen do whose data is at risk of exploitation. All responsibility lies on the government because the citizens do not have any other choice, as it seems to me. What protective measure can someone take…

The industry standard seems to be disclosure to the entity followed by a reasonable grace period, at which point the bug is disclosed to the general public (where there's room to quibble in what the definition of "reasonable" there is).

I'm not sure that helping individuals protect themselves is the main goal, though. It is important that entities respond to these issues in a reasonable timeframe, because if a small group of researchers, academics, or whatever can find a bug, then other nations' intelligence agencies or industrial espionage groups can as well.

Realistically, in the case of companies, the best an individual can do is not do business with them. In the case of government agencies in democratic countries, public pressure is the probably the way to go.

Post reply on HN