Naming and Shaming of Rapists

After the gory gang rape in Delhi which has attracted unprecedented national attention, the Government of India which is directly in charge of the security of the National Capital, Delhi has announced that they will start a national database of Rape Convicts in an attempt to “Name and Shame” offenders as a “Deterrence”.

Continue reading

Posted in Cyber Crime | Leave a comment

Hackers hold Australian Health records hostage

A group of Russian hackers are reportedly holding medical records of an Australian Clinic hostage and demanding a ransom of Australian $400 million. The cyber criminals hacked into the server of the clinic and encrypted the records and demanding ransom to release the decryption key.

Report

The incident highlights the risk of neglecting information security in an organizational environment particularly if the organization holds sensitive data.

It appears that the clinic is in a vulnerable state since it does not seem to have an effective backup again a failure of a proper Information Assurance program.

Naavi

Posted in Cyber Crime, Information Assurance, Privacy | Leave a comment

When you pick up a glass of water…

Next time when you pick up a glass of water in some body’s place, be careful, your finger print could be picked out of the glass and used to impersonate you. Social engineering attacks in future may therefore start with an offer of a glass of water or juice since picking up the fingerprint using fevicol and using it for biometric authentication is considered extremely easy.

Samir Kelekar, a security expert in Bangalore highlights the issues involved in Aadhar security which is based on biometrics. Details

Posted in Cyber Crime, Privacy | Leave a comment

Bank fraud of 1.05 crores

In an interesting fraud a Mumbai based cooperative bank found that Rs 1.05 crores was fraudulently transferred out of its account with another public sector bank by fraudulent RTGS transfers. TOI report

The amount has been transferred to 12 different accounts and withdrawn as it happens in all phishing cases.

The incident highlights the security vulnerabilities in the banking system and possible insider involvement besides KYC failures.

I would like to highlight here a suggestion I had made to RBI regarding imposing fines on the erring collecting bankers who failed in their KYC to generate funds for a “E banking Security Guarantee Scheme” by which the victims can be immediately compensated.

In the instant case since the transfers have been through RTGS the average amount transferred per account is close to 10 lakhs.

The incident also highlights how the higher “per transaction limit” increases the risk. It is for this reason I have been advocating that in the case of individuals, per transaction and per day limit of transfer should be kept low to reduce the risk of such frauds though in the instant case since the victim is a Bank, no such limit could have been chosen.

So far we have been fighting the case of individuals vs banks and there have been an unholy alliance between bankers to bully the victim customers into submission and absorb the losses. Judicial authorities such as “Adjudicating Officers in Karnataka, “Cyber Appellate Tribunal” have failed to protect the interests of the people. DIT has failed to keep the cyber judicial system in operating condition and preventing victims from getting any relief.

It would be interesting to see how RBI reacts to this incident where one bank’s interest is pitted against other banks. The action taken in this case would be a good precedent to other cases.

Naavi

Posted in Bank, Cyber Crime | Leave a comment

End of the World..

Year 2012 did not bring the end of the world as predicted by the Mayan Calender. But incidents in Delhi following the brutal rape and assault on a girl and the subsequent developments indicate that the end of the world is in fact near at least for the rule of law in India.

Continue reading

Posted in Cyber Law, Uncategorized | Leave a comment

3.84 lakh Aadhar cards cancelled

UIDAI has reportedly cancelled about 3.84 lakh Aadhar registrations done under “no finger print category” recognizing widespread fraud in the creation of the IDs. Money spent on these registrations in the form of commissions paid by the Government is a dead loss.
This also indicates that there could be wide spread fraudulent registrations in the normal category. A review of the system would be in order. Report

PLEASE NOTE:

This website has been in existence since 1998.  

Older posts before the site switched to word press are available through the link at the top and here below.

OLD POSTS

Posted in Uncategorized | Leave a comment