WhatsApp Pay may put Indian digital banking at risk: Experts

Agencies
November 8, 2019

After WhatsApp accounts of 121 Indians were compromised by the Israeli spyware Pegasus, experts have warned that the payment feature the Facebook-owned platform is planning to launch in India may put the digital banking system at risk.

"WhatsApp payment needs to be seen with microscopic eye, primarily because in payment you will be dealing with sensitive personal data and cyber security is going to be an essential building block component for WhatsApp to demonstrate its due diligence," Pavan Duggal, one of the nation's top cyber law experts, told IANS.

The Ministry of Electronics and Information Technology (Meity) has already expressed dissatisfaction over the manner WhatsApp communicated about the compromised accounts.

The piece of NSO Group software called Pegasus allegedly exploited WhatsApp's video calling system by installing the spyware via missed calls to snoop on 1,400 users globally. The devices were compromised with just a WhatsApp video call.

In May, WhatsApp, which has 400 million users in India, urged its 1.5 billion global users to upgrade the app after discovering the vulnerability.

"WhatsApp's recent operations have shown that it's difficult for the government to get information from it. WhatsApp is an intermediary under the Information Technology Act and is mandated to exercise due diligence under the law. But it has failed to do due diligence," Duggal said.

"You should not be in a hurry to grant new licences or permission to WhatsApp without being satisfied with its adherence to cyber-security norms, international best practices and Indian laws," he said.

The Facebook-owned company is learnt to have countered the government charge that it didn't inform it about a privacy breach on the messaging platform. WhatsApp didn't even comply with the data breach notification law in India, Duggal said.

"It (WhatsApp) didn't follow reasonable security practices as mandated in Section 43A of the IT Act, 2000. In fact, it abetted the crime of un-authorised access too. Granting WhatsApp pay licence should be given a second thought by the Reserve Bank of India," said Prashant Mali, cyber lawyer at Bombay High Court.

In light of the recent hack, the government, the RBI and the National Payments Corporation of India (NPCI) is reportedly evaluating the risk of allowing social media apps into the digital payment ecosystem.

"With the government, the RBI and the NPCI planning to evaluate the risks involved in making payments via social media apps and services, the security of the UPI payment infrastructure on WhatsApp Pay has been rendered under a cloud of vulnerability," said Salman Waris, Managing Partner at TechLegis Advocates & Solicitors, a law firm.

The RBI revealed in an affidavit in the Supreme Court earlier that WhatsApp had not complied with the data localisation norms. In an April 2018 circular, the RBI stated that the data of any payment banking system have to physically located in India.

"The history of WhatsApp has shown that it's not cooperative with the government in sharing of information. If financial information is compromised, it will not only have an impact on users, but it can also have an impact on the sovereignty and security of India," Duggal said.

The government must go slow till the time WhatsApp demonstrates compliance to Indian law and showed that the platform was secure, he said.

"Because almost every phone user in India is on WhatsApp, it's all the more important for the government and the RBI to ensure that WhatsApp not only complies with the parametres of cyber security and data localisation norms, but also the IT Act and the rules and regulations thereunder.

"If WhatsApp doesn't comply with the data localisation norms, rules and regulations of the IT Act, then there is no question of granting new permission," Duggal said.

In a statement, a WhatsApp spokesperson said that safety and security of users remains the platform's highest priority.

"In May, our security team caught and stopped a cyber attack designed to send malware to mobile devices. Unable to break end-to-end encryption, this kind of malware abuses vulnerabilities within the underlying operating systems that power our mobile phones," the WhatsApp spokesperson said.

"Technology companies are constantly working to stay ahead of these kind of challenges through updates and patches. The safety and security of our users remains our highest priority, which is why in May we blocked the attack and have taken action in the courts to hold NSO accountable," the statement added.

Facebook filed a lawsuit against Israel's NSO Group last month. According to Facebook, the NSO Group violated laws, including the US Computer Fraud and Abuse Act.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
April 26,2024

katee.jpg

Mangaluru/Udupi: The Dakshina Kannada and Udupi-Chikmagalur Lok Sabha constituencies recorded a tentative voter turnout of 77.4% and 76.1% respectively until 6 pm on Friday. In the 2019 polls, Dakshina Kannada recorded 77.9%, while Udupi recorded a 75.8% voter turnout.

The DK Lok Sabha constituency recorded a poll percentage of 71.8% at 5 pm. Among the constituencies, Sullia recorded a maximum of 78.4%, followed by Belthangady at 75.6%, Puttur at 75.2%, Bantwal at 73.7%, Mangalore at 73.5%, Mangalore City North at 69.8%, and Mangalore City South at 61.8%.

Urban apathy continued, with Mangalore City South recording the lowest polling percentage.

Meanwhile, Banjarumale, a remote village in Belthangady taluk, recorded 100% polling with all 111 voters showing up two hours before polling ended at 6pm.

Another interior polling station at Elaneer in the same taluk recorded 82% polling at 4 pm. The booth has 471 voters. The district has a total of 18,18,127 voters, with 9,30,928 females, 8,87,122 men, and 77 transgender individuals.

A good number of people turned out to vote during the early hours. Voters are bearing the scorching sun while stepping out to exercise their franchise as heat wave is sweeping through the state. 

The polling process remained largely peaceful, with long queues observed at polling stations from 7 am onwards in several polling stations. However, technical glitches caused delays at a polling station in Karopady, and at St. Xavier School Bejai, where polling was reportedly delayed by nearly two hours.

Polling staff at a booth near the Mulki police station mistakenly marked the wrong finger with ink during voting. They reportedly applied ink to the index finger of the right hand. According to sources, at least 50 individuals had their index finger of the right hand inked. Deputy Commissioner Mullai Mulihan clarified, "The matter was promptly addressed by the sector office. This error affected 8-9 voters"

A total of 18.18 lakh voters in the Dakshina Kannada Lok Sabha constituency and 15.85 lakh in Udupi-Chikmagalur hold the power to determine the fate of candidates competing for their respective segments. The polling process is currently underway across 1,876 booths in Dakshina Kannada and 1,842 polling stations in the Udupi-Chikmagalur segment.

In Dakshina Kannada, a closely contested battle is anticipated between Captain Brijesh Chowta representing the BJP and Padmaraj R Poojary from the Congress. Meanwhile, in the Udupi-Chikmagalur constituency, Kota Shrinivas Poojary of the BJP and K Jayaprakash Hegde of the Congress are the prominent contenders.

DKUdup.jpg

udupi.jpg

DKvote4.jpg

DKvote5.jpg

DKvote3.jpg

DKvote2.jpg

DKvote1.jpg

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
May 4,2024

New Delhi: Congress leader Rahul Gandhi has written to Karnataka Chief Minister Siddaramaiah, urging him to extend all possible help to the victims of JD(S) leader Prajwal Revanna's alleged sexual abuse.

In a letter to Siddaramaiah, Gandhi condemned the actions of Revanna, an MP from Hassan in Karnataka, and accused him of enjoying immunity with the blessings of Prime Minister Narendra Modi and Union Home Minister Amit Shah.

In a veiled attack on Modi, the Congress leader said he has never come across a senior public representative who has constantly chosen silence in the face of untold violence against women.

"I request you to kindly extend all possible support to the victims," Gandhi said in his letter to the Karnataka chief minister.

"They deserve our compassion and solidarity as they fight their battle for justice. We have a collective duty to ensure that all parties responsible for these heinous crimes are brought to book," he added.

Describing the incidents as "horrific sexual violence" unleashed by the incumbent Member of Parliament, Gandhi alleged that Revanna sexually assaulted and filmed hundreds of women over several years.

"Many who looked up to him as a brother and son were brutalised in the most violent manner and robbed of their dignity. The rape of our mothers and sisters warrants the strictest possible punishment."

"I am deeply shocked to learn that as far back as December 2023, our Home Minister Shri Amit Shah was informed by Shri G Devaraje Gowda about Prajwal Revanna's antecedents, especially his history of sexual violence and the presence of videos filmed by the perpetrator," the former Congress chief said.

He said what is even more shocking is that despite these gruesome allegations being brought to the notice of the seniormost leadership of the ruling Bharatiya Janata Party (BJP) at the Centre, Modi campaigned and canvassed for a "mass rapist".

"Furthermore, the Union government wilfully allowed him to flee India to derail any meaningful investigation. The deeply perverse nature of these crimes and the absolute immunity enjoyed by Prajwal Revanna with the blessings of the Prime Minister and Home Minister deserves the strongest condemnation," Gandhi said.

"In my two decades in public life, I have never come across a senior public representative who has constantly chosen silence in the face of untold violence against women. From our wrestlers in Haryana to our sisters in Manipur, Indian women are bearing the brunt of the Prime Minister's tacit support for such criminals," he alleged.

In this backdrop, Gandhi said the Congress has a moral duty to fight for justice for "our mothers and sisters".

"I understand that the Karnataka government has constituted a Special Investigation Team (SIT) to investigate the grave allegations, and a request has been made to the Prime Minister to cancel Prajwal Revanna's diplomatic passport and get him extradited to India at the earliest," he said.

H D Revanna, the Janata Dal (Secular) MLA from Holenarasipura in Karnataka's Hassan district, is the son of former prime minister and JD(S) patriarch H D Deve Gowda and elder brother of former chief minister H D Kumaraswamy. He is facing allegations of sexually abusing women.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
April 26,2024

evm.jpg

The Supreme Court of India on Friday, April 26, rejected pleas seeking 100% cross-verification of votes cast using EVMs with a Voter Verifiable Paper Audit Trail (VVPAT) and said “blindly distrusting” any aspect of the system can breed unwarranted scepticism.

A bench of Justices Sanjiv Khanna and Dipankar Datta delivered two concurring verdicts. It dismissed all the pleas in the matter, including those seeking to go back to ballot papers in elections.

An EVM comprises three units – the ballot unit, the control unit and the VVPAT. All three are embedded with microcontrollers with a burnt memory from the manufacturer. Currently, VVPATs are used in five booths per assembly constituency.

EVM VVPAT case: Supreme Court issues two directives

1.    Justice Khanna directed the Election Commission of India to seal and store units used to load symbols for 45 days after the symbols have been loaded to electronic voting machines in strong rooms.

2.    The Supreme Court also allowed engineers of the EVM manufacturers to verify the microcontroller of the machines after the declaration of the results at the request of candidates who stood second and third. The top court said the request for the verification of the microcontroller can be made within seven days of the declaration of the results after payment of fees.

Option for candidates to seek verification of EVM programmes

•    Candidates who secure second and third position in the results can request for the verification of burnt memory semicontroller in 5% of the EVMs per assembly segment in a Parliamentary constituency. The written request to be made within seven days of the declaration of the results.

•    *On receiving such a written request, the EVMs shall be checked and verified by a team of engineers from the manufacturer of the EVMs.

•    Candidates should identify the EVMs to be checked by a serial number of the polling booth.

•    Candidates and their representatives can be present at the time of the verification.

•    After verification, the district electoral officer should notify the authenticity of the burnt memory.

•    Expenses for the verification process, as notified by the ECI, should be borne by the candidate making the request.
What did the Supreme Court say?

•    "If EVM is found tampered during verification, fees paid by the candidates will be refunded," the bench said.

•    "While maintaining a balanced perspective is crucial in evaluating systems or institutions, blindly distrusting any aspect of the system can breed unwarranted scepticism...," Justice Datta said.

Who filed the petitions?

NGO Association for Democratic Reforms, one of the petitioners, had sought to reverse the poll panel's 2017 decision to replace the transparent glass on VVPAT machines with an opaque glass through which a voter can see the slip only when the light is on for seven seconds.

The petitioners have also sought the court's direction to revert to the old system of ballot papers.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.