WhatsApp Pay may put Indian digital banking at risk: Experts

Agencies
November 8, 2019

After WhatsApp accounts of 121 Indians were compromised by the Israeli spyware Pegasus, experts have warned that the payment feature the Facebook-owned platform is planning to launch in India may put the digital banking system at risk.

"WhatsApp payment needs to be seen with microscopic eye, primarily because in payment you will be dealing with sensitive personal data and cyber security is going to be an essential building block component for WhatsApp to demonstrate its due diligence," Pavan Duggal, one of the nation's top cyber law experts, told IANS.

The Ministry of Electronics and Information Technology (Meity) has already expressed dissatisfaction over the manner WhatsApp communicated about the compromised accounts.

The piece of NSO Group software called Pegasus allegedly exploited WhatsApp's video calling system by installing the spyware via missed calls to snoop on 1,400 users globally. The devices were compromised with just a WhatsApp video call.

In May, WhatsApp, which has 400 million users in India, urged its 1.5 billion global users to upgrade the app after discovering the vulnerability.

"WhatsApp's recent operations have shown that it's difficult for the government to get information from it. WhatsApp is an intermediary under the Information Technology Act and is mandated to exercise due diligence under the law. But it has failed to do due diligence," Duggal said.

"You should not be in a hurry to grant new licences or permission to WhatsApp without being satisfied with its adherence to cyber-security norms, international best practices and Indian laws," he said.

The Facebook-owned company is learnt to have countered the government charge that it didn't inform it about a privacy breach on the messaging platform. WhatsApp didn't even comply with the data breach notification law in India, Duggal said.

"It (WhatsApp) didn't follow reasonable security practices as mandated in Section 43A of the IT Act, 2000. In fact, it abetted the crime of un-authorised access too. Granting WhatsApp pay licence should be given a second thought by the Reserve Bank of India," said Prashant Mali, cyber lawyer at Bombay High Court.

In light of the recent hack, the government, the RBI and the National Payments Corporation of India (NPCI) is reportedly evaluating the risk of allowing social media apps into the digital payment ecosystem.

"With the government, the RBI and the NPCI planning to evaluate the risks involved in making payments via social media apps and services, the security of the UPI payment infrastructure on WhatsApp Pay has been rendered under a cloud of vulnerability," said Salman Waris, Managing Partner at TechLegis Advocates & Solicitors, a law firm.

The RBI revealed in an affidavit in the Supreme Court earlier that WhatsApp had not complied with the data localisation norms. In an April 2018 circular, the RBI stated that the data of any payment banking system have to physically located in India.

"The history of WhatsApp has shown that it's not cooperative with the government in sharing of information. If financial information is compromised, it will not only have an impact on users, but it can also have an impact on the sovereignty and security of India," Duggal said.

The government must go slow till the time WhatsApp demonstrates compliance to Indian law and showed that the platform was secure, he said.

"Because almost every phone user in India is on WhatsApp, it's all the more important for the government and the RBI to ensure that WhatsApp not only complies with the parametres of cyber security and data localisation norms, but also the IT Act and the rules and regulations thereunder.

"If WhatsApp doesn't comply with the data localisation norms, rules and regulations of the IT Act, then there is no question of granting new permission," Duggal said.

In a statement, a WhatsApp spokesperson said that safety and security of users remains the platform's highest priority.

"In May, our security team caught and stopped a cyber attack designed to send malware to mobile devices. Unable to break end-to-end encryption, this kind of malware abuses vulnerabilities within the underlying operating systems that power our mobile phones," the WhatsApp spokesperson said.

"Technology companies are constantly working to stay ahead of these kind of challenges through updates and patches. The safety and security of our users remains our highest priority, which is why in May we blocked the attack and have taken action in the courts to hold NSO accountable," the statement added.

Facebook filed a lawsuit against Israel's NSO Group last month. According to Facebook, the NSO Group violated laws, including the US Computer Fraud and Abuse Act.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
March 13,2020

Bengaluru, Mar 13: In the wake of fresh cases of Covid-19 reported in Karnataka, Infosys Foundation chairperson Sudha Murty has urged the Karnataka government to take steps to shut malls and theatres, saying the coronavirus multiplies in air-conditioned areas.

In a letter to the government, she said preventive measures should be taken to control the spread of coronovirus before it gets worse.

Murty, who also leads the State government-constituted Karnataka Tourism Task Force, said she has discussed the current situation with Chairman and Executive Director of Narayana Health, Devi Prasad Shetty.

She suggested closure of all schools and colleges with immediate effect, malls, theatres and “all air-conditioned areas where the virus multiplies”, and allow only essential services like pharmacy, grocery and petrol bunks.

“It is not scientifically proven that the virus dies in high temperature,” she said pointing to spread of the virus -- despite heat -- in peak summer in Australia and Singapore, which have “summer all 12 months”.

“I request you to vacate one government hospital with at least 500 - 700 beds for this purpose (to deal with coronavirus cases), which requires oxygen lines and pipes,” she said.

“Infosys Foundation, the philanthropic and CSR arm of software major Infosys, would do the civil work and Devi Shetty has agreed to share resources like medical equipment,” she added.

“We would like to work with the government proactively so that we can prevent this as early as possible,” Sudha Murty said.

The total number of confirmed coronavirus positive cases in Karnataka is five, including the 76-year old man from Kalaburagi who died on Tuesday night.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
January 28,2020

Jan 28: China said on Tuesday that 106 people had died from a new coronavirus that is spreading across the country, up from the previous toll of 81.

The number of total confirmed cases in China rose to 4,515 as of Jan. 27, the National Health Commission said in a statement, up from 2,835 reported a day earlier.

The United States warned against travel to China on Monday and Canada issued a more narrow travel warning as the death toll from the spreading coronavirus passed 100, with tens of millions stranded during the biggest holiday of the year and global markets rattled.

Global stocks fell, oil prices hit three-month lows, and China's yuan dipped to its weakest level in 2020 as investors fretted about damage to the world's second-biggest economy from travel bans and the Lunar New Year holiday, which China extended in a bid to keep people at home.

The health commission of China's Hubei province said on Tuesday that 100 people had died from the virus as of Jan. 27, according to an online statement, up from the previous toll of 76, with the number of confirmed cases in the province rose to 2,714.

Other fatalities have been reported elsewhere in China, including the first in Beijing, bringing the deal toll to 106 so far, according to the People's Daily. The state newspaper put the total number of confirmed cases in China at 4,193, though some experts suspect a much higher number.

On Monday, US President Donald Trump offered China whatever help it needed, while the State Department said Americans should "reconsider" visiting all of China due to the virus.

Canada, which has two confirmed cases of the virus and is investigating 19 more potential cases, warned its citizens to avoid travel to China's Hubei province, at the heart of the outbreak.

Authorities in Hubei province are taking increasing flak from the public over their initial response to the virus. Chinese Premier Li Keqiang visited the city of Wuhan, epicentre of the outbreak, to encourage medical workers and promise reinforcements.

Visiting Wuhan in blue protective suit and mask, Li praised medics, said 2,500 more workers would join them in the next two days, and visited the site of a new hospital to be built in days.

The most senior leader to visit Wuhan since the outbreak, Li was shown on state TV leading medical workers in chants of "Wuhan jiayou!" - an exhortation to keep their strength up.

China's ambassador to the United Nations, following a meeting with UN Secretary-General António Guterres on Monday, said "the Chinese government attaches paramount importance to prevention and control of the epidemic, and President Xi Jinping has given important instructions. ...

"China has been working with the international community in the spirit of openness, transparency and scientific coordination," he said.

Guterres said in a statement, "The UN appreciates China's effort, has full confidence in China's ability of controlling the outbreak, and stands ready to provide any support and assistance."

MOUNTING ANGER

On China's heavily censored social media, officials have faced mounting anger over the virus, which is thought to have originated from a market where wildlife was sold illegally.

Some criticised the governor of Hubei province, of which Wuhan is the capital, after he corrected himself twice during a news conference over the number of face masks being produced.

"If he can mess up the data multiple times, no wonder the disease has spread so severely," said one user of the Weibo social media platform.

In rare public self-criticism, Wuhan Mayor Zhou Xianwang said the city's management of the crisis was "not good enough" and indicated he was willing to resign.

The central Chinese city of 11 million people is in virtual lockdown and much of Hubei, home to nearly 60 million people, is under travel curbs.

Elsewhere in China, people from the region faced questioning about their movements. "Hubei people are getting discriminated against," a Wuhan resident complained on Weibo.

Cases linked to people who travelled from Wuhan have been confirmed in a dozen countries, from Japan to the United States, where authorities said they had 110 people under investigation in 26 states. Sri Lanka was the latest to confirm a case.

INVESTORS WORRIED

Investors are worried about the impact. The consensus is that in the short term, economic output will be hit as authorities limit travel and extend the week-long New Year holiday — when millions traditionally travel by rail, road and plane - by three days to limit spread of the virus.

Asian and European shares tumbled, with Japan's Nikkei average sliding 2%, its biggest one-day fall in five months. Demand spiked for safe-haven assets such as the Japanese yen and Treasury notes. European stocks fell more than 2%.

The US S&P 500 closed down nearly 1.6%.

"China is the biggest driver of global growth so this couldn't have started in a worse place," said Alec Young, FTSE Russell's managing director of global markets research.

During the 2002-2003 outbreak of Severe Acute Respiratory Syndrome (SARS), which originated in China and killed nearly 800 people globally, air passenger demand in Asia plunged 45%. The travel industry is more reliant on Chinese travellers now.

Chinese-ruled Hong Kong, which has had eight cases, banned entry to people who had visited Hubei recently.

Some European tour operators cancelled trips to China, while governments around the world worked on repatriating nationals.

Officially known as 2019-nCoV, the newly identified coronavirus can cause pneumonia, but it is still too early to know just how dangerous it is and how easily it spreads.

"What we know about this virus it that transmission occurs through human contact but we are speaking of close contact, i.e. less than a meter," said Jerome Salomon, a senior official with France's health ministry.

"Crossing someone (infected) in the street poses no threat," he said. "The risk is low when you spend a little time near that person and becomes higher when you spend a lot of time near that person."

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
July 18,2020

Days after Twitter accounts of several billionaires were hacked to engineer a crypto scam, Twitter on Saturday said it is embarrassed, disappointed and, more than anything, sorry for what happened with some of its high-profile users as attackers successfully manipulated its employees and used their credentials to access internal systems, including getting through the two-factor protections.

In the first detailed summary of the "social engineering attack" via a crypto scam that hit at least 130 users this week, Twitter said for 45 of those accounts, the attackers were able to initiate a password reset, login to the account and send Tweets.

"We are continuing our forensic review of all of the accounts to confirm all actions that may have been taken. In addition, we believe they may have attempted to sell some of the usernames," the micro-blogging platform said in a statement.

For up to eight of the Twitter accounts involved, the attackers took the additional step of downloading the account's information via "Your Twitter Data" tool.

This is a tool that is meant to provide an account owner with a summary of their Twitter account details and activity.

"We are reaching out directly to any account owner where we know this to be true. None of the eight were verified accounts," said Twitter.

The company said the attackers were not able to view previous account passwords, as those are not stored in plain text or available through the tools used in the attack.

"Attackers were able to view personal information including email addresses and phone numbers, which are displayed to some users of our internal support tools," informed Twitter.

In cases where an account was taken over by the attacker, they may have been able to view additional information, Twitter added, saying its forensic investigation of these activities was still ongoing.

"We are actively working on communicating directly with the account-holders that were impacted".

The company said it will soon restore access for all account owners who may still be locked out as a result of the remediation efforts.

The New York Times reported on Friday that the Twitter crypto scam can be traced back to a group of hackers who congregate online at OGusers.com, a username-swapping community where people buy and sell coveted online handles.

The report said that the Twitter hack is not from Russian, Chinese or North Korean hackers but was done by a group of young people, "one of whom says he lives at home with his mother".

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.