WhatsApp Pay may put Indian digital banking at risk: Experts

Agencies
November 8, 2019

After WhatsApp accounts of 121 Indians were compromised by the Israeli spyware Pegasus, experts have warned that the payment feature the Facebook-owned platform is planning to launch in India may put the digital banking system at risk.

"WhatsApp payment needs to be seen with microscopic eye, primarily because in payment you will be dealing with sensitive personal data and cyber security is going to be an essential building block component for WhatsApp to demonstrate its due diligence," Pavan Duggal, one of the nation's top cyber law experts, told IANS.

The Ministry of Electronics and Information Technology (Meity) has already expressed dissatisfaction over the manner WhatsApp communicated about the compromised accounts.

The piece of NSO Group software called Pegasus allegedly exploited WhatsApp's video calling system by installing the spyware via missed calls to snoop on 1,400 users globally. The devices were compromised with just a WhatsApp video call.

In May, WhatsApp, which has 400 million users in India, urged its 1.5 billion global users to upgrade the app after discovering the vulnerability.

"WhatsApp's recent operations have shown that it's difficult for the government to get information from it. WhatsApp is an intermediary under the Information Technology Act and is mandated to exercise due diligence under the law. But it has failed to do due diligence," Duggal said.

"You should not be in a hurry to grant new licences or permission to WhatsApp without being satisfied with its adherence to cyber-security norms, international best practices and Indian laws," he said.

The Facebook-owned company is learnt to have countered the government charge that it didn't inform it about a privacy breach on the messaging platform. WhatsApp didn't even comply with the data breach notification law in India, Duggal said.

"It (WhatsApp) didn't follow reasonable security practices as mandated in Section 43A of the IT Act, 2000. In fact, it abetted the crime of un-authorised access too. Granting WhatsApp pay licence should be given a second thought by the Reserve Bank of India," said Prashant Mali, cyber lawyer at Bombay High Court.

In light of the recent hack, the government, the RBI and the National Payments Corporation of India (NPCI) is reportedly evaluating the risk of allowing social media apps into the digital payment ecosystem.

"With the government, the RBI and the NPCI planning to evaluate the risks involved in making payments via social media apps and services, the security of the UPI payment infrastructure on WhatsApp Pay has been rendered under a cloud of vulnerability," said Salman Waris, Managing Partner at TechLegis Advocates & Solicitors, a law firm.

The RBI revealed in an affidavit in the Supreme Court earlier that WhatsApp had not complied with the data localisation norms. In an April 2018 circular, the RBI stated that the data of any payment banking system have to physically located in India.

"The history of WhatsApp has shown that it's not cooperative with the government in sharing of information. If financial information is compromised, it will not only have an impact on users, but it can also have an impact on the sovereignty and security of India," Duggal said.

The government must go slow till the time WhatsApp demonstrates compliance to Indian law and showed that the platform was secure, he said.

"Because almost every phone user in India is on WhatsApp, it's all the more important for the government and the RBI to ensure that WhatsApp not only complies with the parametres of cyber security and data localisation norms, but also the IT Act and the rules and regulations thereunder.

"If WhatsApp doesn't comply with the data localisation norms, rules and regulations of the IT Act, then there is no question of granting new permission," Duggal said.

In a statement, a WhatsApp spokesperson said that safety and security of users remains the platform's highest priority.

"In May, our security team caught and stopped a cyber attack designed to send malware to mobile devices. Unable to break end-to-end encryption, this kind of malware abuses vulnerabilities within the underlying operating systems that power our mobile phones," the WhatsApp spokesperson said.

"Technology companies are constantly working to stay ahead of these kind of challenges through updates and patches. The safety and security of our users remains our highest priority, which is why in May we blocked the attack and have taken action in the courts to hold NSO accountable," the statement added.

Facebook filed a lawsuit against Israel's NSO Group last month. According to Facebook, the NSO Group violated laws, including the US Computer Fraud and Abuse Act.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
February 14,2020

Lucknow, Feb 14: Uttar Pradesh doctor Kafeel Khan was on Friday booked under the National Security Act (NSA) over his alleged anti-CAA speech at Aligarh Muslim University on December 12, 2019.

The Uttar Pradesh slapped NSA on Kafeel Khan on Friday even as the doctor waited to be released from jail despite being granted bail on Monday in connection with his alleged inflammatory speech.

SP Crime Dr Arvind said that there were sufficient grounds to book the doctor under NSA.

The suspended pediatrician, Kafeel Khan, was arrested for allegedly delivering a controversial speech during Anti-CAA protests on December 12 at the Aligarh Muslim University or AMU. While he was granted bail on Monday, his family members claimed on Thursday that he was yet to be released.

Dr Kafeel Khan's brother Adeel Ahmed Khan had issued a statement saying that despite being granted bail Mathura jail authorities had not honoured the court's order.

Dr Kafeel Khan was arrested by the UP Special Task Force from Mumbai on January 29 for participating anti-CAA protest at AMU. A case was registered against him at the Civil Lines police station here for promoting enmity between different religions.

After his arrest in Mumbai, Dr Khan was brought to Aligarh, from where he was shifted to the district jail in neighbouring Mathura.

According to police, this was done as a precautionary measure in view of the anti-CAA protests on the AMU campus and at the Eidgah grounds in the old city. Police had said that the Dr Khan's presence in the Aligarh jail could have aggravated the law and order situation in the city.

The doctor was earlier arrested for his alleged role in the death of over 60 children in one week at the BRD Medical College in Gorakhpur in August 2017. Short supply of oxygen at the children's ward was blamed at that time for the deaths.

About two years later, a state government probe cleared Khan of all major charges, prompting him to seek an apology from the Yogi Adityanath government.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
January 19,2020

New Delhi, Jan 19: Reacting to a tweet by ace lawyer Indira Jaising urging her to forgive the four men on death row for brutally raping that finally took her life, Nirbhaya's mother said on Saturday: "Even if God asks me, I won't forgive them."

Speaking to news agency, over the phone, the mother who had been fighting for seven long years to send her daughter's killers to the gallows, said, "...even if god comes and asks me to forgive them, I will not. People like these (Jaising) are a blot on the society."

Commenting on Jaising's tweet, she said: "Who is she to tell or suggest to me to forgive them. What relation does she have with me. I have nothing to do with such people. She can be a relative of those (the convicts) that she is having a soft corner for."

"She is an insult to women. She is running a business in the name of human rights. She is a veteran, she should give a message to the society. But she instead will go against her own kind," she added.

Earlier in the day, Jaising had requested Nirbhaya's mother to follow the example of Congress president Sonia Gandhi, who had moved for the clemency of a woman, Nalini Murugan convicted for the assassination of her husband and former Prime Minister Rajiv Gandhi.

"While I fully identify with the pain of Nirbhaya's mother I urge her to follow the example of Sonia Gandhi who forgave Nalini and said she didn't want the death penalty for her. We are with you but against death penalty," Jaising tweeted on Friday.

A Delhi Court on Friday issued fresh death warrants against the four convicts -- Akshay, Pawan, Mukesh and Vinay in the Nirbhaya gang rape and murder case.

Additional Sessions Judge (ASJ) Satish Kumar Arora fixed 1 February as the date of execution of the four death row convicts. They will be hanged at 6am.

The move came after the prosecution moved an application seeking issuance of fresh death warrants following the rejection of the mercy plea of one of the convicts Mukesh by President Ram Nath Kovind.

The 23-year-old victim was brutally gang-raped and tortured on December 16, 2012, which later led to her death.

All the six accused were arrested and charged with sexual assault and murder. One of the accused was a minor and appeared before a juvenile justice court, while another accused committed suicide in Tihar Jail.

Four of the convicts were sentenced to death by a trial court in September 2013, and the verdict was confirmed by the Delhi High Court in March 2014 and upheld by the Supreme Court in May 2017, which also dismissed their review petitions.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
June 15,2020

Sitamarhi, Jun 15: Eyewitness accounts from locals in Bihar's Sitamarhi district recount the brutality and intimidation by Nepal's security personnel who on June 12 had resorted to unprovoked firing on a group of people at the international border, which left one Indian dead and two others injured.

"18-20 shots were fired for over one hour and everyone is in shock even now," said Nitish Kumar, a resident of Jankinagar recalling the incident that took place early on Friday morning.

Nepal's Armed Police Force (APF) opened fire at the Lalbandi-Jankinagar border in which three men - Vikesh Yadav, Umesh Ram and Uday Thakur - suffered gunshot injuries. Vikash Yadav succumbed to his injuries on Friday itself.

Another person Lagan Kishore, who was at the border with his family to meet his daughter-in-law, a Nepali national and her family, said he was detained by the APF personnel who dragged him to the other side of the border.

Lagan Kishore said that the Nepali personnel abused and hit him with rifle butts and even abused his son and later resorted to firing.

Several residents of Jankinagar, who spoke to media, termed the incident as "unfortunate and shocking".

Nitish Kumar recalled: "A family was here to meet their in-laws (Nepali nationals). The daughter-in-law was talking to her family while her husband and her father-in-law sat a little distance away. Suddenly I saw Nepali personnel abusing her husband who complained about it to his father. All of a sudden the Nepali forces started thrashing them and then opened fire. They also took the father into custody."

"We were all shocked. I could hear about 18-20 gunshots fired over a period of one hour," Kumar said.

Another local, Ajit Kumar, said he was perplexed with the behaviour of the Nepali Police.

"There used to be no problems earlier. We don't understand what happened to the Nepal Police that day. The firing is unfortunate. If this continues, how will people in the border area live?" he questioned.

Ajit Kumar stated that such an incident has taken place for the first time. "People from here go to work in fields in Nepal and their people come to work in our fields. Such a thing has happened for the first time. About 80 per cent of our people are married to Nepalis," he said.

Many people who live in the adjoining districts of Bihar, which shares over 600 kilometres of border with Nepal, have relatives on either side of the border.

Meanwhile, Nepali police have claimed that Lagan Kishore, who was taken into custody following the firing by APF and handed over to Indian Security Forces at no man's land on June 13, was detained for trying to snatch a weapon from one of their personnel during an altercation.

However, both Kishore and his family have denied the claims and said he was "dragged" across the border and was beaten.

Kishore said that during the firing he had rushed towards the Indian side but Nepalese personnel hit him with rifle butt and took him to Nepal's Sangrampur. He was also asked to confess that he was taken into custody from the Nepali side.

"We ran to return to India when they started firing, but they dragged me from the Indian side, hit me with a rifle butt and took me to Nepal's Sangrampur. They told me to confess that I was brought there from Nepal. I told them you can kill me but I was brought there from India," said Kishore.

Kishore's son also said that Nepali personnel started abusing them and hit him and his father.

Speaking to ANI, Kishore's son said, "We went to meet my brother-in-law. Security personnel started abusing me but I could not understand their language. However, my brother's wife asked them to not abuse. After that, they came to the Indian side and hit me. I told my father about the incident and he confronted them."

"They started beating him and called fellow personnel who started firing and dragged my father from the Indian side, hit him with a rifle butt and took him to Nepal''s Sangrampur," he said.

Relations have become strained between India and Nepal after the latter released a map showing parts of Indian Territory-Lipulekh, Kalapani and Limpiyadhura as its own.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.