WhatsApp Pay may put Indian digital banking at risk: Experts

Agencies
November 8, 2019

After WhatsApp accounts of 121 Indians were compromised by the Israeli spyware Pegasus, experts have warned that the payment feature the Facebook-owned platform is planning to launch in India may put the digital banking system at risk.

"WhatsApp payment needs to be seen with microscopic eye, primarily because in payment you will be dealing with sensitive personal data and cyber security is going to be an essential building block component for WhatsApp to demonstrate its due diligence," Pavan Duggal, one of the nation's top cyber law experts, told IANS.

The Ministry of Electronics and Information Technology (Meity) has already expressed dissatisfaction over the manner WhatsApp communicated about the compromised accounts.

The piece of NSO Group software called Pegasus allegedly exploited WhatsApp's video calling system by installing the spyware via missed calls to snoop on 1,400 users globally. The devices were compromised with just a WhatsApp video call.

In May, WhatsApp, which has 400 million users in India, urged its 1.5 billion global users to upgrade the app after discovering the vulnerability.

"WhatsApp's recent operations have shown that it's difficult for the government to get information from it. WhatsApp is an intermediary under the Information Technology Act and is mandated to exercise due diligence under the law. But it has failed to do due diligence," Duggal said.

"You should not be in a hurry to grant new licences or permission to WhatsApp without being satisfied with its adherence to cyber-security norms, international best practices and Indian laws," he said.

The Facebook-owned company is learnt to have countered the government charge that it didn't inform it about a privacy breach on the messaging platform. WhatsApp didn't even comply with the data breach notification law in India, Duggal said.

"It (WhatsApp) didn't follow reasonable security practices as mandated in Section 43A of the IT Act, 2000. In fact, it abetted the crime of un-authorised access too. Granting WhatsApp pay licence should be given a second thought by the Reserve Bank of India," said Prashant Mali, cyber lawyer at Bombay High Court.

In light of the recent hack, the government, the RBI and the National Payments Corporation of India (NPCI) is reportedly evaluating the risk of allowing social media apps into the digital payment ecosystem.

"With the government, the RBI and the NPCI planning to evaluate the risks involved in making payments via social media apps and services, the security of the UPI payment infrastructure on WhatsApp Pay has been rendered under a cloud of vulnerability," said Salman Waris, Managing Partner at TechLegis Advocates & Solicitors, a law firm.

The RBI revealed in an affidavit in the Supreme Court earlier that WhatsApp had not complied with the data localisation norms. In an April 2018 circular, the RBI stated that the data of any payment banking system have to physically located in India.

"The history of WhatsApp has shown that it's not cooperative with the government in sharing of information. If financial information is compromised, it will not only have an impact on users, but it can also have an impact on the sovereignty and security of India," Duggal said.

The government must go slow till the time WhatsApp demonstrates compliance to Indian law and showed that the platform was secure, he said.

"Because almost every phone user in India is on WhatsApp, it's all the more important for the government and the RBI to ensure that WhatsApp not only complies with the parametres of cyber security and data localisation norms, but also the IT Act and the rules and regulations thereunder.

"If WhatsApp doesn't comply with the data localisation norms, rules and regulations of the IT Act, then there is no question of granting new permission," Duggal said.

In a statement, a WhatsApp spokesperson said that safety and security of users remains the platform's highest priority.

"In May, our security team caught and stopped a cyber attack designed to send malware to mobile devices. Unable to break end-to-end encryption, this kind of malware abuses vulnerabilities within the underlying operating systems that power our mobile phones," the WhatsApp spokesperson said.

"Technology companies are constantly working to stay ahead of these kind of challenges through updates and patches. The safety and security of our users remains our highest priority, which is why in May we blocked the attack and have taken action in the courts to hold NSO accountable," the statement added.

Facebook filed a lawsuit against Israel's NSO Group last month. According to Facebook, the NSO Group violated laws, including the US Computer Fraud and Abuse Act.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
March 10,2020

New Delhi, Mar 10: Minutes after Jyotiraditya Scindia submitted his resignation to the party membership to Congress chief Sonia Gandhi, the Congress expelled him for anti-party activities after reports emerged that he had met PM Modi and Amit Shah.

Disgruntled Congress leader Jyotiraditya Scindia met Prime Minister Narendra Modi on Tuesday amid indications that he might join hands with the BJP to topple the Madhya Pradesh government.

Sources said Scindia first met Union Home Minister Amit Shah, and then the two leaders met Modi at the prime minister's residence.

Legislators loyal to Scindia, who has been upset with the Congress leadership with his marginalisation in the affairs of the Madhya Pradesh Congress, are likely to quit the party to reduce the Kamal Nath-led government to a minority.

It is likely to be followed by the Bharatiya Janata Party staking claim to form the government in the state.

The Congress President has approved the expulsion of Jyotiraditya Scindia from the Indian National Congress with immediate effect for "anti-party activities," said KC Venugopal, General Secretary Congress.

No person is, nor will be greater than the party: Congress youth wing chief

Indian Youth Congress (IYC) chief Srinivas B V on Tuesday slammed Jyotiraditya Scindia, who has announced his resignation from the primary membership of the Congress, and thanked party chief Sonia Gandhi for expelling the former Guna MP "who was promoting anti-party activities and factionalism".

"The history of 1857 and 1967 was once again repeated," Srinivas B V said, referring to the 1857 Revolt against East India Company and the role of the Scindia royals back then as well as Vijayaraje Scindia's switch from the Congress to the Jana Sangh in 1967.

"I would like to thank Congress president Sonia Gandhiji for taking the strong steps to expel the leader who was promoting anti-party activities and factionalism," the IYC chief said.

"No person is, nor will be greater than the party," he added.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
March 16,2020

Mar 16: An investigation into Coffee Day Enterprises Ltd., initiated by its board after the death of founder V.G. Siddhartha, is likely to conclude that at least Rs 2,000 crore is missing from its accounts, according to people familiar with the matter.

The months-long probe following the suicide of Siddhartha in July examined the financial transactions of India’s largest coffee chain and its dealings with dozens of private companies owned by the entrepreneur. The draft report, running more than a hundred pages, points to thousands of rupees that have gone missing, said the people, asking not to be named because the details aren’t public. It also details hundreds of transactions between the founder’s listed and personal businesses that were not conducted at arm’s length, they said.

Though the report is in its final stages, the precise details could change before its release, expected as early as this week, the people said. The missing funds could total more than Rs 2500 crore, one person said.

“The investigation report is still a work in progress, and not finalized,” a spokesman for the company said. “The board of directors and the company are unaware of its content at this point of time. Hence it would be premature to speculate on the investigation findings.”

The priority for management and Siddhartha’s family “is to keep the business running in a challenging environment and meet all stakeholder commitments, including 30,000 jobs associated with the group,” the spokesman added.

The disappearance of the 59-year-old founder last year stunned India’s business community. He had last been seen telling his driver he was going for an evening walk along a bridge in southern India; his body was found by local fishermen two days later. A letter delivered to Coffee Day’s board and employees, which appeared to be signed by Siddhartha, described massive debts and complained of pressure from lenders and tax authorities. It claimed he bore sole responsibility for the company’s financial transactions.

The probe began about a month later when the company brought in Ashok Kumar Malhotra, a retired senior official from India’s federal enforcement agency, to investigate. A senior lawyer practicing in India’s top court is assisting, the company said in a regulatory filing at the time.

The publicly traded Coffee Day was supposed to be India’s answer to Starbucks Corp. More than 1,500 of its Café Coffee Day outlets blanketed cities and highways, with affordable options for the country’s aspiring middle classes. The chain’s tagline: “A lot can happen over coffee.”

But the empire has been battered since the founder’s death. Its shares plummeted about 90% and its market value dropped to about $80 million. Trading was suspended in February.

India’s regulators are tracking the situation and may use the company’s final report as part of a deeper dive into its internal affairs, the people said. Coffee Day showed about Rs 2400 crore in cash and cash equivalents on its balance sheet as of March 2019, the most recent figures the company has issued.

After the death of Siddhartha however, the company faced a severe liquidity crunch and had “zero cash in the bank,” according to one of the people. It struggled with day-to-day expenses and paying salaries has been a strain, the person said.

The draft report details personal guarantees by Siddhartha for loans taken by Coffee Day, and his unsecured loans at high interest rates from local money lenders, the people said. It also probes Coffee Day’s defaults to coffee growers and other vendors, they said.

A related issue is that coffee estates owned by Siddhartha and several employees had been used as collateral for bank loans. The report found that valuations for properties were inflated to get the loans, one person said.

Investigators have examined several theories about what happened to the company’s money, including whether Coffee Day was manipulating its finances to show cash and profit and whether Siddhartha was taking cash out of the listed company to pay off a large investor to whom he had guaranteed a return, the person said. From the filings of his listed and private companies, the entrepreneur’s loans had totaled more than Rs 10,000 crore, and he had been squeezed by borrowing to repay interest on earlier loans, the person said.

In the letter purportedly from Siddhartha, the entrepreneur said he had tried his best but failed as an entrepreneur. “I am solely responsible for all mistakes,” the letter read. “Every financial transaction is my responsibility. My team, auditors and senior management are totally unaware of all my transactions. The law should hold me and only me accountable, as I have withheld this information from everybody including my family.”

As the report nears release, Coffee Day is finalizing a deal with Blackstone Group Inc. for real estate assets. A large tranche of the payment is due in about a week, one person said.

Coffee Day said it is working to reduce its debt load by divesting non-core enterprises.

“The aim is to save employment and preserve this iconic Indian brand,” the spokesman said.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
January 12,2020

Patna, Jan 12: Prashant Kishor, national vice-president of the Janata Dal (United), a key ally of the BJP-led NDA, has thanked Congress general secretary Priyanka Gandhi and former AICC chief Rahul Gandhi for their support in opposing CAA (Citizenship Amendment Act) and NRC (National Register of Citizens).

Perceived as one of the closest associates of Bihar Chief Minister Nitish Kumar, who is also the party’s national president, PK (as Prashant is fondly called) also assured the two top Congress leaders that the contentious legislation would not be implemented in Bihar where JD (U) is ruling the State with the support of the BJP.

“I join my voice with all to thank #Congress leadership for their formal and unequivocal rejection of #CAA_NRC. Both @rahulgandhi and @priyankagandhi deserve special thanks for their efforts on this count….also would like to reassure to all – CAA/NRC won’t be implemented in Bihar,” tweeted PK on Sunday.

The development assumes significance as a day back, the Congress Working Committee (CWC) meeting, chaired by Sonia Gandhi, had strongly opposed CAA/NRC/NPR as it was aimed at “sinister design of the present regime to divide Indian people into religious lines.”

The latest tweet by PK is also being seen as a rebuff to the BJP, which again recently reiterated that “the BJP should project its own chief ministerial candidate during the 2020 Bihar Assembly elections.”

The JD (U) had taken umbrage over such provocative statements by BJP leaders and asked the saffron camp to rein in its ‘loudmouths’ as BJP chief Amit Shah had already made it clear that the next Assembly polls in Bihar would be fought under the leadership of Nitish.

Of late, PK has been quite vocal about his opposition to the Centre’s policies, particularly the contentious issues of NRC and CAA. Besides, he even dubbed senior BJP leader Sushil Modi as the man who became Bihar’s Deputy Chief Minister due to ‘circumstances’ as the BJP was decisively decimated during the 2015 Assembly elections.

Nitish never reprimanded PK for his jibe against Modi, thereby giving rise to speculations whether Bihar was again heading for a political churning ahead of Assembly polls slated for October this year.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.