🚨 Important data security story on
@livemint P1 today. TL;DR: if you get a call where someone offers you unclaimed money, be careful—this could well be from a government platform that left your precise address exposed for years.
Here’s what happened:
✒️ Last weekend,
@logicbomb_1 found a key flaw in
@RBI’s unclaimed deposits platform that could very well have exposed your exact address to absolutely anyone.
✒️ On Sunday, Avinash wrote to
@IndianCERT highlighting this flaw. Prima facie, it appears to be a design flaw, than a data breach.
✒️ The data exposure report, however, got no response from the nodal cyber security agency. Since then, over the past 72 hours, Avinash and I have emailed all relevant authorities at Cert-In,
@GoI_MeitY and the RBI, bringing this matter and its importance to their notice. Today, we went live with the story.
✒️ Why is this important? The ability to access a person’s precise residential address can easily help a scammer with intent trace down other stolen identification details as well. Eventually, it would only be a matter of time before an unknown person with malice knows everything about you: where you stay, your related family names, and even that you have an unclaimed bank account lying dormant for a decade or more. This is how digital arrests were born.
This is why this story was important to tell. Read the story online here:
livemint.com/industry/bankin…, and please spread the word so that people are aware of such a flaw.