WhatsApp Pay may put Indian digital banking at risk: Experts

Agencies
November 8, 2019

After WhatsApp accounts of 121 Indians were compromised by the Israeli spyware Pegasus, experts have warned that the payment feature the Facebook-owned platform is planning to launch in India may put the digital banking system at risk.

"WhatsApp payment needs to be seen with microscopic eye, primarily because in payment you will be dealing with sensitive personal data and cyber security is going to be an essential building block component for WhatsApp to demonstrate its due diligence," Pavan Duggal, one of the nation's top cyber law experts, told IANS.

The Ministry of Electronics and Information Technology (Meity) has already expressed dissatisfaction over the manner WhatsApp communicated about the compromised accounts.

The piece of NSO Group software called Pegasus allegedly exploited WhatsApp's video calling system by installing the spyware via missed calls to snoop on 1,400 users globally. The devices were compromised with just a WhatsApp video call.

In May, WhatsApp, which has 400 million users in India, urged its 1.5 billion global users to upgrade the app after discovering the vulnerability.

"WhatsApp's recent operations have shown that it's difficult for the government to get information from it. WhatsApp is an intermediary under the Information Technology Act and is mandated to exercise due diligence under the law. But it has failed to do due diligence," Duggal said.

"You should not be in a hurry to grant new licences or permission to WhatsApp without being satisfied with its adherence to cyber-security norms, international best practices and Indian laws," he said.

The Facebook-owned company is learnt to have countered the government charge that it didn't inform it about a privacy breach on the messaging platform. WhatsApp didn't even comply with the data breach notification law in India, Duggal said.

"It (WhatsApp) didn't follow reasonable security practices as mandated in Section 43A of the IT Act, 2000. In fact, it abetted the crime of un-authorised access too. Granting WhatsApp pay licence should be given a second thought by the Reserve Bank of India," said Prashant Mali, cyber lawyer at Bombay High Court.

In light of the recent hack, the government, the RBI and the National Payments Corporation of India (NPCI) is reportedly evaluating the risk of allowing social media apps into the digital payment ecosystem.

"With the government, the RBI and the NPCI planning to evaluate the risks involved in making payments via social media apps and services, the security of the UPI payment infrastructure on WhatsApp Pay has been rendered under a cloud of vulnerability," said Salman Waris, Managing Partner at TechLegis Advocates & Solicitors, a law firm.

The RBI revealed in an affidavit in the Supreme Court earlier that WhatsApp had not complied with the data localisation norms. In an April 2018 circular, the RBI stated that the data of any payment banking system have to physically located in India.

"The history of WhatsApp has shown that it's not cooperative with the government in sharing of information. If financial information is compromised, it will not only have an impact on users, but it can also have an impact on the sovereignty and security of India," Duggal said.

The government must go slow till the time WhatsApp demonstrates compliance to Indian law and showed that the platform was secure, he said.

"Because almost every phone user in India is on WhatsApp, it's all the more important for the government and the RBI to ensure that WhatsApp not only complies with the parametres of cyber security and data localisation norms, but also the IT Act and the rules and regulations thereunder.

"If WhatsApp doesn't comply with the data localisation norms, rules and regulations of the IT Act, then there is no question of granting new permission," Duggal said.

In a statement, a WhatsApp spokesperson said that safety and security of users remains the platform's highest priority.

"In May, our security team caught and stopped a cyber attack designed to send malware to mobile devices. Unable to break end-to-end encryption, this kind of malware abuses vulnerabilities within the underlying operating systems that power our mobile phones," the WhatsApp spokesperson said.

"Technology companies are constantly working to stay ahead of these kind of challenges through updates and patches. The safety and security of our users remains our highest priority, which is why in May we blocked the attack and have taken action in the courts to hold NSO accountable," the statement added.

Facebook filed a lawsuit against Israel's NSO Group last month. According to Facebook, the NSO Group violated laws, including the US Computer Fraud and Abuse Act.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 10,2024

Bengaluru: The Karnataka government has warned that disciplinary action will be taken against those officials who change the land mutation records and serve eviction notices to farmers under the Waqf Act.

In a letter, the Revenue Department Principal Secretary Rajender Kumar Kataria reminded all regional commissioners and deputy commissioners in the districts that Chief Minister Siddaramaiah recently had a meeting following complaints about certain land properties being made in favour of the Karnataka Board of Waqfs.

In the meeting it was decided that all the directions issued previously by any government office or authority to change the mutation records has been withdrawn, the letter said.

It added that all the notices served in the past have also been withdrawn and no action should be taken against the farmers who are cultivating on the said land.

On the directions of the chief minister, the previous letters and the latest reminders served on November 7 to the farmers and land owners have been withdraw, the letter said.

"The officials who served reminder-2 despite the chief minister's direction will face appropriate disciplinary action," Kataria said in his letter.

He said he has been instructed to strictly implement the chief minister's direction.

The fresh direction was issued in poll-bound Karnataka, where bypolls to three crucial assembly segments are due on November 13.

Some farmers in Honwad village in Vijayapura in north Karnataka had alleged last month that they were served eviction notices as the Waqf Board claimed rights over it.

Subsequently, complaints started in pouring in from some other parts of the state.

BJP leader Tejasvi Surya on October 25 alleged that Karnataka Waqf Minister B Z Zameer Ahmed Khan directed the deputy commissioners and revenue officials to register lands in favour of the Waqf Board within 15 days, which resulted in confusion.

On Surya's request, the Chairman of the Joint Committee of Parliament on the Waqf (Amendment) Bill, Jagdambika Pal visited Karnataka on November 7 and met farmers in Hubballi, Vijayapura and Belagavi districts who had alleged that their lands were marked as Waqf properties.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 14,2024

srirang.jpg

Bengaluru: The Prime Minister Narendra Modi led union government has requested the Karnataka High Court to direct the Mandya district administration and the state government to clear a madrasa operating within the premises of the historic Jama Masjid in Srirangapatna.

The Waqf Board, opposing this move, has claimed the mosque as its property and defended the right to conduct madrasa activities there.

The matter was brought before a division bench headed by Chief Justice N V Anjaria following a public interest litigation filed by a person named Abhishek Gowda from Kabbalu village in Kanakapura taluk. The petition alleged “unauthorised madrasa activities” within the mosque.

Representing the Central government, Additional Solicitor General of India for High Court of Karnataka, K Arvind Kamath argued that the Jama Masjid was designated as a protected monument in 1951, yet unauthorised madrasa operations continue there.

He noted that concerns over potential law and order issues have so far prevented any intervention. Kamath urged the court to direct the Mandya district administration to take action and vacate the madrasa from the mosque.

In defence, lawyers for the state government and the Waqf Board contested this request, stating that the Waqf Board had been recognised as the owner of the property since 1963 and, thus, conducting madrasa activities there is lawful.

After hearing both sides, the bench adjourned the case for further arguments, scheduling the next hearing for November 20.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 17,2024

hizbullah.jpg

An Israeli airstrike on the office of Syria’s Baath party in Lebanon’s capital Beirut has killed the Lebanese resistance movement Hezbollah's Media Relations Officer, Mohammad Afif, reports say.

Lebanon's National News Agency (NNA) reported that the Israeli raid struck the Ba'ath party’s building in central Beirut district of Ras Al-Naba'a on Sunday, adding that the strike was an attempt to assassinate the leader of the resistance media front.

According to Baath Secretary-General Ali Hijazi, Afif was having a meeting in the Baath Party headquarters when Israel carried out the attack.

"Afif did not fight with weapons and did not lead a military unit in Hezbollah. Rather, he led a media unit," he said.

Reuters, Sky News, Al Jazeera and a number of Henrew-language media reported that Afif was killed in the Israeli strike.

However, Hezbollah has not yet confirmed Afif’s death or whether he was present at the site or not.

Earlier, the Lebanese Health Ministry said at least one person was killed and three others injured after an Israeli strike targeted a central district in Beirut.

Lebanon's al-Mayadeen television network reported that five people were killed in the attack.

The latest development came after Afif said Hezbollah was behind the Caesarea operation and targeting Netanyahu’s home during a speech at the Ghobeiry area in the southern suburbs of Beirut on October 22.

This was the second assassination attempt on Afif in the last two months, after he survived an attack on the Hezbollah media relations office several weeks ago.

Israel launched a ground assault and massive air campaign against Lebanon in late September after a year of exchanging fire across the Lebanese border in parallel with the Gaza war.

At least 3,287 people have been killed in Israeli strikes in Lebanon over the past year, with the vast majority in the past seven weeks. Another 14,222 have been wounded, mostly women and children.

In response to the ongoing aggression, the Lebanese resistance movement Hezbollah has been staging hundreds of retaliatory strikes against the occupied Palestinian territories and the Israeli forces trying to advance on southern Lebanese areas.

The movement has vowed to sustain its strikes until the regime ends the escalation.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.