India Orders VPN Companies to Collect and Hand Over User Data

  • Thread starter Thread starter minuteman
  • Start date Start date
  • Replies Replies 182
  • Views Views 17,408
I read that PDF document from CERT. Unfortunately there's no way to attach it here. It basically is to trace what they call "cyber security incidents" or "crimes". Oh well, let's see how this pans out. It also means no BTC purchases will be allowed as KYC is compulsory.
 
VPNs will make it mandatory for users from India or just ban Indian users. Either one of them will happen. Besides, it is not difficult to trace payments to VPN Cos made via CC or DC as we all do. I renewed my PIA subs 1-2 months back and its easy-peasy for the Govt to ask CC issuer banks to alert them to payments made to such Cos. Only a few in India have recourse to remain truly anonymous by paying via BTC and the like.

This is not the first time a Govt has tried to pressure VPNs and other providers for data. The US and other 5 eye countries are quite well known for it.
 
So using Indian VPN servers will be worse than not using them.
6-hour reporting of cybersecurity events

“Any service provider, intermediary, data centre, body corporate and Government organisation shall mandatorily report cyber incidents as mentioned in Annexure I to CERT-In within six hours of noticing such incidents or being brought to notice about such incidents,” the CERT-In guidelines said.

They have issued more stupid and impractical rules.

Anyone who has managed a server for their personal site only would know how many bots attacks happen everyday. Or you could just launch a vps and see the bots hitting your server instantly.
 
Last edited by a moderator:
What's the link you posted?

They need to define cybersecurity events. Random bots trying to SSH into my server hours afters after launching shouldn't count. lol
 
Last edited:
They included port scanning attempts and a lot of generic terms to be reported.

I have not read the original notification, news sites are reporting this.

What cybersecurity incidents must be mandatorily reported?​

According to the directions, the following cybersecurity incidents must be mandatorily reported within 6 hours. Items in bold are the newly added ones:

  1. Targeted scanning/probing of critical networks/systems
  2. Compromise of critical systems/information
  3. Unauthorised access to IT systems/data
  4. Defacement of website or intrusion into a website and unauthorised changes such as inserting malicious codes or links to external websites etc.
  5. Malicious code attacks such as the spreading of viruses/worms/Trojan/Bots/ Spyware/Ransomware/Cryptominers
  6. Attack on servers such as Database, Mail and DNS and network devices such as Routers
  7. Identity Theft, spoofing and phishing attacks
  8. Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks
  9. Attacks on Critical Infrastructure, SCADA and operational technology systems and Wireless networks
  10. Attacks on applications such as E-Governance, E-Commerce etc.
  11. Data Breach
  12. Data Leak
  13. Attacks on Internet of Things (IoT) devices and associated systems, networks, software, servers
  14. Attacks or incidents affecting Digital Payment systems
  15. Attacks through Malicious mobile Apps
  16. Fake mobile Apps
  17. Unauthorised access to social media accounts
  18. Attacks or malicious/ suspicious activities affecting Cloud computing systems/servers/software/applications
  19. Attacks or malicious/suspicious activities affecting systems/ servers/ networks/ software/ applications related to Big Data, Blockchain, virtual assets, virtual asset exchanges, custodian wallets, Robotics, 3D and 4D Printing, additive manufacturing, Drones
  20. Attacks or malicious/ suspicious activities affecting systems/ servers/software/ applications related to Artificial Intelligence and Machine Learning
 
And what about when Indian companies are breached? Do they submit this much data? They still haven't concluded the Mobikwik breach.
 
Mobikwik is shameless enough to suggest that users might have shared their data themselves on other websites. Without any solid proof that the data was indeed taken from their servers, I don't think there will be any conclusion.
 
It's crazy people who know about mobikwik hacking still use it for minisucile cashback. Even before the hacking incident mobikwik was really a very poor service provider, transaction fail no refund.

I have not seen mobikwik at any shop offline online. How are they still in business?
 
Back