India’s Election Commission fixes privacy flaws that exposed citizens’ information-seeking data

Date:

Share post:


India’s federal election commission has fixed flaws on its website that exposed data related to citizens’ requests for information related to their voting eligibility status, local political candidates and parties, and technical details about electronic voting machines. India is heading for its next general elections, expected between April and May, to elect the members of its parliament’s lower house who will form the new government.

The Election Commission of India fixed the bugs in its Right to Information (RTI) portal, which allows citizens to request access to records of constitutional authorities, as well as state and central government institutions and private organizations receiving substantial funds from the Indian government.

The bugs allowed access to the RTI requests, download transaction receipts, and responses shared by the officials without properly authenticating user logins.

Some of the exposed data included the RTI filing date, the questions asked, the applicant’s name and mailing address, the applicant’s poverty line status, and RTI responses.

Security researcher Karan Saini found the bugs in February and asked TechCrunch to help disclose them to the authorities after the Election Commission, the Indian Computer Emergency Response Team (CERT-In), and the National Critical Information Infrastructure Protection Center did not initially respond to his requests to fix them. The bugs were fixed earlier this week following CERT-In’s intervention.

“CERT-In has been coordinating the issue with the concerned authority. Recently, CERT-In has been informed by the concerned authority that the reported vulnerability has been fixed,” the Indian cybersecurity agency said in an email to TechCrunch on Tuesday.

The agency also confirmed the fix to the researcher.

Even though the RTI applications and responses are not confidential by Indian law, a judgment (PDF) by the Kolkata High Court in 2014 ordered authorities taking RTI applicants’ personal data “to hide such information and particularly from their website so that people at large would not know of the details.”

By default, the Election Commission’s RTI portal does not provide access to individual RTI applications and responses without logging in, which means external access to the data and its ability to be scraped — because it is accessible without a login — made the flaws a privacy issue.

The Election Commission of India did not respond to a request for comment.



Source link

Lisa Holden
Lisa Holden
Lisa Holden is a news writer for LinkDaddy News. She writes health, sport, tech, and more. Some of her favorite topics include the latest trends in fitness and wellness, the best ways to use technology to improve your life, and the latest developments in medical research.

Recent posts

Related articles

OpenAI Startup Fund raises additional $5M

The OpenAI Startup Fund, a venture fund that invests in early-stage AI companies and has recently transferred legal control from Sam...

Accel has a fresh $650M to back European early-stage startups

Early-stage rounds continue to account for the majority of investments in the European startup market, and on...

Cruise founder Kyle Vogt is back with a robot startup

Kyle Vogt, the former founder and CEO of self-driving car company Cruise, has a new VC-backed robotics...

From Miles Grimshaw to Eva Ho, venture capitalists continue to play musical chairs

When Keith Rabois announced he was leaving Founders Fund to return to Khosla Ventures in January, it...

Anthropic is expanding to Europe and raising more money

On the heels of OpenAI announcing the latest iteration of its GPT large language model, its biggest...

TechCrunch Space: You rock(et) my world, moms

Hello and welcome back to TechCrunch Space. Happy belated Mother’s Day! Want to reach out with a...

Apple iPad Pro M4 vs. iPad Air M2: Reviewing which is right for most

Apple devoted a full event to iPad last Tuesday, roughly a month out from WWDC. From the...

GV’s youngest partner has launched her own firm

Terri Burns, a former partner at GV, is venturing into a new chapter of her career by...