16 ms·
India’s largest bank SBI leaked account data on millions of customers
- pjf 8y agoQuote: "But the bank had not protected the server with a password, allowing anyone who knew where to look to access the data on millions of customers’ information."
- ramshanker 8y agoReading from the article, this was READ ONLY access. So privacy implication only. It doesn't make it any less sinful though.
- vijaybritto 8y agoPrivacy only? What do you mean? If you had requested in details in sms often your account can be profiled with some basic parsing. The hacker can create highly accurate targets for social engineering. This is a massive blunder.
- _jgdh 8y agoHe meant, it could have been worse. They could have changed your details. The phone number associated with your account, for example. Or they could have added transactions.
- sremani 8y agoYou have to wonder because SBI is the biggest and possibly best run public sector bank of India. Given the employment structure of Public Sector Banks, its always a challenge how the tech infrastructure is maintained.
- _jgdh 8y agoMy understanding was that most of this tech is built and maintained on contract by Infosys or some other company. Is that not the case?
- worldexplorer 8y agoIt seems like 'Nucleus Software' has many asian bank clients but cannot see SBI in the list (https://www.nucleussoftware.com/customers https://www.nucleussoftware.com/customers)
- deleted 8y ago[deleted]
- scandox 8y agoIs that MongoDB again?
- 1024core 8y agoThat's what I'm thinking! I bet it's MongoDB too.
- Dravidian 8y agoNot just SBI,I bet every nationalized bank in India has pathetic security. I've worked with some of them & I will say that if you want to sleep peacefully don't keep your money in a nationalised Indian bank; unfortunately private banks are out of reach for majority of the population. Anyway, it's not that a criminal needs to target the banks for sensitive data when the govt has made it easy by giving a central depository of citizen data in the name of Aadhaar; for the ease of use -it is linked with bank accounts & mobile numbers as well!
- snambi 8y agobanks use PAN number. They didn't ask for aadhaar number. Btw, I got my PAN number in late 1999, I think.
- webmobdev 8y ago> They didn't ask for aadhaar number. ??? The Indian banks, especially public banks, have been hounding everyone with an account for their Aadhaar number for the past 3+ years. It only stopped when the 5 judge bench of the SC ruled last year that Indians have a Right to Privacy and Aadhaar cannot be demanded for everything.
- mhb 8y agoBill Gates is a big fan of Aadhaar: https://www.gatesnotes.com/Development/Heroes-in-the-Field-Nandan-Nilekani https://www.gatesnotes.com/Development/Heroes-in-the-Field-N...
- plinkplonk 8y agoEasy to be a fan when all the harm falls on other people on the other side of the world.
- edge17 8y agoAlso easy to be a critic when the harm falls on other people on the other side of the world. There is a cost to inaction as well.
- niyaven 8y agoFrom the looks of the screenshots in the article, it's possible they are using MongoDB (json format, $oid field). Old versions had insecure defaults [0]. I'm currently in India, in the finance field, and I think it could happen to my company (passwords on post-its, computers left with unlocked sessions, some servers accessible from any employee - or anyone inside the office actually...). Security is sometimes tough to advocate, and raising awareness is easier said than done. [0] https://news.ycombinator.com/item?id=13374715 https://news.ycombinator.com/item?id=13374715
- eponeponepon 8y agoHonestly, this could happen at any company, for all the same reasons - in my experience, any workplace that isn't actually, or at least run as if it were, military is rife with subpar physical security. And I can't claim not to be part of the problem - I'm forever wandering off to get coffee without locking my screen, holding doors for people I kinda think I might recognise... every security sin you can name, I'm guilty of it at some point. And so are you. Yes, you. No, probably not you, Mr. Schneier.
- Consultant32452 8y agoI have an amusing anecdote about the military and password security. I worked with some folks on a base once and everyone used the same keyboard pattern such that if I knew the first character of a password, I knew the whole password. This pattern was openly shared as a way to "remember" otherwise impossible to remember complex passwords.
- hotsauceror 8y agoSo do I. Worked at a contractor hosting multiple sensitive/classified document repositories for one of the service branches. One of their attorneys' passwords expired for the document review platform. So this highly-qualified, TS/SCI cleared person accessing sensitive data emailed a bunch of our IT support and PMO distribution lists - basically an unknown number of anonymous third-party personnel - with an angry request to "reset [my] password back to [pass1234]! Right now!" One thing I learned is that, with the exception of those directly concerned with the firing of weapons in anger, most military personnel don't give a hoot about operational security, and they HATED our IT department who did.
- iamgopal 8y agoWhen their key software was in needs of urgent upgrade, my friend has to drive two wheeler to their server location and had to replace couple of file using USB sticks.
- edge17 8y agoAre there any websites that give deeper technical briefs about these large security breaches? This article provides a little bit of information, but often times these articles provide little to no information about the nature of the breach, point of weakness, etc.
- sbmthakur 8y agohttps://krebsonsecurity.com/ https://krebsonsecurity.com/ has a lot of technical details on various breaches. But I doubt if they will cover this case.
- 3pt14159 8y agoSigh. I'm starting to half-seriously long for a bank that doesn't use computers at all. Maybe just for encrypted communication between bank staff. I don't really think Canadian banks are all that much safer either.
- alex_anglin 8y agoWhy do you think Canadian banks are insecure?
- 3pt14159 8y agoI've just seen enough shoddy work in the financial sector. The money is safe. The information isn't. Not in the long run, anyway.
- kumarharsh 8y agoThis situation is so bad in India, that I can't even begin to summarise it... The biggest culprits are financial institutions themselves - they have such stupid requirements for passwords - need to change it regularly, can only contain @#!, need one caps, one small, one number, can't be the same as last 5 times, can't be shorter than 8 chars, but can't be longer than 15 chars either(!?!), etc - that you are either forced to write it down somewhere, or need to necessarily use a password manager. For the less computer savvy people, the second option is a non-starter, so they resort to the first option. And then, these stupid banks and mutual fund companies actively try to sabotage the working of password managers, and even disabling paste on password fields. And then, there are incredible incidences like this: I received an SMS from a loyalty program a few weeks back: Login at www.raymondrewards.com with your mobile no. & password <base-64 encoded string> for program benefits. Update your birthday & get 750 bonus pts in your birthday month. And I just sank in utter despair.
- ankitml 8y agoCant use password manager either for most of them. example ICICI (one of the biggest private bank) doesnt allow you to paste passwords either. Only way to use password manager is to meddle with view source to allow pasting.
- baroffoos 8y agoCould probably write a small extension that disables paste blocking
- zodiakzz 8y agoHere's the one I use [1]. My Pakistani bank also does every single thing mentioned lol. 1: https://chrome.google.com/webstore/detail/dont-fuck-with-paste/nkgllhigpcljnhoakjkgaieabnkmgdkb https://chrome.google.com/webstore/detail/dont-fuck-with-pas...
- paulryanrogers 8y agoKeepass can auto type and some extensions can prefill without pasting
- deleted 8y ago[deleted]
- deleted 8y ago[deleted]
- godelmachine 8y agoThis reminds me of my client. We have SBI as our client and often they raise issues to us. Most of their technical staff is a joke, coz they don't even follow the basic etiquette during a call. For ex - The engineer from SBI allowed me to have control of her server, and in a carefree manner called her BF. She knew I would take about 45-50 min to fix her issue, so she went on gossiping with her paramour in the regional language, and all of her lovey-dovey talks were audible to me loud and clear. She didn't even bother to mute her mic. In the same state of passion, she went to have her lunch without bothering about me (She's supposed to be at the server while I am working). After some time her server got locked coz I was pondering over the notes from my computer. I had to wait for the next 30 min for her to finish her lunch and be back at her cubicle to unlock the server.
- deleted 8y ago[deleted]
- sabujp 8y agoI remember I was in the NRI section of a SBI bank in Kolkata maybe ~20 years ago and we needed to get a travelers cheque transaction completed before their closing (bank strikes happen often so timing was critical when we were there, after days we were finally able to get into the bank to do business). Anyways, we were discussing things and the bank manager learned that I was good at computers and I kid you not, he asked me (a customer) to help him with some errors that his computer was making. I obliged because at the time I just didn't care and wanted my transaction to go through. IIRC there was a .com/dll/ocx error, nothing wanted to mess with by looking for a file, trying to run regsrv32, etc. Luckily a reboot fixed the problem ..but yea you can see how screwed up things are there. Things have definitely gotten much more strict recently but I'm sure there are still lots of these shenanigans happening amongst employees
- KorematsuFred 8y agoThere is no concept of privacy in Indian banks. My father in law owns a business that has to deal with large sums being exchanged through checks. Now, unlike USA bounced checks in India are as good as lost money. So most people will simply refuse to accept checks. Since my father in law does large number of transactions with nearly every bank in town he simply calls up the manager and asks "Does Mr. X has Y money in his account ?", the bank manager then gladly tells him how much money the customer has in his account and based on statement if the check in en-cash or not.
- onemantaker 8y agoActually we can trust the security researcher or hacker! Not the SBI bank you donot know when the impose fines and min balance fine
- nstart 8y agoOn another note, tech crunch seems to have done research where they actually monitored information passing through. Is this an ok line to cross in security disclosures? It doesn't feel right. Like as soon as you know you are looking at customer data, realtime or not, you should be closing the terminal/browser/whatever and reporting it immediately. Assuming you aren't a paid for by company security researcher that is. Curious what the more canonical opinion is on this.
- forkLding 8y agoThe disregard for security is so bad, I was actually surprised. How does India, a giant in terms of providing technology and tech workers have such bad standards? And I quote: "The passwordless database allowed us to see all of the text messages going to customers in real time, including their phone numbers, bank balances and recent transactions. The database also contained the customer’s partial bank account number. Some would say when a check had been cashed, and many of the bank’s sent messages included a link to download SBI’s YONO app for internet banking." Most importantly why wasn't this tested for security purposes and instead allowed to go live with adequate QA?
- quantummkv 8y ago> The disregard for security is so bad, I was actually surprised. How does India, a giant in terms of providing technology and tech workers have such bad standards? Most of these data leaks and hacks occur on nationalized banks/govt institutions. Thanks to various legacy decisions such as quotas on everything other than skills and merits, politics, decades of socialism, etc, the actual skill tech workers (or any kind of skilled workers) go to private institutions or immigrate out. You won't hear any private institutions of having data leaks with such frequency. Private sector companies have high standards. Many of the high performing and skilled people across USA are Indians. What not many people understand is than up until the last two decades, the only comfortable job in India was in the government. Private sector jobs were few are far between. Therefore, parents often pressurized kids to get into government services so that they can get official cars, manors and "benefits", without having to do any work. You can imagine what kind of people get into government institutions with such a culture. Rank idiots and rote learners. No one in India is surprised by such shoddy inefficiencies in a govt agency. It's basically expected. Politicians do not try to change this culture as it benefits them immensely and because of opposition pushback. Modi has been trying to offload more and more government agencies into the private markets, but the sheer amount of bureaucratic pushback is not helped by the opposition trying to portray him as a crony capitalist to earn political brownie points.
- known 8y agoA quick look at the audit trail would have prevented this leak;