‹ முகப்புக்கு திரும்ப

CERT-In Stop Order: Nisarga Adhikary-க்கும் CBSE Portal-க்கும் இடையே நடந்தது என்ன?

NISAGA ஆதிக்காரி CBSE portal-ல் flaw கண்டுபிடித்தார். CERT-In-கிட்ட 3-4 வாரம் report செய்து fix ஆகாதது. அதனால public disclosure-ஐ வெளியிட்டார். CERT-In national interest காரணம் காட்டி disclosure-ஐ நிறுத்தச் சொன்னது. இது India-வின் cyber-resilience-க்கு என்ன அர்த்தம்?

Keerthika 5 min read
Google-ல் Follow
Security CERT-In Stop Order: Nisarga Adhikary-க்கும் CBSE Portal-க்கும் இடையே நடந்தது என்ன? 5 நிமிடம் மீதம் Google-ல் Follow
CERT-In Stop Order: Nisarga Adhikary-க்கும் CBSE Portal-க்கும் இடையே நடந்தது என்ன?

தமிழ்டெக் AI சுருக்கம்

Nisarga Adhikary என்ற cybersecurity researcher, CBSE-ன் on-screen marking portal-ல critical data exposure flaw ஒன்னு கண்டுபிடிச்சார்; PostgreSQL backup dumps மற்றும் configuration files API endpoint மூலம் authentication இல்லாமல் open-ஆ இருந்ததால் student names, roll numbers, exam scores, admission details எல்லாம் யாரும் எளிதா எடுக்க முடிஞ்ச நிலை இருந்தது. அவர் responsible disclosure follow பண்ணி CERT-In-கிட்ட report பண்ணி 3-4 வாரம் remediation window கேட்டாரு, ஆனா agency acknowledge கூட பண்ணாம weeks-கணக்கில் silence-ல இருந்தது. Frustrated-ஆ அவர் parents மற்றும் schools-ஐ warn பண்றதுக்காக vulnerability details-ஐ public-ல வெளியிட்டார், அப்புறம் CERT-In “national interest” காரணம் காட்டி further public disclosure எல்லாம் நிறுத்தச் சொல்லி directive அனுப்பியது. இந்த incident India-வின் DPDP Act 2023-ல ethical hackers-க்கு dedicated safe-harbor clause இல்லன்னு தெளிவா காட்டுது, so researcher report பண்ணினாலும் reply வராட்டி legal risk மற்றும் career risk இருக்கு. நமக்கு தெரிஞ்சுக்கணும்னா lakhs of students-ன் data identity theft அல்லது phishing-க்கு misuse ஆகலாம், so CERT-In response time improve ஆகணும், strong vulnerability disclosure policy வேணும், education portals-ல security properly fix பண்ணி maintain பண்ணணும்.

  • 3-4 வார silence CERT-In-ன் opacity-ஐ வெளிச்சம் காட்டியது
  • DPDP Act 2023-ல் ethical hackers-க்கு safe-harbor protection இல்லை
  • Ill-protected student records lakhs of learners-ஐ risk-ல் வைக்கிறது
  • Coordinated release protocol-உம் national interest பேசுவதும் confusion-ஆன SOP-ஐயும்
  • Private ed-tech portals-லும் same vulnerability pattern-ஐ avoid பண்ண முடியாது

AI உதவியுடன் தயாரான சுருக்கம் — தமிழ்டெக் எடிட்டர்ஸ் சரிபார்த்தது.

0:00
0:00
🔒 Listen வசதி subscribers-க்கு மட்டும். Subscribe செய்யுங்கள்

முக்கிய விஷயங்கள்

  • Nisarga Adhikary என்ற cybersecurity researcher, CBSE on-screen marking portal-ல் critical data exposure flaw-ஐ identify செய்தார்.
  • CERT-In-கிட்ட report செய்து 3-4 வார remediation window கேட்டார். But CERT-In அந்த flaw-ஐ fix செய்யாமல், acknowledge கூட செய்யாமல் இருந்தது.
  • அப்புறம் Adhikary, public-க்கு அந்த vulnerability-களை வெளியிட்டார். CERT-In then, "national interest" mention செய்து, எல்லா public disclosure-யும் நிறுத்தச் சொன்னது.
  • India-வின் DPDP Act 2023-ல் ethical hackers-க்கு dedicated safe-harbor clause இல்லை என்பதை இது வெளிச்சம் காட்டியது.
  • CBSE portal-ன் PostgreSQL setup-ல் backup dumps மற்றும் configuration files exposed-ஆக இருந்தது. Student names, roll numbers, exam scores, admission details authentication இல்லாமல் எடுக்க முடிந்தது.

என்ன நடந்தது?

Nisarga Adhikary என்ற cybersecurity researcher, CBSE board-ன் on-screen marking portal-ல் சில முக்கியமான security flaws-ஐ routine security research-ன் போது கண்டுபிடிச்சார். இந்த portal marks, student IDs, and parent contact information-யெல்லாம் handle பண்றது. lakhs of learners across India இதற்கு use பண்றாங்க. Adhikary, code review மற்றும் automated testing மூலமா, backend-ன் PostgreSQL database server-ல் இருக்கிற backup dumps மற்றும் configuration files-ஐ API endpoint மூலமா access பண்ண முடியும்னு தெரிஞ்சிக்கிட்டார்.

அதாவது, ஒரு server-ல backup files இருக்கணும், அதை public-க்கு access ஆகாம இருக்க network level-ல் restrictions இருக்கணும். ஆனால் இந்த portal-ல் அது illegal-ஆ retrieve பண்ண முடிந்தது. Student names, roll numbers, exam scores, admission details — இது எல்லாமே authentication இல்லாமல் எடுக்க முடிந்தது. Adhikary, அவர் data-வை எதுவும் exfiltrate பண்ணல. But attack surface ரொம்ப trivial-ஆ இருக்குன்னு காட்டினார். அதாவது, யாருமே ஒரு browser-ல் simple URL hit பண்ணினால், student data open-ஆக இருக்கும்.

ஏன் Adhikary CERT-In-கிட்ட போனார்?

This போன்ற flaw-ஐ discover செய்யும் ஒரு ethical hacker, direct-ஆ public-க்கு போடுறதுக்கு பதிலா, responsible disclosure protocol பின்பற்றணும். Adhikary அதைதான் follow பண்ணார். CERT-In என்ற agency-க்கு report கொடுத்தார். அவருடைய கோரிக்கை என்னன்னா, 3-4 வார remediation window. அதாவது, 21 முதல் 28 நாட்களுக்குள், CBSE portal-ன் பிழையை சரிசெய்ங்க, அப்படி இல்லனா நான் outside announce பண்ணுவேன் என்று.

CERT-In அந்த report-ஐ custody-ல எடுத்தது. But உள்ளே என்ன நடந்ததுன்னு யாருக்கும் தெரியல. Internal response logs முற்றிலும் opaque-ஆ இருக்கு. Adhikary follow-up emails அனுப்பினாலும் reply இல்லை. Fix-உம் இல்லை. Server-side misconfigurations அப்படியே இருந்தது. இதுதான் அவரை frustrate பண்ணுச்சு. Weeks-களும் silence-உம், private institutions-ல் வந்த மாதிரி same level-ல neglect.

அப்புறம் என்ன ஆனது?

கடைசியா, Adhikary, schools மற்றும் parents-ஐ warn பண்றதுக்கு, அந்த information-ஐ public forums-ல வெளியிட்டார். அது emergency alert-ஆ அமைஞ்சிருக்கும். ஆனால் CERT-In இத வெச்சுக்கொள்ளல. They sent a directive asking him to halt all further public discussion. The notice-ல், "national interest" காரணம் காட்டி, critical educational infrastructure-க்கு coordinated, pre-approved timeline-கள் மட்டும்தான் allow பண்ணுவோம்னு சொன்னார்கள். CERT-In, reporter-க்கும் institution-க்கும் இடையிலான interface-ஆக செயல்படணும். But அந்த notice-ல transparencyவெதும் இல்லை. Coordinated release protocol-உம் national interest பேசுவதும், confusion-ஆன SOP-ஐயே காட்டுகிறது.

Adhikary-வை follow-up செய்ததும், எந்த response-உம் இல்லை. CERT-In-வே intervention பண்ணி, public disclosure-ஐ நிறுத்தச் சொன்னது. And that directive, exactly what he was trying to avoid: no public knowledge means no pressure. When society depends on digital marks and admission portals, even brief exposure periods become dangerous. CBSE portal-ன் exposure could allow unauthorized scraping or targeted attacks on minors. Identity theft is not hyperbole here; it is everyday risk in a country where student records are entry points to scholarships, admissions, and employment.

இது என்ன மாதிரி flaw?

PostgreSQL database server-ல் backup dumps மற்றும் configuration files expose-ஆக இருப்பது இரண்டு வெவ்வேறு threats. Backup dumps-ல் raw data இருக்கும். Configuration files-ல் database passwords, encryption keys, API endpoint secrets இருக்கும். இது ரெண்டும் API endpoint மூலமா illegal-ஆ retrieve பண்ண முடியும்னு Adhikary அமைதியாக்குறார். Adhikary-அப்படி data-வை எடுக்கல. But exposure-ஆன access surface, மற்ற attackers-க்கும் opportunity கொடுக்குது. Meaning, brute force அல்லது weakness exploitation மூலமா data scrape பண்ணலாம். Student names, roll numbers, marks, admission details — இது எல்லாமே identity theft-க்காக misused ஆகலாம்.

உதாரணமாக, ஒரு school admission portal-ல parents-ன் mobile numbers list open-ஆக இருக்குது, அதை data brokers scoop பண்ணலாம். இந்த CBSE case-லும் அதே risk இருக்கு.

இந்தியாவுக்கு என்ன?

இப்போ, India-வில் ed-tech boom-ா இருக்கு. JEE/NEET coaching platforms, scholarship portals, state board exam sites — இது எல்லாமே lakhs of students-ன் personal data-வை collect பண்றாங்க. CBSE எந்த அளவுக்கு central authority-ஆ இருக்குமோ, அதே போல இந்த portals-ம் national-level data hold பண்ணும்போது cybersecurity சரியாக இருக்கணும்.

India-வின் DPDP Act 2023-ல், personal data-க்கு protection இருக்குன்னு சொல்லலாம். ஆனால் ethical hackers-க்கு dedicated safe-harbor clause இல்லை. அதாவது, நீங்க public interest-க்காக flaw கண்டுபிடிச்சு report பண்ணாலும், CERT-In-கிட்ட wait பண்ணா reply இல்லைனா, உங்க career-க்கும், legal action-க்கும் danger இருக்கு. Adhikary-க்கு இதுக்கு பிறகும் ஒரு cease-and-desist order மூலம் warnings வந்திருக்கிறது. இது student-ன் rights-ஐ கேள்விக்குள்ள ஆக்குது. Minor students-ன் personal data unauthorized access-ஆனா, targeted attack, phishing, identity theft-ஆக மாறலாம். Delayed remediation, data-வை exposure-ல் வைக்கிறது. அதனால் India-வுக்கு ஒரு bulletproof vulnerability disclosure policy வேண்டும்.

நமக்கு என்ன தெரியணும்?

இந்த incident-ல பல விஷயங்கள் நமக்கு புரியணும். First, CERT-In response time-ஐ immediate-ஆ monitoring பண்ண வேண்டிய அவசியம் இருக்கு. 3-4 வார silence என்பது acceptable-ஆ இருக்க முடியாது. Second, public institutions-ம் private ed-tech portals-ம் ஒரே vulnerable pattern-ஐ follow பண்றாங்க. Third, India-வுக்கு ஸ்ட்ராங்கான vulnerability disclosure policy வேண்டும்.

Ethical hacker report பண்ணியதும், சில days-ல் status update கொடுக்கணும். If agent silent, reporters-க்கு legal shield, அதாவது question-க்கு பயப்படாமல் இருக்கணும். Fourth, CBSE portal-ல் வந்த இந்த flaw-ஐ fix பண்ண Future-ல என்ன action எடுத்தாங்கன்னு தெரியல. But state-owned infrastructure என்றால் security condition-ஐ strong-ஆ வைக்கணும். Fifth, when India builds more digital public goods, silence after a report is not a feature; it is a flaw.

அதாவது, இந்த incident ஒரு warning. Adhikary-யை judge செய்யலாம். But public-க்கு knowledge இல்லாத போது danger அதிகம். Smart researchers, next time report செய்து wait பண்ணினால் own-க்கு retaliation வரலாம். Also, coordinated release protocol-உம் national interest பேசுவதும், confusion-ஆன SOP-ஐயே காட்டுகிறது. Industry standard-ல், researcher vulnerability-ஐ report பண்ணி, institution-உம் forward-ஆ respond பண்ணுமே. India-வில் இந்த loop சுருங்குகிறது.

What's the benchmark? In the US and Europe, coordinated disclosure timelines are fixed. If a researcher reports and institution silent, reporter can go to a clearinghouse or media. India-வில் அந்த middle ground இல்லை. That is the real lesson.

நாளைய டெக் செய்திகள் உங்க WhatsApp-க்கே

தினமும் ஒரு சின்ன update, இலவசம். TamilTech channel-ஐ follow பண்ணுங்க.

What do you think?

people reacted

Keerthika

தமிழ்டெக் எடிட்டோரியல் டீம் · 3,344 கட்டுரைகள்

Keerthika is an editor at TamilTech, the Tamil and English technology publication founded by Praveen Kumar S. She covers AI, smartphones, gadgets, EVs, startups and cybersecurity i...

மேலும் Keerthika

WhatsApp-ல் TamilTech-ஐக் கேளுங்க

டெக் சந்தேகமா? தமிழிலோ ஆங்கிலத்திலோ கேளுங்க — எங்க WhatsApp அசிஸ்டன்ட் TamilTech கட்டுரைகளில் இருந்து சில நொடிகளில் பதில் சொல்லும்.

தொடர்புடைய செய்திகள்

கருத்துகள் (0)

| Supports **bold**, *italic*, `code`

Be the first to comment!

அடுத்த செய்தி PixelLeak: AI Coding Agents 13,000 கம்பெனி Screenshots-ஐ GitHub-ல Public ஆக்கிடுச்சு
Tamiltech

Tamiltech

Install app for faster access

Earn XP 🏆
WhatsApp
Notifications