முக்கிய விஷயங்கள்
- Nisarga Adhikary என்ற cybersecurity researcher, CBSE on-screen marking portal-ல் critical data exposure flaw-ஐ identify செய்தார்.
- CERT-In-கிட்ட report செய்து 3-4 வார remediation window கேட்டார். But CERT-In அந்த flaw-ஐ fix செய்யாமல், acknowledge கூட செய்யாமல் இருந்தது.
- அப்புறம் Adhikary, public-க்கு அந்த vulnerability-களை வெளியிட்டார். CERT-In then, "national interest" mention செய்து, எல்லா public disclosure-யும் நிறுத்தச் சொன்னது.
- India-வின் DPDP Act 2023-ல் ethical hackers-க்கு dedicated safe-harbor clause இல்லை என்பதை இது வெளிச்சம் காட்டியது.
- CBSE portal-ன் PostgreSQL setup-ல் backup dumps மற்றும் configuration files exposed-ஆக இருந்தது. Student names, roll numbers, exam scores, admission details authentication இல்லாமல் எடுக்க முடிந்தது.
என்ன நடந்தது?
Nisarga Adhikary என்ற cybersecurity researcher, CBSE board-ன் on-screen marking portal-ல் சில முக்கியமான security flaws-ஐ routine security research-ன் போது கண்டுபிடிச்சார். இந்த portal marks, student IDs, and parent contact information-யெல்லாம் handle பண்றது. lakhs of learners across India இதற்கு use பண்றாங்க. Adhikary, code review மற்றும் automated testing மூலமா, backend-ன் PostgreSQL database server-ல் இருக்கிற backup dumps மற்றும் configuration files-ஐ API endpoint மூலமா access பண்ண முடியும்னு தெரிஞ்சிக்கிட்டார்.
அதாவது, ஒரு server-ல backup files இருக்கணும், அதை public-க்கு access ஆகாம இருக்க network level-ல் restrictions இருக்கணும். ஆனால் இந்த portal-ல் அது illegal-ஆ retrieve பண்ண முடிந்தது. Student names, roll numbers, exam scores, admission details — இது எல்லாமே authentication இல்லாமல் எடுக்க முடிந்தது. Adhikary, அவர் data-வை எதுவும் exfiltrate பண்ணல. But attack surface ரொம்ப trivial-ஆ இருக்குன்னு காட்டினார். அதாவது, யாருமே ஒரு browser-ல் simple URL hit பண்ணினால், student data open-ஆக இருக்கும்.
ஏன் Adhikary CERT-In-கிட்ட போனார்?
This போன்ற flaw-ஐ discover செய்யும் ஒரு ethical hacker, direct-ஆ public-க்கு போடுறதுக்கு பதிலா, responsible disclosure protocol பின்பற்றணும். Adhikary அதைதான் follow பண்ணார். CERT-In என்ற agency-க்கு report கொடுத்தார். அவருடைய கோரிக்கை என்னன்னா, 3-4 வார remediation window. அதாவது, 21 முதல் 28 நாட்களுக்குள், CBSE portal-ன் பிழையை சரிசெய்ங்க, அப்படி இல்லனா நான் outside announce பண்ணுவேன் என்று.
CERT-In அந்த report-ஐ custody-ல எடுத்தது. But உள்ளே என்ன நடந்ததுன்னு யாருக்கும் தெரியல. Internal response logs முற்றிலும் opaque-ஆ இருக்கு. Adhikary follow-up emails அனுப்பினாலும் reply இல்லை. Fix-உம் இல்லை. Server-side misconfigurations அப்படியே இருந்தது. இதுதான் அவரை frustrate பண்ணுச்சு. Weeks-களும் silence-உம், private institutions-ல் வந்த மாதிரி same level-ல neglect.
அப்புறம் என்ன ஆனது?
கடைசியா, Adhikary, schools மற்றும் parents-ஐ warn பண்றதுக்கு, அந்த information-ஐ public forums-ல வெளியிட்டார். அது emergency alert-ஆ அமைஞ்சிருக்கும். ஆனால் CERT-In இத வெச்சுக்கொள்ளல. They sent a directive asking him to halt all further public discussion. The notice-ல், "national interest" காரணம் காட்டி, critical educational infrastructure-க்கு coordinated, pre-approved timeline-கள் மட்டும்தான் allow பண்ணுவோம்னு சொன்னார்கள். CERT-In, reporter-க்கும் institution-க்கும் இடையிலான interface-ஆக செயல்படணும். But அந்த notice-ல transparencyவெதும் இல்லை. Coordinated release protocol-உம் national interest பேசுவதும், confusion-ஆன SOP-ஐயே காட்டுகிறது.
Adhikary-வை follow-up செய்ததும், எந்த response-உம் இல்லை. CERT-In-வே intervention பண்ணி, public disclosure-ஐ நிறுத்தச் சொன்னது. And that directive, exactly what he was trying to avoid: no public knowledge means no pressure. When society depends on digital marks and admission portals, even brief exposure periods become dangerous. CBSE portal-ன் exposure could allow unauthorized scraping or targeted attacks on minors. Identity theft is not hyperbole here; it is everyday risk in a country where student records are entry points to scholarships, admissions, and employment.
இது என்ன மாதிரி flaw?
PostgreSQL database server-ல் backup dumps மற்றும் configuration files expose-ஆக இருப்பது இரண்டு வெவ்வேறு threats. Backup dumps-ல் raw data இருக்கும். Configuration files-ல் database passwords, encryption keys, API endpoint secrets இருக்கும். இது ரெண்டும் API endpoint மூலமா illegal-ஆ retrieve பண்ண முடியும்னு Adhikary அமைதியாக்குறார். Adhikary-அப்படி data-வை எடுக்கல. But exposure-ஆன access surface, மற்ற attackers-க்கும் opportunity கொடுக்குது. Meaning, brute force அல்லது weakness exploitation மூலமா data scrape பண்ணலாம். Student names, roll numbers, marks, admission details — இது எல்லாமே identity theft-க்காக misused ஆகலாம்.
உதாரணமாக, ஒரு school admission portal-ல parents-ன் mobile numbers list open-ஆக இருக்குது, அதை data brokers scoop பண்ணலாம். இந்த CBSE case-லும் அதே risk இருக்கு.
இந்தியாவுக்கு என்ன?
இப்போ, India-வில் ed-tech boom-ா இருக்கு. JEE/NEET coaching platforms, scholarship portals, state board exam sites — இது எல்லாமே lakhs of students-ன் personal data-வை collect பண்றாங்க. CBSE எந்த அளவுக்கு central authority-ஆ இருக்குமோ, அதே போல இந்த portals-ம் national-level data hold பண்ணும்போது cybersecurity சரியாக இருக்கணும்.
India-வின் DPDP Act 2023-ல், personal data-க்கு protection இருக்குன்னு சொல்லலாம். ஆனால் ethical hackers-க்கு dedicated safe-harbor clause இல்லை. அதாவது, நீங்க public interest-க்காக flaw கண்டுபிடிச்சு report பண்ணாலும், CERT-In-கிட்ட wait பண்ணா reply இல்லைனா, உங்க career-க்கும், legal action-க்கும் danger இருக்கு. Adhikary-க்கு இதுக்கு பிறகும் ஒரு cease-and-desist order மூலம் warnings வந்திருக்கிறது. இது student-ன் rights-ஐ கேள்விக்குள்ள ஆக்குது. Minor students-ன் personal data unauthorized access-ஆனா, targeted attack, phishing, identity theft-ஆக மாறலாம். Delayed remediation, data-வை exposure-ல் வைக்கிறது. அதனால் India-வுக்கு ஒரு bulletproof vulnerability disclosure policy வேண்டும்.
நமக்கு என்ன தெரியணும்?
இந்த incident-ல பல விஷயங்கள் நமக்கு புரியணும். First, CERT-In response time-ஐ immediate-ஆ monitoring பண்ண வேண்டிய அவசியம் இருக்கு. 3-4 வார silence என்பது acceptable-ஆ இருக்க முடியாது. Second, public institutions-ம் private ed-tech portals-ம் ஒரே vulnerable pattern-ஐ follow பண்றாங்க. Third, India-வுக்கு ஸ்ட்ராங்கான vulnerability disclosure policy வேண்டும்.
Ethical hacker report பண்ணியதும், சில days-ல் status update கொடுக்கணும். If agent silent, reporters-க்கு legal shield, அதாவது question-க்கு பயப்படாமல் இருக்கணும். Fourth, CBSE portal-ல் வந்த இந்த flaw-ஐ fix பண்ண Future-ல என்ன action எடுத்தாங்கன்னு தெரியல. But state-owned infrastructure என்றால் security condition-ஐ strong-ஆ வைக்கணும். Fifth, when India builds more digital public goods, silence after a report is not a feature; it is a flaw.
அதாவது, இந்த incident ஒரு warning. Adhikary-யை judge செய்யலாம். But public-க்கு knowledge இல்லாத போது danger அதிகம். Smart researchers, next time report செய்து wait பண்ணினால் own-க்கு retaliation வரலாம். Also, coordinated release protocol-உம் national interest பேசுவதும், confusion-ஆன SOP-ஐயே காட்டுகிறது. Industry standard-ல், researcher vulnerability-ஐ report பண்ணி, institution-உம் forward-ஆ respond பண்ணுமே. India-வில் இந்த loop சுருங்குகிறது.
What's the benchmark? In the US and Europe, coordinated disclosure timelines are fixed. If a researcher reports and institution silent, reporter can go to a clearinghouse or media. India-வில் அந்த middle ground இல்லை. That is the real lesson.




கருத்துகள் (0)
Be the first to comment!