Sluggishness saves government websites from Heartbleed

ICERT had issued an advisory warning internet user about the bug and its solution

pragya

Praggya Guptaa | April 18, 2014



Believe it or not, government websites in India are less vulnerable to 'Heartbleed' bug. No, not because these websites have world’s best internet security protocols but because of the sluggish approach of government departments in the country. Yes, you read it right: sluggishness.

The Heartbleed bug exploits a flaw in the OpenSSL cryptographic software library. The vulnerability exposes sensitive information such as passwords, credit card numbers and other information to hackers by attacking the security certificates (SSL) of websites designed to protect online accounts for email, instant messaging and e-commerce.

According to experts, the bug has majorly attacked the sites that have updated their certificates. However, most of the Indian government sites are sluggish in updating their certificates, and therefore, the risk of getting affected is comparatively low. The two-year old bug has entered the system while updating these SSL certificates. “Generally government gives contract to vendors and they are less bothered about updating them,” said a security testing expert on the condition of anonymity.

It may be recalled that the Canadian revenue department had recently suspended its e-services for few days after being affected by the bug. The agency had reported that private information of about 900 people had been compromised as hackers exploited the Heartbleed bug. However, according to Indian Computer Emergency Response Team of India (ICERT) no such case has been reported so far in India.

ICERT had also issued an advisory warning internet user about the bug and its solution. “We have also written to large users and other organisations about the steps to be followed to mitigate the risk," said Gulshan Rai, director deneral, ICERT, to Governance Now.

According to some security experts, majority of the agencies and service providers might have already replaced the security certificates after the panic situation. Many experts and agencies are also advising internet users to change their passwords. ICERT’s advisory has also advised service provider to replace the certificate after moving to a fixed version of OpenSSL. It also advises users to change all sensitive credentials like usernames and passwords.

According to eScan MD and CEO Govind Rammurthy, “Since majority of websites are vulnerable to the Heartbleed bug mere changing a password will not help. Website would have to replace their OpenSSL software first in order to mitigate the threat.”

Commenting on the risks, Ajay Dubey, manager-south India, Websense, said, “Due to the nature of this bug data theft is of larger concern. We don’t know which all sites are compromised and what all data are with the hackers. Therefore, it is advisable that after replacing SSL certificate of sites, username and password must be changed.”

Comments

 

Other News

`Development must be judged beyond GDP, with rights and justice at core`

Delivering the IXth Chief Justice M.C. Chagla Memorial Lecture on ‘Human Rights and Sustainable Development Goals’, in Mumbai Friday,  former Chief Justice of India Bhushan R. Gavai questioned whether conventional economic indicators such as gross domestic product (GDP), national income,

RTI exposes Rs 16,909 crore cost blowout on Mumbai-Goa Highway

Seventeen years after the centre first approved the widening of National Highway 66 between Mumbai and Goa into a four-lane highway, a fresh RTI reply has revealed a sharp escalation in the project`s sanctioned cost.   According to the RTI reply obtained by activist Jeetendra

"India`s semiconductor ecosystem is expanding rapidly"

Prime minister Narendra Modi on Thursday inaugurated SEMICON India 2026 in New Delhi. Addressing the occasion and highlighting the significance of the event`s fifth edition, the PM drew a parallel between the launch of Semicon India and Vishwakarma Diwas. He pointed out the beautiful coincidence of

Cabinet approves raising EPFO wage ceiling from Rs.15,000 p.m. to Rs.25,000

The union cabinet, chaired by the prime minister, has approved the proposal of the Ministry of Labour & Employment to enhance the wage ceiling for mandatory coverage under the Employees’ Provident Fund Organisation (EPFO) from Rs.15,000 to Rs.25,000 per month. The decision is expected to bring

UPI continues to remain free for peer-to-peer transactions: Finance Ministry

The new UPI framework introduced has no impact on any person to person transactions, and UPI will continue to remain completely free for all person-to-person transactions, irrespective of the amount transferred, the finance ministry clarified on Tuesday.   Payments to merchan

SEMICON India 2026 and the making of a chip powerhouse

On Thursday, prime minister Narendra Modi will inaugurate SEMICON India 2026 at Yashobhoomi in Dwarka, New Delhi. Global chipmakers, policymakers and investors will fill the halls, all watching an industry India has built from the ground up. For three days, the country`s semi-con (semiconductor) manufact

Upcoming Conferences



-->

Archives

Current Issue

Opinion

Facebook Twitter Google Plus Linkedin Subscribe Newsletter

Twitter