Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Thursday, August 24, 2023

Learn to say NO

Corporate training schools drum into the ears of the trainees , right from the first day of inception not only the importance but also the art of saying NO. A mere nod without realizing the cascading effect in a project could lead to catastrophic consequences making red the faces of the executives facing the client.

People nod for various reasons: For the fear of bosses, not wanting to raise a red flag before others, not giving enough thoughts and it goes on . . . 

In reality, this reluctance to say NO, should not only be checked at the official circles but also amongst friends, family, strangers and public places.

One must be aware of the case of a person lending his mobile phone to a stranger at the airport who wanted to call his waiting cab driver only to realize later that the stranger has made an International call; In another case, the stranger has given this number for a fraudulent online transaction !!

Does this mean that one should not help a stranger, whose appeal could genuine. No, but before extending one's helping arm, one is advised to be prudent and exercise caution by asking for the number and dial it before handing the mobile to the stranger.

With friends too, many are reluctant to say NO though the request seems to be unreasonable, more for the fear of losing friendship, but only to repent later.

In family circles, the NO mostly said with good intention is more often likely to be misunderstood. But then one has to take a call as to which is likely to cause greater heartburn- whether saying NO or the consequences.

Recent case of a man finding his credential being misused to obtain huge loans is a direct aftermath of obliging all and sundry with your personal credentials. The dropping of a slip with your vital data such as email Id and mobile number are enough to trigger creating your profile and a greater search with some technical knowhow could lead the fraudster to create one's identity for further digging into the potential victim's pocket. Better not to drop your details in a box at places like Book fare and Exhibitions, in the fond hope of receiving a lottery promised at the end of the day ! By the by, has anyone won any lottery at such common places? Not to my knowledge.

It was also reported that one need to be cautious in taking photocopies of important documents such as passport, Aadhaar card, pan Card, Ration card etc., as it is believed that some rogue shops have configured their photo copying machines to take an automatic extra copy which will be collected on a daily basis by data scavengers at a nominal cost per piece, but could work to large sums when the numbers increase. This could be avoided by people willing to invest a small amount in a copier at home but then how many could afford and will have the knowledge to do this is a moot point. 

It is also common for many organizations to ask for copies of such important documents as proof of the identity. In such cases, one can write boldly across the face of the document the purpose of sharing along with the date. This could prevent the document being (mis)used at a later date for purposes which were not intended while sharing initially.

Another easy habit that many of the users of digital items have gotten into is to blindly click on 'I Accept' before downloading any App on the mobile or getting into any website without even realizing what are the data that are being requested for and for what purpose! This is akin to and not much different from signing blindly on many pages of a loan application in a bank without reading the various clauses and conditions therein, which could come to haunt them later when they default and deviate from the requested purpose. 

How vulnerable are we could be better understood if one could just type their name in any popular search engine on the web and understand how much their private life is already under public glare. While with the growing methodologies to dig deep into others' pockets, it is nearly impossible to stay completely clear of getting victimized, some basic precautionary measures could help people in preventing their data being misused. Not an expert but will be glad to share some of the precautions I take while welcoming more thoughts to strengthen the cyber Rekha around oneself:

  1. Email id, Date of birth, parents' names, Aadhaar card, Passport details, Pan Number/card, voter id and Ration card are data that need to be guarded very well and not to be shared in public under any circumstance
  2. Wherever possible, get an acknowledgment for the data shared along with the purpose.
  3. Before sharing , smudge the data that are not relevant for the purpose. For instance, if Aadhaar card is given as proof of residence, explore covering the date of birth etc.,
  4. Please note that the QR code on the Aadhaar card is also a vulnerable data pool that needs to be protected. 
  5. While giving such documents , write / print boldly across the document the purpose for which it is shared along with  the date given. 
  6. Think twice before sharing your personal details on social network which is open for all
  7. Do not drop your private data in any public forum
  8. While downloading an App on the mobile or system, make sure that permissions are not granted for accessing or securing your data which are not relevant for the purpose. For instance, if an app for formatting documents is downloaded there is no need to permit access for all the photos and videos in your gallery. 
  9. Take time to check periodically your CIBIL score and ensure that no liability, not created by you, are shown there. 
  10. Say NO not only to Drugs, Tobacco and Alcohol but also for sharing your digital profile.

Friday, October 18, 2019

Safeguarding personal data

The ease with which our personal data is being sought, the thoughtlessness in handing over the critical data relating to one and the reckless way in which such details are shared in public domain is scary, to say the least.

Recently, I attended a spiritually oriented event of a very popular and revered person who gives discourses on Ramayana, Bhagavatham, Narayaneeyam and other such spiritual activities attracting many devotees. At the event, it was announced that an exclusive group is being formed so that interested people are communicated about further events and to join the group a link was sent. The link led to a web page that asked for many personal data related to the potential member of the group. The page also warned that on submission, the name and photo associated with that particular account will be uploaded! Let me clarify at the outset, I have absolutely no issues in personal data being shared with this particular Group/ Event Management team as they are reliable, reputed and I have no reason to believe that they could leave the data unprotected leading to misuse.

But, the thought occurred as to what would happen, if the data so given is shared unintentionally but as part of further processing to some other third party organization, for maintenance? Or what is the guarantee of that third party keeping such data secure? What if there is a leak somewhere in this process, wherein data could be compromised and if so who is responsible for the same ?

So, while the persons seeking data may not be leaking or misusing it but are they aware of the risks and sensitivity of handling the same? More importantly in a group which is unlikely to be filled with only literates, what is their responsibility in seeking such data? In a belief blinded by other attractions and with some justifiable confidence on this group, many people are likely to share the data. But then, should the data seekers not perform their role and responsibilities in apprising the givers about the risks involved and / or confirming about their safety and security by an assurance of non-sharing with others without their consent ?

Normally with some technical know how, I believe, a reasonable profile outline could be created with one's expanded name, date of birth, contact number, email-id and photo. With the prevailing and proliferating instances of cyber crimes particularly over online banking transactions and with innovative cyber crimes like Sim Swap springing up everyday, while the basic security concern lie with the owner of the data, given the illiteracy and lack of awareness, should the data seekers not apprise the givers about the risks involved, so that the innocence and ignorance of the users are not exploited by some unscrupulous elements?

In another group, filled with bankers who could justifiably boast of atleast three decades of banking service, it is still a task to make them understand the risks in sending a mail to all thousand members and use of BCC in emails ! This is a classic case of the data collector unwittingly leaking personal data, which could have damning consequences !  Well then, can an ignorance be cited as an excuse ?

At the entrance of a popular saree shop in Chennai's busy Pondy bazaar, an young man with a neat neck tie was asking for the mobile number of all visitors under the guise of a free prize scheme!!

When the data collected at such different points are collated by any with crooked intention, will it be a huge task to build their profile? The above instances exhibit how personal data is collected with or without any dubious intention and this is what exactly common man should be aware of  before sharing his data.

I feel, fighting cyber crime must be multi-pronged - while the owners need to keep their personal data safe, the data seekers need to ensure privacy of data collected and also make sure that  before collecting the data, the provider is well informed about the risks involved in sharing. Organizations like Banks and other institutions should not only take up measures to ensure that data collected and also created out of the data provided and out of the business transactions are kept secure, but also subject themselves to security audits by recognized bodies or approved and qualified third party auditors, to gain customer confidence. Right now , these are being held more as a formal exercise towards compliance but the need of the hour is more towards customer protection than formal compliance to satisfy legal requirements

My point is data seekers should be more responsible in asking for data, as such acts could be misused by mischief mongers. For the well intentioned seekers- apprise the givers about the risks involved and the measures taken by them to protect their interest and also better not to ask for such data, unless they have the ways and means to protect them!   More importantly, individuals should be weary of sharing any data , unless absolutely essential or feel secured after a basic personal due diligence.  

Saturday, January 31, 2015

Pursuer and the pursued

It all started by the latter half of 1999 when the Airlines started worrying about the safe passage of their flight and the bankers world over were concerned about the smooth changeover of date on that feared night of Dec 31st , heralding the new millennium. As the heat and panic peaked, the training institutes started making money out of a new entity -'fear'. Anyone with some knowledge of Java and more importantly a certificate started getting their passports stamped. There were also pieces of program codes floating around as an instant fix for Y2K and what was until then a distant dream achievable only by the select few became a buzzword in many household - working in U.S!

When the year rolled over, with little glitch belying all fears, the west started shedding the 'no more' wanted Y2K 'specialists' and there were few benches that were not warmed by these as they hovered around, little realizing that you cannot even spend a day there when you and your skills are no longer required.

With the return of the valiant, the importance of computer knowledge continued to gain popularity and the mushrooming Engineering colleges made the best advantage of the craze and need. After a 15 year ride of high and low, the circle seems to have come full, with the reported laying off of thousands from some of the industry's heavyweights, once considered as safe havens!

Such were the opportunities in this sector that anyone serious of making an impact was given a chance and the focused ones made the grade. Those with better perseverance and attitude climbed further and hopped across to vantage positions making ultimate use of the desperation of the emerging sector.

With opportunities came the misuses by people jumping for meager increases without any ethical care and those skillfully placed on contract reversed their gun to demand their pound of flesh and threatened otherwise to look for the better and buttered side of the bread.

When the industry hit the feared low, some wily organizations used them to weed the chaff along with the cats on the wall and this cat and mouse game went on for quite some time, despite the industry picking up.

The industry was more at the receiving end of this 'unforced attrition' born more out of avariciousness than career progress measures but they were able to survive with the ever flowing resources from the uncontrolled emergence of engineering colleges. While the smaller ones were playing with the 'hire and fire' policies there were some industry majors who stood like a rock silently absorbing the mass and strategically waiting for the turnaround. When one such 'majordomo' of the industry, considered as safe and secure, started taking a different route from its traditional and expected path, the panic set in. Thus when the cats stopped and turned back to look at the pursuing mob, the rats got into a huddle, and the pursuers became the pursued.

In my opinion, both were using and misusing the rules of 'notice and performance' to their own ends and faulting either in this race is uncharitable. Being in a matured industry that calls for the highest skills requiring constant skill updates and making one's presence felt, one is also expected to be prepared for the axe while looking for greener pastures.

 To compare the IT industry and its working conditions to other organized and settled sectors like Banks and Insurance is immature and the debate could at best serve the purpose of hogging the headlines for few days with improved TRP for some prime time channels. One is security oriented and the other rests on skill, performance and need. Banking like industries are also burdened with looking for business to keep the 'securely placed workforce' occupied whereas the IT is more on the need based side.

I feel in course of time,  the trade unionism too will creep in, with the support of pressure groups, just to make their presence felt, . But to expect them to have the same stranglehold as in other industries, one must be dreaming, given the expectations and performance levels at the former!


The need of the hour is planning- preserve the grain for the rainy days and await the sun to peep out. The organizations normally plan better, factor-in some attrition and manage to keep their head above the tide. It is the individuals who are unprepared and caught unawares that are likely to cry louder and hoarse!

'You are not matured until you expect the unexpected' - the adage seem to fit this dream industry more than any other. It is for the potential and perceived 'victims' at the industry to be more prepared, expect the unexpected and rise above the mundane to ward off such periodical threats to their career and lifestyle.

The young ones could be faulted to go overboard with a dream pay packet right out of the college. But such rude but timely wake-up call will sure spur the colts to be better equipped.

The experienced lot will need to plan better mentally and keep reminding themselves that there are no comfort zones in this field. I am sure the lessons are already felt, taken and will be handled. I believe and feel that this too shall pass.

After some initial rhetoric and stage managed shows to suit the required ends, the industry and its actors will soon settle down better-prepared to handle mutual pressures. In my opinion, this mid-course correction is the need of the hour and will remind  the Malthusian theory of demography of - 'survival of the fittest' again to the fore, even into this unrelated area .