Skip to main content

Onus Is Still On IDA To Keep Our SingPass Safe

The announcement that 1,200 SingPass were compromised and that quarter of them had their unauthorized password reset raised the question about cyber security. However, it seems from media reports that the blame is on end users. IDA should also take the responsiblity of the safety of our SingPass details.

A FireEye spokesperson suggested that the breach was probably from a malware in a user's device and that it allowed the perpetrator to access 1,200 SingPass. This raises a strong probability that the communication between device and database server may be not as strong as thought. Furthermore, it could highlight that the database server is not as strongly encrypted as a full section was 
accessed via a single malware.

Media reports noted that IDA was receiving complains over the weekend from SingPass users receiving unauthorized password reset letters and CrimsonLogic only raised the matter with IDA on Monday evening. This resulted in the "hastily" arranged press conference on Wednesday. Given that letters take a day to be delivered within Singapore, the unauthorized reset was probably done on Thursday and/or Friday. From this approximated timeline, it took a week from the unauthorized entry for IDA to hold a press conference.

If there were a spike in password reset, there should have been an alert to inform CrimsonLogic. It seems that either there is no such alerts or the level of requests to reset password on a daily basis is so hight, the spike turned into a false positive.

If the former is the reason, there should be concerns as spikes in unusual activities are not resulting in alerts to take prompt action. If it is the latter, IDA should reexamine how passwords are set.

The estimate period of time IDA took to alert the public is also of a concern. If this was a real hack and data compromise, lots of information would have fallen in the wrong hand. 

The delay in implementing third factor authentication is also a concern. What made the situation worst was that reports  highlight the delay as only one vendor bid for the tender. Surely, security of individual data should be critical to call for a new tender? 

Hopefully, IDA can and will learn from this incident. While CrimsonLogic has assured that no data was compromised, there should be more security and encryption especially in how the data is communicated from end to end and how it is being stored.


Comments

Anonymous said…
This happens only once in 50 years. But the Mat keeps making stupid comments almost everyday
Unknown said…
Even if this is an "innocent" breech" this incident would have alerted real hackers to probe for other weaknesses. Although I am not an IT-security guy, I can think of two simple weaknesses.

First: Using our IC No as a default ID already simplifies half the task for hacking since its not difficult to obtain lists of valid ICs, with the check alphabet. eg just get hold of a bunch of entry forms for supermarket lucky draws. So only need to guess the password.
Secondly: Get entry into the sign-in database of a large corporation in SG eg telcos, banks etc with large online user base. Take the IC numbers, telephone numbers and passwords, cover tracks and exit. Use this list to hack into SingPass. Many users tend to used the same password so there will be a reasonable hit rate that the attack will not attract suspicion.

Conclusion: letting us use IC No is an user friendly idea but since IC numbers are not randomly generated, the security regime need to be thought through even more rigourously such as making in compulsory for those who retain the IC as default to register their handphone to receive an SMS code for transaction validation. (and for the occasion when you lose your phone and urgently need to use Singpass, allow you to register your home phone or alternative mobile to receive a call from theif call centre etc.

Popular posts from this blog

Singapore radio personality in "hot soup" for reporting train delays based on Tweets?

Update - Hossan Leong has commented on this post to say " I'm not in trouble pls don't blow this out of proportion. Let it rest. It's getting silly. Thank you for your love and concern and I apologize for any misunderstanding." ~  Hossan Leong. Hossan Leong, a Singapore radio personality for The Gold Breakfast Show on Gold 90.5, was censured today for reporting on train delays on the Circle Line because he based the information on Tweets, rather than waiting for the official reports from the Circle Line operator, SMRT.  It is, however, unknown if the "warning" came from Mediacorp producers or SMRT. Tweeted Hossan Leong ,  OK...I reported it on air and now I'm getting into trouble for it?? The CC line is DOWN rite? I did nothing wrong rite? The SMRT Circle Line was reported to be down this morning during peak hours and started as early as 7am. However, local news only received official statement was received by the mainstream media at about 9...

DBS Bank – One Tweet too little too late.

(Updated post - DBS apologise with the 3Rs – Will social media bite? ) It was the bluest Monday for DBS/POS Bank in its entire banking history when more than 1000 of their ATM and online banking services were taken offline due to a software upgrade an outage (PR announced that it was down due to software upgrade, but the outsourcer, IBM, later claimed it was an outage). So on that Monday, DBS decided to sign up onto Twitter and post a 140 characters one-liner onto Twitter to post a one liner to inform the Twitterverse of the down time. Everybody knows that if you just create a new account on Twitter, you would start off with 0 friends. How would you be able to inform the Twitterverse if you start with 0 friends? DBS Bank did something smart to insert the #dbs and #posb and that probably drew some attention to this account. However, the effectiveness of the tweet was lacking as it drew only 28 retweets. As of this posting, DBS Bank attracted 274 followers. A letter to T...

New field in SocialPR: Social Media Crisis Communications

I have been busy with family for the Lunar New Year week but it seem the Singapore blog-o-sphere was active, and is still is, about recently formed Association of Bloggers (Singapore), ABS for short. To cut a long story short, the announcement of ABS via mainstream media didn’t go down well with Singapore bloggers and in the end resulted in some speculation to why ABS was set-up in the first place. A post by the ABS president defending herself against a harsh criticism from a blogger added to the bad start and created even more speculation that ABS was set-up with an ulterior motive. A week later, some founding members of the pro-team started posting up notice of resignation on their blogs and this just added fuel to fire. Again, a story of ABS appeared in mainstream media and this lead to even more disgruntled bloggers asking why the president isn’t responding via her blog or the association’s blog. I also responded to a post about the ABS incident. You can catch a summary of...