IDA refused to call a spade a spade - no breach, they say. Your own fault!

Confuseous

Alfrescian (Inf)
Asset
Joined
Dec 30, 2010
Messages
12,730
Points
113
You know respect for the prime minister has hit an all time low when, despite blustering and making ugly faces in parliament to insist that a spade should be called a spade, the Infocomm Development Authority of Singapore (IDA) is ignoring him and refusing to own up to a breach in security.

Faces at Crimson Logic turned red when they first discovered that SingPass account holders found password reset notification letters in the mail even though they had made no such requests. Account holders whose personal data, such as contact information, employer details and remuneration records, were in the custody of Crimson Logic, the appointed operator of the SingPass single-factor authentication system for all government e-services in Singapore.

IDA investigated, and discovered 1,560 user profiles were illegally accessed. At least 419 fell for the ruse, and their passwords were reset. Affected SingPass users had their account profiles modified and linked to a small pool of Singapore-registered mobile numbers - IDA refused to tell how many. The mobile number can be used in a two-factor authentication procedure. When the victim changes his or her password, this number will serve to "verify" the request. This is obviously too technical for IDA, "We continue to explore the use of two-factor authentication for e-government transactions, particularly those involving sensitive data..." Nothing much has changed at IDA, ever since the very first chief executive famously said that although she knows zilch about technology, she can always hire someone who does.

The Managing Director for IDA, Ms Jacqueline Poh, is treating the incident as "a shot across the bow" and advised all individuals to "examine themselves" and take personal responsibility for their own cyber security, to borrow the phraseology used by one Arthur Fong about foreign intrusion. IDA has filed a police report, and since they are insisting that the SingPass system has not been compromised or breached, IDA must be saying the stolen addresses and IDs were looted from virtual personal premises. And not filched from the highly secured and firewalled database of the Crimson Logic operator. Go figure.

Check out what readers say of the incident here:

http://singaporedesk.blogspot.sg/2014/06/a-breach-should-be-called-breach.html
 
What to do ? the 419 are true blue 60%...if they receive email, telling them to wank at certain time of the day, purportedly send by the PxP...they will do so. They are so gullible...:rolleyes:
 
When the average retard in here use 1234567 as their password U still blame IDA?
 
So no fine, nothing for Crimson? Is it owned by lackey again? Anyone knows?
 
IDA's Managing Director, Jacqueline Poh Mae-Jean, is another elite with the right connection. Her husband is Andrew Tan, CEO of Maritime & Port Authority Singapore. Both are top civil servants.

Andrew Tan used to be LKY's principal private secretary 10 years back.
 
Back
Top