September 3,2010 | Last update 11 hours ago


RSS Feeds
Subscribe for Updates
Register Now!
Login
For Advanced Access
Newsletters
Free Daily Updates
Kensource Stockletters
Subscribe Now!




What's HOT?
Knowledge Series Books
Pathbreaker Series
Gift Subscription


Shopping
Moneylife Event Reports
Moneylife Events


Moneylife Foundation & the Centre for Advancement of Philanthropy conducted a workshop on 'Legal Compliances (under the Trusts & Societies Act, Income Tax & FCRA) & Good Governance For NGOs' on 16 July 2010

Moneylife Foundation conducted an interactive workshop on managing mutual funds and other investments on 19 June 2010. The event was sponsored by IDBI Mutual Fund. Click here for more pictures.

Moneylife Foundation conducted a workshop on Real Estate titled 'Trends, Issues & Consequences' On 5 May 2010. Click here for more pictures of the event.

Moneylife Foundation conducted a workshop on 'How to be safe and smart with your money', on 20 April 2010. Click here for more pictures of the event.

Noted writer Achyut Godbole chaired a Moneylife Foundation workshop for booklovers on 17 April 2010.

Moneylife Foundation conducts 'Brainstorming seminar on senior citizens issues'(09 April 2010).

Moneylife Foundation conducts financial literacy workshop for women (26 March 2010).

Moneylife Foundation conducted a special financial literacy workshop for women on the occasion of International Women's Day (8 March 2010)

Moneylife Foundation organised an open discussion on "Budget and You" on 27 February 2010. The participants were presented with a detailed analysis of the implications of the Budget proposals.

Sanjay Nirupam, Member of Parliament, inaugurating the Moneylife Knowledge Centre on 6 February 2010.

Moneylife, in association with Reliance Mutual Fund, organised the Big Ideas Essay Contest on “Taking Financial Markets to the Masses,” on 5 December 2009.
About Moneylife
Contact Us

Serious Web security issues in India
February 02, 2010 12:45 PM | Bookmark and Share
Dr Samir Kelekar

We probably need an agency where top hackers would sit day in and day out trying to find security holes in our Internet infrastructure, and work closely with compliance agencies in the government to fix the holes found

A chief technology officer (CTO) of one of world's top mobile service providers is worried about the fact that his company routinely sources critical equipment from a top Chinese vendor. After all, Chinese vendors come ten times cheaper than other Western vendors and the decision is based on purely commercial considerations.

However, the worry is that when critical components in the telecom infrastructure are in control of a potentially hostile country, the whole network could be brought down by just sending a couple of broadcast packets.

Not that there is any evidence that the Chinese have planted Trojans or backdoors in such infrastructure. In fact, there is no evidence either way, but the technology needed to reverse-engineer such components is either not available or would require millions of dollars of research to develop, so we do not know.

The software as it currently stands may even be clean but a routine firmware update could plant software having such nefarious commands. So, the detection problem becomes even more complex. Given that the Chinese government has cyber-war as its high priority strategy, and given that it gives millions of dollars in aid/subsidy to Chinese telecom vendors—heck, we don’t even know who exactly owns Huawei, the top Chinese telecom company—there is surely reason for suspicion that control of telecom infrastructure via equipment sold by Chinese vendors could be part of the Chinese government’s strategy, and this control can then be leveraged in case of any cyber-war.

In the Indian context, BSNL and Reliance routinely source from Chinese vendors. A year back, a couple of hackers demonstrated at the Defcon conference in the US, how mass traffic from an Internet service provider can be completely redirected to another country using a critical routing software called BGP. BGP is software that helps two routers talk to exchange routing information. The interesting part is that the hackers didn’t take advantage of any bug in BGP. BGP written decades ago when the Internet was in the hands of academicians, is a trusting protocol that just believes the data that it receives is true. To give an example, all of a particular ISP's traffic from India that is bound for the US, could go through, say, a node in Dubai, which then forwards it to the US. Another route to the US could be via Pakistan or China. If the Pakistani node's BGP software sends a message to the Indian ISP's BGP router saying that a better route to the US exists via Pakistan, the Indian ISP's router would just believe the above, and change its routing table so as to send all US-bound traffic to Pakistan instead. The traffic can then be legitimately sent to the US from Pakistan, but meanwhile it could also be sniffed and thus all traffic viewed. 

So, to the end user, everything would look fine, just that the intermediate node's owner could have a look at all the traffic.

Given that today, economies are so crucially dependent on the Internet, ability to view a country's traffic is the equivalent of knowing nearly all what goes on in the country, something that could give huge leverage to competitive business, not to mention the criticality of this data if the two neighbours are hostile to each other. A new version of secure BGP is in the offing.

The question is: Have all our Indian ISPs updated their BGP protocols to secure BGP? We don’t know.

Page

Submit your comments

Name * :
Email Id * :
Author Url:
Comment*:
alert me when new comment is posted on this article
Security Code:
Not readable? Change text.
1 Comment
Manali Rohinesh 7 months ago
Just thought I should use this article to warn people of spam emails that are floating around that have the look-n-feel of the IT department's emails - complete with logo and tagline. When my CA showed a printout of this email (which apparently allowed me to claim my refund online), an IT officer suggested lodging a police complaint since the IT department does not ask people to claim refunds by filling anything online. The officer also showed him similar printouts that many other people had brought to him for verification.

The text of this spam email is below:

Subject: Online Refund Form

After the last annual calculation of your fiscal activity we have determined that you are eligible to receive a tax refund of 820.50 Rupees.

Please submit the tax refund and allow us 3-5 days in order to process it.

A refund can be delayed for a variety of reasons. For example submitting invalid records or applying after the deadline.

To access the form for your tax refund, please click here>>

Copyright © Income Tax India. All rights reserved. http://www.incometaxindia.gov.in
» Reply » Link » Report abuse
What's Hot
From this section



What's Hot
Recent Additions


IDBI Bank deals itself a triple whammy 
After changing its employee incentive plan to meet targets; de-emphasising sales of non-banking products, it has now also done away with a number of fee-based charges for banking
Investors furious over SEBI’s hike in arbitration 
With less then 24 hours to the implementation of a SEBI-mandated hike in arbitration fees, investors appeal to the finance ministry for help; they point out that 84% of
Mid-cap Scanner: Adhunik Metaliks 
Not heavily traded and lesser tracked, this stock has some untapped potential
Smaller engineering companies may benefit from higher capex 
An Edelweiss Securities survey points out that infrastructure companies have firmed up higher capex plans over the next two years. This will benefit smaller engineering companies
NSE ‘refutes’ its own data which indicates that 
Ravi Narain, MD of the National Stock Exchange, believes that the bourse under his control is not hollow, shallow or illiquid. But his ‘explanation’ only raises more

> Promotional Material


Moneylife Shop

Pathbreakers
Pages - 223

List Price - Rs.1200
Our Price: - Rs.1000
Plain Truth about Stock Investing
Pages - 96

List Price - Rs.125
Our Price: - Rs.100
Plain Truths about Mutual Funds
Pages - 104

List Price - Rs.125
Our Price: - Rs.100
Plain Truths about Investments
Pages - 115

List Price - Rs.125
Our Price: - Rs.100
Plenty more interesting articles in the ML Store inside, Gift it to someone else or yourself!

Go to Moneylife Shop
Moneylife
Navigator

Subscribe to Moneylife | Send a Gift Subscription | Visit Moneylife Store | Offers & Promotions | Moneylife Newsletter | Useful Resources

Newsviewer | Commentary | Markets | Companies & Sectors | Investing | Personal Finance | Small Business | Life

Moneylife Home | Moneylife Magazine | Moneylife Shop | Corporate Moneylife | Contact Us



© 2009-10. All rights reserved by Moneywise Media and it's subsidiaries.

No contents of Moneylife.in website or Moneylife Magazine shall be reproduced without prior permissions from the authors of
Moneylife.in website and/or publisher of Moneylife Magazine.

You are bound by Terms and Conditions for using this website any further this point.
We maintain standard guidelines of User Privacy and may not disclose private user information to third parties.

Write to Moneylife webmaster for all the questions, reports and complaints pertaining to this website.