This is an archive article published on June 19, 2023
Premium

CoWIN leaks: Where’s government’s due diligence?

Declaring that personal data is secure isn't enough. Privacy guarantees need more

cowin data leakTrusting the integrity of software or hardware is usually avoided because such correctness is often difficult to establish. (Representational)
Written by: Subhashis Banerjee
6 min readJun 19, 2023 09:05 AM IST First published on: Jun 19, 2023 at 07:07 AM IST

The recent media reports about the CoWin data leak are no doubt disconcerting, but what is even more so is the government’s response to them. It is hardly reassuring to be informed through a ministerial declaration that though some data may have leaked due to earlier breaches or poorly modelled use cases, there really is nothing to worry about because the back-end database is probably still secure. The question is — from what?

Data-related privacy and security concerns are usually countered with two kinds of reactions. The first is fatalistic, and they dismiss the worries saying that our phone or Aadhaar numbers may already be out there with hundreds of entities anyway. These reactions are frivolous. Various data protection discourses and the Supreme Court judgement on privacy debunk these adequately. The second is from the keepers of these systems. They often claim security by forceful proclamations. They argue that the security and privacy safeguards deployed are foolproof because they use “state-of-the-art best practices”. These claims often fail to precisely articulate what are the exact security and privacy problems that these best practices address and end up affirming — ad nauseam — that “the backend databases are safe and we have taken care of privacy”. That is neither here nor there.

Latest Comment
Post Comment
Read Comments