؜ Profile picture
Jun 25 17 tweets 8 min read
People highlight genuine issues and are met with silence or blanket denials.

Someone shares a stupid video that goes viral on social media and they respond with a whole page of counter bullshit.
Hey @NPCI_NPCI if this is how your encryption/decryption system works, you are a bunch of incompetent morons.

Banks "lock" data with a "private" key and NPCI decrypts it with corresponding "public" key that only NPCI possesses! #DigitalIndia

WTF is "Hexadecimal Private Key"?
@NPCI_NPCI This statement from NPCI actually says a LOT more in what they left unsaid than the 6 points of bullshit that they hastily put together to put out a statement.
@NPCI_NPCI "built on a 4 party model" in which the owner of the FASTag who is paying money is not considered a party.

It's similar to horse racing, where the jockeys, horse owners, race organisers, bookies and gamblers all make money but horses don't.
@NPCI_NPCI "Several layers of security protocols" but not one word about the security features in the FASTag stickers that have been forced on almost all cars in India.

Because there isn't any?
All security protocols exist to only protect the interests of the 4 parties in the "ecosystem"?
@NPCI_NPCI Text: "an Individual cannot receive money... from fraudulent transactions"

Subtext: Only non-individuals can profit from fraudulent transactions,
(Including secret 5th party "System Integrators")

Remember how @airtelindia siphoned away 100s of crores of lakhs of victims?
@NPCI_NPCI @airtelindia From this Dec 2020, @FinancialXpress report...

According to WheelsEye Technology, one of the largest FASTag providers in India 3% of daily FASTag transactions are "faulty".

financialexpress.com/auto/industry/…
For a mango person using FASTag, both "fraudulent" and "faulty" txns aren't very different both force them to load more money.

Leading to more money parked with the "Issuer banks"! (1 of 4 parties secured by the "ecosystem")
For the first 5+ years of FASTag operation, the 3% "faulty" transactions were locked up for 30 days.

Effectively month long interest free credit.

And even after 5 years @NPCI_NPCI couldn't fix their system to eliminate these "faulty" transactions.
@NPCI_NPCI Since the FASTag system is defective by design and therefore unfixable, the "solution" to "faulty txns" is... Artificial Intelligence!

"The new AI-enabled FASTag management system will now auto-detect wrong transactions and generate refunds within 3-7 days."
@NPCI_NPCI Refunds going down from 30 days to 3-7 days may seem like an improvement, but remember from early 2021, FASTags became mandatory.

The "3% faulty txns" is now worth a lot more and <1 week of interest free credit to the "4 parties" is still worth many crores of rupees and growing.
Back to Captain Subtext and Point #2

At face value is near perfect. IP Firewall + Application Firewall+Hardware Security Module = 💯

Except.. toll plazas are in the middle of nowhere and need to be online 24x7 to make money, they aren't going to tie up with just one ISP/telco.
They'll need spare hardware ready to use in case of hardware failure.

Even if they don't, varying number of toll gates operational at different points of the day.

So at any point there are additional whitelisted IPs and Hardware Security Tokens lying around unused.
Point #3 is the only sensible part of the whole letter but it is a lot of jargon to impress people about what is the absolute bare minimum for any kind of private bank integration.
Point #5 is a free standing statement that doesn't tell us why that is a good thing or even what it is mapped to.

(Is Toll Plaza the entire structure or is each lane considered to be a "Toll Plaza"?)
This is NPCI telling the world that they are collecting and storing location information and can track vehicles on highways and even within cities via FASTag for Parking.

npci.org.in/what-we-do/net…

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with ؜

؜ Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @kingslyj

May 1
3 of 60 days before the new @IndianCERT poiicy comes into effect.

And nobody seems to have tried to use these NTP servers that are supposed to provide reliable and secure time service to the whole country...
@IndianCERT Not just the whole country, even MNCs with infra in other countries need to rely on these servers because...

"it is to be ensured that their time source shall not deviate from NPL and NIC"

From cert-in.org.in/PDF/CERT-In_Di… Image
@IndianCERT The National Informatics Centre @NICMeity NTP server is pretty much impossible to find.

Searching for "NTP" or "NTP Server" on all nic.in sites shows nothing except some old magazine articles that they've archived in their "library"(which BTW doesn't use HTTPS) ImageImageImageImage
Read 17 tweets
Mar 18
This is why @Zomato is forcing people to theit app.

Your personal data that they grab from your phone is far more valuable to them than the money they charge you(delivery fees/subscriptions) for using their services and the huge cut from the restaurants. #SurveillanceCapitalism
@zomato The @zomato share price is down nearly 50% from their all time high and they need to increase their earnings to prevent it from going even lower and that's not going to happen from just selling food, so it's time to monetise their customers' personal data.
@zomato From @Zomato's privacy policy...

zomato.com/policies/priva…
Read 14 tweets
May 28, 2021
Billionaire gatekeeping vaccines...

Translation: "You filthy plebs! Keep away from my ivory tower!"
So @rssharma3 has enabled "secret" vaccination centres for billionaires and their corporations on CoWIN that will not show up on the portal and the idiots at @Bioconlimited missed the toggle and made it public?

After building a portal that has left millions desperately hunting for slots, typing OTPs and solving CAPTCHAs. people who won vax-lottery are being denied vaccine because @rssharma3 is taking appointment cancellation instructions from a billionaire.

Read 4 tweets
Feb 9, 2021
I was under the assumption that one of the few things govts were getting right was rooftop solar power and net metering.

Boy was I wrong.
Parents want to install an AC for the summer and I suggested exploring rooftop solar to go with it so that they don't have to worry about electricity bills and the upfront expense will be recouped in electricity bill savings in a few years.
Only to discover it's a rigged system designed to exploit customers rather than meet renewable energy goals/climate change commitments.
Read 13 tweets
Feb 6, 2021
What you see on the form is only one part of the story.

**ALL KYC data** provided to **ALL** banks in India including photographs an PoI/PoI ID copies/scans are being uploaded to a central server.

ckycindia.in/ckyc/

cc: @SatpathyLive
And the central server also allows banks to **DOWNLOAD** the documents uploaded by other banks. Image
Read 7 tweets
Nov 17, 2020
When was the last time so many banks disappeared in 6 years?

en.wikipedia.org/wiki/Category:…
1st April 2017

State Bank of Bikaner and Jaipur, State Bank of Hyderabad, State Bank of Mysore, State Bank of Patiala, State Bank of Travancore and the Bharatiya Mahila Bank >> SBI.

1st April 2019

Dena Bank and Vijaya Bank >> Bank of Baroda.
1st April 2020

Corporation Bank and Andhra Bank >> Union Bank of India.

Oriental Bank of Commerce and United Bank of India >> Punjab National Bank.

Allahabad Bank >> Indian Bank

Syndicate Bank >> Canara Bank
Read 6 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us on Twitter!

:(