India's Election Commission fixes privacy flaws that exposed citizens' information-seeking data | TechCrunch

India’s Election Commission recently patched critical security vulnerabilities on its Right to Information portal. These flaws allowed unauthorized access to sensitive citizen data, including personal details and voting eligibility records. The incident highlights the fragility of digital transparency infrastructure just ahead of major national elections. The exposure occurred because proper authentication measures were missing, enabling external scraping of application records. Although some data is legally non-confidential, Indian court rulings mandate the protection of applicants' personal information. This breach demonstrated a significant gap between legal privacy requirements and technical implementation, risking citizen privacy on a massive scale. This situation is highly relevant to open data advocates, illustrating the delicate balance between transparency and security. It underscores that open access mechanisms must rigorously protect individual privacy to remain legitimate. Without robust safeguards, well-intentioned transparency initiatives can inadvertently harm citizens, eroding public trust in both government data practices and digital governance systems.

Source: techcrunch.com
Published on 2024-03-09