News Security

Apple’s Security Notifications Challenge, CERT-IN Investigates

Apple's Security Notifications Challenge, CERT-IN Investigates
Apple’s security notifications, signalling potential state-sponsored cyber threats, have prompted concerns about unregulated surveillance activities by India’s intelligence agencies.

In recent developments, the Indian Computer Emergency Response Team (CERT-IN) has been tasked with investigating security notifications from Apple regarding “state-sponsored” attacks. However, the effectiveness of CERT-IN’s role in addressing cybersecurity concerns is under scrutiny, raising questions about its ability to fulfil its mandate.

Apple’s security notifications, signalling potential state-sponsored cyber threats, have prompted concerns about unregulated surveillance activities by India’s intelligence agencies. This situation underscores the classic case of a computer emergency, demanding swift and effective responses.

CERT-IN, mandated to respond to computer emergencies under India’s Information Technology Act, has faced criticism for not delivering on its promises. Past instances, such as notifications to WhatsApp in 2019 regarding the Pegasus incident, reveal a lack of follow-through and translation of issued notices into meaningful regulatory actions.

Current Investigation and Challenges: Chinese Links and Ministerial Denials

As CERT-IN delves into the investigation, it is exploring potential Chinese government-linked agencies due to the production location of most iPhones in China. Despite concerns, the Minister for Electronics and Information Technology has dismissed the possibility of Indian agencies’ involvement, fuelling skepticism.

CERT-IN, positioned under the Ministry of Electronics and Information Technology, is critiqued for lacking independence and failing to conduct serious forensic audits. The organisation’s capacity to investigate state-sponsored attacks is questioned, especially when most cybersecurity industry capacity lies within privately regulated entities.

Forensic Challenges and Rejection of Evidence: Power Dynamics

CERT-IN’s role in empanelling private organisations for cybersecurity audits gives the government significant power to reject forensic evidence. This dynamic poses a challenge, as even credible evidence provided by entities like Apple may face skepticism or rejection without conclusive proof attributing exact actors.

Call for Action: NCIIPC’s Role and Comprehensive Solutions

The National Critical Information Infrastructure Protection Centre (NCIIPC), a unit of the National Technical Research Organisation, is cited as having more experience in handling nation-state actors targeting critical infrastructure. The article suggests a comprehensive approach, emphasising that NCIIPC, with its hands-on capacity, could play a more effective role in incident response

CERT-IN’s role and urges a more proactive and independent approach to cybersecurity regulation. Highlighting security as the central keyword, it underscores the need for meaningful actions, forensic investigations, and transparency to address the evolving landscape of cyber threats.

Leave a Reply

Your email address will not be published. Required fields are marked *