TECHNOLOGY
Kanishk Sajnani did not receive so much as a thank you from a major Indian airline when he contacted them with alarming news -- he had hacked their website and could book flights anywhere in the world for free.
Kanishk Sajnani did not receive so much as a thank you from a major Indian airline when he contacted them with alarming news -- he had hacked their website and could book flights anywhere in the world for free.
It was a familiar tale for India's army of "ethical hackers", who earn millions protecting foreign corporations and global tech giants from cyber attacks but are largely ignored at home, their skills and altruism misunderstood or distrusted. India produces more ethical hackers -- those who break into computer networks to expose, rather than exploit, weaknesses -- than anywhere else in the world.
The latest data from BugCrowd, a global hacking network, showed Indians raked in the most "bug bounties" -- rewards for red-flagging security loopholes. Facebook, which has long tapped hacker talent, paid more to Indian researchers in the first half of 2016 than any other researchers. Indians outnumbered all other bug hunters on HackerOne, another registry of around 100,000 hackers. One anonymous Indian hacker -- "Geekboy" -- has found more than 700 vulnerabilities for companies like Yahoo, Uber and Rockstar Games.
Most are young "techies" -- software engineers swelling the ranks of India's $154-billion IT outsourcing sector whose skill set makes them uniquely gifted at cracking cyber systems.
"People who build software in many cases also understand how it can be broken," HackerOne co-founder Michiel Prins told AFP by email. But while technology behemoths and multinationals are increasingly reliant on this world-class hacking talent, just a handful of Indian firms run bug bounty programs. Information volunteered by these cyber samaritans is often treated with indifference or suspicion, hackers and tech industry observers told AFP.
Anand Prakash, a 23-year-old security engineer who has earned $350,000 in bug bounties, said Facebook replied almost immediately when he notified them of a glitch allowing him to post from anyone's account.
"But here in India, the email is ignored most of the time," Prakash told AFP from Bangalore where he runs his own cyber security firm AppSecure India. "I have experienced situations many times where I have a threatening email from a legal team saying 'What are you doing hacking into our site?'" Sajnani, who has hacked around a dozen Indian companies, said he was once offered a reward by a company that dropped off the radar once the bugs were fixed.
"Not getting properly acknowledged, or companies not showing any gratitude after you tried to help them, that is very annoying," the 21-year-old told AFP from Ahmedabad, where he hunts for software glitches in between his computer engineering studies.
- Attitudes changing -
An unwillingness to engage its homegrown hackers has backfired spectacularly for a number of Indian startups, forcing a long-overdue rethink of attitudes toward cyber security.
In 2015, Uber-rival Ola launched what it called a "first of its kind" bounty program in India after hackers repeatedly exposed vulnerabilities in the hugely-popular app. This month Zomato, a food and restaurant guide operating in 23 countries, suffered an embarrassing breach when a hacker stole 17 million user records from its supposedly secure database. The hacker "nclay" threatened to sell the information unless Zomato, valued at hundreds of millions of dollars, offered bug hunters more than just certificates of appreciation for their honesty.
"If they were paying money to the good guys, maybe 'nclay' would have reported the vulnerability and made the money the right way," Waqas Amir, founder of cyber security website HackRead, told AFP by email. The incident was especially galling for Prakash. He had hacked Zomato's database just two years earlier, and said if they listened to him then "they would never have been breached in 2017."
In a mea culpa rare for an Indian tech company, Zomato agreed to launch a "healthy" bounty program and encourage other firms to work with ethical hackers.
"We should have taken this more seriously earlier," a Zomato spokeswoman said in a statement to AFP. The Zomato hack, and panic surrounding this month's global WannaCry cyber attack, comes as the Indian government aggressively denies suggestions its massive biometric identification program is susceptible to leaks.
The government has staunchly defended its "Aadhaar" program, which stores the fingerprints and iris scans of more than one billion Indians on a national database, and has accused those who have raised concerns of illegal hacking.
Prakash said it was vital the government embrace its own through a programme like the "Hack the Pentagon" initiative, which last year saw 1,400 security engineers invited to poke holes in the US Department of Defense's cyber fortifications. "The Indian government definitely needs a bounty programme to make their system more secure," Prakash said.
PM Modi condemns Pahalgam terror attack, assures justice: 'Nyaye milke rahega'
On eve of election, several killed as SUV rams into crowd at festival in Canada's Vancouver
Pakistan makes new offers in third attempt to sell PIA, lure buyers by offering a stake of...
Big update on Mumbai-Ahmedabad bullet train project, NHSRCL successfully launches the first...
Good news for MS Dhoni's fans, former Indian all-rounder shares CSK skipper's plans for IPL 2026
How much do IPL umpires earn? Here's what you need to know
Massive explosion at Iranian Oil port kills 18, injures over 750 amid nuke talks with US
Pakistan's ISI agency is funded by..., large part of this money is used for...
'Prepare for full-scale war': Pak minister's nuclear threat to India over Indus Water treaty
IPL 2025: Good news for DC fans, this star player to make comeback after injury for RCB clash
Jammu and Kashmir: House of another terrorist bombed after Pahalgam terrorist attack, watch video
Is SRH owner Kavya Maran in love with this popular star? Know her net worth, education and more
Mughal emperors Akbar, Jahangir and Shah Jahan used their shoes to show their power by...
Meet woman, mother of two, hearing impaired, cracked UPSC in 7th attempt, at the age of...
Did Donald Trump doze off at Pope Francis' funeral? Viral photos trigger netizens' reactions
Massive fire breaks out at ED office building in Mumbai: Here's what we know so far
Hamas open to end Gaza war, release all hostages, but demands this from Israel in return, it is...
Meet man, once a shepherd belonging to a small village, cracked UPSC exam with AIR...
BIZARRE! Groom calls off wedding after DJ plays 'Channa Mereya' during festivities
'Modi bunkers' back in use amid fear of escalation along LoC after Pahalgam massacre
RCB youngster mocked with meme for shadowing Virat Kohli, his reply stumps everyone - Watch
Deepika Padukone swears by HIFU treatment for radiant skin: Here's everything you need to know
'Single for over...': Shubman Gill clears air on Sara Tendulkar dating rumours, watch video
Over 400 injured in explosion at port in Iran's Bandar Abbas city, several feared dead
Bill Gates' Microsoft gives five-day ultimatum to employees, asks them to join a rigorous PIP or...
Attempt to grope breasts is 'aggravated sex assault' but 'not rape,' says Calcutta High Court
Anant Ambani appointed as whole-time director of Mukesh Ambani-led Reliance Industries
Who was Misha Agrawal? Social media influencer who died two days before her 25th birthday
In the middle of IPL 2025, Sara Tendulkar buys this team, the name is...
Will Seema Haider have to leave India over order to expel Pakistani nationals? She says...
Mumbai: One woman dead, six suffer from suffocation after fire breaks out in Andheri apartment
DNA Verified: Viral video claims massive fire at Lahore's Allama Iqbal Airport, truth is...
J-K: Anantnag Police intensifies anti-terror operations following Pahalgam attack
Pakistan ready for neutral probe, says Shehbaz Sharif on Pahalgam terror attack