Govt intends to stop masking NRIC numbers, says there is not 'much value in doing so'

  • Have you been Scammed?
    Follow this advisory from National Crime Prevention Council (NCPC) or call ScamShield Helpline 1799. More info

Should lw step down?


  • Total voters
    108

ninjaghost

Supremacy Member
Joined
Feb 23, 2019
Messages
9,428
Reaction score
3,783
social engineering technique can make good used of this information.
i can provide scenario like:
crawlers can even write a script to do interval crawling without using same ip addr if they able to identify and target all the high value victim. Even they didn't process any further malicious actions, they can even selling the high net worth target list in black market.

important anot i'm not sure, this is for you to judge.
 

PaboJames

Arch-Supremacy Member
Joined
Nov 13, 2013
Messages
11,816
Reaction score
4,970
My login ID is my company email. If you assume a person's company email to be his login ID, I think you will be right half the time.

That is why many companies issues different IDs from their staff ID, surname and emails for system logins

unless they are going to change how we login to Singpass.... that one is a potential problem
 

ckling

Arch-Supremacy Member
Joined
Apr 29, 2002
Messages
18,353
Reaction score
506
NRIC is like address, last time even got yellow pages publish all phone number
 

Philipkee

High Supremacy Member
Joined
Jun 8, 2013
Messages
26,493
Reaction score
15,625
NRIC is like address, last time even got yellow pages publish all phone number
Yes. But last time it’s not so easy to do so much harm with basic info. Like last time you can get name phone number address from yellow pages but you are not going to be able to cancel bank accounts with just this info over the phone or online
 

Mr BBFA

Supremacy Member
Joined
Oct 29, 2020
Messages
6,381
Reaction score
3,702

Blacky

Senior Member
Joined
Sep 25, 2002
Messages
1,528
Reaction score
701
There must be a strong reason why pdpa covered NRIC numbers as confidential info to begin with.

why now U-turn?

because some ex-reporter found a huge breach in one of Govt agency, so in order not to impeach themselves, just change some rules to make it not at fault?

noticed anywhere the minister heads, sure have huge saga?
Perhaps after the online posts about this issue, they had to come out with some fire-fighting excuse.

But this makes them look very bad....All this while advising people how to avoid scams etc, but yet they are planning to go ahead with this
 

deathan9el

Honorary Mentor
Joined
Jun 27, 2005
Messages
435,647
Reaction score
92,088
so .. then how now? :s11:
usually there's a need to fill in our IC no. but for the last 3 numbers & the alphabet? :s11:

e.g SXXXX123A
 

TopGun

High Supremacy Member
Joined
Jan 1, 2000
Messages
44,648
Reaction score
7,033
That is why many companies issues different IDs from their staff ID, surname and emails for system logins

unless they are going to change how we login to Singpass.... that one is a potential problem

Login ID is not confi but password is. And 2FA is needed as a 2nd level of authentication. Login ID is never assumed to be confi, and given that it's typed out in clear text.

I don't see an issue with Singpass. There's facial recognition when one is setting up the app. For direct login, there's password and then lockout after 3 or 5 wrong attempts.
 

I_am_bored

Senior Member
Joined
Feb 10, 2014
Messages
2,326
Reaction score
910
To those who kept saying " last time is ok to reveal etc", well, last time we didn't have so many channels or contact points for scammers to exploit.

Also, it's not possible to wipe out savings of victims last time digitally.
 

PaboJames

Arch-Supremacy Member
Joined
Nov 13, 2013
Messages
11,816
Reaction score
4,970
Login ID is not confi but password is. And 2FA is needed as a 2nd level of authentication. Login ID is never assumed to be confi, and given that it's typed out in clear text.

I don't see an issue with Singpass. There's facial recognition when one is setting up the app. For direct login, there's password and then lockout after 3 or 5 wrong attempts.

Having your ID exposed already helped in the first step.
Not everyone uses facial authentication on Singpass... quite a big portion don't

maybe other pranks like the previous thread about some guy kpkb all card got cancelled while he is in japan
 

testart

Greater Supremacy Member
Joined
Jun 15, 2012
Messages
93,269
Reaction score
14,099
2FA?

Username + Password + Phone OTP.

Sure scammers can still make boomer download app on their phone and willingly handover username and password, but better than nothing...

NRIC should not be used for authentication/verification to start with. Identification yes.

NRIC has not been kept private since inception and this allows scammers to exploit a broken system. So the way forward is to drop NRIC as a way to authenticate/verify a person's identify.
Yes. Like google username and bank user ID

no need NRIC
 
Important Forum Advisory Note
This forum is moderated by volunteer moderators who will react only to members' feedback on posts. Moderators are not employees or representatives of HWZ. Forum members and moderators are responsible for their own posts.

Please refer to our Community Guidelines and Standards, Terms of Service and Member T&Cs for more information.
Top