Icasa tightens online security
The Independent Communications Authority of South Africa (Icasa), has put strict controls in place to ensure that there is no leakage of complainants’ personal information from their website.
Last month, Moneyweb revealed how the regulator’s website displayed a technical glitch that allows visitors to view personal information of individuals who have submitted complaints to the regulator. When submitting complaints, disgruntled clients would be asked to upload certain documentation that would substantiate the grievances against various service providers. Sensitive documentation such as ID’s and bank statements were also included.
At the time Icasa spokesperson Paseka Maleka confirmed that these documents were meant to be confidential and had said that the body would initiate an investigation into the allegations after being discovered by a Moneyweb community member, who first alerted us to the issue.
In a written statement, Maleka said, “The Authority took it upon itself to engage the service provider for investigation. The service provider confirmed that this is indeed a problem as it was possible for someone to change the file reference number and then be able to view someone else’s information. Whilst no information was intentionally leaked, access to the data was in fact very limited.”
Maleka says several problems were identified and the feature has since been disabled. Moneyweb later tested the link that enabled the viewing of these files, and was met with the words “Access denied” written in a bold red colour on the screen.
Icasa has made a commitment to ensure that “all complaints are treated with the strictest confidentiality.” Complainants will be advised against sending any personal or financial documentation as part of the complaints procedure. More importantly the regulator has “resolved to expedite the procurement of a Secure Sockets Layer (SSL) certificate for the Icasa website. This is a security certificate similar to those used by financial institutions and it will enhance the security and also encrypt the data,” said Maleka.
“The body had also scheduled with the service provider to discuss this problem and identify steps to ensure this does not reoccur.”
The regulator appears to have taken the matter seriously as discussions to safeguard the website from being hacked have also been held.
Source: Moneyweb