close

Telecommunications Authority Website Found Insecure, Exposes Risk Of User Data Theft

Techpana Techpana

पुस ३, २०८२ १७:५४

Telecommunications Authority Website Found Insecure, Exposes Risk Of User Data Theft

Kathmandu: The official website of Nepal’s telecommunications regulator has been found to be insecure. When users open the site, a “Not Secure” warning appears in the browser address bar.

Experts say this is a serious concern. The institution responsible for setting national standards on digital infrastructure and cybersecurity is itself failing to meet basic security requirements.

Such warnings usually appear when an SSL/TLS (Secure Sockets Layer or Transport Layer Security) certificate has expired or is improperly configured. An SSL certificate encrypts data exchanged between a user’s browser and the website’s server. Without it, the connection becomes vulnerable.

Because of this flaw, any personal information entered on the website may be exposed. The authority’s website hosts sensitive services, including mobile IMEI registration and an online complaint management system. These platforms require users to submit personal details.

Cybersecurity experts warn that, in this condition, user data could be intercepted through man-in-the-middle attacks. The issue also reflects poorly on the regulator’s technical preparedness at a time when the government is promoting the vision of a “Digital Nepal.”

The regulator’s failure to follow basic cybersecurity practices sends a negative message to the public and to the telecom and internet service providers it oversees.

Users are advised not to enter personal details or passwords on the website until the issue is fully resolved. Accessing the site through public or unsecured Wi-Fi networks is also strongly discouraged.

Responding to the issue, Roja Kiran Basukala, Deputy Director at the Authority’s Legal Research and Development Branch, said the SSL certificate is still valid. She claimed there is no major problem with the website.

“It is not time for the SSL certificate to expire. If there is any technical issue, we will check it and fix it,” she said.

 

पछिल्लो अध्यावधिक: पुस ३, २०८२ १७:५४