Details of students breached due to DU admit card portal glitch

University introduces OTP system to resolve the issue

July 03, 2020 12:08 am | Updated 12:08 am IST - New Delhi

A picture taken on October 17, 2016 shows an employee typing on a computer keyboard at the headquarters of Internet security giant Kaspersky in Moscow. / AFP PHOTO / Kirill KUDRYAVTSEV / TO GO WITH AFP STORY BY Thibault MARCHAND

A picture taken on October 17, 2016 shows an employee typing on a computer keyboard at the headquarters of Internet security giant Kaspersky in Moscow. / AFP PHOTO / Kirill KUDRYAVTSEV / TO GO WITH AFP STORY BY Thibault MARCHAND

Personal details of over 2,000 students, especially of Delhi University’s Faculty of Law, were left poorly secured on the university’s admit card portal till Thursday evening.

The Hindu was able to access over 30 admit cards of students from the Campus Law Centre, Law Centre 1 and Law Centre 2, containing their personal details due to the breach.

‘Easily accessible’

Dean of Examinations Vinay Gupta admitted that there was an issue, especially with the Faculty of Law students as details from the previous semester were accessible from the results page of the university’s website.

To access the admit cards, only three fields were required to be filled up: students’ names, roll numbers and a college ‘gateway code’, which was a single code issued to all students for a particular institution.

In the case of the Law Faculty Centres, students informed that the college code for all three centres were circulated on the WhatsApp group. Using this, combined with the information available online, personal details of all final-year students could be accessed. Students of other colleges also informed that it was very easy to identify the roll number of a fellow student given that they were sequentially organised. “It would be very easy to get this information using it,” said a Ramjas College student.

Changes were made to the process after The Hindu reached out for comments, Mr. Gupta confirmed. An OTP system was introduced for students to get their admit cards after submitting a password to unlock it. The OTP would be sent to their registered email accounts, Mr. Gupta said.

The issue was initially raised by Vivek Prasad, a final-year CLC student on social media. “Delhi University’s online admit cards are a privacy disaster!...Anyone with college code [easily known] can access any student’s admit card...and see the address” he tweeted, detailing the issue. Mr. Prasad said that the the gateway code had been sent late last night.

Student’s group NSUI, raised concerns over the issue, arguing that personal details of women students could be used by stalkers as well as by private coaching institutes. Highlighting that the university had made other mistakes in the open book examination process, the NSUI argued that the exam should be cancelled.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.