◉ HEADLINES

PTPTN draws online ire for negating X user’s exposé of potential web security issues

Agency cites CCA, PDPA against netizen for posting report detailing threat level of its corporate webpage, triggering criticism

10:44 PM MYT

 

KUALA LUMPUR – The National Higher Education Fund (PTPTN) has received online brickbats after it invalidated an X user’s concern over the agency’s website security.  

Last night, the user who uses the handle @HilmiAdi posted a screenshot listing supposed cyber vulnerabilities and a report detailing the threat level of “passive web application vulnerabilities” on PTPTN’s website, which appears to be a corporate webpage.  

@HilmiAdi’s X post.

Responding to the now-deleted post, PTPTN’s official X account said that its inspection of the posting found that the user had violated the Communications and Multimedia Act 1998, the Computer Crimes Act (CCA) 1997 and the Personal Data Protection Act (PDPA) 2010.  

“To avoid any possible misunderstanding or other implications due to this post, we respectfully request that the post be removed from your social media platforms immediately or before 10pm on January 29,” it added.  

PTPTN’s response to the concerned citizen has drawn the ire of other X users, who lambasted the agency for its “threats” against the original account owner. 

Among those who criticised the agency was Umno communications director Datuk Lokman Noor Adam, who also cautioned PTPTN against stoking the people’s displeasure with government entities.  

“When the rakyat informs us of details that could potentially harm us, we should thank them, check the veracity of their claims and never respond by threatening them.  

“Do not increase the people’s hatred towards the government with this kind of arrogant attitude,” he said.  

Samantha Chong, a former press secretary with the Prime Minister’s Department, also pressed PTPTN to disclose how the posting violated any law while raising her grouses with its website.  

Expressing similar sentiments, user @fdajesfry said that PTPTN should be thankful that there are citizens who volunteered to improve its website security while another user, @woody2shoez, admonished the agency for supposedly “shooting the whistleblower.”  

“Is this the quality of an organisation that looks over millions of ringgit of taxpayers’ money?” the latter asked.  

User @DanisyEisyraf also questioned PTPTN’s assertion of the original post violating the CCA, saying: “It’s a simple vulnerability scanner. Anyone can do it and it’s a critical step for VA (vulnerability assessment). It’s not even a pen test (penetration test).  

“It’s not (a) modification (and) it’s not unauthorised access, so how is it chargeable under the CCA?” he asked. – January 29, 2024 

Topics

 

◉ Popular

Worrying number of youth spending 18 hours on social media daily: MCMC 

The Malaysian Communications and Multimedia Commission has drawn attention to the substantial number of young individuals who spend extended periods online, expressing concerns about harmful aspects of specific social media platforms. 

Penang’s shores in peril: a deadly mix of climate change and coastal development”

Rising sea levels, erratic weather, and unchecked development are driving coastal erosion to alarming new heights in Penang, threatening both nature and livelihoods.

What does AGC say about withdrawing police reports? – Hafiz Hassan 

According to its e-Participation Policy portal, complainant may submit an application so no action taken on lodged report but decision lies with public prosecutor

◉ Related