Skip to main content

Government / Agriculture

Krushak Odisha: CERT-In cyber security audit

Security audit of the farmer identity and benefit-delivery registry for the state of Odisha.

Scale

State farmer registry

Government of Odisha

  • CERT-In Audit
  • VAPT

The brief

CERT-In empanelled audit of the farmer registry and benefit platform for Odisha.

What we did

  • Application and API assessment of the registry and benefit workflows
  • Authorisation testing across farmer, verifier and administrative roles
  • Personal data handling review against DPDP Act 2023 obligations
  • CERT-In audit report, remediation support and retesting

Krushak Odisha is a farmer registry, which means it holds identity and land data for a very large population with comparatively little recourse if that data is misused. The security question and the dignity question are the same question here.

Registry platforms have a particular weakness

The value of a registry is lookup. The risk of a registry is also lookup. Almost every serious exposure we have seen on platforms of this shape came from a search or verification endpoint that was designed for legitimate bulk use and could be driven by someone who was not entitled to it.

We tested those endpoints specifically: rate limiting, authorisation on lookup, what an authenticated low privilege account could enumerate, and whether identifiers were sequential enough to walk.

Verification workflows

A benefit registry has a verification chain, and each step is a role with a different view of the data. We tested each role's actual reach against its intended reach, including what happens when a record moves between states and whether a role retains visibility it should have lost.

Data protection observations

Alongside the security findings we recorded observations relevant to the DPDP Act 2023: what is collected against what is used, retention, and whether access to personal data is logged in a way that would let the department answer a question about who looked at what.

These are not security findings in the traditional sense and we report them separately, because they belong to a different owner inside the department.

What was handed over

CERT-In format audit report, separate data protection observations, remediation support and retesting through to certificate.

Audit type
CERT-In empanelled
Emphasis
Registry lookup and enumeration
Also covered
DPDP Act 2023 observations

Engagement detail is summarised. Specific findings, payloads and architecture remain confidential under our client agreements.

Not sure where to start?

Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.