LCI Learning

Share on Facebook

Share on Twitter

Share on LinkedIn

Share on Email

Share More

Jayanta Bandyopadhyay   24 October 2024

Custodian of dsc (digitial signature certificate)

DSCs of Directors are mostly kept at Secretarial Depts. or outsourced shared services offices. There is an exposure to misuse.

Is there any guideline by MCA about usage of DSC thru' registered IP (Computer)? 

 



Learning

 3 Replies

T. Kalaiselvan, Advocate (Advocate)     25 October 2024

What are the possible misuses of digital signature certificates?

Digital signature certificates (DSCs) are crucial for ensuring the authenticity and integrity of electronic documents. However, they can be misused in several ways:

 

Unauthorized Signing: If a digital signature certificate is obtained or accessed by an unauthorized individual, they can sign documents on behalf of the legitimate certificate holder, leading to fraud.

Phishing Attacks: Attackers may create fake websites that closely resemble legitimate ones to trick users into providing their digital signature credentials, which can then be used for malicious purposes.

Certificate Theft: If a certificate is not securely stored, it can be stolen, allowing the thief to sign documents or transactions fraudulently.

Replay Attacks: Attackers can capture signed documents and reuse them in different contexts, potentially leading to unauthorized transactions or agreements.

Misleading Authenticity: Digital signatures can create a false sense of security. If users do not verify the signer's identity or the integrity of the document, they may trust a signed document that is actually fraudulent.

Revocation Challenges: If a certificate is compromised, revoking it can be difficult. If users do not regularly check the revocation status, they may inadvertently rely on a compromised certificate.

Weak Encryption: Using weak cryptographic methods can lead to vulnerabilities that attackers can exploit to forge signatures or compromise the integrity of signed documents.

Insider Threats: Employees with access to digital signature certificates may misuse them for unauthorized transactions or to commit fraud against their own organization.

Inadequate Policies: Organizations that do not have strong policies and procedures for managing digital signatures may inadvertently allow misuse, such as sharing credentials or not properly auditing signed documents.

To mitigate these risks, it is essential to implement strong security practices, including secure storage of certificates, regular audits, employee training, and using robust authentication methods.

Dr. J C Vashista (Advocate )     25 October 2024

Very well explained by learned expert Mr. T Kalaiselvan, nothing more.

Is it a legal dispute / problem vis-a-vis query for consideration and obligation of experts on this platform ?

Jayanta Bandyopadhyay   25 October 2024

Sir, there is a growing family dispute. There could be a vertical split of family business. So far everything going smoothly . Based on verbal instructions of directors  office was putting DSC. Now, staffs are under threat. Except MNC and big cos, most small companies prepare docs at back end without a formal meeting.

Regards 


Leave a reply

Your are not logged in . Please login to post replies

Click here to Login / Register