bitcoin
bitcoin

$102268.149013 USD

0.78%

ethereum
ethereum

$3861.671504 USD

-1.02%

tether
tether

$0.999513 USD

-0.05%

xrp
xrp

$2.423163 USD

-1.42%

solana
solana

$219.179909 USD

-2.93%

bnb
bnb

$710.183650 USD

-1.73%

dogecoin
dogecoin

$0.399372 USD

-1.85%

usd-coin
usd-coin

$0.999901 USD

0.00%

cardano
cardano

$1.089706 USD

-1.53%

tron
tron

$0.281241 USD

-4.80%

avalanche
avalanche

$49.476557 USD

-6.15%

chainlink
chainlink

$28.850816 USD

-4.15%

shiba-inu
shiba-inu

$0.000028 USD

-2.53%

toncoin
toncoin

$6.228457 USD

-1.70%

polkadot-new
polkadot-new

$8.673529 USD

-2.78%

加密貨幣新聞文章

PDPC 表示,身分證號碼不應用作密碼

2024/12/15 13:39

國家資料隱私監管機構也警告組織不要使用身分證號碼來驗證個人身分或設定預設密碼。

PDPC 表示,身分證號碼不應用作密碼

The Personal Data Protection Commission (PDPC) has stated that National Registration Identity Card (NRIC) numbers should not be used as passwords.

個人資料保護委員會 (PDPC) 表示,國民註冊身分證 (NRIC) 號碼不應用作密碼。

The data privacy watchdog also warned against organisations using NRIC numbers to authenticate an individual’s identity or set default passwords.

資料隱私監管機構也警告組織不要使用身分證號碼來驗證個人身分或設定預設密碼。

PDPC's statement on Dec. 14 comes after public attention was drawn to the disclosure of NRIC numbers on the Accounting and Corporate Regulatory Authority's (ACRA) new Bizfile portal.

PDPC 在 12 月 14 日發表聲明之前,會計與企業監管局 (ACRA) 新的 Bizfile 入口網站上披露的身份證號碼引起了公眾的關注。

Earlier, the Ministry of Digital Development and Information (MDDI) had said in a statement on Dec. 13 that it intends to move away from the practice of masking NRIC numbers.

此前,數位發展和資訊部 (MDDI) 在 12 月 13 日的聲明中表示,打算放棄掩蓋身分證號碼的做法。

"As a unique identifier, the NRIC number is assumed to be known, just as our real names are known. As such, there should "not be any sensitivity in having one's full NRIC number made public," MDDI had stated.

MDDI 表示:「作為唯一標識符,身分證號碼被假定為已知,就像我們的真實姓名已知一樣。因此,「公開一個人的完整身分證號碼不應該有任何敏感性」。

However, PDPC reiterated that like any personal identifier, the NRIC number will still be subjected to the data protection obligations in the Personal Data Protection Act (PDPA).

然而,PDPC 重申,與任何個人識別碼一樣,身分證號碼仍將受到《個人資料保護法》(PDPA) 中資料保護義務的約束。

Use of NRIC numbers by individuals as passwords

個人使用身分證號碼作為密碼

According to PDPC, the NRIC number should not be used as a password, just as personal names are not used as passwords.

根據 PDPC 的規定,身分證號碼不應用作密碼,就像個人姓名不應該用作密碼一樣。

"Anyone who has done so should immediately change their password," the commission emphasised.

該委員會強調:“任何這樣做的人都應該立即更改密碼。”

“If the change function cannot be found on the service portal, it is best to contact the service provider immediately for advice to change the password," it added.

「如果在服務入口網站上找不到更改功能,最好立即聯繫服務提供者以獲取更改密碼的建議,」它補充道。

Use of NRIC numbers by organisations for authentication

組織使用 NRIC 號碼進行身份驗證

PDPC stated that as the NRIC number is not a secret, it should not be used by an organisation for authentication purposes.

PDPC 表示,由於 NRIC 號碼不是秘密,因此組織不應將其用於身份驗證目的。

"A person’s name and NRIC number identifies who the person is. Authentication is about proving you are who you claim to be. This requires proof of identity, for example, through a password, a security token or biometric data," it explained.

「一個人的姓名和身分證號碼可以識別這個人是誰。身份驗證是為了證明你就是你所聲稱的人。這需要身份證明,例如透過密碼、安全令牌或生物識別數據,」它解釋道。

The watchdog added that action will be taken against organisations who have used NRIC numbers for authentication.

該監管機構補充說,將對使用身分證號碼進行身份驗證的組織採取行動。

PDPC also advised that the NRIC number should not be used as the default password for services provided to an individual and organisations that have such practices are advised to phase them out as soon as possible.

PDPC 還建議,不應將身分證號碼用作向個人提供的服務的預設密碼,並建議有此類做法的組織盡快逐步淘汰。

While the government is moving away from masking the NRIC number, the number is still subject to the data protection obligations in the Personal Data Protection Act (PDPA), PDPC said.

PDPC 表示,雖然政府不再封鎖身分證號碼,但該號碼仍受《個人資料保護法》(PDPA) 中資料保護義務的約束。

Therefore, organisations collecting NRIC data must still obtain valid consent and comply with reasonable use and ensure protection, it added.

因此,收集身分證資料的組織仍必須獲得有效同意並遵守合理使用並確保保護。

PDPC's advisory guidelines

PDPC 的諮詢指南

Following MDDI's statement on the appropriate use and mis-use of NRIC numbers, PDPC has received questions and feedback from the public, it said.

MDDI 就身分證號碼的正確使用和濫用發表聲明後,PDPC 收到了公眾的問題和回饋。

"We recognise that the PDPC advisory guidelines for NRIC and National Identification Numbers needs to be updated to be aligned with the statement," it said.

聲明中寫道:“我們認識到,PDPC 針對身份證和國民身份證號碼的諮詢指南需要更新,以與聲明保持一致。”

"We are sorry for the confusion caused to the public and will fully address the public’s concerns and questions as soon as possible."

“對於給公眾帶來的困惑,我們深表歉意,並將盡快全面解答公眾的關切和疑問。”

The commission said it will not be making any further changes until they have completed consultations with industry and members of the public.

該委員會表示,在完成與業界和公眾的協商之前,不會做出任何進一步的改變。

The guidelines will then be updated to align with the new policy intent, PDPC added.

PDPC 補充說,隨後將更新指導方針,以符合新的政策意圖。

NRIC numbers publicly listed on new ACRA website

新 ACRA 網站上公開列出的 NRIC 號碼

A recently-launched digital portal by the Accounting and Corporate Regulatory Authority (ACRA) was found to have a somewhat alarming new feature: the ability to search for citizens' NRIC numbers.

會計和企業監管局 (ACRA) 最近推出的數位入口網站被發現有一個令人擔憂的新功能:能夠搜尋公民的身分證號碼。

Through the platform's new "People Profile" feature, Singaporeans' full NRIC numbers can be searched, simply by keying in the citizen's name.

透過該平台新的「人員檔案」功能,只需輸入公民姓名即可搜尋新加坡人的完整身分證號碼。

This included politicians and people who were deceased.

其中包括政治家和死者。

The feature was described as a means to help users "search for business information" and "[track] the business entities a person is/was involved in", according to the website.

據該網站稱,該功能被描述為幫助用戶「搜尋商業資訊」和「[追蹤]一個人正在/曾經參與的商業實體」的一種手段。

In a Frequently Asked Questions segment about the platform, ACRA explained that the NRIC numbers are not masked to allow for "clear and unambiguous identification of individuals associated with businesses".

在有關該平台的常見問題部分中,ACRA 解釋說,身分證號碼不會被隱藏,以便「清晰、明確地識別與企業相關的個人」。

In 2019, the Personal Data Protection Commission (PDPC) announced that organisations would be legally barred from collecting, using, or disclosing NRIC numbers.

2019 年,個人資料保護委員會 (PDPC) 宣布法律禁止組織收集、使用或揭露身分證號碼。

Top photo from ICA

來自 ICA 的頂級照片

新聞來源:mothership.sg

免責聲明:info@kdj.com

The information provided is not trading advice. kdj.com does not assume any responsibility for any investments made based on the information provided in this article. Cryptocurrencies are highly volatile and it is highly recommended that you invest with caution after thorough research!

If you believe that the content used on this website infringes your copyright, please contact us immediately (info@kdj.com) and we will delete it promptly.

2024年12月15日 其他文章發表於