bitcoin
bitcoin

$102194.892188 USD

0.65%

ethereum
ethereum

$3861.162469 USD

-1.30%

tether
tether

$0.999502 USD

-0.05%

xrp
xrp

$2.420252 USD

-1.80%

solana
solana

$219.194865 USD

-2.99%

bnb
bnb

$710.312314 USD

-1.80%

dogecoin
dogecoin

$0.399426 USD

-1.97%

usd-coin
usd-coin

$0.999829 USD

0.00%

cardano
cardano

$1.092021 USD

-1.50%

tron
tron

$0.281388 USD

-4.92%

avalanche
avalanche

$49.536149 USD

-6.08%

chainlink
chainlink

$28.824022 USD

-4.55%

shiba-inu
shiba-inu

$0.000028 USD

-2.69%

toncoin
toncoin

$6.228175 USD

-1.90%

polkadot-new
polkadot-new

$8.661050 USD

-3.09%

加密货币新闻

PDPC 表示,身份证号码不应用作密码

2024/12/15 13:39

国家数据隐私监管机构还警告组织不要使用身份证号码来验证个人身份或设置默认密码。

PDPC 表示,身份证号码不应用作密码

The Personal Data Protection Commission (PDPC) has stated that National Registration Identity Card (NRIC) numbers should not be used as passwords.

个人数据保护委员会 (PDPC) 表示,国民注册身份证 (NRIC) 号码不应用作密码。

The data privacy watchdog also warned against organisations using NRIC numbers to authenticate an individual’s identity or set default passwords.

数据隐私监管机构还警告组织不要使用身份证号码来验证个人身份或设置默认密码。

PDPC's statement on Dec. 14 comes after public attention was drawn to the disclosure of NRIC numbers on the Accounting and Corporate Regulatory Authority's (ACRA) new Bizfile portal.

PDPC 在 12 月 14 日发表声明之前,会计与企业监管局 (ACRA) 新的 Bizfile 门户网站上披露的身份证号码引起了公众的关注。

Earlier, the Ministry of Digital Development and Information (MDDI) had said in a statement on Dec. 13 that it intends to move away from the practice of masking NRIC numbers.

此前,数字发展和信息部 (MDDI) 在 12 月 13 日的一份声明中表示,打算放弃掩盖身份证号码的做法。

"As a unique identifier, the NRIC number is assumed to be known, just as our real names are known. As such, there should "not be any sensitivity in having one's full NRIC number made public," MDDI had stated.

MDDI 表示:“作为唯一标识符,身份证号码被假定为已知,就像我们的真实姓名已知一样。因此,“公开一个人的完整身份证号码不应该有任何敏感性”。

However, PDPC reiterated that like any personal identifier, the NRIC number will still be subjected to the data protection obligations in the Personal Data Protection Act (PDPA).

然而,PDPC 重申,与任何个人标识符一样,身份证号码仍将受到《个人数据保护法》(PDPA) 中数据保护义务的约束。

Use of NRIC numbers by individuals as passwords

个人使用身份证号码作为密码

According to PDPC, the NRIC number should not be used as a password, just as personal names are not used as passwords.

根据 PDPC 的规定,身份证号码不应用作密码,就像个人姓名不应用作密码一样。

"Anyone who has done so should immediately change their password," the commission emphasised.

该委员会强调:“任何这样做的人都应该立即更改密码。”

“If the change function cannot be found on the service portal, it is best to contact the service provider immediately for advice to change the password," it added.

“如果在服务门户上找不到更改功能,最好立即联系服务提供商以获取更改密码的建议,”它补充道。

Use of NRIC numbers by organisations for authentication

组织使用 NRIC 号码进行身份验证

PDPC stated that as the NRIC number is not a secret, it should not be used by an organisation for authentication purposes.

PDPC 表示,由于 NRIC 号码不是秘密,因此组织不应将其用于身份验证目的。

"A person’s name and NRIC number identifies who the person is. Authentication is about proving you are who you claim to be. This requires proof of identity, for example, through a password, a security token or biometric data," it explained.

“一个人的姓名和身份证号码可以识别这个人是谁。身份验证是为了证明你就是你所声称的人。这需要身份证明,例如通过密码、安全令牌或生物识别数据,”它解释道。

The watchdog added that action will be taken against organisations who have used NRIC numbers for authentication.

该监管机构补充说,将对使用身份证号码进行身份验证的组织采取行动。

PDPC also advised that the NRIC number should not be used as the default password for services provided to an individual and organisations that have such practices are advised to phase them out as soon as possible.

PDPC 还建议,不应将身份证号码用作向个人提供的服务的默认密码,并建议有此类做法的组织尽快逐步淘汰。

While the government is moving away from masking the NRIC number, the number is still subject to the data protection obligations in the Personal Data Protection Act (PDPA), PDPC said.

PDPC 表示,虽然政府不再屏蔽身份证号码,但该号码仍受《个人数据保护法》(PDPA) 中数据保护义务的约束。

Therefore, organisations collecting NRIC data must still obtain valid consent and comply with reasonable use and ensure protection, it added.

因此,收集身份证数据的组织仍必须获得有效同意并遵守合理使用并确保保护。

PDPC's advisory guidelines

PDPC 的咨询指南

Following MDDI's statement on the appropriate use and mis-use of NRIC numbers, PDPC has received questions and feedback from the public, it said.

MDDI 就身份证号码的正确使用和滥用发表声明后,PDPC 收到了公众的问题和反馈。

"We recognise that the PDPC advisory guidelines for NRIC and National Identification Numbers needs to be updated to be aligned with the statement," it said.

声明称:“我们认识到,PDPC 针对身份证和国民身份证号码的咨询指南需要更新,以与声明保持一致。”

"We are sorry for the confusion caused to the public and will fully address the public’s concerns and questions as soon as possible."

“对于给公众带来的困惑,我们深表歉意,并将尽快全面解答公众的关切和疑问。”

The commission said it will not be making any further changes until they have completed consultations with industry and members of the public.

该委员会表示,在完成与行业和公众的协商之前,不会做出任何进一步的改变。

The guidelines will then be updated to align with the new policy intent, PDPC added.

PDPC 补充说,随后将更新指导方针,以符合新的政策意图。

NRIC numbers publicly listed on new ACRA website

新 ACRA 网站上公开列出的 NRIC 号码

A recently-launched digital portal by the Accounting and Corporate Regulatory Authority (ACRA) was found to have a somewhat alarming new feature: the ability to search for citizens' NRIC numbers.

会计和企业监管局 (ACRA) 最近推出的数字门户网站被发现有一个令人担忧的新功能:能够搜索公民的身份证号码。

Through the platform's new "People Profile" feature, Singaporeans' full NRIC numbers can be searched, simply by keying in the citizen's name.

通过该平台新的“人员档案”功能,只需输入公民姓名即可搜索新加坡人的完整身份证号码。

This included politicians and people who were deceased.

其中包括政治家和死者。

The feature was described as a means to help users "search for business information" and "[track] the business entities a person is/was involved in", according to the website.

据该网站称,该功能被描述为帮助用户“搜索商业信息”和“[跟踪]一个人正在/曾经参与的商业实体”的一种手段。

In a Frequently Asked Questions segment about the platform, ACRA explained that the NRIC numbers are not masked to allow for "clear and unambiguous identification of individuals associated with businesses".

在有关该平台的常见问题部分中,ACRA 解释说,身份证号码不会被隐藏,以便“清晰、明确地识别与企业相关的个人”。

In 2019, the Personal Data Protection Commission (PDPC) announced that organisations would be legally barred from collecting, using, or disclosing NRIC numbers.

2019 年,个人数据保护委员会 (PDPC) 宣布法律禁止组织收集、使用或披露身份证号码。

Top photo from ICA

来自 ICA 的顶级照片

新闻来源:mothership.sg

免责声明:info@kdj.com

The information provided is not trading advice. kdj.com does not assume any responsibility for any investments made based on the information provided in this article. Cryptocurrencies are highly volatile and it is highly recommended that you invest with caution after thorough research!

If you believe that the content used on this website infringes your copyright, please contact us immediately (info@kdj.com) and we will delete it promptly.

2024年12月15日 发表的其他文章