Maha Kumbh 2025 was the event with highest recorded gathering of humans ever known. About 670 million people visited the Kumbh and took a dip at the river junction of Prayagraj, within period of about 45 days. There was lot of publicity and hype around this event even before it started. I also got interested in it and participated in the same. Watching the event and the buzz around it, I could say there are a lot of dimensions around this event. I will share what were mine and some of the most widely know theories.
Thoughts
Tuesday, April 22, 2025
Maha Kumbh Mela 2025
Tuesday, April 30, 2024
Maya OS - Interesting Journey
There was a recent announcement of the release of Maya OS in India. I saw that news and got interested. There were lot of comments on X as well about the fact that Maya OS is based on Ubuntu. It should have been based on Debian, a more stable and secure platform. Being interested in the domain of security, this was enticing for me. So I looked at it from different vantage points.
From a high level view, I see a trend where lot of nations are trying to get out of Windows OS. There was a news of Germany and Russia treading the same path. Below is the list of reasons.
- Windows being a product from US head quartered company, there is a risk wherein state administration can force Windows to behave in an adversarial fashion for the rest of the world. This is not hypothetical. There are too many instances of the same starting with financial sanctions for outright adversary to controlling the functionality of defense technology sold to allies that will work only to the extant allowed by state administration of the seller. One can argue that in very secure environments that are within controlled network, it is difficult to exercise the level of control from outside. But, as we move forward in time, we see the operating systems need more and more network feature and some form of connection to the mother ship(OS company) for upgrades or other aspects. It is operationally difficult to prevent payloads being passed from mothership to individual devices hosting the OS. Lot of nations and nation groups have launched their own GPS satellites for the similar reason.
- With so many devices hosting Windows, there is lot of focus and surface area ready to be exploited by bad actors. With such a large pool, comes out large pool of vulnerabilities.
- Countries using specific OS within small number of critical departments provide a very small surface area to be exploited by large number of attackers. Only the dedicated and state funded actors generally focus on attacking these devices. So you kind of raise the cost of attack for the attacker. They can't pick easily available vulnerability, rather they will have to develop something by themselves.
- Reducing software supply chain risk is big part of this effort where the state should have few options and some of them controlled by the state itself rather someone outside the state.
- Saving forex can be a motivator. But, very low in the list if at all. This is true specially when it comes to government departments. If some of these OS turn out to be user friendly and the state if ready to allow civilian use, then saving forex for general public becomes a decent motivation.
The Chaos
When I was looking for this topic, I found there is another OS called Bharat OS that was released some time back and is also in use in certain pockets. Bharat OS is trying to provide alternative to Android. The reviews suggest BOSS version 9 and above are really smooth to work with. It is based on Debian OS. This was developed by state owned company called C-DAC. The same company is involved in development and launch of Maya OS as well, which is Ubuntu OS based OS. The look and feel of Maya OS is very close to Windows 11. So looks C-DAC is releasing different operating systems to provide for different level of user experience and security combination products. This will help ease the transition out of Windows. To maintain an operating system is no easy task. Managing more than one makes it even more difficult. This is going to be a journey for sure.
The Order
Intent seems right. There are few thousand employees in the C-DAC and other partner organizations launching the Operation Systems. With that type of human resources, it should be possible to manage the OS and the journey. Looking at the history of this effort so far, I can see few years have passed and there are versions released over time. So this doesn't look like one off release and forget. The initiative is very much alive. This opportunity create a very large talent pool that has product development and management experience. I can see this will help software product development in other spaces as well. India has done well in software services space. But, not so much in software product creation so far. I can see initiatives like this will help on software product creation side.
India had an option of not wasting time and money on such initiatives and keep using Windows/Android products just like most of the world does. They picked up an hard but India first kind of initiative. There are many other examples I see in recent past, be in terms of UPI development and use when they already had VISA/Mastercard or even Rupay network for payments. One off right initiatives can be result of chance. But, when you see more than one thing going in right direction, it gives you a sense of nation starting to move in right direction. We will see lot of failures and missteps along the way. That is natural. As someone really smart said, "Failure doesn't matter, success does", we will have to look for successes and not get bogged down too much about failures to see the trajectory of nation. I think it is time to bet in favor of the this country now.
Tuesday, January 9, 2024
Evolving phone scam landscape
Lot of us have heard of someone getting scammed over the phone. Typically it is the result of some action triggered by the scammer by reaching out to the target via phone call/email/message. I have seen lots of instances where one of these channels was utilized.
Recently, I came across
another type of attack where the scammer sets up a bait, then waits and lets
the victim reach out to the scammer. The attack scenario is like this. The
victim placed an order on a trusted website like amazon. The order was paid for
via credit card. Now, the victim didn’t get the order and the order suddenly
disappears on the amazon website. The initial part of the flow looks something like
as shown below wherein the trap is set up by scammers and then they wait for
some issue to happen on third party retailers like Amazon and the affected
customer to call them.
By relaying back the name
and amount associated with the order, scammers gain confidence of the victim
that they have reached the right support even when they didn’t get a callback
from the retailer. As part of user security training over the years, it has
been taught to not trust the call you get but always call the publicly listed
numbers yourself to make sure you are talking to the right people. The scammer
then mentions that there is some system error that is causing the refund to
fail the original payment method. They send a message with a link to click in
order to accept the payment. This link typically contains a malware payload.
Since the confidence level of the victim is high, they do end up clicking the
link and the phone is compromised at this point. Now, the scammer tells the victim
that payment is still failing and if the victim can share other account
details, those accounts will be tried for refund. Victim shares another account
details and the scammer triggers the payment using the victim phone that is
under the control of the scammer. There are OTP messages generated and received
by the victim's phone during the call and those are read by scammers. The
victim still thinks that they didn’t share any OTP with the person on the phone
so they are safe. This is another aspect of security training over the years.
Scammers try to keep the victim on the phone as long as possible in order
to show how helpful they are and also get as many accounts as possible and try
to empty out the accounts. These calls sometimes go as long as an hour. The victim did have some knowledge of scams and basic knowledge
to avoid these by not picking up calls from strangers and never sharing their
OTP passcodes. Still the fraud happened. So far, we covered the How of the
attack. Now, let's get into Who all are responsible for this. It would be naïve
to put blame on one party in the flow. So what are the weak links or points of
failures here.
- First and foremost is the user/victim. They have been trained to avoid clicking any link. They still did it and stuck on call sharing accounts one after the other.
- Retailer is the next participant in this chain that is responsible here. The policy of leaving the holes on older channels as part of either saving operational cost or going after certain demographics can result in those gaps being filled by bad actors. We know that technological change takes time in society. We know people keep switching between the channels over time like paper based mail, phones, Fax, email, Messengers, etc. But different demographics adapt to these channels at different paces. By just switching to the latest channel and avoiding presence over the old channels, the company might be behind a certain demographic. Maybe they just want young customers. For whatever reason these gaps are, they end up being the source of trouble. The other bigger issue from the retailer side is the loss of integrity of data. The sudden disappearance of order from the supported app/website is big damage to trust. A canceled order for whatever reason is better than a disappeared order where customers will get anxious and try to call the support. The retailer on their side does try to make the experience better for users to never have to call the support. But, it doesn’t happen. Good goal but there are failures.
- Search Engines are also responsible for the problem. This one is a little tricky. On one hand, search engines are just gathering information and distributing without validation. The whole argument around the legal protections these platforms enjoy. I get that part. Now where it gets tricky is that we know these platforms are starting to do more than just search and distribute functions. As part of Covid misinformation spread, we have seen the content distribution channels starting to filter or mark articles as not verified or something to stop the misinformation. The major search engines are moving towards AI capabilities telling us they can and will be doing way more than just search and distribute. They apply a lot more checks to control the spread of misinformation.
Now let's cover the
solution. The solution may involve more than one party.
- We will start with the first weak link. User/victim is the first weak link here. One of the strategies to help with the issue will be user training by making them aware of these issues with dos and don’ts. But, with ever evolving threat landscape, we can see that some of the guidelines can help them fail by giving false confidence when the attack is changed. As we can see in the current scenario, the fact that the victims themselves called the scammer and heard some information they expected only the trusted retailer to be aware of and also, they never shared the OTP gave them false confidence. During the interview with the victim, it did come out that they saw the messages from the bank regarding money transfer. But they were confident that no one could take the money out as long as they didn’t tell the OTP to another person, this caused them to ignore all the red flags and still continue on call and support the scammer trying other accounts. We know there is a lag between training start and its impact on the general population. These are generally multi-year cycles. It becomes even more hard when you have to change the original training and those old teachings start to become a problem. Another aspect around user training is that it is important but not foolproof. Some users in certain tricky situations will always fail. So, we will have to think of quickly updating the user security training content, fast distribution. But will still have to assume that this link can fail, and we need to tighten other parts of the flow as well.
- Retailers can take multiple actions to address this. First is to make sure the orders don’t just disappear. We can understand that even retailers would not like this to happen. But the checks on their side need to be more stringent. As of now it is obviously a big known gap that scammers are trying to utilize. Second aspect is to provide contact information in easily accessible ways to force misinformation to be reduced. One of the ways they can use it is to provide contact information in EV certs. If the information is easily available, the search engines of the world can utilize this and mark this verified information.
- Search engines can utilize EV certificates or some other reliable sources of contact information. There is lot of talk about Digital Public Infrastructure. A clean and vetted contact information for business entities seem good candidates for this Digital Public Infrastructure as a home. Search Engines can utilize those in case information is not present in EV certificates.
- Banks/Financial institutions have important role to play here. For one, they employ strong fraud control technologies on the credit card side of the business than the bank account side. Even in case I interviewed, when the scammer tried to charge on credit card account, that was immediately declined. That means from technology perspective, there are tools to help on this problem in terms of fraud that are effective but are not being utilized fully. Another aspect is that use of SMS for OTP got developed as second factor in multi-factor authentication schemes. But with smart phone where caller is using the phone to talk and also get SMS on same phone that is now compromised is not adding much value. Banks need to switch from SMS to towards either hardware token devices or Authenticator apps on the phone. Hardware token devices can present operational challenge in terms of how many devices one will carry in case of multiple accounts at different financial institutions. An Authenticator App on the phone still presents a nice compromise where in order to get the token, there is additional user action required so use does know that token is being generated explicitly and is more difficult to just read the SMS on compromised phone.
Tuesday, December 27, 2022
Attendance
I live in a democracy. One of the issues I hear in some of the countries, which are democracies, is the poor attendance of elected representative in the legislative sessions. Sometimes I think there election governing bodies should debar people from running elections, who have been elected previously and have less than say 70% attendance. If these people have shown lack of commitment towards the position they are running after, then why allow them getting into the race altogether?
Friday, December 2, 2022
Forgot your WiFi password?
It is very common to find yourself in a spot where you need to find the password of your Wifi network whenever you need to setup the same on any new IOT purchase. Below is the way to find the same.
Windows command line:
Netsh wlan show profile name=”Wi-F name” key=clear
Sunday, March 6, 2022
Modern Jesus
Few days back, I saw parts of Maha Shivratri event live from Isha foundation. I have seen few other videos of Sadhguru before. After watching the event, I am starting to see emergence of Sadhguru as modern Jesus. This is a period of big change in the world where there is talk of possible world war 3, we are just passing through Covid as well and lot of other changes in the society are speeding up. ESG concepts are slowly and surely gaining ground. 5 years back, no one would have thought of ESG movement resulting in board level changes in big oil company in US. There are vegan banks coming up. So this period is surely going to command special mention in history when looked upon 50-100 years later. Some of the changes will survive and some won't. But the change is visible. One of the change talked about in Maha Shivratri event is SaveSoil movement. Sadhguru is starting a long bike ride to bring awareness towards goals of saving the soil. This is totally part of ESG efforts that entire world needs. There is lot of acceptance of this effort across color/geography/religion. Apart from the SaveSoil, if you discard/disbelief everything that Sadhguru talks about, you can hardly discount the travel and his age. He surely is very healthy and everyone wants what he has to talk about health. The Maha Shivratri event had live viewership cross 120 million across the digital platforms. So, he has the attention of world, he has ESG on his side and his health mantra as his biggest sales pitch. If someone is a follower of Sadhguru, they will have a lot more to add in his favor. I am just putting down basic minimum that works for him. In a world that is questioning the religion, national boundaries, he is surely emerging as new Jesus with ESG and health practices defining the basic minimum of a new version of religion. He has claimed few times that none of the typical gods had the kind of outreach he has, thanks to social media. Every God had fellowship and resistance. He gets fair share of both. I think the chances of people talking about the lucky people of 2ks who saw Sadhguru live are pretty high. I will be watching him transform to that role.
Thursday, February 17, 2022
Democracy 2.0
I am someone who has lived in democracies throughout my life. Is it perfect way of governance? Clearly not. Is it best way? Probably yes. At least to me. Just like no single medicine is cure for all diseases, democracy in traditional form may not work for all societies in the same way and I do appreciate that fact. Knowing clearly that democracy is not perfect system, I sometimes wonder what can be a perfect or just even a better system of governance. Trying to put down some of my thoughts of what can be done.
1) Wisdom of informed crowd can be better than wisdom of crowd: There are different ways to look at it. One of them being that in traditional democracies, there are groups formed by legislative bodies to help study a problem and come up with recommendations to vote from. Now these groups can be called informed crowd spending time and utilizing SME(Subject Matter Expert) comments to weed out lot of bad options. This is good. But, we still see that the recommendations of these groups/panels are often ignored. We can't get rid of this process still because of the value it brings in cases where the recommendations are followed through. So some level of smartness is part of the process. How about increasing the voting age? As I think about it, I am more inclined towards this option. Seeing my understanding of the world change based on my experiences as I age, I find my self opting for really bad choices during my teens or even twenties. I think the minimum voting age should be 30. No, I didn't just cross 30 recently. I know some might suggest why I am proposing 30, why not 60 or any another number for that matter. If we go very high, we loose on the general representation a lot. Another idea to find right age can be to link it with median age of the country. Just like there are initiates like population surveys that are taken up every few years/decade, the minimum age can be revised and kept little lower than median age so as to still cover most of the people in the country and at the same time tilt it towards people with more experience in life so as to make better choices.
2) We stop appreciating what we have: This is true for most aspects of life. When it comes to democracy or any system of governance, none of which are perfect, lot of negative feelings develop over period of time. For newly created governance systems, there are people who remember the pain of the change. As time passes, we forget the pain as a society and stop appreciating what we have. I was wondering if there should be secured zones in the countries where the traditional governance systems will stop working so people can visit and do whatever they want without any controls that exist in society. Anyone can go there, they can try to become a king if they desire. They can setup any currencies, some sort of government or keep it like a jungle system. No one will stop them. They want to fight till death or have a war with any person/group resisting, they can do that without any charges.Think of it like leaving the country so there is a checkpoint based entry to that region and everyone made aware that anything is fare game in the region they are visiting. After that, it is individual choice. Checkpoint is required to make sure people are not being forced to that part of land just to be killed without any negative consequence. Checkpoints are also required to make sure that stuff not getting carried inside to launch an attack on the other parts of the country. For most practical purposes, this part of land is like foreign country. There will be no service provided by government in these zones. No taxes imposed either. In fact, government can act to create unrest in these zones so as to make sure people don't get comfortable in simulated environment trying to just evade taxes and getting free security from external state. Just like any real country having whatever form of governance, there will always be external influences trying to impact internal dynamics. I am sure most of the people visiting these zones will rediscover the value of what they have or we will invent a better system in that cradle of innovation. One argument against this proposal can be that you let people travel out of the country and same can be done even now. There have been reports of people participating towards overthrowing rulers in foreign land and going to high risk regions and getting killed. The way it is different is that in lot of cases there are diplomatic ties and people can be charged in some cases. In others, the foreign governments can claim that the activity by a citizen are actually motivated by government to achieve foreign policy objectives and result in diplomatic backlash. With a land inside the country, all these complexities can be avoided.
3)Impact of Web 3.0, cryptocurrencies: With Web 3.0 still in its infancy and growth of cryptocurrencies, there are big changes happening. Even the definition of Web 3.0 is too loose to say much about it. I do understand one aspect of Web 3.0 and that is basically creation of global identities. Some might like anonymity provided by internet, Web 3.0 is probably going to result in proper identities. I have heard arguments that you should need a license to get on internet as there is whole lot of negative impact of uninformed or ill intentioned actors spitting out content to harm societies intentionally or unintentionally. With strong identities, we may be able to associate responsibility of actions on internet in better fashion. This can also open up the possibility of wider and more frequent public vote in the field of governance as well. There can be newer capabilities built like asking for vote to issue municipal bonds to fund schools. I have seen those on ballots. I wonder how someone can decide if it is a good option or bad option without any understanding of finance/economics and also the current state of affairs in terms of what is current loan obligation, income, growth projections, etc. So with Web 3.0, we can have a capability built where you can vote and attach your credentials like a degree in economics/finance that is already part of blockchain and linked to your vote. Your vote will only count if it passes the rule check for degree in these fields. It is really hard to predict the future of cryptocurrencies and what shape they will take. But, one change I can see is a move away from state control and going in the direction of global citizenship. This weakens the national identity and any type of governance. I have lot of doubts about current state structures letting the control go away that easily. But any version of the governance might have to live with this if cryptocurrencies survive the test of time and remain outside of any single government control. This aspect ties up with first proposal on informed crowd wisdom and provides a technical backbone for the same.
4)Role of AI in governance: This is already happening in some form in the field of executive branch. Example could be police issuing a ticket for traffic violation. Now, lot of camera/AI based tickets are getting issue in different parts of the world I am not sure what role it can play in legislative branch at this time. What if there is more and more done by general AI in terms of helping main executive of state making decisions. Whosoever is the President/PrimeMinister/Mayor/Governor, anyway gets lot of public wrath. Any decision they make, you can find lot of people calling it bad. What if AI makes the decision so the blame can be shared by AI or totally put on AI. With society going more complex, it is getting even more tough to manage the state and keep mental state in order to be making the right choices as a leader. It may already have gone out of hands for any person to handle. It may be lack of trust/technology that is keeping is away. In terms of need, we have surely crossed the line. I am sure newer world order is going towards that in some sense. In judicial branch, there is a scope of AI being a helping tool in terms of looking at vast amount of data and being able to guide the outcomes. Again, some level of usage is already present. I understand there is some sort of system generated scoring created to decide upon the punishment periods where there is a range. Now, coming to the next branch, some call media as fourth state/branch. Clearly AI has made lot of negative inroads in this branch. Deepfakes, Facebook, WhatsApp University are some of the examples. The current state of society is getting stressed by these changes. There is a chance that lot of societies will go into chaos as a result of this development. The newer governance, including Democracy 2.0 would have to learn to handle these changes in society and be resilient of it
Any other ideas?.



