Featured image by MS News and adapted from natasaadzic on Canva, for illustration purposes only.
The Personal Data Protection Commission (PDPC) and Cyber Security Agency of Singapore (CSA) issued a joint advisory today against using NRIC numbers for authentication.
They aimed the advisory at private sector organisations doing so or intending to do so.
“Organisations that are using full or partial NRIC numbers to authenticate persons should stop this practice as soon as possible,” they said.
Authentication means making sure someone is really who they say they are before allowing them to access services or information meant just for them.
One way of authenticating a person is through passwords.
The joint advisory highlighted that NRIC numbers should not be used in passwords.
This is because NRICs are issued to uniquely identify a person. As such, NRICs must be assumed to have been disclosed to at least a few others.
Contrarily, users should never share passwords with anyone else.
PDPC and CSA also said that passwords should not contain information that can be guessed.
This includes easily obtained personal data, such as names, NRIC numbers, or birth dates.
The government agencies thus advised organisations not to set NRIC numbers as default passwords.
Source: Leung Cho Pan on Canva, for illustration purposes only
They also urged against using full or partial NRIC numbers together with other personal data to create passwords for authentication.
Instead, PDPC and CSA recommended the following examples of better authentication:
The advisory showed a preference for the latter two options for stronger phishing resistance.
Source: ar130405 on Canva, for illustration purposes only
For passwords, the agencies suggested a long series of random words for ease of remembrance, such as “LearntoRIDEabikeat5”.
“Do set up two-factor authentication for an additional layer of security,” they stated.
The Ministry of Digital Development and Information (MDDI) had also previously discouraged using NRIC numbers for authentication.
They classified NRIC numbers as being used for identification, not authentication.
Even so, most people felt uncomfortable with the government’s intention to unmask the numbers.
Also read: MS Polls: ‘It bothers me’: 80% of people polled not comfortable with unmasking NRIC number
Have news you must share? Get in touch with us via email at news@mustsharenews.com.
Featured image adapted from MS News and adapted from natasaadzic on Canva, for illustration purposes only.