PTPTN draws online ire for negating X user’s exposé of potential web security issues

Agency cites CCA, PDPA against netizen for posting report detailing threat level of its corporate webpage, triggering criticism

10:44 PM MYT

 

KUALA LUMPUR – The National Higher Education Fund (PTPTN) has received online brickbats after it invalidated an X user’s concern over the agency’s website security.  

Last night, the user who uses the handle @HilmiAdi posted a screenshot listing supposed cyber vulnerabilities and a report detailing the threat level of “passive web application vulnerabilities” on PTPTN’s website, which appears to be a corporate webpage.  

@HilmiAdi’s X post.

Responding to the now-deleted post, PTPTN’s official X account said that its inspection of the posting found that the user had violated the Communications and Multimedia Act 1998, the Computer Crimes Act (CCA) 1997 and the Personal Data Protection Act (PDPA) 2010.  

“To avoid any possible misunderstanding or other implications due to this post, we respectfully request that the post be removed from your social media platforms immediately or before 10pm on January 29,” it added.  

PTPTN’s response to the concerned citizen has drawn the ire of other X users, who lambasted the agency for its “threats” against the original account owner. 

Among those who criticised the agency was Umno communications director Datuk Lokman Noor Adam, who also cautioned PTPTN against stoking the people’s displeasure with government entities.  

“When the rakyat informs us of details that could potentially harm us, we should thank them, check the veracity of their claims and never respond by threatening them.  

“Do not increase the people’s hatred towards the government with this kind of arrogant attitude,” he said.  

Samantha Chong, a former press secretary with the Prime Minister’s Department, also pressed PTPTN to disclose how the posting violated any law while raising her grouses with its website.  

Expressing similar sentiments, user @fdajesfry said that PTPTN should be thankful that there are citizens who volunteered to improve its website security while another user, @woody2shoez, admonished the agency for supposedly “shooting the whistleblower.”  

“Is this the quality of an organisation that looks over millions of ringgit of taxpayers’ money?” the latter asked.  

User @DanisyEisyraf also questioned PTPTN’s assertion of the original post violating the CCA, saying: “It’s a simple vulnerability scanner. Anyone can do it and it’s a critical step for VA (vulnerability assessment). It’s not even a pen test (penetration test).  

“It’s not (a) modification (and) it’s not unauthorised access, so how is it chargeable under the CCA?” he asked. – January 29, 2024 

Topics

Popular

Mamak restaurants’ group to sue TikTok user for defaming industry

The Malaysian Muslim Restaurant Owners’ Association (Presma) will proceed with suing a TikTok user for making defamatory claims about food preparation and cleanliness at mamak restaurants.

Fuad has no right to intervene in Sabah 40% special grant case: Kitingan

Deputy CM asserts that the lawyer has no authority to speak for state govt as he was not appointed

[UPDATED] Desperate, doomed move: Lokman Adam claims Daim, Dr Mahathir behind Langkah Dubai  

Langkah Dubai, a move by the opposition to topple Prime Minister Datuk Seri Anwar Ibrahim’s administration, is allegedly masterminded by former prime minister Tun Dr Mahathir Mohamad and his right-hand man Tun Daim Zainuddin.

Related