Debated in Parliament on 7 Jul 2014.
Mr Zaqy Mohamad asked the Minister for Communications and Information (a) what is the outcome of the investigation into the breach of SingPass IDs and passwords; (b) what measures have been taken to prevent future breaches of security and assure Singaporeans of the continued confidentiality of their personal data; (c) how is the Government planning to improve IT security measures for citizens using online services; and (d) what can be done to improve IT security awareness of citizens, particularly among citizens who are less Internet-savvy.
Ms Mary Liew asked the Minister for Communications and Information in view of the recent possible compromise of SingPass accounts (a) whether there are plans to introduce additional security measures to protect citizens' data; and (b) whether the Ministry will consider further educating the less computer-savvy Singaporeans on the importance of online security and the choice of appropriate passwords.
Mr Yee Jenn Jong asked the Minister for Communications and Information in respect of the recent security breach of SingPass accounts (a) what additional interim and permanent measures are being put in place to ensure that the operator carries out its operational roles, particularly in the monitoring, investigation and flagging of suspicious activities on the platform; (b) what is the latest update on the Ministry's investigations into the breaches, including when the full findings will be released; and (c) whether efforts have been made to find out whether the security breach is larger than the 1,560 accounts reported.
Madam, with your permission, can I take Question Nos 8, 9 and 10 together, please?
Yes, please.
Mdm Speaker, SingPass is a password system for the public to identify themselves when using various Government e-services. Launched in 2003, SingPass is part of the e-Government masterplan initiatives spearheaded by MOF and Infocomm Development Authority (IDA).
Since its launch in 2003, various security improvements have been implemented. For example, since September 2012, the SingPass system requires users to enter strong passwords when the password is changed. Strong passwords must include a combination of
Page: 23
letters and numbers and contain eight to 24 characters. For Government e-services that require online payment, users must further authenticate themselves using the systems put in place by their financial institutions.
In November 2007, SingPass introduced the Immediate Reset (IMR) feature. This allowed users to reset their password online immediately. The need for IMR arose when users wanted to use an e-service but realised they forgot their password. Before IMR was introduced, SingPass users could only reset their passwords at the physical SingPass counters located at CPF Board offices or at the community centres located across the island. Alternatively, they could submit an online request to reset their SingPass and a password would be mailed to their registered addresses within four working days.
To activate the IMR, the user must login using SingPass and provide (a) the answers to two security questions; and (b) his mobile number. When using IMR to reset the password, the user will be required to: (a) provide his Name, NRIC and the Date of Issue of his NRIC, and (b) answer the two security questions. A one-time password would then be sent to his mobile number. This one-time password enables the user to set a new password. After the password is reset through IMR, a notification letter would be sent to the user's registered address to inform him this had been done.
On Monday, 2 June 2014, IDA was informed that the SingPass helpdesk received 11 calls from different members of the public reporting that they received a SingPass Reset Notification Letter even though they did not request for any password reset. Due to the alertness of these 11 SingPass users, IDA was able to initiate an immediate investigation. IDA detected that the one-time passwords of these 11 accounts were sent to a single mobile number at or around the same day. Further checks revealed that 1,560 accounts had also been linked to a small number of mobile phone numbers. As a precaution, IDA immediately ordered that these SingPass accounts should be deactivated. Affected users were notified by a letter via urgent delivery to their registered addresses. IDA has also alerted and has been working with other agencies on the affected SingPass accounts. As reported, investigations revealed that six fraudulent transactions involving work permit applications were made from three affected SingPass accounts. MOM has since contacted the affected users and cancelled the applications involved. Should other fraudulent transactions be found, Government agencies will contact those affected.
Arising from the incident, IDA also initiated a further round of review of the different layers of protection at the network and application level. The system was also scanned for any undetected vulnerabilities. No vulnerability was uncovered. The perpetrator may have obtained the users' SingPass credentials through other means.
Page: 24
One possibility is the widespread use of simple passwords. For example, in October 2013, Adobe reported that its system was hacked, leading to the disclosure of millions of user accounts. When security experts examined the published passwords, it found millions of users were using weak passwords such as "123456", or the word "password". Another possibility is that malware was installed in users' computers, thus allowing the perpetrator to see the user's keystrokes.
Members have asked how security can be improved. My Ministry will work with MOF and IDA to further enhance security measures for SingPass and introduce stronger authentication using second-factor authentication (2FA) for e-services involving sensitive data or transactions.
Besides 2FA, IDA will also further enhance SingPass. In April this year, a new contract was awarded to implement a new SingPass system by Q3 2015. The new SingPass system will require even stronger passwords. We are also looking into allowing users to define their own usernames instead of the current NRIC or FIN number. In addition, the new SingPass will come with more advanced analytics capability to identify anomalies in login transaction patterns so as to mitigate any potential security risks. Agencies will be required to implement 2FA for e-services involving sensitive data or transactions. More details on the 2FA implementation will be available in the later part of the year. IDA will work with the SingPass operator to improve the processes in handling customer queries and helpdesk services provided to SingPass users.
We are also exploring mandating more frequent password changes for SingPass accounts. This may mean a slight increase in the number of cases where users cannot immediately use some e-services because they forgot their password. We seek the public's understanding and patience for this. These additional authentication steps will allow for greater peace of mind when performing sensitive online transactions.
While IDA enhances the security at the SingPass end, we also need the assistance of Singaporeans to secure their own systems. In particular, malware can disclose even strong passwords to perpetrators. Hence, users need to maintain basic computer hygiene practices, such as making sure that their computer software and anti-virus software are always updated.
Over the years, the Singapore Government has also stepped up efforts to foster better cyber security practices of businesses and individuals. IDA has partnered the industry through the setting up of the Cyber Security Awareness Alliance and embarked on various cyber-security awareness and outreach activities. My Ministry will continue to work with IDA and all Government agencies to improve IT security awareness of our citizens. This year, Madam, IDA will be partnering with the National Crime Prevention Council to produce an
Page: 25
episode of CrimeWatch enacting a cybercrime case.
I thank the Minister for the clarification. I have a few supplementary questions. Is the Ministry quite confident that the accounts breached are the only ones that are breached? Secondly, I hear the Minister saying that SingPass itself is not breached but, basically, the likelihood is that it comes from other sources. The bigger question would then be this: how do we instil confidence in our citizens that the e-services are secure? Of course, the two-factor authentication is not a new technology. The banks have implemented this before. Why has the Government not considered this earlier?
I thank the Member for the questions. I agree with him that it is important for us to continue to build trust in the system. As I mentioned earlier, the investigation revealed that there were no vulnerabilities that were uncovered within the system. Having said that, we also agree that the system can be strengthened. As I had mentioned in my reply, all of us have to work in partnership and, therefore, we hope that ordinary Singaporeans who are using the SingPass accounts can first use stronger passwords and, secondly, check at their own end whether their computer software, especially the anti-virus software, is updated frequently.
On the Member's question about why we have not been using second-factor authentication, bear in mind that there are three million users in terms of SingPass accounts of varying capabilities and expertise in understanding the use of the Internet and, therefore, we have to balance the ease of use and the practicality. But we recognise that Singaporeans are now in favour of further authentication. Therefore, we are now mandating for all those services involving sensitive data and transactions to use the second-factor authentication.
I would like to ask the Minister: SingPass is used by 3.3 million users for over 340 Government e-services. So, it is rather worrying that it has been for so long supported by just a single level of authentication. I would like to ask:
(a) Has there been any detected attack on SingPass in the past and did any breach happen?
(b) What is the timeline for the implementation of the two-factor authentication and whether there will be any costs that would be borne directly by the users because of additional hardware that it may need?
Page: 26
(c) What is the status of the One-Key National Authentication Framework Programme that was launched two years ago?
On the last question regarding the One-Key National Authentication Framework Programme, I do not have the latest figures. I would be happy to update the Member on the adoption rate for the one-key programme.
I agree with the Member that it is worrying that we are having a lot of transactions and we have not adopted second-factor authentication. That is why IDA has, in fact, been working with the various agencies to mandate it and to make it a possibility. In terms of the timeline, I had mentioned that everything should be in place by the third quarter of next year. [Please refer to "Clarification by Minister for Communications and Information", Official Report, 7 July 2014, Vol 92, Issue No 7.]
In terms of the cost, we do not think there will be any cost on the part of the user. There will be a cost, of course, on the part of the operator and the various agencies involved. In terms of attacks, we have not seen any attack on the SingPass accounts in the past, but there have been one or two breaches, especially in the applications of Work Permits and MOM discovered it even before the latest breach and they have cancelled these immediately. Obviously, people out there are trying to get into the accounts because it leads to some things which they want and we have to continue to strengthen the infrastructure.