Posts

What Happens When Your Email Is Used as a “Forgot Password” Recovery Point You Didn’t Expect

TL;DR: Most people set a recovery email once and forget about it — but that recovery point often becomes the single most powerful key to dozens of accounts you signed up for years ago. If that recovery email is old, shared, or itself compromised, it's a silent risk sitting underneath your entire digital identity. Here's how to audit it. Every account you've ever created has a recovery mechanism attached — usually an email address, sometimes a phone number. Over years of signing up for services, that recovery chain quietly accumulates, and most people have never actually traced where it leads. Why This Matters More Than It Seems A single email address is often the recovery point for far more accounts than most people realise — social media, shopping accounts, old forums, subscription services, sometimes even financial platforms. If that email is compromised, or if it's an old account you no longer actively monitor, an attacker doesn't need to breach each indiv...

How Loan Apps in India Collect and Misuse Personal Data

TL;DR: Unregulated instant-loan apps have built a well-documented playbook: request excessive permissions at install, extract a tiny loan, then use your contact list and photos to harass you and everyone you know when repayment terms turn predatory. Here's how the data misuse actually works and how to check if a lending app is legitimate. India has seen a genuine crackdown on fraudulent loan apps, with the RBI removing large numbers of unauthorised lending apps from Indian app stores. Understanding the data-misuse mechanism — not just the financial scam — is key to recognising the risk before installing anything. The Data These Apps Request — and Why It's a Red Flag Legitimate, RBI-regulated lenders typically need minimal data beyond standard KYC and a camera permission for a verification selfie. Fraudulent loan apps, by contrast, routinely request: Full contact list access — the single most important permission for their business model, since it becomes the harassme...

What Data Do Health and Fitness Apps in India Collect, and Where Does It Go?

TL;DR: Health and fitness apps — from gym and workout apps to diagnostic and telemedicine platforms — collect some of the most sensitive personal data that exists: biometric readings, medical history, menstrual cycle data, and behavioural patterns. Here's what's actually gathered, how India's health data framework treats it, and what to check before you share it. Fitness and health apps have become a normal part of daily life for many Indians — workout trackers, diet apps, telemedicine platforms, and diagnostic services. What's less visible is just how sensitive the underlying data is, and how differently it's treated compared to, say, a shopping app. What These Apps Actually Collect Biometric and physiological data — heart rate, sleep patterns, step count, sometimes blood glucose or other health metrics from connected wearables Medical history — conditions, medications, and consultation notes on telemedicine and diagnostic platforms Location data — wor...

Setting Up Passkeys and Authenticator Apps: A Step-by-Step Guide for Your Main Accounts

TL;DR: Knowing you should move beyond SMS-only authentication is one thing — actually setting it up is another. This is a practical, account-by-account walkthrough for setting up authenticator apps and passkeys on the accounts that matter most: email, banking-adjacent logins, and major platforms. Once you understand why SMS-only 2FA has gaps, the next question is simply: how do I actually turn on something stronger? Here's the practical setup process, starting with the accounts worth prioritising. Where to Start: Prioritise by Impact Not every account needs the same level of protection immediately. Start with: Your primary email — because it's usually the recovery point for everything else Banking and UPI apps that support app-based or biometric authentication Any account tied to your professional identity — LinkedIn, work email, cloud storage Setting Up an Authenticator App Google Authenticator, Microsoft Authenticator, and Authy are the most widely used optio...

Digital Arrest Scams in India: How They Work and What Personal Data Makes Them Convincing

TL;DR: "Digital arrest" is not a real legal process anywhere in Indian law — but the scam built around that fake premise has caused massive financial losses across India. Fraudsters impersonate police, CBI, ED, or RBI officials over video call, using real personal details to make the threat feel credible. Here's exactly how it works and what information makes it convincing. Digital arrest scams have become one of the fastest-growing categories of cyber fraud in India, with cumulative losses reported in the thousands of crores over the past two years. Understanding the mechanism — and specifically what personal data scammers use to make the con work — is the most effective defence. How the Scam Typically Unfolds The pattern is consistent across most reported cases: The initial contact — a call or message claiming to be from a courier company (often referencing a parcel supposedly containing drugs, fake passports, or illegal SIM cards), a telecom operator, or dir...

Two-Factor Authentication and Account Recovery: Closing the Gaps Attackers Actually Use

TL;DR: Most people set up 2FA once and assume they're covered. Attackers don't target the 2FA itself — they target the recovery process around it: SIM swaps, weak security questions, and outdated backup emails. This guide covers where the real gaps are and how to close them, including India's shift away from SMS-only authentication. Why SMS-Based 2FA Alone Is No Longer Considered Sufficient SMS one-time passwords have been the default second factor in India for years, largely because they require no extra app and work on any phone. The weakness is structural: SMS OTPs depend on your phone number remaining under your control, and SIM swap fraud specifically targets that dependency. In a SIM swap, a fraudster convinces or bribes a telecom outlet — or exploits weak verification — into porting your number onto a SIM they control. Once that happens, they receive your OTPs directly, and password-reset flows that rely on SMS become a way in, not a safeguard. This risk has...

How Employers Actually Run Background Checks in India

TL;DR: Employer background checks in India typically combine formal verification services with informal online searches — and candidates are often unaware of exactly what gets checked. This article covers the actual mechanics: what recruiters and HR teams commonly verify, what's legally permissible, and what a background check actually surfaces. Most conversations about background checks focus on what a candidate should clean up. This one looks at the other side — how the process actually works from the employer's end, and what that means for what you should expect. What a Formal Background Check Typically Covers Larger companies, particularly in IT, BFSI, and MNC environments, often use third-party verification agencies. A standard check typically includes: Employment history verification — confirming dates, designation, and sometimes salary with previous employers Education verification — confirming degrees and institutions directly with universities or through d...