{"id":237,"date":"2007-05-10T05:14:00","date_gmt":"2007-05-10T05:14:00","guid":{"rendered":"https:\/\/sanjibmitra.ie\/blog\/2007\/05\/10\/identity-leakage\/"},"modified":"2026-05-28T18:50:08","modified_gmt":"2026-05-28T17:50:08","slug":"identity-leakage","status":"publish","type":"post","link":"https:\/\/sanjibmitra.ie\/blog\/2007\/05\/10\/identity-leakage\/","title":{"rendered":"Identity Leakage: Trust VFS to reveal all"},"content":{"rendered":"<div  align=\"left\" style=\"font-family:georgia;\"><span style=\"font-size:100%;\">The Visa Facilitation Services (<span class=\"blsp-spelling-error\" id=\"SPELLING_ERROR_0\">VFS<\/span>) in India have over the years greatly simplified any need to escape the motherland. If you&#8217;re privileged enough to possess appropriately valid and verified documents, be it travel for holiday, human trafficking, business, family reunion or work, the <span class=\"blsp-spelling-error\" id=\"SPELLING_ERROR_1\">VFS<\/span> in India will see to it that you needn&#8217;t do the worrying nor have to stand in long queues overnight wondering whether you&#8217;ve filled in that visa form correctly. According to recent reports I&#8217;ve been hearing, those days are almost gone.<\/p>\n<p>On the <a href=\"http:\/\/www.vfs-uk.co.in\/\"><span class=\"blsp-spelling-error\" id=\"SPELLING_ERROR_2\">VFS<\/span> UK India website<\/a>, you can nowadays apply online for most United Kingdom (UK) visa categories, as part of their Business Express Program and track your application too. <span class=\"blsp-spelling-error\" id=\"SPELLING_ERROR_3\">VFS<\/span> India are the British High Commission&#8217;s commercial partner, and they operate application centres on behalf of the 4 visa departments in India.They have about 11 offices across Indian cities.<\/p>\n<p>Last year, while I was directed to this <span class=\"blsp-spelling-error\" id=\"SPELLING_ERROR_4\">VFS<\/span> website due to an UK assignment, I stumbled upon a technical problem. After entering all my details on the online visa application form, I couldn&#8217;t proceed further. All I had was this blank browser page on my computer monitor, and a &#8216;Back&#8217; button that refused to do what it was designed to do.<\/p>\n<p>Having spent a good hour typing in my details, I decided to twiddle around with the URL in my browser to see if something could be salvaged. About two minutes of twiddling with the <span class=\"blsp-spelling-error\" id=\"SPELLING_ERROR_5\">VFS<\/span> Uniform Resource <span class=\"blsp-spelling-error\" id=\"SPELLING_ERROR_6\">Locator<\/span> (URL) resulted in the following revelation: <strong><em>Anyone who has ever applied for a UK visa online, have their personal details exposed to everyone on the Internet.<\/em><\/strong> Personal details such as passport number, address, phone numbers, email, family details, work details, salary, clients, real-estate owned, countries you&#8217;ve visited, where you&#8217;re going and when you&#8217;re travelling&#8230;the list goes on. Essentially, the entire form, i.e. <em>everything the British High Commission needs to know about you to grant you a visa is available for anyone to misuse<\/em>. Security is thrown out the window.<\/p>\n<p>This was naturally quite shocking. I quickly verified that what I was seeing was true: that <span class=\"blsp-spelling-error\" id=\"SPELLING_ERROR_7\">VFS<\/span> India could be responsible for large scale identity theft, for every online visa application that it receives. I sent an email to both <span class=\"blsp-spelling-error\" id=\"SPELLING_ERROR_8\">VFS<\/span> India and the British High Commission explaining this serious security issue. After about two months, I heard back from the British High Commission thanking me for the email bringing this to their notice, and promising to look into this matter. A year later nothing has happened. And this is in spite of the fact that identity theft in the UK is treated quite seriously and there is a <a href=\"http:\/\/www.opsi.gov.uk\/ACTS\/acts1998\/19980029.htm\">parliamentary act <\/a>that protects such information.<\/p>\n<p>Identity theft occurs when a criminal uses another person&#8217;s personal information to take on that person&#8217;s identity. Identity theft in any form has serious consequences, and our law-makers in India should take a tougher stance. From a <span class=\"blsp-spelling-error\" id=\"SPELLING_ERROR_9\">Wikipedia<\/span> entry on <a href=\"http:\/\/en.wikipedia.org\/wiki\/Identity_theft\">Identity Theft<\/a>, <em>&#8220;The crimes include illegal immigration, terrorism and espionage, to mention a few. It may also be a means of blackmail if activities undertaken by the thief in the name of the victim would have serious consequences for the victim&#8221;.<\/em><\/p>\n<p>Terms &amp; Conditions on the <span class=\"blsp-spelling-error\" id=\"SPELLING_ERROR_10\">VFS<\/span> UK India website state that <em>&#8220;Under the Data Protection Act, we have a legal duty to protect any information we collect from you&#8221;<\/em>. And they go on to say <em>&#8220;<span class=\"blsp-spelling-error\" id=\"SPELLING_ERROR_11\">VFS<\/span> shall not disclose or allow access to any personal data provided by the Foreign &amp; Commonwealth Office or acquired by <span class=\"blsp-spelling-error\" id=\"SPELLING_ERROR_12\">VFS<\/span> during the execution of the contract, other than to <span class=\"blsp-spelling-error\" id=\"SPELLING_ERROR_13\">VFS<\/span> personnel or those otherwise lawfully concerned with the execution of the contract&#8221;.<\/em><\/p>\n<p>Doesn&#8217;t look like that to me. Whoever <span class=\"blsp-spelling-error\" id=\"SPELLING_ERROR_14\">VFS<\/span> India uses to design their website has some serious answering to do, and heads will surely roll. I&#8217;m not sure whether this security hole is visible in the United States <span class=\"blsp-spelling-error\" id=\"SPELLING_ERROR_15\">VFS<\/span> site or any other country&#8217;s visa processing that <span class=\"blsp-spelling-error\" id=\"SPELLING_ERROR_16\">VFS<\/span> India handle.<\/p>\n<p>In any case, I don&#8217;t think I want to pay <span class=\"blsp-spelling-error\" id=\"SPELLING_ERROR_17\">VFS<\/span> for their services and then be exposed to this gaping security hole.<\/p>\n<p><\/span><\/div>\n<div style=\"font-family: georgia;\" align=\"left\"> <\/div>\n<div  align=\"left\" style=\"font-family:georgia;\"><span style=\"font-size:100%;\">Excuse me while I try to find the end of this queue.<\/p>\n<p><\/span><span style=\"font-size:100%;\"><span style=\"font-weight: bold;\">Update<\/span>: Problem &#8220;sol-<span class=\"blsp-spelling-error\" id=\"SPELLING_ERROR_18\">ved<\/span>&#8220;, as they say here in Bangalore! Check this <a href=\"http:\/\/sanjibmitra.blogspot.com\/2007\/05\/vfs-plugs-security-hole.html\">post<\/a>. This posting was also the basis of a <a href=\"http:\/\/www.channel4.com\/news\/articles\/business_money\/online+visa+security+flaw\/517157\">Channel 4<\/a> television news report in the UK on the 17th of May, just a week after publishing on this blog.<\/p>\n<p><\/span><\/div>\n","protected":false},"excerpt":{"rendered":"<p>The Visa Facilitation Services (VFS) in India have over the years greatly simplified any need to escape the motherland. If you&#8217;re privileged enough to possess appropriately valid and verified documents,<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[70,7],"tags":[],"class_list":["post-237","post","type-post","status-publish","format-standard","hentry","category-opinion","category-think"],"_links":{"self":[{"href":"https:\/\/sanjibmitra.ie\/blog\/wp-json\/wp\/v2\/posts\/237","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sanjibmitra.ie\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sanjibmitra.ie\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sanjibmitra.ie\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/sanjibmitra.ie\/blog\/wp-json\/wp\/v2\/comments?post=237"}],"version-history":[{"count":1,"href":"https:\/\/sanjibmitra.ie\/blog\/wp-json\/wp\/v2\/posts\/237\/revisions"}],"predecessor-version":[{"id":248,"href":"https:\/\/sanjibmitra.ie\/blog\/wp-json\/wp\/v2\/posts\/237\/revisions\/248"}],"wp:attachment":[{"href":"https:\/\/sanjibmitra.ie\/blog\/wp-json\/wp\/v2\/media?parent=237"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sanjibmitra.ie\/blog\/wp-json\/wp\/v2\/categories?post=237"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sanjibmitra.ie\/blog\/wp-json\/wp\/v2\/tags?post=237"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}