LCI Learning
New LIVE Course: Toxicology and Law. Batch begins 21st July. Register Now!

Share on Facebook

Share on Twitter

Share on LinkedIn

Share on Email

Share More

Jayanta Bandyopadhyay   24 October 2024

Custodian of dsc (digitial signature certificate)

DSCs of Directors are mostly kept at Secretarial Depts. or outsourced shared services offices. There is an exposure to misuse.

Is there any guideline by MCA about usage of DSC thru' registered IP (Computer)? 

 



 5 Replies

T. Kalaiselvan, Advocate (Advocate)     25 October 2024

What are the possible misuses of digital signature certificates?

Digital signature certificates (DSCs) are crucial for ensuring the authenticity and integrity of electronic documents. However, they can be misused in several ways:

 

Unauthorized Signing: If a digital signature certificate is obtained or accessed by an unauthorized individual, they can sign documents on behalf of the legitimate certificate holder, leading to fraud.

Phishing Attacks: Attackers may create fake websites that closely resemble legitimate ones to trick users into providing their digital signature credentials, which can then be used for malicious purposes.

Certificate Theft: If a certificate is not securely stored, it can be stolen, allowing the thief to sign documents or transactions fraudulently.

Replay Attacks: Attackers can capture signed documents and reuse them in different contexts, potentially leading to unauthorized transactions or agreements.

Misleading Authenticity: Digital signatures can create a false sense of security. If users do not verify the signer's identity or the integrity of the document, they may trust a signed document that is actually fraudulent.

Revocation Challenges: If a certificate is compromised, revoking it can be difficult. If users do not regularly check the revocation status, they may inadvertently rely on a compromised certificate.

Weak Encryption: Using weak cryptographic methods can lead to vulnerabilities that attackers can exploit to forge signatures or compromise the integrity of signed documents.

Insider Threats: Employees with access to digital signature certificates may misuse them for unauthorized transactions or to commit fraud against their own organization.

Inadequate Policies: Organizations that do not have strong policies and procedures for managing digital signatures may inadvertently allow misuse, such as sharing credentials or not properly auditing signed documents.

To mitigate these risks, it is essential to implement strong security practices, including secure storage of certificates, regular audits, employee training, and using robust authentication methods.

Dr. J C Vashista (Advocate )     25 October 2024

Very well explained by learned expert Mr. T Kalaiselvan, nothing more.

Is it a legal dispute / problem vis-a-vis query for consideration and obligation of experts on this platform ?

Jayanta Bandyopadhyay   25 October 2024

Sir, there is a growing family dispute. There could be a vertical split of family business. So far everything going smoothly . Based on verbal instructions of directors  office was putting DSC. Now, staffs are under threat. Except MNC and big cos, most small companies prepare docs at back end without a formal meeting.

Regards 

S Jadhav 98336 98330 (Jadhav & Associates)     05 May 2025

Whether it is a family owned company or not a DSC is for the use of an individual.

The authorities in India do not realise(most likely they are aware but purposely ignore) that the DSCs and passwords are used by the assistants and not the DSC owner due to lack of knowledge in using or the likelihood of mistakes.

The general practice is to provide the DSC to the asisstant in you presence for uploading documents etc to avoid misuse, especially in an environment that you seem to be in.

Jayanta Bandyopadhyay   05 May 2025

Sir

 

Class  3 DSC is kept at Bengal Offices and Directors are either in Mumbai or outside India. If Geo-tag and location mapping can detect absence of Directors ,what responsibility they own, if there is misuse. Can office staff bypass ownership for any misuse or unknowingly mistake committed. 

Kindly guide 


Leave a reply

Your are not logged in . Please login to post replies

Click here to Login / Register