ECINET में Cyber Security Flaws का दावा: Election Technology की Security पर क्यों उठे सवाल?
![]()
ECINET, यानी Election Commission of India का नया integrated digital platform, अब voter services और election management के लिए एक महत्वपूर्ण digital infrastructure बन चुका है। लेकिन अब एक security researcher द्वारा ECINET app और ECI के voter-services portal में कथित vulnerabilities की जानकारी सामने आने के बाद Election Technology, Cyber Security और Voter Data Protection को लेकर सवाल उठने लगे हैं।
सबसे महत्वपूर्ण बात यह है कि सामने आई जानकारी किसी verified election hack या EVM tampering का सबूत नहीं है। मामला मुख्य रूप से digital systems की security, access controls और sensitive information की protection से जुड़ा है।
क्या है ECINET?
Election Commission of India ने January 2026 में ECINET को एक unified digital platform के तौर पर launch किया था। इसका उद्देश्य voter registration, voter-list search, complaints, election information और officials से जुड़ी कई services को एक ही ecosystem में लाना है। ECI के अनुसार platform में 40 से अधिक apps और web services को integrate किया गया है।
ECI ने May 2026 में बताया था कि ECINET ने election operations में महत्वपूर्ण भूमिका निभाई और counting day पर platform ने भारी traffic handle किया। Commission के अनुसार उस दिन उसके cybersecurity systems ने 68 लाख से अधिक malicious hits को counter किया था।
यानी ECINET अब सिर्फ एक सामान्य government app नहीं, बल्कि India’s election infrastructure का एक महत्वपूर्ण digital layer है।
Security Researcher ने क्या दावा किया?
Hindustan Times की 8 October की रिपोर्ट के अनुसार security researcher Nisarga Adhikary ने दावा किया कि उन्होंने July 2026 में Election Commission और cyber-security agency CERT-In को ECINET और voter-services website से जुड़े कई security concerns के बारे में जानकारी दी थी।
रिपोर्ट के मुताबिक एक concern voter portal के पीछे मौजूद server से जुड़ा था। Researcher का दावा था कि कुछ election officials के names और mobile numbers जैसी जानकारी ऐसे requests से मिल सकती थी जिनमें login या CAPTCHA जैसी स्पष्ट authentication requirement नहीं थी।
उन्होंने यह भी कहा कि उन्होंने limited testing की और वास्तविक dataset download नहीं किया।
अगर ऐसे findings independent security audit में confirm होते हैं, तो इसका सबसे बड़ा concern voter data से ज्यादा election officials की information का misuse हो सकता है। ऐसी जानकारी phishing, impersonation या targeted cyber attacks के लिए इस्तेमाल की जा सकती है।
ECINET App पर भी उठे सवाल
Researcher ने ECINET Android app के कुछ components को लेकर भी concerns बताए। रिपोर्ट के अनुसार app में cVIGIL, observer, candidate और Suvidha जैसे modules शामिल हैं।
दावा किया गया कि कुछ network traffic में genuine ECI server की verification कमजोर थी और app में कुछ encryption keys तथा access tokens मौजूद थे। Researcher के मुताबिक इससे किसी attacker के लिए data communication को intercept या manipulate करने का risk पैदा हो सकता था।
एक अन्य concern यह था कि कुछ tokens, phone numbers और observer module में bank-related information device पर unencrypted form में stored हो सकती थी।
हालांकि, उपलब्ध रिपोर्ट में किसी वास्तविक data theft या misuse का evidence सामने नहीं आया है। इसलिए इन findings को confirmed breach कहना सही नहीं होगा।
CERT-In ने क्या कहा?
इस पूरे मामले में एक महत्वपूर्ण development 6 October को सामने आया।
रिपोर्ट के अनुसार CERT-In ने researcher को बताया कि reported vulnerabilities में से कम से कम एक issue fix किया जा चुका है, जबकि बाकी concerns पर काम चल रहा है। Fixed issue को “Client-Side Static Response Encryption” से संबंधित बताया गया।
इससे यह संकेत मिलता है कि security concerns को लेकर remediation process शुरू हुई है। लेकिन सवाल यह है कि बाकी reported issues का independent verification और resolution कितनी जल्दी होता है।
क्या इसका मतलब Election System Hack हो गया?
नहीं।
यह distinction समझना बहुत जरूरी है।
ECINET एक digital platform है जिसका इस्तेमाल voter services और election administration के कई हिस्सों में होता है। इसके security flaws का दावा अपने आप यह साबित नहीं करता कि:
- EVM में बदलाव किया गया है।
- किसी election result को manipulate किया गया है।
- पूरे voter database को hack कर लिया गया है।
- किसी political party ने system access किया है।
अभी सामने आई जानकारी मुख्य रूप से application security और access-control vulnerabilities के allegations से संबंधित है।
यही वजह है कि इस मुद्दे को “Election System Hack” की बजाय Election Technology की Cyber Security पर उठे सवाल के रूप में देखना ज्यादा accurate होगा।
Voter Data Security क्यों महत्वपूर्ण है?
आज elections में technology की भूमिका लगातार बढ़ रही है। Voter registration से लेकर electoral rolls, complaints, polling information और election officials के communication तक कई processes digital systems पर depend करते हैं।
ऐसे में security की तीन layers बेहद महत्वपूर्ण हो जाती हैं:
1. Authentication:
कौन system में access कर रहा है और उसके पास क्या permissions हैं?
2. Data Protection:
Names, phone numbers, voter information और officials की sensitive details किस तरह encrypted और stored हैं?
3. Audit & Monitoring:
अगर कोई unusual activity होती है तो क्या उसे तुरंत detect, investigate और report किया जा सकता है?
किसी भी national-level election platform के लिए इन तीनों layers का strong होना जरूरी है।
ECINET पर पहले से भी क्यों बढ़ी है scrutiny?
ECINET की security debate ऐसे समय में सामने आई है जब electoral-roll management को लेकर पहले से political और legal scrutiny चल रही है।
The Indian Express की एक explainer report के अनुसार ECINET और ERONET electoral rolls के management और revision में महत्वपूर्ण भूमिका निभाते हैं। Platform में किए गए कुछ changes और Electoral Registration Officers की functionality को लेकर भी सवाल उठे हैं।
इस broader debate के बीच cybersecurity concerns सामने आने से transparency और independent auditing की मांग और महत्वपूर्ण हो जाती है।
आगे क्या होना चाहिए?
Election technology पर public trust बनाए रखने के लिए सिर्फ यह कहना पर्याप्त नहीं है कि system secure है। जरूरी है कि critical election infrastructure का regular independent security audit, vulnerability disclosure mechanism और timely remediation process मजबूत हो।
ECI ने September 26 को ECINET की review के लिए एक committee बनाने का आदेश भी दिया था, जिसमें senior Deputy Election Commissioner और एक independent expert शामिल थे।
आखिरकार चुनावों में technology का इस्तेमाल transparency और efficiency बढ़ाने के लिए किया जाता है। लेकिन जितना बड़ा digital infrastructure होगा, उतनी ही मजबूत उसकी cybersecurity, auditability और accountability भी होनी चाहिए।
निष्कर्ष
ECINET को लेकर सामने आई security concerns को लेकर अभी सबसे जरूरी बात यही है कि alleged vulnerability और confirmed cyber attack के बीच अंतर समझा जाए।
फिलहाल उपलब्ध reports किसी election result manipulation या EVM hacking का प्रमाण नहीं देतीं। लेकिन अगर security researcher द्वारा बताए गए vulnerabilities independent assessment में सही पाए जाते हैं, तो यह Election Commission के लिए एक serious technology-security challenge जरूर होगा।
भारत जैसे विशाल लोकतंत्र में election technology पर public trust केवल accurate results से नहीं, बल्कि इस भरोसे से भी जुड़ा है कि voter और election-related data सुरक्षित है, systems independently audited हैं और किसी vulnerability की स्थिति में timely action लिया जाता है।