Post by Henry Emeka (@Emekus)
Respectfully if the system stays leaky, the politics almost doesn’t matter.
Lock down INEC’s backend access
Strong access control:
Role-based access: Only staff whose job requires backend access should have it.
Least privilege: Even insiders should only see the minimum data needed for their role.
Multi-factor authentication (MFA):
Every login to the admin portal should require MFA (token, app, or hardware key), not just a password.
Unique accounts only:
No shared logins. Every user must have a personal account so actions can be traced directly to a person.
Full audit trails and real consequences
Comprehensive logging:
Every action—login, search, record view, export, screenshot attempt—must be logged with who, when, what, and from where.
Real-time monitoring:
Automated alerts for suspicious behavior:
Unusual bulk lookups
Access outside working hours
Access from strange locations/IPs
Enforce penalties:
If a political aide is found with backend-only data, someone inside INEC (or a contractor) either leaked it or was negligent.
That should trigger internal investigation, suspension, and possible prosecution, not just press statements.
Separate INEC from parties—technically and culturally
No direct party access to backend:
Parties can get anonymized, aggregated data e.g., total registered voters per polling unit), not raw personal records.
Data-sharing protocols:
Any data given to parties must be:
Documented who requested, who approved, what was shared
Redacted (no full PII unless legally required, and even then, tightly controlled)
Conflict-of-interest rules:
Staff with direct backend access should be barred from holding party positions or doing open partisan work during their tenure.
Technical hardening of the system
Network restrictions:
Admin portal only accessible from whitelisted devices and locations (INEC offices, secure VPN), not random laptops or phones.
Data minimization:
Don’t show more than needed on screen. For example:
Mask parts of BVN/NIN/phone numbers unless absolutely necessary.
Separate highly sensitive fields into a higher-security layer.
Export controls:
Disable or tightly control:
Bulk export
Screenshots on admin machines (via DLP tools)
Copy–paste of sensitive fields
Work with the Data Protection Commission (NDPC)
INEC is already engaging NDPC to improve data protection and secure its voter database.
To make that real, they should:
Run independent security audits before the 2026 primaries and 2027 election.
Publish a short public report on:
What was wrong
What was fixed
What remains a risk
What 240 million Nigerians and opposition parties can push for now 5/30/2026
240 million nIgerians demand that INEC, before the primaries:
Publicly commit to:
MFA for all admin users
Full audit logs and external review
Zero direct backend access for political parties
Set up a whistleblower and complaint channel for:
Staff who see misuse internally
Nigerians who find their data leaked or misused
Insist on an investigation into any known leak (like the Emeka Ike case) with:
Named findings
Sanctions where guilt is proven
https://x.com/ebona69/status/2060794822059868286?s=46
https://247ureports.com/2026/05/inec-portal-leak-outrage-erupts-as-apc-operatives-breach-restricted-database-to-track-actor-emeka-ike/?utm_source=copilot.com
0 likes · 0 comments · 0 shares