# Scene Script: .bank.in — The Political Vulnerability (Short-Form)

> ⚠️ **HUMAN CHECKPOINT — GATE 1**
> Review this scene breakdown. Production (TTS, images, video assembly) will NOT begin
> until you explicitly approve ("approve", "go", "continue"). Request edits freely.

**Format:** 16:9 landscape · **Target duration:** ~2 min 20 sec (under 140s) · **6 scenes**
**Sources:**
- Shutdown critique: https://bankin-report.cashlessconsumer.in/shutdown-critique
- IDRBT leak (main investigation): https://bankin-report.cashlessconsumer.in/
**Lens:** CashlessConsumer — bridges the *technical* IDRBT leak disclosure to the deeper truth: **not all vulnerabilities are technical. Some are inherently political — and those have no patch.**

---

## SCENE 1 — Hook: An Award and a Darker Reading (≈22s)

**Narration:**
"In March 2026, the Reserve Bank of India won an international award for `.bank.in` — a mandatory domain namespace for all Indian banks, called a key tool against cyber crime. And it does fight phishing. But the same namespace can also keep the banks running while the rest of the internet goes dark."

**Visual direction:** Award trophy morphs into a glowing firewall rule. Tense cold open. Title card: ".bank.in — Shield, or Choke-point?"

---

## SCENE 2 — The Technical Vulnerability (And Its Patch) (≈28s)

**Narration:**
"We've already seen `.bank.in` fail — technically. The very system that issues every banking domain — IDRBT's registration portal, the gatekeeper RBI set up — was found wide open. Thirty-three unauthenticated endpoints exposed the credentials of over fifty-five hundred bank employees: password hashes, phone numbers, device fingerprints. The padlock maker was leaking every key. The good news? That one got patched. An authentication gate went in, about eighteen days after it was reported."

**Visual direction:** The IDRBT portal as a vault labeled "gatekeeper for every .bank.in domain." The vault swings open — "33 open endpoints / 5,576 credentials / 13 months live." Then a "PATCHED ✅" stamp + "~18 days" tag.

**Key facts (verify against source):** 33+ unauthenticated endpoints · 5,576 bank-employee credentials · 1,072 orphan Super Admin accounts · live 13+ months · reported to CERT-In Jun 8, fixed Jun 25 · no public tender (IKCON Technologies) · IDRBT's published security policy was false.

---

## SCENE 3 — The Pivot (≈18s)

**Narration:**
"Here's the thing. Not every vulnerability is technical. Some are inherently political — baked into the design, not the code. And a political vulnerability doesn't come with a patch."

**Visual direction:** Screen splits: left = "Technical: supercookies → patched." Right = "Political: ??? → no patch." The right side stays unresolved, pulsing red.

---

## SCENE 4 — The Political Vulnerability: The Shutdown Whitelist (≈32s)

**Narration:**
"India already has the power to block the internet at many levels — cables, providers, DNS. The state's problem has always been precision. How do you shut down social media without shutting down the banks? `.bank.in` answers it with a single firewall rule: allow dot-bank-dot-in, block everything else. One rule. And it matters — because India is the world leader in internet shutdowns. In 2019, Kashmir was cut off for over five hundred days, and banking was among the hardest hit. This architecture makes that kind of surgical split trivial."

**Visual direction:** Single rule `ALLOW *.bank.in / DENY *` ignites. World map: India glowing red (60% of global shutdowns). J&K "533 days" counter.

---

## SCENE 5 — The Infrastructure Already Exists (≈22s)

**Narration:**
"And unlike a cookie bug, this can't be fixed with a registry entry. Every banking domain now ends in `.bank.in` — mandatory. The sole registrar is IDRBT, owned by the RBI. Delegation can be revoked at any time. The infrastructure for 'banking stays on while everything goes dark' already exists. The only missing ingredient is an order."

**Visual direction:** Four panels: mandatory / centralised / revocable / monitored. Build to: "✓ infrastructure exists — ? only an order is missing." Cross out "patch" — it doesn't apply here.

---

## SCENE 6 — Risks + CTA (≈20s)

**Narration:**
"So shutdowns get cheaper. Financial exclusion becomes a weapon. Every `.bank.in` lookup reveals which bank you visit, and when. You can patch a leaking portal. You cannot patch this. The time to ask is now — before a crisis forces the question. This is CashlessConsumer. Full investigation in the description."

**Visual direction:** Three risk flashes (cheap shutdowns / exclusion weapon / surveillance). Final frame: "You can patch a portal. You cannot patch a design." CashlessConsumer logo + URL overlay.

---

## Timing Summary

| Scene | Duration | Words |
|-------|----------|-------|
| 1. Hook | ~22s | ~58 |
| 2. Technical Vuln — IDRBT Leak (patched) | ~28s | ~72 |
| 3. The Pivot | ~16s | ~32 |
| 4. Political Vuln — Shutdown Whitelist | ~32s | ~82 |
| 5. Infrastructure Exists | ~20s | ~52 |
| 6. Risks + CTA | ~20s | ~55 |
| **Total** | **~2m 18s (138s)** | **~351** |

> Trimmed to ≤140s — IKCON/no-tender detail moved to research-brief only.

## Narrative Arc (the key move)
The script's spine is the **technical → political** bridge:
- Scene 2 establishes a *technical* vulnerability — the IDRBT leak: the registrar that issues every `.bank.in` domain exposed 5,576 bank employees' credentials via 33+ unauthenticated endpoints (13+ months live, no tender, built by IKCON). It was disclosed and **patched** with a simple auth gate in ~18 days.
- Scene 3 delivers the thesis: **not all vulnerabilities are technical; some are inherently political — and those have no patch.**
- Scenes 4–6 then unfold the *political* vulnerability (shutdown-whitelist architecture) which, by construction, cannot be fixed with an auth gate, a CVE, or a security audit.

## Visual System (consistent across scenes)
- **Style:** dark cinematic documentary, deep blues/blacks, red accents for risk.
- **Recurring motif:** the `.bank.in` namespace as a glowing thread through every scene; the "patch ✅ / no patch ❌" contrast as the visual spine.
- **End card:** CashlessConsumer logo + `bankin-report.cashlessconsumer.in`.

## Notes
- Technical disclosure accurately reflects the CashlessConsumer IDRBT investigation (reported to CERT-In Jun 8 2026, fixed Jun 25, ~18 days; 33+ unauthenticated endpoints; 5,576 bank-employee credentials; 1,072 orphan Super Admin accounts; single-source IKCON deal, no tender; IDRBT's published security policy was false).
- Anti-phishing merits acknowledged in one line (Scene 1), then set aside — the shutdown angle is the focus.
- All acronyms expanded on first use (DNS, IDRBT).
- Sources in `research-brief.md`.
