The rapid evolution of Indonesia’s digital economy has brought unprecedented convenience, yet it has simultaneously exposed a critical structural vulnerability: the reliance on self-claimed verification by platform providers. During the recent "The Forum" discussion held in Jakarta, titled "Semakin Digital, Siapa Menjamin Kita Semakin Aman?" (Increasingly Digital, Who Guarantees Our Safety?), legal experts, cybersecurity specialists, and data protection advocates converged on a singular consensus: the era of relying on internal platform verification must come to an end. To ensure legal validity and protect consumers from mounting cyber threats, the integration of independent Electronic Certification Providers (PSrE) and Certified Electronic Signatures (TTE) is no longer a luxury—it is a fundamental requirement for the digital ecosystem.
The core of the issue lies in the anonymity inherent in digital transactions. When two parties engage in a financial or legal contract without physical presence, the traditional hallmarks of identity—handwritten signatures, face-to-face verification, and physical documentation—are rendered obsolete. In their place, digital systems have stepped in, but many have proven insufficient to withstand modern forensic scrutiny.
The Legal Fallacy of Self-Claimed Verification
Edmon Makarim, a former Dean of the Faculty of Law at the University of Indonesia and a leading authority on telematics law, delivered a stark warning during the forum. He pointed to Article 15 of the Law on Electronic Information and Transactions (UU ITE), which mandates that electronic systems must be reliable and secure. However, Makarim argues that many providers interpret "security" too loosely.
"Under the current legal framework, electronic systems lack the necessary weight of evidence in a court of law if they rely solely on ‘self-claiming’ by the platform operator," Makarim explained. "When a company acts as the sole judge and jury of its own verification process, it creates a massive conflict of interest. We need to move toward independent third-party verification, utilizing asymmetric cryptography and PSrE-certified entities to ensure that digital signatures are legally binding and irrefutable."
The implications of this are profound. Without independent certification, when a dispute arises—such as a fraudulent loan application or an unauthorized fund transfer—the platform’s internal logs are often challenged in court. Because the platform controls the data and the verification algorithm, the consumer is left in a disadvantaged position, lacking the "digital evidence" required to prove that they were not the party who authorized the transaction.
Cybersecurity and the Account Takeover Crisis
Complementing the legal perspective, Yudho Giri Sucahyo, a prominent information technology expert, shifted the focus to the technical mechanisms of trust. He emphasized that trust in cyberspace is not a social construct; it is a technical one.
"Confidence in digital platforms must be proven through rigorous, multi-layered authentication," Sucahyo stated. He noted that the transition from static passwords to robust systems—including CAPTCHA, biometric scanning, and TTE—is the only way to mitigate the rising tide of account takeovers (ATO).
The technical vulnerability often manifests during device migration. When a user logs in from a new smartphone or laptop, many platforms rely on simple SMS-based One-Time Passwords (OTP). As cybercriminals have become more adept at SIM-swapping and intercepting messages, this single-factor authentication has become a gateway for fraud. Sucahyo argued that the failure of systems to accurately identify the legitimate owner on a new device is a systemic design flaw, not merely a user error. By mandating certified electronic signatures, platforms could ensure that even if a password is stolen, the transaction itself remains tethered to a verified digital identity that cannot be easily spoofed.
The Human Cost: When Cost-Cutting Compromises Security
The urgency of these reforms is best illustrated by the lived experiences of victims. Zico L. Djagardo, an advocate and a victim of data misuse, provided a harrowing account of how the lack of stringent verification protocols can dismantle a person’s financial life.
Djagardo shared his experience with predatory peer-to-peer (P2P) lending platforms that failed to implement robust verification. In many instances, he discovered that financial platforms were intentionally bypassing the use of PSrE-certified services to reduce their operational overhead. By choosing cheaper, internal verification methods, these companies effectively externalized the risk of fraud onto the users.
"The platforms admit that their internal systems are insufficient, yet they persist in using them because it is cheaper," Djagardo noted. "When my data was misused to initiate a fraudulent loan, the platform could not provide a cryptographically sound audit trail of my consent. It was a failure of the system to act as an impartial intermediary."
Djagardo is now lobbying for more granular regulations regarding the implementation of TTE. He points to the Constitutional Court’s recent rulings, which emphasize the need for "multiple protection" for personal data. In his view, the PSrE must act as a "digital referee," ensuring that in any dispute, there is an objective, third-party record of who initiated a transaction, thereby guaranteeing that consumers are not left defenseless against corporate negligence.
Government Response: Reforming the Regulatory Landscape
The Indonesian government has acknowledged the urgency of the situation. Aulia, representing the Directorate of Digital Space Supervision Strategy and Policy at the Ministry of Communication and Digital (Komdigi), confirmed that the state is actively working on a revision of Government Regulation (PP) Number 71 of 2019.
The proposed revisions are expected to address several critical gaps:
- High-Risk Transaction Protocols: New mandates for transactions involving high financial value, requiring enhanced security standards that surpass basic password protection.
- National Digital Identity: Integration of the government’s digital identity infrastructure (Identitas Kependudukan Digital) with private sector authentication to create a unified, high-assurance trust framework.
- Accountability for PSrE: Establishing stricter oversight on Electronic Certification Providers to ensure they maintain the technical capability to act as independent forensic witnesses.
The revision process involves a multi-stakeholder dialogue, including industry players, cybersecurity agencies, and legal experts, reflecting a shift toward a more proactive, risk-based regulatory posture.
Analysis: Implications for Indonesia’s Digital Economy
The transition toward a certified, third-party verification model represents a maturation point for the Indonesian digital economy. For years, the industry operated under a "growth-first" mindset, where friction-less onboarding was prioritized over security. However, as the volume of digital transactions grows, the cost of fraud is beginning to outweigh the benefits of low-friction systems.
If the proposed regulations are successfully implemented, the following impacts can be expected:
- Consolidation of the PSrE Market: Platforms will be forced to outsource their verification to certified providers, likely leading to a more specialized and robust industry of cybersecurity firms.
- Reduction in Financial Crime: By moving away from SMS-based OTPs toward biometric and TTE-based authentication, the rate of account takeovers is projected to drop significantly.
- Increased Consumer Confidence: A legal framework that empowers the consumer in disputes will likely lead to higher adoption rates for high-value digital services, such as digital banking and investment.
Conclusion
The forum in Jakarta serves as a wake-up call for both industry players and regulators. The current state of "self-claiming" in digital verification is a relic of an earlier, more naive stage of the internet. As Indonesia moves toward a more sophisticated digital economy, the infrastructure of trust must be built on the foundation of independent, verifiable, and legally sound authentication. The path forward requires a transition from the convenience of internal silos to the integrity of certified systems, ensuring that in the digital age, security is not just a claim, but a verifiable fact.
