In 2009, I became extremely concerned with the concept of Unique Identity for various reasons. Connected with many like minded highly educated people who were all concerned.
On 18th May 2010, I started this Blog to capture anything and everything I came across on the topic. This blog with its million hits is a testament to my concerns about loss of privacy and fear of the ID being misused and possible Criminal activities it could lead to.
In 2017 the Supreme Court of India gave its verdict after one of the longest hearings on any issue. I did my bit and appealed to the Supreme Court Judges too through an On Line Petition.
In 2019 the Aadhaar Legislation has been revised and passed by the two houses of the Parliament of India making it Legal. I am no Legal Eagle so my Opinion carries no weight except with people opposed to the very concept.
In 2019, this Blog now just captures on a Daily Basis list of Articles Published on anything to do with Aadhaar as obtained from Daily Google Searches and nothing more. Cannot burn the midnight candle any longer.
"In Matters of Conscience, the Law of Majority has no place"- Mahatma Gandhi
Ram Krishnaswamy
Sydney, Australia.

Aadhaar

The UIDAI has taken two successive governments in India and the entire world for a ride. It identifies nothing. It is not unique. The entire UID data has never been verified and audited. The UID cannot be used for governance, financial databases or anything. It’s use is the biggest threat to national security since independence. – Anupam Saraph 2018

When I opposed Aadhaar in 2010 , I was called a BJP stooge. In 2016 I am still opposing Aadhaar for the same reasons and I am told I am a Congress die hard. No one wants to see why I oppose Aadhaar as it is too difficult. Plus Aadhaar is FREE so why not get one ? Ram Krishnaswamy

First they ignore you, then they laugh at you, then they fight you, then you win.-Mahatma Gandhi

In matters of conscience, the law of the majority has no place.Mahatma Gandhi

“The invasion of privacy is of no consequence because privacy is not a fundamental right and has no meaning under Article 21. The right to privacy is not a guaranteed under the constitution, because privacy is not a fundamental right.” Article 21 of the Indian constitution refers to the right to life and liberty -Attorney General Mukul Rohatgi

“There is merit in the complaints. You are unwittingly allowing snooping, harassment and commercial exploitation. The information about an individual obtained by the UIDAI while issuing an Aadhaar card shall not be used for any other purpose, save as above, except as may be directed by a court for the purpose of criminal investigation.”-A three judge bench headed by Justice J Chelameswar said in an interim order.

Legal scholar Usha Ramanathan describes UID as an inverse of sunshine laws like the Right to Information. While the RTI makes the state transparent to the citizen, the UID does the inverse: it makes the citizen transparent to the state, she says.

Good idea gone bad
I have written earlier that UID/Aadhaar was a poorly designed, unreliable and expensive solution to the really good idea of providing national identification for over a billion Indians. My petition contends that UID in its current form violates the right to privacy of a citizen, guaranteed under Article 21 of the Constitution. This is because sensitive biometric and demographic information of citizens are with enrolment agencies, registrars and sub-registrars who have no legal liability for any misuse of this data. This petition has opened up the larger discussion on privacy rights for Indians. The current Article 21 interpretation by the Supreme Court was done decades ago, before the advent of internet and today’s technology and all the new privacy challenges that have arisen as a consequence.

Rajeev Chandrasekhar, MP Rajya Sabha

“What is Aadhaar? There is enormous confusion. That Aadhaar will identify people who are entitled for subsidy. No. Aadhaar doesn’t determine who is eligible and who isn’t,” Jairam Ramesh

But Aadhaar has been mythologised during the previous government by its creators into some technology super force that will transform governance in a miraculous manner. I even read an article recently that compared Aadhaar to some revolution and quoted a 1930s historian, Will Durant.Rajeev Chandrasekhar, Rajya Sabha MP

“I know you will say that it is not mandatory. But, it is compulsorily mandatorily voluntary,” Jairam Ramesh, Rajya Saba April 2017.

August 24, 2017: The nine-judge Constitution Bench rules that right to privacy is “intrinsic to life and liberty”and is inherently protected under the various fundamental freedoms enshrined under Part III of the Indian Constitution

"Never doubt that a small group of thoughtful, committed citizens can change the World; indeed it's the only thing that ever has"

“Arguing that you don’t care about the right to privacy because you have nothing to hide is no different than saying you don’t care about free speech because you have nothing to say.” -Edward Snowden

In the Supreme Court, Meenakshi Arora, one of the senior counsel in the case, compared it to living under a general, perpetual, nation-wide criminal warrant.

Had never thought of it that way, but living in the Aadhaar universe is like living in a prison. All of us are treated like criminals with barely any rights or recourse and gatekeepers have absolute power on you and your life.

Announcing the launch of the # BreakAadhaarChainscampaign, culminating with events in multiple cities on 12th Jan. This is the last opportunity to make your voice heard before the Supreme Court hearings start on 17th Jan 2018. In collaboration with @no2uidand@rozi_roti.

UIDAI's security seems to be founded on four time tested pillars of security idiocy

1) Denial

2) Issue fiats and point finger

3) Shoot messenger

4) Bury head in sand.

God Save India

Friday, March 2, 2018

12919 - As We Build The ID Systems Of The Future, Where Does Privacy Fit In? - Huffington Post

LIFESTYLE
India’s Aadhaar could be a blueprint for identity systems in the 21st century, but there’s a difference between what institutions want and what individuals need.

By Padmaparna Ghosh

28/02/2018 11:07 SAST | Updated 13 hours ago

                                 DARREN GARRETT

When Anantha Subramanian got a new email address in 2004, he soon found himself living other people's lives. 

"I started getting all kinds of emails, including sensitive material, meant for other people with the name Anantha," says Subramanian, an IT engineer who lives in Chennai, India. 

"One Anantha Laxmi Talluri, a real person, decides to get a bank account and uses my email ID as hers. I start getting her bank statements. The same with telecom companies: I get emails for six or seven numbers, even though I have one number."

A week before we spoke, he'd received an email about someone's insurance claim: details of the incident, phone numbers, an address. No one is verifying these email IDs, which mystifies him. As an IT engineer, he's especially concerned with how data is collected—and how it's maintained—both by private companies and the government. "The system," he says, "is flawed."

Despite his worries about digital security, Subramanian hasn't left the web: He has Facebook and Twitter accounts, he makes purchases online, and he uses search engines even though he knows they track his proclivities. But he's very concerned about digital privacy. He uses an ad blocker, and browses the web incognito. "It may seem like I wear a tinfoil hat, but I take a few precautions on what I post and upload," he says. "It might be misguided. But I have a sense of control."

Few of the websites we give our information to are truly secure; as long as you use Google or Facebook, there's a limit to how much of your data you will ever be able to control. But a Facebook profile isn't mandatory for modern life. What about digital systems that are? As governments around the world build biometric databases and online ID systems, they are creating networks that we can't opt out of.

"It might be misguided. But I have a sense of control."
We've already explored some of the gaps in India's Aadhaar system, and the damage done when people—especially young children—are unable to get a digital ID. Assuming you can get an ID, there are a whole host of other privacy and security issues to contend with. Subramanian is part of a Facebook group where people share stories about Aadhaar data being leaked or misused. "One member posted that he'd received an email from a bank official in India, which had details of all the bank accounts in that branch, with Aadhaar numbers attached," he says.

For all his research, Subramanian does not know where his information goes, who owns it, and which third parties have access to it. This uncertainty defines all of our digital lives: our financial records, job applications, medical information, and, above all, government ID. Can we truly trust that our most sensitive information is secure?

SUBSCRIBE AND FOLLOW
Get top stories and blog posts emailed to me each day. Newsletters may offer personalized content or advertisements. 

Newsletter

                SAUMYA KHANDELWAL / REUTERS
A girl waits for her turn to enrol for the Unique Identification (UID) database system, also known as Aadhaar, at a registration centre in New Delhi, India, January 17, 2018. Picture taken January 17, 2018.

On the web, we're building systems based on relationships that help us figure out who we can trust. 

Those often begin with an email address, even though—as Anantha Subramanian found out—few companies take the trouble of verifying that email ID.

Governments, on the other hand, have long been in the business of verifying identity. When they issue a passport or a driver's license, they have processes in place to make sure it's really your photo and address under the lamination. No form of identity is wholly immune to fraud, but government IDs carry more trust than most.

But will this hold as governments extend their digital reach? Gemalto, a multinational firm which sells digital ID systems, predicts that 3.6 billion people around the world will carry some form of national electronic ID card by 2021. Some countries are using biometrics in their national identity frameworks, from small ones like Nepal to large, populous ones like Mexico.
The Chinese government is planning to take digital identity to a Black Mirror extreme: the Social Credit System will rate the trustworthiness of its 1.3 billion citizens on the basis of daily online activities, social media posts, and tax payments. An individual's rating could be compared to those of other citizens to determine who gets a loan or a job. The emergence of these electronic IDs reflects a concerted move towards digital government which, designed and implemented correctly, has the potential to change lives on a scale that analog identity systems never could.

The Indian national biometric ID card, Aadhaar, has kicked up a storm of concerns since its inception, from inclusion to transparency to privacy to the security of personal data. The government has decided to link Aadhaar to mobile phone numbers, bank accounts, land registrations, car purchases, and, as we saw in the last episode, school admissions: the card could soon be a part of every aspect of private and public life.

"[I]f the Aadhaar number is 'seeded' into all these databases...I lose control over who reconstructs my profile."

"When they set up Aadhaar...the purpose was identification only, and it was voluntary," says Subramanian, the eternal digital privacy worrier. "But slowly, slowly, slowly—look at the scope of it, it's endless." Indian privacy advocates have taken the government to court, challenging the reach of the Aadhaar scheme. Aadhaar has become linked to countless aspects of a person's life, a key that could conceivably unlock every one of those attributes and build a sort of "profile" of an individual.
Reetika Khera, an economics professor at the Indian Institute of Technology in Delhi, explains the risk of the aggregated profile. "Today, information about my life is stored in different data silos — train travel, air travel, bank account, mobile phone, employment history, health," she says. "The only person who can easily construct a full picture of my life is me. But if the Aadhaar number is 'seeded' into all these databases, it integrates these silos, and I lose control over who reconstructs my profile."

Aadhaar is sold to the public as part of the "India Stack," a technology platform that allows integration with both current and future digital services. In theory, it means that any given service will be able to verify someone's ID just by using the biometric information stored in the Aadhaar database.
The India Stack features "layers" where information like bank details for cashless payments can be stored. To pay for something, you'll only need to prove your identity with fingerprints or iris scans. In the future, it might be possible to walk straight through an airport's doors and onto a flight without having to show a passport. But centralizing so much personal data presents a substantial data protection risk; a single data breach could expose everything, and our most private information is on the line.

                SAUMYA KHANDELWAL / REUTERS

A man goes through the process of eye scanning for the Unique Identification (UID) database system, also known as Aadhaar, at a registration centre in New Delhi, India, January 17, 2018.

When you enter your personal information online, it doesn't go directly to the company running the website. There is almost always a middle man in between: a "Customer Identity and Access Management," or CIAM, platform. Many companies offer these services, from large players like Microsoft and Salesforce to smaller ones like Janrain and Auth0.
CIAMs were initially developed to allow different people in a organization access to different amounts of data in a safe and secure way. They were never intended to control data collection, but to protect what was already in the system. Different CIAM providers recommend different privacy protocols to protect their clients' data, but ultimately the decision is up to that client—the company that wants your data.

Oregon-based Janrain follows Privacy by Design, a protocol that minimizes and secures the information collected. "We make sure there's a reasonable purpose for asking for that data," says Mayur Upadhyaya, a managing director at Janrain. "For instance, why do you need the location? Is it to offer some targeted content that customers can opt into? Is it for a delivery service? Then great. If it's arbitrary, then no." But while Janrain advocates for the Privacy by Design approach, it can never fully enforce it. "We could say, this is our best practice, this is our recommendation. But if a customer did want to collect more data, they could."

Companies barter services for our information; states claim the right to diminish our privacy in exchange for things like physical safety and national security.
Governments are slowly becoming aware of the vulnerabilities in their digital data collecting. The European Union, which has a history of standing up to multinational companies over the privacy concerns of its citizens, is trying to give back some of what individuals are losing online: control and ownership. The EU's General Data Protection Regulations (GDPR) takes effect from May 2018. The rules include the right to have your personal information deleted from a company's database (the right to be forgotten); the right to transfer your data from one company to another (portability); and the right to know when your data has been compromised.

The GDPR requires companies to seek your informed consent, in clear and plain language and at every stage, as they collect and store your data. The regulations also ban data "profiling," a technique used to analyze or predict a person's performance at work, economic situation, location, health, or behavior based on the automated processing of personal data. The fines for violating these rules are considerable: smaller offences could result in penalties of up to €10 million or two percent of a firm's global turnover, whichever is greater, and more serious infractions carry penalties of up to €20 million or four percent of global turnover.

NURPHOTO VIA GETTY IMAGES
Facebook's mobile site is testing the 'name as per Aadhaar' prompt when users create a new account.

In an era of data breaches, hacking, and leaks, the stringency of the EU's rules should be a comfort to those who will benefit from their protections. But while governments will protect personal data across the commercial web, data collection by governments themselves is another story. The state, which has our most basic data and controls access to essential services, can be even harder to hold to account than commercial tech giants. Companies barter services for our information; states claim the right to diminish our privacy in exchange for things like physical safety and national security.

This is not a theoretical issue. Estonia, often referred to as the most digitally-minded state in the world, had security issues with its ID cards that made identity theft easier, and had to pause their rollout as a result. While there have been so many leaks from corporate services that it's nearly impossible to keep track, government websites in the UK and the U.S. have had private data leaks in recent years as well.

In India, Aadhaar has been plagued by personal information leaks since its launch. The most recent of over a dozen incidents saw more than 200 government websites publicly host private personal data. Corporations are also finding it hard to secure their data: in July 2017, Reliance Jio, one of India's biggest telecom companies, leaked the data of 120 million people, the largest hack in the country's history. You verify your identity with Aadhaar to get a SIM card—so Aadhaar numbers were leaked as well. As the Centre for Internet & Society has found, giving so many different services access to Aadhaar has greatly increased the risk of abuse and future leaks.




HOW WE GET TO NEXT

What should the objective of a digital identity be? What should it look like? In most users' ideal scenario, it would be a verified, portable ID that would be controlled entirely by the individual, who can choose to parcel out some parts of their identity and not others. Verification should be robust, leaving no room for doubt as to the authenticity of an individual's identity—but once verified, a user should be able to carry that identity into commercial platforms with the assurance that it's just as secure as it would be on a government platform.
Privacy advocates argue that digital identity ought to be sovereign unto itself, unaffected by the circumstances of its use, always fully in control of its owner, and as inalienable a right as any other civic freedom. Individuals should control their digital identities in full, and should be able to choose when to offer or retract it, in whole or in part. These aspects of control and choice are essential, because we cannot know how we will need to deploy our digital identities; we cannot know what the future will hold.
This piece is part of The ID Question, a series examining how identity is changing in the modern world—from ID cards to Facebook profiles, work life to indigenous rights. You can explore the whole series, including videos, a reading list, and more, at How We Get To Next. The ID Question on How We Get To Next is published under a Creative Commons Attribution ShareAlike 4.0 International license.

Suggest a correction

Padmaparna Ghosh

Journalist.