In 2009, I became extremely concerned with the concept of Unique Identity for various reasons. Connected with many like minded highly educated people who were all concerned.
On 18th May 2010, I started this Blog to capture anything and everything I came across on the topic. This blog with its million hits is a testament to my concerns about loss of privacy and fear of the ID being misused and possible Criminal activities it could lead to.
In 2017 the Supreme Court of India gave its verdict after one of the longest hearings on any issue. I did my bit and appealed to the Supreme Court Judges too through an On Line Petition.
In 2019 the Aadhaar Legislation has been revised and passed by the two houses of the Parliament of India making it Legal. I am no Legal Eagle so my Opinion carries no weight except with people opposed to the very concept.
In 2019, this Blog now just captures on a Daily Basis list of Articles Published on anything to do with Aadhaar as obtained from Daily Google Searches and nothing more. Cannot burn the midnight candle any longer.
"In Matters of Conscience, the Law of Majority has no place"- Mahatma Gandhi
Ram Krishnaswamy
Sydney, Australia.

Aadhaar

The UIDAI has taken two successive governments in India and the entire world for a ride. It identifies nothing. It is not unique. The entire UID data has never been verified and audited. The UID cannot be used for governance, financial databases or anything. It’s use is the biggest threat to national security since independence. – Anupam Saraph 2018

When I opposed Aadhaar in 2010 , I was called a BJP stooge. In 2016 I am still opposing Aadhaar for the same reasons and I am told I am a Congress die hard. No one wants to see why I oppose Aadhaar as it is too difficult. Plus Aadhaar is FREE so why not get one ? Ram Krishnaswamy

First they ignore you, then they laugh at you, then they fight you, then you win.-Mahatma Gandhi

In matters of conscience, the law of the majority has no place.Mahatma Gandhi

“The invasion of privacy is of no consequence because privacy is not a fundamental right and has no meaning under Article 21. The right to privacy is not a guaranteed under the constitution, because privacy is not a fundamental right.” Article 21 of the Indian constitution refers to the right to life and liberty -Attorney General Mukul Rohatgi

“There is merit in the complaints. You are unwittingly allowing snooping, harassment and commercial exploitation. The information about an individual obtained by the UIDAI while issuing an Aadhaar card shall not be used for any other purpose, save as above, except as may be directed by a court for the purpose of criminal investigation.”-A three judge bench headed by Justice J Chelameswar said in an interim order.

Legal scholar Usha Ramanathan describes UID as an inverse of sunshine laws like the Right to Information. While the RTI makes the state transparent to the citizen, the UID does the inverse: it makes the citizen transparent to the state, she says.

Good idea gone bad
I have written earlier that UID/Aadhaar was a poorly designed, unreliable and expensive solution to the really good idea of providing national identification for over a billion Indians. My petition contends that UID in its current form violates the right to privacy of a citizen, guaranteed under Article 21 of the Constitution. This is because sensitive biometric and demographic information of citizens are with enrolment agencies, registrars and sub-registrars who have no legal liability for any misuse of this data. This petition has opened up the larger discussion on privacy rights for Indians. The current Article 21 interpretation by the Supreme Court was done decades ago, before the advent of internet and today’s technology and all the new privacy challenges that have arisen as a consequence.

Rajeev Chandrasekhar, MP Rajya Sabha

“What is Aadhaar? There is enormous confusion. That Aadhaar will identify people who are entitled for subsidy. No. Aadhaar doesn’t determine who is eligible and who isn’t,” Jairam Ramesh

But Aadhaar has been mythologised during the previous government by its creators into some technology super force that will transform governance in a miraculous manner. I even read an article recently that compared Aadhaar to some revolution and quoted a 1930s historian, Will Durant.Rajeev Chandrasekhar, Rajya Sabha MP

“I know you will say that it is not mandatory. But, it is compulsorily mandatorily voluntary,” Jairam Ramesh, Rajya Saba April 2017.

August 24, 2017: The nine-judge Constitution Bench rules that right to privacy is “intrinsic to life and liberty”and is inherently protected under the various fundamental freedoms enshrined under Part III of the Indian Constitution

"Never doubt that a small group of thoughtful, committed citizens can change the World; indeed it's the only thing that ever has"

“Arguing that you don’t care about the right to privacy because you have nothing to hide is no different than saying you don’t care about free speech because you have nothing to say.” -Edward Snowden

In the Supreme Court, Meenakshi Arora, one of the senior counsel in the case, compared it to living under a general, perpetual, nation-wide criminal warrant.

Had never thought of it that way, but living in the Aadhaar universe is like living in a prison. All of us are treated like criminals with barely any rights or recourse and gatekeepers have absolute power on you and your life.

Announcing the launch of the # BreakAadhaarChainscampaign, culminating with events in multiple cities on 12th Jan. This is the last opportunity to make your voice heard before the Supreme Court hearings start on 17th Jan 2018. In collaboration with @no2uidand@rozi_roti.

UIDAI's security seems to be founded on four time tested pillars of security idiocy

1) Denial

2) Issue fiats and point finger

3) Shoot messenger

4) Bury head in sand.

God Save India

Wednesday, November 1, 2017

12177 - Data Auditor General: A regulator to protect a Digital India - Live Mint

If sophisticated players such as Equifax can fall prey to cyberattacks, then what are the chances that our government and companies will not suffer the same fate?

As much as technology has enabled privacy breaches, it can and must be enlisted to enforce compliance. Photo: iStock

A little less than a month ago, the identity of every single adult in the US was stolen. On 7 September, the credit bureau Equifax admitted to the fact that their servers were compromised. Think about that for a second. Anonymous hackers now have access to the names, addresses, birth dates, and Social Security numbers—essentially the digital identity—of every American.

Bloomberg released a feature story on the Equifax breach on 29 September that I read with an almost perverse fascination. It details how a Chinese cybersecurity researcher exposed a flaw in popular back-end software for web applications called Apache Struts. This information published on 6 March, showed how the flaw could be used to steal data from any firm using the software.
Within 24 hours, the information was posted to FreeBuf.com, a Chinese security website, and showed up the same day in Metasploit, a popular free hacking tool. From then on, over the course of several months, hackers systematically looted data from the servers undetected until 29 July, when Equifax finally detected the breach.
The breach occurred even though Equifax had invested millions of dollars in sophisticated security measures, ran a dedicated operations centre and deployed a suite of expensive anti-intrusion software. To make matters worse, the fact that users’ data hasn’t shown up on online black markets seems to indicate that it was a state-sponsored hack. In other words, the hack probably isn’t about stealing credit card information, but probably an act of cyber warfare.
While this is without a doubt the worst data breach that’s occurred so far, it’s far from the only one. From Yahoo to Zomato, and even domestic banks, multiple entities that serve Indians have also been victims of such attacks in the recent past.

And so, while this does not seem like a “Bharat” problem today, chances are it will be tomorrow.

If sophisticated players such as Equifax, which spend millions of dollars every year on data security, can fall prey to such attacks, then what are the chances that our government and companies will not suffer the same fate?

The short answer is that if we don’t take proactive, systemic, and ongoing measures to continuously protect user data stored on government and private company servers, it is as good as gone. Because given the current state of security of most of these databases, we might as well download it on a hard drive, gift-wrap it and hand it over to China and Pakistan.

As the nation plunges headlong into Digital India, information on every citizen is steadily being digitized. This information includes financial records, medical data, employment history and demographic details around name, address, religion, etc. The government’s insistence on linking each of these previously disparate databases to a unique identifier, namely one’s Aadhaar number, presents the possibility of aggregating multiple data-points about an individual by indexing across databases.

Let me be clear—I’m not among those that believe that the state is out to get us. I have worked as a volunteer on several government projects, including Aadhaar, and have tremendous respect for the work most government departments undertake, often thanklessly and in the face of severe criticism, to serve citizens.

At the same time, I’m also a firm believer in Hanlon’s Razor, which states—“Never attribute to malice that which is adequately explained by incompetence”.

Hanlon’s Razor was on proud display when details of over 100 million Indians including bank account details with Aadhaar numbers and other personal identifying information were published publicly across a number of government portals a few months ago. While this was done in the interest of transparency around government beneficiary details, these departments failed to balance it with privacy concerns.

This incident is a symptom of a systemic lack of awareness of good information security practices. In order to protect citizen data, we need a holistic systems-driven approach. The first step should be the drafting of a comprehensive law on data protection and privacy, which follows a rights-based approach fundamentally limiting data collection, storage and sharing. The law should ideally specify granular use-based regulations, definitions of offences, procedures of audit and penalties for violations, along with grievance redressal mechanisms.
But a law alone is not enough. We need an independent regulatory authority which will audit both state and private entities and enforce compliance. Data is the currency of the digital age. Therefore, just like the Comptroller and Auditor General, or CAG, audited and enforced compliance for accounts, I posit that we need a Data Auditor General, or DAG, to ensure the same is done for citizen data.

An independent regulator is only as good as the people that staff it. And the founding head of these authorities tends to set the tone for the organization and its future successes. From Homi Bhabha and India’s atomic aspirations to Vijay Bhatkar and PARAM 8000 (India’s first supercomputer) at CDAC to Nandan Nilekani and a billion Aadhaars, India’s history is replete with examples of seemingly impossible goals being achieved by government bodies when helmed by visionaries.

And so it must be with the DAG. I imagine a lean regulatory entity staffed almost entirely by an elite engineering corps. White-hat hackers tasked with the unenviable and never-ending objective of securing the digital histories of India. Imagine a regulatory regime that is almost fully automated and standards-driven. The DAG would prescribe data security standards for every type of entity and audit them through a crawler. No human intervention, no licence-raj era babu handing out certificates of compliance. Our future could be one where data governance is delivered through algorithms.

Such a system could enable the kind of accountability we all yearn for. In case of a data breach, citizens would have the ability to lodge a grievance with the DAG. And since audit trails would be automated and digital, a complete resolution along with a penalty in case of an offence, could be delivered in a specified and limited turn-around time.

As much as technology has enabled privacy breaches, it can and must be enlisted to enforce compliance. At the same time, we cannot understate the importance of building a citizen-centric, truly independent and technically savvy team at the DAG. This is and will remain the most crucial part of ensuring that our data is secured in a future where it is increasingly becoming our most valuable asset.

Sahil Kini is a principal with Aspada Investment Advisors. The Bharat Rough Book is a weekly column on building businesses for the middle of India’s income pyramid.


First Published: Mon, Oct 02 2017. 11 41 PM IST