In 2009, I became extremely concerned with the concept of Unique Identity for various reasons. Connected with many like minded highly educated people who were all concerned.
On 18th May 2010, I started this Blog to capture anything and everything I came across on the topic. This blog with its million hits is a testament to my concerns about loss of privacy and fear of the ID being misused and possible Criminal activities it could lead to.
In 2017 the Supreme Court of India gave its verdict after one of the longest hearings on any issue. I did my bit and appealed to the Supreme Court Judges too through an On Line Petition.
In 2019 the Aadhaar Legislation has been revised and passed by the two houses of the Parliament of India making it Legal. I am no Legal Eagle so my Opinion carries no weight except with people opposed to the very concept.
In 2019, this Blog now just captures on a Daily Basis list of Articles Published on anything to do with Aadhaar as obtained from Daily Google Searches and nothing more. Cannot burn the midnight candle any longer.
"In Matters of Conscience, the Law of Majority has no place"- Mahatma Gandhi
Ram Krishnaswamy
Sydney, Australia.

Aadhaar

The UIDAI has taken two successive governments in India and the entire world for a ride. It identifies nothing. It is not unique. The entire UID data has never been verified and audited. The UID cannot be used for governance, financial databases or anything. It’s use is the biggest threat to national security since independence. – Anupam Saraph 2018

When I opposed Aadhaar in 2010 , I was called a BJP stooge. In 2016 I am still opposing Aadhaar for the same reasons and I am told I am a Congress die hard. No one wants to see why I oppose Aadhaar as it is too difficult. Plus Aadhaar is FREE so why not get one ? Ram Krishnaswamy

First they ignore you, then they laugh at you, then they fight you, then you win.-Mahatma Gandhi

In matters of conscience, the law of the majority has no place.Mahatma Gandhi

“The invasion of privacy is of no consequence because privacy is not a fundamental right and has no meaning under Article 21. The right to privacy is not a guaranteed under the constitution, because privacy is not a fundamental right.” Article 21 of the Indian constitution refers to the right to life and liberty -Attorney General Mukul Rohatgi

“There is merit in the complaints. You are unwittingly allowing snooping, harassment and commercial exploitation. The information about an individual obtained by the UIDAI while issuing an Aadhaar card shall not be used for any other purpose, save as above, except as may be directed by a court for the purpose of criminal investigation.”-A three judge bench headed by Justice J Chelameswar said in an interim order.

Legal scholar Usha Ramanathan describes UID as an inverse of sunshine laws like the Right to Information. While the RTI makes the state transparent to the citizen, the UID does the inverse: it makes the citizen transparent to the state, she says.

Good idea gone bad
I have written earlier that UID/Aadhaar was a poorly designed, unreliable and expensive solution to the really good idea of providing national identification for over a billion Indians. My petition contends that UID in its current form violates the right to privacy of a citizen, guaranteed under Article 21 of the Constitution. This is because sensitive biometric and demographic information of citizens are with enrolment agencies, registrars and sub-registrars who have no legal liability for any misuse of this data. This petition has opened up the larger discussion on privacy rights for Indians. The current Article 21 interpretation by the Supreme Court was done decades ago, before the advent of internet and today’s technology and all the new privacy challenges that have arisen as a consequence.

Rajeev Chandrasekhar, MP Rajya Sabha

“What is Aadhaar? There is enormous confusion. That Aadhaar will identify people who are entitled for subsidy. No. Aadhaar doesn’t determine who is eligible and who isn’t,” Jairam Ramesh

But Aadhaar has been mythologised during the previous government by its creators into some technology super force that will transform governance in a miraculous manner. I even read an article recently that compared Aadhaar to some revolution and quoted a 1930s historian, Will Durant.Rajeev Chandrasekhar, Rajya Sabha MP

“I know you will say that it is not mandatory. But, it is compulsorily mandatorily voluntary,” Jairam Ramesh, Rajya Saba April 2017.

August 24, 2017: The nine-judge Constitution Bench rules that right to privacy is “intrinsic to life and liberty”and is inherently protected under the various fundamental freedoms enshrined under Part III of the Indian Constitution

"Never doubt that a small group of thoughtful, committed citizens can change the World; indeed it's the only thing that ever has"

“Arguing that you don’t care about the right to privacy because you have nothing to hide is no different than saying you don’t care about free speech because you have nothing to say.” -Edward Snowden

In the Supreme Court, Meenakshi Arora, one of the senior counsel in the case, compared it to living under a general, perpetual, nation-wide criminal warrant.

Had never thought of it that way, but living in the Aadhaar universe is like living in a prison. All of us are treated like criminals with barely any rights or recourse and gatekeepers have absolute power on you and your life.

Announcing the launch of the # BreakAadhaarChainscampaign, culminating with events in multiple cities on 12th Jan. This is the last opportunity to make your voice heard before the Supreme Court hearings start on 17th Jan 2018. In collaboration with @no2uidand@rozi_roti.

UIDAI's security seems to be founded on four time tested pillars of security idiocy

1) Denial

2) Issue fiats and point finger

3) Shoot messenger

4) Bury head in sand.

God Save India

Showing posts with label Aadhaar Fraud. Show all posts
Showing posts with label Aadhaar Fraud. Show all posts

Friday, June 22, 2018

13700 - People warned against surge in cyber-crimes - Hans India

THE HANS INDIA |   Jun 16,2018 , 01:16 AM IST
   
 
                            SP Sarvasrest Tripathi


Vijayawada: Criminals are using every opportunity to rob the bank customers by asking their personal and bank account details over phones. Three cybercrime cases have been reported in Krishna district in the last two months.

Even educated people are duped and cheated by the criminals. A school teacher lost Rs 65,000, a college lecturer lost Rs 56,000 and an elderly man lost Rs.18,000 in three different cases registered in Krishna district within two months.

According to Superintendent of Police Sarvasrest Tripathi, a school teacher in Bantumilli village was duped by a cyber-criminal, who robbed Rs 65,000 from his bank account. The victim has applied for the credit card two months ago.

Recently, a caller from Mumbai introduced himself as SBI official and collected details from the school teacher. The victim had trusted the caller and informed the OTP and other details related to his bank accounts. The accused had cleverly robbed Rs 65,000 from the bank account of teacher, said the SP.

Tripathi said case was booked by the Bantumilli police in this regard. He asked the people not to give any details related to password, OTP, bank account numbers to others.

In another case, a lecturer in Machilipatnam was cheated by a criminal. The unknown caller said the Aadhar card details should be linked to his bank account. SP Tripathi said the lecturer blindly trusted the caller and gave information and later noticed Rs 56,000 was missing from his bank account. Machilipatnam police are investigating the case.

In another case, an unidentified person robbed Rs 18,000 from an illiterate elderly man in Jaggaiahpet recently. The aged man asked an unknown person to withdraw cash from the ATM. The culprit duped the old man and gave another ATM card and he escaped with the card of old man. The victim lodged a complaint with the Jaggaiahpet police about the cheating.

the people to be careful with the cyber criminals and said the culprits were seeking details of OTPs, passwords, bank account numbers, Aadhaar numbers and other details over phone. He appealed to people not to reveal any information regarding their bank and Aadhaar number details to others.


He suggested the people to go to their banks personally and speak to the staff concerned to get information. The SP said the offenders are using every opportunity to rob the bank customers and suggested the latter not to disclose any information to others.  

13692 - Telangana: Members of inter-district gang arrested - The Hindu


SANGAREDDY, JUNE 15, 2018 00:03 IST

The five are accused of robbing liquor shops and vehicle theft
The police of Sangareddy (Rural) arrested five members of an inter-district gang involved in robbing liquor stores.
Police said after breaking into liquor stores, the stolen liquor was sold at a licensed shop located at Machareddy in Kamareddy district.

The gang was also involved in lifting of cars from showrooms at Sangareddy and other places. Another four members of the gang were still at large. Police have recovered about ₹3.95 lakh cash from them.

The arrested were identified as Gurrala Srinivas, Nayakera Shiva, Velupuala Shiva Kumar, Burla Satish and Siddula Srikanth. Another four persons Rajita, Radhika, Gopala Rao and Satish were absconding.

Police said the accused had changed their names and obtained fraudulent Aadhaar cards. They have a criminal history of at least six years. Repeated efforts by the police to identify them went in vain, until they were finally nabbed.

The gang was involved in thefts at Sangareddy, Medak, Siddipet, Kamareddy, Nizamabad, Karimnagar, Warangal, Jagityal and Peddpally districts and committed as many as 43 offences. Police said 38 of these instances involved robbing liquor stores and five were vehicle lifting cases.

Disclosing the details here on Thursday, S. Chandrasekhar Reddy, Superintendent of Police, said the gang members were constructing houses at Machareddy, which would be attached in the case. He said Srinivas had changed his name to Srinivas Goud.


He said that Rural Circle Inspector Narender, Sub- Inspector Srikanth and others involved in nabbing the accused would be rewarded.

Wednesday, June 20, 2018

13680 - With A Rubber Stamp Of His Thumb, Aadhaar Officer In Maharashtra Was Running A Money-Making Scam - Huffington Post

11/06/2018 9:47 AM IST | Updated 11/06/2018 9:48 AM IST

The Aadhaar Enrolment Officer has been booked for cheating and forgery
  • HuffPost Staff


SAUMYA KHANDELWAL / REUTERS

The Aadhaar is supposedly tamper proof, but Indians have long been able to find a way around the rules, and the latest from Maharashtra is that an Aadhaar enrolment officer in Waluj, Aurangabad, had a team of subordinates using his thumb impression to access the Aadhaar software.

According to a Times of India report, the Aadhaar enrolment officer, Mangesh Sitaram Bhalerao, prepared a rubber stamp of his thumb impression, and then gave it to underlings who were able to use this to access the Aadhaar software, which can be used to register new people and also edit existing Aadhaar data.
The enrolment officer and his 'workers' then made money by charging people for registering for Aadhaar, or making corrections in the existing Aadhaar cards. The UIDAI has lodged a police complaint, and charges of forgery and cheating have been raised.

Maharashtra Industrial Development Corporation (MIDC) Waluj inspector Dnyaneshwar Sable told the Times of India, "The gross breach came to light on April 16, when two application analysts reached the city and inspected Arihant Xerox at Maharana Pratap Chowk of Bajajnagar, only to find that the person carrying out the Aadhaar work had neither a valid license nor was authorised to do so."

Although this ring has been busted, the case raises a number of questions. At the start of the year, a report in the Tribune showed that you can have access to Aadhaar data for just Rs. 500.

After the paper sent Rs. 500 via Paytm to an agent, it was given a login ID and password with which to access Aadhaar data, without any biometric authentication. Later, another report went on to show that cracked Aadhaar software was being circulated for prices ranging from Rs. 500 to Rs. 2,000.


But these are still sophisticated hacks that would have taken a lot of time and effort to put together. On the other hand, being able to break the security protocol of the Aadhaar with a rubber stamp, as the enrolment officer in Aurangabad did, shows just how serious the security concerns around Aadhaar are.

Wednesday, June 6, 2018

13648 - India's biometric identification system is becoming increasingly susceptible to fraud - Business Insider


DILSHER DHILLONJUN 4, 2018, 12.59 PM

At the beginning of 2018, the Unique Identification Authority of India (UIDAI) declared that the individual Aadhaar card details of Indians were “fully safe and secure”. The statement was a response to reports that 210 government-run websites had made Aadhaar info and bank details of a number of people public. 

To confirm their belief, UIDAI added that the Aadhaar card details of a person couldn’t be misused without their biometric data as transactions could only be processed after biometric authentication. 

Five months later, the UIDAI’s statement rings false in more ways than one. 

A report in IndiaSpend highlights the fact that the number of Aadhaar-related fraud incidents reported in the English-language media outlets in the year so far (as of 7 May) is 73. This has already surpassed the total of 65 incidents reported in 2017. 

This means that there are roughly four incidents of Aadhaar fraud that are reported by English news outlets every week. The number would likely be much higher if Hindi and regional language media outlets were taken into account. Further still we must also account for the fact that a lot of incidents involving fraud go unreported. 

A total of 164 cases of fraud have been reported since the scheme’s launch in September 2011 that currently has around 1.2 billion people currently enrolled. 

Nature of fraud 

The incidents mainly involve the forgery, counterfeiting and outright theft of Aadhaar card information for a variety of reasons - purchasing SIM cards, securing loans, transferring assets, and receiving handouts from the government. Around 52 out of the 73 cases recorded as of May 2018 centre on the use of fake or forged Aadhaar card information or the use of fake details to get an Aadhaar card. 

The remainder involve the use of stolen or fake Aadhaar card data in banking transactions. For example, in March, an investigation by the Mumbai police uncovered the opening of around 40 bank accounts with stolen Aadhaar card details. The accounts were opened for the purpose of financing an import-export business. 

Lack of awareness 

A significant portion of these frauds is due to the lack of awareness people have regarding their privacy and identity rights. Those enrolled on the Aadhaar scheme aren’t completely aware of what they can and can’t share with third parties and government agencies, as well as all the ways their information can be misused. If it can happen to anyone, people usually assume the odds of it happening to them are very low. 

Furthermore, the biometric authentication aspect of the programme is itself flawed. As per documents from the Supreme Court, the UIDAI itself admitted that authentication failure rates for transactions through fingerprints and irises were 6% and 8.5%, respectively. 


Last month, a 38-day hearing over the privacy and data security issues of the Aadhaar scheme came to an end. While a verdict on the constitutional validity of the scheme is expected within the next few months, the Supreme Court did declare that the scheme needed more effective regulatory oversight. 

13642 - SIM swap becomes the new threat on cyber crime front - TNN


Dwaipayan Ghosh | TNN | Jun 2, 2018, 08:40 IST

KOLKATA: Tania Bhattacharya of Regent Estate in south suburban Kolkata received a call, allegedly from her cellphone service provider two weeks ago and was offered a SIM upgrade. The caller asked her to share her 20-digit SIM number and her Aadhaar number, which she provided. However, what she didn’t realise was that her bank details had already been stolen and, within 72 hours she was duped of Rs 70,000. 

“As the caller did not ask for personal details, she divulged her SIM and Aadhaar numbers,” said an officer. 

The anti-bank fraud section of Lalbazar said the SIM-swap fraud has become a new headache in Kolkata. While the mobile service providers have reacted to this by making Aadhaar number mandatory to issue a SIM card, the fact that the cops busted a gang working with fake SIMs in central Kolkata has proved that this is not a major challenge for fraudsters. 

The operation — which hit the US and Europe in 2013 — began here last year, mostly targeting senior citizens.

“Fraudsters are pretending to upgrade SIM cards and gaining access to any transactions that you conduct through your phone,” explained an officer. “The caller claims to be a customer care representative of the network provider and informs the victim that the SIM could easily be upgraded from 3G to 4G. Alternately, he offers to link the Aadhaar number with the mobile phone. As the victim agrees to continue with the offer, the fraudster tells him to check his messages. He is told he would receive a text to which he must reply by pressing ‘1’. After this call, the victim’s number gets shut down. He remains unaware of the fraud till he sees his bank statements,” he said.

LATEST COMMENT
Mobile service provider should take necessary action such as advertising on this issue so that all will be aware of this.
Raja Datta

SIM swapping is usually the second phase of a fraud attack. Initially, the criminals send a phishing email to get the intended victim’s banking details. These details can also be stolen using trojans or malware. They work towards getting the victim’s personal information and may even go as far as stealing identity and creating fraudulent ID documents. In order to use all of this, they need access to the victim’s mobile messages, hence the SIM is swapped.


“The scamsters are making the customer apply for a new SIM card and the victim unknowingly accepts the request. The numbers being used to commit the fraud are registered mostly in Jharkhand and Bihar,” said an officer. We have come across a few cases where the SIM has been changed, but no financial frauds have been carried out yet. We are investigating these cases as well,” he said.

Friday, May 25, 2018

13586 - From cheating banks to faking identity, Aadhaar frauds peak in 2018: Report - Business Standard


At a recent court hearing, UIDAI admitted that 6% of Aadhaar authentication requests using fingerprints transactions are known to fail

Last Updated at May 23, 2018 09:44 IST

ALSO READ
In January 2018, eight persons were arrested in Chandigarh for purchasing expensive mobile phones with fraudulent loans secured using fake Aadhaar cards. The accused, among whom were former bankers and employees of a finance company, had placed their own photographs on others’ Aadhaar cards to secure bank loans, and were booked for cheating, fraud, forgery and criminal conspiracy under the relevant sections of the Indian Penal Code.

This is just one among the 73 incidents of misuse of the Unique Identity Authority of India’s (UIDAI) Aadhaar programme that have been reported in the English-language media so far this year (up to May 7, 2018). This averages nearly four incidents each week, as per a new database created by independent researchers Anmol Somanchi and Vipul Paikra.

Of these, 52 cases involved fake or forged Aadhaar numbers–coming up with entirely new Aadhaar enrolment based on fake details, or forging existing cards by replacing certain details like photographs–and 21 involved Aadhaar-related banking frauds.
In the six years since the launch of the Aadhaar programme in September 2011, 164 cases of forged or fake Aadhaar numbers and Aadhaar-related banking frauds have been reported in the English-language media, the database noted. These include 123 cases of fake or forged Aadhaar numbers or cards and 41 cases of Aadhaar-related banking fraud.

“This database does not include the whole gamut of reported incidents of Aadhaar-related fraud and forgery,” Somanchi told IndiaSpend. “We had initially included Hindi reports and found more such incidents. However, since we couldn’t include all other regional languages we restricted the database to English news reports.”

Several attempts to reach out to the UIDAI for comment on the findings of the database met with no response. On April 30, 2018, IndiaSpend reached out to the office of the chief executive officer of UIDAI via email. On May 2, 2018, we reached out again and were told by the communications team that UIDAI would get back to us. On May 3, 2018, IndiaSpend reached out a third time, telephonically. On May 8, 2018, we sent out a third email.

The story will be updated with the Authority’s response when we receive one.

Lack of clarity
“The ambiguity around Aadhaar has led to an increasing number of cases where citizens are swindled of their money,” Somanchi said. “India is still grappling with limited financial, technological literacy–people aren’t sure of what they should or should not share and the authorities have failed to provide that clarity.”
The government has been speaking “with a forked tongue” in this regard, Somanchi said, adding, “On one hand they insist the uniqueness of the Aadhaar number prevents duplicity and is an in-built layer of security–on the other hand they advise caution on sharing of Aadhaar details. So what should citizens believe?”

As of April 2018, more than 1.2 billion Indians–99.7% of the population–had enrolled under the programme. The Aadhaar database, which the government is keen to integrate with policy, regulation and benefits-transfer programmes, includes fingerprints, iris scans and demographic details of every enrolled individual. From July 1, 2018, the system will also include facial recognition features for identity authentication.

Year-Wise Aadhaar Enrolment And Cases Of Fake Or Fraud Aadhaar Reported
Year
Citizens Enrolled (Cumulative)
Reported Incidents Of Aadhaar Misuse
2011
100 million

2012
210 million
3
2013
510 million
1
2014
720 million
4
2015
930 million
6
2016
1.11 billion
13
2017
1.18 billion
65
2018*
1.21 billion
73

Source: Unique Identity Authority of India; Somanchi & Paikra’s database of media reports on Aadhaar-related forgery, counterfeit and fraud

Note: *Data as of May 2018


1/3rd cases involve multiple UID numbers
Among cases of fake or forged Aadhaar numbers or cards, 52 of the 123 reported incidents (42%) involved forgery of only Aadhaar details, according to the database.
In at least 38 cases (31%), other documents such as permanent account number–a unique 10-digit alphanumeric identity allotted to taxpayers by the income tax department–driver’s license and voter identity card were also forged or faked, the database showed.

In a recent case of forgery reported from Mumbai, 40 bank accounts had been opened using forged documents including Aadhaar, as noted in the Hindustan Times report of March 31, 2018, that is included in the database. The accused–who had acquired eye and finger scanners to produce fake Aadhaar numbers–would charge Rs 2,000 to make a fake Aadhaar card, Rs 800 to 1,000 for a fake PAN card, Rs 10,000 for a fake driver’s license and Rs 1,000 for a fake voter identity card, the report said.

Information on how many documents were forged was unavailable for 33 or 27% of cases, the database noted.
More than a third (43) of the fake or forged Aadhaar card/number cases involved forgery of multiple Aadhaar numbers, which researcher Somanchi has described in the database as an “Aadhaar racket”. These include five cases where Aadhaar numbers have been counterfeited to misuse the public distribution system (PDS), under which subsidised foodgrain and non-food items are provided to underprivileged citizens across the country.

In Bengaluru, for instance, the Karnataka state food and civil supplies department had discovered large-scale use of fake Aadhaar numbers linked to bogus below-poverty-line (BPL) ration cards to siphon off subsidised foodgrain distributed under the state’s Anna Bhagya scheme, according to this Deccan Chronicle report from October 13, 2016, listed in the database.

Controversies, contestations
However, Aadhaar-related hiccups are far fewer than other problems holding up beneficiaries’ access to PDS, the State of Aadhaar Report 2017-18 by philanthropic investment firm Omidyar Network, released on May 17, 2018, showed.
Between September and December 2017, about 2 million PDS beneficiaries in rural Andhra Pradesh, Rajasthan and West Bengal, accounting for 0.8%, 2.2% or 0.8% of all PDS beneficiaries, respectively, were found excluded from the states’ PDS programmes due to Aadhaar-related factors. However, a much larger proportion of beneficiaries, 6.5%, were excluded due to non-Aadhaar factors (such as non-availability of ration), the report said.

From 2014-15 to 2017-18, Aadhaar’s direct benefit transfer system as well as digitisation and other initiatives had enabled the government to detect and delete 27.5 million fake and duplicate ration cards, saving Rs 16,792 crore in the PDS programme, the report added.

However, the government did not provide data to back this claim. It also did not clarify how the deletions were counted, if they included genuine beneficiaries caught up in the system’s technical snags, and how Aadhaar specifically contributed to deletion of fakes, the report said.

Eliminating identity corruption has been one of the primary aims of the Aadhaar programme, but some experts believe Aadhaar integration has led to no significant gains for welfare programmes, as economist Reetika Khera said in this study published in the Economic & Political Weekly in December 2017.
Aadhaar-linking has facilitated over-centralisation of administrative controls, Khera argued in her study. “If a person does not get authenticated, there is no easy or accessible redress available… adding a sense of disempowerment,” she said. Further, privileging Aadhaar over other technologies that had a proven track record at improving administration displaced efforts to scale those up, she said.

“The evidence increasingly suggests quantity fraud more than identity or eligibility fraud is the main problem in welfare corruption,” Somanchi told IndiaSpend. “Despite Aadhaar, there are still instances of individuals getting more or less than the allotted amount of foodgrains and other rations under the PDS and this issue remains unaddressed.”

Aadhaar rackets aside, 19 cases of illegal migrants faking or forging Aadhaar identities to reside in India have also been reported, the database noted. In four cases, Aadhaar numbers were forged to fraudulently obtain bank loans. In two cases, terrorists had procured fake/forged Aadhaar numbers to legitimise their stay in the country.

The Aadhaar programme has always been controversial, particularly since the government’s 2016 move to compulsorily link several government services and benefits with Aadhaar, as IndiaSpend reported on March 31, 2017. The Supreme Court has just finished hearing a bunch of petitions challenging the constitutional validity of Aadhaar–the second-longest oral hearing in the history of the top court–and is likely to announce a verdict in July or August, DNA reported on May 11, 2018.
At one of the hearings, Attorney General K. K. Venugopal, appearing for the state, argued that the programme would prevent bank fraud, illegal financial transactions, and the misuse of telecommunication networks by terrorists, The Financial Express had reported on April 5, 2018.

However, the apex court observed that Aadhaar could do little to stop banking fraud and questioned the government’s move to demand that the entire population of the country link their mobile phones with Aadhaar “just to catch a few terrorists”, the The Financial Express report said.

“This is a fundamental misunderstanding of what causes terrorism or banking frauds,” Somanchi said. “Serving up Aadhaar as a panacea for all problems is taking it too far. A socio-economic problem such as terrorism can’t be solved with a technological fix like Aadhaar–assigning sophisticated numbers to individuals isn’t a crime deterrent.”

Further, there have been cases where individuals have been unable to use their Aadhaar cards as proof of identity because their biometric data did not match with the records.
At a recent court hearing, UIDAI admitted that 6% of Aadhaar authentication requests using fingerprints (927,123 transactions) are known to fail, and 8.5% (36.9 million transactions) using iris scans, LiveLaw reported on April 3, 2018.

In all, Aadhaar-based biometric authentication for accessing government services have been recorded as failed 12% of the time, UIDAI told the court, according to this report in TheQuint on March 29, 2018. It denied, however, that this meant exclusion from or denial of subsidies or benefits, saying the authentication requesting agency is supposed to use alternative means of identification in such cases, the LiveLaw report said.
Combined with the findings of the database, UIDAI’s submissions in court suggest neither are Aadhaar biometrics reliable, nor are the cards infallible, Somanchi said.

(Saldanha is an assistant editor with IndiaSpend. Manpreet Singh, an intern with IndiaSpend and a graduate student at the Symbiosis School of Economics, Pune, contributed to the story.)
We welcome feedback. Please write to respond@indiaspend.org. We reserve the right to edit responses for language and grammar.






First Published: Wed, May 23 2018. 09:44 IST

13573 - ‘Illegal conversion’ through AADHAAR - Herald Goa

19 MAY 2018
05:03AM IST


The lady with two Aadhaar cards may have opened up a Pandora’s box, as to how she effortlessly could lay her hands on two ‘identity’ cards with different names and faiths, with the same photograph. Questions must be raised as to who helped her and whether this could be a racket waiting to be unearthed. Obviously, there is more than what meets the eye and officials concerned must take a serious note and possibly probe the matter, for it is not only for the data safety of the individual, but also for social security. NESHWIN ALMEIDA believes the matter needs to be probed, unless it is a case of sheer negligence

While the parish priest, the parishioners and all those who apprehended the lady with two Aadhaar cards and a bunch of scooter keys, may have eventually forgiven the woman on humanitarian grounds, considering the ‘thief’ had two minor children, the question remains why no probe was initiated by the Cuncolim police on how she managed to be in possession of two Aadhaar cards with different names.

For those who claim it to be a minor issue, the security angle should be considered, as those with malafide intentions could harm the society and even the country, if procuring dual or even more Aadhaar cards by one person was not such a difficult affair.

It may be brought to light that a fortnight ago a lady thief was caught red-handed by locals while breaking open the storage space under the seat of scooters parked by devotees outside Our Lady of Hope Church, Chinchinim, knowing that most that attend church service keep their cash and valuables there, before entering the church.

What made the case appear like no other witnessed in the area was not the fact that the lady in question was found in possession of a bunch of scooter keys, but the fact that she was apprehended with two different Aadhaar cards, with two different names, but bearing her photograph on both.

Despite a hue and cry being made for possessing two Aadhaar cards – one with a name of person belonging to one faith and the other with a name from another faith, of the same person, Cuncolim police have failed to register an FIR, nor have initiated an investigation on how she could have dual Aadhaar cards, that too with different names.

A random investigation in such cases will reveal that the Delhi police had filed the first FIR in the country and are investigating a similar situation in March 2017, wherein a local was arrested in Delhi for holding two Aadhaar cards in one name and bio-metrics.

The modus operandi in the incident at Chinchinim too was similar. Locals recovered two Aadhaar cards from the woman, where her name appeared as Amreen Shaikh in one Aadhaar card and Akshata Vaibhav Naik on the other, when she was caught red-handed stealing from scooters parked outside the Chinchinim church.

“Both the Aadhaar cards had registration number 3893 5437 1462 and it’s not really a case of two Aadhaar cards in the same or biometrics, but rather one card with two different details. But the locals backed out from filing any FIR against the lady as she had two small children and was apparently pardoned by the mob, leaving us to ignore the matter,” explains Cuncolim PI Harish Madkaiker, who elaborately defended as to why no FIR was filed or any probe initiated.

Similarly, Fr Antonio Costa, parish priest of Chinchinim, explained that the parishioners and villagers did not file a case only because they did not want to communalise the matter, as the lady was from a different religion and also because she had children below five years of age.

“The problem here is that of identify. People often make changes post marriage or update details based on changes on another identity document. In such a scenario people are left with two Aadhaar copies with different details. But the most-recent updated as per the date of issue will be the one that can be authenticated for official identity purpose. There needs to be a system to cancel the previously issued Aadhaar card or we should demand the old one and officially destroy it which is not currently done as it can be misused. However, for official purpose the government database will accept only the last issued copy,” explains Harish Amonkar, UID Aadhaar in-charge for Goa centre.

“Even worse is the fact that the Goa government is yet to make amendments to identity proof for address and many departments still do not use or accept Aadhaar card, especially at Hospicio or even the transport department for vehicle licenses or driving licenses, as there is misuse of documents like election card and license, which are devoid bio-metrics,” Minaks Naik, an agent who facilitates issuing driving licenses at Margao, pointed out.




Thursday, May 10, 2018

13498 - Rs 1 lakh gone from account after ‘SIM-swap’ call - TNN


Bagish Jha | TNN | May 9, 2018, 01:49 IST

GURUGRAM: A 28-year-old woman was cheated of Rs 1 lakh on May 3 by a man who claimed to be an executive calling from her telecom operator’s office. 

“I am using Airtel for the last 10 years. On May 3, I received a call from a man, who identified himself as a customer care executive, and asked me to reveal my Aadhaar number for the verification process. He then sent me an SMS which he asked me to forward to 121 (the customer care number),” Nidhi Sharma, a resident of Sector 10A, told the police. 

Allegedly, the man told her that after forwarding the message, her mobile number would get deactivated for 24 hours by when the verification would be completed. 


The message, that the accused sent, had a 20-digit number. Within 5 minutes of Sharma forwarding the SMS, her SIM got deactivated. “In the meantime, I noticed some alerts on my email id about some net-banking login attempts,” Sharma said. She realised that she had been cheated and immediately called her bank’s customer care, asking them to block her account. 

Next day, when she visited the bank, she was informed that Rs 1 lakh was withdrawn from her account in three transactions (Rs 50,000, Rs 25,000 and Rs 25,000). “Though my SIM card wasn’t working, I didn’t get any transaction alert on my email id too. More so, even if the accused hacked my bank account, I can’t understand how they got the unicode, that bank shares only with customers,” Sharma said.

She approached the cyber cell of Gurugram police on Sunday and filed a complaint. According to the cops, several people have fallen prey to online fraud in the name of Aadhaar verification recently. 

“The message that Sharma was asked to forward to 121 was for SIM swapping. Therefore, her number got deactivated,” said a cyber cell officer.

An FIR under relevant IPC and IT Act sections has been registered in Cyber Cell police station

Tuesday, May 8, 2018

13487 - UIDAI On the Defensive Again Amid Aadhaar Fraud Claims - Find Bio Metrics

Posted on May 7, 2018

“This isn’t the first time the UIDAI has sought to publicly defend itself against allegations that it is mishandling or not adequately securing the Aadhaar database, which is now used to authenticate Indian citizens across a wide range of scenarios.”

The Unique Identification Authority of India is once again defending its administration of the country’s Aadhaar biometric ID program in the wake of alleged security flaws.

In a press release, the agency says it “completely dismisses” reports of Aadhaar’s enrollment software having been tampered with and sold on the black market, leading to the production of fraudulent Aadhaar cards. In so doing, the UIDAI insisted that it adheres to a “stringent enrolment and updation [sic] process” in which the fingerprint and iris biometrics uploaded to the system are matched against all other stored templates, ensuring that there is no way that an administrator could enroll their own biometrics as the credentials for a fraudulent Aadhaar identity.
UIDAI added that other checks are also in place, such as verifying the enrollment machine; and that in cases where fraudulent Aadhaar creation has been attempted, “[t]he concerned enrolment machines and the operators are identified, blocked and blacklisted permanently from [the] UIDAI system,” adding that complaints are also made to police authorities where appropriate.

This isn’t the first time the UIDAI has sought to publicly defend itself against allegations that it is mishandling or not adequately securing the Aadhaar database, which is now used to authenticate Indian citizens across a wide range of scenarios. For example, last November, the agency tried to reassure citizens that the online publication of Aadhaar information on more than 200 government websites was a “proactive disclosure” on the part of government authorities, and not the leak it was widely perceived to be. In its latest defense concerning its protocols for Aadhaar operators, the agency says that so far over 50,000 operators have been “blacklisted”, a claim meant to demonstrate the organization’s “zero tolerance” approach, but which also points to what looks like a substantial problem in Aadhaar ID issuance.

May 7, 2018 – by Alex Perala

Friday, May 4, 2018

13450 - Bill Gates endorses Aadhaar scheme; says it doesn't pose privacy issues - Business Today


New Delhi     
Last Updated: May 3, 2018  | 16:52 IST

Aadhaar has been a boiling issue in India for the past few months. Data theft cases for as little as Rs 500, fake software to create Aadhaar cards, and alleged 'loopholes' in the unique identity scheme have left a dent on its credibility. It has been facing increased scrutiny over privacy concerns following several instances of breaches and misuse. Despite all this, Aadhaar as a scheme has been appreciated by many prominent people all over the world. Bill Gates, founder of one of the world's biggest tech companies, Microsoft, has been a staunch supporter of the Aadhaar scheme since the very beginning of its rollout. This time, he has again come out openly saying the Aadhaar technology does not pose any privacy issue. Not only that, he also appreciated Prime Minister Narendra Modi for fully "embracing" the scheme, which was initiated during the previous UPA regime.

The founder of Bill and Melinda Gates Foundation told PTI his organisation has funded the World Bank to "emulate" the project as it is worth doing so. Bill and Melinda want other countries to also adopt the scheme. "The bio-ID verification programme has multiple benefits," says Bill. To undertake this level of project in other countries, the World Bank and the Gates Foundation have reportedly roped in multi-billionaire Nandan Nilekani. The Infosys founder, who is also considered as the chief architect of Aadhaar, will consult and help the World Bank carry out the 'Aadhaar-like' project in other countries.
After the successful implantation of the Aadhaar scheme in India, other countries have also approached New Delhi for assistance in creating similar data base.

Appreciating India for successfully implementing the scheme, Gates said India's Aadhaar technology could be implemented across the world. Bill Gates thinks the Aadhaar-like scheme could help improve governance, which is directly linked to economic growth and the overall improvement in society.
"The benefits of that (basic ID -- Aadhaar) are very high. Yes, countries should adopt that approach because the quality of governance has a lot to do with how quickly countries are able to grow their economy and empower their people. Aadhaar in itself doesn't pose any privacy issue because it's just a bio ID verification scheme," said Gates.

One of the world's richest men, Bill Gates, also tried to sooth fears around the Aadhaar data misuse, saying individual application users need to properly check who can see information. He also defended financial institutions seeking Aadhaar details for opening an account. "Application by application, you have to make sure that's well-managed. In the case of the financial bank account, I think it's handled very well. (It uses) Aadhar to set up the accounts so that you can both get your cell phone and get your bank account," he said, reported the agency.

He said some of the initiatives carried out by the Narendra Modi government on digitisation could help improve the level of education in the country, and hence, the governance. Before this in 2016, Gates had said the Aadhaar is a scheme "never been done by any government before, not even in a rich country". The UIDAI's ambitious Aadhaar project is the world's largest biometric database with whopping 111 crore people of the total 125 crore Indians already connected with the identity scheme.


Thursday, May 3, 2018

13439 - Aadhaar Fraud is Not Only Real, But is Worth More Closely Examining - The Wire



An online examination of publicly reported incidents shows that contrary to its proponents’ claims, Aadhaar has indeed facilitated a range of frauds.

Aadhaar is designed to be a number, not a card. In fact, the word ‘card’ does not figure even once in the Aadhaar Act. 
Credit: PTI

270
interactions

8 HOURS AGO

Aadhaar, India’s biometric authentication number, is often touted to be the ‘most trusted ID’ in the country. One of the arguments made in favour of Aadhaar is that it is more reliable compared to other IDs which can be easily faked or forged.

In the ongoing Supreme Court hearings, the Indian government and the Unique Identification Authority of India (UIDAI), the agency implementing the Aadhaar project, have repeatedly argued that Aadhaar will help curb ills like terrorism and banking fraud by ensuring that only “genuine” persons get access to mobiles, and banking services.

Keeping aside the fact that such arguments suggest a complete misunderstanding (or perhaps intentional misrepresentation) of what causes terrorism and banking frauds, a question remains: is Aadhaar as reliable and infallible as it is claimed to be? 

Contrary to the claims of curbing fraud, there have been various news reports which suggest that fake and forged Aadhaar details have facilitated frauds and unscrupulous activities. That Aadhaar could open the door to identity fraud and identity theft is something that has not been fully understood yet.

In the absence of any official data on this issue, a Google search was done for four sets of keywords – ‘fake Aadhaar’, ‘forged Aadhaar’, ‘Aadhaar fraud’ and ‘Aadhaar scam’ – to explore this vulnerability further.

The aim of the search was to get a better sense of the extent to which Aadhaar was being used for frauds and what made such use possible.

About 100 different cases (31 of which are from 2018) from all over the country were found where fake or forged Aadhaar was used. The full list can be accessed here.



A snippet of the online search for Aadhaar fraud. Credit: The Wire

Even this number is quite likely to be an underestimate as the search was restricted to only English media outlets. It is important to note that these cases are not meant to be exhaustive nor representative, but instead, seek to bring to light an issue that has not received much attention.

A long list of frauds
The search reveals that Aadhaar has been used for a wide range of purposes – carrying out land transfers, procuring passports, getting loans, casting votes, obtaining other IDs, siphoning off ration grains, etc. These include cases of ‘identity theft’ – Aadhaar details of persons have been altered, or Aadhaar details have been forged by changing the photographs and names and taking scans. The genuine holders of Aadhaar have subsequently found themselves in a soup when they were told that loans in their name were not honoured or land transfers in their name were carried out without consent. Such instances are especially striking given that identity theft is precisely what Aadhaar was supposed to fix.

While most of the cases involved a single or few persons indulging in petty frauds, a third of the cases were related to rackets where fake or forged Aadhaar were being mass-produced. The methods involved in these cases varied – the two most common were Aadhaar numbers being issued based on fake or forged documents, and details like name, photographs being forged using rudimentary editing techniques and printers. There have also been instances of biometric and/or demographic details (fingerprints, photographs, names and addresses) being altered at the stage of enrollment. In a few cases, sophisticated methods were used to exploit loopholes in the enrollment process to generate fake Aadhaar numbers. The most prominent of these was the case of a gang in Uttar Pradesh that was caught generating Aadhaar for fictitious persons by cloning the fingerprints of Aadhaar enrollment operators.

A man goes through the process of eye scanning for the Unique Identification database system, also known as Aadhaar, at a registration centre in New Delhi, India, January 17, 2018. Picture taken January 17, 2018. Credit: Reuters/Saumya Khandelwal – RC1F67907F80

The usual official response has been to discredit such reports by stating that no authentic Aadhaar numbers were generated in these cases – that they were simply instances of forgery. Going by the various methods of fraud employed, this justification is only partly correct. In 45 cases, either valid Aadhaar numbers were generated (for instance using fake/forged documents) or the Aadhaar details in the database altered (for instance, using the online detail updating facility).

Moreover, this UIDAI argument misses a key point: irrespective of the method involved, Aadhaar seems to have become extremely easy to fake or forge in paper form and use as ID for a range of services including to obtain SIM cards, open bank accounts, obtain loans, book hotel rooms, get married in court, prove identity for air and train travel, etc. That many of these instances did not involve UIDAI issuing an authentic Aadhaar number does not change the fact that fake or forged Aadhaar details have been used to carry out fraud. 

In addition to the cases of forgery and fakes, 17 cases of Aadhaar-enabled banking frauds were compiled by Vipul Paikra, an independent researcher (also available here). In a country with low financial and technological literacy, it is easy for people to fall prey to various types of frauds, especially phishing scams.

A member of parliament recently lost Rs 27,000 after revealing an Aadhaar one-time-password (OTP) to fraudsters over the phone. In another instance, con-men tricked persons on the pretext of linking their Aadhaar to their PAN (issued by the income-tax department for tracking financial transactions) into revealing an OTP which was then used to change the linked-mobile number in the Aadhaar database. Such instances highlight the need for authorities to raise awareness about how to use Aadhaar and clarify what information is not supposed to be shared.

On the latter, unfortunately, the UIDAI has itself spoken with a forked tongue – they have claimed that Aadhaar numbers are not supposed to be confidential every time data leaks have been identified, while at the same time issuing notices urging people to be careful when sharing Aadhaar numbers.

It is worth recalling that Aadhaar is designed to be a number, not a card. In fact, the word ‘card’ does not figure even once in the Aadhaar Act. Aadhaar is supposed to be an identification number to establish the identity of a person using their biometrics. Since Aadhaar cards are often simply Aadhaar details printed on normal paper using standard printers, the ‘card’ does not come with any security features. While the QR code allows checking for authenticity, these checks are rarely ever performed. Further, a recent press release by the UIDAI cautioned persons against getting their Aadhaar laminated or obtaining Aadhaar ‘smart cards’, stating that the QR code on them often cannot be used. Despite this serious lack of credibility, the paper-based Aadhaar ‘card’ continues to be accepted as a valid proof of identity for a range of services.

Neither Aadhaar ‘card’ reliable, nor Aadhaar-based biometric authentication

As its scale and use has expanded, several aspects of Aadhaar have created cause for worry. Regular reports of data leaks have raised doubts about the reliability of the data-security infrastructure. Most recently, a security researcher identified an online dashboard of the Andhra Pradesh government that was publicly displaying Aadhaar numbers linked to large amounts of personal information including addresses and bank details which were compiled through Aadhaar. Moreover, the fact that the dashboard allowed households to be precisely geo-located by caste and religion highlights the grave implications of Aadhaar on privacy.

Importantly, recent evidence has raised serious concerns about the reliability of Aadhaar even for biometric authentication – the feature that makes Aadhaar more reliable than other identification documents. Mandatory biometric authentication to receive welfare benefits has led to increased transaction costs and serious exclusion problems. According to a recent submission to the Supreme Court by the UIDAI itself, authentication failure rates are as high as 6% for fingerprints and 8.5% for iris. A related Supreme Court presentation by the CEO of UIDAI suggests that recent failures are even higher (about 12%) for ‘government services’. It is worrying that biometric authentication remains mandatory for welfare programmes in various states despite evidence of such high failure rates.  

To add to these serious concerns, the results from the online search suggest that contrary to its proponents’ claims, Aadhaar has facilitated a range of frauds. They also highlight the urgent need for closely monitoring the rapidly expanding use of Aadhaar ‘cards’ and increasing awareness about Aadhaar usage and vulnerabilities.

Further research is however needed to better understand both, the role of Aadhaar in curbing fraud, and the extent to which it enables fraud.  


Anmol Somanchi (anmol.somanchi94@gmail.com) is a graduate of Development Studies from TISS, Mumbai and is currently with a development consultancy based in New Delhi. Views expressed here are personal.

13435 - Compromised Aadhaar enrolment software being sold for as little as Rs 500: Report - Business Today

Compromised Aadhaar enrolment software being sold for as little as Rs 500: Report
 BusinessToday.In   New Delhi     
Last Updated: May 2, 2018  | 12:09 IST

PC: Reuters
The Unique Identification Authority of India (UIDAI) has usually been quick to refute most reports of Aadhaar database breaches and leaks. But at a time when a far more serious security threat is reportedly looming in the enrolment side of things, the authority tasked with issuing the unique ID number is being uncharacteristically tight-lipped.

What is the new threat?
According to a report in the Asia Times, a modified Aadhaar enrolment software, known as ECMP (Enrolment Client Multi Platform), has been compromised. It is, in fact, being illegally distributed for as little as Rs 500, going up to Rs 2,000.
ECMP is basically Aadhaar client software that was developed to allow enrolment operators to collect personal data and biometrics from applicants in order to generate the 12-digit number. It was supposed to be fully-secure, since it not only required biometrics of an authorized operator but also sought out geo-location. The latter, on paper, ensured that the sensitive data was being collected by someone authorised to do so, in a secure and mandated location.

However, the report claims that a "jailbreak" version of the software was on sale on certain WhatsApp groups among Punjab-based enrolment operators, which promised to bypass the above-mentioned biometric and geo-location safeguards. The illegal software basically came preconfigured with user credentials of various registrars. "The GPS module to track the location of the enrolment has also been disabled through a patch," an information security professional, who looked at the compromised software, told Asia Times. Worse, this version of the software could be installed on any laptop.

Why is it a concern?
The compromised ECMP software sans any safeguards would effectively allow anybody to pose as an authorised Aadhaar enrolment operator, free to enrol anyone they like, from anywhere in the world, and pass off their information as legitimate. Given that Aadhaar is being billed by the government as a tamper-proof verification for identity as well as residency, imagine what will happen if this hacked software is unleashed in areas prone to illegal migrant flows like Assam or in areas susceptible to militant intrusions like Jammu and Kashmir.

Furthermore, as the report explains, the compromised ECMP will allow any unauthorised entity to update anyone's identity and address details without any verification, bypassing all security protocols set in place by UIDAI. So the threat posed by this "jailbreak" ECMP version is actually a pan-India concern.
In March, Ajay Bhushan Pandey, CEO of UIDAI, had declared that "Each Aadhaar biometric is encrypted by a 2048-key combination and to decode it, the best and fastest computer of our era will take the age of the universe just to hack into one card's biometric details." But what about a compromised enrolment process itself, which puts a question mark on the authenticity of the Aadhaar data collected?

Does UIDAI know about this threat?
An operator from Punjab, Bharat Bhushan Gupta, reportedly informed UIDAI about the compromised software in an email, even offering help to access to the same. Just last month, a Punjab-based journalist also alerted the Aadhaar body about these developments. But while UIDAI acknowledged the warnings, the daily claims that no details of any follow-up action were forthcoming.


(With PTI inputs)

Wednesday, May 2, 2018

13426 - Aadhaar enrollment software compromised, bypasses biometric, geo-location safeguards: Report


Updated May 01, 2018 | 20:19 IST | Mirror Now Digital

Warnings sent to the Unique Identification Authority of India (UIDAI) though acknowledged, have not been acted upon leading us to believe that the problem is yet to be resolved, said the report.

Aadhaar enrollment software compromised, claims media report |Photo Credit: Representative Image

New Delhi: In yet another development that is likely to compel the UIDAI to run for cover, a media report has claimed that a modified Aadhaar enrollment  software which is currently being sold for as less as Rs 500 can pose national security concerns.
In a report, the Asia Times cited ECMP, the software in question as leading to national security implications owing to the fact that it is currently being circulated from anywhere between Rs 500 and Rs 2000. Warnings sent to the Unique Identification Authority of India (UIDAI) though acknowledged, have not been acted upon leading us to believe that the problem is yet to be resolved, said the report.

In its initial phases, the ECMP was developed as software to be used by operators in order to register recipients who wished to get a unique digital Aadhaar number. However, with reports of discrepancies surfacing from across the length and breadth of the country, the UIDAI decided to blacklist nearly 50,000 private operators eventually tasking public sector banks and post offices with the job of enrolling Aadhaar recipients.


With a nine-judge bench currently hearing a series of clubbed petitions against the government of India's aggressive push for Aadhaar linking with the filing of taxes and issue of SIM cards among other things, it was discovered that the ECMP software enabled now-blacklisted private contractors to not just collect biometric data such as iris scans and fingerprints but also addresses and date of birth in addition to other private data.
According to media reports, several videos easily accessible on the internet show how this software can be downloaded and installed. In fact, evidence gathered from group WhatsApp messages of former private operators working with the UIDAI prove how security features such as biometric and geo-location safeguards were bypassed rendering the software as compromised.

Recently, the Supreme Court bench hearing the Aadhaar case, clearly stated that the mad rush to link Aadhaar with mobile phone numbers supposedly to comply with a direction of the apex court was uncalled for, adding that it had not ordered any such mandatory linkage. The final hearings in the Aadhaar case came in the wake of a nine-judge Constitution Bench headed by the then Chief Justice of India JS Khehar ruling in August last year that privacy was a fundamental right guaranteed under the Constitution.


13425 - Cracked Aadhaar Enrolment Software Being Sold for Rs 500 to Rs 2,000: Report - The Wire



This compromised software could allow anyone to create new Aadhaar numbers without accompanying identity proof or documentation, leading to major national security implications.

There are broad implications for national security from this vulnerability. Credit: File photo

1.6K
interactions
22 HOURS AGO

New Delhi: Modified or ‘jailbroken’ versions of Aadhaar enrolment software – which can theoretically be used by anybody to add new entries to the UID database or modify their own existing entries – are being sold by rogue operators for Rs 500 to Rs 2,000, according to a report published on Tuesday by Asia Times.

If correct, this cracked software could allow anyone to create new Aadhaar numbers without accompanying identity proof or documentation, leading to major national security implications.
The official enrolment software, known as ECMP, was developed to allow authorised operators to register people so that they could get an Aadhaar number.

Given the sensitive nature of the data that flows through the software, ECMP came with two safeguards. One, it asks for the biometrics of the authorised operator and two, it uses geolocation data to ensure that the data being collected is being done by someone with authorisation and that the process is being carried out a secure and mandated location.

It appears that these safeguards have now been compromised.
“Messages posted in several WhatsApp groups among Punjab-based operators began to surface at the end of last year, offering to sell a “jailbreak” version of the software. This version, to be installed on the laptops of anyone willing to pay the amount, could bypass the biometric and geo-location safeguards,” the report notes.

“This basically meant that anyone posing as an “authorised operator” could make changes to the data and enrol new people from anywhere and pass their information off as legitimate. This is easier as the number is only proof of residency and not citizenship,” the report adds.

According to the report, the Unique Identification Authority of India (UIDAI) and state police across the country have already in the last six months received complaints of criminal groups bypassing the biometric safeguards of the software.

What are the implications?
There are two broad implications for national security from this vulnerability. 

Firstly, as the Asia Times report points out, it could theoretically allow the creation of new Aadhaar numbers for fake people, ghosts or worse, even foreign nationals and potential terrorists who have never even visited India.

Secondly, it allows anyone with access to the cracked software to update their own Aadhaar information, such as address details, without any checks or validation from the authorities.

According to the report, at least three separate attempts by different parties have been made to inform the UIDAI of the security loophole in the enrolment software, but the Aadhaar agency is yet to respond.

Sunday, April 29, 2018

13401 - Hyderabad: People line-up at banks over fake Aadhaar alert - Deccan Chronicle

DECCAN CHRONICLE. | COREENA SUARES
Published
Apr 29, 2018, 2:03 am IST

Programmed messages throw bank customers into panic.

  After standing in the queue for nearly 20 minutes, the staffer after verifying my account informed me that my Aadhaar linkage is successful.”, Geetha Naik said

Hyderabad: Geetha Naik, 52, of Vahini Nagar, Sikh Village, received a message on March 12, 2018, from Axis Bank with a header saying “Government Mandate, Your Aadhaar linkage has failed, to avoid blocking of your Axis bank account by 31/03/18, visit your branch.” Following this, the 52-year-old said, “I took my grandson along to Bowenpally (centre point branch). After standing in the queue for nearly 20 minutes, the staffer after verifying my account informed me that my Aadhaar linkage is successful.”
Unverified bulk messages like “We regret to inform you that your attempt to update Aadhaar has failed due to a difference in your details updated with the bank & UIDAI. We request you to visit the nearest branch at the earliest” from certain banks are proving a hassle to customers. But in reality, many of these customers’ accounts are already linked with their Aadhaar.  An insider of a regional bank said such messages were programmed months ago and are being sent now.








Another Ms Ananya (name changed) who received a similar message from Standard Chartered bank, said, “The text read my Aadhaar card linkage has failed and I need to update it to avoid transactions being blocked. I rushed to the regional branch the same afternoon only to hear the banker say my Aadhaar has been linked and there is no issue. Such messages panic account holders, especially senior citizens living on a pension who fear even that personal revenue being blocked.” 
Another problem prevailing at the banks was that staffers hesitate to link accounts with Aadhaar cards if the customers’ full names are not printed on their cards. Those having initials printed instead of full name have a tough time answering several questions. Thogota Arvind Reddy of Erramanzil faced a tough time as the bank employee did not accept his Aadhaar card as his name read T Arvind Reddy. “I have been a longtime customer of SBI through which I'm currently drawing my pension, even then they asked my details out of suspicion,” said Mr Reddy.

An insider from a regional bank said, “These messages were programmed when the banks starting asking for Aadhaar card account, linkage and few more messages were structured to inform customers if their linkage has failed, however since the messages are sent in bulk, they end up reaching those whose linkage is successful. Messages are sent through shortcode gateways to all customers registered with the bank. In case the customer has linked his/her Aadhaar and there is no block in transactions, this message should be ignored or reported to the bank.” 

13400 - Beware, SIM card sellers can misuse your Aadhaar biometrics - The Hindu


HYDERABAD, APRIL 28, 2018 23:37 IST


Thumb rule: Linking of Aadhaar card being done for a new SIM card.   | Photo Credit: G_RAMAKRISHNA

New cards can be activated using fingerprints multiple times
Next time you want to buy a new Subscriber Identity Module (SIM) card for your mobile device, be wary if your retailer tries to take your Aadhaar-linked fingerprints more than once.

The retailer can get a new SIM card activated — without your knowledge — using your thumb impression multiple times. Cases have surfaced of SIM cards thus activated being sold to persons who have then used them to commit crimes.

A SIM card retailer of Yasin Mobiles shop, Mohammed Rahmatullah, in Amberpet of Hyderabad was caught by Department of Telecommunications officials here two days ago on such a charge. “He admitted to have sold over 150 SIM cards fraudulently acquired in this manner. Some of these cards are being used to operate illegal Voice over Internet Protocol (VoIP) phone call rackets at different places in the country,” a senior DoT officer told The Hindu.

VoIP racket
A Hyderabadi woman grew suspicious when she got a phone call from abroad with a local mobile phone number. She complained to a DoT call centre. “Our inquiries confirmed that she got phone call from abroad through someone operating a VoIP racket, who purchased a local SIM card from a retailer. The latter got that SIM card activated by misusing Aadhaar biometrics of an unsuspecting person,” they explained. 

Further investigations suggested that SIM cards obtained by misusing customers were being used by many illegal phone call operators in other parts like Delhi. “We’re alerting officials concerned and catching them with the help of local police,” the DoT officials said. VoIP call rackets are not only making a huge dent on the exchequer but also raising security concerns. The authorities are worried that these cards may land in the hands of terrorists.

Mobile phone service SIM card sellers have Aadhaar card biometrics readers, and the scanners are connected to a computer to process applications for different service providers. Retailers verify customer’s fingerprints often with customers not being able to see the confirmation of identify on computer screens.

“Customers do not know if biometrics matched in the first attempt. Hence, retailers collect fingerprints multiple times,” the authorities said. When the fingerprints match, automatically all details, including photograph, available in Aadhaar card, are captured in the mobile phone service provider’s Know Your Customer (KYC) form.

Earlier, this was done manually using a photocopy of customer’s identity proof document. The retailers who create multiple SIM using a single identity are reportedly selling them to fraudsters for ₹1,000 to ₹3,000 each.

Since roaming charges were done away with, SIM cards purchased in Hyderabad can be used anywhere. “Our analysis of some SIM cards sold by Rahmathullah suggest that they were being used to operate VoIP call rackets from various places in the country,” the investigators said.

Amberpet police of Hyderabad Commissionerate registered a criminal case against Mohammed Rahamatullah and he was booked under sections 471 (using forged document or electronic record as genuine) and 420 (cheating) of IPC, besides Indian Telegraph Act provisions.

DoT officials are planning to take up a countrywide campaign to caution people against falling prey to the misuse of Aadhaar biometrics by SIM card sellers. Mobile phone service providers have been asked to send individual messages to all their customers about the fraudulent practice.


The campaign would use short video clips, slides and photos. “We are yet to devise a plan on alerting people of rural and remote parts about the scam,” the officials said.

Saturday, April 28, 2018

13383 - Operator’s Phone Number In Several Aadhar Cards, Gets Control Of All Data - eNews Room




Alarm bells ring for Aadhar Data security in Jharkhand for the second time, the first being the breach of MS Dhoni’s Aadhar data

By Shahnawaz Akhtar Last updated Apr 25, 2018



Aadhar card of a woman in Jharkhand, has Raju Kumar's phone number listed

Ranchi: Last year in March, Sakshi Dhoni, wife of former Team India, captain, Mahendra Singh Dhoni had raised an alarm concerning the M S Dhoni’s confidential data listed in Aadhar being leaked. She had also complained regarding the same to Union Law and Information Technology Minister Ravi Shankar Prasad. With the government giving an assurance that there would not be a repeat, it was believed that no Aadhar information would ever be leaked in Jharkhand.

But, within a year, this incident where a Common Service Center (CSC) operator, at Ganwah More, Ganwah block, Giridih has put his phone number in most of the Aadhar cards made through him, has exposed once again, as to how vulnerable the data listed in one’s Aadhar identity proof is.

The center used to operate from Ganwah Panchayat Building, has now been shutdown, with Aadhar now being made at banks. But till January 31, 2018 one Raju Kumar, had put one single phone number in every Aadhar card that was applied for through his centre. A little bit of investigation revealed that the number belongs to him. Several Aadhar cards and the enrollment slips have the same phone number—8969877638 listed in it.

Phone number listed in the Aadhar card has great significance as now one can only get rations, pensions and several other welfare scheme’s benefits authentification get done only after submitting OTP (One Time Password).

When eNewsroom contacted Raju on the number listed on the card, he received the call and explained that he had had his number listed as he wanted to help certain people who didn’t have any phone or mobile numbers to list. “If I would not have added my number, they would have not been able to get an Aadhar,” he told eNewsroom.

On being asked, if he was aware of the fact that his action of listing his own number was a punishable offence and that the Unique Identification Authority of India (UIDAI) can book him, or that the card owner would be dependent on him for life, Raju had no answer. However, his modus operandi exposes the fact that Aadhar credentials can easily be manipulated or accessed by anyone.

When contacted Shambhu Singh, General Manager, Technology SCS eGovernance Services, he told eNewsroom, “The person (Raju Kumar) has been removed from CSC center in March itself for some other reason.”

“However, we had no idea about this issue, and now when UIDAI will instruct us, then only we can take action against him,” he added.


This year in January, The Tribune newspaper had done a story, which had shown how by paying just Rs 500 anybody can get access to millions of personal Aadhar data.