In 2009, I became extremely concerned with the concept of Unique Identity for various reasons. Connected with many like minded highly educated people who were all concerned.
On 18th May 2010, I started this Blog to capture anything and everything I came across on the topic. This blog with its million hits is a testament to my concerns about loss of privacy and fear of the ID being misused and possible Criminal activities it could lead to.
In 2017 the Supreme Court of India gave its verdict after one of the longest hearings on any issue. I did my bit and appealed to the Supreme Court Judges too through an On Line Petition.
In 2019 the Aadhaar Legislation has been revised and passed by the two houses of the Parliament of India making it Legal. I am no Legal Eagle so my Opinion carries no weight except with people opposed to the very concept.
In 2019, this Blog now just captures on a Daily Basis list of Articles Published on anything to do with Aadhaar as obtained from Daily Google Searches and nothing more. Cannot burn the midnight candle any longer.
"In Matters of Conscience, the Law of Majority has no place"- Mahatma Gandhi
Ram Krishnaswamy
Sydney, Australia.

Aadhaar

The UIDAI has taken two successive governments in India and the entire world for a ride. It identifies nothing. It is not unique. The entire UID data has never been verified and audited. The UID cannot be used for governance, financial databases or anything. It’s use is the biggest threat to national security since independence. – Anupam Saraph 2018

When I opposed Aadhaar in 2010 , I was called a BJP stooge. In 2016 I am still opposing Aadhaar for the same reasons and I am told I am a Congress die hard. No one wants to see why I oppose Aadhaar as it is too difficult. Plus Aadhaar is FREE so why not get one ? Ram Krishnaswamy

First they ignore you, then they laugh at you, then they fight you, then you win.-Mahatma Gandhi

In matters of conscience, the law of the majority has no place.Mahatma Gandhi

“The invasion of privacy is of no consequence because privacy is not a fundamental right and has no meaning under Article 21. The right to privacy is not a guaranteed under the constitution, because privacy is not a fundamental right.” Article 21 of the Indian constitution refers to the right to life and liberty -Attorney General Mukul Rohatgi

“There is merit in the complaints. You are unwittingly allowing snooping, harassment and commercial exploitation. The information about an individual obtained by the UIDAI while issuing an Aadhaar card shall not be used for any other purpose, save as above, except as may be directed by a court for the purpose of criminal investigation.”-A three judge bench headed by Justice J Chelameswar said in an interim order.

Legal scholar Usha Ramanathan describes UID as an inverse of sunshine laws like the Right to Information. While the RTI makes the state transparent to the citizen, the UID does the inverse: it makes the citizen transparent to the state, she says.

Good idea gone bad
I have written earlier that UID/Aadhaar was a poorly designed, unreliable and expensive solution to the really good idea of providing national identification for over a billion Indians. My petition contends that UID in its current form violates the right to privacy of a citizen, guaranteed under Article 21 of the Constitution. This is because sensitive biometric and demographic information of citizens are with enrolment agencies, registrars and sub-registrars who have no legal liability for any misuse of this data. This petition has opened up the larger discussion on privacy rights for Indians. The current Article 21 interpretation by the Supreme Court was done decades ago, before the advent of internet and today’s technology and all the new privacy challenges that have arisen as a consequence.

Rajeev Chandrasekhar, MP Rajya Sabha

“What is Aadhaar? There is enormous confusion. That Aadhaar will identify people who are entitled for subsidy. No. Aadhaar doesn’t determine who is eligible and who isn’t,” Jairam Ramesh

But Aadhaar has been mythologised during the previous government by its creators into some technology super force that will transform governance in a miraculous manner. I even read an article recently that compared Aadhaar to some revolution and quoted a 1930s historian, Will Durant.Rajeev Chandrasekhar, Rajya Sabha MP

“I know you will say that it is not mandatory. But, it is compulsorily mandatorily voluntary,” Jairam Ramesh, Rajya Saba April 2017.

August 24, 2017: The nine-judge Constitution Bench rules that right to privacy is “intrinsic to life and liberty”and is inherently protected under the various fundamental freedoms enshrined under Part III of the Indian Constitution

"Never doubt that a small group of thoughtful, committed citizens can change the World; indeed it's the only thing that ever has"

“Arguing that you don’t care about the right to privacy because you have nothing to hide is no different than saying you don’t care about free speech because you have nothing to say.” -Edward Snowden

In the Supreme Court, Meenakshi Arora, one of the senior counsel in the case, compared it to living under a general, perpetual, nation-wide criminal warrant.

Had never thought of it that way, but living in the Aadhaar universe is like living in a prison. All of us are treated like criminals with barely any rights or recourse and gatekeepers have absolute power on you and your life.

Announcing the launch of the # BreakAadhaarChainscampaign, culminating with events in multiple cities on 12th Jan. This is the last opportunity to make your voice heard before the Supreme Court hearings start on 17th Jan 2018. In collaboration with @no2uidand@rozi_roti.

UIDAI's security seems to be founded on four time tested pillars of security idiocy

1) Denial

2) Issue fiats and point finger

3) Shoot messenger

4) Bury head in sand.

God Save India

Showing posts with label Aadhaar Leaks. Show all posts
Showing posts with label Aadhaar Leaks. Show all posts

Monday, July 2, 2018

13760 - Aadhaar data of 11,000 AP govt staff leaked - TNN


U Sudhakar Reddy | TNN | Jun 28, 2018, 11:20 IST

AMARAVATI: In yet another case, AP government website has leaked Aadhar numbers of around 11,000 government employees. Endowments department shut down the website after being alerted by security researchers on Wednesday.

“AP published Aadhaar numbers of 11,000 government employees working in the endowment department. They have shut down the pages publishing the details now,” security researcher Srinivas Kodali told TOI. Researchers say AP government has repeatedly been at fault on the issue of leaking Aadhaar data.

LATEST COMMENT
AP itself is a leaking state with governance at pathetically low levels. Shows how media hyped yellow crook is running his state.
ragsvan6

“AP government has a serious problem and needs to pay attention towards it. It is ironical that a state that boasts of information technology initiatives has no cybersecurity capacity,” said Srinivas Kodali.

Recently, security researchers found that the AP government smart survey website had data of 4.5 crore people and free access was given by typing their Aadhaar number. After the notification by the data researcher, AP government has suspended the link 


Monday, June 25, 2018

13725 - Data breach in Andhra Pradesh again, 4.5 crore citizen's details exposed 0 TNN

Data breach in Andhra Pradesh again, 4.5 crore citizen's details exposed

U Sudhakar Reddy | TNN | Jun 19, 2018, 22:17 IST

HYDERABAD: In yet another significant instance of breach of data of citizens, AP government has put up the details of citizens online. If someone knows the Aadhaar number of a person, they can use it to understand several aspects of the citizens collected by AP Government as part of Praja Sadhikhara Survey (Smart Pulse Survey). 

Security researchers say that the website technically has 4.5 crore peoples data. 

Data security researcher Srinivas Kodali on Tuesday notified the government of AP regarding the free access to the data by typing the number. 

Browsing the link http://push73.sps.ap.gov.in/spsnew/MIS_Out_New/MIS_ONStatus/ and filling Aadhaar number would reveal the mobile number, name and other demographic details of persons. 

After the notification by the data researcher, AP government has suspended the link. 

Srinivas Kodali told TOI, "I have reported the security issue to the AP government. Just visiting the link and entering a number will give the information. The website has 4.5 crore peoples data, and all the details of the survey are here. The data is about smart pulse survey. The survey started in July 2016 and is ongoing. Earlier when similar breach happened, officials brought down the site."

Previously the details of people including family, housing location by geo-tagging and caste details at cluster /booth level were available.

The AP government has been updating the pulse survey data of residents of the state since 2016 with an e-KYC based verification system linked to Aadhaar.

LATEST COMMENT
AP is a failed state full of holes & breaches as revenues are siphoned of through leakages.
ragsvan6

Advisor of Information Technology to AP government J Satyanarayana has reiterated that the data security has been a constant process and it has been strengthening by the government.

When contacted UIDAI authorities, they were not available for comment. 

13718 - Medical data of Andhra customers leaked, 27 lakh orders shown on Anna Sanjivini site - News Minute

This comes just two months after Aadhaar data of least 1.34 lakh citizens of the state was compromised.

Nearly two months after the Andhra Pradesh government made Aadhaar data and other details of at least 1.34 lakh citizens of the state public, purchases of nearly 27 lakh orders of medicines made at the state-run Anna Sanjivini stores, were put in the open.

The details of these purchases were publicly listed on the Anna Sanjivini portal, which has now been taken down.

The homepage of the Anna Sanjivini website displayed the number of stores, the day’s orders and total orders along with the current day’s sales and cumulative sales. On clicking the hyperlinked number of orders, one could simply select the district and store and view details. It showed the name and phone number of the individual, medicine ID, date ordered, which store it was ordered from, along with the quantity ordered and amount paid.

As per the website, a little over 27 lakh orders had been placed so far at Anna Sanjivini stores, which could mean that details of tens of thousands of citizens could have been accessed.
This breach was discovered by security researcher Srinivas Kodali, who claims that these details had been in the public domain for a very long time – maybe even a couple of years. However, after Huffpost reported the issue on Monday, the link has since been removed.

Anna Sanjivini stores are generic medical stores set up by the AP government in 2015 to provide medicines at low costs for all critical and long-term diseases. There are 301 such stores across the state.
“If you are a resident of AP and if you were using any of the govt facilities for medical purposes, all your information including what you purchased has been public for a really long time,” Srinivas says.
He also claims that Chief Minister N Chandrababu Naidu’s dashboard is linked to this. Saying that this seems to be part of AP government’s real-time governance initiative, he adds, “AP CM’s dashboard is the reason why everyone’s been publishing details - because CM wants to track what’s happening in the state. And if this is the kind of info they are collecting, it is really flawed.”
The availability of the data points to the fact that the government has been tracking sales of all medicines, which also means that it has information on the health conditions of every individual that made a purchase at the store.
“There are serious privacy implications of this. It’s a serious breach from a medical ethics point of view because anyone can identify what ailment you have, based on the medicines you buy,” Srinivas says.
According to the Regulation of Privacy in Government and Private Hospitals and Diagnostic Laboratories, the information collected from the patient in both government and private hospitals, is used solely for the purpose that the patient has been informed of.
“Government hospitals however do not let any medical personnel access these records except for the doctor involved in the treatment of that particular patient,” the centre for internet and society website states.
This is also not the first time that data from a government website of Andhra Pradesh has been breached.
Aadhaar data of at least 1.34 lakh citizens in the state, along with their other details like their religion, caste and bank details among other things were made public. The names were part of a list titled ‘Beneficiary Details belonging to Entry Report for Scheme Hudhud’ and were available on the website of the Andhra Pradesh State Housing Corporation.

The page clearly showed the father’s name, address, panchayat, mobile number, ration card number, occupation, religion, caste, Aadhaar number, along with other details, including their bank details like bank branch, IFSC code and account number.

Wednesday, June 6, 2018

13641 - Express Impact: Kozhikode Corporation removes Aadhaar data from its website - Indian Express


A day after 'Express' reported Aadhaar data leakage through Kozhikode Corporation's website, authorities have removed the data from the public domain.

Published: 02nd June 2018 08:25 AM  |   Last Updated: 02nd June 2018 08:25 AM
  
By Express News Service

KOZHIKODE: A day after 'Express' reported Aadhaar data leakage through Kozhikode Corporation's website, authorities have removed the data from the public domain.
The Corporation had negligently uploaded the Aadhaar number and other private data of 1,783 beneficiaries of Prime Minister's Awas Yojana (PMAY).

It was seen as a clear case of data security lapse on the part of the Corporation at a time when the country was debating Aadhaar data leakage. The Corporation authorities had claimed they uploaded the data because of a clause in the PMAY project.

The clause, according to the Corporation, had asked all civic bodies to display the Aadhaar number of beneficiaries list.

Sunday, May 20, 2018

13552 - Government website leaks Aadhaar information - Biometric Update

May 16, 2018 | Chris Burt

Yet another website has published the Aadhaar numbers and biographic details of Indian citizens; this time the official website for Prime Minister Narendra Modi’s electricity access project, Bloomberg reports.

The website published the name, Aadhaar number, biographical details, village of residence, and photograph of “several” residents, Bloomberg says, before blocking access to the portal. Aadhaar numbers, demographic details, and banking information for more than 130,000 people was published by the state of Andhra Pradesh in April, and several other government websites, including that of the Central Bureau of Investigation, have published Aadhaar numbers together with personal data.

The Unique Identity Authority of India (UIDAI) has consistently maintained that no breach of its central database has occurred, and all biometric data is secure.Although Aadhaar numbers are not secret, and are used to connect biometric data with individuals, the frequent leakage of personal information may bolster the case of petitions to India’s Supreme Court, which is expected to rule on the constitutional validity of the program as a whole, and several of its different facets, in the coming months.

“There is a need for India to come out of the ostrich approach” internet law expert Pavan Duggal told Bloomerg. “Rather than adopting the philosophy of shooting the messenger or pushing the problems under the carpet, it is imperative to start dealing with the challenges facing Aadhaar before making it mandatory.”

Related Posts


Thursday, May 10, 2018

13499 - Worrying gaps - Telegraph India

May 09, 2018 00:00 IST

Data leaks and security breaches have become a part of 21st-century life. However, how organizations — especially the government — react to such events is important in assuring the citizen that this is something not to be condoned and something that must be made more infrequent through greater security. Taking away personal data (for whatever purpose) without the consent or knowledge of the individual is as good as property theft — both are violations of rights and constitute an act of coercion. The theft of information can be humiliating for the person whose data has been stolen. Personal data can be of various kinds and misuse could lead to substantial losses for the owner. This is often not realized.

In India too, data breaches are becoming more common. The reactions of the people who fail to prevent the breach and those of the government and the experts who know how certain security lapses lead to breaches can, at times, be shocking. Some time back, the government of Andhra Pradesh put up on its website the Aadhaar details of a large number of citizens. When the lapse was pointed out, the government hastily removed some of the details, but claimed that it was done to provide transparency regarding beneficiaries of certain publicly-funded projects. The more recent news about the Employees Provident Fund Organisation data breach is even scarier. 
Financial details could be widely misused. The government has chosen to remain silent, as have civil service experts. Transparency is not the opposite of privacy. Achieving transparency by the coercive violation of privacy is patently wrong. Silence on the part of the government can only be seen as a gradual and systematic blurring of the lines separating the private and the public spheres. This is an ominous sign; it portends greater control and manipulation on the part of agencies and institutions of the lives of ordinary citizens. Unlike in India, the Equifax data breach — it had taken place in the United States of America last year — had led to a quick apology and beefed-up security.



Monday, May 7, 2018

13470 - UIDAI slams enrolment software breach reports, says stringent processes in place; Gates bats for Aadhaar - First Post


Business PTI May 03, 2018 20:59:54 IST
Comment 0

The Unique Identification Authority of India (UIDAI), on Thursday, said it follows a "stringent enrolment and updation process" for issuance of Aadhaar cards, and that it has blacklisted over 50,000 operators for various violations, amid reports of a breach in its enrolment software.

The UIDAI said its enrolment software incorporates the necessary safeguards and checks to protect against any manipulation, and the Authority discredited claims in the report as "baseless and false".


Image: UIDAI

The statement follows reports of alleged tampering of the Aadhaar enrolment software, supposedly being sold in the black market, which purportedly bypasses operators' biometric authentication and facilitates issuance of Aadhaar cards without any documents.

Emphasising its "zero tolerance policy" when it comes to ensuring security and safety of its processes, the UIDAI said that any operator found to be violating its stipulated processes, or those indulging in any type of fraudulent or corrupt practices, are blocked, blacklisted and also face a stiff penalty of up to Rs 1 lakh per instance.

"Also, all such enrolment attempts get rejected and Aadhaar is not generated. As on date more than 50,000 operators have been blacklisted," the UIDAI added in a statement.
The UIDAI said its system matches all 10 fingerprints and both irides of a resident enrolling for Aadhaar with the biometrics of all Aadhaar holders before issuing the 12 digit unique identifier.

Bill Gates endorses Aadhaar
The Aadhaar technology does not pose any privacy issue and the Bill and Melinda Gates Foundation has funded the World Bank (WB) to take the approach to other countries as it is worth emulating, Microsoft founder Bill Gates has said.

The 62-year-old multi-billionaire philanthropist said Nandan Nilekani, the Infosys co-founder who is considered as the chief architect of Aadhaar, is helping the World Bank on the project.

                       A file photo of Bill Gates. Reuters.

Asked if India's Aadhaar technology is worth emulating by other countries, he replied, "Yes". "The benefits of that (basic ID -- Aadhaar) are very high," he told the PTI this week
"Yes, countries should adopt that approach because the quality of governance has a lot to do with how quickly countries are able to grow their economy and empower their people," Gates said in response to a question. "We have funded the World Bank to take this Aadhaar approach to other countries," he said.
"Aadhaar in itself doesn't pose any privacy issue because its just a bio ID verification scheme," Gates, the head of the Bill and Melinda Gates Foundation, said when asked about the concerns about privacy issues raised by certain quarters in India.

Updated Date: May 03, 2018 20:59 PM

13469 - How long can its captain – UIDAI – continue to deny the Aadhaar leaks? - News Click


Newsclick Report 04 May 2018


A few days back, Asia Times and Medium, a popular website reported on security holes in the Aadhaar system. Saikat Datta wrote that a number of people have warned the UID Authority of this hole, without getting any response. Today, the French security expert, who goes by the twitter handle Elliot Alderson @fs0c131y and had earlier exposed a number of security breaches in the Aadhaar and government websites, has tweeted the details of a YouTube video that shows a software that can be used to edit the personal data of anybody enrolled in the Aadhaar system; that too without any security checks! And to add insult to the injury – for UIDAI – the person who posted the video is asking those who liked his video for contributions to his PayTM account.



Is the video fake? If it is, we can heave a sigh of relief. The problem is that very similar complaints have been made by various people to UIDAI without any response, indicating that this software is available for as little as Rs. 500. Anand Venkatanarayanan, in his Medium piece , has also explained why a software – called ECMP (Aadhaar Enrolment Client Multiplatform) software – that resides in the e-Kendra computers, can be hacked more easily. And if it is hacked, it will allow any change in the personal data of the person enrolled in the Aadhaar database. This means the mapping between the biometric and the personal data can be changed.

UIDAI’s contention is that the biometric database cannot be hacked and remains behind secure walls (13 feet high according to the Attorney General). The problem is not that the ridges and whorls of our fingers are safely stored, but whether the name and other details, attached to the fingerprints, are truly mine. If they are not secure and can be changed by buying a Rs 500 software, it means identity theft can occur on a mass scale. And more service providers are added to the Aadhaar system, more potential of holes for such identity thefts. This is the central risk of the Aadhaar system. And our nightmare.

We have been warning the government in our columns and videos, why the Aadhaar system is a poor one and will not lead to any foolproof identity verification system. If biometrics are used, poor connectivity, lack of electricity, apart from at least 10% of biometrics like fingerprints not being verifiable, will defeat the system. If biometrics are dispensed with, the Aadhaar ID proof is as good as self-certification. Why then, are tens of thousands of crores being spent on the system?

The logic of the system lies elsewhere. Yes, Aadhaar system leaks like a sieve. It is capable of being bypassed in various ways. Yes, people who are legitimate beneficiaries of various systems are being denied their dues or rations, as the biometric system does not work properly.

So what is the purpose of Aadhaar? For the government, it provides a method of collecting a huge amount of information of the citizens: religion, caste, geotagging of their houses, collating it with their income and expenditures, etc. This is a surveillance tool that can be used against individuals and communities. For a government that is against a particular section, it can be used to bypass from development in certain areas, where a particular community may be staying. For big Indian capitalists, such as Ambanis, it provides the tool of big data at government expense. Once such big data is available, the capitalists can tap into it in various ways. This is why, from a Nilekani to an Ambani, all of them have lined up behind Aadhaar.

Unfortunately for both the government and big capitalists, the ecosystem of Aadhaar, as engineered and deployed, is so poor that it is likely to fail. Sooner rather than later. Even if the Supreme Court does not strike it down on our privacy violations.

The Aadhaar system is increasingly looking like a ship with a large number  of holes. How long can its captain – UIDAI – continue to deny these leaks? And how long will we pump in good money after the bad?


Saturday, May 5, 2018

13459 - Leaks ? What Leaks ? By Ram Krish


Friday, May 4, 2018

13450 - Bill Gates endorses Aadhaar scheme; says it doesn't pose privacy issues - Business Today


New Delhi     
Last Updated: May 3, 2018  | 16:52 IST

Aadhaar has been a boiling issue in India for the past few months. Data theft cases for as little as Rs 500, fake software to create Aadhaar cards, and alleged 'loopholes' in the unique identity scheme have left a dent on its credibility. It has been facing increased scrutiny over privacy concerns following several instances of breaches and misuse. Despite all this, Aadhaar as a scheme has been appreciated by many prominent people all over the world. Bill Gates, founder of one of the world's biggest tech companies, Microsoft, has been a staunch supporter of the Aadhaar scheme since the very beginning of its rollout. This time, he has again come out openly saying the Aadhaar technology does not pose any privacy issue. Not only that, he also appreciated Prime Minister Narendra Modi for fully "embracing" the scheme, which was initiated during the previous UPA regime.

The founder of Bill and Melinda Gates Foundation told PTI his organisation has funded the World Bank to "emulate" the project as it is worth doing so. Bill and Melinda want other countries to also adopt the scheme. "The bio-ID verification programme has multiple benefits," says Bill. To undertake this level of project in other countries, the World Bank and the Gates Foundation have reportedly roped in multi-billionaire Nandan Nilekani. The Infosys founder, who is also considered as the chief architect of Aadhaar, will consult and help the World Bank carry out the 'Aadhaar-like' project in other countries.
After the successful implantation of the Aadhaar scheme in India, other countries have also approached New Delhi for assistance in creating similar data base.

Appreciating India for successfully implementing the scheme, Gates said India's Aadhaar technology could be implemented across the world. Bill Gates thinks the Aadhaar-like scheme could help improve governance, which is directly linked to economic growth and the overall improvement in society.
"The benefits of that (basic ID -- Aadhaar) are very high. Yes, countries should adopt that approach because the quality of governance has a lot to do with how quickly countries are able to grow their economy and empower their people. Aadhaar in itself doesn't pose any privacy issue because it's just a bio ID verification scheme," said Gates.

One of the world's richest men, Bill Gates, also tried to sooth fears around the Aadhaar data misuse, saying individual application users need to properly check who can see information. He also defended financial institutions seeking Aadhaar details for opening an account. "Application by application, you have to make sure that's well-managed. In the case of the financial bank account, I think it's handled very well. (It uses) Aadhar to set up the accounts so that you can both get your cell phone and get your bank account," he said, reported the agency.

He said some of the initiatives carried out by the Narendra Modi government on digitisation could help improve the level of education in the country, and hence, the governance. Before this in 2016, Gates had said the Aadhaar is a scheme "never been done by any government before, not even in a rich country". The UIDAI's ambitious Aadhaar project is the world's largest biometric database with whopping 111 crore people of the total 125 crore Indians already connected with the identity scheme.


Thursday, May 3, 2018

13447 - Karnataka police share Aadhaar details of housing scam victims on website - TNN


Kiran Parashar | TNN | May 3, 2018, 06:19 IST

BENGALURU: Even while the security and privacy of data secured by the Unique Identification Authority of India (UIDAI) under its Aadhaar project is being questioned, Karnataka police have shared personal details — including Aadhaar numbers — of victims of the Gruha Kalyan housing scam on an open network. 
TOI noticed that personal details such as names, addresses, contact numbers and Aadhaar numbers apart from other details of 1,157 complainants — the victims of the estimated Rs 79 crore scam —have been uploaded on a police website, and were available until the time of going to the press on Wednesday. Also listed were PAN numbers of complainants alongside the sums they had paid and the moneys refunded. 

The Criminal Investigation Department (CID) is investigating the scam which came to light in 2016. Officers probing the case had claimed the accused had floated companies such as Dreamz Infra India Ltd and Gruha Kalyan Private Limited and duped people crores of rupees. The entire scam spanning several cities is estimated at over Rs 500 crore. 

Victims are now aghast at the callous manner in which their details have been shared on a public platform by the police. The victims TOI spoke to say they were unaware that their personal details were listed on the website. 

Dr C Giridharan from Chennai, who was allegedly cheated out of Rs 6 lakh, said: “Why should police share somebody’s details on an open forum. This is shocking to say the least.” Ashok, another victim, said he wasn’t asked for consent before his Aadhaar number was uploaded on the website. 

Kislay Chaudhary, chairman and CEO of Indian Cyber Army, a cyber security organization, and an analyst to cybercrime investigation units of Uttar Pradesh, Madhya Pradesh, Bihar and Delhi, said police are in breach of UIDAI rules. “With Aadhaar numbers in hand, miscreants can access financial and social details of the individuals,” he said. “This data can easily be misused.” 

Under the Aadhaar Act 2016, any individual, entity or agency, which is in possession of Aadhaar number(s) of Aadhaar number holders, shall ensure security and confidentiality of the Aadhaar numbers and of any record or database containing the Aadhaar numbers.

M Mohan Reddy, convener of State-Level Bankers Committee (SLBC), revealed the rules pertaining to Aadhaar was made stringent under the Aadhaar Act. “Previously we could display Aadhaar details, but the Act has been modified and we cannot publish Aadhaar numbers any more,” Reddy said. “Now, no one is allowed to publish Aadhaar details.”

TOP COMMENT
The need of hour-- Educate the Govt employee

Paban S

Times View
Critics argue that such an enormous and potentially lucrative database such as Aadhaar can never be fully secured and too often, lax government officials and now police have lent credence to this view. No matter how stridently UIDAI claims that data obtained under the Aadhaar project is safe, citizens are unlikely to be consoled especially since fraudsters have been able to reach into bank accounts of people with even less data than UIDAI has under its thumb. With police too leaking personal data, one wonders who UIDAI can call on to ensure strict action.



13435 - Compromised Aadhaar enrolment software being sold for as little as Rs 500: Report - Business Today

Compromised Aadhaar enrolment software being sold for as little as Rs 500: Report
 BusinessToday.In   New Delhi     
Last Updated: May 2, 2018  | 12:09 IST

PC: Reuters
The Unique Identification Authority of India (UIDAI) has usually been quick to refute most reports of Aadhaar database breaches and leaks. But at a time when a far more serious security threat is reportedly looming in the enrolment side of things, the authority tasked with issuing the unique ID number is being uncharacteristically tight-lipped.

What is the new threat?
According to a report in the Asia Times, a modified Aadhaar enrolment software, known as ECMP (Enrolment Client Multi Platform), has been compromised. It is, in fact, being illegally distributed for as little as Rs 500, going up to Rs 2,000.
ECMP is basically Aadhaar client software that was developed to allow enrolment operators to collect personal data and biometrics from applicants in order to generate the 12-digit number. It was supposed to be fully-secure, since it not only required biometrics of an authorized operator but also sought out geo-location. The latter, on paper, ensured that the sensitive data was being collected by someone authorised to do so, in a secure and mandated location.

However, the report claims that a "jailbreak" version of the software was on sale on certain WhatsApp groups among Punjab-based enrolment operators, which promised to bypass the above-mentioned biometric and geo-location safeguards. The illegal software basically came preconfigured with user credentials of various registrars. "The GPS module to track the location of the enrolment has also been disabled through a patch," an information security professional, who looked at the compromised software, told Asia Times. Worse, this version of the software could be installed on any laptop.

Why is it a concern?
The compromised ECMP software sans any safeguards would effectively allow anybody to pose as an authorised Aadhaar enrolment operator, free to enrol anyone they like, from anywhere in the world, and pass off their information as legitimate. Given that Aadhaar is being billed by the government as a tamper-proof verification for identity as well as residency, imagine what will happen if this hacked software is unleashed in areas prone to illegal migrant flows like Assam or in areas susceptible to militant intrusions like Jammu and Kashmir.

Furthermore, as the report explains, the compromised ECMP will allow any unauthorised entity to update anyone's identity and address details without any verification, bypassing all security protocols set in place by UIDAI. So the threat posed by this "jailbreak" ECMP version is actually a pan-India concern.
In March, Ajay Bhushan Pandey, CEO of UIDAI, had declared that "Each Aadhaar biometric is encrypted by a 2048-key combination and to decode it, the best and fastest computer of our era will take the age of the universe just to hack into one card's biometric details." But what about a compromised enrolment process itself, which puts a question mark on the authenticity of the Aadhaar data collected?

Does UIDAI know about this threat?
An operator from Punjab, Bharat Bhushan Gupta, reportedly informed UIDAI about the compromised software in an email, even offering help to access to the same. Just last month, a Punjab-based journalist also alerted the Aadhaar body about these developments. But while UIDAI acknowledged the warnings, the daily claims that no details of any follow-up action were forthcoming.


(With PTI inputs)

13431 - Another Aadhaar howler? EPFO data stolen by hackers - Money Control

May 02, 2018 06:43 PM IST | Source: Moneycontrol.com


Intelligence Bureau had provided leads of "hackers exploiting the vulnerabilities prevailing in the website (aadhaar.epfoservices.com) of EPFO".

Moneycontrol News

Vulnerabilities related to the security of Aadhaar data once again came to the fore following reports of hackers stealing EPFO data.

In a letter dated March 23, Central Provident Fund Commissioner, VP Joy, said that the Intelligence Bureau had provided leads of "hackers exploiting the vulnerabilities prevailing in the website (aadhaar.epfoservices.com) of EPFO".

The letter has been addressed to the Common Services Team (Delhi) of MeitY. As of now, servers and other hosted services on the EPFO website are offline.

But later in the day, UIDAI issued a statement saying that no confirmed data leakage has been established or observed so far.
“The said website does not belong to UIDAI in any manner whatsoever. This matter does not pertain at all to any Aadhaar data breach from UIDAI servers. There is absolutely no breach into Aadhaar database of UIDAI. Aadhaar data remains safe and secure," UIDAI said in a statement.


Currently, out of 4.6 crore contributing members, as many as 2.75 crore have linked their Aadhaar with their PF accounts. However, out of 2.75 crore, 1.25 crore Aadhaar numbers have been verified.

13427 - UPDATED: Security Sources Confirm Data Loss In Hack On EPFO Aadhaar Seeding Platform - Huffington Post



Security loophole open for "few weeks".

BLOOMBERG VIA GETTY IMAGES

Government sources have confirmed that a vulnerability in a government-run website meant to assist employees link their provident fund accounts with their Aadhaar numbers was targeted by hackers who made off with an unknown amount of sensitive personal data.

The website, the source said, was leaking data for "a few weeks" before it was detected and taken offline. Authorities are still trying to ascertain the nature, and quantity, of the data obtained by the hackers.

The data breach came to light earlier today, when a secret note, sent by Employee Provident Fund Organisation (EPFO)'s Chief Provident Fund Commissioner V.P. Joy, surfaced on Twitter.



EPFO data stolen by hackers exploiting the vulnerabilities prevailing in the website (http://aadhaar.epfoservices.com ) : VP Joy, Central Provident Fund Commissioner to MeitY.
Aadhaar case in SC at the last stage, how will the Govt defend this now ?


The note, marked "Secret" and dated 23 March 2018, was a rare instance of an attack on a vulnerable state data cache becoming public knowledge. The vulnerability was detected in the Aadhaar-seeding platform provided by the Common Services Centre (CSC) E-governance Services Ltd, a special purpose vehicle of MEITY.

EPFO is just one of many government departments that use this platform for Aadhaar-seeding various services. In February this year, the Unique Identification Authority of India (UIDAI) terminated its relationship with CSC, citing corruption and violations in the aadhaar-enrollment centres run by the company.

This security breach is the latest illustration of the vulnerabilities of India's ambitious e-governance push and, security analysts say, highlights the risks of the central government push to seed citizen aadhaar numbers in multiple state-maintained databases.

"It has been intimated that data has been stolen by hackers by exploiting the vulnerabilities prevailing in the website (aadhaar.epfoservices.com) of EPFO," the March 23 letter said, adding that the attack had been first spotted by the Intelligence Bureau.


SCREEN SHOT OF EPFO LETTER
An excerpt of a secret letter dated 23 March 2018 revealing details of a security breach in an Aadhaar-seeding portal maintained by the Ministry of Electronics and Information Technology

The website was since been taken down soon after the letter was sent, and is yet to come back online.
V.P. Joy, the Central Provident Fund Commissioner of the EPFO and author of the note, confirmed the authenticity of the letter in a phone call with HuffPost, but played down its significance.
"I am not aware of any data leak," Joy said. "We received a warning from the IB on March 22, and so I forwarded it to the relevant authorities the next day. This is a routine administrative matter."

A press release issued by his office, this afternoon, echoed Joy's comments, but seemingly contradicted his March 23 note. "No confirmed data leakage has been established or observed so far," the press release stated.

That the breach occurred from a portal seeding Aadhaar numbers with EPFO UAN numbers, suggests that the hackers are likely to have harvested some Aadhaar numbers. Thus far, the EPFO has linked 34.5 million out of a total of 47.1 million active provident fund accounts with Aadhaar according to news reports.But Joy was at pains to clarify that information about EPFO-Aadhaar linked accounts was maintained on a separate server, which was not compromised.

HuffPost has written to Dinesh Tyagi, CEO of the state-run Common Services Centre, and will update this copy with his comments once he replies.

Known Vulnerability
The March 23 2018 refers to two specific vulnerabilities: "Strut vulnerabilities" and "Backdoor Shells."
While "backdoor shells" refer to the possibility of hackers gaining control of a portal's administrator privileges, Struts refers to "Apache Struts", a widely used Java application with an established history of vulnerabilities, the best of known which is the 2017 Equifax data breach which exposed the personal details of 143 American citizens.

In April this year, the Minister of State for Electronics and Information Technology K.J. Alphons, told the Rajya Sabha that the UIDAI had audited Equifax in the aftermath of the data breach.

"It is a known vulnerability," said security researcher Srinivas Kodali. "Had UIDAI audited EPFIO like they audited Equifax, they would have found it."

A similar vulnerability was exploited by French security researcher Robert Baptiste to penetrate the Telangana MNRega website.

On Twitter, where the letter was first posted, security analyst Kiran Jonnalagadda, said it was likely that the vulnerability was spotted by hackers trawling the internet for sites running an insecure version of Struts.


Java Struts vulnerability. Likely caught up in a wide sweep of Struts-powered websites. The Aadhaar angle is incidental, but the leak of Aadhaar-linked data is almost certain. https://twitter.com/arvindgunasekar/status/991540003229454336 …

This story has been updated to reflect information passed on by government sources monitoring the data breach

Wednesday, May 2, 2018

13426 - Aadhaar enrollment software compromised, bypasses biometric, geo-location safeguards: Report


Updated May 01, 2018 | 20:19 IST | Mirror Now Digital

Warnings sent to the Unique Identification Authority of India (UIDAI) though acknowledged, have not been acted upon leading us to believe that the problem is yet to be resolved, said the report.

Aadhaar enrollment software compromised, claims media report |Photo Credit: Representative Image

New Delhi: In yet another development that is likely to compel the UIDAI to run for cover, a media report has claimed that a modified Aadhaar enrollment  software which is currently being sold for as less as Rs 500 can pose national security concerns.
In a report, the Asia Times cited ECMP, the software in question as leading to national security implications owing to the fact that it is currently being circulated from anywhere between Rs 500 and Rs 2000. Warnings sent to the Unique Identification Authority of India (UIDAI) though acknowledged, have not been acted upon leading us to believe that the problem is yet to be resolved, said the report.

In its initial phases, the ECMP was developed as software to be used by operators in order to register recipients who wished to get a unique digital Aadhaar number. However, with reports of discrepancies surfacing from across the length and breadth of the country, the UIDAI decided to blacklist nearly 50,000 private operators eventually tasking public sector banks and post offices with the job of enrolling Aadhaar recipients.


With a nine-judge bench currently hearing a series of clubbed petitions against the government of India's aggressive push for Aadhaar linking with the filing of taxes and issue of SIM cards among other things, it was discovered that the ECMP software enabled now-blacklisted private contractors to not just collect biometric data such as iris scans and fingerprints but also addresses and date of birth in addition to other private data.
According to media reports, several videos easily accessible on the internet show how this software can be downloaded and installed. In fact, evidence gathered from group WhatsApp messages of former private operators working with the UIDAI prove how security features such as biometric and geo-location safeguards were bypassed rendering the software as compromised.

Recently, the Supreme Court bench hearing the Aadhaar case, clearly stated that the mad rush to link Aadhaar with mobile phone numbers supposedly to comply with a direction of the apex court was uncalled for, adding that it had not ordered any such mandatory linkage. The final hearings in the Aadhaar case came in the wake of a nine-judge Constitution Bench headed by the then Chief Justice of India JS Khehar ruling in August last year that privacy was a fundamental right guaranteed under the Constitution.


13425 - Cracked Aadhaar Enrolment Software Being Sold for Rs 500 to Rs 2,000: Report - The Wire



This compromised software could allow anyone to create new Aadhaar numbers without accompanying identity proof or documentation, leading to major national security implications.

There are broad implications for national security from this vulnerability. Credit: File photo

1.6K
interactions
22 HOURS AGO

New Delhi: Modified or ‘jailbroken’ versions of Aadhaar enrolment software – which can theoretically be used by anybody to add new entries to the UID database or modify their own existing entries – are being sold by rogue operators for Rs 500 to Rs 2,000, according to a report published on Tuesday by Asia Times.

If correct, this cracked software could allow anyone to create new Aadhaar numbers without accompanying identity proof or documentation, leading to major national security implications.
The official enrolment software, known as ECMP, was developed to allow authorised operators to register people so that they could get an Aadhaar number.

Given the sensitive nature of the data that flows through the software, ECMP came with two safeguards. One, it asks for the biometrics of the authorised operator and two, it uses geolocation data to ensure that the data being collected is being done by someone with authorisation and that the process is being carried out a secure and mandated location.

It appears that these safeguards have now been compromised.
“Messages posted in several WhatsApp groups among Punjab-based operators began to surface at the end of last year, offering to sell a “jailbreak” version of the software. This version, to be installed on the laptops of anyone willing to pay the amount, could bypass the biometric and geo-location safeguards,” the report notes.

“This basically meant that anyone posing as an “authorised operator” could make changes to the data and enrol new people from anywhere and pass their information off as legitimate. This is easier as the number is only proof of residency and not citizenship,” the report adds.

According to the report, the Unique Identification Authority of India (UIDAI) and state police across the country have already in the last six months received complaints of criminal groups bypassing the biometric safeguards of the software.

What are the implications?
There are two broad implications for national security from this vulnerability. 

Firstly, as the Asia Times report points out, it could theoretically allow the creation of new Aadhaar numbers for fake people, ghosts or worse, even foreign nationals and potential terrorists who have never even visited India.

Secondly, it allows anyone with access to the cracked software to update their own Aadhaar information, such as address details, without any checks or validation from the authorities.

According to the report, at least three separate attempts by different parties have been made to inform the UIDAI of the security loophole in the enrolment software, but the Aadhaar agency is yet to respond.

13424 - Aadhaar data leaks: Andhra govt begins audit of department websites - The News Minute

The AP Cyber Security Operations Centre based in Visakhapatnam has started inspection of various government websites.

Days after an independent researcher highlighted cases of Aadhaar details of citizens that were leaked online, the Andhra Pradesh government has started remedial measures.
According to reports, the AP Cyber Security Operations Centre (Cyber SOC) based in Visakhapatnam has taken over various government websites for inspection.

“We have started the AP Cyber Security Operations Centre to sanitise and monitor all the websites of the various government departments. All the departments are now submitting their website details and we are sanitising backend servers. Cyber SOC has taken over all the AP government websites and we are doing an audit and inspection to find out how secure the data is, where it is stored and how to protect it better. It will take about a week to complete the operation,” IT Minister Nara Lokesh was quoted as saying.

The leaks
Less than a week ago, whistleblower Srinivas Kodali had said that the Aadhaar data of at least 1.34 lakh citizens in the state was compromised, along with other details like their religion, caste and bank details.

The names were part of a list titled ‘Beneficiary Details belonging to Entry Report for Scheme Hudhud’ and were available on the website of the Andhra Pradesh State Housing Corporation. The details made it easy to ‘profile’ the citizens, which was in contradiction of the Unique Identification Authority of India's (UIDAI) stand that it does not link such details with the Aadhaar number.

A day later, Srinivas put out screenshots that suggested that the Unique Identity Number (UID) numbers of 89,38,138 MNREGA (Mahatma Gandhi National Rural Employment Guarantee Act) beneficiaries had been compromised on the website of the Andhra Pradesh Benefit Disbursement Portal.
On April 28, Srinivas claimed that the Aadhaar data of 69,83,048 children was exposed online from the website of the Andhra Pradesh Commissionerate of school education.
On April 30, he tweeted that the Aadhaar numbers of 20,71,913 pregnant women and recent mothers during the period of from 2015-2018 had been published.

“While the government has legitimate interest in collecting this data for helping track mortality rates, the linking with Aadhaar and sharing is bad,” he had explained at the time.

Is Andhra more prone to leaks?
Speaking to TNM, Srinivas pointed out that Andhra Pradesh had been one of the first states to introduce Aadhaar along with Maharashtra and Rajasthan.

“In fact, a lot of details were collected before the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act in 2016, and being a technologically advanced state, Andhra Pradesh made sure that there was 100% linking and seeding,” Srinivas said.
“When more data is collected, there will be more leaks as we can’t be sure who has access to the information. Aadhaar data is such that it can be demanded by design,” he added.
Srinivas points out that several companies collect Aadhaar details under the garb of Know your Customer (KYC).
“Several private companies now ask for the data and store it, they could even be linking it with your internet searches or your location. Say two large companies decide to go ahead with a merger. They will merge all these data sets too, and more people will now have access to that information,” he explained.
“UIDAI says Aadhaar is privacy by design, but it is actually leaky by design,” he added.

Even as the debate rages on, the state government has reportedly made Aadhaar a must for visitors to the state’s Secretariat in Amaravati. In an order issued by the General Administration Department, the security personnel were asked to only accept Aadhaar as ID to issue passes.

UIDAI still silent
UIDAI, however, is yet to respond on the matter.
“That’s how their business model works. They force everyone to register and then generate more income as broker charges for APIs, and everyone makes money in that particular ecosystem,” Srinivas claims. 

He also alleged that the Andhra Pradesh government violated the 2013 Act and continues to do so.

“Andhra Pradesh is just an example of what could happen if your data is not protected. The entire country may follow suit soon,” he added.


TNM has reached out to UIDAI for a response and this story will be updated if and when they do.

13409 - 'Strengthen legal system to avoid data breach' - Indian Express


Panish Hangal, partner, Arka Advisory Services India, Bengaluru,  said our legal system must be further strengthened to tackle Aadhaar database leak.

Published: 30th April 2018 06:23 AM  
By Express News Service

KOCHI:Panish Hangal, partner, Arka Advisory Services India, Bengaluru,  said our legal system must be further strengthened to tackle Aadhaar database leak. Speaking at a seminar on  ‘Cyber Security for Business Resilience’ organized by Indo- American Chamber of Commerce here, he pointed out that in US and European countries, the legal system is so stringent that huge penalty has to be paid for a data breach.

“As the Facebook authorities didn’t give us any undertaking on the privacy of data, we are not in a position to go for legal remedy against the company for data breach”, Panish said, in a reply to a question.

In today’s scenario, data breach is the biggest threat a business can face. 

How one can protect his business from this risk? Many business owners feel that their company is too small to be at risk.  Figures revealed by Symantec show that over 43% of cyber attacks in the recent past were targeted towards small businesses. This shows why cyber security is all the more critical to small and medium-sized business than larger ones, who may have the resources to constantly upgrade their security systems from time to time.

Cyber security is not just about technology and computers. It involves people, information systems, processes, culture and physical surroundings as well as technology. It aims to create a secure environment where businesses can remain resilient in the event of a cyber breach. Email ‘phishing’ attacks regarding payment requests have impacted numerous clients in recent months resulting in millions of dollars of financial fraud. Laptops, desktops and handheld devices are being hacked using malicious software resulting in exfiltration of sensitive and confidential corporate documents.


Again disgruntled former employees are sabotaging information systems impacting the company’s business operations. Information Security Management System (ISMS) implementation leading to ISO 27000:2013 certification can help organisation’s with a structured approach for achieving or maintaining their objective, adds Panish Hangal.Indo- American Chamber of Commerce Kerala Chapter chairman  P  Ravindranath welcomed the gathering and Sujatha Sunil offered a vote of thanks.

Tuesday, May 1, 2018

13405 - AP puts up Aadhaar data of 4.8 lakh pregnant women on site - TNN


TNN | Updated: Apr 30, 2018, 13:39 IST

HYDERABAD: In another data leak of sorts, the Andhra Pradesh woman and child welfare department put up the Aadhaar numbers of 4.8 lakh pregnant women enrolled by the department of nutrition and health tracking system on its dashboard. After STOI enquired about the issue, the department disabled the column showing the Aadhaar numbers on Sunday. 

Cybersecurity researchers, who notified the Aadhaar leak to Computer Emergency Response Team of India (CERT-In) and the Unique Identification Authority of India (UIDAI), said that the Aadhaar details of around 20 lakh mothers and pregnant women, including the current 4.8 lakh, has been leaked since 2015. 

The dashboard of the women and child welfare department is linked to the AP chief minister's core dashboard. It made public details such as name, husband's name, Aadhaar number, dare of enrolment with anganwadi centres, high-risk grading and status of follow-ups. Mandal-wise data of pregnant women in 13 districts up to Feb 2018 were displayed.

"I notified the CERT-In, UIDAI and the AP Core Digital Data Authority regarding the Aadhaar numbers put up openly on the website. There was no response. Perhaps, they are closed on Sunday. Collecting data of pregnant women is a good initiative so that the government can follow-up with them to decrease the maternal mortality and infant mortality rates, prevent anaemia in mothers and malnutrition in kids. But the problem is linking it with Aadhaar. The violation of rules is in making this data public," Kodali Srinivas, cybersecurity researcher, told STOI.

TOP COMMENT
bakwaas aadhaar

JHAKAAS nniraadhaar
Anonymous

"The e -commerce websites selling baby products and merchandise for new mothers may try to use this data as it is openly available on net," he added.

When contacted, the women and child welfare department's IT coordinator, Ratnakar, told STOI: "After the Supreme Court directions in 2017, we removed all Aadhaar details put up in the public domain. Even for intra-department purposes, we use only the last four digits to identify beneficiaries. But due to unknown reasons, the Aadhaar numbers were displayed openly on the dashboard. We are disabling it instantly." Security researchers alleged, the government is not doing an audit. "AP has an Act which protects officials from prosecution for data revealed 'in good faith," Srinivas said.

13404 - In A Week, Aadhaar Data Of 70 Lakh Children On Andhra Pradesh Government Sites - NDTV



Public display of Aadhaar numbers is illegal. In November 2017, the UIDAI said that 210 government websites had publicly displayed Aadhaar details.

All India | Written by Sukirti Dwivedi | Updated: April 30, 2018 16:59 IST

Thirty FIRs have been registered so far for alleged violations of the Aadhaar law. 

NEW DELHI:  The UIDAI, the body that governs Aadhaar, has maintained that its database is secure with them. But there have been reports of multiple government departments using the Aadhaar data and have been found disclosing private details of lakhs of citizens. Despite these leaks being reported, no substantial action seems to have been taken. 

A Hyderabad-based cyber security researcher found 3 different portals of the Andhra Pradesh government disclosing Aadhaar numbers of 90 lakh adults and 70 lakh children in the last seven days.

The Jharkhand government's social security department was found to have recently published Aadhaar numbers of 15 lakh pensioners on its website. The Chandigarh Public Distribution scheme website disclosed Aadhaar numbers of 5 lakh ration card holders. The Kerala government's pension scheme website was found to have displayed the unique identification numbers of 35 lakh pensioners.

In November last year, the UIDAI (Unique Identification Authority of India) said that 210 central and state government websites had publicly displayed Aadhaar details.

Srinivas Kodali, the cyber security researcher who found 3 Andhra Pradesh government portals disclosing Aadhaar data, said government officials want to link "everything" to Aadhaar since it eases their administrative tasks. "But when you do this, you stop securing it and leaks become easier. You don't know which data is to be disclosed publicly and which one is to be safeguarded. The UIDAI and state officials hound the whistle-blowers and go after them instead of figuring out the problem. Just like the way they reacted when Rachna Khaira reported in The Tribune about buying Aadhaar data of millions for 
Rs.500."

Public display of Aadhaar numbers is illegal under the Aadhaar Act 2016 but the UIDAI, which has filed 30 police complaints so far for alleged violations of the law, including those against journalists and cyber security researchers, has not taken any action against the government departments that put up the Aadhaar data.

7

The UIDAI did not respond when NDTV contacted the agency. 

Experts believe that the problem also lies in the Aadhaar laws. 

Supreme Court lawyer and cyber law expert, Pavan Duggal said, "I believe the Aadhaar ecosystem is completely unsafe. There is so much Aadhaar information flowing in this ecosystem and the Aadhaar Act is completely deficient in addressing the ecosystem related legal issues... The Aadhaar Act strips the citizens of India, all Aadhaar card holders of even their basic right to report about misuse of Aadhaar. You cannot register an FIR, only the UIDAI can."