In 2009, I became extremely concerned with the concept of Unique Identity for various reasons. Connected with many like minded highly educated people who were all concerned.
On 18th May 2010, I started this Blog to capture anything and everything I came across on the topic. This blog with its million hits is a testament to my concerns about loss of privacy and fear of the ID being misused and possible Criminal activities it could lead to.
In 2017 the Supreme Court of India gave its verdict after one of the longest hearings on any issue. I did my bit and appealed to the Supreme Court Judges too through an On Line Petition.
In 2019 the Aadhaar Legislation has been revised and passed by the two houses of the Parliament of India making it Legal. I am no Legal Eagle so my Opinion carries no weight except with people opposed to the very concept.
In 2019, this Blog now just captures on a Daily Basis list of Articles Published on anything to do with Aadhaar as obtained from Daily Google Searches and nothing more. Cannot burn the midnight candle any longer.
"In Matters of Conscience, the Law of Majority has no place"- Mahatma Gandhi
Ram Krishnaswamy
Sydney, Australia.

Aadhaar

The UIDAI has taken two successive governments in India and the entire world for a ride. It identifies nothing. It is not unique. The entire UID data has never been verified and audited. The UID cannot be used for governance, financial databases or anything. It’s use is the biggest threat to national security since independence. – Anupam Saraph 2018

When I opposed Aadhaar in 2010 , I was called a BJP stooge. In 2016 I am still opposing Aadhaar for the same reasons and I am told I am a Congress die hard. No one wants to see why I oppose Aadhaar as it is too difficult. Plus Aadhaar is FREE so why not get one ? Ram Krishnaswamy

First they ignore you, then they laugh at you, then they fight you, then you win.-Mahatma Gandhi

In matters of conscience, the law of the majority has no place.Mahatma Gandhi

“The invasion of privacy is of no consequence because privacy is not a fundamental right and has no meaning under Article 21. The right to privacy is not a guaranteed under the constitution, because privacy is not a fundamental right.” Article 21 of the Indian constitution refers to the right to life and liberty -Attorney General Mukul Rohatgi

“There is merit in the complaints. You are unwittingly allowing snooping, harassment and commercial exploitation. The information about an individual obtained by the UIDAI while issuing an Aadhaar card shall not be used for any other purpose, save as above, except as may be directed by a court for the purpose of criminal investigation.”-A three judge bench headed by Justice J Chelameswar said in an interim order.

Legal scholar Usha Ramanathan describes UID as an inverse of sunshine laws like the Right to Information. While the RTI makes the state transparent to the citizen, the UID does the inverse: it makes the citizen transparent to the state, she says.

Good idea gone bad
I have written earlier that UID/Aadhaar was a poorly designed, unreliable and expensive solution to the really good idea of providing national identification for over a billion Indians. My petition contends that UID in its current form violates the right to privacy of a citizen, guaranteed under Article 21 of the Constitution. This is because sensitive biometric and demographic information of citizens are with enrolment agencies, registrars and sub-registrars who have no legal liability for any misuse of this data. This petition has opened up the larger discussion on privacy rights for Indians. The current Article 21 interpretation by the Supreme Court was done decades ago, before the advent of internet and today’s technology and all the new privacy challenges that have arisen as a consequence.

Rajeev Chandrasekhar, MP Rajya Sabha

“What is Aadhaar? There is enormous confusion. That Aadhaar will identify people who are entitled for subsidy. No. Aadhaar doesn’t determine who is eligible and who isn’t,” Jairam Ramesh

But Aadhaar has been mythologised during the previous government by its creators into some technology super force that will transform governance in a miraculous manner. I even read an article recently that compared Aadhaar to some revolution and quoted a 1930s historian, Will Durant.Rajeev Chandrasekhar, Rajya Sabha MP

“I know you will say that it is not mandatory. But, it is compulsorily mandatorily voluntary,” Jairam Ramesh, Rajya Saba April 2017.

August 24, 2017: The nine-judge Constitution Bench rules that right to privacy is “intrinsic to life and liberty”and is inherently protected under the various fundamental freedoms enshrined under Part III of the Indian Constitution

"Never doubt that a small group of thoughtful, committed citizens can change the World; indeed it's the only thing that ever has"

“Arguing that you don’t care about the right to privacy because you have nothing to hide is no different than saying you don’t care about free speech because you have nothing to say.” -Edward Snowden

In the Supreme Court, Meenakshi Arora, one of the senior counsel in the case, compared it to living under a general, perpetual, nation-wide criminal warrant.

Had never thought of it that way, but living in the Aadhaar universe is like living in a prison. All of us are treated like criminals with barely any rights or recourse and gatekeepers have absolute power on you and your life.

Announcing the launch of the # BreakAadhaarChainscampaign, culminating with events in multiple cities on 12th Jan. This is the last opportunity to make your voice heard before the Supreme Court hearings start on 17th Jan 2018. In collaboration with @no2uidand@rozi_roti.

UIDAI's security seems to be founded on four time tested pillars of security idiocy

1) Denial

2) Issue fiats and point finger

3) Shoot messenger

4) Bury head in sand.

God Save India

Showing posts with label Abhinav Srivastava. Show all posts
Showing posts with label Abhinav Srivastava. Show all posts

Wednesday, March 7, 2018

12936 - Easy to recognise 'state-sponsored' malwares: Researchers at Nullcon - Tribune India

Posted at: Mar 3, 2018, 5:49 PM; last updated: Mar 3, 2018, 6:42 PM (IST)


At the 9th annual edition of Nullcon, the international security conference, in Goa. — Tribune photo

Rachna Khaira
Tribune News Service
Goa (Cavelossim), March 3

It is easy to differentiate between an ordinary malware from 'state-sponsored' ones by identifying the patters on the victims, said researchers at the 9th annual edition of the Nullcon, the international security conference, that kicked off in Goa on Friday. 

Leading security researcher Eva Galperin, Director of cyber security, Electronic Frontier Foundation (EFF), who has published research on malware in Syria, Vietnam and Kazakhstan, said if a malware is targeting only activist Ahmed Mansoor in UAE, it is not necessarily a state-sponsored malware.

"However, along with Mansoor, if it is also targeting an activist of Human Rights Watch and somebody in the New York Times who cover the Middle east, then we can draw the conclusion that it is probably a nation-sponsored malware," said Eva, adding that if a particular malware is targeting more activists in a particular region, a conclusion can also be drawn as to which state is sponsoring the malware.

She also spoke on her world-acclaimed research to track down Dark Caracal, a leading espionage programme, which was allegedly found to have been routed from a building in Beirut belonging to the Lebanese General Security Directorate.

Analysis made by EFF showed that devices of military personnel, businesses, journalists, lawyers, educators, and medical professionals were compromised.

In yet another exciting hacking workshop, security researcher Adam Laurie, better known by his hacker name 'Major Malfunction' showed how easy it is to hack credit cards, office keys and even the passports having electronic chip fitted inside them.

He even demonstrated the hacking of his son's British passport and how he changed the facial recognition configuration embedded inside the electronic chip to replace his own picture on it. Laurie claimed that he has informed the British authorities about the cracked software around six years ago but they did not paid heed to it and are using the same technology till date.

This was despite the fact that over 3,000 blank passports having an electronic chip embedded inside were stolen from a van few years ago, Laurie said calling it a grave security concern for UK facing terrorist attacks from the last many years.

In another panel discussion moderated by Saikat Datta, an award-winning journalist whose research papers were published by the Centre for Land warfare studies (CLAWS), centre for Airpower studies (CAPS) and the National Security Guards (NSG), the complexity of regulation and cyber security issues were discussed.

Also, technology entrepreneur Abhinav Srivastava, an MSc graduate from IIT Kharagpur, and also the prime accused in the online Aadhaar data theft in 2017 spoke as to how he astonished the investigators by explaining the shortcuts he used to hack the government website to  get Aadhaar data. 

The Tribunes report 'Rs 500, 10 minutes and you can have access to a billion Aadhaar details' on Aadhaar data breach published on January 4 this year was also discussed in the session.

The researchers also spoke about how they hacked Google and a workshop on bug hunter methodology was also held.

According to Antriksh Shah, co-founder of Nullcon, more than 1,400 people, including security experts and researchers, are participating in the two-day event. 

The idea of Nullcon came from null, an open security community having presence in over 13 national and international chapters. With everyone leading a digital life everyday, cyber research and security has become a global concern nowadays and to address this concern, the conference is being held every year from the last nine years, said Shah.

In addition to speeches, exhibitions, workshops, hacking competitions and job fairs are also being held at the venue

Friday, August 18, 2017

11795 - Aadhaar is fully protected: Nandan Nilekani - Deccan Herald


N V Vijayakumar, Bengaluru, 
DH News Service, Aug 16 2017, 14:45 IST


Aadhaar, India's biometric citizen identification platform, is well secured and can't be hacked in, said Nandan Nilekani, former chairman of Unique Identity Development Authority of India (UIDAI). 

In an interaction with DH, Nilekani said there is no need to panic. "Aadhaar system has not been breached and it has well-established security frame work," he said. 

Nilekani also pointed out that Aadhaar platform has implemented best in class global security practices. 

When asked about the recent DH story on the first UIDAI technology head Srikant Nadhamuni's statement on Aadhar, he said Nadhamuni is correct in his observation. 

His comments assume significance as UIDAI lodged a complaint with the Bengaluru police last month against an IIT-Kharagpur engineer Abhinav Srivastava and his start-up Qarth Technologies Pvt Ltd for developing an app and illegally accessing the Aadhaar database.

Nilekani was speaking at the Carnegie India panel discussion on "Who owns personal data: Technology and Policy frameworks". 

He expressed hope that the Justice BN Srikrishna committee which is drafting a data protection framework would look at the model for sharing data and managing privacy developed already. 

"We can't imitate the European GDPR (General Data Protection Regulation) in the Indian context," said Nilekani. He said that the European GDPR was over two decades old and that India needs a new framework in the time of IoT, AI and Machine learning. 


Monday, August 14, 2017

11760 - Bengaluru techie who hacked Aadhaar database may walk away free - Asia Net

By Team Asianet Newsable | 04:24 PM August 08, 2017

Highlights
  • Abhinav Srivastava was arrested after the Unique Identification Authority of India (UIDAI) officials complained about unauthorised access to know your customer (KYC) details of Aadhaar cardholders
  • However, The 31-year-old IIT Kharagpur alumnus may soon walk away free
  • Cyber-law experts say that the IITian had no criminal intent when he developed the App to access KYC details
The 31-year-old IIT Kharagpur alumnus who hacked into Aadhar database and accessed information illegally may soon walk away free. 
Abhinav Srivastava was arrested after the Unique Identification Authority of India (UIDAI) officials complained about unauthorised access to know your customer (KYC) details of Aadhaar cardholders. 
Cyber-law experts and police insiders say that the IITian had no criminal intent when he developed the App to access KYC details and may be let go with a fine and no imprisonment, reported the Deccan Herald.
“Srivastava, through his app, facilitated access to particulars of a given Aadhaar cardholder to get his/her Aadhaar details and not those of anybody else. Thus, it does not amount to cheating. If there were mala fide intention, he would have designed, developed the app and written codes for it from proxy-IDs, leaving no digital footprints of his involvement. But that is not the case here,” said Na Vijayashankar of Naavi-Cyber Law Educationist to Deccan Herald.
The police adopted an over-aggressive approach towards the IITian because his ‘Aadhaar e-KYC’ app fiddled with the Centre’s UIDAI server. Srivastava has been booked under Section 468 of the IPC (forgery for the purpose of cheating), which is a non-bailable offence. But investigation so far has not established that he had cheated anybody. 
However, Srivastava will only face charges of an oversight offence and ignorance for the law and will be penalised accordingly.
The IITian, however, demonstrated loopholes in the coding and security of the database and the cyber police and Aadhaar officials will now fix the flaws.


Saturday, August 12, 2017

11749 - Police Arrest Engineer For Hacking Indian Identity Platform - Bloomberg

By Saritha Rai
7 August 2017 8:46:57 PM AEST
  • Case marks first prosecution for alleged Aadhaar data theft 
  • Arrest comes amid criticism about security and privacy 
Police have arrested a software engineer for stealing sensitive information on more than 50,000 people from India’s Aadhaar biometric identity program, the first criminal charges stemming from a government initiative that’s been criticized for lacking privacy protections.

In a Bangalore police complaint, the engineer was accused of gaining information from the nationwide platform from January to July by using an app to mimic another initiative that lets Aadhaar holders set up appointments online with Delhi hospitals.

Launched in January of 2009, Aadhaar’s overseers are already grappling with accusations of inadequate security for data gathered from more than a billion Indians, as well as potential violations of personal privacy. The country’s Supreme Court is about to rule on a separate case that seeks to uphold privacy as a fundamental right, in a challenge to the program’s legality.
Though data leakages have been reported in the local press, the case involving the engineer marks the first prosecution related to the system.

“The person is in police custody and has been charged with criminal conspiracy and forgery under the Indian Penal Code as well as the Information Technology Act,” said Suneel Kumar, police commissioner of Bangalore.

According to the complaint, the engineer farmed details including names, addresses and phone numbers through an app. If proven guilty, the engineer faces three years in jail and a hefty fine.

Conceived as a program to curb the siphoning-off of welfare meant for the poor, Prime Minister Narendra Modi has pushed the system’s adoption into uses spanning buying a phone, getting utilities connected or conducting financial transactions online.


Ajay Bhushan Pandey, chief executive officer of the Unique Identification Authority of India, which oversees the program, said in a statement that Aadhaar data is completely secure and asked users not to disclose their individual numbers to unknown persons, callers or websites.

11744 - Aadhaar data theft hasn't compromised UIDAI server: Cops - TNN

TNN | Updated: Aug 8, 2017, 06:47 AM IST

BENGALURU: Cyber crime police officers questioning software developer Abhinav Srivastava, 31, arrested for allegedly stealing Aadhaar data, said his actions had not compromised the server of the Unique Identification Authority of India (UIDAI).

Srivastava, a software developer with Ola, had developed an Aadhaar e-KYC app that helped users illegally access Aadhaar data from the UIDAI server. Police discovered that around 40,000 users had downloaded the app in a span of seven months.

"Most of the downloads happened within the country. This is a relief as we had anticipated trouble if foreigners had laid their hands on Aadhaar data. We've studied around 22,000 downloads and most of them were by individuals/entities in Delhi, Mumbai, Ahmedabad and Bengaluru," police sources said.

Asked what would be the next step in the investigation, senior police officials said they will interact with officials from the e-hospital platform of National Informatics Centre. Srivastava's app would lead users to the e-hospital platform which had legitimate access to Aadhaar data. "We have already interacted with a few officials from UIDAI," sources said, adding, "We've been told the e-hospital server will soon be redesigned."

It may be recalled that police had on August 1 arrested Abhinav Srivastava, MSc graduate from IIT-Kharagpur, and currently employed with cab aggregator Ola as a software development engineer, for allegedly hacking and illegally accessing the UIDAI server. The arrest was made after UIDAI officials filed a complaint with police. Preliminary investigations revealed that the accused had helped internet users download demographic data -- details like address, mobile phone number, email address, age and sex -- of at least 40,000 Aadhaar cardholders. 

Wednesday, August 9, 2017

11735 - Aadhaar theft: IIT graduate had done meticulous search of Indian and Chinese govt sites - News Minute

Abhinav was arrested for allegedly illegally stealing data from the UIDAI webiste.


The 31-year-old techie, Abhinav Srivastava, who has been arrested for allegedly illegally accessing Aadhaar data had initially told the police that he had done it just for kicks and to make an extra buck. But according to a report by the Times of India, further questioning has revealed that Abhinav had thoroughly researched the websites of international airports, state governments and the Indian railways as well.

The Bengaluru Cyber Crime Police, studied the four laptops and hard disk seized from Abhinav Srivastava. A preliminary study of these, revealed that he was meticulous in his work, the report adds.
An official in the investigating team told TNM that Abhinav considers himself an ethical hacker. 
“He has meticulously studied the government websites and even the websites of the Chinese government. He has studied how the airline booking system works and also the railway bookings,” the official said.
The officer said that the browser history was blank on all of in Abhinav’s laptops and that the forensic team is in the process of recovering the details. 

“We have approached the internet service providers and have sought the details of the sites he visited and also his online correspondence to ascertain who else is involved in this data theft,” the officer said.

Abhinav was employed with Ola and was arrested on August 1 for allegedly accessing Aadhaar data through the e-hospital server of National Informatics Centre. 

“The Unique Identification Authority of India (UIDAI) officials are slated to meet us by Tuesday and after taking their statements, it will be possible to know the impact on the UIDAI server. The team members are tracking down the people who downloaded the app Abhinav created,” the officer said.
Abhinav, who is from Uttar Pradesh’s Kanpur, and residing in Yeshvanthpur was employed with Ola in Bengaluru. Ola has stated that it had never commissioned or was involved in such activity.
According to the CCB police, Abhinav had developed a mobile application named Aadhaar e-KYC verification for public download. As per the complaint, "Aadhar related information, which is legally housed by the NIC server was illegally and unauthorised accessed and used to support this mobile application."  
“He had tapped into the server in January and had downloaded data of 50,000 people. He had earned about Rs 40,000 in advertisement revenue through this application. There is suspicion that he has developed several other apps so far and he earned Rs 40,000 from advertisements,” the police added.


11734 - Aadhaar data can be stolen easily, techie arrested for theft holds demonstration - North Lines


August 6, 2017

Aadhaar data can be stolen easily, techie arrested for theft holds demonstration

In a six hour demonstration, a Bengaluru techie and entrepreneur showed the police how easy it was for him to access Aadhaar data from the UIDAI data base. Abhinav Srivastava was arrested last week for the data theft following a complaint by the UIDAI authorities.

Cyber crime police in Bengaluru recorded Abhinav’s modus operandi which highlighted a glaring security chink, the lack of Hypertext Transfer Protocol Secure (HTTPS) in the URL that helped Abhinav access details. The founder of an Ola subsidiary firm, Qarth Technologies Pvt Ltd, Abhinav used shortcuts to access data from various websites that used Aadhaar data.
HTTPS consists of communication over Hypertext Transfer Protocol within a connection encrypted by Transport Layer Security. In simpler terms, it is a far better secure connection than the HTTP. HTTPS is aimed at authentication of the visited website and protection of the privacy and integrity of the exchanged data. The lack of it helped the accused hack into an e-hospital website.

On initial investigation, it was found that Abhinav accessed Aadhaar information from an e-hospital’s server hosted by the National Informatics Centre. The hospital was a Know Your Customer user agency which has tied up with the UIDAI. Abhinav hacked into the hospital’s system and linked the information on its server to an app that he developed.
The app, which was available on google store, has been removed now. It was able to redirect users to the e-hospital’s servers to access KYC data. Even as he claimed that he did not steal any information but only gave access to a server, using Aadhaar data without prior permission from the UIDAI is a violation of the Aadhaar law.

Abhinav who holds a masters degree from IIT-Kharagpur used the loopholes in the e-hospital’s URL to gain access to its unsecured servers. With his app, anyone could access details about anyone who had an Aadhaar card breaching the privacy of individuals. Following a complaint by the UIDAI, the High grounds police in Bengaluru booked Abhinav, his company and its promoters for accessing secure Aadhaar database and leaking information under sections 37, 38, 29(2) of Aadhaar (Targeted Delivery of Financial and other Subsidies, Benefits and Services) Act 2016, sections 65 and 66 of the IT Act.


Sunday, August 6, 2017

11723 - Flaws in Aadhaar data security: Investigators - Indian Express

By Akram Mohammed  |  Express News Service  |   Published: 05th August 2017 

BENGALURU: Even as Cyber Crime wing of the police is looking into the case of illegal access to Aadhaar database, a few independent investigators have discovered a security flaw in the Aadhaar system.

Cyber security experts said that the flaw can be used to get SIM cards, opening bank accounts etc.

Meanwhile, police officials who are probing the case are looking the technical details on how the accused Abhinav Srivasatav got the required access to provide e-KYC, and how the database did not display the name of the KYC agency calling the server to provide Aadhaar verification and others.

Sources from Unique Identification Authority of India (UIDAI) said that the accused might have accessed passwords by hacking or ‘piggy-backing’ on E-Hospital - a healthcare delivery platform developed by National Informatics Centre (NIC).
Independent investigators, who are analysing the ‘Aadhaar e-KYC’ application, ruled out the possible hacking into the Central Identities Data Repository. 

Cyber analyst Anand Venkatanarayanan, who verified the process employed by the Android app, felt that the owner of the application might have reused a licence key from one of the User Agencies - either Authentication User Agency or KYC User Agency.

Apart from it, the code of the app, allowed it to run against the production database without displaying the name of the agency running the programme, leading to violation of Aadhaar Act.

One of the other shortcomings, discovered during the analysis was that the app did not use OTP or fingerprint authentication but the demographic authentication. Though the OTP and fingerprint authentication has some security features, demographic authentication is forbidden under law, since it uses name or mobile number or Aadhaar to verify the credentials.

“Since demographic authentication does not require notifying the holders via email and/or mobile phone, it opens up the terrible possibility that these holders details could have been used as eKYC for getting SIM cards, opening bank accounts etc. While we have no data to indeed claim that this did happen, this is a massive security hole in the entire eco-system and must be plugged immediately,” Venkatanarayanan wrote in a blog related to the case.

Until the security hole is plugged, using Aadhaar as eKYC is no better than existing paper based KYC process. The primary purpose of using eKYC is that it provides a safety net for residents against their paper based KYC documents getting forged and used without their knowledge for illegal purposes, he added.

There is no breach of any Aadhaar data: UIDAI


Following the arrest, UIDAI issued a release on Tuesday, stating, “The UIDAI has carefully gone into the matter and would like to inform and reassure public that there is no breach of any Aadhaar data and compromise of individual’s privacy and security in this case.” “As far as the said App is concerned, it was trying to provide Aadhaar verification to the residents based upon their own consent and to download their own demographic data. Hence, alleged privacy violations reported in some section of media is not true as no one could  get any data of any other person through this App. Aadhaar data remains fully safe and secure.” “Aadhaar based authentication is robust and secure as compared to any other contemporary systems,” the release added.

11722 - Hacker shows cops how he got Aadhaar data - TNN


Rajiv Kalkod | TNN | Updated: Aug 6, 2017, 01:29 PM IST

HIGHLIGHTS
  • The hacker said the absence of Hypertext Transfer Protocol Secure from the URL helped him hack into the e-hospital website
  • He said he did not have any criminal intention
  • He said he developed the app giving out e-KYC details, thinking it would help the common man access Aadhaar information
BENGALURU: Abhinav Srivastava, prime accused in the Aadhaar data theft case, stunned investigators on Saturday with a six-hour demonstration explaining the shortcuts he used to hack+ into websites.

He disclosed the modus operandi he used to hack into the government website to access Aadhaar data. The cyber crime sleuths recorded the entire process on a video camera. "He said the absence of Hypertext Transfer Protocol Secure (HTTPS) from the URL helped him hack into the e-hospital website. HTTPS is the secure version of HTTP (Hypertext Transfer Protocol)," a source said, adding, "All communications between the browser and the website were not encrypted. HTTPS is often used to protect highly confidential online transactions like banking and shopping order forms."

Top Comment
HTTPS is basic security and how come NIC could a website could be hosted without mandatory HTTPS for eKYC agent... someone should be held responsible at NIC/ eHospital/ UIDAI authorities rather than this hacker
natrajv

An MSc graduate from IIT-Kharagpur, Srivastava+ was recently arrested for allegedly hacking into e-hospital server hosted by the National Informatics Centre (NIC), a KYC user agency (KUA) which has tied up with the Unique Identification Authority of India (UIDAI) for Aadhaar authentication services. He allegedly hosted the Aadhaar e-KYC app on Google Playstore. Anyone clicking on it could gain access to Aadhaar data available on the server. The hacker, however, reiterated that he had no criminal intention.

"I developed the app giving out e-KYC details, thinking it would help the common man access Aadhaar information. I had no other intention," police said quoting the accused. Senior officials told Srivastava hacking into the server itself was a criminal act. "He's trying to convince us that he is not a hardcore criminal but that can only be decided after the investigation is over," a Central Crime Branch (CCB) sleuth said. Laptops, hard disks have been sent to FSL. CCB police sent the four laptops and one hard disk they seized from Srivastava's residence to the forensic science laboratory. "We need to carefully examine the gadgets as they contain all the information of his activities," a CCB cop said. 

Thursday, August 3, 2017

11694 - Police suspect user agency insiders responsible for Aadhaar data leak - Biometric Update


July 31, 2017 - 

Indian police and Aadhaar officials suspect that insiders at an authentication user agency (AUA) and a KYC user agency (KUA) are responsible for last week’s Aadhaar data leak, according to sources cited in a report by Deccan Herald.

On July 29, the case was transferred from High Grounds police station to the cyber crime police station.

The leak was discovered when an app offered e-KYC (know your customer) certificates, allegedly by accessing an Aadhaar database without authorization.

The Unique Identification Authority of India (UIDAI) filed a complaint against two of its own authentication service agencies (ASUs), as well as the developer of the app, Qarth Technologies.

Although the complaint alleges that an authentication user agency (AUA) and a KYC user agency (KUA) were behind the data leak, it does not refer to the agencies by name.
The UIDAI said it had issued detailed instructions addressed to all such agencies to ensure the security of the authentication process.

The agencies were tasked with maintaining the confidentiality of Aadhaar information, according to an official source.

The UIDAI framework mandates that an AUA/KUA may be a government, public, private legal agency registered in India.

According to the Aadhaar Act of 2016, a registered authentication agency cannot allow another entity to perform authentication.

Agencies are not allowed to share a licence key, nor are they allowed to forward authentication requests as it would require the use of personal identity data captured by an unaudited application.

“Even for a sub-AUA, separate licence key is used,” a source said.

The complaint registered at the High Grounds police station names mobile app developer Abhinav Srivastava as the prime entity accused, followed by an AUA and a KUA.
Since no sharing of information is allowed without the use of the licence key, the investigation would involve determining which insider leaked the information.

“It looks like some agencies have shared information illegally in connivance with Abhinav Srivastava,’’ a police source said.

There are approximately 400 AUAs and KUAs in operation across India. An AUA provides Aadhaar-enabled services to Aadhaar holders, using authentication as facilitated by an Authentication Service Agency (ASA).


Last week, India’s Supreme Court heard from several petitions challenging the legality of the Aadhaar project in order to determine whether citizens are entitled to privacy as a fundamental right.