In 2009, I became extremely concerned with the concept of Unique Identity for various reasons. Connected with many like minded highly educated people who were all concerned.
On 18th May 2010, I started this Blog to capture anything and everything I came across on the topic. This blog with its million hits is a testament to my concerns about loss of privacy and fear of the ID being misused and possible Criminal activities it could lead to.
In 2017 the Supreme Court of India gave its verdict after one of the longest hearings on any issue. I did my bit and appealed to the Supreme Court Judges too through an On Line Petition.
In 2019 the Aadhaar Legislation has been revised and passed by the two houses of the Parliament of India making it Legal. I am no Legal Eagle so my Opinion carries no weight except with people opposed to the very concept.
In 2019, this Blog now just captures on a Daily Basis list of Articles Published on anything to do with Aadhaar as obtained from Daily Google Searches and nothing more. Cannot burn the midnight candle any longer.
"In Matters of Conscience, the Law of Majority has no place"- Mahatma Gandhi
Ram Krishnaswamy
Sydney, Australia.

Aadhaar

The UIDAI has taken two successive governments in India and the entire world for a ride. It identifies nothing. It is not unique. The entire UID data has never been verified and audited. The UID cannot be used for governance, financial databases or anything. It’s use is the biggest threat to national security since independence. – Anupam Saraph 2018

When I opposed Aadhaar in 2010 , I was called a BJP stooge. In 2016 I am still opposing Aadhaar for the same reasons and I am told I am a Congress die hard. No one wants to see why I oppose Aadhaar as it is too difficult. Plus Aadhaar is FREE so why not get one ? Ram Krishnaswamy

First they ignore you, then they laugh at you, then they fight you, then you win.-Mahatma Gandhi

In matters of conscience, the law of the majority has no place.Mahatma Gandhi

“The invasion of privacy is of no consequence because privacy is not a fundamental right and has no meaning under Article 21. The right to privacy is not a guaranteed under the constitution, because privacy is not a fundamental right.” Article 21 of the Indian constitution refers to the right to life and liberty -Attorney General Mukul Rohatgi

“There is merit in the complaints. You are unwittingly allowing snooping, harassment and commercial exploitation. The information about an individual obtained by the UIDAI while issuing an Aadhaar card shall not be used for any other purpose, save as above, except as may be directed by a court for the purpose of criminal investigation.”-A three judge bench headed by Justice J Chelameswar said in an interim order.

Legal scholar Usha Ramanathan describes UID as an inverse of sunshine laws like the Right to Information. While the RTI makes the state transparent to the citizen, the UID does the inverse: it makes the citizen transparent to the state, she says.

Good idea gone bad
I have written earlier that UID/Aadhaar was a poorly designed, unreliable and expensive solution to the really good idea of providing national identification for over a billion Indians. My petition contends that UID in its current form violates the right to privacy of a citizen, guaranteed under Article 21 of the Constitution. This is because sensitive biometric and demographic information of citizens are with enrolment agencies, registrars and sub-registrars who have no legal liability for any misuse of this data. This petition has opened up the larger discussion on privacy rights for Indians. The current Article 21 interpretation by the Supreme Court was done decades ago, before the advent of internet and today’s technology and all the new privacy challenges that have arisen as a consequence.

Rajeev Chandrasekhar, MP Rajya Sabha

“What is Aadhaar? There is enormous confusion. That Aadhaar will identify people who are entitled for subsidy. No. Aadhaar doesn’t determine who is eligible and who isn’t,” Jairam Ramesh

But Aadhaar has been mythologised during the previous government by its creators into some technology super force that will transform governance in a miraculous manner. I even read an article recently that compared Aadhaar to some revolution and quoted a 1930s historian, Will Durant.Rajeev Chandrasekhar, Rajya Sabha MP

“I know you will say that it is not mandatory. But, it is compulsorily mandatorily voluntary,” Jairam Ramesh, Rajya Saba April 2017.

August 24, 2017: The nine-judge Constitution Bench rules that right to privacy is “intrinsic to life and liberty”and is inherently protected under the various fundamental freedoms enshrined under Part III of the Indian Constitution

"Never doubt that a small group of thoughtful, committed citizens can change the World; indeed it's the only thing that ever has"

“Arguing that you don’t care about the right to privacy because you have nothing to hide is no different than saying you don’t care about free speech because you have nothing to say.” -Edward Snowden

In the Supreme Court, Meenakshi Arora, one of the senior counsel in the case, compared it to living under a general, perpetual, nation-wide criminal warrant.

Had never thought of it that way, but living in the Aadhaar universe is like living in a prison. All of us are treated like criminals with barely any rights or recourse and gatekeepers have absolute power on you and your life.

Announcing the launch of the # BreakAadhaarChainscampaign, culminating with events in multiple cities on 12th Jan. This is the last opportunity to make your voice heard before the Supreme Court hearings start on 17th Jan 2018. In collaboration with @no2uidand@rozi_roti.

UIDAI's security seems to be founded on four time tested pillars of security idiocy

1) Denial

2) Issue fiats and point finger

3) Shoot messenger

4) Bury head in sand.

God Save India

Showing posts with label Anumeha Yadav. Show all posts
Showing posts with label Anumeha Yadav. Show all posts

Saturday, January 20, 2018

12693 - Who Is Running the ‘Orchestrated Wine And Cheese Campaign’ Against Aadhaar in the SC? - The Wire

Who Is Running the ‘Orchestrated Wine And Cheese Campaign’ Against Aadhaar in the SC?

Defenders of Aadhaar have called opposition to it an organised campaign stemming from paranoia. But a look at the petitioners proves it is anything but.

One cannot confirm if any of these petitioners, who have all submitted bulky petitions, do in fact drink wine or/and eat cheese. Credit: File photo

New Delhi: Just last week, UIDAI’s former chairman Nandan Nilekani called the opposition to Aadhaar, an “orchestrated campaign”. A few days before that, an editorial in an Indian news portal said the opposition comes from “activists of the upper crust, upper class, wine ‘n cheese, Netflix-watching social media elite – mostly of the Left”.

And in an interview with The Wire last year, former Attorney General Mukul Rohatgi said, “This paranoia is coming from a few people in a country of 150 crore.”

Nilekani, the architect of the Aadhaar project, has also spoken at length in reference to a major story in The Tribune that took on global resonance on how India’s entire Aadhaar database is being breached and leaked through various vendors.

Among the more prominent faces at the helm of the fight is one Padma Shri awardee, three Ramon Magsaysay awardees, three former Indian army personnel, a retired high court judge, a parliamentarian and the entire government of West Bengal.

And yet who are these people who apparently “drink wine, eat cheese”, and also make a commitment to the Supreme Court to spend money and time (over six years for some), only to spite Nilekani’s Aadhaar project?

The protesters
A look at the 30 challenges filed before the Supreme Court and the people behind them casts doubts on the accusations that the ‘wine and cheese’ lot have no understanding of base realities.

In fact, by simply looking at the various sections of society those opposed to the project belong to, it becomes clear that this isn’t an organised and ‘orchestrated’ campaign, but a motley bunch of individuals who have been tagged together by the Supreme Court on a now bloated Aadhaar petition. The earliest petition (by retired Justice Puttaswamy) has been plodding along for six years, since 2012, and 11 others out of the 30, joined the fight the very next year.


One cannot confirm if any of these petitioners do in fact drink wine or/and eat cheese, but from reading their bulky submissions, they appear have committed themselves to a cause that they truly believe interferes with the lives of the Indian people.

Justice (retired) Puttaswamy: At 92, Puttaswamy is one of the oldest living petitioners in the Supreme Court, and the oldest petitioner in the Aadhaar case. He was born in 1926 and enrolled as an advocate in 1952. By 1977, he was appointed a judge of the Karnataka high court. His challenge, a path he put himself on in 2012, is the first challenge to the Aadhaar case. The now historic privacy judgement delivered in August 2017, takes its name from his challenge.

Bezwada Wilson: Wilson has been the driving force behind India’s efforts at providing dignity, security and emancipation to manual scavengers who risk their lives while cleaning drains and latrines. Manual scavengers, who largely belong to the ‘lower caste’ in India, face stigma and exclusion. Wilson is not new to long-fought and hard-won public interest litigations and has fought a case which led to the government to pass laws for the prohibition of the employment of manual scavengers. In 2016, he received the Ramon Magsaysay award.

Major General (retired) SG Vombatkere: Vombatkere retired as a major general of the Indian Army after 35 years of service. He is now over 70 was awarded the Visishta Seva Medal by the President of India in 1993. He is a key petitioner in this case along with Bezwada Wilson. Their submission says it is “wider” than Puttaswamy’s and calls for the Aadhaar Act to be declared a violation of Article 14, 19 and 21 of the Indian constitution and asks that no one be denied any service on account of Aadhaar. They have also asked the court to direct that all data collected under Aadhaar by the public and private sector be destroyed. They have challenged the National Population Register and Aadhaar’s link.

Shantha Sinha: Shantha Sinha was the first chairperson of the National Commission for Protection of Child Rights and served two consecutive terms (2007 to 2013). She has also been on various other government committees on national integration, right to education, mid-day meals and adult education. Her work on the ground in Andhra Pradesh was directed at rescuing children from child labour and admitting them to government schools. She also received the Ramon Magsaysay award in 2003 and the Padma Shri in 1998.

Kalyani Menon Sen: Sen is a feminist scholar and has been an activist for women’s rights for over 25 years. She has worked with the United Nations Development Programme, advising on gender related issues. Sinha and Sen are co-petitioners in their case. Some of their prayers are similar to Wilson’s and Vombatkere’s. They’ve also moved court seeking that “accounts of current bank account holder will not be made in-operational and future applicants will not be coerced to submit their Aadhaar numbers.” They’ve petitioned the court similarly for the government’s order on linking mobile numbers to Aadhaar.

Aruna Roy: Roy was briefly a bureaucrat in the Indian Administrative Service (1968 to 1975) but resigned and is now known for her nearly 40 years of work with the rural poor in Rajasthan and ‘Mazdoor Kisan Shakti Sangathan’ which she runs. She was also a key figure in the movement which led to India passing the Right to Information Act as well as the Right to Food. She was a member of the UPA’s National Advisory Council for five years and was instrumental in the passage of the Mahatma Gandhi National Rural Employment Guarantee scheme. Along with Wilson and Sinha, Roy has also received the Ramon Magsaysay award.

Nikhil Dey: Dey is a long-time colleague of Aruna Roy, a co-founder of the ‘Mazdoor Kisan Shakti Sangathan’ and a co-petitioner with her on this case. With Roy, he too has worked on the right to information, food and employment in India. Their petition saw every state and union territory of India being made a respondent. “The present experimentation would undoubtedly result in social exclusion by depriving persons of the fundamental rights and also putting at stake vast sums of tax payer’s money,” says their petition.

Major General (retired) SCN Jatar: Jatar served with the Indian Army from 1954. He commanded an engineer regiment in India’s 1971 war in the Poonch Sector (Jammu and Kashmir) and was the commander of infantry brigades in the Kashmir Valley and Rajasthan dessert, from 1977 to 1981. He has been appointed to several government committees and was also the Chairman at ONGC Videsh Limited and Oil India. His petition saw the Election Commission and Reserve Bank of India appear as respondents.

Colonel (retired) Mathew Thomas: Thomas, who is around 80, retired as Colonel from the Indian Army and has seen military action in Nagaland, China and Pakistan. In 2014, he was invited to address a BJP parliamentary panel, where he explained various issues around the Aadhaar scheme. He has asked the court to direct an investigation into the role of foreign and private companies in the collection of biometric data of Indians.

Supporting material in the form of research has been submitted to the court by Reetika Khera (professor at IIT Delhi), Jean Dreze (co-author with Amartya Sen of An Uncertain Glory: India and its Contradictions), Jude Terence D’souza (securities system specialist in Mumbai), Anand Venkatanarayanan (data security expert in Bangalore), Samir Kelkar (security consultant) and Anumeha Yadav (journalist, formerly at Scroll.in).


Liked the story? We’re a non-profit. Make a donation and help pay for our journalism.

Sunday, May 21, 2017

11442 - Will Aadhaar leaks be used as an excuse to shut out scrutiny of welfare schemes? - Scroll.In

Will Aadhaar leaks be used as an excuse to shut out scrutiny of welfare schemes?
Aadhaar data of all 23 crore beneficiaries of Direct Benefit Transfer schemes could be publicly available, says a report by Centre for Internet and Society.

Published 13 hours ago.  

                                   Noah Seelam/AFP

In the past three months, there have been several reports about caches of Aadhaar data being publicly displayed on government websites across the country.

Personal information associated with the biometric-based 12-digit unique identification number, which the government wants every Indian resident to have, is mandated to be confidential under the Aadhaar Act, 2016.

But exactly how much Aadhaar data has been compromised by negligent government departments?

On May 2, researchers at the non-profit Centre for Internet and Society released a comprehensive report on the extent of the data breaches. They documented four government portals using Aadhaar for making payments and found that sensitive personal and financial information of nearly 13 crore people was being displayed on them, including details of about 10 crore bank accounts.

Two of the portals, for the Mahatma Gandhi National Rural Employment Guarantee Act and the National Social Assistance Programme, belong to the Union rural development ministry. The others are run by the Andhra Pradesh government for the workers’ insurance scheme Chandranna Bima and for filing Daily Online Payment Reports of MNREGA.

The researchers estimated that Aadhaar data of all 23 crore beneficiaries of the central government’s various Direct Benefit Transfer schemes could be publicly available. This means nearly a fifth of India’s population is potentially exposed to irreversible privacy harm, and financial and identity fraud.

The Unique Identification Authority of India, the agency which manages the Aadhaar database, had denied any breach of confidential data on May 3. But two weeks later, on May 17, the UIDAI wrote to the Centre for Internet and Society, asking it to provide more details. In the report, the researchers had demonstrated that Aadhaar numbers could be easily accessed on the National Social Assistance Program, a pensions scheme administered by the Ministry of Rural Development, even behind a login, and that this pointed to poor security standards. The UIDAI has now termed this as an instance of illegal access by the researchers.

CIS has clarified that it did not violate the Information Technology Act 2000 by adopting this research method, and that the organisation had notified concerned government departments, including the UIDAI, prior to publishing its report so that the sensitive data could be removed.

The rural development ministry, on its part, has changed how its MNREGA database is accessed, redacting Aadhaar numbers and bank account details of the beneficiaries. Senior officials of the ministry, however, denied making systemic changes in the wake of the Centre for Internet and Society report.

“The researchers claimed that financial information of over 10 crore individuals was available publicly, on pension and MNREGA portals,” said Nagesh Singh, additional secretary in the ministry, “but bank account details were displayed only on two state department websites of Andhra Pradesh and Telangana as these states are far advanced in transparency practices.”

“For all other states,” Singh added, “financial information and Aadhaar numbers were removed or masked last year. For pension schemes we masked the data in June 2016, and for MNREGA this data was removed in December. Even if any data was showing, it would only be for the particular block the resident is in, not for any other state workers.”

All this was done, he said, “because the UIDAI communicated to us that this information is sensitive and should not be displayed and the Aadhaar regulations prohibit display of Aadhaar numbers”. The Aadhaar (Sharing of Information) Regulations were introduced last September.

The chief executive officer of UIDAI, Ajay Bhushan Pandey, did not respond to Scroll.in’s questions emailed on May 19.



Contrary to Singh’s claims, social activists outside Andhra Pradesh and Telangana confirmed they could access bank account details of MNREGA workers until May 3. Only on May 4, two days after the Centre for Internet and Society report was released, did the details stop showing on the Management Information System.

“We could no longer access the electronic muster roll, and it started returning error messages,” said Ashish Ranjan of Jan Jagran Shakti Sangathan, a registered union of unorganised workers in Araria, Bihar. But until early May, he added, the Management Information System allowed anyone in any state to access the personal information of workers, even from other states.

Activists and beneficiaries relied on this system for two things. “Several of the new bank accounts have errors, and accessing this information directly helped get the discrepancies corrected without going to block level officials,” Ranjan explained. “It also helped track where the wages of workers were stuck.”
When activists asked why the data was no longer accessible, Ranjan said, rural development department officials said the Management Information System was changed “on the directions of the Supreme Court and the Union cabinet secretary.”

“This has been the pattern with the MNREGA MIS for long,” Ranjan said, referring to the information system. “Senior officials change access to a feature as they wish without clear processes or explanations.”

James Herenj, an activist with NREGA Watch, a non-profit which monitors the implementation of MNREGA in Jharkhand, had the same experience. “Bank account details were removed from the website last week,” he said, “this is a problem as we can no longer help MNREGA workers get data entry errors corrected.”
The Centre for Internet and Society researchers too contested the rural development ministry’s claim that Aadhaar numbers and bank account details were displayed only on Andhra Pradesh and Telangana government websites. They released a video clip showing them accessing bank account details and Aadhaar numbers of 801 MNREGA workers of Agara panchayat in Bengaluru through an internet search on March 25.



Screenshot of a Chandigarh Union Territory website displaying Aadhaar information.
Consent, please?
The Aadhaar Act, 2016 requires both government and private agencies to take informed consent before using a person’s Aadhaar for authentication, but there is little evidence that consent is sought before Aadhaar is seeded with personal and financial information.
Indeed, when the Supreme Court first permitted the voluntary use of Aadhaar for MNREGA in October 2015, Aadhaar numbers of 2.36 crore workers had already been seeded to their bank accounts, without the consent of over 99% of them.
The rural development ministry’s data shows that until June 2016, only about 4,10,000, or less than 1% of the 10.7 crore MNREGA workers, had agreed to Aadhaar-based payments. The ministry worked around this by organising “consent camps” to retrospectively collect proof of consent.
Poor standards
Writing in The Economic Times, Ram Sewak Sharma, chairperson of the Telecom Regulatory Authority of India and former director general of the Unique Identification Authority of India, argued that the reports about “Aadhaar leaks” on government websites failed to account for provisions of the Right to Information Act, 2005. Section 4 of this law provides for proactive disclosure of government decisions while Section 8 mandates public authorities to publish all information on welfare schemes, including details of beneficiaries.
This has created a situation, Sharma pointed out, where the transparency law may require even Aadhaar numbers of beneficiaries to be made public even though the Aadhaar Act mandates them to be confidential. 
Right to Information activists, however, said the authorities were anything but devoted to the transparency law. Crucial information they seek on the efficacy of Aadhaar in welfare schemes is routinely denied under Right to Information requests.
“The government is willfully manipulating information systems to subvert details of biometric failures,” said Amrita Johri, a member of the National Campaign for People’s Right to Information and an activist with the Right to Food campaign, which has petitioned the Delhi High Court against Aadhaar being mandatory for food rations. “We have come across instances of ration cardholders being turned back because of fingerprints being falsely rejected, or network failure, but on the Delhi government’s website, this is shown as the beneficiaries not having come to the ration shop at all.”
“Similarly, the government claims it has removed bogus ration cards through Aadhaar,” Johri added, “but they do not show any administrative action if such bogus cards were really found through Aadhaar even though Section 4 of the RTI Act requires disclosure of such decisions.”



Jharkhand Directorate of Social Security displayed Aadhaar numbers, bank accounts numbers and transaction details of over 15 lakh pensioners.
Johri is concerned that the “Aadhaar leaks” could become an excuse to deny people “other useful information”. “When we requested officials to display how many biometric transaction were not successful, they told us that in a few days, they will remove the entire MIS as there had received orders from the food ministry to not display demographic data associated with Aadhaar,” she said. “But we pointed out that it was the creation of a single identification number that is the problem. Why should information on all other government schemes be removed?”
The Centre for Internet and Society report points out that while the law now makes Aadhaar numbers confidential, the government has failed to specify data masking standards. Section 6 of the Aadhaar Regulations lays down that no government or private agency should publish Aadhaar numbers unless they are redacted or blacked out “through appropriate means”.
But this is too vague, the report points out. “In some instances, the first four digits are masked while in others the middle digits are masked,” Srinivas Kodali, one of the authors of the report, explained, “which means someone with access to different databases can use tools for aggregation to reconstruct information hidden or masked in a particular database.”
Kodali said that for information other than Aadhaar numbers, each ministry and department is required to classify the data that is sensitive, restricted or open, which they have failed to do. “The National Data Sharing and Accessibility Policy, 2012 requires securing information of sensitive and restricted data but it does not recommend the ways to do it,” he said. “The standards around information disclosure and control do not exist, and the Ministry of Statistics expert committee on this was unable to suggest one last month.”
“Even for MNREGA data,” Kodali continued, “the Ministry of Rural Development’s chief data officer should have classified the financial information as restricted or open when the database was first created. But did they do this.”
Nagesh Singh, the additional secretary, however said his ministry “does not have a chief data officer to do this”. “The ministry’s economic advisor is the official responsible for categorising data and advises us on this,” he added.
We welcome your comments at letters@scroll.in.

Thursday, April 27, 2017

11144 - Govt websites are leaking Aadhaar details. Who will take action against ? - Business Standard

Personal details of 1.5 mn pensioners were publicly displayed on the website of the Jharkhand govt
April 26, 2017 Last Updated at 09:54 IST

The Narendra Modi government insists that the biometric data of over 1.1 billion Indians who have enrolled for Aadhaar, a 12-digit identity number, is safe. Yet, it is struggling to keep these identity numbers confidential as required by law.

On Saturday, the personal details of nearly 1.5 million pensioners were publicly displayed on the website of the Jharkhand government’s Directorate of Social Security. The details included their Aadhaar and mobile phone numbers and bank account details – a breach that could potentially expose the beneficiaries to profiling and even financial fraud. The website was taken down by the administrators on Saturday night.

On Monday, the website of the Food and Civil Supplies Department of Chandigarh was reported to have publicised Aadhaar numbers of its Public Distribution System beneficiaries. The Union Territory has nearly 490,000 such beneficiaries.

Such breaches of confidentiality have become frequent lately. On Monday, the website of the central government’s flagship Swachh Bharat Mission was found leaking Aadhaar details of its beneficiaries.

On March 29, the Unique Identification Authority of India, which manages the centralised database, blacklisted an enrolment agency after it inadvertently leaked details of former Indian cricket team captain M S Dhoni’s application to join the Aadhaar programme on Twitter. The leak and the authority’s swift action in the high-profile case were even debated in Parliament.

Security researchers, in fact, have pointed out that Aadhaar numbers and associated demographic data is even showing up through simple internet searches. On February 17, security researcher Srinivas Kodali had alerted the authorities that a website had leaked the Aadhaar demographic data of over five lakh minors.

“When I reported the government website that was leaking this data, the UIDAI did not even acknowledge the complaint,” he alleged.

He added: “Besides the one I reported, the ministry of rural development’s website was showing Aadhaar numbers and details of over 100 million MNREGA workers. That was not the first and these will not be the last, because by design, you are allowing the Aadhaar number and details to be stored by anyone. You do not even need an Application Programme Interface, right now everyone can build their own database of Aadhaar numbers.”

Yet, the government has remained silent about these repeated instances of negligence leading to the exposure of ordinary citizens’ data. It has given wide publicity to its action against nine private enrolment agencies, including the one that leaked Dhoni’s application, but is yet to take action against any government agency for serious breaches of data security.

Why are the leaks serious?

Section 6 of the Aadhaar (Sharing of Information) Regulations states: the Aadhaar number of an individual shall not be published, displayed or posted publicly by any person or entity or agency.

In mandating confidentiality, the law-makers have acknowledged the sensitivity of what is designed as a single, universal, digital identity number that any registered entity, whether public or private, can use to “authenticate” an Indian resident.

Authentication can be performed either by verifying a resident’s biometrics (fingerprints or iris scans) or by matching the Aadhaar number with demographic attributes, or through a one-time password sent to a mobile number/email stored in the Central Identities Data Repository. There, the UIDAI confirms if the details — demographic or biometrics — are indeed associated with that particular Aadhaar number.

While Aadhaar regulations state that an electronic know your customer query will require biometric authentication that may make it harder to commit fraud, government authorities have negligently published large caches of demographic data associated with Aadhaar that could be misused to carry out other fraudulent authentications on behalf of an individual.

A number of mobile apps already offer commercial services to verify potential employees, tenants, etc through Aadhaar. For example, TrustID, a mobile-based platform offers to verify individuals through their Aadhaar identities, using either biometrics or by simply matching demographic details or one-time password associated with the Aadhaar number. When such platforms send a query to the UIDAI, the latter responds with a Yes/No to authenticate the individual.

Kiran Jonnalgadda, co-founder of HasGeek, a community for software developers in Bengaluru, said such fraud would be “not be easy to detect and fix, as it is an electronic verification over a mobile app with no tell-tale physical signs.”

“And once an individual faces fraud, it is not clear how their Aadhaar numbers will be replaced with new ones as these are linked to third party databases that expect the number to be unique to an individual. What happens when the same individual shows up in a third party databases with both old and new numbers?,” he added. “The only solution would be is if these were revocable hardware tokens, such as chip and PIN credit or debit cards, or SIM cards, where having the physical card matters, but which can be replaced.”

There are also concerns with the government having made Aadhaar mandatory for a wide range of schemes. Increasingly, an Aadhaar card is being considered sufficient as a form of identification by authorities.

In a blog post, writer Senthil has pointed out that the UIDAI does not include holograms or physical signatures or any other security information in the Aadhaar cards that are sent to applicants?. These are just colour printouts that are easy to replicate. The availability of Aadhaar numbers and demographic data in the public domain could heighten the risk of the use of fake Aadhaar cards.

On its part, the UIDAI allows individuals to receive alerts on mobile or email each time their Aadhaar number is authenticated, but it is not mandatory to register for it.

More seriously, under the law, the UIDAI is not under any legal obligation to inform Aadhaar users when a crime related to their personal data occurs. And the victims cannot approach a court directly because under Section 47 (1) of the Aadhaar Act, the UIDAI has the exclusive power to make complaints in case of any violation or breach of privacy.


In arrangement with Scroll.in



Saturday, April 8, 2017

10998 - It isn't just Dhoni: UIDAI received 1,390 complaints about Aadhaar agents – but took no legal action - Scroll.In


IDENTITY PROJECT

RTIs filed by Scroll.in show complaints about enrolling agencies
demanding bribes and doing fraud enrolments.

8 hours ago.
Anumeha Yadav

On Wednesday, the Unique Identification Authority of India said that it had blacklisted the enrolment agency that had inadvertently leaked details of former Indian cricket team captain MS Dhoni’s application to join the Aadhaar programme.

The day before, Dhoni’s wife Sakshi had sent a tweet to Information and Technology Minister Ravi Shankar Prasad informing him of a breach when the cricketer visited the Common Services Centre in his home town of Ranchi to register for the programme, which aims to give all Indian residents a 12-digit Aadhaar number linked to scans of their fingerprints and irises.

The Unique Identification Authority of India administers the
centralised database in which the information of the 112 crore people who have enrolled for the programme is stored.

After the cricketer’s visit, excited staff at the Common Services
Centre shared the his personal Aadhaar details on Twitter. The tweet was later deleted.


On Wednesday, this data leak and the Authority’s action were even debated in Parliament.

Police complaint
This isn’t the first controversy the Unique Identification Authority of India found itself facing this week. On Tuesday, newspapers reported that the Unique Identification Authority of India had registered a First Information Report against a CNN-News 18 journalist after the television network aired a report demonstrating that it was possible to obtain two enrolment numbers, or enrolment IDs, in Aadhaar despite submitting the same set of biometrics.

Enrolment IDs are temporary numbers issued immediately after a resident submits the demographic and biometric data necessary to obtain an Aadhaar number. In its recent notifications making Aadhaar necessary to access a number of services and programmes, such as mid-day meals for students, the government has permitted these temporary enrolment identity numbers to be used as an identity proof.

The CNN-News 18 report on March 22 showed that journalist Debayan Roy fraudulently obtained two enrolment IDs from an enrolment centre in NOIDA in Uttar Pradesh. The report noted he was unable to obtain two Aadhaar numbers but emphasised that it aimed to highlight concerns about corruption and security at the enrolment stage. On March 24, the television channel interviewed ABP Pandey, the Chief Executive Officer of the Unique Identification Authority of India, about the safeguards
in Aadhaar’s systems.

However, three days later, on March 27, the UIDAI deputy director Delhi regional office Ramesh Kumar filed a police complaint against the reporter, Debayan Roy, for “impersonating”, leading commentators to ask if the government was more concerned with managing its public
image than improving security.

Was this the first case of fraud involving a person enrolling for the programme multiple times?

If it was not, what action has the UIDAI taken on complaints?

After the Aadhaar regulations were notified in September, as part of Scroll.in’s ongoing Identity Project series on the implementation of Aadhaar, this reporter submitted several right-to-information applications posing questions to the Unique Identification Authority of India about the complaints received against enrolling agencies and registrars, the action taken by the UIDAI in response to each complaint, and whether the UIDAI had filed any criminal cases against any enrolling agencies and registrars. The period for which information was sought was from September 2010, when the first Aadhaar
number was issued, till October 31, 2016. Most of the replies from the Authority’s regional offices were received in December and January, with a final response coming in on March 1.

Previous complaints resolved, closed, dropped
While the Aadhaar number is issued by the Unique Identification
Authority of India, the actual process of collecting demographic
information and capturing biometrics is done by enrolment agencies,most of which are private firms, hired by registrars. These agencies are paid a fee by the Authority for every enrolment that they process.

The UIDAI has regional offices in Delhi, Mumbai, Lucknow, Chandigarh, Ranchi, Guwahati, Bengaluru and Hyderabad that supervise enrolment and data collection by these firms across all states and union territories.

Replying to Scroll.in’s query, the UIDAI stated that there are
currently 556 enrolment agencies and 125 Registrars working with it.
The UIDAI stated it had received 1,390 complaints about enrolment agencies between September 29, 2010, when the first Aadhaar number was issued, and October 31, 2016, when more than 80% of all Indian residents had been enrolled.

Out of 1,390 complaints registered by residents as well as local
officials, the UIDAI filed a police complaint against enrolling
agencies in only three instances. All three police complaints were filed by the Authority’s regional Bengaluru office, which has a jurisdiction over Karnataka, Tamil Nadu, Kerala, Puducherry, and Lakshadweep.

In all other over 1,300 instances of complaints against enrolment agencies, the cases were “resolved” or “dropped” or “closed” without a criminal complaint.

Till the police complaint against journalist Roy, no criminal
complaint had been received or registered at the UIDAI’s regional office at Delhi (jurisdiction over Madhya Pradesh, Rajasthan, Uttarakhand, Delhi) as per the RTI reply by UIDAI deputy director Ramesh Kumar.

UIDAI regional office, Delhi did not receive any complaint and did not register any case till the FIR against a TV journalist recently. UIDAI regional office, Delhi did not receive any complaint and did not register any case till the FIR against a TV journalist recently. All three FIRs registered by the UIDAI's eight regional offices till date were at Bengaluru regional office.
All three FIRs registered by the UIDAI's eight regional offices till
date were at Bengaluru regional office.

The maximum number complaints – 1,050 – were recorded at the Authority’s Lucknow office, which has jurisdiction only over Uttar Pradesh, according to the UIDAI’ss reply.

Of these, 759 were recorded as complaints against enrolment agencies, stated the UIDAI regional office at Lucknow. The UIDAI did not file a criminal complaint or a lawsuit in any of these complaints, which were lodged by residents, as well as by district officials.

UIDAI's regional office at Lucknow got over 750 complaints against enroling agencies but did not register a single police complaint against any enrolment agencies.

UIDAI's regional office at Lucknow got over 750 complaints against enroling agencies but did not register a single police complaint against any enrolment agencies.

From bribes to fake enrolments
In the replies shared by the UIDAI’s eight regional offices, 90% of the complaints they received related to agencies charging bribes for enrolment, even though the Aadhaar programme is to be free of cost.

The UIDAI’s recent police complaint against journalist Roy states that he violated sections 34, 35 of the Aadhaar (Targeted Delivery of Financial and Other Benefits, Subsidies and Services) Act, and the Information Technology Act, and other sections of the Indian Penal Code, when he attempted to enrol multiple times in the Aadhaar database.

However, the RTI replies received by Scroll.in show that though
several complaints related to enrolment agencies registering the same person multiple times, no action was taken by the UIDAI. In one case of an operator of enrolment agency CMS Computers Ltd “using a rubber thumb to carry out fake enrolment” in Amroha district, the case was closed without a police complaint.

Other cases related to JNet, Virinchi, India Computers, Lankipalli and other agencies that were “delinquent [in] carrying out enrolment without permission” were also “resolved” without a criminal case.



The complaints show repeated instances of enrolment agencies
registering fake data, misbehaviour by agency staff, agencies running centres in areas where they had no legal authorisation, and centres found running without verifying staff on inspection. There are also repeated complaints of agencies refusing to accord the biometric exception to children below 5 years, who are not required to provide finger prints or iris scans.

Even in cases where a complaint was made by an official, the UIDAI did not make a police case. For instance, in Allahabad, the district magistrate complained that enrolment agency Virgo Softech Ltd was illegally charging money from residents. The case was closed. No criminal complaint was registered against the firm.

The other cases that were resolved without criminal cases include:

In Azamgarh, Meerut and Auraiya, “Goddess Saraswati”, “Lord Ganesha”, “Jhansi ki Rani” were enrolled in the Aadhaar biometrics database.

In Basti, Gautam Budh Nagar and Ghazipur districts, Aadhaar enrolment numbers issued to a cow, a puppy and “Mantu Dog”.
In Meerut, a complaint about enroling agency Smart Chip Limited case was closed.

In Lucknow district, enrolling agency KDMSL enrolled same person multiple times but the case was resolved without a police complaint.

Residents complained about misbehaviour by the staff of enroling agency Agro Tech Engineers, but the case was closed.
In Hapur district, enrolling agency Wipro Ltd. enrolled a puppy, and then enrolled same person multiple times

Complaints pile up
The Authority’s Mumbai office (covering Gujarat, Maharashtra, Goa) said that it recorded 509 complaints, of which 447 were about agencies charging bribes. The enrolment agencies were blacklisted – no duration has been specified – but no criminal complaint was filed in even a single case.

No complaints were recorded at the UIDAI regional office in Ranchi, which works in Jharkhand, Bihar, West Bengal.

A total of 85 complaints were registered against enrolment agencies atthe Hyderabad regional office (covering Andhra Pradesh, Telangana,Chhattisgarh, Odisha), of which 61 were in Telangana. UIDAI did not register a a criminal complaint in any case.

A total of 85 complaints were registered against enrolment agencies at the Hyderabad regional office. UIDAI did not take legal action in any of these instances.
A total of 85 complaints were registered against enrolment agencies at the Hyderabad regional office. UIDAI did not take legal action in any of these instances.
The only office that filed criminal complaints against the agencies was Bengaluru. Its reply shows that of a list of 35 complaints against enrolment agencies, most of which relate to bribery allegations, the agencies were blacklisted for one year in 19 instances, and for five years in one instance.

Legal experts pointed out even though the Aadhaar Act was passed only in March 2016, the Authority could have reported these instances to the police under the IT Act, 2000, or under various sections of the Indian Penal Code. “It is surprising the Authority did not take legal action against these enroling agencies,” said Prashant Reddy Thikkavarapu, a lawyer and a researcher specialising in technology policy at the Singapore Managment University. “Even before the Aadhaar Act, the IT Act and other laws also make impersonation and misuse of data a crime.”

He added: “Also, if the enrolling agencies are being paid per
enrolment under a contract, it is not enough to merely blacklist them for a few years, the Authority should also take steps to recover the payments made to these agencies.”

Suspension, no legal action
Officials of the Unique Identification Authority of India in New Delhi said it was the prerogative of the regional authorities to take legal action against the agencies. “The decision to initiate a criminal complaint or file a FIR with the police lies with the regional offices, for the enrolling firms working in their areas as per guidelines,” Vikash Shukla, senior manager, communications and public outreach with UIDAI told Scroll.in when the agency responded to RTI applications.

While nearly all details of complaints were shared by the regional offices, the UIDAI Headquarters at New Delhi stated in a reply that from September 2010 till October 2016, the Authority’s Enrolment and Update Division has suspended six agencies and canceled their empanelment.

Till date, the Authority’s Enrolment and Update Division has suspended six agencies – M/S 4G Identity Solutions, IL&FS, E-Centric Solutions, Madras Security Printers, CSS Technology and Multiwave Innovations – and canceled their empanelment, according to the reply from its New Delhi office.

The UIDAI headquarters did not provide reasons for suspension of these agencies. Here too, the Authority did not take any action against the firms, limiting itself to suspending their contracts for violating processes.

Of these, CSS — now known as Cosyn — still claimed to be working for the UIDAI on its website.

Legal experts have criticised the UIDAI for lacking clear streamlined processes in its functioning and operating without clearly designated roles and public accountability.

“The UIDAI clearly has had an ongoing transparency problem and the Aadhaar legislation enables this instead of restricting it,” said Chinmayi Arun, executive director, Centre for Communications Governance at the National Law University. “This is unconscionable from an information security as well as an essential service delivery point of view. Instead of stepping back and course-correcting the state continues to steamroll us into making ourselves very vulnerable.”

Sunday, January 22, 2017

10756 - Despite the comparisons, India's Aadhaar project is nothing like America's Social Security Number- Scroll.In


It has more uses and fewer safeguards.
Sunday, January 22nd 2017
Anumeha Yadav


From food rations to marriage certificates, entrance exams to train ticket concessions, mobile phone cards to banking, Indians are now being asked to produce a 12-digit Aadhaar number to access both government and private sector services.

This number is connected to their fingerprint and iris scans that are stored in a centralised database. As of September 2016, this database held the demographic and biometric information of more than 105 crore people – more than 80% of India’s population, and three times the population of the United States.

India’s Unique Identification project is the world’s largest biometrics-based identity programme. Initially, the project had a limited aim – to stop theft and pilferage from India’s social welfare programmes by correctly identifying the beneficiaries using their biometrics. But now, the use of Aadhaar is expanding into newer areas, including business applications.
As the uses of Aadhaar proliferate, what are the rewards and risks?

Over the next week, a special series on Scroll.in will take a closer look at the many dimensions of Aadhaar, from its use for social welfare, to its expansion in the private sector, to concerns over privacy and data violations.

First, a quick comparison with the Social Security Number of the United States. The nine-digit number, which is used widely by government agencies in the US, is seemingly as ubiquitous as Aadhaar. It is often used as an example of an advance economy successfully doing something similar to India’s unique identity project. But there are important differences between the two, starting with the fact that the Social Security Number is, well, not an identity number.

Aadhaar is an identification number. Social Security Number is not.
The Social Security Number has its origins in the years of the Great Depression. During this period of economic recession in the US, the Roosevelt government launched the “New Deal”, a series of programmes to provide relief and employment to the poor.
In 1936, under the Social Security Act, it began using a nine-digit number, the Social Security Number, to track the earnings of workers and compute the amount of social security benefits to be credited to their accounts.

Over the years, the ease of using the number led more government agencies to incorporate it in their records. In 1961, for instance, the Internal Revenue Service began using the Social Security Number for taxpayer identification, similar to the Permanent Account Number in India.

With no legal restrictions on use of the Social Security Number by private companies, several businesses such as credit bureaus started asking individuals for their Social Security Number and storing it.

But in 1977, the Carter administration clarified that while it may used to be verify whether an individual had the legal permit to work, the Social Security Number could not serve as an identification document.

The Social Security Administration website states in a 2009 bulletin: “The card was never intended to serve as a personal identification document that is, it does not establish that the person presenting the card is actually the person whose name and SSN appear on the card.”

By contrast, Aadhaar has been designed as a single, universal, digital identity number that any registered entity, whether public or private, can use to “authenticate” an Indian resident. Anyone who has lived in India for 182 days can enroll in Aadhaar for proof of identity, while only citizens and those authorised to work in the US can obtain a Social Security Number.

Aadhaar authenticates a person. The Social Security Number does not.
Aadhaar authenticates a person by matching his or her demographics or biometrics with the records in its database. The government says this will help prevent identity fraud – for example, no one will be able to collect wages or food subsidies in another person’s name.
The Social Security Number was never intended for authentication purposes and has not been built to do this on a national scale. It matches a name and associated Social Security Number against its records only in limited circumstances, such as before issuing a replacement Social Security Number, or establishing a claims record.
It “does not verify an individual’s identity”, notes the Social Security Administration website, explaining the verification methods.

Aadhaar captures biometrics. The Social Security Number does not.
Aadhaar collects biometrics, which include the scan of all fingerprints, face and the iris of both eyes. Aadhaar Act’s section 2(g) states that “other biological attributes” may be collected in the future, a provision that was intensely debated in Parliament.

The elderly and the poor is India have hardened, wrinkled hands.
In contrast, when the Social Security Number was created in the 1930s, the US government decided not to collect fingerprints. “The use of fingerprints was associated in the public mind with criminal activity, making this approach undesirable,” notes the Social Security Administration website. The Social Security Number is thus printed on a small paper card and does not carry even a photograph.
In recent years too, the Social Security Administration has restrained from collecting biometrics of residents. In 2007, when the Intelligence Reform and Terrorism Prevention Act asked the SSA to improve the security of Social Security Number cards, the SSA considered adding the holder’s photograph or biometrics to the card but eventually decided against it.
“A biometric identifier, such as a fingerprint, can be an effective and highly accurate way to establish the identity of an individual, but it can also facilitate a much higher degree of tracking and profiling than would be appropriate for many transactions,” said Marc Rotenberg, the president of Electronic Privacy Information Center, a research organisation, in a testimony to the House of Representatives.
He added: “The problems that will arise when biometric identifiers are compromised are severe. What will happen at the point that your biometric identifiers no longer identify you?”
Around 2011, American authorities considered introducing a new biometrics-linked identity card for work authorisation for residents. Called the Biometric Enrollment, Locally-stored Information, and Electronic Verification of Employment or BELIEVE card, it aimed capture fingerprints or scans of veins on the back of hands.
BELIEVE card supporters presented it as necessary for immigration reform but many opposed it. “We pointed out that a biometrics ID system would be expensive, intrusive and ineffective, and requiring such an ID card would fundamentally transform the information demands the US government places on its citizens,” said Michael Froomkin, a professor of law at Miami University.
Ultimately, the proposal was dropped.

Aadhaar links databases. The Social Security Number does not.
One of the key concerns around Aadhaar is that the government has “seeded”, or introduced the number in multiple databases, which makes it easier for government agencies to converge personal information of individuals across databases.
Millions of Aadhaar numbers have been linked to the bank records, ration lists, educational records, and telecom documents of individuals. New analytical data techniques mean this “big data” could reveal much more about a person than standalone data could in the past.
The PRS Legislative Research has pointed out the Aadhaar Act of 2016 does not specifically prohibit law enforcement and intelligence agencies from using the Aadhaar number to search various datasets. This could lead to inappropriate profiling and innocent individuals identified incorrectly as potential threats by law agencies could face harassment.
There is no seeding done using the Social Security Number. Federal agencies and private entities that collect the Social Security Number for a specific service store the number at the organisational level. The US government has cautioned against the use of the Social Security Number as a single, unique identifier.
For instance, the Department of Homeland Security in 2007 directed its officials: “Department of Homeland Security programs shall not collect or use an SSN as a unique identifier; rather, programs shall create their own unique identifiers to identify or link information concerning an individual.” The Department of Defence removed SSNs from military identity cards by 2011, and instead issued departmental-level IDs.
The emphasis is on using different identifiers for specific purposes, to reduce the risks associated with a single identifier.

Aadhaar does not have privacy safeguards quite in the same way as the Social Security Number.
In response to growing concerns over the accumulation of massive amounts of personal information, the US government passed the Privacy Act of 1974. The law was passed in recognition of the dangers of the widespread use of Social Security Numbers as universal identifiers.
Subsequently, the Computer Matching and Privacy Protection Act of 1988 tightened regulation, by providing for the establishment of Data Integrity Boards at each agency.
India does not have a privacy law either at the national or state level. As per section 8 of the Aadhaar Act, requesting agencies are required to obtain the consent of individuals before collecting their identity information and inform them of what information will be shared. But as per section 47, a person whose information is collected and shared without their consent cannot invoke the criminal penalty. The Act says such a complaint can only be made by Unique Identification Authority.
Further, when the Unique Identification Authority of India authenticates the identity of individuals against the Aadhaar database, it generates millions of authentication logs every day, containing the request received, the response, and the metadata related to the transaction.
The Authority retains the authentication data for six months, and archives it for five years. It also requires the requesting entities – both public agencies and private companies – to maintain the logs, including the Aadhaar number, for two years, and then archive it for five years, and even longer in case of a court order.
Experts caution against the retention of data for such long periods. Data breaches could potentially violate people’s privacy. In 2014, European Union’s highest court ruled that data retention is illegal.

Aadhaar is designed to be used by private companies. The Social Security number was not, but its use by the private sector has led to identity theft.
Identity theft affects over 90 lakh Americans every year.
Over the years, commercial enterprises, particularly in the financial services sector, have created a system of files containing the personal and financial information of a majority of the American adult population, based on their Social Security Numbers. This information is sold and traded freely, in some instances leading to identity theft, particularly of elderly pensioners and students. Privacy expert Rotenberg has described financial companies as “among the strongest opponents of SSN restrictions.”
A major government report on privacy in 1973 said that legislation should be adopted prohibiting use of the Social Security Number “for promotional or commercial purposes”.
In most states, legally, an individual is required to provide their Social Security Number to a business only if the transaction requires so under Internal Revenue Service or federal Customer Identification Program rules. A few states such as Colorado, Arizona and California have passed laws that restrict the disclosure and use of the Social Security Number by private actors.
In contrast, Aadhaar has been designed for use by both public and private entities. Billionaire software entrepreneur Nandan Nilekani, who is the founder chairperson of Unique Identification Authority of India, while explaining the differences between Aadhaar and the Social Security Number, said Aadhaar had been designed “as an open platform on which you can build applications”.
In a foreword to a Credit-Suisse report, he noted that the use of Aadhaar by the financial sector could open up a $600 billion business opportunity.
The Unique Identification Authority of India has already entered into agreements with a number of companies providing authentication and identification services using Aadhaar as a platform.

Aadhaar functioned without a legal framework till recently. The Social Security Number was created through a law.
Since its inception, the Social Security Number has been governed by the Social Security Act of 1935.
In contrast, the Aadhaar project functioned without a legal framework for seven years since it was launched by the United Progressive Alliance government in 2009. It was run under an executive order, which meant Parliament had no oversight over it.
An Aadhaar Bill was introduced in 2010 but it was rejected by a parliamentary committee over legislative, security, and privacy concerns. In March 2016, the National Democratic Alliance government passed the Aadhaar Act as a Money Bill, bypassing the Rajya Sabha – a move that was widely criticised.

The use of Aadhaar is expanding. The use of the Social Security Number is getting restricted.

The Privacy Act of 1974 makes it unlawful for a governmental agency in the US to deny a right, benefit, or privilege merely because the individual refuses to disclose his Social Security Number, except when disclosure is required by federal statute.
Section 7 of the Act provides that any agency requesting an individual to disclose his Social Security Number must “inform that individual whether that disclosure is mandatory or voluntary, by what statutory authority such number is solicited, and what uses will be made of it.”
Given privacy concerns over the use of Social Security Numbers, governments have passed several laws and orders since 1996 to restrict and limit its use and collection.
The Social Security Administration website says state entities have begun to delete Social Security Numbers on electronic public records. An executive order of 1943 that required federal agencies to use the Social Security Number when establishing a system of permanent account numbers was rescinded by an Executive Order, which made such use optional in 2008.
Several US states have also passed laws. New York and West Virginia have statutes that limit the use of the Social Security Number as a student identity number. Kentucky allows students to opt out of the use of Social Security Numbers. Arizona law requires companies to give a right to users to opt out. California prohibits businesses from printing Social Security Numbers on bills, and companies must notify individuals in case of data breaches.
The Intelligence Reform and Terrorism Prevention Act of 2004 prevented the printing of Social Security Numbers on driver licenses and other government- issued identity cards. A 2015 law prohibited the inclusion of Social Security Numbers on Medicare cards, though this has not yet been achieved.
In contrast, since the first Aadhaar number was issued in 2010, the government in India has tried to link maximum schemes and benefits to Aadhaar, pausing briefly when the Supreme Court issued orders restricting the government from making Aadhaar compulsory.
The Supreme Court passed at least six orders since 2013 saying the government cannot require people to register for an Aadhaar number and no one can be deprived of a government service for not having an Aadhaar number.
But under section 7 of the Aadhaar Act, the government can ask a resident to produce Aadhaar for any “benefit, subsidy or service”, which has made the ambit of the project very wide. Now even private companies have incorporated the Aadhaar number in their systems.
The current trajectories of two ubiquitous numbers – Aadhaar and the Social Security Number – appear to be in opposite directions.

We welcome your comments at letters@scroll.in.