In 2009, I became extremely concerned with the concept of Unique Identity for various reasons. Connected with many like minded highly educated people who were all concerned.
On 18th May 2010, I started this Blog to capture anything and everything I came across on the topic. This blog with its million hits is a testament to my concerns about loss of privacy and fear of the ID being misused and possible Criminal activities it could lead to.
In 2017 the Supreme Court of India gave its verdict after one of the longest hearings on any issue. I did my bit and appealed to the Supreme Court Judges too through an On Line Petition.
In 2019 the Aadhaar Legislation has been revised and passed by the two houses of the Parliament of India making it Legal. I am no Legal Eagle so my Opinion carries no weight except with people opposed to the very concept.
In 2019, this Blog now just captures on a Daily Basis list of Articles Published on anything to do with Aadhaar as obtained from Daily Google Searches and nothing more. Cannot burn the midnight candle any longer.
"In Matters of Conscience, the Law of Majority has no place"- Mahatma Gandhi
Ram Krishnaswamy
Sydney, Australia.

Aadhaar

The UIDAI has taken two successive governments in India and the entire world for a ride. It identifies nothing. It is not unique. The entire UID data has never been verified and audited. The UID cannot be used for governance, financial databases or anything. It’s use is the biggest threat to national security since independence. – Anupam Saraph 2018

When I opposed Aadhaar in 2010 , I was called a BJP stooge. In 2016 I am still opposing Aadhaar for the same reasons and I am told I am a Congress die hard. No one wants to see why I oppose Aadhaar as it is too difficult. Plus Aadhaar is FREE so why not get one ? Ram Krishnaswamy

First they ignore you, then they laugh at you, then they fight you, then you win.-Mahatma Gandhi

In matters of conscience, the law of the majority has no place.Mahatma Gandhi

“The invasion of privacy is of no consequence because privacy is not a fundamental right and has no meaning under Article 21. The right to privacy is not a guaranteed under the constitution, because privacy is not a fundamental right.” Article 21 of the Indian constitution refers to the right to life and liberty -Attorney General Mukul Rohatgi

“There is merit in the complaints. You are unwittingly allowing snooping, harassment and commercial exploitation. The information about an individual obtained by the UIDAI while issuing an Aadhaar card shall not be used for any other purpose, save as above, except as may be directed by a court for the purpose of criminal investigation.”-A three judge bench headed by Justice J Chelameswar said in an interim order.

Legal scholar Usha Ramanathan describes UID as an inverse of sunshine laws like the Right to Information. While the RTI makes the state transparent to the citizen, the UID does the inverse: it makes the citizen transparent to the state, she says.

Good idea gone bad
I have written earlier that UID/Aadhaar was a poorly designed, unreliable and expensive solution to the really good idea of providing national identification for over a billion Indians. My petition contends that UID in its current form violates the right to privacy of a citizen, guaranteed under Article 21 of the Constitution. This is because sensitive biometric and demographic information of citizens are with enrolment agencies, registrars and sub-registrars who have no legal liability for any misuse of this data. This petition has opened up the larger discussion on privacy rights for Indians. The current Article 21 interpretation by the Supreme Court was done decades ago, before the advent of internet and today’s technology and all the new privacy challenges that have arisen as a consequence.

Rajeev Chandrasekhar, MP Rajya Sabha

“What is Aadhaar? There is enormous confusion. That Aadhaar will identify people who are entitled for subsidy. No. Aadhaar doesn’t determine who is eligible and who isn’t,” Jairam Ramesh

But Aadhaar has been mythologised during the previous government by its creators into some technology super force that will transform governance in a miraculous manner. I even read an article recently that compared Aadhaar to some revolution and quoted a 1930s historian, Will Durant.Rajeev Chandrasekhar, Rajya Sabha MP

“I know you will say that it is not mandatory. But, it is compulsorily mandatorily voluntary,” Jairam Ramesh, Rajya Saba April 2017.

August 24, 2017: The nine-judge Constitution Bench rules that right to privacy is “intrinsic to life and liberty”and is inherently protected under the various fundamental freedoms enshrined under Part III of the Indian Constitution

"Never doubt that a small group of thoughtful, committed citizens can change the World; indeed it's the only thing that ever has"

“Arguing that you don’t care about the right to privacy because you have nothing to hide is no different than saying you don’t care about free speech because you have nothing to say.” -Edward Snowden

In the Supreme Court, Meenakshi Arora, one of the senior counsel in the case, compared it to living under a general, perpetual, nation-wide criminal warrant.

Had never thought of it that way, but living in the Aadhaar universe is like living in a prison. All of us are treated like criminals with barely any rights or recourse and gatekeepers have absolute power on you and your life.

Announcing the launch of the # BreakAadhaarChainscampaign, culminating with events in multiple cities on 12th Jan. This is the last opportunity to make your voice heard before the Supreme Court hearings start on 17th Jan 2018. In collaboration with @no2uidand@rozi_roti.

UIDAI's security seems to be founded on four time tested pillars of security idiocy

1) Denial

2) Issue fiats and point finger

3) Shoot messenger

4) Bury head in sand.

God Save India

Showing posts with label Cross Match Technologies. Show all posts
Showing posts with label Cross Match Technologies. Show all posts

Sunday, September 3, 2017

11949 - Forget Aadhaar, there's a bigger privacy risk you have already taken - Economic Times


BY ECONOMICTIMES.COM | SEP 01, 2017, 05.00 PM IST

The Centre has directed 30 smartphone makers to inform it about the procedures they follow to ensure the security of mobile phones sold in India.

Those who protest against Aadhaar, the 12-digit biometric identification number, due to privacy concerns and risk of data theft, may have missed the elephant in the room — the smartphone. Indians run a bigger risk of data theft and loss of privacy through their smartphones. 

India's former union home secretary Rajiv Mehrishi has flagged this concern which does not evoke enough debate. Mehrishi, who retired as Union Home Secretary on Thursday, told a parliamentary panel last month that 40 per cent of people who use smartphones and top applications, knowingly or unknowingly, share data with the entire world including the Central Intelligence Agency (CIA) of the US, according to a report in The Indian Express. 

Mehrishi made this remark on July 21 when he appeared before the Parliamentary Standing Committee on Home Affairs, according to the report. 

Mehrishi said fingerprints and biometrics were being captured through smartphones. 

Before Mehrishi's made this statement, Wikileaks had claimed to have exposed CIA's humongous hacking programmes. In March, Wikileaks released a data dump which it claimed were Central Intelligence Agency (CIA) tools used for hacking into smart devices. The software targeted by the hacking tools included Apple’s iOS and Google’s Android. 

There is a growing awareness about security issued related to smartphone apps. 

Recently, the Ministry of Electronics and IT directed 30 smartphone makers to inform it about the procedures and processes they follow to ensure the security of mobile phones sold in India, following reports of data leakage and theft. 

The smartphone makers, which include global players such as Apple and Samsung and Chinese makers such as Oppo, Vivo, Xiaomi, Lenovo and Gionee, besides home-bred ones such as Micromax, have been asked to provide details about security practices, architecture, frameworks, guidelines and standards followed for providing secure transmission and storage of data. 

The government is finalising cyber security standards for mobile phones. 

According to a recent study by IMDEA Networks Institute of Spain, more than 70 per cent of smartphone apps are reporting personal data to third-party companies like Google and Facebook 

When a smartphone user installs a new app, it asks for the user's permission before accessing personal information. While some of the information collected is required for the app to run, apps can get access to more information than actually required or the required information is used for purposes that violate privacy. For example, third parties can even get to know and track your location and find out what you are doing at a particular moment.


11948 - Is Aadhaar Card Data Safe? Here's the Answer from UIDAI - News 18

UIDAI has said that the Aadhaar biometric information is protected by the best available security measures .
Updated:September 1, 2017, 12:12 PM IST

New Delhi: The Unique Identification Authority of India (UIDAI), the organisation that is responsible for issuing Aadhaar cards in India, has been questioned recently that it doesn’t have adequate safety and security measures to protect the biometric data of crores of citizens who have got an Aadhaar card.

Recently, an RTI application came to light that brought forward that the biometric data collected at the time of issuance of Aadhaar card such as fingerprints and iris scans, is being accessed by foreign firms. 

Also, a recent tweet by Wikileaks stated that CIA had accessed the Aadhaar Database via espionage from Cross Match Technologies (One of the Vendors of UIDAI for Biometric Solutions).

UIDAI refuted all these allegations and in its defence revealed that the Aadhaar biometric information is protected by the best available security measures within UIDAI’s data centre. 

They said that the data is always stored and processed in its own data centre, in addition to being accessed only on completely secure UIDAI servers within the data centre. These servers are not connected to anything be it the Internet or laptop or pen drives beyond the UIDAI data centres. 

The authority also mentioned that the premises are not just protected physically but even the hardware and the devices used are checked twice. The employees are not permitted to be in possession of this data and there are firewalls and intrusion prevention software to ensure no untoward incident happens. 


UIDAI also has contracts signed by the service provides with strict confidentiality clauses in it and any violation of the same could lead to an imprisonment of 3 years.

Friday, September 1, 2017

11943 - Cross Match denies allegations of cyber spying on Aadhaar - TNN

Rachel Chitra | TNN | Aug 30, 2017, 06:45 IST

Cross Match Technology, the company involved in the latest WikiLeaks-Aadhaar controversy, has denied all allegations made in media reports. 

WikiLeaks, last Thurday, published documents that claimed to "expose" that the CIA is using tools devised by US-based Cross Match for cyber spying that may have comprised Aadhaar data.

John B Hinmon, vice-president (global marketing), Cross Match, said, "There is no truth to the claims. Cross Match does not capture, store or process in any manner personal private information, such as fingerprint images, collected by any of its customers."

The technology service provider to the UIDAI since 2011 also denied that its devices had the ability to capture such information."We do not have the technical ability to `remote into' databases and systems that do store such personal data nor have we ever developed or supported such capability for any government or private entity," said Hinmon in an emailed interview with TOI.

Monday, August 28, 2017

11907 - UIDAI Dismisses Reports Of Aadhaar Data Leak - NDTV

The statement came after WikiLeaks hinted that CIA had allegedly accessed the Aadhaar database.

Press Trust of India | Last Updated: August 27, 2017 17:33 (IST)


New Delhi: The UIDAI today asserted that Aadhaar system has stringent security features to prevent any unauthorised capture or transmission of data, refuting reports that hinted at sensitive biometric data being allegedly accessed by certain foreign agencies.

The statement by the Unique Identification Authority of India (UIDAI) came after WikiLeaks hinted that CIA had allegedly accessed the Aadhaar database. Dismissing the allegations, UIDAI said Aadhaar biometric capture system has been "developed within our own country and it has adequate and robust security features to prevent any possibility of any such unauthorised capture and transmission of data regardless of any biometric device that may be used."

The UIDAI said that such "misinformation was being spread by certain "vested interests".

"Some vested interests are trying to spread misinformation that since 'Cross Match' is one of many devices which are being used in biometric devices by various registrars and agencies in Aadhaar ecosystem, the biometrics being captured for Aadhaar are allegedly unauthorisedly accessed by others," the UIDAI statement said rejecting charges of data compromise.

Outlining the stringent checks and balances in UIDAI system, it said that any biometric device before being used in Aadhaar system is "thoroughly tested" internally and externally extensively by Standardised Testing Quality Certification (STQC) and certified.

"In addition, there are many other rigorous security features and processes within UIDAI through which it ensures that no biometric data of any individual is unauthorized accessed by anyone in any manner whatsoever," the UIDAI said.

The Aadhaar issuing body said that the biometric identifier had been issued to over 117 crore people, with around 4 crore authentication taking place every day. "Till date, there has not been a single case of leak of biometric data, theft of identity,  or financial loss  to any one on account of use of Aadhaar.
The UIDAI will continue to take every possible measure to ensure  that Aadhaar  remains safe and secure," it said.

(This story has not been edited by NDTV staff and is auto-generated from a syndicated feed.)

For latest news on Business, like us on Facebook and follow us on Twitter.
Story first published on: August 27, 2017 17:33 (IST)

11906 - Aadhaar Vendor, Recently Linked With CIA, Says It Does Not Store or Capture Customers' Biometric Information - NDTV


Manish Singh, 27 August 2017

Photo Credit: Wikileaks Mobile Information Collection Unit / Flickr

HIGHLIGHTS
  • WikiLeaks published CIA's confidential documents this week
  • The documents revealed that CIA ran a program to collect biometric data
  • One company that could have been impacted has also worked with UIDAI
Cross Match Technologies, a US-based company that offers biometric products and services to a range of customers including India's Aadhaar authority (UIDAI), told Gadgets 360 that it has not captured, or stored, or processed any personal private information of its customers. The clarification comes days after WikiLeaks reported that US federal agency CIA had the capability to disguise Cross Match's software and then spy on Cross Match clients, theoretically giving it access to biometric data of over 1 billion Indians, if UIDAI were to be one of the organisations targeted. But Cross Match has clarified that its software does not have such capabilities.

John Hinmon, vice president of global marketing at Cross Match Technologies, told Gadgets 360 that the US-based company takes personal privacy very seriously. He added that Cross Match "does not capture, store or process in any manner personal private information, such as fingerprint images, collected by any of its customers," adding that the company doesn't have the "technical ability" to "covertly 'remote into' databases and systems that do store such personal data, nor have we ever been involved in developing or supporting such capability for any government or private entity."

"Crossmatch’s fingerprint scanners and software allow end users to capture, store and process those images in their own systems, under security protocols defined by that end user. Typically, these systems are accessible only by trusted 'administrative users.' To be clear, this is the case with India UID. All software utilised with our scanners was developed, tested and certified under the direction of India UID," Hinmon told Gadgets 360. "We value our partnership with India to support the historic and progressive Aadhaar program that widens social and economic inclusion and channels welfare payments more effectively."

Earlier this week, WikiLeaks published secret CIA documents detailing a biometric collection system that the US agency ran, for which it worked with its intel partners including the National Security Agency (NSA), the Department of Homeland Security (DHS) and the Federal Bureau of Investigation (FBI). The intel partners were "expected" to "voluntarily" share the biometric information they collected, WikiLeaks reported.

The CIA, however, didn't find the arrangement for the biometric collection system sufficient so it reportedly created a secret program called ExpressLane, using which it installed a trojan -- disguised as software update -- that would covertly collect the biometric information, according to WikiLeaks. Citing CIA's internal documents, WikiLeaks alleged that the agency was also using Cross Match's technologies for its biometric collection system, and ExpressLane program could compromise Cross Match's services.

In the aftermath of the WikiLeaks' revelation, reports claimed that the CIA could have managed to access and collect the biometric information -- Aadhaar data -- of Indians, since the UIDAI has also worked with Cross Match Technologies. It needs to be stressed that there is no evidence in WikiLeaks' report that explicitly states that the Aadhaar infrastructure is impacted, too. It is also not known whether Cross Match still provides its services to UIDAI. Update: Cross Match told Gadgets 360 that its software -- Crossmatch MOBS -- which has been referenced in the confidential CIA documents -- "has never been used in any UIDAI application."

More than 1.17 billion people have enrolled in the Aadhaar system — for which a person’s print of all fingers, iris data, and other private information such as name, data of birth, address, and phone number — are collected. Originally conceptualised to help a portion of Indians avail social welfare programs, the central government has made Aadhaar identity mandatory for availing several other services including filing income tax returns and getting a new phone number.

According to a press release issued by Cross Match in 2011, it had received a three-year certification to supply biometric authentication solutions to UIDAI. "Today's milestone demonstrates that Cross Match, as a global leader in image quality and performance, and its Indian partner for the UID program, Smart Identity Devices Pvt. Ltd. (Smart ID), are ideally suited to help make this historic project a reality," Cross Match CEO David Buckley had said then.

The issue, as reported by WikiLeaks, however is that the CIA's ExpressLane program could gather biometric information from systems without knowledge -- and presumably consent -- of its intel partners. In a brief conversation with Gadgets 360, Julian Assange, the founder and publisher of non-profit organisation WikiLeaks said CIA, through its ExpressLane program, installs "trojaned versions of the Cross Match under the cover of a "[software] update.”

A CIA-assigned officer would visit offices and install ExpressLane program — disguised as software update — which would set wheels in motion to covertly collect the biometric information, according to CIA's confidential documents published by WikiLeaks. Several documents detail how the authorised officer would install the program, and the technical details of how the program had been created.

Over the years WikiLeaks, founded in 2006, has published several confidential documents detailing various controversial programs run by governments. "Wikileaks has a solid history of producing legitimate material, but they've also been known to over-inflate the significance of it,” top security analyst Troy Hunt told Gadgets 360. "Especially in more recent times, there's growing concern that the material they're publishing is less in the best interests of the people, and more to further their own agendas. In reality, it's probably a bit of both.”

Update: In a follow-up conversation with Gadgets 360, Cross Match said, "The leaked documents specifically indicate that although malware was installed using a file name that was similar to the name of our software, the malware was designed to not affect, change or interact with our software. Rather, it was designed to act independently of our software." The company added that it had no knowledge about the creation or use of ExpressLane.

The story was updated at 01:40AM IST Monday to add further clarification from Cross Match. 

11905 - WikiLeaks report: Aadhaar-approved biometric firm used in covert info gathering - Indian Express

WikiLeaks report: Aadhaar-approved biometric firm used in covert info gathering
"The core components of the OTS system are based on products from Crossmatch, a US company specialising in biometric software for law enforcement and the Intelligence Community,” it added.


By: ENS Economic Bureau | New Delhi | Published:August 27, 2017 2:13 am

The US-based company Crossmatch, which is one of the certified biometric hardware service provider for the Aadhaar project, has been named in the latest WikiLeaks report as “one of the core components” of ExpressLane — a covert information collection tool run by the Central Investigation Agency (CIA) to “secretly exfiltrate” biometric data. A senior official at the Unique Identification Authority of India (UIDAI), however, denied any connection between ExpressLane and Aadhaar.

“The OTS (Office of Technical Services), a branch within the CIA, has a biometric collection system that is provided to liaison services around the world — with the expectation for sharing of the biometric takes collected on the systems. But this ‘voluntary sharing’ obviously does not work or is considered insufficient by the CIA, because ExpressLane is a covert information collection tool that is used by the CIA to secretly exfiltrate data collections from such systems provided to liaison services,” WikiLeaks said in its article posted on Thursday explaining the leaked ExpressLane documents.

“ExpressLane is installed and run with the cover of upgrading the biometric software by OTS agents that visit the liaison sites. Liaison officers overseeing this procedure will remain unsuspicious, as the data exfiltration disguises behind a Windows installation splash screen. The core components of the OTS system are based on products from Crossmatch, a US company specialising in biometric software for law enforcement and the Intelligence Community,” it added.

On its website, Crossmatch describes its biometric devices like fingerprint scanners as: “Crossmatch is the leading global provider of certified fingerprint readers, from single and dual finger to full ten fingerprint and palm print capture. We offer single finger readers that meet numerous international specifications, from FBI PIV IQS and Mobile ID certifications to India’s STQC certification for the UID program.”

STQC is the Ministry of Electronics and Information Technology’s Standardisation Testing and Quality Certification Directorate. The UIDAI official mentioned above pointed out that only the devices certified by STQC are used for Aadhaar authentication. 

An e-mail query sent to UIDAI CEO Ajay Bhushan Pandey seeking comments on the issue did not elicit any response at time of going to the press.

11898 - Wikileaks says 'CIA can access Aadhaar database', government denies claim - Zee News

WikiLeaks published documents that claims the United State's Central Intelligence Agency (CIA) is using specific tools to secretly collect Aadhaar data


By Zee Media Bureau | Last Updated: Saturday, August 26, 2017 - 14:11

New Delhi: WikiLeaks on Friday published documents that claims the United State's Central Intelligence Agency (CIA) is using specific tools to secretly collect Aadhaar data. These claims have been dismissed by the government.
Wikileaks documents say CIA used ExpressLane – a tool devised by Cross Match Technologies – to cyber spy. “ExpressLane is a covert information collection tool that is used by the CIA to secretly exfiltrate data collections from such systems provided to liaison services," says the published document.
Cross Match Technologies, a US company specialising in biometric software, was one of the first suppliers of biometric devices certified by UIDAI for Aadhaar program. 

Another article, Wikileaks states, “UIDAI, as far as is known, did not do a background check on these companies or their business, professional and personal associations.”
It further claims “CIA agents can access Aadhaar database in real-time.”
Earlier on Friday Wikileaks tweeted:

Have CIA spies already stolen #India's national ID card database? #aadhaar #biometric


A few minutes later, another tweet read: 

Have CIA spies already stolen #India's national ID card database? #aadhaar #biometric

See also "#Aadhaar in the hand of spies"


In 2011, Cross Match Technologies hit the headlines “when it was reported that the US military used a Cross Match product to identify Osama bin Laden during the assassination operation in Pakistan.”

11897- Has CIA got access to India's Aadhaar data bank? Officials say 'no': report - Deccan Herald

DECCAN CHRONICLE.
Published
Aug 26, 2017, 11:33 am IST

Mumbai: US' premier spy agency, the CIA, is deploying tools provided by technology firm Cross Match Technologies for cyber spying that, as a result, may have compromised India's vast Aadhaar data bank, according to a report in The Times of India. So far, the Unique Identification Authority of India, that issues these biometric-based cards, has allotted Aadhaar to around 115 crore Indians.

Cross Match Technologies is a US-based technology solutions firm that provides support to the CIA. Interestingly, CMT also shares its biometric solutions with the UIDAI, nodal agency for Aadhaar. According to the report, CMT's this common thread gives a further push to the claims of possible data leakage.

Officials concerned in India have vociferously denied any such data theft by any agency in the world, the report further said. 

The news comes in just days after India's apex court overwhelmingly ruled in favour of privacy rights. The latest judgement that overruled top court's earlier stands on the issue has once again ignited debate around right to privacy, gay sex and food choices.

On Thursday, WikiLeaks published a release on its Twitter handle that claimed CIA uses a secret 'Express Lane' program to steal biometric data of its partner agencies. According to the WikiLeaks, that claims to have accessed the secret documents of Express Lane project, the CIA conducts cyber operations against liaison services.

RELEASE: CIA 'Express Lane' system for stealing the biometric databases of its 'partner' agencies around the world. 



RELEASE: CIA 'Express Lane' system for stealing the biometric databases of its 'partner' agencies around the world.

This is not the first time that a report about Aadhaar data theft has surfaced. Earlier this month, the government had revealed it has deactivated more than 81 lakh Aadhaar cards suspecting them of being fake. In July, reports said more than a million Aadhaar card data were compromised in Jharkhand due to a programming error that occurred on state's social security website.

In the past as well, similar breaches had occurred in the eastern Indian state that had exposed personal data details of family of M S Dhoni, who was then the captain of the Indian cricket team. Uncovering of any such sensitive data diffuses personal details as name, address, Aadhaar and bank account numbers.

11896 - Wikileaks point to report alleging CIA could have access to Aadhaar data; officials say database is secure - First Post

Wikileaks point to report alleging CIA could have access to Aadhaar data; officials say database is secure

tech2 News Staff Aug, 26 2017 09:55:27 IST
Comment 0

Wikileaks sent out a tweet on Friday, which almost seems to allege that central intelligence agency (CIA) spies might already be having access to the Aadhaar database.

According to the link to a story tweeted out by Wikileaks, tools developed by US-based technology company Cross Match Technologies are being used by CIA to access the Aadhaar database. This claim has been dismissed by the official sources in India.

Cross Match Technologies was one of the first suppliers of biometric devices which were certified by the unique identification authority of India (UIDAI) for the Aadhaar program. The company had received approvals for its 'Guardian' fingerprint capture device and 'I Scan' iris scanning devices in 2011.

Official sources who spoke to the Times of India have said that the reports do not have any basis in fact. "Aadhaar data is safely encrypted and is inaccessible to any other agency," say official sources.

Have CIA spies already stolen #India's national ID card database? #aadhaar #biometric


According to the story published on Great Game India, Express Lane which is a covert information collection tool used by the CIA to secretly exfiltrate data collection, has been used to get access to biometric data. The report claims that the office of technical services (OTS) is a branch within the CIA which has a biometric collection system that is meant to liaison with services around the world.

"The core components of the OTS system are based on products from Cross Match, a US company specialising in biometric software for law enforcement and the Intelligence Community. The company hit the headlines in 2011 when it was reported that the US military used a Cross Match product to identify Osama bin Laden during the assassination operation in Pakistan," says the report on Wikileaks. The report goes on to say that Express Lane is installed and run on the biometric data collection software by OTS agents who visit the liaison sites.

Published Date: Aug 26, 2017 09:55 am