In 2009, I became extremely concerned with the concept of Unique Identity for various reasons. Connected with many like minded highly educated people who were all concerned.
On 18th May 2010, I started this Blog to capture anything and everything I came across on the topic. This blog with its million hits is a testament to my concerns about loss of privacy and fear of the ID being misused and possible Criminal activities it could lead to.
In 2017 the Supreme Court of India gave its verdict after one of the longest hearings on any issue. I did my bit and appealed to the Supreme Court Judges too through an On Line Petition.
In 2019 the Aadhaar Legislation has been revised and passed by the two houses of the Parliament of India making it Legal. I am no Legal Eagle so my Opinion carries no weight except with people opposed to the very concept.
In 2019, this Blog now just captures on a Daily Basis list of Articles Published on anything to do with Aadhaar as obtained from Daily Google Searches and nothing more. Cannot burn the midnight candle any longer.
"In Matters of Conscience, the Law of Majority has no place"- Mahatma Gandhi
Ram Krishnaswamy
Sydney, Australia.

Aadhaar

The UIDAI has taken two successive governments in India and the entire world for a ride. It identifies nothing. It is not unique. The entire UID data has never been verified and audited. The UID cannot be used for governance, financial databases or anything. It’s use is the biggest threat to national security since independence. – Anupam Saraph 2018

When I opposed Aadhaar in 2010 , I was called a BJP stooge. In 2016 I am still opposing Aadhaar for the same reasons and I am told I am a Congress die hard. No one wants to see why I oppose Aadhaar as it is too difficult. Plus Aadhaar is FREE so why not get one ? Ram Krishnaswamy

First they ignore you, then they laugh at you, then they fight you, then you win.-Mahatma Gandhi

In matters of conscience, the law of the majority has no place.Mahatma Gandhi

“The invasion of privacy is of no consequence because privacy is not a fundamental right and has no meaning under Article 21. The right to privacy is not a guaranteed under the constitution, because privacy is not a fundamental right.” Article 21 of the Indian constitution refers to the right to life and liberty -Attorney General Mukul Rohatgi

“There is merit in the complaints. You are unwittingly allowing snooping, harassment and commercial exploitation. The information about an individual obtained by the UIDAI while issuing an Aadhaar card shall not be used for any other purpose, save as above, except as may be directed by a court for the purpose of criminal investigation.”-A three judge bench headed by Justice J Chelameswar said in an interim order.

Legal scholar Usha Ramanathan describes UID as an inverse of sunshine laws like the Right to Information. While the RTI makes the state transparent to the citizen, the UID does the inverse: it makes the citizen transparent to the state, she says.

Good idea gone bad
I have written earlier that UID/Aadhaar was a poorly designed, unreliable and expensive solution to the really good idea of providing national identification for over a billion Indians. My petition contends that UID in its current form violates the right to privacy of a citizen, guaranteed under Article 21 of the Constitution. This is because sensitive biometric and demographic information of citizens are with enrolment agencies, registrars and sub-registrars who have no legal liability for any misuse of this data. This petition has opened up the larger discussion on privacy rights for Indians. The current Article 21 interpretation by the Supreme Court was done decades ago, before the advent of internet and today’s technology and all the new privacy challenges that have arisen as a consequence.

Rajeev Chandrasekhar, MP Rajya Sabha

“What is Aadhaar? There is enormous confusion. That Aadhaar will identify people who are entitled for subsidy. No. Aadhaar doesn’t determine who is eligible and who isn’t,” Jairam Ramesh

But Aadhaar has been mythologised during the previous government by its creators into some technology super force that will transform governance in a miraculous manner. I even read an article recently that compared Aadhaar to some revolution and quoted a 1930s historian, Will Durant.Rajeev Chandrasekhar, Rajya Sabha MP

“I know you will say that it is not mandatory. But, it is compulsorily mandatorily voluntary,” Jairam Ramesh, Rajya Saba April 2017.

August 24, 2017: The nine-judge Constitution Bench rules that right to privacy is “intrinsic to life and liberty”and is inherently protected under the various fundamental freedoms enshrined under Part III of the Indian Constitution

"Never doubt that a small group of thoughtful, committed citizens can change the World; indeed it's the only thing that ever has"

“Arguing that you don’t care about the right to privacy because you have nothing to hide is no different than saying you don’t care about free speech because you have nothing to say.” -Edward Snowden

In the Supreme Court, Meenakshi Arora, one of the senior counsel in the case, compared it to living under a general, perpetual, nation-wide criminal warrant.

Had never thought of it that way, but living in the Aadhaar universe is like living in a prison. All of us are treated like criminals with barely any rights or recourse and gatekeepers have absolute power on you and your life.

Announcing the launch of the # BreakAadhaarChainscampaign, culminating with events in multiple cities on 12th Jan. This is the last opportunity to make your voice heard before the Supreme Court hearings start on 17th Jan 2018. In collaboration with @no2uidand@rozi_roti.

UIDAI's security seems to be founded on four time tested pillars of security idiocy

1) Denial

2) Issue fiats and point finger

3) Shoot messenger

4) Bury head in sand.

God Save India

Showing posts with label Elliot Alderson. Show all posts
Showing posts with label Elliot Alderson. Show all posts

Thursday, August 9, 2018

13844 - Hacker claims he can crack eAadhaar password in under 3 seconds - India Today




Aadhaar has become quite the buzzword these days, and particularly since Telecom Regulatory Authority of India (TRAI) chief RS Sharma caused a furor by revealing his Aadhaar number on Twitter. Ever since Sharma pulled the stunt to prove that Aadhaar was safe and secure, people on social media are trying to prove him wrong. In latest such effort, a hacker called Somdev Sangwan has claimed that he can crack the password of eAadhaar in less than 3 seconds. And to prove his point, he has detailed his methodology in a blog post.

Sangwan in a blog post on Noteworthy has claimed that he can crack the eAadhaar password in just 3 seconds! In case you are wondering how he achieves such a feat, the answer, as he says is simple: using some basic mathematics and clever algorithms that can cycle through the possible password combinations very fast.

Sangwan uses the classic brute force password cracking method, but cleverly prunes the dictionary of possible password combinations that his algorithms will use to crack the eAadhaar password to shorten the duration the whole exercise will take.

In his blog post, Sangwan explains that the Aadhaar password is the combination of the first four letters of a person's name in upper case and his year of birth. Given that data, the total number of combinations possible is 2821109907456, which will take around 92 years to for a person to crack a password if one tries 1000 combinations per second.

But no one has that much time. So, Sangwan has come up with a different method. He reduces the duration required to go through the possible password combinations to 53 days by breaking down the password into two strings. But 53 days is a time period too long to dedicate for cracking a password. And so, he further reduces the time duration to 13 hours by eliminating the years that aren't valid for the possible password. For example no one born before 1910 is likely to have Aadhaar number.
To this then he adds a dictionary of popular Indian names, giving the password crunching algorithms even a narrower focus and thereby reduces the time duration to around 2 minutes and 39.8 seconds.
If you think you can't go lower than that, think again as the hacker then goes on to explain how you can crack the password in just 1.73 seconds by further dividing the names into groups based on popularity and religion.
If his calculations are accurate, one should be able to crack eAadhaar password in a blink of an eye (literally).
This is not the first time that hackers have made such claims. Back in March this year, French security researcher Elliot Alderson shared a video demonstrating how it was possible to bypass the protection on Aadhaar's Android app in one minute.



Alderson is one of the strongest critics of Aadhaar and time and again he has pointed out vulnerabilities in the Aadhaar system.

13840 - Aadhaar helpline in Android phones: From Google’s apology to UIDAI’s assurance in 10 points - Live Mint


Although experts have clarified that the uploading of a contact number, that too from UIDAI, doesn’t cause harm, yet the issue has reignited the debate over the security of data of Aadhaar cardholders

Last Published: Mon, Aug 06 2018. 03 51 PM IST


After UIDAI said it has not asked anyone to include 1800-300-1947 or 1947 in the default list of public service numbers on mobile phones, Google apologised for the “inadvertent” act. Photo: Mint

Android phone users were shocked last week by the presence of a Unique Identification Authority of India (UIDAI) helpline number in the contact list. Frightened by WhatsApp forwards warning them of a breach of privacy, scores of smartphone holders deleted the number and ranted on Twitter.

Although experts have clarified that the uploading of a contact number, that too from UIDAI, doesn’t cause harm, yet the issue has reignited the debate over the security of data of Aadhaar cardholders.

Here in 10 points is everything you need to know about the controversy over the Aadhaar helpline number:

1. The controversy began after a French security expert, who goes by the pseudonym Elliot Alderson on Twitter, flagged off the presence of the UIDAI toll-free number 1800-300-1947 in the contact list of Android smartphone users. This sparked a flurry of tweets and WhatsApp messages.

2. Rumours spread fast that Android mobile phone data had been hacked and privacy of mobile phone users compromised by the insertion of the new number.

3. To quell rumours, UIDAI issued a statement saying that no one can steal data by just by adding a helpline number in a mobile’s contact list. It asked people not to panic and said no harm to anyone has been done.

4. Describing instances of people being asked to delete UIDAI helpline numbers as “totally false propaganda”, UIDAI said vested interests were trying to scare people.

5. The French hacker, who has been running an anti-Aadhaar campaign on Twitter, changed his name to—Elliot Alderson aka “Vested Interest”—in retort to UIDAI’s statement.

6. It was later brought to notice that the toll-free number found in mobile phones is no longer in use by UIDAI, which replaced it with a new number—1947— two years ago. It said people can simply delete the number from their list or update it with the new number if they wish to.

7. The French expert said there was no need to panic as the number was just a contact, but he was alarmed that it could be the tip of “an iceberg”.

8. At first, UIDAI clarified that it did not ask anyone to include the number in mobile phones and then mobile phone service providers denied any involvement.

9. The mystery was solved when Google issued a statement saying the helpline number was inadvertently coded into the setup wizard of Android phones in 2014 and remained there. Apologising for the error, Google said it will fix it in the next release of the setup wizard that will be made available over the next few weeks.

10. The row has sparked a fresh debate over the privacy of users’ data after Telecom Regulatory Authority of India (Trai) chairman R.S. Sharma challenged hackers to harm him by using his Aadhaar data. UIDAI had afterwards warned people not to post their Aadhaar numbers on social media.


First Published: Mon, Aug 06 2018. 03 51 PM IST

Wednesday, June 20, 2018

13685 - Aadhaar Critics are not Ludites - National Herald


Aadhaar critics are not luddites


VIDYUT GORE
Published: Jun 14th 2018, 12.14 PM


              Photo courtesy: Twitter/@ceo_uidai
      File photo of UIDAI chief Ajay Bhushan Pandey

UIDAI chief writes that the fear of a threat to privacy because of the use of core biometrics in Aadhaar is exaggerated because biometrics are not secret information like PIN or password

The CEO of UIDAI, Ajay Bhushan Pandey, has written yet another opinion piece in a newspaper, which bravely argues against established tech security practices.

While Aadhaar FAIL generally tends to ignore individuals and their opinions, it is important to examine the claim and competence of a highly placed public servant, who arguably occupies one of the most important positions related to technology in India.

The UIDAI chief writes that the fear of a threat to privacy because of the use of core biometrics (fingerprints and iris) in Aadhaar is exaggerated because biometrics are not secret information like PIN or password. People, he went on to add, must know that even the theft of biometrics in a rare eventuality will not put one to the same level of risk as the leakage of a password.

A threat to privacy, however, is not about whether the information is secret or not. It is about having the choice of what information we grant and to whom. The residents of India are not criminals that their rights must be waived away and they be compelled to grant access to their biometrics, and that too, to an insecure system, because of a system whose compliance with the Constitution of the country itself has been questioned.

This, in fact, has been repeatedly brought up by the judges in the Supreme Court itself, and Pandey had the opportunity of being the only non-lawyer allowed to present his perspective directly to the judges themselves. The judges did not appear convinced and continued to see the invasion of privacy as an important issue left unanswered.

Perhaps Pandey means to call the judges Luddites as well? A Luddite, for those unaware of the term, is a person who is opposed to technological developments. Dr. Pandey calling those who oppose Aadhaar Luddites betrays knowledge of the meaning of the term, because the technological criticism of Aadhaar has been actually backed by technologically sound arguments and evidence. In contrast, the bombast of the "Aadhaar mafia" as the proponents of Aadhaar are increasingly being referred to, due to ongoing unethical practices, are yet to present any factual rebuttal.

It is worthwhile to take note of some of the Luddites, as Dr Pandey would prefer to call them, who have been critical of Aadhaar. Justice K.S. Puttaswamy, retired judge of the Karnataka High Court and the original petitioner in the landmark ‘privacy case’ is one.

It is an irony that while critics of Aadhaar seem to have impeccable technological credentials while the UIDAI chief, who has the gumption to call these critics Luddites, himself doesn’t seem to understand the difference between private information and secret keys despite repeated explanations

Vicram Crishna, one of the two Indians to help develop software to enable Stephen Hawkins to ‘talk’through his wheelchair, J.T. D’Souza, biometrics expert, Troy Hunt, a web security professional and regional director for Microsoft in Australia, French cyber security researcher Baptiste Robert who tweets as Elliot Alderson and Anupam Saraph, a respected inventor and advisor on governance, informatics and strategic planning are also among those who have publicly expressed their concern about Aadhaar.

Alderson in fact has compared unfavourably Aadhaar’s approach to security as a ‘school level project’. Mozilla, the organisation behind the Firefox browser, has come out publicly in criticism of Aadhaar. And in case more critics are to be named, one can cite the names of legal scholar Shamnad Basheer, Linux consultant Anivar Arvind and Samir Kelekar, who has a PhD in computer networking and holds three patents related to mobile security.

It is an irony that while critics of Aadhaar seem to have impeccable technological credentials while the UIDAI chief, who has the gumption to call these critics Luddites, himself doesn’t seem to understand the difference between private information and secret keys despite repeated explanations.

For his benefit, let me repeat the explanation. When you use a key to control access or authorisation, that key must be secret and not merely private. Just like guessing where you were on Saturday night or knowing the name of the street your home is on should not allow people to create a bank account in your name, lifting fingerprints off your glass of water shouldn't allow them to create a bank account and launder money in your name either.

A secret key must be one that is known only to the person who is the rightful owner of that access. In the event of a breach, it must be readily revoked and replaced. It must be unique. Just like you don't use the same password for your Twitter and netbanking, you should not use the same fingerprints for your PDS and money transfers either.

This is not very difficult to understand. If Dr. Pandey is not able to understand it with so many explanations provided repeatedly over years, perhaps he should undertake correcting the deficiencies first before holding a technology related job.
Till date there hasn't been a shred of factual explanation for why the criticism of Aadhaar is incorrect, while there have been various face saving measures because the UIDAI has no answers for valid criticism. Like the farce of "Virtual ID" to protect privacy after Aadhaar data has already been proliferated with little caution. If he has any factual explanation to show how Aadhaar does not violate privacy, he should not have kept it a secret from the Supreme Court.

While he is at it, Dr. Pandey should also name one private corporation that would pay the kind of money Aadhaar has cost the country for the quality of work on display. One corporation that deals with sensitive identity information or access to financial transactions that would be willing to risk access being protected by something as flimsy, as unrevokable, easily leaked, private information.

When public funds are used to subvert public interest, criticism is inevitable. Calling critics names cannot stop it.

Sorry, sir. "Fikar not, all is well" does not quite answer the mounting criticism.

Click here to subscribe to National Herald on WhatsApp & Facebook

Thursday, May 10, 2018

13497 - Elliot Alderson: Saying Aadhaar Is Un-Hackable Does Not Make It So - Mid Day

May 09, 2018, 07:08 IST | Gaurav Sarkar

In another exclusive interview with mid-day, French ethical hacker Elliot Alderson talks about how things have changed since he revealed his identity and how flaws in the Aadhaar system have remained the same

                                Robert Baptiste

Elliot Alderson, the French ethical hacker who exposed flaws in the Aadhaar application has finally come out of the woodwork and revealed his true identity. He is Robert Baptiste, 28, a resident of Toulouse in France, who works as an app developer. Speaking to mid-day once again, Baptiste explains how simply stating the Aadhaar system cannot be hacked does not make it un-hackable and reveals how his efforts to reach out to Indian authorities regarding the flaws in the Aadhaar system have been in vain.

Baptiste revealed his identity a few weeks ago on Twitter, and even put up a photo of himself as the display picture for a brief time. He also appeared in an interview on a French news channel.


Nothing has changed
Has anything changed since? "Things have not really changed," said Baptiste, adding, "I declined all interviews after the appearance on French TV, and worked on non-India related topics. There are some people who recognize me at local conferences but abroad I'm mostly still anonymous." And how did people react to his picture?: "As far as I saw, reactions were quite good. People were curious to see a real picture of me."

Regarding his work on the flaws in the Aadhaar system, Baptiste maintains his stance about the system, with all its current loopholes, being as dangerous as ever. "In general, the issue is to make links in your digital life. By linking everything with everything, you will give a lot of information to the people who handle the data," he says.

But what about prominent UIDAI faces who have been claiming the system cannot be hacked? "There is no un-hackable system. End of story. Saying that Aadhaar is un-hackable does not make it un-hackable," says Baptiste, further pointing out, "Authorities are really playing a dangerous game. They need to fix the flaws exposed by whistleblowers as soon as possible."

Going on a more serious note, Baptiste states the 'state of security in the Indian cyberspace is quite bad.' "Every time I find something, I try to reach out to the concerned authorities. I contact them a lot, but they keep on declining," he says. While he continues to seek answers from the Indian government, he has been receiving a barrage of almost daily threats. But he's unperturbed, "I receive a lot of threats...I don't keep a count of them. In general, this is nothing serious, mostly just bored kiddos. It (the threats) does not affect me."


Half-marathon awaits
Baptiste is not all about exposes and ethical hacking. When he's not doing any of those, he is busy building apps and services, running and being with his family. "I try to be a good father and a good husband. I run a lot as well. Last year, I ran a marathon and I will run a half-marathon at the end of the month."

Monday, May 7, 2018

13469 - How long can its captain – UIDAI – continue to deny the Aadhaar leaks? - News Click


Newsclick Report 04 May 2018


A few days back, Asia Times and Medium, a popular website reported on security holes in the Aadhaar system. Saikat Datta wrote that a number of people have warned the UID Authority of this hole, without getting any response. Today, the French security expert, who goes by the twitter handle Elliot Alderson @fs0c131y and had earlier exposed a number of security breaches in the Aadhaar and government websites, has tweeted the details of a YouTube video that shows a software that can be used to edit the personal data of anybody enrolled in the Aadhaar system; that too without any security checks! And to add insult to the injury – for UIDAI – the person who posted the video is asking those who liked his video for contributions to his PayTM account.



Is the video fake? If it is, we can heave a sigh of relief. The problem is that very similar complaints have been made by various people to UIDAI without any response, indicating that this software is available for as little as Rs. 500. Anand Venkatanarayanan, in his Medium piece , has also explained why a software – called ECMP (Aadhaar Enrolment Client Multiplatform) software – that resides in the e-Kendra computers, can be hacked more easily. And if it is hacked, it will allow any change in the personal data of the person enrolled in the Aadhaar database. This means the mapping between the biometric and the personal data can be changed.

UIDAI’s contention is that the biometric database cannot be hacked and remains behind secure walls (13 feet high according to the Attorney General). The problem is not that the ridges and whorls of our fingers are safely stored, but whether the name and other details, attached to the fingerprints, are truly mine. If they are not secure and can be changed by buying a Rs 500 software, it means identity theft can occur on a mass scale. And more service providers are added to the Aadhaar system, more potential of holes for such identity thefts. This is the central risk of the Aadhaar system. And our nightmare.

We have been warning the government in our columns and videos, why the Aadhaar system is a poor one and will not lead to any foolproof identity verification system. If biometrics are used, poor connectivity, lack of electricity, apart from at least 10% of biometrics like fingerprints not being verifiable, will defeat the system. If biometrics are dispensed with, the Aadhaar ID proof is as good as self-certification. Why then, are tens of thousands of crores being spent on the system?

The logic of the system lies elsewhere. Yes, Aadhaar system leaks like a sieve. It is capable of being bypassed in various ways. Yes, people who are legitimate beneficiaries of various systems are being denied their dues or rations, as the biometric system does not work properly.

So what is the purpose of Aadhaar? For the government, it provides a method of collecting a huge amount of information of the citizens: religion, caste, geotagging of their houses, collating it with their income and expenditures, etc. This is a surveillance tool that can be used against individuals and communities. For a government that is against a particular section, it can be used to bypass from development in certain areas, where a particular community may be staying. For big Indian capitalists, such as Ambanis, it provides the tool of big data at government expense. Once such big data is available, the capitalists can tap into it in various ways. This is why, from a Nilekani to an Ambani, all of them have lined up behind Aadhaar.

Unfortunately for both the government and big capitalists, the ecosystem of Aadhaar, as engineered and deployed, is so poor that it is likely to fail. Sooner rather than later. Even if the Supreme Court does not strike it down on our privacy violations.

The Aadhaar system is increasingly looking like a ship with a large number  of holes. How long can its captain – UIDAI – continue to deny these leaks? And how long will we pump in good money after the bad?


Monday, April 2, 2018

13168 - How safe is your Aadhaar data? - DECCAN CHRONICLE.

Published
Apr 1, 2018, 6:27 am IST
Updated
Apr 1, 2018, 6:27 am IST


Fingerprints should never be saved on local computers, says cyber expert.

Prasanna

Chennai :The state governments vested with the role of collecting personal details from public for Aadhaar purpose had failed to understand the seriousness of data leak and most of the outsourced portals and websites that deal with Aadhaar, lack adequate cyber security measures, making Aadhaar data vulnerable for the data breach, opines J. Prasanna, cyber security expert, cyber security and foundation Pte Ltd. In an interview with DC, Prasanna explains that the breach is not in the Unique Identification Authority of India (UIDAI), but the state governments, which execute the project had messed it up.

Elliot Alderson kicked up a storm across the country when he leaked details of close to 20,000 Aadhaar cards on the Internet and shared samples of fingerprint data on his handle. How can the state government be held responsible for this?

On an Aadhaar system where you can do fingerprint authentication, the print should not be saved on the local computer, but directly transmitted. Digital fingerprint would normally be 8 bit to 128 bit digital signature. So, when you put a fingerprint, it converts into a string (it will be 8 bit or 128 bit), which is transmitted at the backend and the hashes of the two strings are compared. The fingerprint is never sent to the back end system. That is the normal security process. What the guys collecting have been doing is that, they are actually storing the fingerprint themselves. In a credit card system, every payment gateway does not store credit card number. Same way they should not store fingerprint locally. They should directly transmit it and authenticate it with Aadhaar system.

Can you give an example about the involvement of third party websites of the state government, which is eventually messing up the system?
In every Aadhaar, there is be a string at the bottom saying       "Mera Aadhar Mera Pehchaan". Do a google search for this string with the file type PDF. You will get hundreds of results in government sites and various forums. Some of them have been recently taken off after leaks from Elliot.  Yet, few government sites still have this broken authentication, where they upload all these Aadhaar card insights without securing the directory. That means you go and visit the URL, download the files to get access to actual Aadhaar cards. Ofcourse, the biometric is not there. But, Aadhaar is enough to do crazy stuff. One can reprint another Aadhaar card, change the picture and appear anywhere.

How is Tamil Nadu in terms of cyber security of Aadhar?
In Tamil Nadu, still there has not been much breach, which has been reported. It was reported mainly in Andhra and Maharashtra. But, the government must take precautionary measures. Currently they are only focusing on the benefits of Aadhaar and not cyber security where they are falling short.

What needs to be done?
UIDAI should start with using the web to find data breaches on third party websites. Identify and go behind all the third party service providers and state governments to fix vulnerabilities on cyber security front. Also, any portal that works with UIDAI should be subjected to cyber security vulnerability assessment to find the vulnerability before they can actually allow them to connect to their system. Stringent laws should be applied even on governments, which are not taking personal ID or Aadhaar act more seriously.

For this, do we have enough cyber security personnel?
No. Most of them claim to be cyber security personnel, but there is not enough skill for the job. The government must start recruiting white hat hackers who can actually work with security team or application development team to give them insights on how to build security.

Thursday, March 29, 2018

13134 - Who is 'ethical hacker' Elliot Alderson? Aadhaar whistleblower says he's 'not Indian' - Money Control

Mar 28, 2018 10:31 AM IST | Source: Moneycontrol.com


The so-called ethical hacker started the revelation as a “game”, with the intention of keeping the government agency UIDAI on its toes.
Moneycontrol News


A Twitter user known as Elliot Alderson, who kicked up a storm across the country when he leaked details of close to 20,000 Aadhaar cards on the internet a few weeks ago, has now claimed that he is "not Indian".

The so called ethical hacker started the revelation as a “game”, with the intention of keeping the government agency UIDAI on its toes. But he did not just stop there.

Alderson, as he is known on Twitter, has now jumped in the midst of a recent data theft scandal by “exposing” loopholes in mobile applications of political parties, including the Bharatiya Janata Party (BJP) and the Congress.

Here's a look at who Elliot Alderson really is and why he is in the news.


Elliot Alderson is not Indian

Who is Elliot Alderson?
Elliot Alderson is the Twitter username of a French security researcher Baptiste Robert, who is a network and telecommunications engineer by profession, according to a report by NewsBytes.

The 28-year-old cybersecurity expert is said to be a one-man army, with no team assisting him.

How Alderson started the Aadhaar fiasco
On March 10, the French researcher posted on his handle that he intended to play a game that night. The game was about how many Aadhaar cards he could find in a span of three hours.

I will play a game tonight: How many #Aadhaar card I can found in 3 hours?
Note: All the cards must be available publicly

The game ended after Alderson had posted details of 20,142 Aadhaar cards online.

This was followed by another low blow when on March 13, Alderson posted a walkthrough to bypass the password protection feature in the official Aadhaar Android application in less than a minute.

He iterated that it was the newest version of the app, and that the attacker need not even have a rooted phone to mount the attack.


How to bypass the password protection of the official #Aadhaar #android #app in 1 minute. 

For this attack, the attacker need a physical access to the phone, rooted phone is not needed and yes this is the latest version of the app.
cc @uidai @ceo_uidai


Shift to data security loopholes in mobile apps of BJP and Congress
On March 23, Alderson posted: “I checked the NaMo app and this is not good”. He followed by saying that PM Narendra Modi’s NaMo app shares personal data of users with third parties.


When you create a profile in the official @narendramodi #Android app, all your device info (OS, network type, Carrier …) and personal data (email, photo, gender, name, …) are send without your consent to a third-party domain called 

.

The researcher did not limit himself to just the NaMo app and moved to Congress’ mobile app next. “Of course, I will check the With INC #android app too” read another of his tweets. At the end of the exercise, he shared the loopholes he found on the internet.



When you apply for membership in the official @INCIndia #android #app, your personal data are send encoded through a HTTP request to 

.

Does Alderson want to make money out the whole endeavour?
It doesn't seem that way. In one of his tweets, Alderson posted the screenshot of an e-mail seeking to purchase the details of the Aadhaar cards from him, and wrote “No need to send me this kind of mail. The answer is a big NO” along with it.
In another tweet, he reiterated that he was neither against, nor in favour of Aadhaar and thinks that a project of this size deserves maximum security.





No need to send me this kind of mail. The answer is a big NO

So, why is he doing what he is doing?
From the series of tweets, it seems that the researcher wants to help the organizations in fixing the vulnerability of the data security system.
His tweet reads: “If it is really a reaction to my tweets, this is really a bad signal. Instead of making disinformation @UIDAI, please discuss with me. Your threats are useless and I will continue my work. So please stop denying and let’s fix things together.”
But why does he want to help? Is it to gain fame? Possible. But nothing can be said clearly unless the man himself clarifies.

Tuesday, March 27, 2018

13111 - ModiApp Leaks - The Lid Finally Lifts! No place to hide

The Lid Finally Lifts! No place to hide: After Indian Express, BBC and NDTV Report on NaMo App Sharing Personal Data, Collected also through Coercion, with (or Selling to?) a Third Party in the US without Consent of the Persons Concerned


I. <<*Indian PM Narendra Modi's official mobile application has been criticised for sending personal user data to a third party without their consent.*
A security researcher had tweeted that the app was sending personal user data to a third-party domain that was traced to a US company.>>

(Excerpted from sl. no. II. below.)

II. <app of Prime Minister Narendra Modi,
downloaded over five million times on Android alone, sent user data to a US-based company without consent, security researchers have found in claims that were verified by NDTV. Allegations against the Narendra Modi app, which have sparked a furore on social media and biting criticism from Congress President Rahul Gandhi, come at a time of heightened sensitivity around the alleged misuse of personal data amid the unfolding Facebook-Cambridge Analytica controversy.
...
Alderson, who initially pointed out that the application, popularly known as NaMo app in India, was sharing data with a third party without the consent of users, earlier on Sunday posted a new tweet saying the app had "quietly" updated its privacy policy after his previous tweets.

NDTV checked the claims, consulting experts and using a popular tool called Burp Suite. The findings showed that as a user kept entering personal information such as name, email address, gender and city, the data was being shared with the website in.wzrkt.com.>>

(Excerpted from sl. no. I. below.)

III. <<***Students enrolled in the National Cadet Corps (NCC) programme in the state are being asked to install the official app of Narendra Modi on their phones*** [emphasis added] ahead of a planned interaction with the prime minister in March.

Schools and colleges, which are affiliated with the programme, started informing the students this week after receiving a directive from Mumbai-based ‘1 Maharashtra Naval Unit NCC’.
The letter addressed to principals and associate NCC officers, who manage the cadets’ training, reads: “…***Prime Minister Shri Narendra Modi has desired a direct interaction with maximum cadets of NCC*** emphasis added]. This is feasible by downloading ‘Narendra Modi App’ in the cell phones of the cadets. Mid-March has been fixed for inviting the questions, queries and suggestions from the cadets via ‘Modi App’ directly to the PM (sic).”

The missive, sent on February 26, ***asks schools and colleges to share, by Wednesday, a list of all NCC cadets, their mobile numbers and email addresses. In case, the cadets don’t have a phone, their parents’ numbers should be mentioned*** [emphasis added]. The nominal roll, as the list is called, will also include a “remarks column”.
“This matter should be treated as very urgent,” the letter states.>>


IV. <the privacy policy on PM Narendra Modi’s website has quietly been changed to accommodate for this lapse.
A screenshot of the present policy can be seen below.
...
Till a day before the exposé, the privacy policy on the website read as, “Your personal information and contact details shall remain confidential and shall not be used for any purpose other than our communication with you. The information shall not be provided to third parties in any manner whatsoever without your consent.”
A screenshot of the same can be seen below.>>

***An excellent dissection of the Operation Cover-up***.)]

I/II.

Narendra Modi App Sends User Data To US Firm. Congress App Too, Says BJP
The privacy policy of the Narendra Modi app was updated after criticism mounted on social media over the unauthorised use of user data.

All India | Written by Sukirti Dwivedi

Updated: March 26, 2018 12:33 IST
  
Narendra Modi App Sends User Data To US Firm. Congress App Too, Says BJP
Click to Play

The Narendra Modi app is promoted by the BJP as a one-stop channel for government achievements.

NEW DELHI:

HIGHLIGHTS
Security researcher said app was sharing user data without consent
NDTV verifies claim, finds data being sent to servers run by US firm
Privacy policy of app updated, BJP says Congress app shares data too

 The official mobile app of Prime Minister Narendra Modi, downloaded over five million times on Android alone, sent user data to a US-based company without consent, security researchers have found in claims that were verified by NDTV. Allegations against the Narendra Modi app, which have sparked a furore on social media and biting criticism from Congress President Rahul Gandhi, come at a time of heightened sensitivity around the alleged misuse of personal data amid the unfolding Facebook-Cambridge Analytica controversy.

The ruling BJP has denied the allegations and said the data was being used only for analytics to offer all users the "most contextual content". It also hit out at the Congress, saying the opposition party's app shared data with third parties without consent.

It was a security researcher, who has previously highlighted vulnerabilities in India's national identity card project Aadhaar and who tweets under the pseudonym Elliot Alderson, who first posted a series of messages on Twitter on Saturday stating the Narendra Modi app was sending personal user data to a third-party domain that was traced to an American company.

Alderson, who initially pointed out that the application, popularly known as NaMo app in India, was sharing data with a third party without the consent of users, earlier on Sunday posted a new tweet saying the app had "quietly" updated its privacy policy after his previous tweets.

NDTV checked the claims, consulting experts and using a popular tool called Burp Suite. The findings showed that as a user kept entering personal information such as name, email address, gender and city, the data was being shared with the website in.wzrkt.com.

narendra modi app data
The email address "hello@world.com" entered during registration was sent to in.wzrkt.com

During the entire process of registration the user is never informed or asked permission for sending data to a third party - a procedure which is usually followed by most apps.

NDTV found that the domain in.wzrkt.com belonged to a company called WizRocket Inc which is registered in California and the data is being sent to a server in Mumbai. WizRocket is a data analytics platform developed by a US-based company called CleverTap.

narendra modi app us company
The Narendra Modi app shares user with a server registered to WizRocket Inc. in California.

CleverTap's website says it is as a mobile marketing platform that "visually builds and delivers omnichannel campaigns based on user behavior, location and lifecycle stage". The company was founded in 2013 by three Indians and has offices in several cities in USA and Indian offices are in Mumbai, New Delhi and Bengaluru.

The link, earlier pointed out by Alderson and fact-checking website AltNews, sponsored an attack by Rahul Gandhi who tweeted, "Hi! My name is Narendra Modi. I am India's Prime Minister. When you sign up for my official App, I give all your data to my friends in American companies. Ps. Thanks mainstream media, you're doing a great job of burying this critical story, as always."

Stung by mounting criticism on social media, the BJP admitted that it was sharing information but that this was par for the course. The BJP's official Twitter handle tweeted, "Contrary to Rahul's lies , fact is that data is being used for only analytics using third party service, similar to Google Analytics. Analytics on the user data is done for offering the most contextual content."

Amit Malviya, the chief of BJP's IT operations, also attacked Rahul Gandhi and Congress, alleging similar privacy and consent conflicts.
10h

Amit Malviya
@malviyamit
Hi! My name is Rahul Gandhi. I am the President of India’s oldest political party. When you sign up for our official App, I give all your data to my friends in Singapore. pic.twitter.com/ceCTkod17D


Amit Malviya
@malviyamit
Full marks to @INCIndia for stating upfront that they'll give your data to **practically anyone** - undisclosed vendors, unknown volunteers, even 'groups with similar causes'. In theft of all forms, Congress has never been discreet! pic.twitter.com/FCSIv6nPMn

8:13 AM - Mar 26, 2018
View image on Twitter
869
747 people are talking about this
Twitter Ads info and privacy
The Congress, however, countered the claim.

Divya Spandana/Ramya
@divyaspandana
We don’t collect any personal data through the INC app. We discontinued it a long time ago. It was being used only for social media updates. 
We collect data for membership and this is through our website http://www.INC.in , this is encrypted. https://twitter.com/pranesh/status/978092007250788352

8:20 AM - Mar 26, 2018
991
625 people are talking about this
Twitter Ads info and privacy

Experts say that data shared with political parties is prone to misuse. Srinivas Kodali, a cybersecurity expert said, "It can be misused by sharing with private companies like Cambridge Analytica which could build voter profiles of volunteers who are active through the Narendra Modi application."

The BJP's response, however, did not appear to address the crucial issue of consent. The privacy policy for the NaMo app, posted on the website narendramodi.in, until yesterday, read, "Your personal information and contact details shall remain confidential and shall not be used for any purpose other than our communication with you. The information shall not be provided to third parties in any manner whatsoever without your consent."

The backlash was also compounded by criticism over 13 lakh cadets of India's National Cadet Corps being asked to install the app and share phone numbers and email addresses with the Prime Minister's office.

As the controversy swelled, that policy was changed to say, "The following information may be processed by third party services to offer you a better experience as stated above: name, email, mobile phone number, device information, location and network carrier."

NDTV has contacted both the BJP IT cell as well as CleverTap for their responses and is yet to receive them. The story shall be updated once a response is received.

II.

India PM Modi app sparks social media furore

5 hours ago

Image copyrightNARENDRA MODI APP

Indian PM Narendra Modi's official mobile application has been criticised for sending personal user data to a third party without their consent.

A security researcher had tweeted that the app was sending personal user data to a third-party domain that was traced to a US company.

Mr Modi's ruling Bharatiya Janata Party (BJP) has denied the allegation.

The party said the data was being used only for analytics to offer all users the "most contextual content".

Narendra Modi app is 'like Tinder for good governance'
Narendra Modi app: Humour and praise on Twitter

The researcher, who tweets under the pseudonym Elliot Alderson, posted a series of tweets on Saturday stating Mr Modi's app was sending personal user data to a third party.

Skip Twitter post by @fs0c131y
View image on Twitter

Elliot Alderson
@fs0c131y
When you create a profile in the official @narendramodi #Android app, all your device info (OS, network type, Carrier …) and personal data (email, photo, gender, name, …) are send without your consent to a third-party domain called http://in.wzrkt.com .

1:04 AM - Mar 24, 2018
5,323
6,572 people are talking about this
Twitter Ads info and privacy
Report
End of Twitter post by @fs0c131y
Skip Twitter post 2 by @fs0c131y

View image on Twitter

Elliot Alderson
@fs0c131y
Replying to @fs0c131y
After a quick search, this domain belongs to an American company called @CleverTap. According to their description, “#CleverTap is the next generation app engagement platform. It enables marketers to identify, engage and retain users and provides developers"

1:04 AM - Mar 24, 2018
560
619 people are talking about this
Twitter Ads info and privacy
Report
End of Twitter post 2 by @fs0c131y
Skip Twitter post 3 by @fs0c131y

Elliot Alderson
@fs0c131y
Replying to @fs0c131y
.@narendramodi, I know privacy is not your thing but any thoughts about sharing the personal data of your users without their consent to a third-party company?

1:04 AM - Mar 24, 2018
2,045
1,589 people are talking about this
Twitter Ads info and privacy
Report
End of Twitter post 3 by @fs0c131y

Rahul Gandhi, the chief of the the main opposition Congress party, took to Twitter on Sunday to criticise Mr Modi.

Skip Twitter post by @RahulGandhi

Rahul Gandhi
@RahulGandhi
Hi! My name is Narendra Modi. I am India's Prime Minister. When you sign up for my official App, I give all your data to my friends in American companies. 

Ps. Thanks mainstream media, you're doing a great job of burying this critical story, as always.http://www.jantakareporter.com/india/data-theft-allegations-reaches-pm-modis-doorstep-french-vigilante-hackers-stunning-revelation/177957/

10:54 AM - Mar 25, 2018

Data theft allegations reaches PM Modi’s doorstep, French vigilante hacker’s stunning revelation

A French vigilante hacker has made a stunning revelation accusing Prime Minister Narendra Modi of having compromised the personal data of millions of Indians, who had downloaded his personal mobile...

22.5K
15.5K people are talking about this
Twitter Ads info and privacy
Report
End of Twitter post by @RahulGandhi

The BJP responded swiftly, saying Mr Gandhi was trying to divert attention.

Last week India's law and IT minister Ravi Shankar Prasad said there were "numerous reports" of the Congress party's connections with controversial data analytics firm Cambridge Analytica.

He asked Mr Gandhi to "explain" the company's role in his social media outreach.

The opposition party has denied the charges.

Cambridge Analytica is embroiled in a storm over claims it exploited the data of millions of Facebook users.

Skip Twitter post by @BJP4India

BJP
@BJP4India
Rahul Gandhi is in sublime form these days. After MRI & NCC, today he exposes his great knowledge about technology. He is so rattled by the Cambridge Analyitca expose that he daily tries to divert attention from it, yesterday it was the judiciary and today it is Namo App.

1:03 PM - Mar 25, 2018
2,302
1,199 people are talking about this
Twitter Ads info and privacy
Report
End of Twitter post by @BJP4India

The party said the data from Mr Modi's app was being used for analytics:

Skip Twitter post 2 by @BJP4India

BJP
@BJP4India
This ensures that a user gets the best experience by showing content in his language & interests. A person who looks up agri-related info will get agri related content easily. A person from TN will get updates in Tamil and get an update about an important initiative about TN.

1:07 PM - Mar 25, 2018
1,442
656 people are talking about this
Twitter Ads info and privacy
Report
End of Twitter post 2 by @BJP4India

The security researcher later posted a new tweet on Sunday saying Mr Modi's app had been "quietly" updated its privacy policy.

Skip Twitter post 4 by @fs0c131y

Elliot Alderson
@fs0c131y
After the NaMo #android app exposé yesterday, the privacy policy of @narendramodi has been change quietly. The cached version is accessible here http://web.archive.org/web/20180325053015/http://webcache.googleusercontent.com/search?q=cache:37wMakar_CAJ:www.narendramodi.in/privacy-policy+&cd=1&hl=en&ct=clnk&gl=in

3:29 PM - Mar 25, 2018
901
722 people are talking about this
Twitter Ads info and privacy
Report
End of Twitter post 4 by @fs0c131y

Mr Modi launched his official app in 2015, adding another platform to his massive social media presence.


He is among the five most popular politicians on Twitter with 41.4 million followers.

Monday, March 26, 2018

13103 - Modi app leaks data? More privacy scare after Cambridge Analytica, Aadhaar - Business Standard



French researcher Elliot Alderson has alleged that information of those who download the Narendra Modi app is being provided to a third-party US company, Clever Tap, without users' consent
BS Web Team  |  New Delhi 

Last Updated at March 25, 2018 14:34 IST

File photo of Congress President Rahul Gandhi speaking during the 84th Plenary Session of Indian National Congress
After the data leak scandal involving Facebook and Cambridge Analytica, and the many reports of Aadhaar data of Indian being at a risk of compromise, the Narendra Modi app seems to be in the eye of a storm, and a new flashpoint in the war between the Congress and the Bhartiya Janata Party (BJP).

Rahul Gandhi on Sunday alleged that Prime Minister Narendra Modi's app was leaking data to US companies. In a post on Twitter, Gandhi claimed that the Prime Minister was allowing ‘American companies’ to take away the data of users who signed up for his application.

“Hi! My name is Narendra Modi. I am India’s Prime Minister. When you sign up for my official App, I give all your data to my friends in American companies,” Rahul Gandhi tweeted.

To this, the BJP countered the charge by saying that Gandhi and his party had zero knowledge of technology.

The development comes close on the heels of the Cambridge Analytica scandal causing a political slugfest between the BJP and Congress. Both the parties accused each other of having links with the data company under the scanner for stealing data from Facebook and influencing elections.

BJP alleged that Cambridge Analytica was involved in Rahul Gandhi's social media campaigns, especially in last year's Gujarat Assembly election. Congress on its part claimed that BJP availed of the company's services in various state Assembly elections -- Bihar, Maharashtra, Haryana, Jharkhand, and Delhi -- besides for its 'Mission 272 plus' in the 2014 general elections.

Apart from these, the two parties also crossed swords several times over the Aadhaar data security.

In January, when the nodal agency implementing the Aadhaar project, Unique Identification Authority of India (UIDAI) filed an FIR against the The Tribune and its reporter Rachna Khaira for an article reportedly exposing the ease with which anybody would steal Aadhaar-related data, Congress had accused the NDA government of destroying the Aadhaar programme and called the FIR "unfortunate".

Here are the top developments in the latest data breach row allegedly involving the Narendra Modi app:

1. Rahul claims Modi's app steals data: Rahul took a jibe at PM Modi on Twitter on Sunday, alleging that his Narendra Modi app was leaking data to US companies.


Hi! My name is Narendra Modi. I am India's Prime Minister. When you sign up for my official App, I give all your data to my friends in American companies.

Ps. Thanks mainstream media, you're doing a great job of burying this critical story, as always.


2. BJP counters Rahul's claim: BJP said that Rahul Gandhi and his party had no knowledge about technology. Here is what BJP said in the tweet.


Rahul Gandhi truly shows why he and his party have zero knowledge of technology. All they can do is scare the masses about technology while they continue to steal data using his ‘Brahmastra’ of Cambridge Analytica.

3. Union Minister K J Alphons responds: In an apparent response to Rahul Gandhi, Alphons said “I filled up to 10 pages for a US visa form.

We have absolutely no problem giving our fingerprints and being naked before the white man at all. When your own government asks for your name and address, there is a massive revolution saying it's intrusion of privacy.”

4. 'Narendra Modi app sending user info to US company': French researcher Elliot Alderson has alleged that information of those who have downloaded the app was being provided to third party US company Clever Tap without users’ consent.

In a series of tweet, Anderson had claimed that user's device information, as well as personal data, was sent to a third-party domain called in.wzrkt.com. when a person creates profile in the app.

5. Latest row after govt issued notice to Cambridge Analytica: The government on Friday issued a notice to UK-based Cambridge Analytica, asking it to give a list of clients and the source of data it had collected.

The IT Ministry has asked the firm to respond by March 31 on six questions, including how the company had collected user data, whether consent was taken from the individuals, and how the data was used.

6. Cambridge Analytica behind Rahul Gandhi's 'Gabbar Singh Tax' jibe, claimed BJP: Stepped up its attack on Rahul Gandhi and the Congress, BJP had said that Cambridge Analytica's "footprints" were visible in the Opposition party's campaign in Gujarat. Further, the BJP suggested that Cambridge Analytica had a role in the Congress chief's use of the term "Gabbar Singh Tax".

Union minister Ravi Shankar Prasad also suggested that the firm had a role in Gandhi's social media campaign and the Congress' "poisonous" electioneering in Gujarat.

7. Take action instead of holding press conferences, Congress tells BJP: Senior Congress leader Abhishek Manu Singhvi adviced the BJP that instead of holding press conferences, the ruling party should take action over its allegation that the Opposition party is indulging in data theft to influence elections in India.

Alleging that the BJP has dished out fake news for long, Singhvi said that the spread of false information has been its forte.

"BJP is the party in power. Rather than holding press conferences, why doesn't it take action?" he said about Union Law and Information Technology Minister Ravi Shankar Prasad's charge that the Opposition party was using data manipulation and theft to woo voters.

8. Congress called Ravi Shankar Prasad 'lie minister': Equating Ravi Shankar Prasad to Hitler's Goebbels, Congress spokesperson Randeep Singh Surjewala said that "now a new fake agenda" is being used to stop the proceedings in Parliament. Surjewala added that instead of law minister, Prasad should be called a "lie minister".

"One who stole data (Facebook and Mark Zuckerberg) is also Prime Minister Narendra Modi's friend. Still they are shouting so much. Modiji and Prasad must reply to a few questions," he added.

9. The battle over Aadhaar: Aadhaar has been another flashpoint between the two parties in their battle over data theft and privacy. Congress has time and again accused the NDA government of destroying the Aadhaar programme. In January, Congress had condemned action against the reporter for an article which reportedly exposed the ease with which anybody can steal Aadhaar-related data.

"Instead of helping the poor, it has become a tool of spying and surveillance," Congress spokesperson Shobha Oza had said.

In reply to Motion of Thanks to the President's address on February 7, prime minister Modi had attacked the Congress party over it's questions on the implementation of Aadhaar, saying that Congress was crying foul because we made Aadhaar scheme better.

“I remember clearly, when we won elections, you (the Congress) said Modi will finish Aadhaar because it is our scheme… (But) When Modi furthered it more scientifically and found new ways to implement it, now after it has been implemented and started benefiting the poor, you question its implementation,” the Prime Minister had said.


First Published: Sun, March 25 2018. 14:34 IST

Wednesday, March 21, 2018

13042 - Know the man behind Elliot Alderson, who exposed flaws in Aadhaar, OnePlus & Paytm - Hindustan Times

Inspired by Mr. Robot’ Elliot Alderson, Robert Baptiste has been exposing security flaw in popular applications, smartphones and other online services
TECH Updated: Mar 20, 2018 13:28 Ist

Kul Bhushan 
Hindustan Times

A sceengrab of Alderson’s Twitter profile picture.(Elliot Alderson)

Elliot Alderson, a Twitter alias inspired by a character in popular TV series Mr. Robot, has his own cult following on the social media platform. Just like Mr. Robot’s Alderson, he has taken upon himself to expose serious security flaws in several applications, smartphones and other internet services. But he’s primarily known for finding flaws in India’s massive biometric-based programme, Aadhaar.
Earlier this year, Alderson claimed to have found a massive loophole in the Aadhaar’s mobile application on Google that allowed anyone with basic coding knowledge to gain users’ data. The alleged flaw expose gained wide media attention as it came shortly after a Tribune report disclosed that full Aadhaar details was being sold for mere Rs 500 by anonymous sellers.
Knowing the man behind Elliot Alderson
Elliot Alderson’s real name is Robert Baptiste, or at least he tells us so. Robert describes himself as a French developer who develops applications for Android platform and customise AOSP (Android Open Source Project) for smartphone companies. By profession, he’s a network and telecommunications engineer.
When asked about whether he considers himself as a whistleblower, Robert said, “I consider myself as a random guy. I am not special or whatever. As I said multiple times, I encourage people to do the same thing.”
Robert says he follows a “standard process” to find vulnerabilities and doesn’t have a team. But he does get tip off from his followers.
“I have a standard process, nothing fancy. I am working alone. However, a lot of my followers shared what they find because nobody listen to them or they are afraid to be harassed,” he said.



Why Aadhaar?
When asked about why has he a special interest in the Aadhaar programme, he responded, “Aadhaar is interesting by his scale. This is a gigantic project with a lot of security implications.”
“I will not give an opinion on Aadhaar as I don’t think I’am legitimate. However, I think this project deserve the maximum [security],” he said.



Hi #Aadhaar ! Can we talk about the #BenefitsOfAadhaar for the #India population?

I quickly check your #android app on the #playstore and you have some security issues...It's super easy to get the password of the local database for example...

Is it possible to have 100% privacy in modern digital era? “This is complicated, very complicated but you can be close to 100%, yes,” he added.
Read more


  •  
  • How Facebook made its Cambridge Analytica data crisis even worse 




    •  
  • Trump consultants harvested data from 50 million Facebook users during 2016 election campaign: Reports 
  • Alderson’s other work
    Apart from Aadhaar, Alderson has found some security flaws in OnePlus phones in the past. Earlier this year, he pointed out that OnePlus’ clipboard application came with a strange file called “badwords.txt” which was transmitting data to a company called TeddyMobile. The data was being shared without the knowledge. OnePlus later acknowledged the issue and said that the code was just meant for China and was inactive in other markets.

    All these files are used in a obfuscated package which seems to be an #Android library from teddymobile



    TeddyMobile is a Chinese company, they worked with a lot of manufacturers including @oppo.


    Most recently, Alderson and a few other Twitter users pointed out that Paytm was seeking root access to users’ devices. Alderson also got into a brief Twitter tussle with Paytm’s Deepak Abott over the issue. Paytm later removed the root request.



    After this tweet, @Paytm contact me in private. Today, according to them, they remove remotely this root rights request. Do you confirm it?