In 2009, I became extremely concerned with the concept of Unique Identity for various reasons. Connected with many like minded highly educated people who were all concerned.
On 18th May 2010, I started this Blog to capture anything and everything I came across on the topic. This blog with its million hits is a testament to my concerns about loss of privacy and fear of the ID being misused and possible Criminal activities it could lead to.
In 2017 the Supreme Court of India gave its verdict after one of the longest hearings on any issue. I did my bit and appealed to the Supreme Court Judges too through an On Line Petition.
In 2019 the Aadhaar Legislation has been revised and passed by the two houses of the Parliament of India making it Legal. I am no Legal Eagle so my Opinion carries no weight except with people opposed to the very concept.
In 2019, this Blog now just captures on a Daily Basis list of Articles Published on anything to do with Aadhaar as obtained from Daily Google Searches and nothing more. Cannot burn the midnight candle any longer.
"In Matters of Conscience, the Law of Majority has no place"- Mahatma Gandhi
Ram Krishnaswamy
Sydney, Australia.

Aadhaar

The UIDAI has taken two successive governments in India and the entire world for a ride. It identifies nothing. It is not unique. The entire UID data has never been verified and audited. The UID cannot be used for governance, financial databases or anything. It’s use is the biggest threat to national security since independence. – Anupam Saraph 2018

When I opposed Aadhaar in 2010 , I was called a BJP stooge. In 2016 I am still opposing Aadhaar for the same reasons and I am told I am a Congress die hard. No one wants to see why I oppose Aadhaar as it is too difficult. Plus Aadhaar is FREE so why not get one ? Ram Krishnaswamy

First they ignore you, then they laugh at you, then they fight you, then you win.-Mahatma Gandhi

In matters of conscience, the law of the majority has no place.Mahatma Gandhi

“The invasion of privacy is of no consequence because privacy is not a fundamental right and has no meaning under Article 21. The right to privacy is not a guaranteed under the constitution, because privacy is not a fundamental right.” Article 21 of the Indian constitution refers to the right to life and liberty -Attorney General Mukul Rohatgi

“There is merit in the complaints. You are unwittingly allowing snooping, harassment and commercial exploitation. The information about an individual obtained by the UIDAI while issuing an Aadhaar card shall not be used for any other purpose, save as above, except as may be directed by a court for the purpose of criminal investigation.”-A three judge bench headed by Justice J Chelameswar said in an interim order.

Legal scholar Usha Ramanathan describes UID as an inverse of sunshine laws like the Right to Information. While the RTI makes the state transparent to the citizen, the UID does the inverse: it makes the citizen transparent to the state, she says.

Good idea gone bad
I have written earlier that UID/Aadhaar was a poorly designed, unreliable and expensive solution to the really good idea of providing national identification for over a billion Indians. My petition contends that UID in its current form violates the right to privacy of a citizen, guaranteed under Article 21 of the Constitution. This is because sensitive biometric and demographic information of citizens are with enrolment agencies, registrars and sub-registrars who have no legal liability for any misuse of this data. This petition has opened up the larger discussion on privacy rights for Indians. The current Article 21 interpretation by the Supreme Court was done decades ago, before the advent of internet and today’s technology and all the new privacy challenges that have arisen as a consequence.

Rajeev Chandrasekhar, MP Rajya Sabha

“What is Aadhaar? There is enormous confusion. That Aadhaar will identify people who are entitled for subsidy. No. Aadhaar doesn’t determine who is eligible and who isn’t,” Jairam Ramesh

But Aadhaar has been mythologised during the previous government by its creators into some technology super force that will transform governance in a miraculous manner. I even read an article recently that compared Aadhaar to some revolution and quoted a 1930s historian, Will Durant.Rajeev Chandrasekhar, Rajya Sabha MP

“I know you will say that it is not mandatory. But, it is compulsorily mandatorily voluntary,” Jairam Ramesh, Rajya Saba April 2017.

August 24, 2017: The nine-judge Constitution Bench rules that right to privacy is “intrinsic to life and liberty”and is inherently protected under the various fundamental freedoms enshrined under Part III of the Indian Constitution

"Never doubt that a small group of thoughtful, committed citizens can change the World; indeed it's the only thing that ever has"

“Arguing that you don’t care about the right to privacy because you have nothing to hide is no different than saying you don’t care about free speech because you have nothing to say.” -Edward Snowden

In the Supreme Court, Meenakshi Arora, one of the senior counsel in the case, compared it to living under a general, perpetual, nation-wide criminal warrant.

Had never thought of it that way, but living in the Aadhaar universe is like living in a prison. All of us are treated like criminals with barely any rights or recourse and gatekeepers have absolute power on you and your life.

Announcing the launch of the # BreakAadhaarChainscampaign, culminating with events in multiple cities on 12th Jan. This is the last opportunity to make your voice heard before the Supreme Court hearings start on 17th Jan 2018. In collaboration with @no2uidand@rozi_roti.

UIDAI's security seems to be founded on four time tested pillars of security idiocy

1) Denial

2) Issue fiats and point finger

3) Shoot messenger

4) Bury head in sand.

God Save India

Showing posts with label Kiran Jonnalagadda. Show all posts
Showing posts with label Kiran Jonnalagadda. Show all posts

Thursday, May 3, 2018

13427 - UPDATED: Security Sources Confirm Data Loss In Hack On EPFO Aadhaar Seeding Platform - Huffington Post



Security loophole open for "few weeks".

BLOOMBERG VIA GETTY IMAGES

Government sources have confirmed that a vulnerability in a government-run website meant to assist employees link their provident fund accounts with their Aadhaar numbers was targeted by hackers who made off with an unknown amount of sensitive personal data.

The website, the source said, was leaking data for "a few weeks" before it was detected and taken offline. Authorities are still trying to ascertain the nature, and quantity, of the data obtained by the hackers.

The data breach came to light earlier today, when a secret note, sent by Employee Provident Fund Organisation (EPFO)'s Chief Provident Fund Commissioner V.P. Joy, surfaced on Twitter.



EPFO data stolen by hackers exploiting the vulnerabilities prevailing in the website (http://aadhaar.epfoservices.com ) : VP Joy, Central Provident Fund Commissioner to MeitY.
Aadhaar case in SC at the last stage, how will the Govt defend this now ?


The note, marked "Secret" and dated 23 March 2018, was a rare instance of an attack on a vulnerable state data cache becoming public knowledge. The vulnerability was detected in the Aadhaar-seeding platform provided by the Common Services Centre (CSC) E-governance Services Ltd, a special purpose vehicle of MEITY.

EPFO is just one of many government departments that use this platform for Aadhaar-seeding various services. In February this year, the Unique Identification Authority of India (UIDAI) terminated its relationship with CSC, citing corruption and violations in the aadhaar-enrollment centres run by the company.

This security breach is the latest illustration of the vulnerabilities of India's ambitious e-governance push and, security analysts say, highlights the risks of the central government push to seed citizen aadhaar numbers in multiple state-maintained databases.

"It has been intimated that data has been stolen by hackers by exploiting the vulnerabilities prevailing in the website (aadhaar.epfoservices.com) of EPFO," the March 23 letter said, adding that the attack had been first spotted by the Intelligence Bureau.


SCREEN SHOT OF EPFO LETTER
An excerpt of a secret letter dated 23 March 2018 revealing details of a security breach in an Aadhaar-seeding portal maintained by the Ministry of Electronics and Information Technology

The website was since been taken down soon after the letter was sent, and is yet to come back online.
V.P. Joy, the Central Provident Fund Commissioner of the EPFO and author of the note, confirmed the authenticity of the letter in a phone call with HuffPost, but played down its significance.
"I am not aware of any data leak," Joy said. "We received a warning from the IB on March 22, and so I forwarded it to the relevant authorities the next day. This is a routine administrative matter."

A press release issued by his office, this afternoon, echoed Joy's comments, but seemingly contradicted his March 23 note. "No confirmed data leakage has been established or observed so far," the press release stated.

That the breach occurred from a portal seeding Aadhaar numbers with EPFO UAN numbers, suggests that the hackers are likely to have harvested some Aadhaar numbers. Thus far, the EPFO has linked 34.5 million out of a total of 47.1 million active provident fund accounts with Aadhaar according to news reports.But Joy was at pains to clarify that information about EPFO-Aadhaar linked accounts was maintained on a separate server, which was not compromised.

HuffPost has written to Dinesh Tyagi, CEO of the state-run Common Services Centre, and will update this copy with his comments once he replies.

Known Vulnerability
The March 23 2018 refers to two specific vulnerabilities: "Strut vulnerabilities" and "Backdoor Shells."
While "backdoor shells" refer to the possibility of hackers gaining control of a portal's administrator privileges, Struts refers to "Apache Struts", a widely used Java application with an established history of vulnerabilities, the best of known which is the 2017 Equifax data breach which exposed the personal details of 143 American citizens.

In April this year, the Minister of State for Electronics and Information Technology K.J. Alphons, told the Rajya Sabha that the UIDAI had audited Equifax in the aftermath of the data breach.

"It is a known vulnerability," said security researcher Srinivas Kodali. "Had UIDAI audited EPFIO like they audited Equifax, they would have found it."

A similar vulnerability was exploited by French security researcher Robert Baptiste to penetrate the Telangana MNRega website.

On Twitter, where the letter was first posted, security analyst Kiran Jonnalagadda, said it was likely that the vulnerability was spotted by hackers trawling the internet for sites running an insecure version of Struts.


Java Struts vulnerability. Likely caught up in a wide sweep of Struts-powered websites. The Aadhaar angle is incidental, but the leak of Aadhaar-linked data is almost certain. https://twitter.com/arvindgunasekar/status/991540003229454336 …

This story has been updated to reflect information passed on by government sources monitoring the data breach

Sunday, April 1, 2018

13165 - What’s your Aadhaar? - Indian Express

By Ramzauva Chhakchhuak  |  Express News Service  |   Published: 31st March 2018 05:14 AM  |  

BENGALURU: Despite the matter of linking the Aadhaar to one's bank account and mobile connection being in the court for a while now, companies who offer such services insist on the same in clear violation of the laws. 

The Supreme Court judgment on March 13, extending the dates for linking such services indefinitely,  has come as a shot in the arm for those who have been opposing the move right from the beginning.

Many are not taking things lying down and are taking a stand whether in their individual capacity or as part of groups.

Take the case of Eliot Lobo, a city-based freelance writer who went to meet the relationship manager of his bank, a day prior to the March 13 ruling to weigh his options in case Aadhaar was made mandatory to avail such services. So far, Eliot has refused to get an Aadhaar identity for himself. Linking his bank account and mobile connection to Aadhaar was always out of the question for him, he says. 

Had the SC judgment  not been in favour of people like him, Eliot says, "I was considering the possibility of taking out all my money from the bank." He says he was receiving emails from his bank on a daily basis asking him to link his account to Aadhaar. Eliot has an account with a private bank in Pune, which he has not yet moved to Bengaluru yet.



"I asked the manager what the withdrawal restrictions were. He told me that I could move my money through cheques in around two instalments. He understood the predicament of customers like me. In fact, he himself told me that he had not linked his mobile phone to Aadhaar yet," he adds. However, thanks to the judgment, Eliot has put off plans to close his account for the time being.
   
No to ‘arm twisting’
Another Bengaluru resident, C R Sridhar is a lawyer by profession, who has also been badgered by firms to link his bank account to his Aadhaar. He thinks it's "crude arm twisting" on the part of banks and telecom operators to force customers into something that has not been fully cleared by the courts. On the morning of the day the SC gave its judgment on the matter, Sridhar immediately visited his bank in R T Nagar. "I had to be the one to tell the bank the deadline had been extended. They were sending a lot of messages on my phone and frankly, I was fed up.

I went to a senior manager and told him that I was filing a contempt of court proceedings if they did not stop all this," says Sridhar. The bank finally backed off. He further adds that banks should tell customers about the legality of the issue and not mindlessly hound them.

Others like Kiran Jonnalagadda, a techie and a well-known face in the city against the Aadhaar, joined hands with other like-minded individuals to start a website where citizens can write directly to their MPs, respective banks and mobile service providers in case of continuous ‘harassment’ to link Aadhaar. Called Speak For Me, the website was started four months ago and has become a huge hit.

Since it started till now, as many as 30,700 emails have been sent to MPs, 1,500 to banks, 1,600 to various mobile service providers. "I do not have an Aadhar card but like everyone else, I am also being constantly harassed to link it to various services. So instead of just me sending one email, now thousands are sending their concerns. We have also helped parliamentarians frame questions to ask in the hosue and it's bearing fruit," says Jonnalagadda. 


Stay up to date on all the latest Bengaluru news with The New Indian Express App. Download now

Thursday, March 29, 2018

13128 - UIDAI servers or third parties, Aadhaar leaks are dangerous: Experts - Business Standard


Even though the UIDAI has denied these reports, its arguments rest on shaky grounds, according to experts

Mayank Jain  |  New Delhi 
Last Updated at March 27, 2018 00:33 IST

                            Illustration: Binay Sinha

The government has told the Supreme Court that the Aadhaar data “remains safely behind 13-feet high walls” and it will take “the age of the universe” to break one key in the Unique Identification Authority of India’s (UIDAI’s) encryption.

Even if this claim is taken at face value, experts suggest leaks from third-party databases seeded with Aadhaar numbers are equally dangerous and the UIDAI is responsible for the damage.

The most recent case came from a report published online and it said random numbers could provide access to the Aadhaar data, which also includes people’s financial information, from a state-owned company’s database.

Even though the UIDAI has denied these reports, its arguments rest on shaky grounds, according to experts.

“There is no truth in this story as there has been absolutely no breach of the UIDAI’s Aadhaar database. Aadhaar remains safe and secure,” the UIDAI said on Twitter shortly after the story broke on ZDNet.

The authority added even if the report was taken to be true, “it would raise security concerns on the database of that Utility Company and has nothing to do with the security of the UIDAI’s Aadhaar database”.

This has been the authority’s defence in several such cases but those in the know of things say it doesn’t hold water simply because the Aadhaar data is not concentrated in the UIDAI’s complexes anymore and has spread across various databases.
“Publishing this by the state entities is a violation under the Aadhaar Act. Even if you publish your Aadhaar number, it is a violation of the law,” said Pranesh Prakash, policy director at the Centre for Internet and Society.

“Saying that the UIDAI has not been compromised is thoroughly insufficient because for customers, it doesn’t matter if the leak comes from servers operated by the UIDAI or from others holding copies of the UIDAI database.”

Prakash said it should be the authority’s responsibility to help others comply with the law and prevent data leaks. He gave the example of biometric leaks from Gujarat government servers and how criminals used them to forge fingerprints.

The possibility of data leaks was demonstrated when Robert Baptiste, purportedly a French app developer, announced on Twitter how he got access to thousands of scanned Aadhaar card copies through simple Google searches.

In an interview to Business Standard, Baptiste said the major threat was data handling by third parties, which could lead to identity theft.

Even the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016, has provisions that debar making public citizens’ Aadhaar-related information public unless required for certain purposes.

“Whoever intentionally discloses, transmits, copies or otherwise disseminates any identity information collected in the course of enrolment or authentication to any person not authorised under this Act” can be in jail for three years and pay a fine of ~10,000 under the Act.

A lawyer appearing on the petitioners’ side in the ongoing Supreme Court case on the constitutional validity of Aadhaar said only the UIDAI had the powers to file cases against people who published Aadhaar information. Hence everyone else is helpless despite the leaks.

The UIDAI’s argument that Aadhaar information can’t be misused is duplicitous because the regulations under the Aadhaar Act assure individuals that if biometric authentication fails, they should have other means of identifying themselves, says Kiran Jonnalagadda, founder of HasGeek.

“So the regulations guarantee that anyone in possession of stolen identity information will be able to misuse it without biometric authentication,” he said.

Prakash agreed with this. He said demographic authentication, which is an acceptable authentication method under the Aadhaar Act, was prone to misuse as long as Aadhaar numbers remained public.

“Aadhaar is used as just a piece of paper, unlike security features embedded in passports or even permanent account number cards. Thus, demographic authentication merely involves providing Aadhaar numbers and details like addresses, which can be used even for things like getting entry into an airport by just printing a ticket and having a fake Aadhaar,” he said.
Queries sent to the UIDAI were not answered till the time of going to press



First Published: Tue, March 27 2018. 00:31 IST

Monday, January 22, 2018

12715 - The Aadhaar ecosystem leaks too much data - Live Mint


The Aadhaar ecosystem leaks too much data

The ecosystem treats a breach as a simple accident, without regard for consequences to the victims

Last Published: Thu, Jan 18 2018. 12 49 AM IST
Kiran Jonnalagadda



Aadhaar endangers national security and the government needs to act fast. Photo: Priyanka Parashar/Mint

People don’t respond well to dystopian scenarios”, a professor of marketing warned me late last year. The true extent of Aadhaar-linked data leakage is hard to process, so we tend to ignore it. Smaller inconveniences are easier to understand.

Some awareness, however, has now seeped into public consciousness due to an exposé by Rachna Khaira in The Tribune, who showed that access to the entire database could be purchased for as little as Rs500. The response was predictable. First, multiple denials that a breach had even occurred. Second, an FIR against Khaira and The Tribune, combined with allusions of “an orchestrated campaign to malign Aadhaar”. Third, when the repeated assertions of Aadhaar’s safety wore thin, a public dare demanding to know how anyone could be harmed if their private information got leaked.

Section 59 of the Aadhaar Act covers activities that are illegal under the rest of the Act. Many states have sought to collect deeply personal information such as religion and caste in their state resident data hubs (SRDHs), coupled with biometrics, and without the cover of a state law. UIDAI (Unique Identification Authority of India) has enabled this in their enrolment and other software with such innocuous names as “DBT Seeding Data Viewer (DSDV)” and “Rapid Aadhaar Seeding Framework (RASF)”. Andhra Pradesh links everything to Aadhaar, all the way down to minor traffic offences. The police are allowed access to biometrics for identifying criminals and lost children. The sensitivity of such detailed personal information coupled with voter ID during an election should be obvious.

The Aadhaar ecosystem is widespread, extending to former UIDAI members like Nandan Nilekani and think tanks like iSPIRT, private firms like Khosla Labs, venture capital firms and their research vehicles like Omidyar and IDinsight, service providers like Airtel, Jio and Paytm, and the National Payments Corporation of India. UIDAI is a hopelessly ill-equipped steward of the ecosystem, and its ongoing meltdown is apparent to anyone tracking the details. While the ecosystem members may not always agree with each other, what unites them is their desire to keep Aadhaar afloat regardless of the risks, because it lowers their government-imposed “know your customer” (KYC) costs. This is an inversion of democracy, where societal concerns are primary. This Aadhaar ecosystem treats a breach as a simple accident, without regard for consequences to the victims.

In 2014, Nilekani, former chairman of UIDAI, accidentally leaked his own Aadhaar details when he posted a photograph of his Aadhaar card with the number masked out while keeping the accompanying QR code which contained his number, date of birth and residential address. Copies of his information remain available on multiple websites, accessible via a simple Google search. If someone as powerful as Nilekani is unable to make the internet forget his details, what hope does anyone else have?

The Tribune breach required one to know an Aadhaar number to retrieve personal information. It takes a computer mere seconds to produce all 80 billion possible Aadhaar numbers. The one billion currently-valid numbers can be filtered out by using the 130 million already-leaked numbers, and the rest using a number of verification services, including UIDAI’s own—which is technically protected by a “captcha” to prevent such automated attempts, but which is so trivial that amateurs break it to win programming contests, and then share on code repository GitHub.com. One has to be incredibly naïve to believe hostile actors, including foreign powers, haven’t already harvested all data.

A valid Aadhaar number is a key that opens multiple locks. Dialing *99*99# connects you to NPCI’s query service on Aadhaar mapper (QSAM), which cheerfully tells you which bank the Aadhaar holder is receiving subsidy deposits in. Indane’s website will tell you the name of the Aadhaar holder and their LPG connection ID, and the history of banks they have received subsidies in. Keep probing services like this, and soon enough one builds a comprehensive profile of an individual containing information that is most certainly not known to Google and Facebook, the Aadhaar ecosystem’s preferred bogeymen. Forget state-level actors, this is now available to common scamsters. Everyone from housemaids to members of Parliament have fallen prey to targeted phishing scams that use private information to convince the victim that they genuinely represent the service provider, only to find that money has been stolen from their bank accounts soon after.

The leaks get worse. UIDAI has no capability to audit the security practices of even its licensed ecosystem of over 300 agencies, all with the power to query the main database, sublicence access, and combine with other data. Every few weeks a new leak is discovered. The SRDHs operate without public oversight and contain contact information of children. The Kārana blog documents how the known leaks happen, but who knows how many undocumented leaks are actively abused?

One must remember that the Aadhaar ecosystem also holds data on all military personnel. The military has independent standards for everything, from data storage to transmission, because of how sensitive their data is, and now UIDAI and its out-of-control ecosystem are leaking data left, right and centre. Aadhaar endangers national security and the government needs to act fast.

Kiran Jonnalagadda is a co-founder of the Internet Freedom Foundation.

Comments are welcome at theirview@livemint.com
First Published: Wed, Jan 17 2018. 11 34 PM IST

Saturday, January 20, 2018

12694 - The Aadhaar ecosystem leaks too much data - Live Mint

The ecosystem treats a breach as a simple accident, without regard for consequences to the victims
Last Published: Thu, Jan 18 2018. 12 49 AM IST


Aadhaar endangers national security and the government needs to act fast. Photo: Priyanka Parashar/Mint

People don’t respond well to dystopian scenarios”, a professor of marketing warned me late last year. The true extent of Aadhaar-linked data leakage is hard to process, so we tend to ignore it. Smaller inconveniences are easier to understand.
Some awareness, however, has now seeped into public consciousness due to an exposé by Rachna Khaira in The Tribune, who showed that access to the entire database could be purchased for as little as Rs500. The response was predictable. First, multiple denials that a breach had even occurred. Second, an FIR against Khaira and The Tribune, combined with allusions of “an orchestrated campaign to malign Aadhaar”. Third, when the repeated assertions of Aadhaar’s safety wore thin, a public dare demanding to know how anyone could be harmed if their private information got leaked.
Section 59 of the Aadhaar Act covers activities that are illegal under the rest of the Act. Many states have sought to collect deeply personal information such as religion and caste in their state resident data hubs (SRDHs), coupled with biometrics, and without the cover of a state law. UIDAI (Unique Identification Authority of India) has enabled this in their enrolment and other software with such innocuous names as “DBT Seeding Data Viewer (DSDV)” and “Rapid Aadhaar Seeding Framework (RASF)”. Andhra Pradesh links everything to Aadhaar, all the way down to minor traffic offences. The police are allowed access to biometrics for identifying criminals and lost children. The sensitivity of such detailed personal information coupled with voter ID during an election should be obvious.
The Aadhaar ecosystem is widespread, extending to former UIDAI members like Nandan Nilekani and think tanks like iSPIRT, private firms like Khosla Labs, venture capital firms and their research vehicles like Omidyar and IDinsight, service providers like Airtel, Jio and Paytm, and the National Payments Corporation of India. UIDAI is a hopelessly ill-equipped steward of the ecosystem, and its ongoing meltdown is apparent to anyone tracking the details. While the ecosystem members may not always agree with each other, what unites them is their desire to keep Aadhaar afloat regardless of the risks, because it lowers their government-imposed “know your customer” (KYC) costs. This is an inversion of democracy, where societal concerns are primary. This Aadhaar ecosystem treats a breach as a simple accident, without regard for consequences to the victims.
In 2014, Nilekani, former chairman of UIDAI, accidentally leaked his own Aadhaar details when he posted a photograph of his Aadhaar card with the number masked out while keeping the accompanying QR code which contained his number, date of birth and residential address. Copies of his information remain available on multiple websites, accessible via a simple Google search. If someone as powerful as Nilekani is unable to make the internet forget his details, what hope does anyone else have?

The Tribune breach required one to know an Aadhaar number to retrieve personal information. It takes a computer mere seconds to produce all 80 billion possible Aadhaar numbers. The one billion currently-valid numbers can be filtered out by using the 130 million already-leaked numbers, and the rest using a number of verification services, including UIDAI’s own—which is technically protected by a “captcha” to prevent such automated attempts, but which is so trivial that amateurs break it to win programming contests, and then share on code repository GitHub.com. One has to be incredibly naïve to believe hostile actors, including foreign powers, haven’t already harvested all data.
A valid Aadhaar number is a key that opens multiple locks. Dialing *99*99# connects you to NPCI’s query service on Aadhaar mapper (QSAM), which cheerfully tells you which bank the Aadhaar holder is receiving subsidy deposits in. Indane’s website will tell you the name of the Aadhaar holder and their LPG connection ID, and the history of banks they have received subsidies in. Keep probing services like this, and soon enough one builds a comprehensive profile of an individual containing information that is most certainly not known to Google and Facebook, the Aadhaar ecosystem’s preferred bogeymen. Forget state-level actors, this is now available to common scamsters. Everyone from housemaids to members of Parliament have fallen prey to targeted phishing scams that use private information to convince the victim that they genuinely represent the service provider, only to find that money has been stolen from their bank accounts soon after.
The leaks get worse. UIDAI has no capability to audit the security practices of even its licensed ecosystem of over 300 agencies, all with the power to query the main database, sublicence access, and combine with other data. Every few weeks a new leak is discovered. The SRDHs operate without public oversight and contain contact information of children. The Kārana blog documents how the known leaks happen, but who knows how many undocumented leaks are actively abused?
One must remember that the Aadhaar ecosystem also holds data on all military personnel. The military has independent standards for everything, from data storage to transmission, because of how sensitive their data is, and now UIDAI and its out-of-control ecosystem are leaking data left, right and centre. Aadhaar endangers national security and the government needs to act fast.

Kiran Jonnalagadda is a co-founder of the Internet Freedom Foundation.

Comments are welcome at theirview@livemint.com
First Published: Wed, Jan 17 2018. 11 34 PM IST

Friday, January 12, 2018

12714 - Virtual Aadhaar ID: too little, too late? - The Hindu



NEW DELHI, JANUARY 11, 2018 23:10 IST

The UIDAI on Wednesday introduced the concept of a virtual ID  
Problems persist as many have already shared their 12-digit number with various entities, say experts

The move to introduce an “untested” virtual ID to address security concerns over Aadhaar database is a step in the right direction, but may be a case of too little, too late, according to experts, as many of the 119 crore Aadhaar holders have already shared their 12-digit numbers with various entities.

“What about all the databases that are already linked up with our Aadhaar number? Virtual ID will therefore not attack the root of the problem. At best, it is band-aid,” said Reetika Khera, faculty, Indian Institute of Technology-Delhi.
“Can we realistically expect rural folks to use this to protect themselves? Or are we pushing the barely literate into the hands of middlemen who will ‘help’ them navigate it?” she questioned.

The Unique Identification Authority of India (UIDAI) on Wednesday introduced the concept of a virtual ID that can be used in lieu of the Aadhaar number at the time of authentication, thus eliminating the need to share and store Aadhaar numbers. It can be generated only by the Aadhaar number-holder via the UIDAI website, Aadhaar enrolment centre, or its mobile application.

Experts pointed out that the virtual ID is voluntary and the Aadhaar number will still need to be used at some places.
“Unless all entities are required to use virtual IDs or UID tokens, and are barred from storing Aadhaar numbers, the new measures won’t really help,” said Pranesh Prakash, Policy Director, Centre for Internet and Society, Bengaluru.
Kiran Jonnalagadda, co-founder of the Internet Freedom Foundation, agreed. “The idea is good but it should have been done in 2010, as now all the data is already out. Now, what can be done is revoke everybody’s Aadhaar and give new IDs.”
Mr. Jonnalagadda added that Authentication User Agencies (AUAs) categorised as ‘global AUAs’ by the UIDAI will be exempted from using the virtual IDs. “These are likely to be entities which require de-duplication for subsidy transfer, such as banks and government agencies. All the leaks have happened till now from these entities. So, basically, the move will exempt the parties that are the problem,” he said.
Vipin Nair, one of the advocates representing the petitioners who have challenged the Aadhaar Act in the Supreme Court said, “It is potentially a case of unmitigated chaos purely from an Information Technology perspective.”

12707 - UIDAI introduces new two-layer security system to improve Aadhaar privacy - Economic Times

ET Bureau|
Updated: Jan 11, 2018, 06.22 AM IST

It will not possible to locate your aadhaar based on your virtual id. 

NEW DELHI: The Unique Identification Authority of India (UIDAI) has introduced a system of virtual authentication for citizens enrolled on its database and limited the access available to service providers in a move aimed at allaying widespread concern over security breaches that have dogged the world's largest repository of citizen data. 

In one of the most significant security upgrades by the eightyear old agency, the UIDAI announced the creation of a "virtual ID" which can be used in lieu of the 12-digit Aadhaar number at the time of authentication for any service. 

The UIDAI has also limited access to stored personal information and mandated the use of unique tokens through which authenticating agencies can access required data. It claims that the measures will strengthen privacy and also prevent combining of databases linked to Aadhaar. 

ET was the first to report about the UIDAI plan to introduce virtual numbers to address security concerns in its November 20 edition last year. 

A top government official told ET that UIDAI has been working on this technology since July of 2016. "This is going to be one of the biggest innovations ever, people can change their virtual ID whenever they want or after every authentication or every 10 seconds." He added that this will silence most critics of Aadhaar. 

"The Aadhaar number being the permanent ID for life, there is need to provide a mechanism to ensure its continued use while optimally protecting the collection and storage in many databases," the UIDAI said in a notification on Wednesday while announcing the new measures. 

More Needed to be Done: Experts 

"The collection and storage of Aadhaar number by various entities has heightened privacy concerns," it stated. 

Under the new regime, for every Aadhaar number, the authority will issue a 16-digit virtual identity number which will be "temporary and revocable at any time." 

This virtual ID can be generated only by the individual Aadhaar holder and can be replaced by a new one after a minimum validity period. 

In addition, while some Authentication User Agencies (AUA) — categorised by the UIDAI as 'Global' — will have access to all the details or the e-KYC of a specific Aadhaar number, all other agencies will only have access to limited data through the virtual identity number. 

"So this is a very very significant thing and I think this is a great step forward," said Nandan Nilekani, former chairman of UIDAI, in an interview to television channel ET Now on Wednesday. 

Nilekani, widely regarded as the architect of Aadhaar, said that through these new security measures the possibility of the Aadhaar number being stored in many databases also goes away. 

It will make a huge difference in allaying the concerns and it really "eliminates all the arguments against Aadhaar," he told ET Now. 

Last week, Chandigarh-based daily The Tribune reported that demographic data from the Aadhaar database could be accessed for as little as Rs 500. The expose led to the UIDAI barring over 5,000 officials from accessing its portal through login ids and passwords. It also introduced biometric authentication for future access, as reported by ET on Tuesday. 

The widespread fear of misuse of demographic data is heightened by the fact that India still does not have a data protection legislation. The country's apex court is scheduled to resume its hearing on the validity of the Aadhaar scheme next week on January 17. 

Kamlesh Bajaj, former CEO of the Data Security Council of India said by limiting access to only those agencies mandated by law, the UIDAI has ensured that "someone will not be able to combine database. It's a positive development in my view and technologically feasible," he said 

EXPERT VIEWS 

Privacy experts and activists were of the view that more needs to be done to ensure foolproof security for critical personal information. 

The Bengaluru-based research organisation Centre for Internet and Society has suggested that all the Aadhaar seeding with all the existing databases should be revoked. "Until then, it is one step ahead and but not enough," said Sunil Abraham, executive director of CIS. 

To enable a speedy rollout of the new safety standards, the UIDAI plans to release the required technical updates by March 1, 2018 and all the Authentication agencies using the Aadhaar database will need to upgrade their systems latest by June 1, 2018. 

In its circular, UIDAI has also said that agencies not allowed to use or store the Aadhaar number should make changes inside their systems to replace Aadhaar number within their databases with UID Token. 

"Unless there is complete revocation, some database with Aadhaar numbers will still float around and secondly there is no reason why some data controllers should be trusted, the tokenisation should be implemented for everyone," said CIS's Abraham. 

The circular said that authentication using virtual ID will be performed in the same manner as the Aadhaar number and people can generate or retrieve their virtual numbers (in case they forget) at the UIDAI's resident portal, Aadhaar Enrolment Centers, or through the Aadhaar mobile application. 

In addition to the virtual numbers, UIDAI will also provide "unique tokens" to each agency against an Aadhaar number to ensure that they are to establish the uniqueness of beneficiaries in their database such as for distributing government subsidies under cooking gas or scholarships. 

Activists argue that most service providers — even digital ones — work with a paper ID card system. "They don't cross-check it with the UIDAI database. UIDAI is not issuing virtual ids for paper cards, and a new category of so called Global AUAs are exempted from using the virtual ids, so citizens are not protected almost anywhere that they need to use Aadhaar," said Kiran Jonnalagadda, co-founder of the Internet Freedom Foundation, who said the change doesn't help enough to secure the ecosystem .. 

Read more at:

Friday, December 29, 2017

12568 - Facebook asks new users to enter names ‘as per Aadhaar’ while signing up - Hindustan Times

Facebook asks new users to enter names ‘as per Aadhaar’ while signing up

Facebook says the new feature is aimed at encouraging users to enter their real names while signing up.

TECH Updated: Dec 27, 2017 15:37 Ist


Kul Bhushan 
Hindustan Times

Well, we did see this coming.(AFP)

Facebook is testing a new feature in India wherein it is encouraging new users to enter their names as per their Aadhaar card.

The move is aimed at encouraging users to put their real names on the social network. Since it’s being tested with a small population in India, not all users may be able to see this. It is worth pointing out here that the Aadhaar-based sign up is not mandatory.

Facebook confirmed that it is indeed testing such feature.
“We want to make sure people can use the names they’re known by on Facebook, and can easily connect with friends and family. This is a small test where we provide additional language when people sign up for an account to say that using the name on their Aadhaar card makes it easier for friends to recognise them. This is an optional prompt which we are testing. People are not required to enter the name on their Aadhaar card,” said a Facebook spokesperson.

Note that Facebook isn’t asking for your Aadhaar number, but just the name as per your Aadhaar card.

The association with Aadhaar, however, is expected to raise eyebrows. There have been concerns about the safety of Aadhaar data after private details of citizens were leaked on government websites and from private bodies like banks, telecom operators, insurance providers and financial organisations.

According to a government reply in Parliament in June 2017, more than 200 government websites published names of beneficiaries of welfare schemes with their addresses and Aadhaar numbers.

The government has argued that Aaadhar is necessary to plug leakages in its subsidised welfare programmes, to prevent corruption, and to protect national security.

Earlier, several users on Reddit and Twitter posted messages about Facebook’s new feature. Some users, however, claim this feature was being tested since a longer time.

“FB actually does it for a long time now. India is new in this maybe. But they ask for photo ID like driver licence/passport/some others. They even ask for you to upload your real photo (by opening front camera) for verification (if your dp isn’t),” claimed a user on Reddit.

“Any data is useful data . Maybe not now but in future. And I’m sure FB already has internal profiles in which they wrote entire persons’ data like name address phone number aadhaar number etc,” said another user while responding to a query whether Facebook has access to Aadhaar details.

Conspiracy wasn’t the intention , but the power of data and lack of any provision to safeguard it. But let’s hope the discussions happen and we get to safer and better system


How hard is it?

1. Facebook has a longstanding real names policy.

2. The average Indian’s understanding of real name is what they give for Aadhaar or their bank account.

3. An Aadhaar card is meant to be id proof, unlike a bank account.

See? No conspiracy involved.


With the number of fake profiles around its hightime tht the government should ask people to link thr aadhar card with thr facebook and instagram account @narendramodi ji please consider this #Aadhaar #pan #31stdecember 

Thursday, December 14, 2017

12504 - Website on Aadhaar plaints launched, gets 1k emails in 3 hrs - Times of India



Kim Arora | TNN | Dec 14, 2017, 02:41 IST

NEW DELHI: On the day the government extended the deadline to link Aadhar with bank accounts, activists started a website on Wednesday called speakforme. in. Using this, citizens can write to their MPs, banks, mobile operators, and other government service providers to complain about repeated calls and messages from various entities asking citizens to link their Aadhaar numbers with various services.

Number of emails sent crossed the 1,000 mark in little over three hours of the website going live, said those who started it. At least 780 of these were sent to MPs. The website is being run by a group of about 90 volunteers, many of whom also participated in the campaign for net neutrality two years ago. Chief among them is Bengaluru-based IT professional Kiran Jonnalagadda.

"We want Parliament to discuss this. Everyone has been receiving harassing SMSes and calls to link their Aadhaar to mobile phones and bank accounts. This is coercion. The technology behind Aadhaar is broken in various ways. Coercion will make it worse. It has to be fixed before it is forced on people," says Jonnalagadda. The winter session of Parliament starts later this week.

TOP COMMENT
Adhar business has become public nuissance to people as no one gives acknowledment after proving adhar in Banks, LIC etc
Appa Durai

Nikhil Pahwa, founder of Medianama.com, is also part of the team behind speakforme-.in. "If all your services are linked to it, then Aadhaar becomes a kill switch. You can be disconnected by the government for no reason. There is also the issue of mass surveillance, when Aadhaar is used along with NATGRID, which is a surveillance system the government is setting up," says Pahwa.

When writing to an MP, a user can select his or her state and constituency from a drop down menu. Using publicly available information about MPs online, the website pulls out the relevant MP's email address. The user can then send a template email demanding that Aadhaar be made non-mandatory. The letter can be edited and customised before sending as well.

Thursday, July 27, 2017

11655 - Can Your Aadhaar Number Be A Threat To Your Privacy? - Business World



Aadhaar exposes you to an increased risk of identity theft since your biometrics can be harvested by shopkeepers and reused without your permission

26

The whole debate around Aadhaar has sidelined and the right to privacy has taken centre stage. While the noble intentions behind making Aadhaar as a national identity card cannot be questioned, its vulnerability to data abuse can also not be denied. For instance, if you use your Aadhaar number to buy a SIM card, the company can use it to access all your identity information, barring your core biometrics.

The United Progressive Alliance (UPA) government brought in Aadhaar but the incumbent National Democratic Alliance government is giving more push to Aadhaar by linking it with welfare schemes like National Action Plan for Skill Training of Persons with Disabilities, Central Sector Scholarship Schemes, Saakshar Bharat (adult literacy), Sarva Shiksha Abhiyan, National Health Mission, National Career Services, Support to Training and Employment Programme (women-centric entrepreneurial assistance), Ujjawala Scheme under the Protection and Empowerment of Women Scheme, and more.

Although, the government’s effort to remove middle men from the scene by bringing in Aadhaar in every space is commendable but the lack of a comprehensive privacy law is slowly becoming a worrying factor for the nation. Recently, MS Dhoni's Aadhaar number and the rest of the information were leaked and one of his ‘fans’ posted all that information on Twitter.

This is not a lone case; there have been breaches earlier as well. Many third parties (neither UIDAI nor government officials) are creating a private database with Aadhaar information and interlinking identity with other sources. Kiran Jonnalgadda, co-founder, HasGeek and Internet Freedom Foundation told BW Businessworld, “Aadhaar, with the current laws, can is vulnerable to data abuse. We need a comprehensive law. We are awaiting the Supreme Court’s verdict on privacy laws.”
Another glaring fact is that the Unique Identification Authority of India had outsourced the responsibility of collecting the data to 556 private agencies. There have been 1,390 complaints against them but the proceedings took place only in the case of Dhoni.

A senior IT expert, who wished to remain anonymous, told BW Businessworld, “Aadhaar exposes you to an increased risk of identity theft since your biometrics can be harvested by shopkeepers and reused without your permission. Further, by using the same Aadhaar number in multiple locations the government has created a system by which a 360° view of a person can be had by combining multiple databases.  For instance, a hospital and a health insurance company can combine their databases without your consent.  While this is possible even without Aadhaar, it is made easier and more accurate with Aadhaar. To prevent this from happening, we need to have a strong privacy law in India that applies to both the government and the private sector.  We also need to limit the ability of the private sector to force you to give up your biometrics.”

Aadhaar-related security breaches may leave the individual wide open to commercial exploitation and identity fraud. Aadhaar is often compared to the United States (US) Social Security Number but it must be noted that biometrics are not taken in the US and there is a law for privacy in the US as well.
Since Aadhaar is gradually becoming an identity tool for almost all purposes; the government must try to figure out some way to remove all the technical discrepancies that can make all our details transparent at an immediate basis.



Wednesday, June 14, 2017

11517 - Why did Nandan Nilekani praise a Twitter troll? - Indian Express

As the Supreme Court upholds the linking of ‘Aadhar’ with PAN, questions around ex-UIDAI chairman Nandan Nilekani praising iSPIRT head Sharad Sharma Twitter troll and ‘Aadhar’s privacy properties will continue to be asked


Written by Kiran Jonnalagadda | Updated: June 10, 2017 2:16 pm


Last month, Sharad Sharma, the head of the Indian Software Product Industry Round Table (iSPIRT) Foundation, an organisation that promotes Aadhaar to industry, was outed as the operator of at least two anonymous Twitter troll accounts that viciously harassed and defamed critics of Aadhaar. The shocking revelation was first met with denial by iSPIRT, and then followed by what may be understood as a reticent apology from Mr Sharma.

In a bizarre sequence of events, the apology received praise from several quarters. iSPIRT’s Guidelines and Compliance Committee (IGCC) investigated Mr Sharma and the ‘Sudham’ team that coordinated the trolling campaign. Two members of the investigating committee subsequently resigned, although only one confirmed.

The committee’s findings, confirming that Mr Sharma was responsible, were summarised for the public by Mr Sharma himself, who then announced that his role as a public spokesperson would now be handled by Sanjay Jain. Mr Jain was once with the Unique Identification Authority of India (UIDAI), launched by Nandan Nilekani, is currently a director at Nandan Nilekani’s EkStep Foundation, and a close confidante of Mr Sharma. The two have often pitched iSPIRT’s IndiaStack initiative together.

In an internal email questioning this decision, an iSPIRT member asked whether Mr Jain was a part of the ‘Sudham’ team, and whether he was also “at least partially culpable for the [troll] campaign and the violation of the code of conduct.”
The victims of the trolling have received no report, and the two apologies posted by Mr Sharma were both for having “condoned uncivil behaviour”, but not for personally orchestrating the attacks. Among those who praised him was Nandan Nilekani, former chairman of UIDAI and chief mentor of iSPIRT.
Critics have been pointing out for years that Aadhaar lacks sufficient checks and balances, and that claims of benefits are overstated. These concerns have been met with denial, condemnation of critics, and often outright refusal to engage in debate. This has unfortunately only served to alienate an even larger section of the population, turning ordinary citizens into activists.

We can gain an insight into how Aadhaar is promoted by examining iSPIRT. The organisation was founded in 2013 by volunteers who had been working together on the sidelines of the NASSCOM Product Conclave. These volunteers felt the need for an independent grassroots organisation to represent tech entrepreneurs who were building products for India and the world. iSPIRT has grown phenomenally influential over its few years, largely by the work of volunteers who were truly interested in building a mutual assistance community.
Level playing fields are a recurring topic. Just as there is a desire to lower bureaucratic hurdles to give every entrepreneur a fair chance, there is also the question of how a startup can compete against a foreign competitor that has the advantage of a stronger home market.

Flipkart and Ola are two prominent examples in their fight to defend their market share against Amazon and Uber, competitors armed with global experience, more capital, and better trained talent. iSPIRT’s take is that for Indian companies to thrive they must have a supportive ecosystem that enables rapid growth, and so iSPIRT must step up as an “activist think tank”.

One aspect of this activism is IndiaStack, which seeks to help startups by promoting a suite of ‘public goods’: Aadhaar and eKYC for id verification, eSign and Digilocker for digital contracts and certificates, and UPI for payments. If one accepts at face value that these services are well intentioned, then IndiaStack is on a noble quest. The details, unfortunately, are less pristine.
iSPIRT is a private non-profit, but its volunteers include several former members of UIDAI. The guidance and compliance committee (IGCC) investigating the trolling included a current member of government. iSPIRT helped build and evangelise the UPI (United Payments Interface) platform and BHIM app for NPCI, but the level of involvement and terms of the agreement are not public.

For an organisation that claims to champion public goods, iSPIRT is opaque on the level of influence they wield with government (Mr Sharma once claimed some influence but no control), and on who exactly built the various components of IndiaStack, within or outside of government.

They showed a remarkable degree of influence when foisting UPI on a change-resistant banking sector. They have funding from four banks (IDFC, SBI, Bank of Baroda and Axis Bank) and from fintech startups. Despite this level of responsibility, they also have no accountability since they are a pro bono volunteer force, allowing them to distance themselves from failures (UPI failures are NPCI’s problem and Aadhaar failures are UIDAI’s problem, etc) and unpleasant incidents such as the ‘Sudham’ trolling project. (No one has accepted responsibility for operating a troll account.)

At the core of IndiaStack is ‘Aadhaar’, which as it currently stands has serious concerns from its technical architecture to institutional safeguards. Aadhaar lacks publicly verifiable audits, a data breach disclosure policy, or an engagement process for researchers to report concerns.

For reasons best known to them, the promoters of ‘Aadhaar’ are in a tearing hurry to impose it everywhere, in every aspect of an Indian’s life, out of an apparent fear that it will die if adoption slows down. This is eerily reminiscent of startup mantras like “fake it till you make it” and “move fast and break things”.
But ‘Aadhaar’ already has a billion enrollments and the backing of legal measures pushed by the Union Government. There is no threat of imminent demise. And yet, as the Twitter trolling shows, this fear continues to exist for ‘Aadhaar’s proponents, so much so that critics must be silenced at any cost.

Where trolling failed to work, subtler attacks are sure to follow. There have been some in the recent past.
The Centre for Internet and Society (CIS) is facing one such attack for its report on the leak of 130 million Aadhaar numbers. The report received wide coverage and was followed by new rules from MEITy (ministry of Electronics & Information Technology) regarding the handling of Aadhaar numbers, but instead of commending CIS for its role in improving safeguards, UIDAI is accusing it of hacking, demanding the identity of the researcher so that he or she may be individually prosecuted.
When Sameer Kochhar demonstrated that previously captured fingerprints were being reused because Aadhaar’s API lacked technical safeguards, UIDAI responded by prosecuting him. A News18 journalist was also prosecuted for demonstrating how double application for enrollment was possible using different names.

As of September 30, 2017, ‘registered’ devices will be mandatory as the current devices are not secure against fingerprint reuse, and an unknown number of fingerprints have already been captured and stored. This sort of forced technological upgrade will happen again as more problems surface into public consciousness, with more researchers and critics harassed for pointing these out.

‘Aadhaar’ pursues inherently contradictory goals. The process of ‘inorganic seeding’, for instance, allows a database to be seeded with ‘Aadhaar’ numbers, to help a service provider identify and eliminate duplicates without the individual’s cooperation. (Inorganic seeding is an official UIDAI scheme.) And yet, the law prohibits using and sharing ‘Aadhaar’ numbers without the individual’s consent.

‘Aadhaar’ aims to be an inclusive project, providing an identity for everyone, and yet easily lends itself to being an instrument of exclusion. There is technical exclusion when biometrics fail to match, and there is institutional exclusion when Aadhaar is made mandatory and an individual is then blacklisted from a service or denied Aadhaar enrollment.

Aviation minister Jayant Sinha recently announced a proposal to use digital id for just this purpose. ‘Aadhaar’ in its current state makes it extraordinarily simple for an organisation to demand it for authentication, but what of the necessary safeguards to protect an individual’s rights? Or of ensuring that grievance redressal mechanisms are in place and actually functional? These are not solved by a technical API integration.

Just as we’ve seen with nuclear power, weak institutions which are sensitive to criticism and fail to ensure effective oversight amplify the risks of the underlying technology. Aadhaar’s supporting institutions, whether government bodies like UIDAI or private bodies like iSPIRT, are immature for the mandate they carry. All technology improves with time, but weak institutions hamper their benefit to society.

As the leading promoter of Aadhaar, founding chairman of UIDAI, and chief mentor of iSPIRT, Mr Nilekani must step up and commit to improving the institutions he commands, and take responsibility for their failures. Condemning critics instead does not help build institutions.

Kiran Jonnalagadda is a tech and society enthusiast, co-founder of @HasGeek and Internet Freedom Foundation. He tweets @jackerhack

For all the latest Opinion News, download Indian Express App
© IE Online Media Services Pvt Ltd

Wednesday, May 31, 2017

11493 - Ispirt Shuts Down Controversial Aadhaar Critics Trolling Programme Sudham

Key iSPIRT Members Parting Ways?


Indian software products think tank iSPIRT has disclosed that ‘Sudham’ – the alleged programme sanctioned by the organisation to troll anti-Aadhaar activists has been dissolved.

iSPIRT founder Sharad Sharma disclosed the development in an official statement.

Also, in the aftermath of this controversy, key iSPIRT members are said to be distancing themselves from the organisation.

Ispirt Shutting Down Sudham
The decision to shut down Sudham was revealed in an official statement by Sharad Sharma titled: “The End Doesn’t Justify The Means: A Public Statement.” In the post, Sharad stated that iSPIRT had created an iSPIRT Guidelines and Compliance Committee (IGCC) to investigate the controversy. As a result, Sudham has been dissolved and Sharad will not be responsible for iSPIRT’s external communications for the next four months, as a consequence of the “transgression.

He stated, “And, on that count, I as one of the builders have stumbled. I condoned uncivil behaviour by some anonymous handles over a period of ten days. I have owned up to this transgression. It was investigated internally by the iSPIRT Governing Council: Sudham as a team stands dissolved and I will no longer be communicating on behalf of iSPIRT externally for 4 months.”

Talking about the events that took place Sharad added, “Having danced with such tactics myself for ten days in May, I can say with certainty that it is conduct unbecoming of our prior actions and accomplishments. Put simply, I have learnt my lesson. One that should have been painfully clear to begin with. Such behaviour — uncivil comments made while hiding behind anonymity — is loathsome and abhorrent. And I will never engage in or condone such methods ever again.”

Sharad’s statement comes a week after he publicly apologised for iSPIRT anonymously trolling those voicing concerns over privacy and security standards in Aadhaar. The trolling programme was brought to light by Kiran Jonnalagadda, Aadhaar’s most vocal critic and co-founder of Internet Freedom Foundation (IFF), an advocacy group. Kiran revealed in a series of tweets that @Confident_India, one of the anonymous accounts arguing in favour of Aadhaar and attacking its critics on Twitter, was being operated by none other than Sharad Sharma. He also revealed in detail about the programme in a series of Medium posts that Sharma and other iSPIRT members were behind the anonymous trolls.

In response to Kiran’s post and criticism from all quarters, iSPIRT’s Governing Council put together a Guidelines and Compliance Committee, which conducted an investigation that concluded on 28 May, 2017. Sharad’s post is a reflection on the same, though the IGCC itself has not issued a public statement.

Kiran pointed this out in yet another Medium post where he states that, “Following my posts and much media coverage, iSPIRT’s Governing Council put together a Guidelines and Compliance Committee (IGCC), which conducted an investigation that concluded on 28 May, 2017. We do not have a public statement from IGCC, but instead—curiously enough—have a public statement from Sharad Sharma himself, summarising the decisions of the committee that investigated him.”
In the post, Kiran stated, “As a primary victim of Sharad’s trolling, and as someone who deposed before the IGCC, I have yet to hear back from them officially.”

He further added that, “I’m pained to point out that Sharad continues to not admit to being the person behind at least two troll accounts, instead merely admitting to ‘condoning’ the behaviour of unnamed persons.”

Kiran clearly expressed his disappointment with the statement when he said that, “I’m aware that Sharad wasn’t operating alone. Others were involved and, so far, no one has come forward to be identified as the operator of a troll account, not even Sharad himself.”

Key Ispirt Members Parting Ways?
Meanwhile, the trolling programme, which has cast a negative light on iSPIRT, that started as an organisation to promote software products, seems to have taken a toll on the organisation itself. As per a TOI report, a few higher ups, including InMobi co-founder Naveen Tewari and FusionCharts founder Pallav Nadhani are distancing themselves from the organisation, as of now.

In an emailed response to Inc42, Pallav stated, “I will be working with iSPIRT from the sidelines, not as a part of it, at least for some time. The cause is larger than any of us and important for the country. As of now, I have expressed my intent to move on, but I do hope that iSPIRT will emerge way stronger and continue contributing to Indian ecosystem. There are over 200 passionate volunteers behind the cause. “
For an organisation that holds an important place in the Indian startup ecosystem as far as promoting software is concerned, in the aftermath of this controversy, it seems like the right time for it to refocus on its primary objective and owning up to its gaffes.

Because, as Sharad aptly writes, “There will be a time when we must choose between what is easy and what is right. It is our choices that show what we truly are, far more than our abilities.” – Albus Dumbledore.”

The Aadhaar critics trolling programme may not have been the finest hour of the forward-thinking organisation, but it has become an important part of the larger social conversation. Here is hoping that iSPIRT chooses the right kinds of path, going forward.


Note: We at Inc42 take our ethics very seriously. More information about it can be found here.

Wednesday, May 24, 2017

11465 - ‘In a battle between staying anonymous and being unmasked, there is no excuse for being unprepared’ - Factor Daily



Kiran Jonnalagadda May 23, 2017 5 min


Editor’s note: Anonymity on the internet has its pros and cons. It helps whistleblowers, but also gives rise to online abuse. Last week, Bangalore-based internet activist and entrepreneur Kiran Jonnalagadda showed that set of sock puppet accounts anonymously operated by members of India’s software products think tank iSpirt were running campaigns to support Aadhaar, India’s biometric identity system. Some of those accounts were also trolling anti-Aadhaar voices on Twitter

Here’s a take from Kiran on why anonymity is still important to protect.

Anonymity is both good and necessary. It is a recurring feature in any closed system. Take elections for example. Your vote is anonymous, and this is an essential feature, but you only have voting privileges if you meet specific criteria such as being a citizen and over 18 — meaning it is a closed system. Anonymity does not allow anyone outside the system to participate.
Anonymity is both good and necessary. It is a recurring feature in any closed system… Anonymity does not allow anyone outside the system to participate  

Throughout most of history, closed systems have been easy to maintain because distance and language make natural barriers. The early internet, by simple virtue of being a relatively small place and limited to those geeky and privileged enough to get online, functioned like a closed system.

Early chat forums, from Usenet to IRC to email lists, also use the metaphor of a “room” wherein you had to enter a room to see the conversations within. A statement made inside a room was therefore unlikely to be seen by anyone not in the room.

Also read:

The social network metaphor, starting from the early 2000s, did away with the concept of rooms and instead defined networks around individuals based on their follows and followers, letting each user exist in a virtual room that shared significant overlap with the next person’s virtual room. Once these networks introduced sharing — Twitter’s retweet, Facebook’s share and so on — they added the ability for your words to be carried to an audience far beyond what you thought it was going to, with all the attendant upsides (influence) and downsides (loss of context and unwanted attention).

We can see one example of careful thought being put into anonymity on a social network on Quora, the Q&A site. When Quora launched, it included anonymous Q&A as a standard feature. However, since this could easily be abused for harassment, Quora added two other restrictions:
1. You had to have a Quora account to post anonymously, ensuring that you were part of the closed system, not an outsider.
2. Quora membership was available by invite only, preventing people from making new accounts just to use anonymously.

Both of these constraints worked to create a community that maintained civil discourse even while embracing anonymity. In Quora’s vision, a question or answer can continue to remain relevant even if you don’t know who is asking or answering.
Online social networks continue to be subject to the rule of law, but social networks, as with all software-defined matchmaker platforms, also find it necessary to define their own governance system, separate from the law  

While anonymous speech has a long tradition in society (consider, for instance, writing and publishing under pen names), society has also evolved mechanisms for dealing with unwanted speech such as libel, blasphemy and harassment, allowing the government to demand your identity from your associates (such as your publisher) under specific conditions and with due process (such as a court warrant).

Online social networks continue to be subject to the rule of law, but social networks, as with all software-defined matchmaker platforms, also find it necessary to define their own governance system, separate from the law. These are usually defined as the community code of conduct and can include rules such as Facebook’s ban on nudity, or the underlying process behind the “Report this” button on any of these sites. (See Matchmakers for a detailed examination of why these governance rules become necessary.)

What we’ve seen in the case of Twitter in particular is governance rules that overemphasise free and anonymous speech and under-emphasise limits on such speech, which is why Twitter is particularly prone to anonymous harassment  
What we’ve seen in the case of Twitter in particular is governance rules that overemphasise free and anonymous speech and under-emphasise limits on such speech, which is why Twitter is particularly prone to anonymous harassment. In my opinion, this is something for Twitter to reflect on and make amendments for, and this appears to be a widely held opinion.
Finally, if you’re doing anything that is likely to draw unwelcome attention, it is imperative for you to know how to protect yourself. The world of technology is a constant arms race, and in a battle between staying anonymous and being unmasked, there is no excuse for being unprepared. The recent episode has been a reminder for me on how badly educated people are. While I have no sympathy for those trying to abuse me (apart from their lack of education), I’m also concerned for others doing good work anonymously who may suddenly have a new tool (password reset) used against them. I hope they will stay alert and stay ahead of the curve.

Lead visual: Nikhil Raj

11463 - Co-founder of UIDAI-associated outfit admits to anonymously trolling Aadhaar critics on Twitter - Scroll.In


Sharad Sharma, governing council member of iSpirt, offered an apology and said he would be investigated by a compliance committee.


Published Yesterday · 05:25 pm.  


A co-founder of iSpirt, a private non-governmental organisation closely associated with the Aadhaar-administering Unique Identification Authority of India, has admitted to anonymously trolling critics of the Aadhaar project on Twitter. In a tweet on Tuesday, iSpirt governing council member Sharad Sharma said he had “slipped”, offered an apology for his behaviour and announced that the organisation had set up a committee to investigate his actions.

“Anonymity seemed easier than propriety, and tired as I was by personal events and attacks on iSPIRT’s reputation, I slipped,” Sharma wrote in his Twitter post. “I won’t be part of anything like this nor passively allow such behaviour to happen, even in the worst of times.”

The admission of anonymous trolls harassing Aadhaar critics – suggesting that they were likely to be in the pay of Pakistan’s ISI intelligence agency, for instance – comes just days after the UIDAI officially complained about researchers who had pointed to holes in the security standards of the Aadhaar project. Taken together, this suggests an environment where anyone questioning the government’s biometrically linked identity number programme is likely to be subject to both official and anonymous attacks.

What is iSpirt?

iSpirt, or the Indian Software Product Industry Roundtable, was constituted in 2013 as an offshoot of industry body NASSCOM’s annual product conclave. It was built by donors, volunteers and partners from the Indian tech industry, and included former UIDAI chairman Nandan Nilekani as a mentor. It also featured at least two key members of the team that worked at UIDAI: Pramod Varma, who was the Chief Technology Architect of Aadhaar, and Sanjay Jain, its Chief Product Manager.

The organisation helped build India Stack, a set of software products that are explicitly aimed at building apps on top of the Aadhaar database. India Stack builds Aadhaar-based apps and then “evangelises” them to the government – which Medianama’s Nikhil Pahwa points out is uncomfortably close to them – as well as to private organisations.

As legal researcher Usha Ramanthan explains, “The same people who worked within the government to set the framework for Aadhaar went on to create products in the private sector to harness its commercial potential – a clear case of conflict of interest.”

Pro-Aadhaar trolls

Sharma’s admission is a reference to allegations first made by Internet Freedom Foundation co-founder Kiran Jonnalagadda. Jonnalagadda had pointed out that earlier in the month a number of anonymous accounts had started harrassing him and others who had questioned Aadhaar, the Indian government’s programme to provide a 12-digit unique identity to more than 120 crore residents which is under challenge in the Supreme Court over privacy concerns.

The tweets swung from arguing that Jonnalagadda was being a hypocrite to going as far as alleging that a research organisation critiquing Aadhaar’s implementation was funded by Pakistan.

Denial & admission
Jonnalagadda examined some of the tweets and concluded, in a blog post, that at least one of the accounts was being run by iSpirt’s Sharad Sharma, who is quite well known within India’s tech industry. Speaking to the technology news website FactorDaily soon after, Sharma categorically denied that he was behind the “Confident_India” Twitter account and said that it was “some kind of silly frameup”.

Following this denial, Jonnalagadda added more details to his blogpost, including a leaked iSpirt presentation that referenced the organisation’s plan for handling criticism. One of the slides mentioned a group of iSpirt volunteers referred to as “swordsmen” who were placed under the category of “informed but trolling”, which Jonnalagadda took as further evidence that the organisation was involved in anonymous trolling. Again, iSpirt denied these allegations, saying that Jonnalagadda was misreading the leaked slide.


@Confident_India @criticrahul @Indiaforward2 @munshiji2017 @draveedian @Acitizen13 Here's the full story on #AadhaarTrollMafia. Read till the end. It's far more sinister than one rogue agent trolling

But on his apology on Tuesday, Sharma admitted that there were anonymous Twitter accounts operating beyond just his. “There was a lapse of judgment on my part,” he wrote. “I condoned tweets with uncivil comments.”


On my flight back from the US, I reflected on my recent behaviour on Twitter.... I unreservedly apologize to all who were hurt... more below
Sharma’s post says iSpirt’s governing council has set up a committee to investigate the issue and recommend a revision of the code of ethics and corrective actions. “They’ll decide and I will abide by their decision,” he added.

Sharma’s admission that he had been trolling critics received praise from Nandan Nilekani, the architect of the Aadhaar project, who said he would certainly take iSpirt to greater heights.


Bravo, Sharad! I am sure that the indefatigable @sharads will take iSPIRT to greater heights.



We welcome your comments at letters@scroll.in.