In 2009, I became extremely concerned with the concept of Unique Identity for various reasons. Connected with many like minded highly educated people who were all concerned.
On 18th May 2010, I started this Blog to capture anything and everything I came across on the topic. This blog with its million hits is a testament to my concerns about loss of privacy and fear of the ID being misused and possible Criminal activities it could lead to.
In 2017 the Supreme Court of India gave its verdict after one of the longest hearings on any issue. I did my bit and appealed to the Supreme Court Judges too through an On Line Petition.
In 2019 the Aadhaar Legislation has been revised and passed by the two houses of the Parliament of India making it Legal. I am no Legal Eagle so my Opinion carries no weight except with people opposed to the very concept.
In 2019, this Blog now just captures on a Daily Basis list of Articles Published on anything to do with Aadhaar as obtained from Daily Google Searches and nothing more. Cannot burn the midnight candle any longer.
"In Matters of Conscience, the Law of Majority has no place"- Mahatma Gandhi
Ram Krishnaswamy
Sydney, Australia.

Aadhaar

The UIDAI has taken two successive governments in India and the entire world for a ride. It identifies nothing. It is not unique. The entire UID data has never been verified and audited. The UID cannot be used for governance, financial databases or anything. It’s use is the biggest threat to national security since independence. – Anupam Saraph 2018

When I opposed Aadhaar in 2010 , I was called a BJP stooge. In 2016 I am still opposing Aadhaar for the same reasons and I am told I am a Congress die hard. No one wants to see why I oppose Aadhaar as it is too difficult. Plus Aadhaar is FREE so why not get one ? Ram Krishnaswamy

First they ignore you, then they laugh at you, then they fight you, then you win.-Mahatma Gandhi

In matters of conscience, the law of the majority has no place.Mahatma Gandhi

“The invasion of privacy is of no consequence because privacy is not a fundamental right and has no meaning under Article 21. The right to privacy is not a guaranteed under the constitution, because privacy is not a fundamental right.” Article 21 of the Indian constitution refers to the right to life and liberty -Attorney General Mukul Rohatgi

“There is merit in the complaints. You are unwittingly allowing snooping, harassment and commercial exploitation. The information about an individual obtained by the UIDAI while issuing an Aadhaar card shall not be used for any other purpose, save as above, except as may be directed by a court for the purpose of criminal investigation.”-A three judge bench headed by Justice J Chelameswar said in an interim order.

Legal scholar Usha Ramanathan describes UID as an inverse of sunshine laws like the Right to Information. While the RTI makes the state transparent to the citizen, the UID does the inverse: it makes the citizen transparent to the state, she says.

Good idea gone bad
I have written earlier that UID/Aadhaar was a poorly designed, unreliable and expensive solution to the really good idea of providing national identification for over a billion Indians. My petition contends that UID in its current form violates the right to privacy of a citizen, guaranteed under Article 21 of the Constitution. This is because sensitive biometric and demographic information of citizens are with enrolment agencies, registrars and sub-registrars who have no legal liability for any misuse of this data. This petition has opened up the larger discussion on privacy rights for Indians. The current Article 21 interpretation by the Supreme Court was done decades ago, before the advent of internet and today’s technology and all the new privacy challenges that have arisen as a consequence.

Rajeev Chandrasekhar, MP Rajya Sabha

“What is Aadhaar? There is enormous confusion. That Aadhaar will identify people who are entitled for subsidy. No. Aadhaar doesn’t determine who is eligible and who isn’t,” Jairam Ramesh

But Aadhaar has been mythologised during the previous government by its creators into some technology super force that will transform governance in a miraculous manner. I even read an article recently that compared Aadhaar to some revolution and quoted a 1930s historian, Will Durant.Rajeev Chandrasekhar, Rajya Sabha MP

“I know you will say that it is not mandatory. But, it is compulsorily mandatorily voluntary,” Jairam Ramesh, Rajya Saba April 2017.

August 24, 2017: The nine-judge Constitution Bench rules that right to privacy is “intrinsic to life and liberty”and is inherently protected under the various fundamental freedoms enshrined under Part III of the Indian Constitution

"Never doubt that a small group of thoughtful, committed citizens can change the World; indeed it's the only thing that ever has"

“Arguing that you don’t care about the right to privacy because you have nothing to hide is no different than saying you don’t care about free speech because you have nothing to say.” -Edward Snowden

In the Supreme Court, Meenakshi Arora, one of the senior counsel in the case, compared it to living under a general, perpetual, nation-wide criminal warrant.

Had never thought of it that way, but living in the Aadhaar universe is like living in a prison. All of us are treated like criminals with barely any rights or recourse and gatekeepers have absolute power on you and your life.

Announcing the launch of the # BreakAadhaarChainscampaign, culminating with events in multiple cities on 12th Jan. This is the last opportunity to make your voice heard before the Supreme Court hearings start on 17th Jan 2018. In collaboration with @no2uidand@rozi_roti.

UIDAI's security seems to be founded on four time tested pillars of security idiocy

1) Denial

2) Issue fiats and point finger

3) Shoot messenger

4) Bury head in sand.

God Save India

Showing posts with label Mathew Thomas. Show all posts
Showing posts with label Mathew Thomas. Show all posts

Saturday, January 20, 2018

12693 - Who Is Running the ‘Orchestrated Wine And Cheese Campaign’ Against Aadhaar in the SC? - The Wire

Who Is Running the ‘Orchestrated Wine And Cheese Campaign’ Against Aadhaar in the SC?

Defenders of Aadhaar have called opposition to it an organised campaign stemming from paranoia. But a look at the petitioners proves it is anything but.

One cannot confirm if any of these petitioners, who have all submitted bulky petitions, do in fact drink wine or/and eat cheese. Credit: File photo

New Delhi: Just last week, UIDAI’s former chairman Nandan Nilekani called the opposition to Aadhaar, an “orchestrated campaign”. A few days before that, an editorial in an Indian news portal said the opposition comes from “activists of the upper crust, upper class, wine ‘n cheese, Netflix-watching social media elite – mostly of the Left”.

And in an interview with The Wire last year, former Attorney General Mukul Rohatgi said, “This paranoia is coming from a few people in a country of 150 crore.”

Nilekani, the architect of the Aadhaar project, has also spoken at length in reference to a major story in The Tribune that took on global resonance on how India’s entire Aadhaar database is being breached and leaked through various vendors.

Among the more prominent faces at the helm of the fight is one Padma Shri awardee, three Ramon Magsaysay awardees, three former Indian army personnel, a retired high court judge, a parliamentarian and the entire government of West Bengal.

And yet who are these people who apparently “drink wine, eat cheese”, and also make a commitment to the Supreme Court to spend money and time (over six years for some), only to spite Nilekani’s Aadhaar project?

The protesters
A look at the 30 challenges filed before the Supreme Court and the people behind them casts doubts on the accusations that the ‘wine and cheese’ lot have no understanding of base realities.

In fact, by simply looking at the various sections of society those opposed to the project belong to, it becomes clear that this isn’t an organised and ‘orchestrated’ campaign, but a motley bunch of individuals who have been tagged together by the Supreme Court on a now bloated Aadhaar petition. The earliest petition (by retired Justice Puttaswamy) has been plodding along for six years, since 2012, and 11 others out of the 30, joined the fight the very next year.


One cannot confirm if any of these petitioners do in fact drink wine or/and eat cheese, but from reading their bulky submissions, they appear have committed themselves to a cause that they truly believe interferes with the lives of the Indian people.

Justice (retired) Puttaswamy: At 92, Puttaswamy is one of the oldest living petitioners in the Supreme Court, and the oldest petitioner in the Aadhaar case. He was born in 1926 and enrolled as an advocate in 1952. By 1977, he was appointed a judge of the Karnataka high court. His challenge, a path he put himself on in 2012, is the first challenge to the Aadhaar case. The now historic privacy judgement delivered in August 2017, takes its name from his challenge.

Bezwada Wilson: Wilson has been the driving force behind India’s efforts at providing dignity, security and emancipation to manual scavengers who risk their lives while cleaning drains and latrines. Manual scavengers, who largely belong to the ‘lower caste’ in India, face stigma and exclusion. Wilson is not new to long-fought and hard-won public interest litigations and has fought a case which led to the government to pass laws for the prohibition of the employment of manual scavengers. In 2016, he received the Ramon Magsaysay award.

Major General (retired) SG Vombatkere: Vombatkere retired as a major general of the Indian Army after 35 years of service. He is now over 70 was awarded the Visishta Seva Medal by the President of India in 1993. He is a key petitioner in this case along with Bezwada Wilson. Their submission says it is “wider” than Puttaswamy’s and calls for the Aadhaar Act to be declared a violation of Article 14, 19 and 21 of the Indian constitution and asks that no one be denied any service on account of Aadhaar. They have also asked the court to direct that all data collected under Aadhaar by the public and private sector be destroyed. They have challenged the National Population Register and Aadhaar’s link.

Shantha Sinha: Shantha Sinha was the first chairperson of the National Commission for Protection of Child Rights and served two consecutive terms (2007 to 2013). She has also been on various other government committees on national integration, right to education, mid-day meals and adult education. Her work on the ground in Andhra Pradesh was directed at rescuing children from child labour and admitting them to government schools. She also received the Ramon Magsaysay award in 2003 and the Padma Shri in 1998.

Kalyani Menon Sen: Sen is a feminist scholar and has been an activist for women’s rights for over 25 years. She has worked with the United Nations Development Programme, advising on gender related issues. Sinha and Sen are co-petitioners in their case. Some of their prayers are similar to Wilson’s and Vombatkere’s. They’ve also moved court seeking that “accounts of current bank account holder will not be made in-operational and future applicants will not be coerced to submit their Aadhaar numbers.” They’ve petitioned the court similarly for the government’s order on linking mobile numbers to Aadhaar.

Aruna Roy: Roy was briefly a bureaucrat in the Indian Administrative Service (1968 to 1975) but resigned and is now known for her nearly 40 years of work with the rural poor in Rajasthan and ‘Mazdoor Kisan Shakti Sangathan’ which she runs. She was also a key figure in the movement which led to India passing the Right to Information Act as well as the Right to Food. She was a member of the UPA’s National Advisory Council for five years and was instrumental in the passage of the Mahatma Gandhi National Rural Employment Guarantee scheme. Along with Wilson and Sinha, Roy has also received the Ramon Magsaysay award.

Nikhil Dey: Dey is a long-time colleague of Aruna Roy, a co-founder of the ‘Mazdoor Kisan Shakti Sangathan’ and a co-petitioner with her on this case. With Roy, he too has worked on the right to information, food and employment in India. Their petition saw every state and union territory of India being made a respondent. “The present experimentation would undoubtedly result in social exclusion by depriving persons of the fundamental rights and also putting at stake vast sums of tax payer’s money,” says their petition.

Major General (retired) SCN Jatar: Jatar served with the Indian Army from 1954. He commanded an engineer regiment in India’s 1971 war in the Poonch Sector (Jammu and Kashmir) and was the commander of infantry brigades in the Kashmir Valley and Rajasthan dessert, from 1977 to 1981. He has been appointed to several government committees and was also the Chairman at ONGC Videsh Limited and Oil India. His petition saw the Election Commission and Reserve Bank of India appear as respondents.

Colonel (retired) Mathew Thomas: Thomas, who is around 80, retired as Colonel from the Indian Army and has seen military action in Nagaland, China and Pakistan. In 2014, he was invited to address a BJP parliamentary panel, where he explained various issues around the Aadhaar scheme. He has asked the court to direct an investigation into the role of foreign and private companies in the collection of biometric data of Indians.

Supporting material in the form of research has been submitted to the court by Reetika Khera (professor at IIT Delhi), Jean Dreze (co-author with Amartya Sen of An Uncertain Glory: India and its Contradictions), Jude Terence D’souza (securities system specialist in Mumbai), Anand Venkatanarayanan (data security expert in Bangalore), Samir Kelkar (security consultant) and Anumeha Yadav (journalist, formerly at Scroll.in).


Liked the story? We’re a non-profit. Make a donation and help pay for our journalism.

Sunday, November 5, 2017

12290 - Is Aadhaar Act valid? Supreme Court to hear plea today - Live Mint


The Supreme Court on Thursday agreed to hear a plea challenging the validity of the Aadhaar Act and privacy concerns surrounding the 12-digit unique identity number


New Delhi: The Supreme Court on Thursday agreed to hear a plea challenging the validity of the Aadhaar Act and privacy concerns surrounding the 12-digit unique identity number.
The matter was brought before a bench headed by justice J. Chelameswar, who said that it would be heard on Friday—along with other petitions challenging Aadhaar’s mandatory linking with bank accounts and mobile phone numbers.

The plea was brought by Karnataka-based Mathew Thomas, who has challenged the validity of the 2016 Act, citing privacy concerns and reports that the biometric system was not working properly.

On 30 October, the apex court referred all Aadhaar cases to a five-judge Constitution bench to be formed by the end of November.

The directive was passed by a bench headed by chief justice Dipak Misra after it was informed by the centre of its unwillingness to extend the deadline for linking Aadhaar to various schemes to 31 March and requesting a hearing instead.

First Published: Thu, Nov 02 2017. 01 54 PM IST

12288 - Supreme Court to hear plea challenging validity of Aadhaar Act tomorrow - TNN

Supreme Court to hear plea challenging validity of Aadhaar Act tomorrow


PTI | Nov 2, 2017, 12:44 IST


HIGHLIGHTS
  • The counsel representing the petitioner sought an urgent hearing, saying similar pleas were already listed for hearing before the apex court on Friday.
  • Karnataka-based Mathew Thomas moved the top court challenging the constitutional validity of the Aadhaar Act claiming that it infringes upon the Right to Privacy.
NEW DELHI: The Supreme Court on Thursday agreed to hear a petition challenging the constitutional validity of the Aadhaar Act on Friday. 

The matter was mentioned before a bench headed by Justice J Chelameswar and the counsel representing the petitioner sought an urgent hearing, saying similar pleas were already listed for hearing before the apex court on Friday. 

Karnataka-based Mathew Thomas moved the top court challenging the constitutional validity of the Aadhaar Act claiming that it infringes upon the Right to Privacy and that the biometric mechanism was not working properly. 

On October 30, a bench headed by Chief Justice Dipak Misra had said that a Constitution bench would be constituted and Aadhaar-related matters would come up for hearing before it in the last week of November. 

Several petitions challenging the Centre's move to make Aadhaar card mandatory for availing various services and benefits of government welfare schemes have been filed in the apex court. 

Recently, a nine-judge constitution bench of the apex court had held that Right to Privacy was a Fundamental Right under the Constitution. Several petitioners challenging the validity of Aadhaar had claimed it violated privacy rights.

The Centre had on October 25 told the Supreme Court that the deadline for mandatory linking of Aadhaar to receive the benefits of government schemes has been extended till March 31, 2018 for those who do not have the 12-digit unique biometric identification number and were willing to enroll for it.

Some petitioners in the top court have termed the linking of the Unique Identification Authority of India (UIDAI) number with bank accounts and mobile numbers as "illegal and unconstitutional".

TOP COMMENT
Adhar Mustn''t stop this is one of the revolutionary system for new India.
Francis Bourne trading

They also objected to the CBSE's alleged move to make Aadhaar card mandatory for students appearing for examinations, a contention denied by the Centre.

One of the counsel representing the petitioners had earlier said that final hearing in the main Aadhaar matter, which is pending before the apex court, was necessary as the government "cannot compel" citizens to link their Aadhaar with either bank accounts or cell phone numbers.

12258 - Scrap Aadhaar, it’s snatching away our right to food, privacy: Citizens - TNN



tnn | Updated: Oct 27, 2017, 07:52 IST

BENGALURU: "The lines on our fingers have faded due to the nature of work and it is the only source of income for our families. But the ration shop dealer is turning us away saying our biometric data does not match," rued 60-year-old Jayamma, an agarbatti maker living in Samil slum of Cottonpet. 

She was one among the many aggrieved members from marginalized communities who took part in the public hearing on Aadhaar-related denial of social security held here on Thursday and aired their woes. 

Organized by the Right to Food (RTF) campaign, an informal network of individuals and organizations committed to the realization of the right to food in India, the hearing sought to bring to light the exclusionary nature of Aadhaar and its misuse to systematically isolate the needy despite repeated Supreme Court orders reiterating its voluntary nature. 

Jayamma complained that introduction of the biometric system to verify beneficiaries at ration stores has turned her life miserable. She hasn't received her share for the past two months. "The ration shop dealer is also threatening us with cancellation of the card if we don't get the issue rectified but several trips to the food commissioner's office yielded no results," she said. 

Chandrika, a 39-year-old woman who has been living with HIV for the past 20 years, is facing a different problem. She pointed out that making Aadhaar mandatory to avail the life-saving antiretroviral (ART) therapy is in violation of the right to privacy. "We have the right to confidentiality about our status. Many people like me have stopped using this drug because our treatment, if linked with Aadhaar, would reveal our HIV status. We live in a society where there's a lot of stigma and discrimination against persons living with HIV/AIDS. I reject Aadhaar as it goes against my right to life," she said. 

With the provisions of rations, medical care in case of serious conditions like cancer, tuberculosis, HIV-AIDS, midday meals, pensions, gas connections, abortions, sonograms and even death certificates being dependant on Aadhaar seeding and linking, most beneficiaries have been made to run from pillar to post. Violation of privacy and overarching threat of constant surveillance are the concern for the middleclass urban citizens. 

Aggrieved citizens from Ramanagara, Kolar, Belagavi, Tumakuru and Chikkaballapura put their 'testimonies' before a panel of experts for their adjudication. A compilation of complaints and recommendations will be placed before the SC as it begins hearing from October 30.

Usha Ramanathan, legal expert and scholar, said the reports by the Unique Identification Authority of India (UIDAI) itself suggested that biometric information was unsuitable for authentication. "They themselves have admitted that using biometric information to verify anyone's identity is faulty, making it much worse for daily wager workers. Now that we know it's a failure, why can't we go back to a system that works for the public? The administration should administer in accordance with the law," she said. 

TOP COMMENT
Of course, ''Col Thomas Mathews'' would have a problem with Aadhar. Predictable scum. So what if fingerprints have faded (if at all - as per numerous studies, fingerprints don''t change their unique ... Read More
S R


Don't punish beneficiaries 
The Right to Food is a fundamental one but it is being sabotaged and misused because of this sham identification mechanism. If the government says it is to remove fake and ghost cards from the system, they also need to investigate criminals who allowed this malpractice in the first place, instead of punishing beneficiaries. Form a special investigation team for this

-Col. Matthew Thomas, petitioner in the right to privacy case and RTI activist. 

Wednesday, September 6, 2017

11979 - AADHAAR, DATA SECURITY AND BREACH OF PRIVACY - DAILY PIONEER


Tuesday, 05 September 2017 | Sandhya Jain | in Edit


An RTI reply has punctured the UIDAI's assertion that no private entity had access to unencrypted Aadhaar data. While it is not clear who controls the data; certainly it is prone to misuse
A Right to Information (RTI) application filed by Bengaluru-based Col  Matthew Thomas, a petitioner in the right to privacy case before the Supreme Court, reveals that the Unique Identification Authority of India (UIDAI), custodian of Aadhaar data, signed contracts with foreign firms giving them “full access” to classified data and personal details of citizens, which they were allowed to store for seven years.

The Centre must direct the UIDAI to make a full disclosure of the project since its inception, including contracts signed, and who selected the firms recruited for the task. The then UIDAI chairman  Nandan Nilekani must explain why the technology (hardware and software) for collecting and storing the data was not created domestically when India is supposed to be the hub for information technology services.

The RTI reply punctures the UIDAI’s assertion that no private entity had access to unencrypted Aadhaar data. The contract with US-based biometric service provider, L-1 Identity Solutions Operating Company Private Limited (now owned by French transnational Safran Group), clearly says that the firm was given Aadhaar data access “as part of its job”. Other firms given identical contracts from 2010 to 2012 include Morpho and Accenture Services Private Limited.

In 2014, Prime Minister Narendra Modi was persuaded that Aadhaar could expand the reach of his social welfare programmes exponentially. But recently, when data breaches became glaring, Nilekani dismissed the problem saying data security is challenging in a digital age and ran back to his parent company. The unanimous verdict of the nine-judge bench of the Supreme Court, upholding right to privacy as a fundamental right, reportedly reflects this belated understanding at the top echelons of the Government.

The contract’s Clause 15.1, ‘Data and Hardware’, says the firm “may have access to personal data of the purchaser (UID), and/or a third party or any resident of India...” Clause 3, which deals with privacy, says the biometric service provider could “collect, use, transfer, store and process the data”. Also, the biometric service provider shall process all personal data in accordance with applicable law and regulation and should not disclose such information. The contract does not define ‘personal data’.

However, according to UIDAI, personal data includes biometric (fingerprints, iris) and demographic data (name, date of birth, address, mobile number), and could include bank details, licence number, PAN number, passport number and other information furnished as part of Know Your Customer (KYC). A clause in the contract says the firm should maintain the biometric template created by it and on termination or expiry of contract, “transfer all the proprietary templates to UIDAI”.

The UIDAI claimed it had purchased the software and hardware for the Aadhaar programme but the contracts show that the biometric service providers provided hardware for the first one crore enrollments. It is not known if the hardware was checked to ascertain if data could be stolen via a back door. UIDAI’s assertion that no data ever left its servers and premises cannot be trusted as the language of the contracts clearly shows that foreign firms had access to raw data.

But is this surprising? In a Forward to a Credit Suisse study (Ideas Engine Series, June 29, 2016), Nilekani wrote, “Once in a while a major disruption or discontinuity happens which has huge consequences. In 2007, the Internet and the mobile phone came together in a whole new product called the smartphone... (which) could support Over The Top applications. The messaging solution for the smartphone…came from WhatsApp, a start-up”.

Nilekani argued that Indian banking is experiencing a ‘WhatsApp’ moment, as smartphones could reach 700 million by 2020 and over one billion Indian residents have the online biometric identity, Aadhaar. Hence it is possible to “visualise a future where every adult Indian has an Aadhaar number, a smartphone and a bank account”.

More insidiously, Aadhaar provides on-line authentication using fingerprint or iris, which can be done from anywhere, making transactions ‘presence-less’. Aadhaar’s eKYC feature enables a bank account to be opened instantly by using one’s Aadhaar number and biometric; something prone to misuse. In Jammu & Kashmir, illegal immigrants (Rohingyas) have acquired Aadhaar and ration cards.

Extolling many facets of the new technology (the India Stack), Nilekani states, “as data becomes the new currency, financial institutions will be willing to forego transaction fees to get rich digital information on their customers (italics added)”. This would accelerate the move to a cashless economy as merchant payments will also become digital.

Commending Credit Suisse’s “insightful report”, Nilekani agrees that there is a $600 billion market capitalisation opportunity possible in the next 10 years, which will be shared between existing public and private banks, new banks and new age non-bank financial companies (NBFCs). “It may even go to non-banking platform players, which use the power of data to fine-tune credit risk and pricing, and make money from customer ownership and risk arbitrage”. He expects a serious challenge to public sector banks which currently enjoy a 70 per cent market share.

The Payment Bank (Paytm), launched in 2016 (Alibaba holds 40 per cent stake), and the Unified Payment Interface (UPI)-powered payment interfaces, hope to encash the shift towards digital transactions, and get their share of the coveted $ 600 billion pie. Credit Suisse anticipates that private banks, NBFCs’ and fin-tech players will be its prime beneficiaries.

Credit Suisse explains that financial providers will become data rich in just two or three years as they receive data via transactions made through their apps, digital footprints left by individuals, smartphone data and online tax information, as three  to five billion invoices go digital with the Goods and Services Tax. Forecasting consumer debt to rise to 25 per cent of the gross domestic product from the current 17 per cent on the back of new data availability, the SME lending market could grow from $620 billion to $3,020 billion over the next decade. Aadhaar seems tailored to benefit private bankers.

This writer was invited to enroll for the National Population Register vide acknowledgement slip 130, form number 02046115, household block no. 0021, household number 128, by Enumerator OP Singh, dated May 26, 2010. Aadhaar was supposedly for BPL beneficiaries. It turned out they were one and the same.

Now, it is not clear who controls the data; certainly it is prone to misuse. The Sonia Gandhi-led UPA regime unleashed this menace through lies and deception. The Modi-led Government must fix this treachery. No country in the world has allowed bankers and corporations such totalitarian access to intimate data about its citizens.

(The writer is a political analyst and an independent researcher)

Friday, September 1, 2017

11942 - Foreign firms had access to unencrypted Aadhaar data, reveals RTI - Times Now


Aug 30, 2017 | 17:39 IST | by Times Now, TNN Reports

Bengaluru: The government’s Aadhaar push received a massive jolt a few days ago when the Supreme Court declared Right to Privacy as fundamental under Article 21 of the Constitution.

While the privacy judgement came as a blow to the government, putting its Aadhaar mandate at risk, a right to information plea has now revealed a major flaw.


Begaluru-based RTI activist Col Matthew Thomas, who filed the RTI, said the Unique Identification Authority of India (UIDAI), responsible for storing biometric Aadhaar data, signed contracts with foreign firms earlier to give them “full access” to classified data such as fingerprints, iris scan info, and other personal information like date of birth, address and mobile number of the card holders or applicants.

They were also allowed to store all the data for seven years, reported The Times of India. The RTI was filed by one of the petitioners in the Aadhaar privacy case.

Contrary to the UIDAI’s previous statement, which stated that no private entity had access to unencrypted Aadhaar data, the RTI reply made it clear that some of the rules regarding data sharing were violated.


As per the reply, the contract with one of the biometric service providers (BSPs), US-based L-1 Identity Solutions Operating Co Pvt Ltd – now taken over by French transnational Safran Group) - was given access to Aadhaar database “as part of its job”.

Two others firms, Morpho and Accenture Services Pvt Ltd were given identical 2-year accessibility contracts from 2012 to 14’.

As per Clause 15.1 of the contract awarded to these foreign entities, titled ‘Data and Hardware’, the companies had access to personal data of the “purchaser” or the applicant. 


By virtue of the contract, firms “may have access to personal data of the purchaser (UID), and/or a third party or any resident of India..."
In addition, Clause 3 of the contract that deals with privacy, highlighted that BSP could “collect, use, transfer, store and process the data".
The contract further empowered the BSPs to “process all personal data” in accordance with applicable law and regulation, but barred them from disclosing such information elsewhere. The contract, however, does not discuss what it means by ‘personal data’.
An advocate who explained the contract to TOI, said, “If the contract does not define it, then we must go by the definitions given by UIDAI as part of the project."
In such a scenario, the UIDAI defines ‘personal data’ as biometric (fingerprints and iris) and demographic data (name, date of birth, address, mobile number). Demographic data may also furnish other information such as bank details, licence number, PAN number, passport number, and other KYC details.
The UIDAI, in one of the clauses mentioned in the identical contracts awarded to the companies, said that in the event of termination or expiry of contract, the firms "shall transfer all the proprietary templates to UIDAI".
In view of this, the RTI activist Thomas slammed the UIDAI and questioned them. “If the fir,s did not have any biometric data, what were they (the companies) expected to transfer? Why can't the UIDAI just come out in the open with all the contract details?"
The UIDAI maintains that it had purchased all the software and hardware for the rollout of Aadhaar programme, but the contracts establish that BSPs were responsible for providing hardware for the first one crore enrolments

Thursday, August 31, 2017

11934 - RTI activist says Aadhaar contract gave foreign firms access to unencrypted data - TNN


Chethan Kumar | TNN | Aug 30, 2017, 02:40 IST

HIGHLIGHTS
  • Contracts signed with foreign firms by UIDAI show that they got “full access” to classified data
  • This was revealed through an RTI application filed by Bengaluru-based Col Matthew Thomas

BENGALURU: Contrary to the Centre's claims, contracts signed with foreign firms by the Unique Identification Authority of India (UIDAI), custodian of Aadhaar data, show that they got "full access" to classified data including fingerprints, iris scan info, and personal information like date of birth, address and mobile number of the applicants. They were also allowed to store the data for seven years. 

This was revealed through an RTI application filed by Bengaluru-based Col Matthew Thomas, one of the petitioners in the right to privacy case currently being heard in Supreme Court. 

The RTI reply showed that the nature of the contracts contradicted UIDAI's statements that no private entity had access to unencrypted Aadhaar data. The contract with one of the biometric service providers (BSPs), L-1 Identity Solutions Operating Co Pvt Ltd, headquartered in US, says that the company was given Aadhaar data access "as part of its job". (L-1 has been taken over by French transnational Safran Group). Morpho and Accenture Services Pvt Ltd are two other firms that were given identical contracts with two year (2010 to 2012) Aadhaar data access. 

Clause 15.1 of the contract, titled 'Data and Hardware', says that the firm, by virtue of the contract "may have access to personal data of the purchaser (UID), and/or a third party or any resident of India..." Further, Clause 3, which deals with privacy, says that the BSP could "collect, use, transfer, store and process the data". It also says that the BSP shall process all personal data in accordance with applicable law and regulation and should not disclose such information. The contract, however, does not define 'personal data'. 


An advocate familiar with the subject explained: "If the contract does not define it, then we must go by the definitions given by UIDAI as part of the project." According to UIDAI, personal data includes both biometric (fingerprints and iris) and demographic data (name, date of birth, address, mobile number). The latter may also include bank details, licence number, PAN number, passport number and other information furnished as part of KYC.

Another clause in the contract says that the firm should maintain the biometric template created by it and that in the event of termination or expiry of contract, it "shall transfer all the proprietary templates to UIDAI". Col Thomas says: "If the firms did not have the biometric data, what were they expected to transfer? Why can't the UIDAI just come out in the open with all the contract details?" Though UIDAI maintained that it has purchased the software and hardware to roll out the Adhaar programme, the contracts show that the BSPs were responsible for providing hardware for the first one crore enrolments.

TOP COMMENT
so Aadhar is tool prepared for selling 1ndia on whole sale rate at international market by compromising country''s wealth.
So we are sold.. isn;t it.?
Be U

A cyber expert said: "If the hardware is also installed by the firms, then there must have been thorough checking to see if they contained anything that could steal data." UIDAI has said that no data ever left its servers and premises and every bit of information is safe and secure.

Ravi Visvesvaraya Prasad, a telecom and IT expert, said, "One cannot check for duplication without having raw data. If foreign firms had access to such data, as is clear by the language in the contract, it is potentially dangerous and needs to be looked into." 

Monday, July 10, 2017

11591 - Aadhaar Crime Bomb - India Legal


July 8, 2017

 Access to basic services like health and education will also be determined by biometric scans.

The government’s decision to link these vital numbers to bank accounts could trigger a wave of economic offences. It is time this decision that threatens the banking system is reviewed
~By Ajith Pillai

Is India sitting on an Aadhaar crime bomb that will soon begin ticking? Imagine a scenario where money is transferred from your account into another or vice versa by an unknown entity without your knowledge; when your fingerprint is placed at a scene of a serious crime to implicate you; when criminals track virtually all your activities and plot their next move; when foreign funds are transferred into your bank with devious intent and you find your account blocked pending investigations into your mysterious source of foreign monies…. All this and much more is very much in the realm of possibility thanks to your 12-digit Aadhaar number.

And to speed us on the risk-prone biometric highway is the June 1, 2017 notification (No2/F. No P. 12011/11/2016-Es Cell-DOR) of the Department of Revenue under the Finance Ministry which makes it compulsory for account holders to link their accounts with their PAN and Aadhaar numbers before December 31. 2017. Companies too will have to submit the same identification numbers to the banks, of their board members or those who have been authorised to transact business on their behalf.
Many cyber security experts are of the view that the Unique Identification (UID) programme, launched in 2010, has evolved dangerously and will become a veritable password for those indulging in a range of cyber-related crimes. At the receiving end will be ordinary Indians who now have to furnish the number for virtually every activity of their daily life—from buying a cellphone to opening a bank account.


Illustration: Anthony Lawrence

To them, and to a sizeable section in the police, cyber-crime is an alien concept and the government’s reluctance to accept glitches in the UID programme has not helped. But despite all the apprehensions and a clutch of pending petitions in the Supreme Court relating to the validity of the scheme and privacy concerns, the government has been doggedly pushing ahead with ushering in a biometric revolution of the kind the world has hitherto not seen.

Initially meant to provide an identity for the poor and to ensure that there are no leakages in money transfers under various welfare schemes, the Aadhaar net has been widened to encompass virtually every aspect of life. School admissions, mid-day meal schemes, driving licences, pensions, income tax payments, rail and air tickets and soon, opening a bank account or maintaining one, will require the person’s Aadhaar number.
And each time one shares a number with a new agency/service platform, the number of points from which personal data can be accessed by undesirable elements multiplies. And once the data thief gains access to the data, which includes facial image, image of the iris and fingerprints, he can access the respective bank account because it will be linked to the Aadhaar card.
A copy of a fingerprint is all that will be required to effect transfers or payments into another account using the Bhim app or a point of sale (POS) machine which requires only a fingerprint as proof and bypasses the need to swipe a debit or credit card. The Bhim app, introduced to facilitate cashless transfers by the unlettered, necessitated the need to link UID numbers and data to banks. Now the government has mandated that all accounts holders must also be linked through Aadhaar.


Then PM Manmohan Singh and Congress leader Sonia Gandhi launching the Aadhaar number in Nandurbar, Maharashtra, in 2010. Photo: PIB

This gives a different dimension to data theft as it can facilitate serious financial fraud. It is no longer just about big corporations mining data to size up your credit rating or spending patterns to focus and target their marketing efforts. Neither is it about the CIA keeping a tab on India’s demographics. What we are talking about is an invasion of privacy which may come with a huge criminal quotient and could impact every citizen.



The dividends from data mining are so huge and the implications so varied that this has already begun. It will not be long before the crimes start. Here are some pointers which also reveal how data is not secure with the government:
  • On February15, 2017, the Unique Identification Authority of India (UIDAI) which is mandated to implement the Aadhaar scheme reportedly filed cases against employees of Axis Bank, Suvidha Infoserve and e-Mudhra for attempting unauthorised authentication and impersonation by illegally storing Aadhaar biometrics. The security breach came to light after 397 fake biometric transactions were carried out in five days of February.
  • On February 18, the Hindi news daily Dainik Bhaskar reported the arrest of six salespersons of telecommunications service provider Reliance Jio in Madhya Pradesh for selling SIM cards at inflated prices by using the Aadhaar data and fingerprint scans of other customers.
  • In April this year, the Aadhaar details of one lakh pensioners in Jharkhand who had seeded their UID numbers to bank accounts was freely available on the website of the Jharkhand Directorate of Social Security. A few days later, a leading national daily found that “secured” data was available on the websites of a scholarship database in UP; the PDS website of the Chandigarh administration; a pensioners’ listing in Kerala and the Swachh Bharat Mission.
  • A report released in May 2017 by the Centre for Internet and Society, a Bangalore-based organisation looking at multi-disciplinary research and advocacy in internet use, reveals that in the past few months, data of 13.6 lakh citizens was leaked from four major government data bases, including the portals of NREGA and National Social Assistance Programme.
  • A note generated on March 25 by an official of the Ministry of Electronics and Information Technology accessed by the New Indian Express, confirmed that biometric data was not secure. “There have been instances wherein personal identity or information of residents, including Aadhaar number and demographic information and other sensitive personal data such as bank account details etc. collected by various Ministries/Departments… has been reportedly published online and is accessible through an easy online search,” said the note displayed on the front page of the newspaper. The same ministry on March 5 had issued a statement that the Aadhaar data was absolutely secure.
The financial misuse of data has not been lost on experts. Sunil Abraham, executive director of CIS, has been quoted as saying: “Biometrics is an inappropriate technology for financial services. Linking Aadhaar, which has your biometric data, with bank accounts makes you a lot more vulnerable to financial frauds than before. Your fingerprint can easily be collected at a restaurant or any other public place and can be used to steal your identity and commit frauds. The government needs to rethink its use for Aadhaar as it will impact over a billion people.”

The Foreign Hand
In 2010-2012, Unique Identification Authority of India (UIDAI) awarded contracts for biometric profiling to three US-based Biometric Solution Providers (BSPs). These were—L-1 Identity Solutions, Morpho-Safran, and Accenture Services Pvt. Ltd. All three reportedly have business contracts with US, British and French intelligence agencies. There are also reports in the international media of former intelligence operatives in the employment of these companies and their subsidiaries.
The companies, as per the contract, were given Rs 20 crore each by UIDAI for their services. The charges paid per card was Rs 2.75.
This money went to foreign companies. The UID programme was not an indigenous effort as claimed by Nandan Nilekani, chairman of the UIDAI, when it was launched and the contracts with the foreign companies were signed.
The UIDAI has often made statements that the data collected is encrypted and inaccessible to the BSPs. But the contract with the three companies, accessed by an RTI activist, shows that they had access to unencrypted biometric data. As part of their contract, these BSPs had to weed out duplicate applications. This involved comparing the biometric data of all applicants which necessitated access to it.
It is not known whether the mass of biometric data was copied and stored abroad or sold. But given the demand for data, the possibility of this having happened cannot be ruled out. Also, one cannot say with certainty that it will not be put to use in future by intelligence agencies or exploited by corporates.
Clause 4.1.1 of Annexure ‘E’ of the contract admits that demographic data is inaccurate. Despite RTI requests, UIDAI has refused to provide Annexures ‘I’, ‘J’ and ‘K’ of its contracts with Biometric Solution Providers. It has even refused to comply with the orders to do so by the Chief Information Commissioner, citing security reasons. These annexures give the technical bids of the contractors which would specify the limitations.

Prashant Pandey, who knows a thing or two about cyber security and was the whistle-blower in the Vyapam scam, fears that the linking of Aadhaar cards to bank accounts could lead to serious frauds. He told India Legal: “Just imagine a trickster operating from outside India with leaked Aadhaar database and hundreds of POS machines with the biometric payment system, Bhim. He can pull money out from bank accounts to an anonymous destination abroad. The possibilities are immense unless security is tightened and data secured.”
Professor Anupam Saraph, an expert in governance of complex systems, describes the linking of Aadhaar to bank accounts as a move which will “enable benami bank accounts and scale benami transactions to destroy the Indian economy along with the Indian banking system”.

“The Aadhaar number is for all residents in India. It cannot hence, serve as ID for Indian citizens. It is not an ID card, but a number in a database. Every time people have to be identified, identification is needed by scanning biometrics from the UIDAI database, which is impractical.”
                                                                                             —Colonel Thomas Mathew, anti-Aadhaar campaigner
In his blog, Saraph lists several reasons why he feels the Aadhaar-bank account linking is dangerous. Innocent account holders, he notes, will find their UID numbers being used as “mules for money laundering”. Or their payments under government schemes easily compromised by tricksters. Worse, they can be “framed for economic offences” if someone deliberately transfers illegal money into their accounts. This, in turn, would lead to harassment and accounts being frozen pending investigation.
But how can fingerprints be copied and misused? Pandey pointed to the example of the Vyapam entrance examination scam for MBBS in Madhya Pradesh. Here, qualified persons fronted for the real candidates and wrote the exam on their behalf despite fingerprint scanners being used before allowing access into the examination hall. How were the scanners fooled? “The fake candidates merely copied the fingerprints of the real candidates on a silicon film and wore it on their thumb. This happened in not one or two cases but in several hundreds of them. What happened in Vyapam is proof of how unreliable fingerprint identification is,” he said.

Fingerprints from the Aadhaar database, once accessed, can easily be copied and used to implicate someone in a crime. Pandey believes it is a real possibility. “Your fingerprint can be placed at the scene of a crime by vested interests who can frame you with the help of the police. The prospect of misuse is frightening,” he said. Pandey hopes to demonstrate how Aadhaar data can be misused before the apex court.
Noted human rights activist and senior Supreme Court lawyer Indira Jaising said that privacy concerns are not to be taken lightly. She told India Legal: “As a citizen, why should I surrender all my personal details to the government so that it can be misused against me? Why should people know which hospital I go to or which school my child attends? Why should they know where I am travelling to or on which airline I have booked my tickets? Once all my activities can be mapped, the information can be used to perpetrate a crime against me. Why should I allow that?”
However, those who endorse the UID scheme brush aside privacy concerns by saying that such apprehensions reside only in the minds of those who are involved in illegal activity or have unaccounted wealth and would not like their bank transactions to be monitored. However, what is missed out is that there are already enough ways to keep tabs and there is no need to store personal data which can easily be stolen. “As for Aadhaar providing biometric proof of identity, the less said the better,” said Colonel Thomas Mathew, a Bangalore resident and one of the first to file a civil suit in the apex court against Aadhaar.
“The UID/Aadhaar number is for all residents in India (who could also be outsiders on an extended visa). It cannot hence, serve as an ID for Indian citizens. It is not an ID card, but a number in a database. The UID scheme envisages that people would be identified every time identification is needed, by scanning biometrics and querying the UIDAI database. This is impractical. UIDAI itself admits that demographic data is inaccurate. If demographic data is unreliable, UID cannot be proof of ID,” Mathew told India Legal.



As for the fallibility of biometric data, he quotes the 2010 study titled “Biometric Recognition—Challenges and Opportunities” by four US national academies—the National Academy of Sciences, the National Academy of Engineering, the Institute of Medicine and the National Research Council.
The first principal finding of the research was that “biometric recognition is inherently probabilistic and hence, inherently fallible”. According to estimates, under field conditions, the false matches are 1 in 16.
Added Mathew: “The actual number of false matches is even more—1 in 10. This fact is known from an ignorant, inadvertent admission of UIDAI in its counter-affidavit to my writ petition in which it stated that 80 million fake/ duplicate enrolments were detected (at a time when about 800 million enrolments were done). So, mathematical prediction is proved by ground reality data.”
Even in the Madrid train bombings case of 2004, fingerprints taken at the scene of the crime matched those of 20 people in the FBI database. When even the limited data bank of criminals with the FBI is fallible, imagine the probability of error when the entire population of a country as vast as India is involved.
Ahead of the 2014 general elections, the BJP had opposed the UID programme. In fact, Mathew was invited to make a presentation against Aadhaar before a BJP Parliamentary Party presided by LK Advani. The unanimous view then was that Aadhaar was a security risk and must be vehemently opposed. But things changed after the BJP came to power. Notes Mathew: “The party has done a complete ‘U’ turn without giving any reasons.”
In the final analysis, before the nation heads towards a total Aadhaar regime, it is perhaps time for the government to reassess the entire UID programme to plug the inherent security lapses. Also, it must not promote its use as proof of identity. It was only last month that the Union home ministry issued a communiqué: “Aadhaar (UID) card is not an acceptable travel document for travel to Nepal/Bhutan.” A valid national passport or election ID card issued by the Election Commission would however serve as proof.
Therein lies the harsh reality and identity crisis…

Wednesday, June 7, 2017

11506 - Who Is Opposing the Aadhaar Project? - The Wire



Proponents of Aadhaar have used several derogatory names for those raising questions about the project. But what motivated people to challenge the government’s plan in the first place?

The Aadhaar project has been criticised by many people for many reasons. Credit: Shome Basu

This is the fourth in a series of articles on the UID project that Usha Ramanathan will be writing for The Wire. Read the first part here, the second part here and the third part here.

The proponents of the unique identification (UID) project are angry and in a mood to attack detractors. Nandan Nilekani, the brains behind the project, has many names for them – all delivered pejoratively, of course: Khan Market liberals, JNU types, privacy-wallas who have colonised their minds with Western thought and Goebbelsian liars. He has been open about his contempt for everything happening in India: “In India, half are fake…fake…Fake is the operative word, right?” And, in another interview, “In India, you know, everything is a racket” and “every scheme is a scam” (as the interviewer, Vir Sanghvi, pertly observed, “except Aadhaar”). The last one was while talking about why children should have a UID number to get their mid-day meal in government schools.

Interestingly, all these adjectives are reserved for the hoi polloi. There isn’t a word that he breathes about the scams where the politically powerful and the corporate leadership have been caught with their hand – wrist and elbow – in the till. No Satyam, no 2G, no Commonwealth Games, no Bellary Brothers. No Vyapam, where witnesses are falling like ninepins, except they are falling dead.

ISPIRT, which presents itself as a software product industry roundtable, and of which Nilekani is the mentor, actually had a team that they named ‘Sudham’ allegedly meant to troll anti-UID critics. They had to shut it down after iSPIRT’s convener Sharad Sharma got caught operating Twitter handles using an alias to do some vicious trolling. In that time, they had moved from the relatively mildly contemptuous references about “Lutyens armchair folks (who) have never built anything in their lives” to “JNU-types” to more aggressive posturing and name calling such as “ISI stooge” and talking about the “drivel that comes from either an ignoramus or a malicious mind”.  (Sanjay Jain, who has since taken charge in iSPIRT, reportedly told Economic Times that Sudham was set up in late December 2016 to “dispel myths” about Aadhaar and India Stack.)

The most recent of this was when Ram Sewak Sharma, chief of the Telecom Regulatory Authority of India who was earlier the director general of the UIDAI, spoke to the Indian Express and accused those questioning the UID of launching “motivated campaigns”, apparently to serve the data collection interests of various multinational companies. The immediate provocation was the flooding of the internet with data from leaking departments and ministries, containing information including mobile phone numbers, bank details and UID numbers, to be seen or downloaded. In some, a slight adjustment in the URL was enough to make the database accessible. The problem for Ram Sewak was not the leak. It was the embarrassment that was caused by the leaks being exposed. So it was not those who were leaking the data that were hauled up, but the researchers who were threatened. That is how the provision in the Aadhaar Act 2016, which leaves it to the UIDAI to decide who to pursue and about whom to complain, is being used.

When Sharad was forced into contrition and he made a public apology (for allowing the trolling, but not owning up to the trolling he had done), Nilekani tweeted a “Bravo”. That is how this game is played, it seems. While those opposing the UID are subjected to thinly-veiled intimidation, the India Stack “volunteers” (a word that is going to need some serious interrogation) are hurrah-ed for apologising (when found out) for nasty trolling.

And what motivated them to challenge the project, in court and in other public spaces? There has been plenty of writing by Reetika Khera, Jean Dreze, Gopal Krishna, Praveen Dalal, Himanshu, Ramkumar, Kiran Jonnalagadda, Sunil Abraham, and there was recently Pratap Bhanu Mehta’s dramatic change of opinion.

Moneylife has hosted articles and talks, and Ram Krishnaswamy’s blog is a storehouse of what has been in the media since 2010.

But these are not the exception. There are many others. And here are some of them.”

Shantha Sinha set up the MV Foundation, which works for the eradication of child labour. She is a former chairperson of the National Commission for the Protection of the Rights of Children. According to her,
“The most effective way of tracking child labourers and out of school children is at the level of gram panchayats in rural areas and wards in urban areas where children are not statistics and numbers but real names and persons whose rights are to be protected and with involvement of community.  A UID… can at best give a number to the child but not help rescue the child or restore to her rights. Nor does it strengthen the capacities of public institutions to serve children. Further, it could also lead to stigmatising the child for good as an out-of-school child or child labourer. There can be no short cuts in the process of tracking children.
Deserving children have been denied admission into residential schools for want of Aadhaar. Among many others, there is the case of a tribal boy who fled from the Maoist area in Chattisgarh and joined school in Bhadrachalam in Telengana. He shifted from Hindi medium to Telugu medium, made it into the residential school after intense competition – and then was denied admission because he has no Aadhaar number! He lost one year, never procured an Aadhaar – how could he? He has no documents in Telengana. He then began to work as a construction labourer, and his fate is now sealed. While the Aadhaar card was said to be inclusive, in practice it has been exactly the opposite. It has deprived innumerable children of their legitimate access to their education. Exclusion is hitting the mid-day meal too!”

Bezwada Wilson has spent his adult life working for the eradication of the practice of manual scavenging. In 2010, Wilson was one of 17 concerned citizens, which included Justice V.R. Krishna Iyer, Romila Thapar and S.R. Sankaran among others, who issued a “statement of concern” about the project. He says,
“We want to bury this identity of having been manual scavengers. Coming out of untouchability is not easy. Oppressive identities are to be cast off, not documented and kept forever. What we need is a technology that will destroy this demeaning work and finish off this identity. Instead, what this is doing is branding us forever.
This project was never about plugging leakages in subsidies. Look where they have taken it. First, they said it was only for welfare and then they have kept on expanding it into all kinds of areas. All this time, the government has been waiving corporate loans worth Rs 1.14 lakh crore! How can you expect citizens to trust this? “This project is making nonsense out of choice, consent, even citizenship. It has to be understood that the people are not slaves.”

Colonel Mathew Thomas, who retired after serving ten years in the army and another ten years in defence research, says,
“Everyone has a motivation for what they do or say. In the 1970s, in the early years of computers I used them (computers) for the solution of scientific and business problems; specifically, Finite Element Analysis for structural problems on missile components and production planning and control systems for missile manufacture. The experience was invaluable. I learned the hard way what computers and IT could be used for and where these are useless. Most importantly, I understood two things: one, that physical ground reality must be organised to match proposed computer solutions before the solution yields results. And, two, misapplication of IT systems to problems where they cannot be used is dangerous as it fosters a false sense of resolving issues.
As soon as the project was announced in January 2009, my first thoughts were, ‘How in heaven’s name, are they going to do this?’ So, I wrote to the prime minister and Nandan Nilekani. I received no replies. As I continued to study, research and obtain information on the scheme, I found an organised pattern of untruth and obfuscation. The government then, and now, and those managing the project have been less than honest with us; some in government out of ignorance or misplaced faith, and some wilfully, for reasons that remain unknown. Why do you think the UK scrapped the National ID card and the US is yet to implement its Real ID Act after eleven years? Do you know that the UIDAI says, in its contracts with companies that are handling the data, “No assurance can be provided as to the accuracy of the demographic data in its database”? Do you understand what this means?”

Major General S.G. Vombatkere (retd) has an enduring respect for the liberties which the constitution recognises. His keenness to contest the unconstitutionality of the project derives from what he saw of the making of constitutional history.
“I remember my father and recall a personal debt to the constitution of India and the Supreme Court of India. To elaborate, my father, Vombatkere Gurunandan Row (better known as V.G. Row, barrister-at-law), was general secretary of a society named People’s Education Society and was publishing a newsletter from the society. People’s Education Society was declared as an unlawful association under extant criminal law by the Government of Madras [The State of Madras vs V.G.Row].
My father fought the charge in the courts of law up to the Supreme Court before a five-judge bench including the CJI, and on March 31, 1952, won his case on the basis of the freedom of expression and freedom of association, which the Constitution guarantees every citizen. Indeed years later, on 16 October 2008, Justice K.Kannan (Judge, Punjab & Haryana High Court) noted thus: “The triad of fundamental freedoms of expression, movement and association found the first affirmation in A.K.Gopalan and V.G.Row, the names that are etched into constitutional history via the Madras High Court”.
If my father had not fought and won his freedom on the basis of the constitution of India, he would have been imprisoned, changing everything in a big way for my mother, my brother and me way back in 1952, when I was still a child. That is the debt I and my family owe to the constitution of India, and to the Supreme Court of India which recognised and enforced its freedoms.
Long live the Republic of India, and may the values it enshrines always remain valid in Indian society!”

J.T. Dsouza is a biometrics expert who demonstrated in the Planning Commission how ridiculously simple it is to fake a fingerprint. That was on September 30, 2011, in the presence of representatives from the UIDAI and Natgrid.
“My objection is to the hegemony of the state, where the state treats its citizen as subjects to be subjugated. Identity projects, with control residing in a centrally controlled repository have been repeatedly misused in the past. Nazi Germany and Kosovo (with the ideas of ‘identity cleansing’ and ‘archival cleansing’) in more recent times are examples.
The intrusive bullying and abuse of power by the state that the project has already witnessed is testimony to the problems of the project.
My second objection about technology involves a whole panoply of reasons. One, the use of wholly untested theories as the foundation of the project. Two, intrinsic flaws of biometrics as an authentication factor. Three, vulnerabilities of centralised database to misuse, both official and inadvertent. Four, non-existent technical infrastructure in most of our country. No matter how secure you make the central core, the nature of such a system makes securing the periphery impossible. This project continues to gloss over all of this at our peril.”

Nagarjuna is a professor at the Gnowledge lab, Homi Bhabha Centre for Science Education, at the Tata Institute of Fundamental Research. He says,
“Centralisation of any resource will eventually go against the democratic ideals of distributed justice. Centralisation leads to single point of failure.
In a true democracy, we wish the state to be transparent to the people, and not vice versa. The very possibility of a certified unique identity will create multiple modes of criminal activities that never existed in the past. A certified unique identity will create more crime than reducing the crime.
The Aadhaar system is not built like self-reliant technology ventures like Atomic Energy or Space Research, but with commercial links with global security companies. This will make the entire country vulnerable. Considering that the Aadhaar is promoted by powerful agencies (both private and public), it shows that it serves their interests and it is not about recognising power in  the people.
Identity is not created by birth, real social identity is developed dynamically as we live. Freedom to build or change character without coercion to other lives must be respected at any cost.”

Anupam Saraph is an innovator and polymath, and has been an advisor to government on technology and on identity systems. He asks,
“What is the motivation of the child who sees the emperor’s new robes don’t exist? What will the child do if the emperor insists the robes exist?
Having experience in building identity solutions, and having developed logical frameworks for identity documents, it is plain that the UID is merely a number that is assigned to unverified and unaudited data submitted by private enrolees – 34,000 of who have been suspended by the UIDAI. This means that there can be millions of ghosts in the UIDAI database.
It is fairly obvious that any bank accounts opened solely on the basis of such a number can allow “ghosts” to create and operate “mule” accounts. Furthermore, even while the RBI’s own system of digital money transfers has been used by government for over a decade, the sudden unexplained switch to a non-government payment system based on Aadhaar that facilitates money laundering by destroying the money trail raises serious questions that need investigation.
The UID cannot serve as the basis for identification of any individual in an impartially arbitrable way. This means using it to build governance, national security, digital economy and anything at all is plainly absurd and, because it will destroy lives and the nation, inhuman. If I turn a blind eye to what is so obvious I would be no less guilty of the crimes than the perpetuators of the UID.
Should anyone who sees absurdities, illegalities, anti-national and criminal intent need any further motivation to expose it?”

Vickram Crishna is an engineer who, like most others featured here, has challenged the project in court.
“My problem with the technology is, in most instances, that commercial considerations trump the priority of meeting incredibly high standards, and this can be seen in the design choices at every stage. The manner of implementation of this system, however, is fully dependent upon a very high quality of seamless connectivity across the country, which in itself demands a very high level and availability of specialised labour, apart from electrical power and stability. We are some years away from approaching such a situation  and the present distribution of quality of service is heavily weighted in favour of major cities, and against rural areas in general.
It is attractive to initially bar all failures, and claim reduced expenditure as savings, and this is what is being observed now.
I have a problem with the understanding of ‘social contract’, as expressed in the implementation of the UID scheme. The constitution, as I read it, from its opening phrase of “We, the People…” was intended to lead to a state that is primarily citizen-facing. However, the justification for identity documents of one kind and another is invariably found to be the need to address failures in the state’s ability to identify citizens, and not any failures of the citizens themselves, as part of the social contract expressed as the constitution.”

Kalyani Menon-Sen is a feminist researcher of 25 years’ standing. She says,
“Many years of working with poor women has made me keenly aware of the many barriers they face in accessing their entitlements. Proving their identity is not the major barrier. The real corruption is in the system.This issue of systemic exclusions has been at the centre of my work. Over these last seven years, I have more and more first-hand evidence that UID has not improved service delivery, whether it’s rations or gas cylinders or pensions. Even more worrying is the fact that Aadhaar is actually creating more exclusion, again because of systemic failures – even people with valid UIDs are unable to claim benefits because “machine kharab hai (the machine isn’t working)” or fingerprints don’t match or because some new rule is unearthed that they are not aware of. I think what really brought home to me that the promoters of the scheme were losing their moorings was the announcement of the Aadhaar-midday meal linkage. We have the most horrendous rates of child malnutrition, children come to school starving and for many, the school meal is the only cooked food they get that day. This is a universal provision. What is the sense in making it Aadhaar dependent?
This is true for school admissions too – it is a universal right and making it Aadhaar dependent will only help schools to exclude children whom they don’t want to take – because they are poor, disabled, Muslims or Dalits. These are the exclusions that are happening and are being ignored.
I feel utterly frustrated that we invest so much attention on the GDP and completely ignore the GDI (gender development index) – shocking rates of anaemia, underage pregnancies, maternal deaths, malnutrition, violence, women’s employment. Do we really need to argue about methods of calculation when the naked truth is visible to the naked eye?
So I felt I had to take a stand and do something – I was very sure that if the facts about exclusion are put before the Supreme Court, they would at least stay these notifications while examining all the other constitutional issues.”

M.K. Pai is a software engineer and data scientist. He says,
“I fear that Aadhaar will destroy our delicate democracy by threatening exclusion. We can already see a future where dissenters will be silenced, their bank accounts and phones disabled, and unable to travel.
It is profoundly ugly for any government to require its citizens to get fingerprinted, no matter how noble the objectives. My fingerprints are my property and I should not be compelled to part with them unless I am a threat to society.
I am a software engineer and a data scientist. My work makes me very concerned about the future if we succumb today. Frankly, I do not trust any political party with such power.
Privacy is important and worth fighting for.”

The Meghalaya Peoples’ Committee on Aadhaar in a recent statement said,
“…it is noticed and have been informed regularly that subtle ways are being used to have people enrolled with aadhaar including school children under various guises, putting people in uncomfortable situations and that the statement made by the state government’s chief secretary on the matter (Shillong Times, 04/02/2017) confirms the fact. However, despite the fact that different departments and ministries of the Union government and state government, financial institutions have over and over again issued notifications, advertisements, including regular texting in mobiles, for necessity to enrol or register for aadhaar card, it is to be reiterated and reminded that enrolment for aadhaar is voluntary and so should not be coerced and intimidated by any establishment of government(s), institutions – medical, educational, financial, sports, etc. including corporate bodies.
…Yes,  having  Aadhaar  card  may be  one  of  the  requirements  but  it  is not  the  only  proof  of  one’s  identity  and  must  remain  optional  and  voluntary.”

Nachiket Udupa studied in IIT, has been part of campaigns on rural employment guarantee, food security and the right to information, and is currently involved in the marketing of sustainable foods. According to him,
“At an ideological level it makes profiling and tracking much, much easier than it should be. The path that they are heading down will lead to not just an Orwellian state (as in government doing complete surveillance of its citizens) but also Orwellian corporates (as in companies also knowing way more about their customers than they should). It is attacking privacy in the worst possible way.
At a practical level, because fingerprinting technology doesn’t work well enough, it is leading to large scale exclusions and hardships for many people, especially the poor. I am particularly bothered that this will lead to slow dismantling of the various hard-won rights of the poor, such the rights to food, work, education, etc.
It is compulsory, and with no opt-out feature.
I don’t like how the people behind Aadhaar think that they are holier than thou and seem to have a sense of entitlement and would like to be beyond any sort of accountability.”

Ankita Anand is an award-winning journalist, writer and co-founder of the street theatre group Aatish based in Delhi, and this is how she says it:
U,IDidn’t
I waited for the day someone would ask me my number
Until the state did, and I smirked,
“I know you’ve used that line on a billion others.”
At that it should have left,
But it persisted,
Insisted it would give me one,
If I did not have one of my own.
It wouldn’t take no for an answer,
And now I have fingerprints instead of handholding,
Iris scans, while I wait to be seen,
At least I would be safe, I tried to tell myself,
Until yesterday, when I found myself exposed,
Every single digit of me, up for sale as data porn.
(Anand and Udupa had to battle the system before they could register their marriage without a UID.)

Nikhil Dey, Shankar Singh, Vineet Bhambhu , Nikhil Shenoy, Aruna Roy and others work with the Mazdoor Kisan Shakti Sanghatan, and this is what they say:
“We are activists who live amongst people in rural India and also travel to many places across the country to work with campaigns and movements to improve delivery of programmes meant for poor and marginalised communities and individuals. We believe that well designed people centric social sector programs can make a big difference in people’s lives. We have also spent many years looking at policy and its impact on implementation.
The UID is  currently one of the biggest policy initiatives where proponents of UID claim better delivery by a) ending corruption b) much greater efficiency and most importantly c) of comprehensive inclusion.
We are motivated by the suffering, frustration and pain we are witness to and therefore make strong comments on the UID – initially through apprehension, and, now, through experience and example.
It has, in fact, miserably failed on all three claims. In some ways it has made things worse. Exclusion due to the mandatory use of UID has been so high, that it should cause a comprehensive rethink for the delivery of welfare benefits. Food security rations are supposed to be delivered to 1 crore households in the state of Rajasthan. But figures have shown that at least 25-30% of these households are not able to draw their rations despite being enrolled under UID. This has meant exclusion of some of the most vulnerable people for whom the food security act was designed. In some ways, this is criminal negligence and exclusion, and this has been happening over a period of the nine months since September 2016, when the options started being shut off. We have documented very serious life threatening cases of exclusion and put them up as videos on the net. (We hope these policy makers will see the videos and answer each one of the questions of the poor about who will be held accountable for the failure to enable them to access their entitlements.) Corruption has not reduced – it has only changed its stripes, and inefficiency and delay are now caused by man and machine.
Our own motivation is to use evidence to convince policy makers to change their policy, or to convince those whose minds are still open to refuse to allow mandatory imposition of something that has clearly failed to deliver what it promised to. It has made things worse. Whether or not anyone bothers to listen, we are motivated by the pain and frustration we witness – to keep presenting the facts.
The poor are speaking; only those who need to listen are not even there. In the language of the day, they are ‘presenceless’.”
These are a section of the people who have been challenging the project, in court and outside it. There are many more – and they are from all parts of the country. Such as professor K. Saradamoni from Thiruvananthapuram, a very senior women’s rights activist, who wrote in saying, “Please think of something to stop this.” Or  a retired law professor from a law research institute who wrote to say, “It is only last year that the bank asked for fingerprints verification. Earlier, just physical presence and some ID proof used to be enough. In my case, even when the requirement was not there and despite my giving life certificate (which the bank says they duly forwarded to the EPFO) my pension, so called, was stopped after December 2015. The bank did send them reminders but no result. Then came the requirement of biometrics. My fingerprints did not match but the bank was very cooperative and sent a few letters, as they say, supporting my claim. It has been quite long but no response again from the EPFO. Now the bank has given me a form, certifying my identity, and asked me to go there personally. What disturbs me is why should I be made to run around without any fault? The bank is certifying my case, I have all other documents to prove my identity, why then this stupid requirement of matching of fingerprints?  The entire credibility of fingerprints to establish identity of criminals in criminology and forensic sciences has gone for a toss. It is time things and theories and fundamentals change.”

Usha Ramanathan is a legal researcher.