In 2009, I became extremely concerned with the concept of Unique Identity for various reasons. Connected with many like minded highly educated people who were all concerned.
On 18th May 2010, I started this Blog to capture anything and everything I came across on the topic. This blog with its million hits is a testament to my concerns about loss of privacy and fear of the ID being misused and possible Criminal activities it could lead to.
In 2017 the Supreme Court of India gave its verdict after one of the longest hearings on any issue. I did my bit and appealed to the Supreme Court Judges too through an On Line Petition.
In 2019 the Aadhaar Legislation has been revised and passed by the two houses of the Parliament of India making it Legal. I am no Legal Eagle so my Opinion carries no weight except with people opposed to the very concept.
In 2019, this Blog now just captures on a Daily Basis list of Articles Published on anything to do with Aadhaar as obtained from Daily Google Searches and nothing more. Cannot burn the midnight candle any longer.
"In Matters of Conscience, the Law of Majority has no place"- Mahatma Gandhi
Ram Krishnaswamy
Sydney, Australia.

Aadhaar

The UIDAI has taken two successive governments in India and the entire world for a ride. It identifies nothing. It is not unique. The entire UID data has never been verified and audited. The UID cannot be used for governance, financial databases or anything. It’s use is the biggest threat to national security since independence. – Anupam Saraph 2018

When I opposed Aadhaar in 2010 , I was called a BJP stooge. In 2016 I am still opposing Aadhaar for the same reasons and I am told I am a Congress die hard. No one wants to see why I oppose Aadhaar as it is too difficult. Plus Aadhaar is FREE so why not get one ? Ram Krishnaswamy

First they ignore you, then they laugh at you, then they fight you, then you win.-Mahatma Gandhi

In matters of conscience, the law of the majority has no place.Mahatma Gandhi

“The invasion of privacy is of no consequence because privacy is not a fundamental right and has no meaning under Article 21. The right to privacy is not a guaranteed under the constitution, because privacy is not a fundamental right.” Article 21 of the Indian constitution refers to the right to life and liberty -Attorney General Mukul Rohatgi

“There is merit in the complaints. You are unwittingly allowing snooping, harassment and commercial exploitation. The information about an individual obtained by the UIDAI while issuing an Aadhaar card shall not be used for any other purpose, save as above, except as may be directed by a court for the purpose of criminal investigation.”-A three judge bench headed by Justice J Chelameswar said in an interim order.

Legal scholar Usha Ramanathan describes UID as an inverse of sunshine laws like the Right to Information. While the RTI makes the state transparent to the citizen, the UID does the inverse: it makes the citizen transparent to the state, she says.

Good idea gone bad
I have written earlier that UID/Aadhaar was a poorly designed, unreliable and expensive solution to the really good idea of providing national identification for over a billion Indians. My petition contends that UID in its current form violates the right to privacy of a citizen, guaranteed under Article 21 of the Constitution. This is because sensitive biometric and demographic information of citizens are with enrolment agencies, registrars and sub-registrars who have no legal liability for any misuse of this data. This petition has opened up the larger discussion on privacy rights for Indians. The current Article 21 interpretation by the Supreme Court was done decades ago, before the advent of internet and today’s technology and all the new privacy challenges that have arisen as a consequence.

Rajeev Chandrasekhar, MP Rajya Sabha

“What is Aadhaar? There is enormous confusion. That Aadhaar will identify people who are entitled for subsidy. No. Aadhaar doesn’t determine who is eligible and who isn’t,” Jairam Ramesh

But Aadhaar has been mythologised during the previous government by its creators into some technology super force that will transform governance in a miraculous manner. I even read an article recently that compared Aadhaar to some revolution and quoted a 1930s historian, Will Durant.Rajeev Chandrasekhar, Rajya Sabha MP

“I know you will say that it is not mandatory. But, it is compulsorily mandatorily voluntary,” Jairam Ramesh, Rajya Saba April 2017.

August 24, 2017: The nine-judge Constitution Bench rules that right to privacy is “intrinsic to life and liberty”and is inherently protected under the various fundamental freedoms enshrined under Part III of the Indian Constitution

"Never doubt that a small group of thoughtful, committed citizens can change the World; indeed it's the only thing that ever has"

“Arguing that you don’t care about the right to privacy because you have nothing to hide is no different than saying you don’t care about free speech because you have nothing to say.” -Edward Snowden

In the Supreme Court, Meenakshi Arora, one of the senior counsel in the case, compared it to living under a general, perpetual, nation-wide criminal warrant.

Had never thought of it that way, but living in the Aadhaar universe is like living in a prison. All of us are treated like criminals with barely any rights or recourse and gatekeepers have absolute power on you and your life.

Announcing the launch of the # BreakAadhaarChainscampaign, culminating with events in multiple cities on 12th Jan. This is the last opportunity to make your voice heard before the Supreme Court hearings start on 17th Jan 2018. In collaboration with @no2uidand@rozi_roti.

UIDAI's security seems to be founded on four time tested pillars of security idiocy

1) Denial

2) Issue fiats and point finger

3) Shoot messenger

4) Bury head in sand.

God Save India

Showing posts with label Qarth Technologies. Show all posts
Showing posts with label Qarth Technologies. Show all posts

Friday, August 18, 2017

11795 - Aadhaar is fully protected: Nandan Nilekani - Deccan Herald


N V Vijayakumar, Bengaluru, 
DH News Service, Aug 16 2017, 14:45 IST


Aadhaar, India's biometric citizen identification platform, is well secured and can't be hacked in, said Nandan Nilekani, former chairman of Unique Identity Development Authority of India (UIDAI). 

In an interaction with DH, Nilekani said there is no need to panic. "Aadhaar system has not been breached and it has well-established security frame work," he said. 

Nilekani also pointed out that Aadhaar platform has implemented best in class global security practices. 

When asked about the recent DH story on the first UIDAI technology head Srikant Nadhamuni's statement on Aadhar, he said Nadhamuni is correct in his observation. 

His comments assume significance as UIDAI lodged a complaint with the Bengaluru police last month against an IIT-Kharagpur engineer Abhinav Srivastava and his start-up Qarth Technologies Pvt Ltd for developing an app and illegally accessing the Aadhaar database.

Nilekani was speaking at the Carnegie India panel discussion on "Who owns personal data: Technology and Policy frameworks". 

He expressed hope that the Justice BN Srikrishna committee which is drafting a data protection framework would look at the model for sharing data and managing privacy developed already. 

"We can't imitate the European GDPR (General Data Protection Regulation) in the Indian context," said Nilekani. He said that the European GDPR was over two decades old and that India needs a new framework in the time of IoT, AI and Machine learning. 


Wednesday, August 9, 2017

11734 - Aadhaar data can be stolen easily, techie arrested for theft holds demonstration - North Lines


August 6, 2017

Aadhaar data can be stolen easily, techie arrested for theft holds demonstration

In a six hour demonstration, a Bengaluru techie and entrepreneur showed the police how easy it was for him to access Aadhaar data from the UIDAI data base. Abhinav Srivastava was arrested last week for the data theft following a complaint by the UIDAI authorities.

Cyber crime police in Bengaluru recorded Abhinav’s modus operandi which highlighted a glaring security chink, the lack of Hypertext Transfer Protocol Secure (HTTPS) in the URL that helped Abhinav access details. The founder of an Ola subsidiary firm, Qarth Technologies Pvt Ltd, Abhinav used shortcuts to access data from various websites that used Aadhaar data.
HTTPS consists of communication over Hypertext Transfer Protocol within a connection encrypted by Transport Layer Security. In simpler terms, it is a far better secure connection than the HTTP. HTTPS is aimed at authentication of the visited website and protection of the privacy and integrity of the exchanged data. The lack of it helped the accused hack into an e-hospital website.

On initial investigation, it was found that Abhinav accessed Aadhaar information from an e-hospital’s server hosted by the National Informatics Centre. The hospital was a Know Your Customer user agency which has tied up with the UIDAI. Abhinav hacked into the hospital’s system and linked the information on its server to an app that he developed.
The app, which was available on google store, has been removed now. It was able to redirect users to the e-hospital’s servers to access KYC data. Even as he claimed that he did not steal any information but only gave access to a server, using Aadhaar data without prior permission from the UIDAI is a violation of the Aadhaar law.

Abhinav who holds a masters degree from IIT-Kharagpur used the loopholes in the e-hospital’s URL to gain access to its unsecured servers. With his app, anyone could access details about anyone who had an Aadhaar card breaching the privacy of individuals. Following a complaint by the UIDAI, the High grounds police in Bengaluru booked Abhinav, his company and its promoters for accessing secure Aadhaar database and leaking information under sections 37, 38, 29(2) of Aadhaar (Targeted Delivery of Financial and other Subsidies, Benefits and Services) Act 2016, sections 65 and 66 of the IT Act.


Monday, July 31, 2017

11671 - Bengaluru-based IT professional booked for illegally accessing Aadhaar database -Indian Express


By Express News Service  |   Published: 27th July 2017 11:20 PM  |  

BENGALURU: In a case highlighting the security flaws in the Unique Identification Authority of India (UIDAI), officials have filed a complaint against one Abhinav Shrivastava and others of Qarth Technologies Private Limited for allegedly leaking Aadhaar data.

According to the complaint by the Ashok Lenin, deputy director of UIDAI, Abhinav Shrivastava, the director of Qarth Technologies, had developed an app on Play store to provide e-KYC documents. The documents were allegedly provided by accessing the Aadhaar database without any permission from UIDAI or other authorities.

Aadhar officials also suspected that the accused colluded with others to secure the database before leaking the information to Qarth Technologies.

Pronab Mohanty, deputy director general, UIDAI, Bengaluru confirmed that a case has been filed in Bengaluru. "However, it does not pertain to the regional office, Bengaluru," he said. He also said that the complaint was not a case of malpractice, but that the fault stemmed from the flaws in National Informatics Centre.

Accessing secure Aadhaar database and leaking information from the same is an offence under Aadhaar (Targeted Delivery of Financial and other Subsidies, Benefits and Services) Act 2016 and Information Technology Act, 2000.

In the FIR registered, Section 37 (intentionally discloses, transmits, copies or otherwise disseminates any identity information collected in the course of enrollment or authentication ....), Section 38 (deals with intentionally accessing Central Identities Data Repository and downloading data) read with Section 29 (2) of Aadhaar Act has been evoked. Apart from it, section 65 (tampering with computer source documents) and section 66 (hacking a computer system) of IT Act, and sections of IPC has been filed against the accused.
 

Qarth Technologies

According to Zauba Corp, a data bank of various firms, Qarth Technologies was incorporated in October 2012 at Kolkata and was involved in data processing. Directors of the company were Abhinav Srivastava (accused in the case) and Prerit Srivastava. The company, as per Zauba Corp was based out of Science and Technology Entrepreneurs' Park, IIT Kharagpur, West Bengal

11670 - UIDAI complains of Aadhaar data misuse - The Hindu


STAFF REPORTER
JULY 27, 2017 23:25 IST

Lodges FIR against the co-founder of a mobile payment startup
The Unique Identification Authority of India (UIDAI) on Wednesday lodged a complaint with the Bengaluru police against the co-founder of a mobile payment startup — Qarth Technologies Pvt. Ltd. — about misuse of data from the Aadhaar website.

The complaint was lodged by Ashok Lenin, Deputy Director, UIDAI, Regional Office, Bengaluru. A copy of the FIR, available with The Hindu, says that the suspect, Abhinav Srivastava, created a mobile app and has been giving out e-kyc, misusing data from the Aadhaar website. He did not seek permission from UIDAI before tapping into the website. According to the FIR, Srivastava entered into a conspiracy with others, misused Aadhaar data and leaked the information.

He has been booked under Section 29(2) of Aadhaar (targeted delivery of financial and other subsidies, benefits and services) Act 2016, which deals with restrictions on sharing Aadhaar information; Sections 65 and 66 of the Information Technology Act for tampering with computer source documents and hacking with computer systems; Sections 468 and 471 of IPC for forgery and Section 120(B) for conspiracy.

There is no clarity whether the suspect hacked into the Aadhaar database or misused the authentication of a user agency.
UIDAI officials were not available for comment.

Srivastava told The Hindu that Qarth is a multi-bank mobile payment firm which stopped operations in March 2016. “We have never used Aadhaar for kyc. The app is no longer available. Moreover, I have not been informed about the FIR or any charges against me,” he said.

Prerit Srivastava, co-founder, added that they have filed documents to close the company and have no employee on their rolls. “We don’t own the domain name Qarth,” he said.
Incidentally, Qarth Technologies Pvt. Ltd. was acquired by a city-based cab aggregator in March 2016.
Dr. Chandragupta, DCP (Central), Bengaluru Police said that the case has been transferred to the cybercrime police.

Saturday, July 29, 2017

11665 - Bengaluru company hacks Aadhaar website? How safe is linking PAN? - Daily Hunt


The makers of Aadhaar have filed a complaint against a Bengaluru based start up company charging it with misuse of data from Aadhaar website.

A complaint was lodged by Unique Identification Authority of India's Deputy Director Ashok Lenin, against Qarth Technologies Pvt Ltd. A FIR has been filed against Abhinav Srivastava, the co-founder of the start up company.

The Hindu reported that cases had been filed under the Section 29(2) of Aadhaar (targeted delivery of financial and other subsidies, benefits and services) Act 2016, which deals with restrictions on sharing Aadhaar information; Sections 65 and 66 of the Information Technology Act for tampering with computer source documents and hacking into computer systems; Sections 468 and 471 of IPC for forgery and Section 120(B) for conspiracy.

So far there is no information on how the Aadhaar details were hacked or how were the details misused. What Qarth did has made us all worry as almost all have linked PAN with Aadhaar. And if Aadhaar details can be hacked, even any information, especially bank-related information can also be hacked with PAN linked to it.

Thus there is an immediate need for the Centre and the UIDAI to safeguard its database. First of all, it is wrong on the part of the authorities to make the linking of PAN compulsory when the Aadhaar details are not secure.

Just a complaint against one company who has breached the security of the Aadhaar database is not the solution. Enough of oral assurances that Aadhaar is secure. There is a need for immediate steps to safeguard people's accounts and financial details.


If there is still any doubt left about keeping the public details secure, the plan to link PAN with Aadhaar must be stopped.