In 2009, I became extremely concerned with the concept of Unique Identity for various reasons. Connected with many like minded highly educated people who were all concerned.
On 18th May 2010, I started this Blog to capture anything and everything I came across on the topic. This blog with its million hits is a testament to my concerns about loss of privacy and fear of the ID being misused and possible Criminal activities it could lead to.
In 2017 the Supreme Court of India gave its verdict after one of the longest hearings on any issue. I did my bit and appealed to the Supreme Court Judges too through an On Line Petition.
In 2019 the Aadhaar Legislation has been revised and passed by the two houses of the Parliament of India making it Legal. I am no Legal Eagle so my Opinion carries no weight except with people opposed to the very concept.
In 2019, this Blog now just captures on a Daily Basis list of Articles Published on anything to do with Aadhaar as obtained from Daily Google Searches and nothing more. Cannot burn the midnight candle any longer.
"In Matters of Conscience, the Law of Majority has no place"- Mahatma Gandhi
Ram Krishnaswamy
Sydney, Australia.

Aadhaar

The UIDAI has taken two successive governments in India and the entire world for a ride. It identifies nothing. It is not unique. The entire UID data has never been verified and audited. The UID cannot be used for governance, financial databases or anything. It’s use is the biggest threat to national security since independence. – Anupam Saraph 2018

When I opposed Aadhaar in 2010 , I was called a BJP stooge. In 2016 I am still opposing Aadhaar for the same reasons and I am told I am a Congress die hard. No one wants to see why I oppose Aadhaar as it is too difficult. Plus Aadhaar is FREE so why not get one ? Ram Krishnaswamy

First they ignore you, then they laugh at you, then they fight you, then you win.-Mahatma Gandhi

In matters of conscience, the law of the majority has no place.Mahatma Gandhi

“The invasion of privacy is of no consequence because privacy is not a fundamental right and has no meaning under Article 21. The right to privacy is not a guaranteed under the constitution, because privacy is not a fundamental right.” Article 21 of the Indian constitution refers to the right to life and liberty -Attorney General Mukul Rohatgi

“There is merit in the complaints. You are unwittingly allowing snooping, harassment and commercial exploitation. The information about an individual obtained by the UIDAI while issuing an Aadhaar card shall not be used for any other purpose, save as above, except as may be directed by a court for the purpose of criminal investigation.”-A three judge bench headed by Justice J Chelameswar said in an interim order.

Legal scholar Usha Ramanathan describes UID as an inverse of sunshine laws like the Right to Information. While the RTI makes the state transparent to the citizen, the UID does the inverse: it makes the citizen transparent to the state, she says.

Good idea gone bad
I have written earlier that UID/Aadhaar was a poorly designed, unreliable and expensive solution to the really good idea of providing national identification for over a billion Indians. My petition contends that UID in its current form violates the right to privacy of a citizen, guaranteed under Article 21 of the Constitution. This is because sensitive biometric and demographic information of citizens are with enrolment agencies, registrars and sub-registrars who have no legal liability for any misuse of this data. This petition has opened up the larger discussion on privacy rights for Indians. The current Article 21 interpretation by the Supreme Court was done decades ago, before the advent of internet and today’s technology and all the new privacy challenges that have arisen as a consequence.

Rajeev Chandrasekhar, MP Rajya Sabha

“What is Aadhaar? There is enormous confusion. That Aadhaar will identify people who are entitled for subsidy. No. Aadhaar doesn’t determine who is eligible and who isn’t,” Jairam Ramesh

But Aadhaar has been mythologised during the previous government by its creators into some technology super force that will transform governance in a miraculous manner. I even read an article recently that compared Aadhaar to some revolution and quoted a 1930s historian, Will Durant.Rajeev Chandrasekhar, Rajya Sabha MP

“I know you will say that it is not mandatory. But, it is compulsorily mandatorily voluntary,” Jairam Ramesh, Rajya Saba April 2017.

August 24, 2017: The nine-judge Constitution Bench rules that right to privacy is “intrinsic to life and liberty”and is inherently protected under the various fundamental freedoms enshrined under Part III of the Indian Constitution

"Never doubt that a small group of thoughtful, committed citizens can change the World; indeed it's the only thing that ever has"

“Arguing that you don’t care about the right to privacy because you have nothing to hide is no different than saying you don’t care about free speech because you have nothing to say.” -Edward Snowden

In the Supreme Court, Meenakshi Arora, one of the senior counsel in the case, compared it to living under a general, perpetual, nation-wide criminal warrant.

Had never thought of it that way, but living in the Aadhaar universe is like living in a prison. All of us are treated like criminals with barely any rights or recourse and gatekeepers have absolute power on you and your life.

Announcing the launch of the # BreakAadhaarChainscampaign, culminating with events in multiple cities on 12th Jan. This is the last opportunity to make your voice heard before the Supreme Court hearings start on 17th Jan 2018. In collaboration with @no2uidand@rozi_roti.

UIDAI's security seems to be founded on four time tested pillars of security idiocy

1) Denial

2) Issue fiats and point finger

3) Shoot messenger

4) Bury head in sand.

God Save India

Showing posts with label Rachna Khaira. Show all posts
Showing posts with label Rachna Khaira. Show all posts

Wednesday, May 2, 2018

13415 - India’s ambitious digital ID project faces new security nightmare - Asia Times


A slew of complaints and alerts to UIDAI reveal that operators can bypass biometric and geo-location safeguards to access the database illegally


By SAIKAT DATTA MAY 1, 2018 12:52 PM (UTC+8)

A citizen's biometric data is collected for his Aadhaar card. Photo: Wikipedia Commons

India’s all-pervasive digital identity programme Aadhaar appears to be facing a fresh security scare. The concern may also have national security implications, as suggested by material accessed by Asia Times.

The key to the latest security breach comes from a modified Aadhaar enrolment software, known as ECMP, which is being distributed illegally for a cost ranging from Rs 500 to Rs 2,000.

Must-reads from across Asia - directly to your inbox

Alerts to the Unique Identification Authority of India (UIDAI) and other government agencies have been acknowledged, but no detail of any follow-up action has been revealed. This has given rise to suspicion that the breach is yet to be resolved.

The ECMP was developed as software that can be used by operators to register people so they can get unique digital Aadhaar numbers. There is an elaborate program that allowed “enrolment partners” to be contracted by UIDAI to sign up citizens and residents across the country. The ECMP software ensures that sensitive personal data of those signing up is securely collected in a prescribed format to generate their Aadhaar number.

However, as reports of enrolment fraud began to surface, the UIDAI blacklisted nearly 50,000 private operators and mandated public sector banks and post offices to carry out the enrolment.

For the erstwhile private operators, the blacklisting was a major blow. Public sector banks were overloaded with the additional work of signing up citizens and residents.  The government has made Aadhaar mandatory for filing taxes as well as having bank accounts and a cell-phone connection. Nearly a billion people were signed up, even as the government was engaged in a slew of litigation in India’s Supreme Court challenging the project.

A number of petitioners have challenged the Aadhaar project on the ground that it enables mass surveillance by the state, violates citizens’ privacy and poses a major danger to legitimate entitlements guaranteed by the Indian Constitution. The slew of cases led to an unprecedented nine-judge constitutional bench of the Supreme Court ruling that privacy was a “fundamental right” under the Constitution. The other petitions challenging the program are still being heard by the Supreme Court.

The ECMP software allowed the operators to collect biometric data such as iris scans and fingerprints, as well as details of address and date of birth, among other sensitive personal data. The software has two major safeguards to ensure that it can not be misused. It asks for the biometrics of the authorized operator and seeks the geo-location to ensure that not only is the data being collected by someone authorized to do so, but to also ensure that it is being done at a secure and mandated location. There are many videos explaining how this software can be downloaded and installed.

Software ‘compromised to bypass safeguards’
But material gleaned from group WhatsApp messages of erstwhile private operators and complaints to the UIDAI reveal that the software has been compromised. This allows illegal access to the Aadhaar database by by-passing the biometric and geo-location safeguards.

Messages posted in several WhatsApp groups among Punjab-based operators began to surface at the end of last year, offering to sell a “jailbreak” version of the software. This version, to be installed on the laptops of anyone willing to pay the amount, could bypass the biometric and geo-location safeguards. This basically meant that anyone posing as an “authorized operator” could make changes to the data and enrol new people from anywhere and pass their information off as legitimate. This is easier as the number is only proof of residency and not citizenship.

An Aadhaar government identification card. Photo: iStock

Two information security professionals who looked at the compromised software confirmed to Asia Times that the safeguards had been bypassed. “(The) Aadhaar Enrolment client can be installed on any laptop and is available for public download. It needs to be configured for use by a  registrar (Banks, State governments) by importing registrar data and user credentials of the registrar”, the information security professional said, on strict condition of anonymity.

According to a second information security professional, enrolment and updates are possible only if an operator’s credentials match with their biometrics. However, the illegal enrolment software has been patched to bypass biometric checks and comes preconfigured with user credentials of various registrars. “The GPS module to track the location of the enrolment has also been disabled through a patch,” this expert said. “This allows anyone to become an Aadhaar enrolment operator, thereby violating all the security protocols that UIDAI has put in place for enrolment, including document verification such as proof of identity, proof of address. It also allows anyone to update their proof of identity or address details without any checks whatsoever.”

According to the experts, disabling or ‘spoofing’ the GPS checks gives rise to the possibility of the enrolment happening anywhere in the world, thereby allowing even foreign nationals who have never visited India, to enrol in Aadhaar.

None of these hacks are new. On February 23 this year, UIDAI authorities from the city of Chandigarh filed an official complaint with the Haryana Police. The case found a group of people working in the district of Hisar, using fake rubber thumbprints to bypass the biometric safeguards of the operator. This group was illegally accessing the database, as well as carrying out enrolments.

In the neighboring state of Uttar Pradesh, the police registered an official complaint in the capital Lucknow in August 2017. In this case, the UIDAI found operators who had managed to bypass the biometric safeguards as well.

‘Hostile’ UIDAI
These details and possibilities were brought to the UIDAI’s knowledge by email by an operator from Punjab. Bharat Bhushan Gupta sent them several warnings, which were acknowledged by UIDAI. But he was never informed about any follow-up. Gupta said he was willing to help the UIDAI access the compromised software and enable officials to examine the bypass in detail. But he never heard from them again.
Subsequently, a Punjab-based journalist with a major newspaper also accessed details of the compromised software and promptly alerted the UIDAI in writing in mid-April. This was also acknowledged, but no details of any follow-up action were shared.

To ensure good cybersecurity, the discovery of vulnerabilities depends largely on voluntary disclosure from hackers and information security professionals. However, despite being in existence from 2009, UIDAI lacks a responsible disclosure program, and in fact adopts a hostile stance against any disclosure. In the past, the agency has filed police complaints, not even sparing journalists who only reported on similar vulnerabilities. As a result, most experts shy away from informing the UIDAI about such problems. It continues to claim that their database is safe, despite mounting evidence to the contrary.

Asia Times sent the following queries to the CEO and chairman of UIDAI, to seek a response to these issues. The story will be updated as and when they respond.

1. Is it true that the Enrolment Client Management Platform (ECMP) software, being used for off-line enrolment has been found to have vulnerabilities, which can be exploited to bypass geo-location and biometrics?
2. Is the UIDAI aware that a group of illegal operators are using this software and installing it for a price, enabling people to carry out illegal enrolment and updates?
3. What is the progress on the UP Aadhaar hack – illegal enrolment case, where the Enrolment software was hacked as per the registered First Information Report in September 2017?
4. Was the ECMP software sufficiently hardened so that the above vector of patching the software to bypass an operator’s biometrics cannot happen?
5. If yes, what are the technical measures put in place to plug this vulnerability?
6. A similar incident was reported by operator Bharat Bhushan Gupta from Jullundur on Feb 1, 2018, which the UIDAI has acknowledged. What was the resolution of that incident and details thereof?
7. The same vulnerability was reported by Ms Rachna Khaira and also reported to the National Critical Information Infrastructure Protection Center on April 15, 2018. What is UIDAI’s response to this?

Thursday, April 19, 2018

13303 - Does buying pizza mean exposing your Aadhaar details? Here’s what UIDAI chief has to say - Financial Express


During an Aadhaar hearing, a question asked by Justice Chandrachud during the hearing made an interesting case: What if a pizza chain shares his customers' information with his health insurance firm?

By: FE Online | Updated: April 17, 2018 12:18 PM


UIDAI chief says there is no law that requires a pizza company to ask for your Aadhaar number. (Image: Reuters)

As Supreme Court’s five-judge Constitution bench advocated for a “robust” law to protect the sensitive information of citizen during the Aadhaar hearing, a question asked by Justice Chandrachud during the hearing made an interesting case: What if a pizza chain shares its customers’ information with its health insurance firm? The question was asked from the Unique Identification Authority of India (UIDAI) chief Ajay Bhushan Pandey.

To which, he explained in a TV interview explained that there is “no law that requires a pizza company to ask for your Aadhaar number.” The UIDAI chief in the apex court had testified that no breach of biometric details has taken place in seven years.

“If anyone asks your Aadhaar number you can refuse to provide Aadhaar number- number one,” Ajay Bhushan Pandey said in an interview with CNBC-TV18. He said that the pizza company will be able to know other information that is related to a general data protection law and not Aadhaar.

On concerns of even such information being shared, Ajay Bhushan Pandey said, “We are moving to a regime where such kind of an intermingling of data between the various agencies are prohibited and without consent, it cannot be done.” He once again clarified that the impression that just because Aadhaar is being linked with various services and also liked to bank accounts exposes details of money in your account is not correct.

The Aadhaar Act and its mandatory linking are being heard in the Supreme Court, where multiple petitions have challenged it over privacy and constitutionality. Aadhaar — the 12-digit unique identity — came under a lot of criticism earlier this year when a newspaper report said that details of individuals were up for sale for Rs 500. The UIDAI, while assuring to step-up its security details, rejected claims that biometric details of individuals were breached.


Privacy is currently a hot topic around the globe after it was revealed that social-networking site Facebook shared data of its 87 million users with British political consulting firm Cambridge Analytica, which were used to influence voters. Facebook’s Mark Zuckerberg apologised for the scandal and vowed to enhance its privacy.

Tuesday, April 17, 2018

13301 - India's Aadhaar database and the challenges of reporting it Why covering the world's largest biometric database comes with huge risks for Indian journalists. - Al Jazeera




In January 2018, a local paper in the western Indian state of Punjab, The Tribune, published an article revealing that the private details of millions of Indians - gathered under the Aadhaar scheme - could be bought, cheap.

Aadhaar, a nationwide identity programme that is run by the Indian government, is the world's largest biometric identification system. The programme is the keystone in an ambitious plan to digitise India's economy and to make the distribution of state welfare more efficient.

It took over a decade to design and roll out, and more than 1.2 billion Indians have already signed up to it. But it's been dogged by legal challenges and questions over privacy.

Aadhaar is more dangerous [than Facebook], because it's essentially a disproportionate amount of data in the hands of the state. They're connecting things like traffic violations, property records, and land holding size, religion and caste, which is data which should not be linked to and collected and used by the state.

Nikhil Pahwa, founder and editor, Medianama
Despite news reports raising legitimate questions about data privacy and identity theft, the government body in charge of it, the Unique Identification Authority of India (UIDAI), insists that Aadhaar is secure.

Just days after The Tribune correspondent Rachna Khaira's data breach report was published, UIDAI filed a police complaint against her.

"I have been accused of hatching a conspiracy, I have been charged under Section 419, 420, 468, and 471, that pertains to cheating, impersonation, dishonesty, forgery, Section 36 and 37 of the Aadhaar Act, that is having unauthorised access to the database I have been accused, and now I am on the fugitive list of the Delhi Police," says Rachna Khaira.

"All I wanted was to highlight these concerns. I am depressed to see how officials instead of, paying concerns to the issues which I have raised in my story - they have made me a story," Khaira says.

The UIDAI's official line on data security has been that the reporting is inaccurate, overblown and misleading. However, many journalists say that dealing with the UIDAI is problematic, that officials there are elusive and often unavailable for comment.

"I would say that Aadhaar is more dangerous [than Facebook], because it's essentially a disproportionate amount of data in the hands of the state," explains Nikhil Pahwa, founding and editor of Medianama. "They're connecting things like traffic violations, property records, and land-holding size, religion and caste, which is data which should not be linked to and collected and used by the state. So, I think the risks are substantially greater in terms of misuse of this data."

But Zoheb Hossain, the lawyer representing UIDAI, says, "I think the two domains are extremely different and disparate. Facebook has far more personally sensitive information about you and me than Aadhaar. Aadhaar has very little information about you. Aadhaar is only a tool to match your identity and say that 'yes, you are who you claim to be.'"

Journalists covering the Aadhaar story are having to tread carefully. Two months after that Tribune report was published, the editor of the paper resigned. He gave no reason, but sources at the paper said the pressure on him after the Aadhaar expose was huge.

Contributors:
Rachna Khaira, reporter, The Tribune
Zoheb Hossain, lawyer for UIDAI
Nikhil Pahwa, founder and editor, MediaNama
Srinivas Kodali, cybersecurity specialist
Source: Al Jazeera News

Friday, April 13, 2018

13283 - Aadhaar Act, ‘A Badly Drafted One’, Sc Identifies Legal Loopholes; Uidai Defends - INC 42

The Secured Digitally-Signed QR Code Issued By UIDAI Has Now User’s Image Too, Along With The Demographic Details
April 12, 2018 10 min read
INC42 STAFF

In legal purview, the merits of Aadhaar can’t be used as a defence against the demerits of it.

While Union Minister Ravi Shankar Prasad terms Aadhaar a ‘digital identity’ that supplements one’s ‘physical identity’ the Supreme Court of India, hearing AG KK Venugopal and ASG Tushar Mehta’s arguments observed that several legal loopholes present in the Aadhaar Act.

Hearing the Aadhaar case on a day-to-day basis, the five-member constitution bench headed by CJI Dipak Misra noticed that the UIDAI had already validated biometric enrolments even before the law was enacted with retrospective effect.
Some of the major observations and responses are:
  • SC: There is no doubt that money laundering is a problem. The only question that needs to be answered is how will Aadhaar prevent money laundering.
  • SC To AG Venugopal: You have said that it was voluntary and with minimal invasion. We can’t hold that the fundamental rights can be waived off or compromised.
  • AG: In pre-2016 Aadhaar era, people gave their biometric data voluntarily and at that point of time, it did not violate the privacy as the right to privacy was not a fundamental right.
  • AG: The state has no interest in the collection of biometrics except for the benefit of the individual himself. We want to link Aadhaar not because we see people as criminals, but to protect them from crime.
Hearing a batch of petitions by the former Karnataka High Court Judge K.S. Puttuswamy, Magsaysay awardee Shanta Sinha, feminist researcher Kalyani Sen Menon, social activist Aruna Roy, Nikhil De, Nachiket Udupa, the SC has already countered many of the tall claims presented by the AG.

Countering the counted merits by the AG, the constitution bench commented, “Bank frauds don’t happen because of multiple identities. Banks do due diligence every time they give out loans. Frauds can’t happen unless bank employees are hand in glove.”

Similarly, “Terrorists don’t apply for Aadhaar. They don’t apply for SIMs. They acquire them.”

Aadhaar: Outside Courtroom
While the SC has been hearing the Aadhaar case since January 18, 2018, on a daily basis, Aadhaar developments outside the courtroom are equally engaging. The government has refused to withdraw the FIR filed against journalist Rachna Khaira while maintaining that there was no Aadhaar data leak or breach from the UIDAI-end. On January 3, 2018, Rachna in The Tribune had reported how Aadhaar logins and passwords are being sold along with the Aadhaar software that could pass potential information to wrong hands.

RELATED STORIES:

In an email conversation with Inc42 last month, Vivek Wadhwa, a Distinguished Fellow at Carnegie Mellon University had then commented, “This is just plain wrong. India’s greatest strength is its democracy and free press. Without this, the country will rapidly descend into darkness. The government should be thanking the people who have found the problems with the system, not punishing them. It should be offering rewards to people who can identify the weaknesses just as the tech companies offer bounties for hackers who find and report weaknesses in their systems.”

Meanwhile, to enable and boost offline Aadhaar verification process, the UIDAI has also replaced the existing QR code on eAadhaar having resident’s demographic details now with a secured digitally-signed QR Code which contains demographics along with the photograph of the Aadhaar holder.

As per UIDAI Chief Ajay Bhushan Pandey, this is a simple offline mechanism to quickly verify the genuineness of the Aadhaar card. However, to ensure that a person is a bona fide owner of the Aadhaar card, there has to be a manual check of the photo with the individual’s face or through use of agency-specific authentication scheme.

Amid Aadhaar biometric leaks exposed by a 28-year old French Security Researcher Batiste Robert alias Elliot Alderson, Aadhaar parent organisation UIDAI has recently added another layer of security as virtual IDs.

As per UIDAI, there will be now no need to share the real Aadhaar number at the time of authentication. Instead, a randomly generated 16-digit code will be shared with the agency every time. A user can generate multiple virtual IDs as per the need. The older IDs will get cancelled once a fresh ID is issued to the user. Since the virtual ID would get mapped to the individual’s Aadhaar number, the need to share the original Aadhaar number would be done away.

Aadhaar: Legal Loopholes
Aadhaar right from the UPA to the NDA time, has moved from strength to strength, from merely being notification or circular to a full-fledged Act now.

However, as indicated by the SC, Aadhaar has its own flaws which are legal and more. While Clause 32 of the Aadhaar Act rightly says, “It also provides that the Authority shall not, either by itself or through any entity under its control, collect, keep or maintain any information about the purpose of authentication,” Section 59 tries to justify Aadhaar by saying,  “…anything is done or any action taken by the Central Government under the Resolution of the Government of India, Planning Commission bearing notification number A-43011/02/2009-Admin. I, dated the 28th January, 2009, or by the Department of Electronics and Information Technology under the Cabinet Secretariat Notification bearing notification number S.O. 2492(E), dated the 12th September, 2015, as the case may be, shall be deemed to have been validly done or taken under this Act.”
The SC is still not convinced with implementing an Act like Aadhaar retrospectively.

BDT Acharya, former secretary of Lok Sabha in an IE column had pointed out that as per Article 110(1), a bill that contains only provisions dealing with the following qualifies as a money bill:
  • one – the imposition, abolition, remission, alteration or regulation of any tax;
  • two – regulation of borrowing or the giving of any guarantee by the government of India, or undertaking financial obligation by the government;
  • three – the custody of the Consolidated Fund of India (CFI) or the Contingency Fund of India, the payment of moneys into or withdrawal from them;
  • four – the appropriation of money out of the CFI;
  • five – declaring any expenditure as a charged expenditure on the CFI;
  • six – the receipt of money on account of the CFI or the public account of India or the ambit of accounts of the Union or of a state;
  • seven – any matter incidental to the above issues.
He further went on to say, “Let’s examine the Aadhaar bill in light of the above definition. The bill does not deal with imposition, abolition, alteration, etc. of tax; nor does it deal with the regulation of borrowing or giving a guarantee by the government or an amendment in respect of any financial obligation to be undertaken by the government. This bill also does not deal with the custody of the CFI, etc. The money paid into or withdrawn from such funds are incidental.”
Further, the Clause 4(3) which enables Aadhaar to be accepted as proof for “any purpose”, not merely for the payment of subsidy or other monetary benefits make Aadhaar Act to fall beyond the ambit of a Money bill.

While the Data (Privacy And Protection) Bill has been introduced in the Lok Sabha, the discussion and further proceeding could not occur, as the Parliament has not been allowed to function by the parties.

In a chat with Inc42, Robert alias Elliot averred, “Well, yes having a data protection policy is probably a good idea. It will force the companies,  apps or agencies to care about it and to make the correct implementation.”

Thus, what started with a mere notification, the Aadhaar Act still has enough loopholes to be questioned. And, this can’t be compared with the merits of the Aadhaar, as merits can’t complement Aadhaar demerits which must be dealt separately.
Besides, Elliot is not the first or last to point out the Aadhaar data leak. India Today, The Tribune, The Quint, and other media portals have already published a number of investigative reports suggesting the Aadhaar leak right from the data mining to data processing.

So far, the UIDAI has blacklisted more than 49,000 centres for Aadhaar data leak and not implementing the suggested standards. Most of the centres were shut down after complaint and the UIDAI never had its internal inspection unit in place, as part of its own preventive mechanism. Similar is the case of Aadhaar-data leak by various government organisations. There is no double check of these websites, their data storage and applications are in place, which the UIDAI has denied, as expected.

Angel Investor Mohandas Pai in an email conversation with Inc42 last month clarified, “All the incidents of any concern on Aadhaar data is because public authorities have not kept Data confidential, nothing to do with Aadhaar. The recent media issue was caused by theft of an administrator password and illegal hacking. If UIDAI and government had underestimated the scale would it be possible to have 119 cr registrations?”

There Is No Question Of Going Back!
The Aadhaar issue is still in the Court, and it is difficult to say which way it will land. However, the questions and issues raised by the five-member constitutional bench headed by CJI Dipak Misra have appeared so far constructive and the Judges have nowhere rejected the idea of having Aadhaar and its basic merits of social welfare. The Judges have, however, objected to the other USPs that the UIDAI wants to propagate such as, Aadhaar will stop money laundering or terrorist activities.
While the SC has clearly drawn a line between where Aadhaar must be linked and where it should be voluntary, the Indian government along with the UIDAI has not implemented the decision with the same enthusiasm it showed while linking.
As per the BBC, a dozen deaths have been registered pertaining to Aadhaar issues. Questioning the Aadhaar priority set by the Indian government, Santosh Min, a petitioner in the SC told CJI in person, “In imposing the Aadhaar, the government of the day wanted to keep track of every single paise earned by the citizen and on another hand, political parties can receive funds anonymously through electoral bonds.”

Santosh has complained that he could not withdraw his father’s hard-earned PF after his death, as the authorities have asked to provide the Aadhaar fingerprints for the same. Yet, another example of Aadhaar loophole.

Many hospitals still have the signboards that state, “Aadhaar is essential for the treatment”. As told by Mohandas Pai, most of the Aadhaar issues are implementational issues. Can’t the government just accept the issues and shut the loopholes once and for all?

Sunday, April 1, 2018

13162 - Aadhaar security lapse could allow major chunk of information to be stolen, says data security expert - First Post

India IndiaSpend Mar 30, 2018 13:28:55 IST
Comment 1

By Alison Saldanah

For the second time in the first three months of 2018, the vulnerabilities of the Aadhaar programme — the world’s largest biometric database — were exposed when American business technology website ZDNet reported on 23 March 23, 2018, that the personal data of millions of enrolled Indians could be accessed through unsecure websites and mobile apps of third-party agencies that use the identification system for authenticating transactions.

Aadhaar comprises a unique 12-digit number assigned to Indian residents. As of 29 March, 2018, more than 1.2 billion Indians — or 99.7 percent of the population — have enrolled in the programme. The database, which is fast becoming an integral part of Indian policy, includes fingerprints, iris scans and demographic details of every enrolled individual. From 1 July, 2018, the system will also include facial recognition for identity authentication purposes.

One night in mid-February 2018, in 30 minutes, data security expert Karan Saini, who identifies as a “white-hat” hacker (one who improves security by exposing vulnerabilities before malicious hackers or “black-hat” hackers can detect and exploit these), found the vulnerable point in the Aadhaar database through Indane, a commercial distributor of liquefied petroleum gas (LPG), owned by Indian Oil, a public-sector company. Indane, the second-largest marketer of LPG globally, caters to 110 million households across the country.

Fearing prosecution from the government, Saini reached out to a reporter at ZDnet to notify the Unique Identity Authority of India (UIDAI), in-charge of programme, of the security lapse.
Through Indane, not only could Saini gain access to the Aadhaar numbers, demographic and biometric data of several Indian residents, but also view details of where these individuals hold bank accounts, and what other services their Aadhaar numbers are linked to.

Prior to this, on 3 January, 2018, The Tribune, a Chandigarh newspaper, alleged in an investigation that unrestricted access to details of over one billion Aadhaar numbers could be purchased for as little as Rs 500.

Since its inception in 2011, Aadhaar has been caught in several debates, especially over privacy issues and information leaks. In the absence of a privacy law, lawyers and activists, who have challenged the Aadhaar Act, which essentially now mandates the enrollment of all citizens, as IndiaSpend reported in March 2017, argue that once the programme is linked to various services it will offer the government too much information too easily about individuals.

The UIDAI has dismissed these fears, maintaining that the central database, guarded by a 13-feet-high and five-feet-thick wall, is safe and insists the programme is a “serious effort to end corruption”. Arguing for the constitutional validity of Aadhaar, the UIDAI has denied Saini’s finding and The Tribune report of security lapses in the system during a Supreme Court (SC) hearing on Tuesday, 27 March, 2018.
“There has not been one data leak till date,” Ajay Bhushan Pandey, chief executive officer of UIDAI, told the SC.
In an interview with IndiaSpend, Saini, a freelance information-security professional based in New Delhi, discusses data security and privacy concerns in Aadhaar. Saini, occasionally also participates in “bug bounty programs” that involve identifying and reporting security vulnerabilities to companies. He has worked with Twitter, Uber and the US Department of Defence.

What prompted you to check the third-party security of Aadhaar data and what exactly did you find?
I started looking into the vulnerabilities of Aadhaar on a whim. On the Apple App Store, I found this mobile application ‘Aadhaar Status’ offered by Indian Oil, which claimed to allow you to check your Aadhaar seeding status with Indane. I started to dig into the app and the API [Application Program Interface] it used to access and retrieve Aadhaar data. I wanted to see if it had any security measures in place, and if so, whether and how they could potentially be bypassed. In a few minutes, I was able to determine that a few key countermeasures could be put in place to access the data for an endpoint as sensitive as this.
I found that by cycling through permutations of possible Aadhaar numbers — rapidly, since there was no limit on that like a Captcha or anything — I could get Aaadhar-linked data of other people, without the need for a one-time-password (OTP). After thoroughly checking that the Indane API was not blocking requests, especially when a large number of them were sent rapidly — I could send 5,000 requests in 5-10 minutes — I concluded that it would be possible for a malicious party with sufficient computing power and time to harvest vast amounts of Aadhaar-linked data in no time.

The app, which was also available on the Google PlayStore, has since been removed and the Indane API has been taken down but there is still evidence of it existing on several other third-party services as can be seen in this Google cache:

Google PlayStore app details
On paper, the intent of Aadhaar is to plug leaks and ensure that benefits reach the right individual, and also provide a one-stop verification process for service providers. In a way, sharing of personal data is inevitable in today’s world — so how do you think the government should negotiate big data and privacy needs?
We have to look at the Aadhaar infrastructure as a whole — it’s not just the government’s database to protect. With banks and third parties using the programme for identity verification, Aadhaar data remains partially compromised because it might be shared with parties who do not take data security issues seriously. We need a more comprehensive system to ensure these vendors — and other companies who have data related to or coming from Aadhaar — follow stringent norms to ensure they cannot use the data without taking the needed steps to protect it. Otherwise, it would be a violation of information that was originally provided to the government in good faith.
Do you think the Aadhaar programme adequately acknowledges the role third parties play in data security?

As of now, I don’t believe that these security issues are being properly addressed and remediated by the people in charge. However, they should be concerned. Right now, in not demanding and enforcing stricter data protection measures, neither the third parties with access to Aadhaar data nor the UIDAI are taking responsibility for significant security issues and concerns. This is highly problematic because the personal information of millions is at stake.
At the Supreme Court on Tuesday, 27 March, 2018, UIDAI’s CEO Ajay Bhushan Pandey insisted that except for third parties, the main database itself is well-protected and has not had a single breach yet. What are your findings?

I agree, the main Aadhaar ‘database’ itself might not be compromised. However, through third-party sharing there is potential for the data to become compromised — that should be a primary concern for the UIDAI. If Aadhaar did not exist, verification of identity, while more tedious, would restrict the amount of data a services company could hold about me. So if I sign up for a gas connection or telephone service, one would not have access to information about which bank I use. In fact, the CEO himself wrote to banks warning them to be more careful with Aadhaar authentication as the nature of data it holds could compromise the security of bank accounts, as The Hindu reported. With the information made publicly available through unsecured third parties, the UIDAI is introducing the potential for misuse. One could commit financial fraud or forge another Aadhaar card using its number and demographic details since the card that holds the Aadhaar number does not have any security features of its own — it’s just a card with a number, and in many cases, a two-step verification process with OTPs or fingerprints is not in place.
On the process of enrolment for Aadhaar, Pandey told the Supreme Court on Tuesday, 27 March, 2018, that there is no question of misuse because a 2048-bit encryption on Aadhaar data has been sent to the Central Identities Data Repository (CIDR). “It will take the whole universe’s strength to break this encryption,” he said. What does your assessment show?
I can’t comment on the CIDR’s susceptibility to misuse since I am not aware of it but again, for argument’s sake, (even if) the UIDAI is encrypting its data to this extent it has not clarified if third parties accessing the data for authentication are also encrypting it similarly. While a 2048-bit encryption is very good, that’s a standard requirement for the kind of data the central Aadhaar database holds. Further, we don’t seem to have clarity on how much of the data is encrypted or how the encryption has been carried out. At this point, it seems to be jargon thrown at the audience.

A man goes through the process of eye scanning for Unique Identification (UID) database system. Reuters
Not restricted to Aadhaar, privacy breaches and security incidents are occurring more often and are increasingly involving larger amounts of personal data. What do you make of the UIDAI’s response to these incidents?
I started looking at the Indane app in early February and approached a reporter to take the matter up with Indane and the UIDAI instead of approaching them myself fearing prosecution, given how similar matters have been dealt with in the past.
These last few months have shown that India is getting more serious about privacy and data security and that citizens want accountability for when incidents such as these take place. Increasingly, since we’re now generating so much more data than we ever have before, people have started becoming more concerned about protecting their data, especially when violations come to light.
The UIDAI’s response, when we approached them a month ahead of the story, notifying them of the vulnerable endpoint, was to do nothing. This could have been either because of lack of interest or because they felt that the problem was not too severe. But with more and more security issues being pointed out, there seems to be a clear need for proper redressal techniques.
In this particular case, many publications have inadvertently and inaccurately called this an ‘Aadhaar database breach’. This was not my intent. I found a security lapse which could have allowed for a major chunk of Aadhaar information to be stolen, if someone with that intent wanted to and knew of Indane’s issues.
There are problems with implementation of almost every technology, so understandably there will be errors with Aadhaar to work through as well. But if in the future, those that are responsible continue to deny issues and attempt to shut down conversations with the public, researchers may eventually just stop reporting bugs to them. The issues which are not captured by their internal security teams would simply remain vulnerable to malicious attacks. The government is more likely to succeed in keeping Aadhaar data safe by keeping the channels of communication open.
Distinguishing between the Aadhaar card and a smart card, Pandey said the central database of biometrics plays a key role in ensuring uniqueness and preventing identity theft. Surveillance is not possible with CIDR as silos are not merged but in smart cards, it is still possible by merging databases, he has said. What do you make of the CEO’s arguments on surveillance and identity theft?
While Aadhaar’s central database might be offline and secured, its online data-stores, which are significantly large too, are still merged with third parties like banks and telecom companies. So surveillance through them could still very much be a possibility.
Facial recognition for the sole purpose of authentication — where consent is given — should be completely fine, but only as long as it is used for just that and not for clandestine surveillance and tracking of individuals. If there are no laws in place to protect our rights and guarantee personal liberties, such as privacy, then our society and our very way of living would be put at risk. To quote Edward Snowden“Arguing that you don’t care about the right to privacy because you have nothing to hide is no different than saying you don’t care about free speech because you have nothing to say.” You don’t need to have anything to hide to be opposed to the idea of government surveillance.
It has been argued that privacy is a First World privilege. India is plagued by problems of poverty and deprivation and issues of privacy are ‘elitist’. Do you agree?
This is not just a rich man’s problem. Financial fraud through data breaches could affect the lives of anyone — in fact, it would impact the middle and working class the most, as it would be harder for them than others to recover from it.
I believe that by bringing these problems to light and discussing our rights as citizens we don’t digress from issues such as poverty and deprivation. The reality is that more Indians, regardless of their socio-economic status, are now connecting to smartphones and banking services — just as the Indian government had planned with its digital inclusion program — so obviously, the scope of those susceptible to security and privacy invasions is growing too. This can no longer be dismissed as an “elitist” problem.
The author is an assistant editor with IndiaSpend

Published Date: Mar 30, 2018 13:28 PM | Updated Date: Mar 30, 2018 13:28 PM

13160 - ‘I Found A Security Lapse In Aadhaar That Could Allow A Major Chunk Of Information To Be Stolen’ - India Spend


Alison Saldanha, March 30, 2018

Views
1597

Mumbai: For the second time in the first three months of 2018, the vulnerabilities of the Aadhaar programme–the world’s largest biometric database–were exposed when American business technology website ZDnet reported on March 23, 2018, that the personal data of millions of enrolled Indians could be accessed through unsecure websites and mobile apps of third-party agencies that use the identification system for authenticating transactions.

Aadhaar comprises a unique 12-digit number assigned to Indian residents. As of March 29, 2018, more than 1.2 billion Indians–or 99.7% of the population–have enrolled in the programme. The database, which is fast becoming an integral part of Indian policy, includes fingerprints, iris scans and demographic details of every enrolled individual. From July 1, 2018, the system will also include facial recognition for identity authentication purposes.

One night in mid-February 2018, in 30 minutes, data security expert Karan Saini, who identifies as a “white-hat” hacker (one who improves security by exposing vulnerabilities before malicious hackers or “black-hat” hackers can detect and exploit these), found the vulnerable point in the Aadhaar database through Indane, a commercial distributor of liquefied petroleum gas (LPG), owned by Indian Oil, a public-sector company. Indane, the second-largest marketer of LPG globally, caters to 110 million households across the country.

Fearing prosecution from the government, Saini reached out to a reporter at ZDnet to notify the Unique Identity Authority of India (UIDAI), in-charge of programme, of the security lapse.

Through Indane, not only could Saini gain access to the Aadhaar numbers, demographic data of several Indian residents, but also view details of where these individuals hold bank accounts, and what other services their Aadhaar numbers are linked to.

Prior to this, on January 3, 2018, The Tribune, a Chandigarh newspaper, alleged in an investigation that unrestricted access to details of over one billion Aadhaar numbers could be purchased for as little as Rs 500.

Since its inception in 2011, Aadhaar has been caught in several debates, especially over privacy issues and information leaks. In the absence of a privacy law, lawyers and activists, who have challenged the Aadhaar Act, which essentially now mandates the enrollment of all citizens, as IndiaSpend reported in March 2017, argue that once the programme is linked to various services it will offer the government too much information too easily about individuals.

The UIDAI has dismissed these fears, maintaining that the central database, guarded by a 13-feet-high and five-feet-thick wall, is safe and insists the programme is a “serious effort to end corruption”. Arguing for the constitutional validity of Aadhaar, the UIDAI has denied Saini’s finding and The Tribune report of security lapses in the system during a Supreme Court (SC) hearing on Tuesday, March 27, 2018.

“There has not been one data leak till date,” Ajay Bhushan Pandey, chief executive officer of UIDAI, told the SC.  

In an interview with IndiaSpend, Saini, a freelance information-security professional based in New Delhi, discusses data security and privacy concerns in Aadhaar. Saini, occasionally also participates in “bug bounty programs” that involve identifying and reporting security vulnerabilities to companies. He has worked with Twitter, Uber and the US department of defense.

What prompted you to check the third-party security of Aadhaar data and what exactly did you find?

I started looking into the vulnerabilities of Aadhaar on a whim. On the Apple App Store, I found this mobile application ‘Aadhaar Status’ offered by Indian Oil, which claimed to allow you to check your Aadhaar seeding status with Indane. I started to dig into the app and the API [Application Program Interface] it used to access and retrieve Aadhaar data. I wanted to see if it had any security measures in place, and if so, whether and how they could potentially be bypassed. In a few minutes, I was able to determine that a few key countermeasures could be put in place to access the data for an endpoint as sensitive as this.

I found that by cycling through permutations of possible Aadhaar numbers–rapidly, since there was no limit on that like a Captcha or anything–I could get Aaadhar-linked data of other people, without the need for a one-time-password (OTP). After thoroughly checking that the Indane API was not blocking requests, especially when a large number of them were sent rapidly–I could send 5,000 requests in 5-10 minutes–I concluded that it would be possible for a malicious party with sufficient computing power and time to harvest vast amounts of Aadhaar-linked data in no time.

The app, which was also available on the Google PlayStore, has since been removed and the Indane API has been taken down but there is still evidence of it existing on several other third-party services as can be seen in this Google cache:



On paper, the intent of Aadhaar is to plug leaks and ensure that benefits reach the right individual, and also provide a one-stop verification process for service providers. In a way, sharing of personal data is inevitable in today’s world–so how do you think the government should negotiate big data and privacy needs?

We have to look at the Aadhaar infrastructure as a whole–it’s not just the government’s database to protect. With banks and third parties using the programme for identity verification, Aadhaar data remains partially compromised because it might be shared with parties who do not take data security issues seriously. We need a more comprehensive system to ensure these vendors–and other companies who have data related to or coming from Aadhaar–follow stringent norms to ensure they cannot use the data without taking the needed steps to protect it. Otherwise, it would be a violation of information that was originally provided to the government in good faith.

Do you think the Aadhaar programme adequately acknowledges the role third parties play in data security?

As of now, I don’t believe that these security issues are being properly addressed and remediated by the people in charge. However, they should be concerned. Right now, in not demanding and enforcing stricter data protection measures, neither the third parties with access to Aadhaar data nor the UIDAI are taking responsibility for significant security issues and concerns. This is highly problematic because the personal information of millions is at stake.

At the Supreme Court on Tuesday, March 27, 2018, UIDAI’s CEO Ajay Bhushan Pandey insisted that except for third parties, the main database itself is well-protected and has not had a single breach yet. What are your findings?




ABP says software is secure and there hasn't been one data leak till date. Tells court to not believe media reports. Denies recent report of breach by ZDnet




ABP rubbishes the report by tribune also.


I agree, the main Aadhaar ‘database’ itself might not compromised. However, through third-party sharing there is potential for the data to become compromised–that should be a primary concern for the UIDAI. If Aadhaar did not exist, verification of identity, while more tedious, would restrict the amount of data a services company could hold about me. So if I sign up for a gas connection, or telephone service, one would not have access to information about which bank I use. In fact, the CEO himself wrote to banks warning them to be more careful with Aadhaar authentication as the nature of data it holds could compromise the security of bank accounts, as The Hindu reported. With the information made publicly available through unsecure third parties, the UIDAI is introducing potential for misuse. One could commit financial fraud or forge another Aadhaar card using its number and demographic details since the card that holds the Aadhaar number does not have any security features of its own–it’s just a card with a number, and in many cases a two-step verification process with OTPs or fingerprints is not in place.

On the process of enrolment for Aadhaar, Pandey told the Supreme Court on Tuesday, March 27, 2018, that there is no question of misuse because a 2048-bit encryption on Aadhaar data has been sent to the Central Identities Data Repository (CIDR). “It will take the whole universe’s strength to break this encryption,” he said. What does your assessment show?

I can’t comment on the CIDR’s susceptibility to misuse since I am not aware of it but again, for argument’s sake, (even if) the UIDAI is encrypting its data to this extent it has not clarified if third parties accessing the data for authentication are also encrypting it similarly. While a 2048-bit encryption is very good, that’s a standard requirement for the kind of data the central Aadhaar database holds. Further, we don’t seem to have clarity on how much of the data is encrypted or how the encryption has been carried out. At this point, it seems to be jargon thrown at the audience.

Not restricted to Aadhaar, privacy breaches and security incidents are occurring more often and are increasingly involving larger amounts of personal data. What do you make of the UIDAI’s response to these incidents?

I started looking at the Indane app in early February, and approached a reporter to take the matter up with Indane and the UIDAI instead of approaching them myself fearing prosecution, given how similar matters have been dealt with in the past.

These last few months have shown that India is getting more serious about privacy and data security, and that citizens want accountability for when incidents such as these take place. Increasingly, since we’re now generating so much more data than we ever have before, people have started becoming more concerned about protecting their data, especially when violations come to light.

The UIDAI’s response, when we approached them a month ahead of the story, notifying them of the vulnerable endpoint, was to do nothing. This could have been either because of lack of interest or because they felt that the problem was not too severe. But with more and more security issues being pointed out, there seems to be a clear need for proper redressal techniques. In this particular case, many publications have inadvertently and inaccurately called this an ‘Aadhaar database breach’. This was not my intent. I found a security lapse which could have allowed for a major chunk of Aadhaar information to be stolen, if someone with that intent wanted to and knew of Indane’s issues.

There are problems with implementation of almost every technology, so understandably there will be errors with Aadhaar to work through as well. But if in the future, those that are responsible continue to deny issues and attempt to shut down conversations with the public, researchers may eventually just stop reporting bugs to them. The issues which are not captured by their internal security teams would simply remain vulnerable to malicious attacks. The government is more likely to succeed in keeping Aadhaar data safe by keeping the channels of communication open.

Distinguishing between the Aadhaar card and a smart card, Pandey said the central database of biometrics plays a key role in ensuring uniqueness and preventing identity theft. Surveillance is not possible with CIDR as silos are not merged but in smart cards, it is still possible by merging databases, he has said. What do you make of the CEO’s arguments on surveillance and identity theft?




ABP: there's no identity theft if Aadhaar is lost. The same cannot be said of smart cards.
Surveillance is not possible with CIDR as silos are not merged. Surveillance is possible by smart cards by merging databases.


While Aadhaar’s central database might be offline and secured, its online data-stores, which are significantly large too, are still merged with third parties like banks and telecom companies. So surveillance through them could still very much be a possibility.

Facial recognition for the sole purpose of authentication–where consent is given–should be completely fine, but only as long as it is used for just that and not for clandestine surveillance and tracking of individuals. If there are no laws in place to protect our rights and guarantee personal liberties, such as privacy, then our society and our very way of living would be put at risk. To quote Edward Snowden: “Arguing that you don’t care about the right to privacy because you have nothing to hide is no different than saying you don’t care about free speech because you have nothing to say.” You don’t need to have anything to hide to be opposed to the idea of government surveillance.

It has been argued that privacy is a First World privilege. India is plagued by problems of poverty and deprivation and issues of privacy are ‘elitist’. Do you agree?

This is not just a rich man’s problem; financial fraud through data breaches could affect the lives of anyone– in fact it would impact the middle and working class the most, as it would be harder for them than others to recover from it.

I believe that by bringing these problems to light and discussing our rights as citizens we don’t digress from issues such as poverty and deprivation. The reality is that more Indians, regardless of their socio-economic status, are now connecting to smart phones and banking services — just as the Indian government had planned with its digital inclusion program — so obviously, the scope of those susceptible to security and privacy invasions, is growing too. This can no longer be dismissed as an “elitist” problem.

(Saldanha is an assistant editor with IndiaSpend.)

Update: An earlier version of the story said that through third-party mobile application Indane, Karan Saini could access Aadhaar numbers, demographic and biometric data of several Indian residents, including details of their bank accounts, and what other services their Aadhaar numbers are linked to. Saini has since clarified that biometric data were not accessible.

We welcome feedback. Please write to respond@indiaspend.org. We reserve the right to edit responses for language and grammar.
__________________________________________________


“Liked this story? Indiaspend.org is a non-profit, and we depend on readers like you to drive our public-interest journalism efforts. Donate Rs 500; Rs 1,000, Rs 2,000.”

13159 - Aadhaar security flaw can give access to data without OTP: Ethical hacker - Business Standard


Facial recognition for the sole purpose of authentication-where consent is given-should be completely fine, but only as long as it is not used for clandestine surveillance, says Karan Saini

Last Updated at March 31, 2018 12:24 IST


For the second time in the first three months of 2018, the vulnerabilities of the Aadhaar programme–the world’s largest biometric database–were exposed when American business technology website ZDnet reported on March 23, 2018, that the personal data of millions of enrolled Indians could be accessed through unsecure websites and mobile apps of third-party agencies that use the identification system for authenticating transactions.

Aadhaar comprises a unique 12-digit number assigned to Indian residents. As of March 29, 2018, more than 1.2 billion Indians–or 99.7% of the population–have enrolled in the programme. The database, which is fast becoming an integral part of Indian policy, includes fingerprints, iris scans and demographic details of every enrolled individual. From July 1, 2018, the system will also include facial recognition for identity authentication purposes.

One night in mid-February 2018, in 30 minutes, data security expert Karan Saini, who identifies as a “white-hat” hacker (one who improves security by exposing vulnerabilities before malicious hackers or “black-hat” hackers can detect and exploit these), found the vulnerable point in the Aadhaar database through Indane, a commercial distributor of liquefied petroleum gas (LPG), owned by Indian Oil, a public-sector company. Indane, the second-largest marketer of LPG globally, caters to 110 million households across the country.

Fearing prosecution from the government, Saini reached out to a reporter at ZDnet to notify the Unique Identity Authority of India (UIDAI), in-charge of programme, of the security lapse.
Through Indane, not only could Saini gain access to the Aadhaar numbers, demographic data of several Indian residents, but also view details of where these individuals hold bank accounts, and what other services their Aadhaar numbers are linked to. 

Prior to this, on January 3, 2018, The Tribune, a Chandigarh newspaper, alleged in an investigation that unrestricted access to details of over one billion Aadhaar numbers could be purchased for as little as Rs 500.

Since its inception in 2011, Aadhaar has been caught in several debates, especially over privacy issues and information leaks. In the absence of a privacy law, lawyers and activists, who have challenged the Aadhaar Act, which essentially now mandates the enrolment of all citizens, as IndiaSpend reported in March 2017, argue that once the programme is linked to various services it will offer the government too much information too easily about individuals.

The UIDAI has dismissed these fears, maintaining that the central database, guarded by a 13-feet-high and five-feet-thick wall, is safe and insists the programme is a “serious effort to end corruption”. Arguing for the constitutional validity of Aadhaar, the UIDAI has denied Saini’s finding and The Tribune report of security lapses in the system during a Supreme Court (SC) hearing on Tuesday, March 27, 2018.

“There has not been one data leak till date,” Ajay Bhushan Pandey, chief executive officer of UIDAI, told the SC.
In an interview with IndiaSpend, Saini, a freelance information-security professional based in New Delhi, discusses data security and privacy concerns in Aadhaar. Saini, occasionally also participates in “bug bounty programs” that involve identifying and reporting security vulnerabilities to companies. He has worked with Twitter, Uber and the US Department of Defense. 

What prompted you to check the third-party security of Aadhaar data and what exactly did you find?
I started looking into the vulnerabilities of Aadhaar on a whim. On the Apple App Store, I found this mobile application ‘Aadhaar Status’ offered by Indian Oil, which claimed to allow you to check your Aadhaar seeding status with Indane. I started to dig into the app and the API [Application Program Interface] it used to access and retrieve Aadhaar data. I wanted to see if it had any security measures in place, and if so, whether and how they could potentially be bypassed. In a few minutes, I was able to determine that a few key countermeasures could be put in place to access the data for an endpoint as sensitive as this.

I found that by cycling through permutations of possible Aadhaar numbers–rapidly, since there was no limit on that like a Captcha or anything–I could get Aaadhar-linked data of other people, without the need for a one-time-password (OTP). After thoroughly checking that the Indane API was not blocking requests, especially when a large number of them were sent rapidly–I could send 5,000 requests in 5-10 minutes–I concluded that it would be possible for a malicious party with sufficient computing power and time to harvest vast amounts of Aadhaar-linked data in no time.

The app, which was also available on the Google PlayStore, has since been removed and the Indane API has been taken down but there is still evidence of it existing on several other third-party services as can be seen in this Google cache:



On paper, the intent of Aadhaar is to plug leaks and ensure that benefits reach the right individual, and also provide a one-stop verification process for service providers. In a way, sharing of personal data is inevitable in today’s world–so how do you think the government should negotiate big data and privacy needs?
We have to look at the Aadhaar infrastructure as a whole–it’s not just the government’s database to protect. With banks and third parties using the programme for identity verification, Aadhaar data remains partially compromised because it might be shared with parties who do not take data security issues seriously. We need a more comprehensive system to ensure these vendors–and other companies who have data related to or coming from Aadhaar–follow stringent norms to ensure they cannot use the data without taking the needed steps to protect it. Otherwise, it would be a violation of information that was originally provided to the government in good faith.

Do you think the Aadhaar programme adequately acknowledges the role third parties play in data security?
As of now, I don’t believe that these security issues are being properly addressed and remediated by the people in charge. However, they should be concerned. Right now, in not demanding and enforcing stricter data protection measures, neither the third parties with access to Aadhaar data nor the UIDAI are taking responsibility for significant security issues and concerns. This is highly problematic because the personal information of millions is at stake.

At the Supreme Court on Tuesday, March 27, 2018, UIDAI’s CEO Ajay Bhushan Pandey insisted that except for third parties, the main database itself is well-protected and has not had a single breach yet. What are your findings?




ABP says software is secure and there hasn't been one data leak till date. Tells court to not believe media reports. Denies recent report of breach by ZDnet




ABP rubbishes the report by tribune also.


I agree, the main Aadhaar ‘database’ itself might not compromised. However, through third-party sharing there is potential for the data to become compromised–that should be a primary concern for the UIDAI. If Aadhaar did not exist, verification of identity, while more tedious, would restrict the amount of data a services company could hold about me. So if I sign up for a gas connection, or telephone service, one would not have access to information about which bank I use. In fact, the CEO himself wrote to banks warning them to be more careful with Aadhaar authentication as the nature of data it holds could compromise the security of bank accounts, as The Hindu reported. With the information made publicly available through unsecure third parties, the UIDAI is introducing potential for misuse. One could commit financial fraud or forge another Aadhaar card using its number and demographic details since the card that holds the Aadhaar number does not have any security features of its own–it’s just a card with a number, and in many cases a two-step verification process with OTPs or fingerprints is not in place.

On the process of enrolment for Aadhaar, Pandey told the Supreme Court on Tuesday, March 27, 2018, that there is no question of misuse because a 2048-bit encryption on Aadhaar data has been sent to the Central Identities Data Repository (CIDR). “It will take the whole universe’s strength to break this encryption,” he said. What does your assessment show?

I can’t comment on the CIDR’s susceptibility to misuse since I am not aware of it but again, for argument’s sake, (even if) the UIDAI is encrypting its data to this extent it has not clarified if third parties accessing the data for authentication are also encrypting it similarly. While a 2048-bit encryption is very good, that’s a standard requirement for the kind of data the central Aadhaar database holds. Further, we don’t seem to have clarity on how much of the data is encrypted or how the encryption has been carried out. At this point, it seems to be jargon thrown at the audience.

Not restricted to Aadhaar, privacy breaches and security incidents are occurring more often and are increasingly involving larger amounts of personal data. What do you make of the UIDAI’s response to these incidents?
I started looking at the Indane app in early February, and approached a reporter to take the matter up with Indane and the UIDAI instead of approaching them myself fearing prosecution, given how similar matters have been dealt with in the past.

These last few months have shown that India is getting more serious about privacy and data security, and that citizens want accountability for when incidents such as these take place. Increasingly, since we’re now generating so much more data than we ever have before, people have started becoming more concerned about protecting their data, especially when violations come to light.

The UIDAI’s response, when we approached them a month ahead of the story, notifying them of the vulnerable endpoint, was to do nothing. This could have been either because of lack of interest or because they felt that the problem was not too severe. But with more and more security issues being pointed out, there seems to be a clear need for proper redressal techniques. In this particular case, many publications have inadvertently and inaccurately called this an ‘Aadhaar database breach’. This was not my intent. I found a security lapse which could have allowed for a major chunk of Aadhaar information to be stolen, if someone with that intent wanted to and knew of Indane’s issues.

There are problems with implementation of almost every technology, so understandably there will be errors with Aadhaar to work through as well. But if in the future, those that are responsible continue to deny issues and attempt to shut down conversations with the public, researchers may eventually just stop reporting bugs to them. The issues which are not captured by their internal security teams would simply remain vulnerable to malicious attacks. The government is more likely to succeed in keeping Aadhaar data safe by keeping the channels of communication open.

Distinguishing between the Aadhaar card and a smart card, Pandey said the central database of biometrics plays a key role in ensuring uniqueness and preventing identity theft. Surveillance is not possible with CIDR as silos are not merged but in smart cards, it is still possible by merging databases, he has said. What do you make of the CEO’s arguments on surveillance and identity theft?




ABP: there's no identity theft if Aadhaar is lost. The same cannot be said of smart cards.

Surveillance is not possible with CIDR as silos are not merged. Surveillance is possible by smart cards by merging databases.


While Aadhaar’s central database might be offline and secured, its online data-stores, which are significantly large too, are still merged with third parties like banks and telecom companies. So surveillance through them could still very much be a possibility.
Facial recognition for the sole purpose of authentication–where consent is given–should be completely fine, but only as long as it is used for just that and not for clandestine surveillance and tracking of individuals. If there are no laws in place to protect our rights and guarantee personal liberties, such as privacy, then our society and our very way of living would be put at risk.
To quote Edward Snowden: “Arguing that you don’t care about the right to privacy because you have nothing to hide is no different than saying you don’t care about free speech because you have nothing to say.” You don’t need to have anything to hide to be opposed to the idea of government surveillance.

It has been argued that privacy is a First World privilege. India is plagued by problems of poverty and deprivation and issues of privacy are ‘elitist’. Do you agree?

This is not just a rich man’s problem; financial fraud through data breaches could affect the lives of anyone– in fact it would impact the middle and working class the most, as it would be harder for them than others to recover from it.

I believe that by bringing these problems to light and discussing our rights as citizens we don’t digress from issues such as poverty and deprivation. The reality is that more Indians, regardless of their socio-economic status, are now connecting to smart phones and banking services — just as the Indian government had planned with its digital inclusion program — so obviously, the scope of those susceptible to security and privacy invasions, is growing too. This can no longer be dismissed as an “elitist” problem.

(Saldanha is an assistant editor with IndiaSpend.)
Reprinted with permission from IndiaSpend.org, a data-driven, public-interest journalism non-profit organisation.

First Published: Fri, March 30 2018. 09:31 IST