In 2009, I became extremely concerned with the concept of Unique Identity for various reasons. Connected with many like minded highly educated people who were all concerned.
On 18th May 2010, I started this Blog to capture anything and everything I came across on the topic. This blog with its million hits is a testament to my concerns about loss of privacy and fear of the ID being misused and possible Criminal activities it could lead to.
In 2017 the Supreme Court of India gave its verdict after one of the longest hearings on any issue. I did my bit and appealed to the Supreme Court Judges too through an On Line Petition.
In 2019 the Aadhaar Legislation has been revised and passed by the two houses of the Parliament of India making it Legal. I am no Legal Eagle so my Opinion carries no weight except with people opposed to the very concept.
In 2019, this Blog now just captures on a Daily Basis list of Articles Published on anything to do with Aadhaar as obtained from Daily Google Searches and nothing more. Cannot burn the midnight candle any longer.
"In Matters of Conscience, the Law of Majority has no place"- Mahatma Gandhi
Ram Krishnaswamy
Sydney, Australia.

Aadhaar

The UIDAI has taken two successive governments in India and the entire world for a ride. It identifies nothing. It is not unique. The entire UID data has never been verified and audited. The UID cannot be used for governance, financial databases or anything. It’s use is the biggest threat to national security since independence. – Anupam Saraph 2018

When I opposed Aadhaar in 2010 , I was called a BJP stooge. In 2016 I am still opposing Aadhaar for the same reasons and I am told I am a Congress die hard. No one wants to see why I oppose Aadhaar as it is too difficult. Plus Aadhaar is FREE so why not get one ? Ram Krishnaswamy

First they ignore you, then they laugh at you, then they fight you, then you win.-Mahatma Gandhi

In matters of conscience, the law of the majority has no place.Mahatma Gandhi

“The invasion of privacy is of no consequence because privacy is not a fundamental right and has no meaning under Article 21. The right to privacy is not a guaranteed under the constitution, because privacy is not a fundamental right.” Article 21 of the Indian constitution refers to the right to life and liberty -Attorney General Mukul Rohatgi

“There is merit in the complaints. You are unwittingly allowing snooping, harassment and commercial exploitation. The information about an individual obtained by the UIDAI while issuing an Aadhaar card shall not be used for any other purpose, save as above, except as may be directed by a court for the purpose of criminal investigation.”-A three judge bench headed by Justice J Chelameswar said in an interim order.

Legal scholar Usha Ramanathan describes UID as an inverse of sunshine laws like the Right to Information. While the RTI makes the state transparent to the citizen, the UID does the inverse: it makes the citizen transparent to the state, she says.

Good idea gone bad
I have written earlier that UID/Aadhaar was a poorly designed, unreliable and expensive solution to the really good idea of providing national identification for over a billion Indians. My petition contends that UID in its current form violates the right to privacy of a citizen, guaranteed under Article 21 of the Constitution. This is because sensitive biometric and demographic information of citizens are with enrolment agencies, registrars and sub-registrars who have no legal liability for any misuse of this data. This petition has opened up the larger discussion on privacy rights for Indians. The current Article 21 interpretation by the Supreme Court was done decades ago, before the advent of internet and today’s technology and all the new privacy challenges that have arisen as a consequence.

Rajeev Chandrasekhar, MP Rajya Sabha

“What is Aadhaar? There is enormous confusion. That Aadhaar will identify people who are entitled for subsidy. No. Aadhaar doesn’t determine who is eligible and who isn’t,” Jairam Ramesh

But Aadhaar has been mythologised during the previous government by its creators into some technology super force that will transform governance in a miraculous manner. I even read an article recently that compared Aadhaar to some revolution and quoted a 1930s historian, Will Durant.Rajeev Chandrasekhar, Rajya Sabha MP

“I know you will say that it is not mandatory. But, it is compulsorily mandatorily voluntary,” Jairam Ramesh, Rajya Saba April 2017.

August 24, 2017: The nine-judge Constitution Bench rules that right to privacy is “intrinsic to life and liberty”and is inherently protected under the various fundamental freedoms enshrined under Part III of the Indian Constitution

"Never doubt that a small group of thoughtful, committed citizens can change the World; indeed it's the only thing that ever has"

“Arguing that you don’t care about the right to privacy because you have nothing to hide is no different than saying you don’t care about free speech because you have nothing to say.” -Edward Snowden

In the Supreme Court, Meenakshi Arora, one of the senior counsel in the case, compared it to living under a general, perpetual, nation-wide criminal warrant.

Had never thought of it that way, but living in the Aadhaar universe is like living in a prison. All of us are treated like criminals with barely any rights or recourse and gatekeepers have absolute power on you and your life.

Announcing the launch of the # BreakAadhaarChainscampaign, culminating with events in multiple cities on 12th Jan. This is the last opportunity to make your voice heard before the Supreme Court hearings start on 17th Jan 2018. In collaboration with @no2uidand@rozi_roti.

UIDAI's security seems to be founded on four time tested pillars of security idiocy

1) Denial

2) Issue fiats and point finger

3) Shoot messenger

4) Bury head in sand.

God Save India

Showing posts with label Raj Mashroowala. Show all posts
Showing posts with label Raj Mashroowala. Show all posts

Sunday, July 17, 2016

10157 - Trust at your fingertips Narayanan Krishnaswami | TNN


Narayanan Krishnaswami | TNN | Jun 19, 2016, 07.01 PM

Aadhaar's use of biometrics might not allay the fears of privacy activists but Anil K Jain, the 68-year-old computer scientist who helped build the system, says it offers more privacy than what is in the US. 

Jain, an award winning professor from the Michigan State University, holds several patents in fingerprint recognition. The IIT Kanpur alumnus, who was in the city recently, talks about how security concerns have led to the rise of biometrics. 

How did you get into biometrics? 

I was doing my PhD at Ohio State University in 1973. I was working on pattern recognition and image quality. One of the research projects that my advisor had was funded by the United States Air Force. The USAF wanted to use computers to distinguish between three kinds of aircraft: MiG, Mirage and Phantom based on features extracted from their photographs. You've got to remember that this was when we were using punch cards to communicate with mainframes. It was a cumbersome process. We bought model airplanes and photographed them from a variety of angles. 

Later on, in 2001, we got a call from another federal agency, which had funded the development of a new powerful computer processor, called FPGA (Field Programmable Gate Array), one that could be reconfigured for specific tasks. The object was pattern recognition again, and my students and I conceived that fingerprint recognition would be a good way of using this processor's capabilities. 

How did you get involved with the Aadhaar programme? 

I got involved during the planning stages, around 2008. At that time, Nandan Nilekani had recruited Raj Mashruwala, an entrepreneur from the Silicon Valley, for it. Mashruwala contacted me because he believed the project could use my experience with biometrics, in particular fingerprint recognition. 

I began as an advisor, and my main job was to assist in the biometric deduplications system design (avoiding redundant information) and technical specifications for the vendors. I also roped in other people - experts, and my ex-students to help with this massive task. 

Why has biometric identification taken off in a big way? 

In the 60s if you said that your fingerprints had been taken, it meant that you were suspected of a crime. In other words, the word "fingerprinting" had the connotation of "criminality". Then, fingerprints began to be used by various government agencies to conduct "background check" for people working in sensitive jobs. Before, when people stayed and worked in the same locality, and everyone knew everyone else, you could settle things with a handshake. But now, especially with the increase of security threats, there has been a decline in trust. All of this has led to the necessity and acceptance of biometrics. 

How does computerized fingerprint identification work? 

If you take a look at your finger, you will see it is a series of ridges and valleys. Sometimes, a ridge will end at a point - or will branch out. Now these points are distinctive, and are called minutiae. When you give your fingerprints to the Aadhaar programme - or elsewhere, the images are stored as 512x512 pixels. At that resolution, you will be able to get anything between 60 to 100 minutiae points for each fingerprint, and these are stored in the database. Now, when you give your fingerprints say when you are entering the US, and they check to see whether you are on file, what happens is that these points are matched. If there are 20-25 matches of these points, we can state that the same finger made both prints. 

It's a similar principle to what Apple or Samsung use when they use your fingerprint to allow you to access your phone. But those fingerprints are stored at 90x90 pixels, and therefore the number of points stored is fewer. So even six matches would mean a fingerprint match, so the manufacturers have to use additional methods to bolster security. 

But that leads to other problems. At my lab, we've been able to use a special kind of paper to generate fingerprints that can be used to open phones. The printer prints out fingerprints on the paper, and you can use the printed fingerprint on your phone's detector to unlock the phone. 

What are the misconceptions about biometrics? 

The most common problem that I have seen is that people think that biometrics is foolproof. Every security system is prone to error. What we need to ask is 'What is the error rate?' Another problem is that sometimes people expect too much. A good biometrics system costs a lot of money, and one of the first questions people ask is 'What is the ROI'. But the problem is most current systems are inadequate as far as security is concerned. 

And that's something I've heard as far as Aadhaar is concerned. What you have to remember is that Aadhaar is not a security system. It is for giving the underprivileged access to services. Now, if you remember, after 911, the 911 commission found that while all the US security had some information about the impending attacks, they were not able to prevent them because they didn't talk to each other. Now, after implementing the recommendations, the FBI can do a search and match a face from an image in a CCTV feed to driving licence database. 

The Aadhaar programme provides more privacy than that. The only thing that you can do is query the database - 'Do these fingerprints belong to this person?' and the only answers are yes or no.

Monday, May 9, 2016

9925 - IIT alumni duo Raj Mashruwala, Avinash Manudane to fund ideas in healthcare space - Economi Times


DIVYA RAJAGOPAL, ET Bureau May 3, 2016, 11.32AM IST


MUMBAI: Raj Mashruwala and Avinash Manudane, two IIT Bombay alumni, want Indians to come up with solutions to India's varied healthcare issues. Their wishes are not mere empty talks, the two Silicon Valley investors are offering 50,000 fellowship every month for two years to any Indian who has an innovative idea in the healthcare space.

The Centre for Healthcare Entrepreneurship at IIT Hyderabad will throw its door open to a maximum of 12 potential entrepreneurs who will take up a residency programme in the campus where candidates will receive mix of classroom knowledge and also cut their teeth by spending a year researching on field with various medical professionals, investors on trying to bring a solution to healthcare need.

"Most of the innovation facilities in India are either too classroom oriented or merely serve as a cheap rental space," said Raj Mashruwala, angel investor and IIT Bombay alumni. "What we want to do is bring together the interdisciplinary knowledge along with VCs, clinicians and the industry to come up with a healthcare solution for India," he added.

Mashruwala, who was one of the core team member of Nandan Nilekani's Aadhaar project, wants to replicate the system for healthcare. Aadhaar has connected over six million Indians, Mashruwala said they want to do the same for healthcare.

The fellowship is designed in such a way that the first year the candidates will spend time identifying need by hitting the ground working in hospitals with doctors and medical professionals to identify the problem, following which the teams will create a prototype and pitch the idea to investors who will later mentor them on fine tuning the business plan.

Monday, February 4, 2013

2942 - Could India's Biometric Database Work in the US?


Could India's Biometric Database Work in the US?
By Francie Diep, TechNewsDaily Staff Writer
Published January 18, 2013
TechNewsDaily

Could U.S. residents get a biometrics-based ID like India's? 
(From Homeland Security) 

In the eastern Indian state of Jharkhand, those visiting government-subsidized shops have a new way to pay. Jharkhand is testing hand-held machines called micro-ATMs, which scan people's fingerprints to verify their identity before they do some basic banking, such as depositing or withdrawing cash. 
Many micro-ATM users have never held a bank account before, or owned a smartphone or a computer. The technology is part of Aadhaar, a government-run project that has now scanned and saved data from the irises and fingerprints of more than 255 million Indians. 

Aadhaar works much like U.S. Social Security numbers do. It gives every enrollee a unique 12-digit identification number and an easy way to prove his identity — basic functions that U.S. residents may take for granted, but that have been a problem in India, especially for its poorest citizens.  Officials and supporters hope Aadhaar will help India's poor gain benefits while curbing theft and fraud. The country has never had such a widespread ID.

As the number of Aadhaar's enrollees approaches the population of the United States, which is just under 312 million, we at TechNewsDaily wondered if the U.S. could ever get a biometrics-based ID program. [SEE ALSO: 7 Biometric Technologies on the Horizon]

Not likely, said the experts we contacted. The United States doesn't have the same need for it that India does, and Americans are warier of privacy issues. Yet that doesn't mean U.S. agencies aren't watching Aadhaar's historic growth, gleaning lessons that they might apply to homeland security schemes in the future. 

Why not in the U.S.?
One of the major goals of Aadhaar is to bring basic banking to more Indian adults. Only 35 percent of Indians age 15 and older have an account at a formal financial institution, according to the World Bank. Poorer people and women are less likely to have an account, which means they're unable earn interest and are at risk for theft.

Aadhaar's first steps toward banking won't be big. "I'm basically talking about depositing money, just taking out cash," said Ravi Bapna, a professor in the school of management at the University of Minnesota. Bapna spoke with TechNewsDaily over Skype from India, where he had taken his graduate students to meet Aadhaar chairman Nandan Nilekani and learn about the program. 

"We're not talking about loans, we're not talking about mortgages, we're not talking about insurance products," Bapna said. Such services will come in the future, he added.

In addition, the Indian government hopes that Aadhaar-enabled bank accounts will allow for the direct deposit of benefits, such as scholarships and food subsidies. Right now, such benefits reach people through middlemen who often take cuts illegally. Many experts have called India's benefits programs "broken."

The United States doesn't have problems of comparable severity. Eighty-eight percent of Americans ages 15 and older have bank accounts, the vast majority of Americans of all ages have Social Security numbers, and benefits fraud isn't as widespread. 

Privacy worries
Bapna and Rajesh Mashruwala, a Silicon Valley entrepreneur who previously volunteered as a consultant to Aadhaar, also think that a program like Aadhaar would be politically impossible in the United States. 
"The sense of privacy [that the United States has] is different compared to the sense of privacy that emerging countries have," Mashruwala said. 

One way to think of it is that Indians have decided that this type of development is more important than privacy, Bapna said. "That's the tradeoff that the general populace has made."

Not everyone in India agrees that it's a worthwhile tradeoff. Economist R. Ramakumar has been a vocal opponent, publishing op-eds criticizing the project in national newspapers since 2009. He sees Aadhaar as a violation of civil liberties because Indian states — including Maharashta, home of Mumbai, where he lives — have passed orders that make enrolling in Aadhaar virtually compulsory. He cited orders that those without Aadhaar ID numbers can't draw their salaries or receive their government scholarships.

Aadhaar is supposed to be voluntary, according to the Indian government. "It's a violation of a promise that the government gave to its people," Ramakumar told TechNewsDaily during a Skype call.

In addition, there are no laws in place that specify who may get Aadhaar data and under what circumstances. A recent bill with a provision for oversight to Aadhaar access did not pass parliament. "There is no regulation which allows or prevents sharing of this database with police or other agencies. It's a completely unregulated area," Ramakumar said.

There's even a black market that's sprung up in Mumbai, where poor vendors sell people's Aadhaar-gathered biometric data, Ramakumar said. 

Lessons for the United States
While it may not have an Aadhaar, the United States does have a digital database of fingerprints and machine-recognizable photos for tens of thousands of people. The database is called US-VISIT, short for the United States Visitor and Immigrant Status Indicator Technology. US-VISIT tracks immigrants, foreign visitors and naturalized citizens. Aadhaar actually uses specifications for fingerprint technology provided by the U.S. Federal Bureau of Investigation.
US-VISIT was once the world's largest biometrics database, but Aadhaar has now overtaken it in size and sophistication, as Aadhaar includes iris scans, a more modern technology.

In some U.S. states, those applying for driver's licenses must submit digital fingerprints, though no one's done anything with that data yet, Mashruwala said. Biometrics technology is also creeping into privately made products in the U.S., such as cellphones and tablets that recognize owners' fingerprints.

So biometrics in the U.S. won't look quite like biometrics in India, but it's still coming. And U.S. agencies are talking with their Indian counterparts to learn how to gather and process so many people so quickly, Mashruwala said. US-VISIT collected data from about 70 million people over the course of 13 years, he said. Aadhaar did the same in less than one year. 

American agencies are also interested in seeing how Aadhaar's iris scans work out.

"The U.S. is waiting for someone else to be the first," Mashruwala said.
You can follow TechNewsDaily staff writer Francie Diep on Twitter @franciediep. Follow TechNewsDaily on Twitter @TechNewsDaily, or on Facebook.


Saturday, December 31, 2011

2160 - Aadhaar Ya Niraadhaar? Bumblebee - Fundamatics - IITBAA


Aadhaar Ya Niraadhaar?
Bumblebee



When Nandan Nilekani took charge of the Unique Identification Authority of India he was feted for his business-like approach, his stewardship of a project to give identity numbers to millions of Indians, an exercise unprecedented in its scale across the globe. While most accept the need for creating a systematic database of our citizenry, the path to be taken for this has become the subject matter of a viral attack from many quarters—cabinet ministers and bureaucrats, policy experts and activists, even a few state governments. 


Everything, from Nilekani’s procedures for data collection and the potential errors therein, to concerns over privacy, is being questioned.


UIDAI is also a subject very close to the IIT Bombay family. Nandan and many of his aides are from within the alumni community as are several detractors who question its “security” and “developmental” dimensions of they scheme. They claim that the former leads to an invasive state; the latter leaves us with a retreating state. 


Bumblebee felt that it was time some of that rumpus in the national stage was brought within the pages of Fundamatics in an unbiased point-counterpoint debate straight from the proverbial horse’s mouth.
Bumblebee



Imagining Aadhaar
Raj Mashruwala


The Unique Identification Authority of India (UIDAI) will celebrate its third anniversary next month. When Nandan Nilekani took office, he defined its mission “to issue a unique identification number that can be verified
and authenticated in an online, cost-effective manner, which is robust enough to eliminate duplicate and fake identities.” 


Hardly a day passes without the press reporting on Nandan or UIDAI, with headings like ‘Declare Aadhaar Illegal’, or, ‘Chidambaram wants Nilekani to log out’. Tabloids and bloggers have a field day speculating, insinuating and dispensing free advice on the matter. Interestingly, the ground-level reality is different. The reality is that Aadhaar has become the largest and fastest growing identity database in the world in less than 14 months. Is Aadhaar the first sign of a brave new world, the next stage of people empowerment?


Before we begin a discussion on the future of Aadhaar, let us first take stock of where it is today.


1. Just the numbers: Over 140M enrolled; 3⁄4 million new enrollments per day; active enrollment camps (16) in every populous state. In short, Aadhaar is growing faster than the mobile phone subscription rate, the most successful private initiative in recent times.


2. The system is working. In a year, it has scaled up to become the world’s largest biometric system, doing 100 trillion biometric comparisons per day while exceeding target accuracy. The reality: Indians will receive a unique ID. Built in the system is a portal for transparency, a toll-free call centre for assistance, an online appointment system, an online enrollment status query, a developer portal and more technical documents than one can read. Let us face it: despite IIT alumni running the show, something real and functional has emerged.




3.Aadhaar was sold to the public to facilitate delivery of public service. Whether this means direct payment for a NREGA recipient, delivery of subsidised LPG cylinders, KYC validation for the SIM card or opening of bank accounts for the unbanked, our babus are discussing, defining, building and testing new apps rapidly. We will see them in 2012.


4- Innovation — new ideas of UID’s uses are in the air. Once you assume a reliable verifiable unique ID, you can dramatically simplify banking and payments, healthcare and education monitoring, and identity fraud detection. People are building such systems right now. Our very own IITB professors are changing their 30-year curriculum and giving assignments to students to envision uses of Aadhaar. Admittedly, one application — the biometric student attendance system — is not in the best interest of junta.


5.Costs as per government records, all, I will offer my commentary. At the onset, UIDAI has spent I 468.91 crore (ap- prox. $100 million) from its inception till September, 2011. UIDAI strangely seemed to have grossly under-spent its budget, which was reported to be thousands of crores of rupees. Crap, another target missed.


6- Residents— do they want it? At the moment, enrollments lines don’t seem to be getting shorter. We must love standing in lines for no benefits. Wait, maybe people do need verifiable IDs.


7- What is the problem then? The civil society is deeply concerned. Their objections — privacy, reliance on unproven biometric technology, run-away costs and using the information for security instead of development — ought not to be dismissed summarily. Where do we, the armchair democratic activists, go from here? We could:
  1. Support the continuation of Aadhaar. This is what the government would want us to do.
  2. Raise our voice to scrap the programme. This is what some in the civil society would want.
  3. Find ways to help improve the vision of Aadhaar. This is what the idealist in us would want.
Let us examine some of the objections raised by respected civil society leaders such as Ms Usha Ramanathan, Arundhati Roy, Aruna Roy and Justice V. R. Krishna. As a know-it- it is fair to say that a constructive dialogue has not occurred between them and the Government of India. The government has generally ignored them and the civil society has destructively criticised the government in turn.


1. Privacy: Civil society leaders discuss a number of subtopics -


a. Need for a strong personal privacy law that India lacks. Aadhaar is too dangerous without a personal privacy law in place. No one disagrees on the need for such a law. The question is, do we put infrastructure projects on hold until such a law is passed?


b. Use of Aadhaar data for security, including national ID card. National ID card and building the National Population Registry (NPR) are in an act passed by parliament in 2004. Enrollment in NPR is mandatory and would occur regardless of Aadhaar. Would it make sense to build a chinese wall between Aadhaar and NPR?


c. Operational issues, such as data sharing among agencies Privacy is a topic that every country must find its own balance of. It can’t be borrowed from the US or China. Do we put Aadhaar project on hold until we find acceptable answer to privacy? Do we believe we can achieve a national consensus on privacy any time in the near future? 



2.Unproven biometric technology: The three most common objections are 


(a) it is inherently probabilistic and hence fal- lible, 
(b) it can easily be faked, and 
(c) it is not workable with India’s large and diverse population.


I am absolutely amazed at the speed at which India has produced biometric experts (albeit self-proclaimed) in the last two years. You- Tube is now overflowing with these experts. Having spent a considerable amount of time getting entertained by them, I can safely say that
  1. These experts have zero understanding of the probability theory. For them, Heisen- berg’s theory of uncertainty would be deeply disturbing. Any verification system has a certain probability of error. We need to characterise it, model it to predict error rates, and include additional verification factors if higher accuracy rates are required. Biometric verification is simply one factor.


  2. Faking. A four-digit PIN has 1 in a 10,000 chance of getting faked. Credit cards can be spoofed en masse at a negligible cost. We use both daily. We need to under- stand the cost benefits of each verification method and use whichever method is economically acceptable. Biometric identification has many good uses just like other methods such as tokens and passwords.


  3. Self-proclaimed experts conveniently disregard empirical data analysis on Indian population, which concluded that UIDAI can establish individual uniqueness with desired accuracy (> 99%). Current enroll- ment accuracy results seem to validate the original proof of conceptual results.
d. Indian experts have the uncanny talent of quoting real experts out of the context. The fact remains — we could discuss privacy, technology and intentions of the government ad infinitum. 


The crux of the issue is
a. Do we have a severe leakage problem in public benefits schemes due to duplicate and fake identities?
b. Do we want to provide services to people who need them the most, but lack identity proof?
c. Do we want to continue wasting umpteen hours at the bank, at the mobile shop and at the government office, trying to prove our identity over and over again?


Then we need Aadhaar. Aadhaar is necessary, but it may not be sufficient. Scrapping it is definitely not a solution. Can I challenge the IIT community to suggest ways to improve it?


Raj Mashruwala


The author Raj (Mashru) Mashruwala, 1975, Mechanical Engineering, has painstakingly researched the questions. The same thing can’t be claimed for the answers. He refused to provide his bio(metric) to the editors for verification due to privacy reasons.


Imaginary Aadhaar
Samir Kelekar


At a recent debate on UID in Bangalore, UIDAI's Deputy Director General, Mr. Dalwai was asked about the faking of finger prints, which can easily defeat the biometric scanners of UID. A video of how a faked fingerprint can defeat a typical fingerprint scanner has been put up by Mumbai-based biometric consultant, J. T. D’souza, on You- Tube. One expected a sensible answer from Mr. Dalwai, perhaps something on the lines of, ‘our fingerprint scanners can’t be fooled by such faking’.


But instead, he answered saying that if it does happen, it can only happen in small proportions. As a security professional, I don’t really know whether to laugh or cry at such an answer. It is like saying, yes, our backdoor doesn’t have a latch and is open. But there is little chance that anyone will notice it, or for that matter even if someone does notice it, let us hope that they are not tempted to take anything.


To put it bluntly, we are spending — by various estimates — right from Rs5,000 crores to Rs1,50,000 crores on the UIDAI project. The exact estimate of the project is unknown — so much for its transparency.


But it takes just Rs 30 — a little bit of wax and fevicol — to fake a fingerprint and fool a fin- gerprint scanner. It would take a bit more to
identify someone else's fingerprint from say a glass of water, taking a photograph of it, making a transparency, etching it on a PCB and then making a fake fingerprint.


Fraudsters everywhere are a determined lot, and when such a process to steal and fake fingerprints can be scaled to millions and billions, it makes ‘business’-sense for fraudsters to invest their time and money in the scam.


To top it all, there are various news reports which say that banking will be solely based on one's fingerprints after the UID comes in full swing. This is indeed what the fraudsters would want.


The UIDAI project is meant to give an identity to all Indians. However, it is not just the security aspects, but also other aspects that don’t seem to have been thought of thoroughly. For instance, the iris scan was not present in the originally proposed plan. But when it was commonly known that fingerprints by themselves may not be enough for de-duplication —and that they can be faked easily — the iris scan was introduced. 


There is no cost benefit analysis or feasibility study of any kind available in the public domain. No full life-cycle pilot study of any size for this project has been done and results studied, before launching such a huge and costly project nation wide. Privacy considerations haven’t been looked into either.


All the claimed benefits of this project are mere speculations; they are not based on a systematic study. For instance, one of the claims is that leakages in government- sponsored schemes such as NREGA and PDS will be reduced. There is no substantiation of this claim. Less than 10% of the leakages are due to double-dipping at the last mile. Most leakages take place at the back-end, with the active connivance of politicians and the powers that be, and UIDAI can do nothing about that.


Interestingly, a recent report by a US research entity — the research was commissioned by the US government itself — bursts the myth of the usefulness of biometrics. It recommends that especially in remote areas where no direct supervision is possible, biometrics by itself should not be used for any authentication. If it must be used, there has to be another factor of authentication. Two-factor authentication is not proposed by UIDAI, and cannot be easily introduced in a country like India where due to lack of literacy, things such as passwords cannot be easily used.


Another big problem with biometrics is that unlike a password or a PIN which banks use, biometric information once lost, is irreplaceable. Once you have lost your biometric identity, you have lost it for good. Passwords or PIN numbers on the other hand, can be easily replaced. In a recently reported incident from Mumbai, it was found that fakesters picked up biometrics of people in order to issue them UIDs. These fakesters now have the biometric data of those people, and now, they are forever excluded from the UIDAI project.


Other issues include the fact that the National Identification Authority of India bill has not been passed by the Parliament. Thus, the legality itself of this project is suspicious. Foreign companies have been given control or access to biometric data of our country’s citizens. There is no concept of a security clearance to bid for projects from UIDAI — a fact which puts our national security itself at risk.


All in all, this project is a white elephant in its current form. The earlier it is stopped or at least seriously relooked at, the better it will be for all of us concerned.


Samir has a B.Tech in Electrical Engineering (1983) from IIT Bombay, an MS from Clemson University, South Carolina (1987) and a PhD from Columbia University, New York (1994). He has worked for several companies including Motorola and Alcatel. Currently, he runs a startup called Teknotrends Software Pvt. Ltd. that does cutting-edge work in the area of network security. He is based in Bangalore. 

Friday, December 9, 2011

2059 - In Which Basab Gets UIDed - 6am Pacific Blog


A couple of weeks back, I was in the Infosys Bhubaneswar offices. On Friday, which was my last day at work before my vacation, UID enrollment was going on on campus. SBI, one of the agencies entrusted to enroll people into Aadhar was going to be at Infosys for a week.

I decided that I must get enrolled. There would never be a better chance. And so I did. But it took me two trips and 3 hours.

UID or Aadhaar as it is called is India’s unique identification project. It is a massive, in fact the biggest, biometric identification program anywhere in the world. It is quite different from programs like the US Social Security programs or any country’s passport or driving license programs. It’s sole focus is on unique, infallible biometric identification. It does not have any benefit or purpose associated with it. Rather, it is designed such that any benefits program (like the Public Distribution System) or regulatory purpose (id of bank account owners) may use the Aadhaar infrastructure.

It will be cheap, fast and near infallible. Say you walk up to a bank to open an account. You fill up a form that states your name, UID number and maybe even father’s name and address. Then, you peer into a lens that scans your iris and sends its data and the data from the form to the UID system. The UID system simply sends a Yes or a No – Yes this person, whose iris you scanned, is who he claims to be (name, father’s name etc.). The system will never send back your name, father’s name etc. Just a yay or a nay. Clever.

Actually, it is clever in other ways too. By avoiding a direct connection with any benefits program, it entirely avoids the politics surrounding any benefits program. Also, the government plans to run only those parts of the system itself that it absolutely must. The rest is being outsourced. So we will hopefully not build up a huge bureaucracy to run Aadhar, just a small one.

The original team that worked on the UID project had many team members (and its program manager, Raj Mashruwala) who came from tech companies in the Bay Area. I attended a talk and panel discussion about UID by some of them at Google in Mountain View a few months ago.

Most Indians are cynical about corruption and so a common refrain you will hear about Aadhaar is that politicians and bureaucrats will never let it succeed because it will make leakages in benefits programs so rare. One of the panelists at the event was an ex-IAS officer, now entrepreneur. He said that pols and bureaucrats, especially the ones in New Delhi, won’t mind at all if petty corruption of the kind you find in PDS and NREG went away. In fact, pols might want to take credit for eliminating this most visible form of corruption. The big bucks are anyway in scams like the 2G scam, where UID has no role to play.

So anyway, back to my own odyssey to get enrolled in Aadhaar. At 5pm on Friday, I wound up my work and went and stood in line. There were probably 15 people in front of me. A form was handed out, which I filled out, but not after having to ask for help. Why is there a “Relationship” field after “Father’s Name”? It may not have been this exactly, but there were a few totally befuddling fields to enter.
The line was moving really, really slowly. When my turn came, it was close to 645pm. And then I discovered why.

There were two stations. At the first station, the form you had filled out, was entered into an application on a computer. The trouble was that they (Aadhar or SBI, I don’t know who) needed the fields to be populated in both English and Oriya.

Now typing in Oriya using a QWERTY keyboard needs special skills and a special keyboard. The next best thing is to type in English and transliterate. The enrollment application used Google Translate’s transliteration service. Which is pretty nifty, but only in the hands of a trained operator. The woman at the first station was, shall we say, less trained. As a result, the Oriya part of the form was taking forever.

Eventually, I had to ask her to step aside and let me do it. I can’t read Oriya. So I would type in Roman, transliterate and then she would tell me if it was OK or not. We made some progress. But even with this arrangement, something like “R. K. Puram” proved extremely difficult.

Just after 7pm I got done with the data entry. Now onwards to station 2. Station 2 was for finger printing, iris scan and a photograph. But just my luck. As soon as I sat down, the network connection just disappeared. The operator couldn’t pull my record from Station 1.

The operator tried various things, which to me looked like a variety of paths to reach the same file folder on the other computer which was no longer connected. Then he would jiggle some wires and try the same series of things again.
Doing the same thing again and again and expecting different results is called insanity. Or a random number generator. Windows is somewhere between the two. Sometimes it actually produces results. So I let him keep trying for 5 minutes before I asked him to call his supervisor.

He called (not phone called, just called out loud). The man was getting a cold coffee at the coffee station across the hall. He got back with his drink in another 5 mins.

He tried the same thing a couple of times. But not for too long. He seemed to have had some experience with the mysterious ways of Windows. He rebooted. Another 7 minutes.

Now, finally, the operator had my record. The iris scan was a snap. Next was the finger printing. No problem. And then, what should have been the easiest thing, taking a photograph with webcam, didn’t work. And finally, that’s when I gave up.
I had a scheduled call at 730pm. I left at 725pm, disappointed. I wasted 2.5 hrs of my life and had nothing to show for it.

People say that the profit motive automatically brings in efficiency. This was a clear example of how that is often giving credit where credit is not due. SBI is enrolling people into Aadhaar because it has a vast network and great reach which positions it well to profit from the exercise.

But I doubt if SBI is making money at this. Their costs per day per enrollment center are fixed. They probably get paid per enrollment. But if enrollment is this slow, how can they turn a profit? Simple things like investing a little bit in training, better software and a wireless network instead of wires going all over the place could easily increase throughput. But apparently it hasn’t occurred to them yet.

I also didn’t understand why Aadhaar requires information from enrollees in both English and the local language. Couldn’t it be in one or the other?
Anyway, my story ends on a positive note. I went in to the office on Monday evening just for this. Somebody had already confirmed that my record still existed. All I had to do is get my biometrics recorded. I did and now I am enrolled in Aadhaar.
    

10 Responses to In Which Basab Gets UIDed
  • s anand says:
    July 7, 2011 at 6:52 am
    Just tweeted but 140 characters is less than what i need. So much of this problem is with the fact that SBI handled it. Karvy in Mumbai does it quickly, efficiently. Also, we too were confronted with the Marathi form till we were told it was optional and meant primarily for those who had NO other proof of id, proof of address . The problem with UID is that they are not communicating this properly or the state govt is simply piggybacking on UID to get info much of it having been collected in the census forms earlier.
    Good luck anyway !

  • Shiv Agarwal says:
    July 7, 2011 at 4:30 pm
    LOL! Similar experience during my visit to India. Anyways, I don’t think the revenue is based on number of people enrolled/day rather it is plain and simple number of days enrollment was done irrespective of number of people enrolled. These things are basic flaws in the way business is done in India whether it is an organization like SBI or Airtel where it took me 2.5 hours to purchase a basic 3g wireless connection – Same issues of un-trained people, 3 people to cater to 50 customers and inefficient infrastructure (read electricity). In a population of a billion and such cheap labour I am always surprised at the ratio of the service personnel vs. customers at any business.

  • Vinod Mehta says:
    July 7, 2011 at 10:13 pm
    Congratulation to be part of Aadhar. I still don’t feel confidence enough to share my bio-metric details with Govt. Thank you for your post at least it set some expectation on level of service I will be expecting.
    Good luck.

    • Lehana Singh says:
      July 17, 2011 at 10:53 pm
      Well I have myself worked for UIDAI and team Nandan. This is really a group of spirited people. The IAS officers and other Govt. Officials here are of a different creed.
      This is perfectly safe. Having worked on nitty gritties of UIDAI, I can tell you that there is no harm in submitting your Biometrics and the Govt. have nothing to do with it. The whole program have been outsourced and will be completely managed by a MSP in future.

      • Sandeep says:
        July 25, 2011 at 7:52 pm
        UID still evokes suspicion of the govt and big corporates. May be you can dispel some fears.
        What is the assurance that health providers won’t trade patient data at a cost to insurance providers who may benefit from it. After all, all one needs is a number to link the both. And there is huge incentive to do so.
        There is also talks of making UId mandatory for various things like opening bank accounts etc, which will lead to discrimination as banking companies access personal info and make it basis for accepting/denying requests.
        Personal databases with Aadhar data would start being sold in no time at a price by unscrupulous elements.

  • Anuradha Goyal says:
    July 8, 2011 at 5:40 am
    Do you think this is a good insight into how the CXOs of the technology companies should visit the ground level users of their technologies and figure out issues. When you are talking about Clouds, people at ground level are struggling with wires to connect two computers?

  • suranga date says:
    July 13, 2011 at 4:37 am
    One of the more strange features of this project is that no one announces any schedules for having adhar enrollments in communities. My family and I ended up going for ours after hearing rumors from folks about huge queues, 2-3 hour waiting in the hot Mumbai summer sun, and all kinds of stuff. No one announced the camp, how long or where. Everything was happening by word-of-mouth.

  • The actual operation seemed to go smoothly, with 4 stations, 1 supervisor lady who constantly took rounds, and two guys who simply managed folks cribbing in queues, and directed (polite) folks like me inside. 
    I saw the young people manning the stations, doing an excellent job, explaining what was to be done, to the folks who were not so computer literate and a bit apprehensive of machines, but I didnt see anyone getting anxious as such. The transliteration into marathi was very expertly done, and almost instant.
    I dont know really how much this card will be actually used eventually, given that various governments often act as spokes in the wheel, but this will certainly throw up a huge number of well trained , computer savvy, minimally educated young folks, who can possibly use that skill to get ahead in life. (I am not talking about Btech (CS) folks here).
    I wrote about it here

  • Raj Mashruwala says:
    August 22, 2011 at 3:17 am
    Basab,
    We met when you replaced Phaneesh and when I ran TIBCO. I discovered your site recently. I spent 18 months on designing Aadhaar. While I am no longer volunteering at UIDAI, I will pass some of your learnings to my friends at UIDAI. To respond to some of the issues you raised,
    1. What you see as ultimate system is a combination of the core system provided by UIDAI and custom software developed by local vendor for SBI or a registar. While UIDAI supplied software is rather simple — mandatory 4-6 fields and optional 5 fields, local registar frequenly adds complexity. For example, networking of two machines is not part of UIDAI software. UIDAI software was intentionally designed for a stand alone computer.
    2. Field training continues to be issue as I read reports across various states. UIDAI provides operator training, has empanneled training agency and has instituted third party operator certification. Every operator must go through certification. It appears this is still not sufficient.
    3. Enrollment center management. We have a long way to go here. Respect for resident dignity is non-existent.
    4. Local language. Since you enrolled, there is I believe improvement in the software for local language. The decision was made to use two languages — English and local. I still believe this is a correct decision. When a local villager goes to a ration shop and is going to get authenticated, it is best done in a local language. I believe this area will become much more robust as time passes. Auto transliteration is not trivial and we embarked on solving that problem. The dream is to use this data to standardise India’s physical address system — we are one of the few countries where no standardized addressing format exist (I am referring to a postal address for example).
    Hope this helps
    ….Raj Mashruwala

    • Lehana Singh says:
      August 22, 2011 at 7:58 am
      Dear Mr. Raj,
      Though I am bit surprised but excited to see you on this forum. If you remember correctly, I was working with the consulting team for UIDAI. Some 2 months ago, I also visited this exciting blog and tried to quench a bit of doubts of outsiders to this project. Still, being senior member of team, You can provide a better perspectives about the security issues.
      @ Sandeep et al (all those, who have raised doubts about the privacy and other Issues at UIDAI)
      As stated earlier, I have myself worked with Mr. Raj and others for this UIDAI project. One of the hallmark of this project was that, it has vendor, platform and technology neutrality. While procuring the bio-metrics (BSP) system, it was ensured that there is no bias towards any one particular modus operandi to
      1. Ensure their is no favor to any one vendor (there are 7-8 major OEM’s for Biometric in world)
      2. If in future, one vendor quits or is forced to quit, others are able to replace him
      3. There are 3 vendors working simultaneously, so there is a great level of internal competition between them to ensure quality of data processing, masking and encryption. Also, their revenues are based on some confidential metrics guided by parameters, which ensure utmost quality and data safety.
      4. The test probes have been designed in such a manner that there is literally nil scope for some sub-optimal or illegitimate operation.
      There are hordes of other details, but these are the only public details, which I can give for arguments as I am bound by my professional ethics of confidentiality.
      The level of encryption and complexity in the whole system, makes it literally impossible for anyone to misuse the data. This includes even the internal users and handler of this data.
      Lehana,

    • Basab Pradhan says:
      August 22, 2011 at 8:13 pm
      Raj,
      thanks for stopping by. Indeed, the process appears to differ from registrar to registrar. Later even Infosys Bhubaneswar decided to switch to a different registrar that offered online forms that could be filled out prior to going for the biometric scans.
      The dream is to use this data to standardise India’s physical address system — we are one of the few countries where no standardized addressing format exist (I am referring to a postal address for example).
      Anyone who can do this, will win my undying gratitude. Getting directions in India can be quite an adventure in itself.
      http://6ampacific.com/2008/08/23/getting-roadside-directions-in-india/

2053 - Why did Raj Mashruwala, Chief Biometric Coordinator Quit UIDAI ?

Raj Mashruwala, an IIT Bombay Alumnus took time off to become the Chief Biometric Coordinator of UIDAI headed by Nandan Nilekani.


In the note that follows it is interesting that Raj Mashruwala calls "UID an Audacious Goal". 


Audacious means willingness to take surprisingly bold risks as in 'business takeovers'. It can also mean an impudent lack of respect..'as in an audacious remark'. 


Did Raj Mashroowala "quit UIDAI" when he realised that UID showed an impudent lack of respect for Parliamentary Democratic processes and the collosal waste of tax payers money trying to brand and bar code an entire population?


Term over, experience gained, bulk of private sector team quits Aadhar




Raj Mashruwala said...




Since the article mentions me by name, I would like to set the record straight. I do NOT need UIDAI’s name on my resume. My and my volunteer UIDAI colleagues’ credentials available on Internet for validation. I am thankful to UIDAI and GoI to provide me the opportunity to serve the country and people. I do believe we made a difference to this ambitious project.

A number of my colleagues came through industry sabbatical process and they naturally returned to their employment after their sabbatical was complete.

It would have been advisable for the author to check with us to get facts correct.

He is in denial now but let us hope one day the truth will emerge.
Ram
___________________________________
2010 Biometric Consortium Conference & Technology Expo September 21‐23, 2010


Mr. Raj Mashruwala
Chief Biometric Coordinator
Unique Identification Authority of India, India

E503, Tower 1, Adarsh Palm Retreat Outer Ring Road, Devarabisanhalli Bangalore Karnataka, India Tel: (650) 646‐2938
Email: mashru@iitbombay.org


Designing and Commissioning Multi‐Modal Multi‐Vendor Biometric Solution for India’s Unique ID
Program


Audacious goal of India’s Unique ID program is to enroll entire India’s population above age 5 using multiple biometric modalities. In less than one year, UID Authority has designed, built and implemented multi‐modal, multiple ABIS vendors, capture device agnostic system on a open source private cloud platform. With the help of global IT/biometric community, the design also produced new Indian standard for (a) capture device interface (b) ABIS interface (c ) use of multiple ABIS’ without partitioning of gallery. This presentation will discuss both the architecture and process of building such system.


Biography
Raj Mashruwala has been the Chief Biometric Coordinator for Unique Identification Authority of India (UIDAI) since its inception in 2009. In this capacity, he has been responsible for designing biometric standards and architecture for the ambitious “Aadhaar” program.


He also led technical selection of the ABIS vendors. In his prior life as software entrepreneur, executive and investor, he has founded/co‐founded several successful companies including Consilium and TIBCO Software.


He hold bachelor in Mechanical Engineering from Indian Institute of Technology, Bombay and masters in engineering from University of California, Berkeley.