Why this Blog ? News articles in the Wide World of Web, quite often disappear with time, when they are relocated as archives with a different url. Archives in this blog serve as a library for those who are interested in doing Research on Aadhaar Related Topics. Articles are published with details of original publication date and the url.
Aadhaar
The UIDAI has taken two successive governments in India and the entire world for a ride. It identifies nothing. It is not unique. The entire UID data has never been verified and audited. The UID cannot be used for governance, financial databases or anything. It’s use is the biggest threat to national security since independence. – Anupam Saraph 2018
When I opposed Aadhaar in 2010 , I was called a BJP stooge. In 2016 I am still opposing Aadhaar for the same reasons and I am told I am a Congress die hard. No one wants to see why I oppose Aadhaar as it is too difficult. Plus Aadhaar is FREE so why not get one ? Ram Krishnaswamy
First they ignore you, then they laugh at you, then they fight you, then you win.-Mahatma Gandhi
In matters of conscience, the law of the majority has no place.Mahatma Gandhi
“The invasion of privacy is of no consequence because privacy is not a fundamental right and has no meaning under Article 21. The right to privacy is not a guaranteed under the constitution, because privacy is not a fundamental right.” Article 21 of the Indian constitution refers to the right to life and liberty -Attorney General Mukul Rohatgi
“There is merit in the complaints. You are unwittingly allowing snooping, harassment and commercial exploitation. The information about an individual obtained by the UIDAI while issuing an Aadhaar card shall not be used for any other purpose, save as above, except as may be directed by a court for the purpose of criminal investigation.”-A three judge bench headed by Justice J Chelameswar said in an interim order.
Legal scholar Usha Ramanathan describes UID as an inverse of sunshine laws like the Right to Information. While the RTI makes the state transparent to the citizen, the UID does the inverse: it makes the citizen transparent to the state, she says.
Good idea gone bad
I have written earlier that UID/Aadhaar was a poorly designed, unreliable and expensive solution to the really good idea of providing national identification for over a billion Indians. My petition contends that UID in its current form violates the right to privacy of a citizen, guaranteed under Article 21 of the Constitution. This is because sensitive biometric and demographic information of citizens are with enrolment agencies, registrars and sub-registrars who have no legal liability for any misuse of this data. This petition has opened up the larger discussion on privacy rights for Indians. The current Article 21 interpretation by the Supreme Court was done decades ago, before the advent of internet and today’s technology and all the new privacy challenges that have arisen as a consequence.
Rajeev Chandrasekhar, MP Rajya Sabha
“What is Aadhaar? There is enormous confusion. That Aadhaar will identify people who are entitled for subsidy. No. Aadhaar doesn’t determine who is eligible and who isn’t,” Jairam Ramesh
But Aadhaar has been mythologised during the previous government by its creators into some technology super force that will transform governance in a miraculous manner. I even read an article recently that compared Aadhaar to some revolution and quoted a 1930s historian, Will Durant.Rajeev Chandrasekhar, Rajya Sabha MP
“I know you will say that it is not mandatory. But, it is compulsorily mandatorily voluntary,” Jairam Ramesh, Rajya Saba April 2017.
August 24, 2017: The nine-judge Constitution Bench rules that right to privacy is “intrinsic to life and liberty”and is inherently protected under the various fundamental freedoms enshrined under Part III of the Indian Constitution
"Never doubt that a small group of thoughtful, committed citizens can change the World; indeed it's the only thing that ever has"
“Arguing that you don’t care about the right to privacy because you have nothing to hide is no different than saying you don’t care about free speech because you have nothing to say.” -Edward Snowden
In the Supreme Court, Meenakshi Arora, one of the senior counsel in the case, compared it to living under a general, perpetual, nation-wide criminal warrant.
Had never thought of it that way, but living in the Aadhaar universe is like living in a prison. All of us are treated like criminals with barely any rights or recourse and gatekeepers have absolute power on you and your life.
Announcing the launch of the # BreakAadhaarChainscampaign, culminating with events in multiple cities on 12th Jan. This is the last opportunity to make your voice heard before the Supreme Court hearings start on 17th Jan 2018. In collaboration with @no2uidand@rozi_roti.
UIDAI's security seems to be founded on four time tested pillars of security idiocy
1) Denial
2) Issue fiats and point finger
3) Shoot messenger
4) Bury head in sand.
God Save India
Sunday, July 17, 2016
10157 - Trust at your fingertips Narayanan Krishnaswami | TNN
Monday, May 9, 2016
9925 - IIT alumni duo Raj Mashruwala, Avinash Manudane to fund ideas in healthcare space - Economi Times
Monday, February 4, 2013
2942 - Could India's Biometric Database Work in the US?
Saturday, December 31, 2011
2160 - Aadhaar Ya Niraadhaar? Bumblebee - Fundamatics - IITBAA
When Nandan Nilekani took charge of the Unique Identification Authority of India he was feted for his business-like approach, his stewardship of a project to give identity numbers to millions of Indians, an exercise unprecedented in its scale across the globe. While most accept the need for creating a systematic database of our citizenry, the path to be taken for this has become the subject matter of a viral attack from many quarters—cabinet ministers and bureaucrats, policy experts and activists, even a few state governments.
Everything, from Nilekani’s procedures for data collection and the potential errors therein, to concerns over privacy, is being questioned.
UIDAI is also a subject very close to the IIT Bombay family. Nandan and many of his aides are from within the alumni community as are several detractors who question its “security” and “developmental” dimensions of they scheme. They claim that the former leads to an invasive state; the latter leaves us with a retreating state.
Bumblebee felt that it was time some of that rumpus in the national stage was brought within the pages of Fundamatics in an unbiased point-counterpoint debate straight from the proverbial horse’s mouth.
Bumblebee
Raj Mashruwala
and authenticated in an online, cost-effective manner, which is robust enough to eliminate duplicate and fake identities.”
Hardly a day passes without the press reporting on Nandan or UIDAI, with headings like ‘Declare Aadhaar Illegal’, or, ‘Chidambaram wants Nilekani to log out’. Tabloids and bloggers have a field day speculating, insinuating and dispensing free advice on the matter. Interestingly, the ground-level reality is different. The reality is that Aadhaar has become the largest and fastest growing identity database in the world in less than 14 months. Is Aadhaar the first sign of a brave new world, the next stage of people empowerment?
Before we begin a discussion on the future of Aadhaar, let us first take stock of where it is today.
1. Just the numbers: Over 140M enrolled; 3⁄4 million new enrollments per day; active enrollment camps (16) in every populous state. In short, Aadhaar is growing faster than the mobile phone subscription rate, the most successful private initiative in recent times.
2. The system is working. In a year, it has scaled up to become the world’s largest biometric system, doing 100 trillion biometric comparisons per day while exceeding target accuracy. The reality: Indians will receive a unique ID. Built in the system is a portal for transparency, a toll-free call centre for assistance, an online appointment system, an online enrollment status query, a developer portal and more technical documents than one can read. Let us face it: despite IIT alumni running the show, something real and functional has emerged.
3.Aadhaar was sold to the public to facilitate delivery of public service. Whether this means direct payment for a NREGA recipient, delivery of subsidised LPG cylinders, KYC validation for the SIM card or opening of bank accounts for the unbanked, our babus are discussing, defining, building and testing new apps rapidly. We will see them in 2012.
4- Innovation — new ideas of UID’s uses are in the air. Once you assume a reliable verifiable unique ID, you can dramatically simplify banking and payments, healthcare and education monitoring, and identity fraud detection. People are building such systems right now. Our very own IITB professors are changing their 30-year curriculum and giving assignments to students to envision uses of Aadhaar. Admittedly, one application — the biometric student attendance system — is not in the best interest of junta.
6- Residents— do they want it? At the moment, enrollments lines don’t seem to be getting shorter. We must love standing in lines for no benefits. Wait, maybe people do need verifiable IDs.
7- What is the problem then? The civil society is deeply concerned. Their objections — privacy, reliance on unproven biometric technology, run-away costs and using the information for security instead of development — ought not to be dismissed summarily. Where do we, the armchair democratic activists, go from here? We could:
- Support the continuation of Aadhaar. This is what the government would want us to do.
- Raise our voice to scrap the programme. This is what some in the civil society would want.
- Find ways to help improve the vision of Aadhaar. This is what the idealist in us would want.
1. Privacy: Civil society leaders discuss a number of subtopics -
a. Need for a strong personal privacy law that India lacks. Aadhaar is too dangerous without a personal privacy law in place. No one disagrees on the need for such a law. The question is, do we put infrastructure projects on hold until such a law is passed?
b. Use of Aadhaar data for security, including national ID card. National ID card and building the National Population Registry (NPR) are in an act passed by parliament in 2004. Enrollment in NPR is mandatory and would occur regardless of Aadhaar. Would it make sense to build a chinese wall between Aadhaar and NPR?
c. Operational issues, such as data sharing among agencies Privacy is a topic that every country must find its own balance of. It can’t be borrowed from the US or China. Do we put Aadhaar project on hold until we find acceptable answer to privacy? Do we believe we can achieve a national consensus on privacy any time in the near future?
(a) it is inherently probabilistic and hence fal- lible,
(b) it can easily be faked, and
(c) it is not workable with India’s large and diverse population.
I am absolutely amazed at the speed at which India has produced biometric experts (albeit self-proclaimed) in the last two years. You- Tube is now overflowing with these experts. Having spent a considerable amount of time getting entertained by them, I can safely say that
- These experts have zero understanding of the probability theory. For them, Heisen- berg’s theory of uncertainty would be deeply disturbing. Any verification system has a certain probability of error. We need to characterise it, model it to predict error rates, and include additional verification factors if higher accuracy rates are required. Biometric verification is simply one factor.
- Faking. A four-digit PIN has 1 in a 10,000 chance of getting faked. Credit cards can be spoofed en masse at a negligible cost. We use both daily. We need to under- stand the cost benefits of each verification method and use whichever method is economically acceptable. Biometric identification has many good uses just like other methods such as tokens and passwords.
- Self-proclaimed experts conveniently disregard empirical data analysis on Indian population, which concluded that UIDAI can establish individual uniqueness with desired accuracy (> 99%). Current enroll- ment accuracy results seem to validate the original proof of conceptual results.
The crux of the issue is
a. Do we have a severe leakage problem in public benefits schemes due to duplicate and fake identities?
b. Do we want to provide services to people who need them the most, but lack identity proof?
c. Do we want to continue wasting umpteen hours at the bank, at the mobile shop and at the government office, trying to prove our identity over and over again?
Then we need Aadhaar. Aadhaar is necessary, but it may not be sufficient. Scrapping it is definitely not a solution. Can I challenge the IIT community to suggest ways to improve it?
Raj Mashruwala
The author Raj (Mashru) Mashruwala, 1975, Mechanical Engineering, has painstakingly researched the questions. The same thing can’t be claimed for the answers. He refused to provide his bio(metric) to the editors for verification due to privacy reasons.
But instead, he answered saying that if it does happen, it can only happen in small proportions. As a security professional, I don’t really know whether to laugh or cry at such an answer. It is like saying, yes, our backdoor doesn’t have a latch and is open. But there is little chance that anyone will notice it, or for that matter even if someone does notice it, let us hope that they are not tempted to take anything.
To put it bluntly, we are spending — by various estimates — right from Rs5,000 crores to Rs1,50,000 crores on the UIDAI project. The exact estimate of the project is unknown — so much for its transparency.
But it takes just Rs 30 — a little bit of wax and fevicol — to fake a fingerprint and fool a fin- gerprint scanner. It would take a bit more to
Fraudsters everywhere are a determined lot, and when such a process to steal and fake fingerprints can be scaled to millions and billions, it makes ‘business’-sense for fraudsters to invest their time and money in the scam.
To top it all, there are various news reports which say that banking will be solely based on one's fingerprints after the UID comes in full swing. This is indeed what the fraudsters would want.
The UIDAI project is meant to give an identity to all Indians. However, it is not just the security aspects, but also other aspects that don’t seem to have been thought of thoroughly. For instance, the iris scan was not present in the originally proposed plan. But when it was commonly known that fingerprints by themselves may not be enough for de-duplication —and that they can be faked easily — the iris scan was introduced.
There is no cost benefit analysis or feasibility study of any kind available in the public domain. No full life-cycle pilot study of any size for this project has been done and results studied, before launching such a huge and costly project nation wide. Privacy considerations haven’t been looked into either.
Interestingly, a recent report by a US research entity — the research was commissioned by the US government itself — bursts the myth of the usefulness of biometrics. It recommends that especially in remote areas where no direct supervision is possible, biometrics by itself should not be used for any authentication. If it must be used, there has to be another factor of authentication. Two-factor authentication is not proposed by UIDAI, and cannot be easily introduced in a country like India where due to lack of literacy, things such as passwords cannot be easily used.
Another big problem with biometrics is that unlike a password or a PIN which banks use, biometric information once lost, is irreplaceable. Once you have lost your biometric identity, you have lost it for good. Passwords or PIN numbers on the other hand, can be easily replaced. In a recently reported incident from Mumbai, it was found that fakesters picked up biometrics of people in order to issue them UIDs. These fakesters now have the biometric data of those people, and now, they are forever excluded from the UIDAI project.
Other issues include the fact that the National Identification Authority of India bill has not been passed by the Parliament. Thus, the legality itself of this project is suspicious. Foreign companies have been given control or access to biometric data of our country’s citizens. There is no concept of a security clearance to bid for projects from UIDAI — a fact which puts our national security itself at risk.
All in all, this project is a white elephant in its current form. The earlier it is stopped or at least seriously relooked at, the better it will be for all of us concerned.
Samir has a B.Tech in Electrical Engineering (1983) from IIT Bombay, an MS from Clemson University, South Carolina (1987) and a PhD from Columbia University, New York (1994). He has worked for several companies including Motorola and Alcatel. Currently, he runs a startup called Teknotrends Software Pvt. Ltd. that does cutting-edge work in the area of network security. He is based in Bangalore.
Friday, December 9, 2011
2059 - In Which Basab Gets UIDed - 6am Pacific Blog
- s anand says:
July 7, 2011 at 6:52 am
Just tweeted but 140 characters is less than what i need. So much of this problem is with the fact that SBI handled it. Karvy in Mumbai does it quickly, efficiently. Also, we too were confronted with the Marathi form till we were told it was optional and meant primarily for those who had NO other proof of id, proof of address . The problem with UID is that they are not communicating this properly or the state govt is simply piggybacking on UID to get info much of it having been collected in the census forms earlier.
Good luck anyway !
- Shiv Agarwal says:
July 7, 2011 at 4:30 pm
LOL! Similar experience during my visit to India. Anyways, I don’t think the revenue is based on number of people enrolled/day rather it is plain and simple number of days enrollment was done irrespective of number of people enrolled. These things are basic flaws in the way business is done in India whether it is an organization like SBI or Airtel where it took me 2.5 hours to purchase a basic 3g wireless connection – Same issues of un-trained people, 3 people to cater to 50 customers and inefficient infrastructure (read electricity). In a population of a billion and such cheap labour I am always surprised at the ratio of the service personnel vs. customers at any business.
- Vinod Mehta says:
July 7, 2011 at 10:13 pm
Congratulation to be part of Aadhar. I still don’t feel confidence enough to share my bio-metric details with Govt. Thank you for your post at least it set some expectation on level of service I will be expecting.
Good luck.
- Lehana Singh says:
July 17, 2011 at 10:53 pm
Well I have myself worked for UIDAI and team Nandan. This is really a group of spirited people. The IAS officers and other Govt. Officials here are of a different creed.
This is perfectly safe. Having worked on nitty gritties of UIDAI, I can tell you that there is no harm in submitting your Biometrics and the Govt. have nothing to do with it. The whole program have been outsourced and will be completely managed by a MSP in future.
- Sandeep says:
July 25, 2011 at 7:52 pm
UID still evokes suspicion of the govt and big corporates. May be you can dispel some fears.
What is the assurance that health providers won’t trade patient data at a cost to insurance providers who may benefit from it. After all, all one needs is a number to link the both. And there is huge incentive to do so.
There is also talks of making UId mandatory for various things like opening bank accounts etc, which will lead to discrimination as banking companies access personal info and make it basis for accepting/denying requests.
Personal databases with Aadhar data would start being sold in no time at a price by unscrupulous elements.
- Anuradha Goyal says:
July 8, 2011 at 5:40 am
Do you think this is a good insight into how the CXOs of the technology companies should visit the ground level users of their technologies and figure out issues. When you are talking about Clouds, people at ground level are struggling with wires to connect two computers?
- suranga date says:
July 13, 2011 at 4:37 am
One of the more strange features of this project is that no one announces any schedules for having adhar enrollments in communities. My family and I ended up going for ours after hearing rumors from folks about huge queues, 2-3 hour waiting in the hot Mumbai summer sun, and all kinds of stuff. No one announced the camp, how long or where. Everything was happening by word-of-mouth.
- The actual operation seemed to go smoothly, with 4 stations, 1 supervisor lady who constantly took rounds, and two guys who simply managed folks cribbing in queues, and directed (polite) folks like me inside.
I saw the young people manning the stations, doing an excellent job, explaining what was to be done, to the folks who were not so computer literate and a bit apprehensive of machines, but I didnt see anyone getting anxious as such. The transliteration into marathi was very expertly done, and almost instant.
I dont know really how much this card will be actually used eventually, given that various governments often act as spokes in the wheel, but this will certainly throw up a huge number of well trained , computer savvy, minimally educated young folks, who can possibly use that skill to get ahead in life. (I am not talking about Btech (CS) folks here).
I wrote about it here
- Raj Mashruwala says:
August 22, 2011 at 3:17 am
Basab,
We met when you replaced Phaneesh and when I ran TIBCO. I discovered your site recently. I spent 18 months on designing Aadhaar. While I am no longer volunteering at UIDAI, I will pass some of your learnings to my friends at UIDAI. To respond to some of the issues you raised,
1. What you see as ultimate system is a combination of the core system provided by UIDAI and custom software developed by local vendor for SBI or a registar. While UIDAI supplied software is rather simple — mandatory 4-6 fields and optional 5 fields, local registar frequenly adds complexity. For example, networking of two machines is not part of UIDAI software. UIDAI software was intentionally designed for a stand alone computer.
2. Field training continues to be issue as I read reports across various states. UIDAI provides operator training, has empanneled training agency and has instituted third party operator certification. Every operator must go through certification. It appears this is still not sufficient.
3. Enrollment center management. We have a long way to go here. Respect for resident dignity is non-existent.
4. Local language. Since you enrolled, there is I believe improvement in the software for local language. The decision was made to use two languages — English and local. I still believe this is a correct decision. When a local villager goes to a ration shop and is going to get authenticated, it is best done in a local language. I believe this area will become much more robust as time passes. Auto transliteration is not trivial and we embarked on solving that problem. The dream is to use this data to standardise India’s physical address system — we are one of the few countries where no standardized addressing format exist (I am referring to a postal address for example).
Hope this helps
….Raj Mashruwala
- Lehana Singh says:
August 22, 2011 at 7:58 am
Dear Mr. Raj,
Though I am bit surprised but excited to see you on this forum. If you remember correctly, I was working with the consulting team for UIDAI. Some 2 months ago, I also visited this exciting blog and tried to quench a bit of doubts of outsiders to this project. Still, being senior member of team, You can provide a better perspectives about the security issues.
@ Sandeep et al (all those, who have raised doubts about the privacy and other Issues at UIDAI)
As stated earlier, I have myself worked with Mr. Raj and others for this UIDAI project. One of the hallmark of this project was that, it has vendor, platform and technology neutrality. While procuring the bio-metrics (BSP) system, it was ensured that there is no bias towards any one particular modus operandi to
1. Ensure their is no favor to any one vendor (there are 7-8 major OEM’s for Biometric in world)
2. If in future, one vendor quits or is forced to quit, others are able to replace him
3. There are 3 vendors working simultaneously, so there is a great level of internal competition between them to ensure quality of data processing, masking and encryption. Also, their revenues are based on some confidential metrics guided by parameters, which ensure utmost quality and data safety.
4. The test probes have been designed in such a manner that there is literally nil scope for some sub-optimal or illegitimate operation.
There are hordes of other details, but these are the only public details, which I can give for arguments as I am bound by my professional ethics of confidentiality.
The level of encryption and complexity in the whole system, makes it literally impossible for anyone to misuse the data. This includes even the internal users and handler of this data.
Lehana,
- Basab Pradhan says:
August 22, 2011 at 8:13 pm
Raj,
thanks for stopping by. Indeed, the process appears to differ from registrar to registrar. Later even Infosys Bhubaneswar decided to switch to a different registrar that offered online forms that could be filled out prior to going for the biometric scans.
The dream is to use this data to standardise India’s physical address system — we are one of the few countries where no standardized addressing format exist (I am referring to a postal address for example).
Anyone who can do this, will win my undying gratitude. Getting directions in India can be quite an adventure in itself.
http://6ampacific.com/2008/08/23/getting-roadside-directions-in-india/
2053 - Why did Raj Mashruwala, Chief Biometric Coordinator Quit UIDAI ?
In the note that follows it is interesting that Raj Mashruwala calls "UID an Audacious Goal".
Audacious means willingness to take surprisingly bold risks as in 'business takeovers'. It can also mean an impudent lack of respect..'as in an audacious remark'.
Did Raj Mashroowala "quit UIDAI" when he realised that UID showed an impudent lack of respect for Parliamentary Democratic processes and the collosal waste of tax payers money trying to brand and bar code an entire population?
Term over, experience gained, bulk of private sector team quits Aadhar
Raj Mashruwala said...
A number of my colleagues came through industry sabbatical process and they naturally returned to their employment after their sabbatical was complete.
It would have been advisable for the author to check with us to get facts correct.
He is in denial now but let us hope one day the truth will emerge.
Ram
___________________________________
2010 Biometric Consortium Conference & Technology Expo September 21‐23, 2010
Mr. Raj Mashruwala
Chief Biometric Coordinator
Unique Identification Authority of India, India
E503, Tower 1, Adarsh Palm Retreat Outer Ring Road, Devarabisanhalli Bangalore Karnataka, India Tel: (650) 646‐2938
Email: mashru@iitbombay.org
Designing and Commissioning Multi‐Modal Multi‐Vendor Biometric Solution for India’s Unique ID
Program
Audacious goal of India’s Unique ID program is to enroll entire India’s population above age 5 using multiple biometric modalities. In less than one year, UID Authority has designed, built and implemented multi‐modal, multiple ABIS vendors, capture device agnostic system on a open source private cloud platform. With the help of global IT/biometric community, the design also produced new Indian standard for (a) capture device interface (b) ABIS interface (c ) use of multiple ABIS’ without partitioning of gallery. This presentation will discuss both the architecture and process of building such system.
Biography
Raj Mashruwala has been the Chief Biometric Coordinator for Unique Identification Authority of India (UIDAI) since its inception in 2009. In this capacity, he has been responsible for designing biometric standards and architecture for the ambitious “Aadhaar” program.
He also led technical selection of the ABIS vendors. In his prior life as software entrepreneur, executive and investor, he has founded/co‐founded several successful companies including Consilium and TIBCO Software.
He hold bachelor in Mechanical Engineering from Indian Institute of Technology, Bombay and masters in engineering from University of California, Berkeley.
