In 2009, I became extremely concerned with the concept of Unique Identity for various reasons. Connected with many like minded highly educated people who were all concerned.
On 18th May 2010, I started this Blog to capture anything and everything I came across on the topic. This blog with its million hits is a testament to my concerns about loss of privacy and fear of the ID being misused and possible Criminal activities it could lead to.
In 2017 the Supreme Court of India gave its verdict after one of the longest hearings on any issue. I did my bit and appealed to the Supreme Court Judges too through an On Line Petition.
In 2019 the Aadhaar Legislation has been revised and passed by the two houses of the Parliament of India making it Legal. I am no Legal Eagle so my Opinion carries no weight except with people opposed to the very concept.
In 2019, this Blog now just captures on a Daily Basis list of Articles Published on anything to do with Aadhaar as obtained from Daily Google Searches and nothing more. Cannot burn the midnight candle any longer.
"In Matters of Conscience, the Law of Majority has no place"- Mahatma Gandhi
Ram Krishnaswamy
Sydney, Australia.

Aadhaar

The UIDAI has taken two successive governments in India and the entire world for a ride. It identifies nothing. It is not unique. The entire UID data has never been verified and audited. The UID cannot be used for governance, financial databases or anything. It’s use is the biggest threat to national security since independence. – Anupam Saraph 2018

When I opposed Aadhaar in 2010 , I was called a BJP stooge. In 2016 I am still opposing Aadhaar for the same reasons and I am told I am a Congress die hard. No one wants to see why I oppose Aadhaar as it is too difficult. Plus Aadhaar is FREE so why not get one ? Ram Krishnaswamy

First they ignore you, then they laugh at you, then they fight you, then you win.-Mahatma Gandhi

In matters of conscience, the law of the majority has no place.Mahatma Gandhi

“The invasion of privacy is of no consequence because privacy is not a fundamental right and has no meaning under Article 21. The right to privacy is not a guaranteed under the constitution, because privacy is not a fundamental right.” Article 21 of the Indian constitution refers to the right to life and liberty -Attorney General Mukul Rohatgi

“There is merit in the complaints. You are unwittingly allowing snooping, harassment and commercial exploitation. The information about an individual obtained by the UIDAI while issuing an Aadhaar card shall not be used for any other purpose, save as above, except as may be directed by a court for the purpose of criminal investigation.”-A three judge bench headed by Justice J Chelameswar said in an interim order.

Legal scholar Usha Ramanathan describes UID as an inverse of sunshine laws like the Right to Information. While the RTI makes the state transparent to the citizen, the UID does the inverse: it makes the citizen transparent to the state, she says.

Good idea gone bad
I have written earlier that UID/Aadhaar was a poorly designed, unreliable and expensive solution to the really good idea of providing national identification for over a billion Indians. My petition contends that UID in its current form violates the right to privacy of a citizen, guaranteed under Article 21 of the Constitution. This is because sensitive biometric and demographic information of citizens are with enrolment agencies, registrars and sub-registrars who have no legal liability for any misuse of this data. This petition has opened up the larger discussion on privacy rights for Indians. The current Article 21 interpretation by the Supreme Court was done decades ago, before the advent of internet and today’s technology and all the new privacy challenges that have arisen as a consequence.

Rajeev Chandrasekhar, MP Rajya Sabha

“What is Aadhaar? There is enormous confusion. That Aadhaar will identify people who are entitled for subsidy. No. Aadhaar doesn’t determine who is eligible and who isn’t,” Jairam Ramesh

But Aadhaar has been mythologised during the previous government by its creators into some technology super force that will transform governance in a miraculous manner. I even read an article recently that compared Aadhaar to some revolution and quoted a 1930s historian, Will Durant.Rajeev Chandrasekhar, Rajya Sabha MP

“I know you will say that it is not mandatory. But, it is compulsorily mandatorily voluntary,” Jairam Ramesh, Rajya Saba April 2017.

August 24, 2017: The nine-judge Constitution Bench rules that right to privacy is “intrinsic to life and liberty”and is inherently protected under the various fundamental freedoms enshrined under Part III of the Indian Constitution

"Never doubt that a small group of thoughtful, committed citizens can change the World; indeed it's the only thing that ever has"

“Arguing that you don’t care about the right to privacy because you have nothing to hide is no different than saying you don’t care about free speech because you have nothing to say.” -Edward Snowden

In the Supreme Court, Meenakshi Arora, one of the senior counsel in the case, compared it to living under a general, perpetual, nation-wide criminal warrant.

Had never thought of it that way, but living in the Aadhaar universe is like living in a prison. All of us are treated like criminals with barely any rights or recourse and gatekeepers have absolute power on you and your life.

Announcing the launch of the # BreakAadhaarChainscampaign, culminating with events in multiple cities on 12th Jan. This is the last opportunity to make your voice heard before the Supreme Court hearings start on 17th Jan 2018. In collaboration with @no2uidand@rozi_roti.

UIDAI's security seems to be founded on four time tested pillars of security idiocy

1) Denial

2) Issue fiats and point finger

3) Shoot messenger

4) Bury head in sand.

God Save India

Showing posts with label Robert Baptise. Show all posts
Showing posts with label Robert Baptise. Show all posts

Wednesday, June 20, 2018

13685 - Aadhaar Critics are not Ludites - National Herald


Aadhaar critics are not luddites


VIDYUT GORE
Published: Jun 14th 2018, 12.14 PM


              Photo courtesy: Twitter/@ceo_uidai
      File photo of UIDAI chief Ajay Bhushan Pandey

UIDAI chief writes that the fear of a threat to privacy because of the use of core biometrics in Aadhaar is exaggerated because biometrics are not secret information like PIN or password

The CEO of UIDAI, Ajay Bhushan Pandey, has written yet another opinion piece in a newspaper, which bravely argues against established tech security practices.

While Aadhaar FAIL generally tends to ignore individuals and their opinions, it is important to examine the claim and competence of a highly placed public servant, who arguably occupies one of the most important positions related to technology in India.

The UIDAI chief writes that the fear of a threat to privacy because of the use of core biometrics (fingerprints and iris) in Aadhaar is exaggerated because biometrics are not secret information like PIN or password. People, he went on to add, must know that even the theft of biometrics in a rare eventuality will not put one to the same level of risk as the leakage of a password.

A threat to privacy, however, is not about whether the information is secret or not. It is about having the choice of what information we grant and to whom. The residents of India are not criminals that their rights must be waived away and they be compelled to grant access to their biometrics, and that too, to an insecure system, because of a system whose compliance with the Constitution of the country itself has been questioned.

This, in fact, has been repeatedly brought up by the judges in the Supreme Court itself, and Pandey had the opportunity of being the only non-lawyer allowed to present his perspective directly to the judges themselves. The judges did not appear convinced and continued to see the invasion of privacy as an important issue left unanswered.

Perhaps Pandey means to call the judges Luddites as well? A Luddite, for those unaware of the term, is a person who is opposed to technological developments. Dr. Pandey calling those who oppose Aadhaar Luddites betrays knowledge of the meaning of the term, because the technological criticism of Aadhaar has been actually backed by technologically sound arguments and evidence. In contrast, the bombast of the "Aadhaar mafia" as the proponents of Aadhaar are increasingly being referred to, due to ongoing unethical practices, are yet to present any factual rebuttal.

It is worthwhile to take note of some of the Luddites, as Dr Pandey would prefer to call them, who have been critical of Aadhaar. Justice K.S. Puttaswamy, retired judge of the Karnataka High Court and the original petitioner in the landmark ‘privacy case’ is one.

It is an irony that while critics of Aadhaar seem to have impeccable technological credentials while the UIDAI chief, who has the gumption to call these critics Luddites, himself doesn’t seem to understand the difference between private information and secret keys despite repeated explanations

Vicram Crishna, one of the two Indians to help develop software to enable Stephen Hawkins to ‘talk’through his wheelchair, J.T. D’Souza, biometrics expert, Troy Hunt, a web security professional and regional director for Microsoft in Australia, French cyber security researcher Baptiste Robert who tweets as Elliot Alderson and Anupam Saraph, a respected inventor and advisor on governance, informatics and strategic planning are also among those who have publicly expressed their concern about Aadhaar.

Alderson in fact has compared unfavourably Aadhaar’s approach to security as a ‘school level project’. Mozilla, the organisation behind the Firefox browser, has come out publicly in criticism of Aadhaar. And in case more critics are to be named, one can cite the names of legal scholar Shamnad Basheer, Linux consultant Anivar Arvind and Samir Kelekar, who has a PhD in computer networking and holds three patents related to mobile security.

It is an irony that while critics of Aadhaar seem to have impeccable technological credentials while the UIDAI chief, who has the gumption to call these critics Luddites, himself doesn’t seem to understand the difference between private information and secret keys despite repeated explanations.

For his benefit, let me repeat the explanation. When you use a key to control access or authorisation, that key must be secret and not merely private. Just like guessing where you were on Saturday night or knowing the name of the street your home is on should not allow people to create a bank account in your name, lifting fingerprints off your glass of water shouldn't allow them to create a bank account and launder money in your name either.

A secret key must be one that is known only to the person who is the rightful owner of that access. In the event of a breach, it must be readily revoked and replaced. It must be unique. Just like you don't use the same password for your Twitter and netbanking, you should not use the same fingerprints for your PDS and money transfers either.

This is not very difficult to understand. If Dr. Pandey is not able to understand it with so many explanations provided repeatedly over years, perhaps he should undertake correcting the deficiencies first before holding a technology related job.
Till date there hasn't been a shred of factual explanation for why the criticism of Aadhaar is incorrect, while there have been various face saving measures because the UIDAI has no answers for valid criticism. Like the farce of "Virtual ID" to protect privacy after Aadhaar data has already been proliferated with little caution. If he has any factual explanation to show how Aadhaar does not violate privacy, he should not have kept it a secret from the Supreme Court.

While he is at it, Dr. Pandey should also name one private corporation that would pay the kind of money Aadhaar has cost the country for the quality of work on display. One corporation that deals with sensitive identity information or access to financial transactions that would be willing to risk access being protected by something as flimsy, as unrevokable, easily leaked, private information.

When public funds are used to subvert public interest, criticism is inevitable. Calling critics names cannot stop it.

Sorry, sir. "Fikar not, all is well" does not quite answer the mounting criticism.

Click here to subscribe to National Herald on WhatsApp & Facebook

Thursday, May 10, 2018

13497 - Elliot Alderson: Saying Aadhaar Is Un-Hackable Does Not Make It So - Mid Day

May 09, 2018, 07:08 IST | Gaurav Sarkar

In another exclusive interview with mid-day, French ethical hacker Elliot Alderson talks about how things have changed since he revealed his identity and how flaws in the Aadhaar system have remained the same

                                Robert Baptiste

Elliot Alderson, the French ethical hacker who exposed flaws in the Aadhaar application has finally come out of the woodwork and revealed his true identity. He is Robert Baptiste, 28, a resident of Toulouse in France, who works as an app developer. Speaking to mid-day once again, Baptiste explains how simply stating the Aadhaar system cannot be hacked does not make it un-hackable and reveals how his efforts to reach out to Indian authorities regarding the flaws in the Aadhaar system have been in vain.

Baptiste revealed his identity a few weeks ago on Twitter, and even put up a photo of himself as the display picture for a brief time. He also appeared in an interview on a French news channel.


Nothing has changed
Has anything changed since? "Things have not really changed," said Baptiste, adding, "I declined all interviews after the appearance on French TV, and worked on non-India related topics. There are some people who recognize me at local conferences but abroad I'm mostly still anonymous." And how did people react to his picture?: "As far as I saw, reactions were quite good. People were curious to see a real picture of me."

Regarding his work on the flaws in the Aadhaar system, Baptiste maintains his stance about the system, with all its current loopholes, being as dangerous as ever. "In general, the issue is to make links in your digital life. By linking everything with everything, you will give a lot of information to the people who handle the data," he says.

But what about prominent UIDAI faces who have been claiming the system cannot be hacked? "There is no un-hackable system. End of story. Saying that Aadhaar is un-hackable does not make it un-hackable," says Baptiste, further pointing out, "Authorities are really playing a dangerous game. They need to fix the flaws exposed by whistleblowers as soon as possible."

Going on a more serious note, Baptiste states the 'state of security in the Indian cyberspace is quite bad.' "Every time I find something, I try to reach out to the concerned authorities. I contact them a lot, but they keep on declining," he says. While he continues to seek answers from the Indian government, he has been receiving a barrage of almost daily threats. But he's unperturbed, "I receive a lot of threats...I don't keep a count of them. In general, this is nothing serious, mostly just bored kiddos. It (the threats) does not affect me."


Half-marathon awaits
Baptiste is not all about exposes and ethical hacking. When he's not doing any of those, he is busy building apps and services, running and being with his family. "I try to be a good father and a good husband. I run a lot as well. Last year, I ran a marathon and I will run a half-marathon at the end of the month."

Thursday, March 29, 2018

13134 - Who is 'ethical hacker' Elliot Alderson? Aadhaar whistleblower says he's 'not Indian' - Money Control

Mar 28, 2018 10:31 AM IST | Source: Moneycontrol.com


The so-called ethical hacker started the revelation as a “game”, with the intention of keeping the government agency UIDAI on its toes.
Moneycontrol News


A Twitter user known as Elliot Alderson, who kicked up a storm across the country when he leaked details of close to 20,000 Aadhaar cards on the internet a few weeks ago, has now claimed that he is "not Indian".

The so called ethical hacker started the revelation as a “game”, with the intention of keeping the government agency UIDAI on its toes. But he did not just stop there.

Alderson, as he is known on Twitter, has now jumped in the midst of a recent data theft scandal by “exposing” loopholes in mobile applications of political parties, including the Bharatiya Janata Party (BJP) and the Congress.

Here's a look at who Elliot Alderson really is and why he is in the news.


Elliot Alderson is not Indian

Who is Elliot Alderson?
Elliot Alderson is the Twitter username of a French security researcher Baptiste Robert, who is a network and telecommunications engineer by profession, according to a report by NewsBytes.

The 28-year-old cybersecurity expert is said to be a one-man army, with no team assisting him.

How Alderson started the Aadhaar fiasco
On March 10, the French researcher posted on his handle that he intended to play a game that night. The game was about how many Aadhaar cards he could find in a span of three hours.

I will play a game tonight: How many #Aadhaar card I can found in 3 hours?
Note: All the cards must be available publicly

The game ended after Alderson had posted details of 20,142 Aadhaar cards online.

This was followed by another low blow when on March 13, Alderson posted a walkthrough to bypass the password protection feature in the official Aadhaar Android application in less than a minute.

He iterated that it was the newest version of the app, and that the attacker need not even have a rooted phone to mount the attack.


How to bypass the password protection of the official #Aadhaar #android #app in 1 minute. 

For this attack, the attacker need a physical access to the phone, rooted phone is not needed and yes this is the latest version of the app.
cc @uidai @ceo_uidai


Shift to data security loopholes in mobile apps of BJP and Congress
On March 23, Alderson posted: “I checked the NaMo app and this is not good”. He followed by saying that PM Narendra Modi’s NaMo app shares personal data of users with third parties.


When you create a profile in the official @narendramodi #Android app, all your device info (OS, network type, Carrier …) and personal data (email, photo, gender, name, …) are send without your consent to a third-party domain called 

.

The researcher did not limit himself to just the NaMo app and moved to Congress’ mobile app next. “Of course, I will check the With INC #android app too” read another of his tweets. At the end of the exercise, he shared the loopholes he found on the internet.



When you apply for membership in the official @INCIndia #android #app, your personal data are send encoded through a HTTP request to 

.

Does Alderson want to make money out the whole endeavour?
It doesn't seem that way. In one of his tweets, Alderson posted the screenshot of an e-mail seeking to purchase the details of the Aadhaar cards from him, and wrote “No need to send me this kind of mail. The answer is a big NO” along with it.
In another tweet, he reiterated that he was neither against, nor in favour of Aadhaar and thinks that a project of this size deserves maximum security.





No need to send me this kind of mail. The answer is a big NO

So, why is he doing what he is doing?
From the series of tweets, it seems that the researcher wants to help the organizations in fixing the vulnerability of the data security system.
His tweet reads: “If it is really a reaction to my tweets, this is really a bad signal. Instead of making disinformation @UIDAI, please discuss with me. Your threats are useless and I will continue my work. So please stop denying and let’s fix things together.”
But why does he want to help? Is it to gain fame? Possible. But nothing can be said clearly unless the man himself clarifies.

Wednesday, March 21, 2018

13042 - Know the man behind Elliot Alderson, who exposed flaws in Aadhaar, OnePlus & Paytm - Hindustan Times

Inspired by Mr. Robot’ Elliot Alderson, Robert Baptiste has been exposing security flaw in popular applications, smartphones and other online services
TECH Updated: Mar 20, 2018 13:28 Ist

Kul Bhushan 
Hindustan Times

A sceengrab of Alderson’s Twitter profile picture.(Elliot Alderson)

Elliot Alderson, a Twitter alias inspired by a character in popular TV series Mr. Robot, has his own cult following on the social media platform. Just like Mr. Robot’s Alderson, he has taken upon himself to expose serious security flaws in several applications, smartphones and other internet services. But he’s primarily known for finding flaws in India’s massive biometric-based programme, Aadhaar.
Earlier this year, Alderson claimed to have found a massive loophole in the Aadhaar’s mobile application on Google that allowed anyone with basic coding knowledge to gain users’ data. The alleged flaw expose gained wide media attention as it came shortly after a Tribune report disclosed that full Aadhaar details was being sold for mere Rs 500 by anonymous sellers.
Knowing the man behind Elliot Alderson
Elliot Alderson’s real name is Robert Baptiste, or at least he tells us so. Robert describes himself as a French developer who develops applications for Android platform and customise AOSP (Android Open Source Project) for smartphone companies. By profession, he’s a network and telecommunications engineer.
When asked about whether he considers himself as a whistleblower, Robert said, “I consider myself as a random guy. I am not special or whatever. As I said multiple times, I encourage people to do the same thing.”
Robert says he follows a “standard process” to find vulnerabilities and doesn’t have a team. But he does get tip off from his followers.
“I have a standard process, nothing fancy. I am working alone. However, a lot of my followers shared what they find because nobody listen to them or they are afraid to be harassed,” he said.



Why Aadhaar?
When asked about why has he a special interest in the Aadhaar programme, he responded, “Aadhaar is interesting by his scale. This is a gigantic project with a lot of security implications.”
“I will not give an opinion on Aadhaar as I don’t think I’am legitimate. However, I think this project deserve the maximum [security],” he said.



Hi #Aadhaar ! Can we talk about the #BenefitsOfAadhaar for the #India population?

I quickly check your #android app on the #playstore and you have some security issues...It's super easy to get the password of the local database for example...

Is it possible to have 100% privacy in modern digital era? “This is complicated, very complicated but you can be close to 100%, yes,” he added.
Read more


  •  
  • How Facebook made its Cambridge Analytica data crisis even worse 




    •  
  • Trump consultants harvested data from 50 million Facebook users during 2016 election campaign: Reports 
  • Alderson’s other work
    Apart from Aadhaar, Alderson has found some security flaws in OnePlus phones in the past. Earlier this year, he pointed out that OnePlus’ clipboard application came with a strange file called “badwords.txt” which was transmitting data to a company called TeddyMobile. The data was being shared without the knowledge. OnePlus later acknowledged the issue and said that the code was just meant for China and was inactive in other markets.

    All these files are used in a obfuscated package which seems to be an #Android library from teddymobile



    TeddyMobile is a Chinese company, they worked with a lot of manufacturers including @oppo.


    Most recently, Alderson and a few other Twitter users pointed out that Paytm was seeking root access to users’ devices. Alderson also got into a brief Twitter tussle with Paytm’s Deepak Abott over the issue. Paytm later removed the root request.



    After this tweet, @Paytm contact me in private. Today, according to them, they remove remotely this root rights request. Do you confirm it? 

    13040 - Aadhaar data leak of Andhra Pradesh women raises security concerns - Indian Express


    By Kiranmai Tutika  |  Express News Service  |   Published: 20th March 2018 02:29 AM  |  

    VIJAYAWADA: The Aadhaar details of many people, especially women, from Andhra Pradesh are available in the public domain, increasing fears of their misuse. The details of woman beneficiaries in the Bangaru Talli scheme, which was launched in 2013 in the united AP, has been hacked and the details of women enrolled under the scheme are available in various websites. In fact, pdf files of hundreds of Aadhaar cards can be downloaded through the site of Bangaru Talli scheme.

    French security researcher Elliot Alderson has tweeted some of the Google search queries, where thousands of Aadhaar cards have been displayed in the public domain, which can be downloaded by any internet user. 

    When New Indian Express tried with one of the google query ‘Aam aadmi ka Adhikar filetype:pdf’, hundreds of links surfaced in the portal and majority of them belong to the Bangaru Talli website. The Bangaru Talli scheme was launched to take care of the girl child in every household from her birth till she completes her graduation. If a mother gives birth to a baby girl, Rs 2,500 will be deposited into her account under the scheme. As the baby grows, for the first two years, Rs 1,000 will be given for various vaccinations. 

    From 3rd year till the age of 5, Rs 1,500 will be given to the family every year through Anganwadi centres. Similarly, from schooling to graduation, the girl child will be given Rs 2,000 to Rs 4000 every year. For this, the Aadhaar card details of the mother were taken. After the bifurcation of the State, the scheme was active in 2014 and 2015. However, after 2015, the scheme was suspended by the AP government. However, the website is still active and the details of the beneficiaries are still on the server. 

    Interestingly, the officials of both the Women and Child Welfare Department and Society for Elimination of Rural Poverty (SERP) are completely unaware of the developments. Commissioner of Women and Child Welfare Department W Arun Kumar told Express, “The scheme was initiated by the SERP and they transferred the scheme to our department. By that time, it was stopped. So, we didn’t include that in our database and still it is with SERP and we are not dealing with it.”Similarly, when Express contacted the officials of SERP,  the are completely unaware of the Bangaru Talli website and the Aadhaar details in the website.

    “I am not aware of the scheme or the subject. As Saturday and Sunday are government holidays, the concerned officials are not available. Soon, we will take up the issue to the concerned officials and take suitable action,” said Johnson, Joint Commissioner of SERP. Rama Devi of All India Democratic Women’s Association (AIDWA) said, “The website hosts the details of women, with their residential addresses and other personal details. If such details reach the public through government sites, it will create a lot of safety issues. The government should take strict action for protecting the personal data of the public, especially women.”


    The Aadhaar security: What UIDAI said 
    The security of Aadhaar has been questioned on various instances. A few months ago, reports emerged about a few people selling Aadhaar data for a fee. The  Unique Identification Authority of India (UIDAI) , however, maintained there had not been any breach of the biometric database, which remained totally secure, with the highest encryption. Mere display of demographic information could not be misused without biometrics, UIDAI had said. UIDAI said Aadhaar was like any other identity document and therefore, never to be treated as a confidential document. If anybody publishes someone’s personal information such as Aadhaar card, passport, mobile number, bank account number or photograph without authorisation, he can be sued for civil damages by the person whose privacy right is infringed. 

    13037 - Aadhaar data a Google search away, warns French hacker; UIDAI dismisses data breach risks - Business Today


     BusinessToday.In   New Delhi     Last Updated: March 19, 2018  | 19:51 IST

    A French hacker has come up with a revelation that the Aadhaar documents can be accessed online by using a Google 'dork' search. This comes four days after the same hacker, Robert Baptiste, who goes by the name Elliot Alderson on Twitter, posted a video on how one can bypass the password protection of the Aadhaar Android app in just 1 minute.
    Robert flagged a major flaw in the Aadhaar system, and said the biometric details related to Aadhaar accounts can be accessed on Google. Multiple news reports also suggested that by just typing 'Mera Aadhaar, Meri Pehchan', which is UIDAI's tagline, on Google, the search opens several PDF files containing Aadhaar information like name, parents name, address, Aadhaar number, picture, and even date of birth. The only information that was not available online was biometric details. However, the UIDAI has junked the hacker's claim and said that by simply knowing someone's Aadhaar, no one can impersonate and harm anybody. The UIDAI said one needs biometric details to authenticate identity.

    Reports suggested some websites were openly revealing Aadhaar information on Google. These portals include incois.gov.in (official government website of the Indian National Centre for Ocean Information Services), the-aiff.com (official website of All India Football Federation), and Starcards India, a private payment gateway service provider. A quick online search found that the Incois has taken down the Aadhaar details, but the AIFF didn't bother to remove those details online. One can easily get access to the details of several Aadhaar accounts on the website.
    The French hacker has said it is high time the UIDAI increases protection around the Aadhaar system. "Hi @UIDAI and @ceo_uidai, it's time for you to force your partners to handle #Aadhaar cards in a secure way. If you make a Google search query with one of this line you will find thousand of #Aadhaar card. @UIDAI: It's time to admit that this is not OK and to work on a fix," he tweeted.

    Hi @UIDAI and @ceo_uidai, it's time for you to force your partners to handle #Aadhaar cards in a secure way.
    If you make a Google search query with one of this line you will find thousand of #Aadhaar card.@UIDAI: It's time to admit that this is not OK and to work on a fix.

    The UIDAI has advised people not to get carried away or confused with some news appearing in social and other media on Aadhaar PDF being available on Google search on 'Mera Aadhaar, Meri Pehchan'.  The authority has said such news is intended to "spread misinformation on India's robust identity system - Aadhaar - and are intentional and irresponsible acts of some unscrupulous elements".
    The authority, through a tweet, has suggested that people sharing personal information, including Aadhaar, on internet to some or other service provider or vendor should take due precautions. "Aadhaar just like any other id, therefore, is never to be treated as a confidential document. By simply knowing someone's Aadhaar, no one can impersonate and harm him because Aadhaar alone is not sufficient, it requires biometrics to authenticate one's Identity," the UIDAI said.

    Publications or posting  of Aadhaar cards by some unscrupulous people have absolutely no bearing on UIDAI and not the least on Aadhaar security. Aadhaar as an identity document by its very nature needs to be shared openly with others as and when required and asked for. 5/8


    Aadhaar just like any other id, therefore, is never to be treated as a confidential document. By simply knowing someone’s Aadhaar, no one can  impersonate & harm him because Aadhaar alone is not sufficient, it requires biometrics to authenticate one’s Identity. 6/8

    The UIDAI's ambitious Aadhaar project is the world's largest biometric database with whopping 111 crore people of the total 125 crore Indians already connected with the identity scheme. While there's no doubt the Aadhaar system makes it easy for the government to rollout benefits that can reach the masses effectively, can the government guaranty the safety of this behemoth database?


    13025 - Identity theft is the biggest threat from Aadhaar, says Robert Baptiste -Business Standard


    The biggest issue is with third party companies collecting Aadhaar data. Aadhaar numbers are spread among companies, some of which have poor security

    Mayank Jain  |  New Delhi 
    Last Updated at March 19, 2018 02:13 IST

    ALSO READ

    Over the past few weeks, an anonymous person, claiming to be a French mobile app developer, has been using his Twitter account to flag security concerns in the Aadhaar system. 

    Recently, the account released a video showing a hack into the Aadhaar application (app). The Unique Identification Authority of India (UIDAI) has maintained that Aadhaar remains safe and secure. Mayank Jain spoke to Robert Baptiste, the man behind the Twitter account called ‘Elliot Alderson’, to understand the way forward for citizens to keep their information safe. Edited excerpts:


    Why are you interested in Aadhaar?
    I am a freelance Android developer. Someone asked me to check the Aadhaar app. This is how I found security flaws and loopholes.

    Have you found any significant vulnerabilities in the system?
    I looked at the Android app, not the Aadhaar system as a whole, and found a lot of security issues that need to be fixed as soon as possible.

    Did you convey these findings to the UIDAI?
    I published all my findings on Twitter, tagging the UIDAI. I asked them to take action but they never responded.

    Why did you publish the details and how can people protect their data?
    I want to help citizens and the government to protect data. I want to spread the word that security cannot be taken lightly. To protect their data, especially Aadhaar, people have to be careful about what information they provide to third parties, who are happy to collect this data.

    In the light of these vulnerabilities, how secure is Aadhaar?
    The biggest issue is with third party companies collecting Aadhaar data. Aadhaar numbers are spread among companies, some of which have poor security. This can be a serious threat for citizens.

    Any substantial danger to people’s lives from these security flaws?
    The biggest threat from Aadhaar is of identity theft.

    Are you open to working with authorities to fix the system?
    I am open to working with any authority on fixing these issues. This is the goal of my efforts. I want to communicate with them and help fix the flaws before someone exploits.

    The implications of your findings?
    By tampering with the app, you can bypass the password protection. It is easy for a developer to do this. When inside, you can access a person’s Aadhaar details and impersonate them.

    Are you scared of being legally prosecuted for exposing vulnerabilities in the Aadhaar system?
    I would not be doing this if I were scared of consequences.


    First Published: Mon, March 19 2018. 06:50 IST

    13018 - Aadhaar on shaky foundation? - The Hindu

    Aadhaar on shaky foundation?

    HYDERABAD, MARCH 17, 2018 23:15 IST

    French cyber-security researcher says document can be accessed online using Google ‘dork’ search

    After raising concerns over finding a large number of Aadhaar cards publicly online, French cyber-security researcher Robert Baptiste has revealed that the document can be accessed by means of a Google ‘dork’ search

    Dork is an advanced mechanism which narrows down search by using strings which indicate the type of file. Mr. Baptiste, who operates the Twitter handle Elliot Alderson, tweeted a screenshot of dork strings and keywords that can be used to view Aadhaar cards online.

    Responding to questions from The Hindu, the cybersecurity expert said that Unique Identification Authority of India (UIDAI) should ensure that parties which handle Aadhaar cards should have in place strong security measures. He also said that the QR Code on Aadhaar cards could be scanned with Android apps.

    “Hi @UIDAI and @ceo_uidai, it’s time for you to force your partners to handle #Aadhaar cards in a secure way. If you make a Google search query with one of this line you will find thousand of #Aadhaar card. @UIDAI: It’s time to admit that this is not OK and to work on a fix (sic),” he tweeted.

    Though calls to the regional office in Hyderabad remained unanswered, it was on March 11 that the UIDAI took to Twitter to dismiss Mr. Baptiste’s tweets on the subject, though it did not name him.

    “UIDAI has dismissed the reports as irresponsible, which appeared in a section of social and other media on security of Aadhaar system being questioned on account of a few Aadhaar cards reportedly put on the Internet by some unscrupulous elements. 1/n,” the verified UIDAI Twitter handle said.

    It also pointed out that publication of Aadhaar details neither has a bearing on UIDAI, nor on Aadhaar security. It underscored that Aadhaar is like any other identity document and must not be treated confidential.


    In another tweet, the UIDAI said, “If anybody unauthorisedly publishes someone’s personal information such as Aadhaar card, passport, mobile number, bank account number, his photograph, he can be sued for civil damages by the person whose privacy right is infringed. 6/n”. It signed off by reiterating that Aadhaar remains ‘safe’ and ‘secure’.