In 2009, I became extremely concerned with the concept of Unique Identity for various reasons. Connected with many like minded highly educated people who were all concerned.
On 18th May 2010, I started this Blog to capture anything and everything I came across on the topic. This blog with its million hits is a testament to my concerns about loss of privacy and fear of the ID being misused and possible Criminal activities it could lead to.
In 2017 the Supreme Court of India gave its verdict after one of the longest hearings on any issue. I did my bit and appealed to the Supreme Court Judges too through an On Line Petition.
In 2019 the Aadhaar Legislation has been revised and passed by the two houses of the Parliament of India making it Legal. I am no Legal Eagle so my Opinion carries no weight except with people opposed to the very concept.
In 2019, this Blog now just captures on a Daily Basis list of Articles Published on anything to do with Aadhaar as obtained from Daily Google Searches and nothing more. Cannot burn the midnight candle any longer.
"In Matters of Conscience, the Law of Majority has no place"- Mahatma Gandhi
Ram Krishnaswamy
Sydney, Australia.

Aadhaar

The UIDAI has taken two successive governments in India and the entire world for a ride. It identifies nothing. It is not unique. The entire UID data has never been verified and audited. The UID cannot be used for governance, financial databases or anything. It’s use is the biggest threat to national security since independence. – Anupam Saraph 2018

When I opposed Aadhaar in 2010 , I was called a BJP stooge. In 2016 I am still opposing Aadhaar for the same reasons and I am told I am a Congress die hard. No one wants to see why I oppose Aadhaar as it is too difficult. Plus Aadhaar is FREE so why not get one ? Ram Krishnaswamy

First they ignore you, then they laugh at you, then they fight you, then you win.-Mahatma Gandhi

In matters of conscience, the law of the majority has no place.Mahatma Gandhi

“The invasion of privacy is of no consequence because privacy is not a fundamental right and has no meaning under Article 21. The right to privacy is not a guaranteed under the constitution, because privacy is not a fundamental right.” Article 21 of the Indian constitution refers to the right to life and liberty -Attorney General Mukul Rohatgi

“There is merit in the complaints. You are unwittingly allowing snooping, harassment and commercial exploitation. The information about an individual obtained by the UIDAI while issuing an Aadhaar card shall not be used for any other purpose, save as above, except as may be directed by a court for the purpose of criminal investigation.”-A three judge bench headed by Justice J Chelameswar said in an interim order.

Legal scholar Usha Ramanathan describes UID as an inverse of sunshine laws like the Right to Information. While the RTI makes the state transparent to the citizen, the UID does the inverse: it makes the citizen transparent to the state, she says.

Good idea gone bad
I have written earlier that UID/Aadhaar was a poorly designed, unreliable and expensive solution to the really good idea of providing national identification for over a billion Indians. My petition contends that UID in its current form violates the right to privacy of a citizen, guaranteed under Article 21 of the Constitution. This is because sensitive biometric and demographic information of citizens are with enrolment agencies, registrars and sub-registrars who have no legal liability for any misuse of this data. This petition has opened up the larger discussion on privacy rights for Indians. The current Article 21 interpretation by the Supreme Court was done decades ago, before the advent of internet and today’s technology and all the new privacy challenges that have arisen as a consequence.

Rajeev Chandrasekhar, MP Rajya Sabha

“What is Aadhaar? There is enormous confusion. That Aadhaar will identify people who are entitled for subsidy. No. Aadhaar doesn’t determine who is eligible and who isn’t,” Jairam Ramesh

But Aadhaar has been mythologised during the previous government by its creators into some technology super force that will transform governance in a miraculous manner. I even read an article recently that compared Aadhaar to some revolution and quoted a 1930s historian, Will Durant.Rajeev Chandrasekhar, Rajya Sabha MP

“I know you will say that it is not mandatory. But, it is compulsorily mandatorily voluntary,” Jairam Ramesh, Rajya Saba April 2017.

August 24, 2017: The nine-judge Constitution Bench rules that right to privacy is “intrinsic to life and liberty”and is inherently protected under the various fundamental freedoms enshrined under Part III of the Indian Constitution

"Never doubt that a small group of thoughtful, committed citizens can change the World; indeed it's the only thing that ever has"

“Arguing that you don’t care about the right to privacy because you have nothing to hide is no different than saying you don’t care about free speech because you have nothing to say.” -Edward Snowden

In the Supreme Court, Meenakshi Arora, one of the senior counsel in the case, compared it to living under a general, perpetual, nation-wide criminal warrant.

Had never thought of it that way, but living in the Aadhaar universe is like living in a prison. All of us are treated like criminals with barely any rights or recourse and gatekeepers have absolute power on you and your life.

Announcing the launch of the # BreakAadhaarChainscampaign, culminating with events in multiple cities on 12th Jan. This is the last opportunity to make your voice heard before the Supreme Court hearings start on 17th Jan 2018. In collaboration with @no2uidand@rozi_roti.

UIDAI's security seems to be founded on four time tested pillars of security idiocy

1) Denial

2) Issue fiats and point finger

3) Shoot messenger

4) Bury head in sand.

God Save India

Showing posts with label aadhaar scam. Show all posts
Showing posts with label aadhaar scam. Show all posts

Wednesday, November 1, 2017

12184 - Andhra Bank, Syndicate Bank customers lose lakhs to Aadhaar fraud

Andhra Bank, Syndicate Bank customers lose lakhs to Aadhaar fraud


Five customer accounts belonging to Andhra Bank and Syndicate Bank were subjected to fraudulent withdrawals using the customer’s Aadhaar data, government data indicated.


Four of the five Aadhaar fraud cases took place in Andhra Bank, while the remaining one took place in Syndicate bank.
The four account holders of Andhra Bank lost a total of 4.2 lakh rupees, while the Syndicate bank customer lost Rs 1.22 lakh.
The amounts were withdrawn from their account by faking the customers’ Aadhaar data. The account holders were subsequently compensated by the banks for their losses.

Aadhaar is India’s single number identification system for all residents, and is similar to the social security number of the US.

AADHAAR HACKING
The government has, in recent months, introduced Aadhaar Enabled Payment System or AEPS. Using AEPS, anyone can transfer or pay money by pressing their fingerprint against an AEPS terminal or ATM after entering their Aadhaar number.
It was not immediately clear how the system was ‘hacked’, but likely methods include making a fake ‘finger cover’ with the victim’s finger prints.
A criminal can wear the fake skin over his or her finger and use it to authenticate a money transfer transaction after entering the victim’s Aadhaar number.

The technology behind such attacks is not very new, and there are even videos on the topic on the Internet.
A second, less-likely method is to hack the fingerprint terminal and send non-genuine data onward for verification.
The Aadhaar system, administered by the Unique Identification Authority of India, works by using fingerpints and iris scans to authenticate users.
In most cases, such as payments using the AEPS, only a single fingerprint is used.
However, iris scans can also be faked by using contact lens that mimic the characteristics of the victim’s eye.
Privacy advocates have expressed concerns about the potential for hacking or misuse of the Aadhaar database.
While some have warned about mimicking of fingerprints and iris-scans, others have expressed worries that hackers may gain access to the central database and substitute their data in place of genuine records.
This would then help hackers to successfully authenticate as other people using their own fingerprints and eye scans.
One of the easiest ways to prevent others from misusing Aadhaar data is to keep one’s unique number private, and not share it unnecessarily.

Read more at https://ultra.news/t-t/33661/andhra-bank-syndicate-bank-customers-lose-lakhs-aadhaar-fraud#7rfHQQKFcErASzqr.99

12181 - In new Aadhaar fraud, conmen loot bank accounts using UPI - Money Control


The police in Delhi and the neighbouring areas of Noida have registered at least 30 complaints regarding these fraudulent cases, reports Scroll.in.

Moneycontrol News
Fraudsters have come up with a new way to siphon money out of bank accounts by using a Unified Payment Interface-supported application linked to Aadhaar.



The police in Delhi and the neighbouring areas of Noida have registered at least 30 complaints regarding these fraudulent cases, reports Scroll.in.

With the government pushing to link Aadhaar with every document including the PAN card, these fraudulent schemes have taken advantage of it as well as the introduction of the UPI.



The United Payments Interface (UPI) is a system through which Indian users can transact across 30 banks in the country with the help of a smartphone. The UPI was developed by the National Payments Corporation of India.

The victims who have complained have said that a person calls them as a Unique Identification Authority of India (UIDAI) representative and pretends to help them through the process of linking PAN with Aadhaar. Subsequently, the people are asked to reveal the one time password generated on the mobile phone linked to Aadhaar which completes the job.

Kislay Chaudhary, cyber security consultant told Scroll that the conman uses the OTP to replace the user's number in the UIDAI interface with theirs, thus linking their number to the victim's Aadhaar. The UPI supported interface is then downloaded to the phone which detects the Aadhaar number linked to the phone number automatically and gives access to the bank account in the Aadhaar number. The conman then can generate the transactions.

Bhisham Singh, Deputy Commissioner of Police in Delhi was quoted as saying, "The pretext of linking Aadhaar with PAN seems like a new trend among conmen, who keep updating themselves with the times. We have a dedicated department in the cyber cell which looks into all such cases. Investigation into several such cases is underway."

The UIDAI has informed that it is aware of such frauds taking place and said that the common people should be made aware that no such calls are being forwarded by the UIDAI.

Monday, September 18, 2017

12059 - Aadhaar linkage trick: man cheated of ₹50K - The Hindu

SPECIAL CORRESPONDENT
SEPTEMBER 15, 2017 00:40 IST


Mumbai: Even as the Central government’s move to link Aadhaar card to bank accounts, SIM cards is being discussed, scamsters have started taking advantage of it.

One such case was registered in Goregaon on Wednesday. A senior citizen was tricked into revealing his debit card details, by a conman posing as a representative from his bank and saying he needed the details to link his account to his Aadhaar card.

According to the Goregaon police, the complainant, Sudhir Mestha (71), is a resident of Siddharth Nagar. “Mr. Mestha received a call on his cell phone at around 11:50 a.m., and the caller identified himself as a representative of a nationalised bank, where Mr. Mestha has a savings account. After asking questions to establish that he indeed had an account in the bank and that he used a debit card, the caller informed Mr. Mestha that his bank account needed to be linked to his Aadhaar number,” said an officer with the Goregaon police.
Mr. Mestha gave all the details, including his debit card PIN number, and the caller hung up saying that the needful will be done soon.

Three hours later, Mr. Mestha received a notification from his bank on his cell phone that ₹49,997 had been debited from his account towards some purchases made online.

Mr. Mestha made inquiries with his bank and found that the purchases had been made using his debit card PIN. He blocked his card and approached the police.

“We have written to the bank seeking details of the purchases made, so that we can find out details like the portal through which the purchases were made and the location of the person who made them,” said senior Inspector Dhanaji Nalawade, Goregaon police station.

The police have registered an offence of cheating and impersonation under the Indian Penal Code against unknown persons.

Sunday, March 27, 2016

9652 - Prepare yourself, financial turbulence ahead - Free Press Journal

— By RN Bhaskar | Mar 23, 2016 12:01 am 

Last fortnight, Paytm, the mobile payments firm, declared that it will increase its seller base on its online marketplace multifold to 500,000 by March 2017, compared to 170,000 currently. To increase its ‘stickiness’ with its customers, it plans to increase its loyalty programmes for its sellers.

Paytm already facilitates around 300 million payment transactions per day and has set a target of 1 billion by 2020. By January 2016, the company’s Gross Merchandise Value (GMV) stood at $2 billion. It hopes to triple this by March 2017.  Much of this could be from its recharge business, which is a high-volume, low-margin business.

On the back of the increasing smartphone penetration, Paytm has been adding 2 million wallets per month and had 15 million active wallets within 10 months of its launch. The company has already begun to offer its platform to IRCTC to facilitate payments in much the same way it does with customers of Uber cab services.

The irony couldn’t have been greater. Till just five years ago, IRCTC was India’s largest ecommerce company (see table). By 2015 it was selling 181 million tickets online.  Now compare this with startup Paytm. The latter has already begun targeting revenues of around Rs.700 million by the end of this year, through at least 10 million wallet transactions a day, and want to touch the billion-rupee mark before 2020.

Its management was recently quoted in the media stating that while recharges continue to be the single largest business, the company has been witnessing a huge growth in bill payments as well. Almost 20% of its transaction value comes from bill payments.  Paytm’s market dominance is confirmed by Nielsen’s own rankings. It is by far the top mobile payments app.
Few could have anticipated this line of business, or even growth, just five years ago. In fact, there is no reason why a bank could not have done what Paytm has done.  After all, banks are aligned with credit cards, which in turn make payments.  But credit cards displayed the same stodginess that banks generally show. They refused to lower their merchant commissions, and were reluctant to accept micro payments. While this has changed nowadays, the fact is that the stodginess of banks and credit card companies allowed for the emergence of players like Paytm.

One driving force that will continue to propel all financial transactions through the mobile phones will be the cost per transaction. This is because, while banks bear a cost of Rs.40 or more per transaction, mobile phones involve a cost of under 20 paise. With more information on customer usage patterns being now made available through the internet and the mobile phone, with more data on the identity of individuals (thanks to digitisation of identities through Aadhaar) and with increasing public trust in the payment systems that players offer, expect a surge in mobile and web-based transactions in the coming years.

But before anyone lets out a whoop of joy, a couple of warnings need to be put into place.

First, the market urgently requires a regulator for online transactions. The current practice of having an Ombudsman with the RBI may prove to be inadequate. As such payment platforms proliferate, the danger of identity theft, wallet theft and impersonation looms large. Better encryption is one answer. But having a cyber cell that is capable of prompt action, and tracking the source of mischief, is the desperate need of the hour.

The police cybercell is no solution. It is ill-equipped to handle cyber-crime. It often relies on private consultants to deal with some of the most basic tracking solutions. Anecdotal narrations abound about complainants coming to the police with the findings of their own private investigations, which the police then act upon immediately. Unless the cybercell departments of the police and the RBI are strengthened, expect many small people to get duped.

A second issue relates to the misuse of PAN and Aadhaar card information. Currently, it is very easy for anyone to get a new telephone connection using the PAN/Aadhaar details of someone else. Touts who peddle mobile telephone connections offer these services quite brazenly – at a price of course. While the earlier practice was to use someone else’s PAN card details – in collusion with someone within the mobile telephone and courier companies – the new game is to use Aadhaar cards.

Unlike PAN cards, Aadhaar cards do not bear the signature of the holder.  And most Aadhaar cards sport photographs that are barely recognisable – even less so when they are photocopied. There is almost no way for anyone to verify the genuineness of an Aadhaar card holder because the faces on the cards are unrecognisable.

Reissuing Aadhaar cards is too expensive and time-consuming a proposition. But sending out mobile and email alerts each time a new mobile connection or a fresh transaction is registered can considerably reduce the incidence of malpractice. Providing each card holder access to a web page where he or she can view a list of such registrations every day would be an added help.  Fraudulent use of such cards can be detected almost immediately.  It is time to empower each person with the ability to detect fraudulent use of such cards, and report this promptly.  The rapid growth in mobile transactions requires considerable tightening of verification procedures regarding issue of new SIM cards.

Will the government wake up? Or will it wait for a big scam to prod it into action?


The author is consulting editor with FPJ

Monday, January 19, 2015

7221 - Aadhaar scam for pensions surfaces across Telangana - Deccan Chronicle


DC | L. Venkat Ram Reddy | January 17, 2015, 04.01 am IST

Lack of proper verification mechanisms at the centres to confirm the age of applicants is making the job easier in manipulating age details on Aadhaar Card (Representational Image)

Hyderabad: The over-dependence of the Telangana state government on Aadhaar cards to identify genuine beneficiaries of welfare schemes has been prompting officials and public representatives to resort to irregularities.

Around Rs 2 crore is being siphoned off every month since last November by manipulating age details on Aadhaar. All districts in Telangana have been witnessing heavy rush for re-enrolment at Aadhaar centres seeking age correction to secure enhanced pensions from the government. And lack of proper verification mechanisms at the centres to confirm the age of applicants is making the job easier in manipulating age details on Aadhaar.
Medak, the home district of Chief Minister K. Chandrasekhar Rao tops the list with about 19,000 people applying for age correction in Aadhaar cards. Similarly, in Mahbubnagar, Nalgonda and Ranga Reddy districts, number of age correction applications stand at 18,000, 17,000 and 16,000 respectively. The remaining six districts have witnessed age correction applications ranging from 10,000 to 15,000.
  

Sunday, April 29, 2012

2543 - Aadhaar scam did not stop with kingpin - TOI


Mahesh Buddi, TNN | Apr 29, 2012, 01.58AM IST

HYDERABAD: The Aadhaar scam is turning curiouser. Investigations so far have revealed that Mohammed Ali, the data entry supervisor blamed for the scam, was terminated by Infrastructure Leasing & Financial Services Limited (IL&FS) in September 2011, but the fraud was perpetuated by data entry operators at 20 enrollment centres in the Old City. Also, more flaws in the enrollment process have come to light. 

Investigating officials grilling 22-year-old data entry supervisor Mohammed Ali of Vattepally in Falaknuma for enrolling 30,000 people in a span of just six months from 20 centres in the Old City discovered that he was actually sacked by his employer, IL&FS, in September last year. So, they started probing how Ali could enroll 30,000 people, including 870 in the physically-disabled category, after termination from service. 

They discovered that after his exit from IL&FS, enrolling agents at the 20 centers in the Old City had been using Mohammed Ali's login and password to carry on enrollments and these agents had committed the fraud. However, to upload the Aadhaar card details of an individual, the agent has to log in using a special ID, password and also authorise the details using his thumb impression in the biometric scanner. 

Ideally, the enrollment through Ali's ID should not have happened as he was not present at these centres to authenticate details using his fingerprints, but a flaw in the registration mechanism allowed them to carry out the fraud, a source said. 

The probe revealed that the operators at the 20 centers managed to upload details of 30,000 people by authorising them with their own fingerprints. "The system has a flaw. When an agent provides wrong authorisation fingerprint, it rejects on two occasions, but at the third instance it automatically takes the default authorisation print and completes the enrollment process," a civil supplies department source said. 

The civil supplies department is the nodal agency for Aadhaar cards, being generated by the Unique Identification Authority of India (UIDAI) in the state. 

Probe agencies have realised that some IL&FS officials were in the know of things, but for reasons unknown, allowed the fraudulent enrollments to happen. On Saturday, a senior IL&FS official landed in the city to cooperate with the probe agencies. Police are likely to book cases against the firm's staff soon. 

On Friday, police prepared a questionnaire asking UIDAI officers in Delhi about who had authorised the registration of 30,000 Aadhaar cards from the Old City under the name of Mohammed Ali when he was actually sacked. They also sought to know how the system had been accepting details of an individual without biometric authorisation.