In 2009, I became extremely concerned with the concept of Unique Identity for various reasons. Connected with many like minded highly educated people who were all concerned.
On 18th May 2010, I started this Blog to capture anything and everything I came across on the topic. This blog with its million hits is a testament to my concerns about loss of privacy and fear of the ID being misused and possible Criminal activities it could lead to.
In 2017 the Supreme Court of India gave its verdict after one of the longest hearings on any issue. I did my bit and appealed to the Supreme Court Judges too through an On Line Petition.
In 2019 the Aadhaar Legislation has been revised and passed by the two houses of the Parliament of India making it Legal. I am no Legal Eagle so my Opinion carries no weight except with people opposed to the very concept.
In 2019, this Blog now just captures on a Daily Basis list of Articles Published on anything to do with Aadhaar as obtained from Daily Google Searches and nothing more. Cannot burn the midnight candle any longer.
"In Matters of Conscience, the Law of Majority has no place"- Mahatma Gandhi
Ram Krishnaswamy
Sydney, Australia.

Aadhaar

The UIDAI has taken two successive governments in India and the entire world for a ride. It identifies nothing. It is not unique. The entire UID data has never been verified and audited. The UID cannot be used for governance, financial databases or anything. It’s use is the biggest threat to national security since independence. – Anupam Saraph 2018

When I opposed Aadhaar in 2010 , I was called a BJP stooge. In 2016 I am still opposing Aadhaar for the same reasons and I am told I am a Congress die hard. No one wants to see why I oppose Aadhaar as it is too difficult. Plus Aadhaar is FREE so why not get one ? Ram Krishnaswamy

First they ignore you, then they laugh at you, then they fight you, then you win.-Mahatma Gandhi

In matters of conscience, the law of the majority has no place.Mahatma Gandhi

“The invasion of privacy is of no consequence because privacy is not a fundamental right and has no meaning under Article 21. The right to privacy is not a guaranteed under the constitution, because privacy is not a fundamental right.” Article 21 of the Indian constitution refers to the right to life and liberty -Attorney General Mukul Rohatgi

“There is merit in the complaints. You are unwittingly allowing snooping, harassment and commercial exploitation. The information about an individual obtained by the UIDAI while issuing an Aadhaar card shall not be used for any other purpose, save as above, except as may be directed by a court for the purpose of criminal investigation.”-A three judge bench headed by Justice J Chelameswar said in an interim order.

Legal scholar Usha Ramanathan describes UID as an inverse of sunshine laws like the Right to Information. While the RTI makes the state transparent to the citizen, the UID does the inverse: it makes the citizen transparent to the state, she says.

Good idea gone bad
I have written earlier that UID/Aadhaar was a poorly designed, unreliable and expensive solution to the really good idea of providing national identification for over a billion Indians. My petition contends that UID in its current form violates the right to privacy of a citizen, guaranteed under Article 21 of the Constitution. This is because sensitive biometric and demographic information of citizens are with enrolment agencies, registrars and sub-registrars who have no legal liability for any misuse of this data. This petition has opened up the larger discussion on privacy rights for Indians. The current Article 21 interpretation by the Supreme Court was done decades ago, before the advent of internet and today’s technology and all the new privacy challenges that have arisen as a consequence.

Rajeev Chandrasekhar, MP Rajya Sabha

“What is Aadhaar? There is enormous confusion. That Aadhaar will identify people who are entitled for subsidy. No. Aadhaar doesn’t determine who is eligible and who isn’t,” Jairam Ramesh

But Aadhaar has been mythologised during the previous government by its creators into some technology super force that will transform governance in a miraculous manner. I even read an article recently that compared Aadhaar to some revolution and quoted a 1930s historian, Will Durant.Rajeev Chandrasekhar, Rajya Sabha MP

“I know you will say that it is not mandatory. But, it is compulsorily mandatorily voluntary,” Jairam Ramesh, Rajya Saba April 2017.

August 24, 2017: The nine-judge Constitution Bench rules that right to privacy is “intrinsic to life and liberty”and is inherently protected under the various fundamental freedoms enshrined under Part III of the Indian Constitution

"Never doubt that a small group of thoughtful, committed citizens can change the World; indeed it's the only thing that ever has"

“Arguing that you don’t care about the right to privacy because you have nothing to hide is no different than saying you don’t care about free speech because you have nothing to say.” -Edward Snowden

In the Supreme Court, Meenakshi Arora, one of the senior counsel in the case, compared it to living under a general, perpetual, nation-wide criminal warrant.

Had never thought of it that way, but living in the Aadhaar universe is like living in a prison. All of us are treated like criminals with barely any rights or recourse and gatekeepers have absolute power on you and your life.

Announcing the launch of the # BreakAadhaarChainscampaign, culminating with events in multiple cities on 12th Jan. This is the last opportunity to make your voice heard before the Supreme Court hearings start on 17th Jan 2018. In collaboration with @no2uidand@rozi_roti.

UIDAI's security seems to be founded on four time tested pillars of security idiocy

1) Denial

2) Issue fiats and point finger

3) Shoot messenger

4) Bury head in sand.

God Save India

Showing posts with label cyber crimes. Show all posts
Showing posts with label cyber crimes. Show all posts

Friday, May 25, 2018

13588 - Aadhaar link & DeMon made India cyber vulnerable: Hague Delta boss - TNN


Amrita Didyala | TNN | May 23, 2018, 10:31 IST

HYDERABAD: A host of digitalization programs, linking of Aadhaar, linking of critical infrastructures and demonetisation has made the country cyber-vulnerable, said Joris den Bruinen, deputy director of 'The Hague Security Delta' (HSD) “India has an emerging need for cyber security and we have the expertise,” he said. 

Citing an example of how a computer hacked or attacked with ransomware takes about three to four days to just track down the hacker in India and how few of the Dutch companies can do it within a couple of hours, he said, “While all over the world the cyber security market is growing, we see a huge need of cyber security in India. Since we have the knowledge, we must work together. In fact with the soft landing program (as part of the agreement signed on Tuesday) very soon we hope to see many Dutch companies coming to Hyderabad and vice versa,” added Bruinen, who is in the country, as part of the delegation from Netherlands accompanying the Dutch Prime Minister.

The soft landing program will help cyber security companies and startups to access market, finance as well as talent in Hague and Hyderabad. The HSD (together with the cyber security companies, knowledge institutions and government agencies) offers cyber security to European countries like Belgium and Germany, UK, Canada, Japan and Singapore too have been collaborating with the HSD for a while.

“With the cluster set up in Hyderabad, India becomes the newest country to collaborate with us on cyber security,” he added.


The first manifestation of the agreement signed between the two clusters on Tuesday is the Hague summer school, slotted to begin in July. “It will include classes from NATO. Students from India will visit Hague for the summer school,” said JGM Michel Rademaker, from the Hague Centre of Strategic Studies.

Saturday, December 2, 2017

12453 - Unsafe Aadhaar serves cybercrime - Deccan Herald

Kuldeep Singh, Nov 29 2017, 1:28 IST

In August 2017, Abhinav Srivastava, a Bengaluru-based IT professional, was arrested for stealing Aadhaar data. He piggybacked on the e-hospital server of National Informatics Centre to access Aadhaar data.

Earlier, in February, six employees of telecom service provider Reliance Jio acquired fingerprints from the Aadhaar Central Identities Data Repository to activate and sell SIM cards. These incidents clearly show that Aadhaar biometric and demographic data is vulnerable to electronic identity thefts. Clearly, the nation's capability to secure Aadhaar data amounts to an index of its cybersecurity status.

Evidently, Aadhaar data, due to its design, is vulnerable to identity theft and can be hacked. It appears the hackers acquired fingerprints and unique identification numbers from either the central database or database of other organisations and used it to assume identities and carry out fraudulent transactions. Hackers can digitally replay fingerprints for authentication purposes, or to even create a physical fingerprint with the use of a 3D printer.

The Department of Computer Science and Engineering, Michigan State University, US, conducted a study that established that replication of fingerprints was possible for under $500. With fingerprint replication being accessible so easily and at such low costs, making biometrics the universal access key will have severe repercussions, especially a rise in cybercrimes and identity theft.

While the government has made it easy for the common man to access services through Aadhaar, it may be too ambitious in its application. Clearly, Aadhaar lacks a security mechanism to uphold it. New Delhi should have looked at similar systems with unification of identity and authentication that the US follows to foresee cyber threats.

In 2008, the US Federal Regulator for Consumer Protection released a report on the correlation between identity theft and social security numbers which said that over 7% of the adult US population experienced identity theft, but also that it grossed over $100 billion in losses. The Aadhaar and the US social security numbers are different, but it is their dual use as identifier and authenticator that gives rise to the risk of identity theft.

Far from being a hypothetical prediction, the above statistics may well apply to India in the near future. In February, UIDAI filed a report against an employee of Suvidhaa Infoserve. This claim stated that 400 transactions were undertaken through replication of Aadhaar information saved on the Axis Bank gateway, which proves that the affliction of fraudulent transactions has achieved a head start on the legal and technical framework designed to prevent it.

The government launched the Aadhaar project in January 2009 to provide individuals and institutions a unified form of identification to eliminate the need for multiple identity documents. People, especially the underprivileged classes, seek services and benefits such as food coupons, pensions, insurance and apply to check their bank accounts; it is therefore necessary to ensure that only rightful recipients obtain the data associated with the new identification process.
Hot-zone for cyberattacks

Aadhaar is created on a central database that stores biometric information of citizens, called the Central Identities Data Repository - the treasure vault of an identity thief. Therefore, it is a hot-zone for cyberattacks from outside. Also, those who guard the vault have access to it, and have the potential to breach the database to make it susceptible to misuse and theft.
Aadhaar is also a prime target for hackers due to its dual role in identification and authentication of user credentials. Imagine that an individual's name is a password to access his valuables. People need to feed in their unique identification number and biometrics in order to verify their identity, and that identification alone gives them access to services and benefits.

Therefore, the remedial process that makes an excellent initiative also an efficient initiative is two-pronged. India requires the imposition of a legal framework that overcomes its current shortcomings and an improvement in its design to ensure it cannot be breached easily.

The shortcomings in the legal framework include the lack of a notification system that informs when a data breach does occur and a fee imposed upon individuals that request a log of their authentications. Additionally, a mechanism to reimburse losses incurred through identity theft is mandatory. Currently, all that an afflicted individual can access is a grievance centre, after which the law has no accountability to anybody to reimburse losses or process criminal charges.

Other measures to make Aadhaar a universal measure of identification and authentication must include steps to streng ­then the application infrastructure of Aadhaar. Towards this objective, encryption is the first step to secure a database of bio-metric records. It must also create another layer of security which strengthens the process through the use of a confidential element, such as a password or a PIN.

After hackers poach biometrics, it is imperative to acknowledge that this data cannot be reissued and becomes useless. A person's fingerprints in the hands of a hacker are useless to him/her. To store electronic identities in a barrel that can be ferreted out by hackers benefits cybercriminals more than it serves the entitled people.

(The writer is a Bengaluru-based cybersecurity professional and ethical hacker)


Friday, November 17, 2017

12385 - As Aadhaar becomes mandatory to open bank accounts, cyber thugs switch to digital wallets - TNN



Shalabh | TNN | Updated: Nov 16, 2017, 07:41 IST

LUCKNOW: Cyber thugs have started using e-wallets as opening bank accounts is getting difficult without Aadhaar card. The revelation came when a three-member gang was busted by special task force of UP police on Wednesday noon. 

The three arrested from Vibhav Khand, Gomtinagar asked victims to deposit money in Paytm wallet and confessed to interrogators that they were unable to open fresh bank account for carrying out fraudulent activities without providing Aadhaar. Cyber wing of STF pursued complaint it received over email last month. The complainant from sector 24 in Noida had been duped of Rs 3,400 he paid to buy an electronic device. 

The team probing the case found out that Nadeem Haider, Vikas Kumar and Rahul Yadav had managed to get their hands on personal information of 6,000 customers who had shared their details with Snapdeal.

Nodal officer of cyber wing, additional SP Triveni Singh said, "They posed as sales executive of Snapdeal and offered incredible deals to customers. But with a catch. The potential targets were asked to deposit money in Paytm wallets instead of buying the item over Snapdeal. While many turned their offer down, some agreed to deposit money as they felt the fraudsters were really offering some lucrative limited period offer."

The police team was following up with the two e-commerce companies. "While Paytm would share the details of the wallet holders, Snapdeal has initiated internal inquiry to find out how the three were able to possess personal data of customers," said Singh.

TOP COMMENT
This is aachhe din for peoples of India. Feeling proud,voted for Modi.
Soumya Prakash jena

Cyber expert Rakshit Tandon said that cyber thugs have started switching over to e-wallets since maintaining anonymity is very easy. "e-commerce is largely unregulated sector. Security concerns of patrons is not priority for such companies. As biometrics have to be provided to the bank identifying the culprit would get easy," said Tandon highlighting the vulnerability.

An FIR against the three was registered at Vibhuti Khand police station for cheating and forgery and IT Act has also been pressed. The police team has also found details of four savings accounts the three held in different banks to find out how much money they have been able to make. 


Friday, August 18, 2017

11792 - Now, cyber thieves more innovative to loot money -New Indian Express

By Express News Service  |   Published: 15th August 2017 08:52 AM  |  
Last Updated: 15th August 2017 08:52 AM  |   A+A A-   |  


VIJAYAWADA: Post demonetisation of `500 and `1,000 currency notes, those resorting to cyber crime are adopting new technologies to loot money from gullible people. The miscreants are using online classified advertising platforms to attract and cheat people.According to police, when people do online shopping pseudo portals, often they end up getting fake goods. Most of the times, the consumers do not receive the products they had ordered for. A senior police officer divulged that offenders are choosing online platforms to sell stolen goods. If a product does not have any digital identification, it is highly difficult to trace out certain products. Several people, who are unaware about white collar frauds, reveal their confidential data such as debit and credit card details by entertaining phone calls from inter-state gangs. Police alerted citizens that banks will not ask customers for their confidential details over the telephone.
Besides the inter-state gang traps, Nigerian frauds also send phishing emails luring with big amounts. Customers are asked to log in to their accounts using the links provided in emails. If the customer logs in, the login credentials are sent to the offenders.

Nowadays, SMS from various e-commerce websites telling ‘You have `2,000 in your wallet’ are rampant. If anyone responds to these messages, they have to shell out a huge sum in order to claim the virtual money. In the case of One-Time-Password (OTP) frauds, the offenders contact random people asking for the OTPs that may have been generated as a result of any transaction made. Once the person reveals the OTP he has received, the offenders finish their work online.When an offence committed involves a small amount, it becomes a burden for the government as they have to incur more money than stolen amount for investigation. According to reports, many such crimes has its origin in Uttar Pradesh and Bihar.

When contacted, DCP Gajarao Bhupal admitted that cyber crime is on the rise. He said, “People should not reveal personal details such as Aadhaar numbers and OTPs to any incoming calls.” 
He further added that the public is vulnerable to such calls as many of them don’t have knowledge about such frauds. Police authorities are requesting people to opt for cash on delivery option and hand over the cash after thorough verification of the goods. The city police have set up a temporary cyber crime wing with a Sub Inspector level officer in the premises of Commissioner of Police Office. 

11784 - Mumbai man promises to link 70-yr-old’s bank account to Aadhaar card, dupes her of Rs1.67 lakh - Hindustan Times

Mumba police said the woman approached them on August 2, saying the man asked her for her 16-digit card number, CVV and one time password
MUMBAI Updated: Aug 14, 2017 11:13 Ist


Hindustan Times

Police said they were struggling to solve cases of cybercrime, with as many as 391 being reported till July.(HT File)

A cybercriminal posing as a bank official duped a 70-year-old woman of Rs1.67 lakh on the pretext of linking her bank account to her Aadhaar card.

Police said the woman approached them on August 2, saying the man asked her for her 16-digit card number, CVV and one time password she received on her mobile phone.

“He said he worked for a bank in which I have an account, so I did not find his request suspicious. I don’t know how he found out that I was a customer of that bank. He told me he needed to link my account to my Aadhaar card and so asked for my card number and details. He asked me for the ‘verification number’ I received on my mobile phone. I didn’t know that was a one time password,” said the woman, who did not wish to be identified.


Read more
  •  
  • Know senior citizens in Mumbai? Warn them against men posing as bank officials, two were duped of Rs61K 


    •  
  • A year after customer’s card is cloned, used to withdraw Rs40K, Mumbai bank asks cops to file case 

  • The DN Nagar police registered a case against the unidentified fraudster. However, they said they were struggling to solve cases of cybercrime, with as many as 391 being reported till July. This means an average of one case was reported daily.
    Almost 90% of these fraudsters are still operating as only 44 of 391 cases have been solved — a detection rate of 11%.

    “We keep trying to make people aware, through the media and through social networking sites, that they must never share their card details with a stranger. A bank will never call you asking for your personal details. There is a need to ramp up awareness drives, especially among senior citizens,” said an officer.

    11781 - Rise in cyber crime jolts centre into action - Live Mint

    The home ministry clarifies that the government has taken several legal, policy and institutional measures to check cyber crime


    A cyber cell at a police station in Ghaziabad. Authorities had blocked 652 URLs until June 2017. Photo: HT

    New Delhi: The Union home ministry has been jolted into action after the Indian Computer Emergency Response Team (CERT-In) reported that 50 incidents of cyber crime, affecting 19 financial organizations, took place between November 2016 and June 2017.

    CERT-In data showed that there were a total of 50,362 cyber crime incidents in 2016. This year, there have been 27,482 incidents until June. Authorities had blocked 652 URLs (uniform resource locators) until June 2017.

    While CERT-In has issued 21 advisories for security safeguards covering the point of sale, micro ATMs, electronic wallets, online banking, smart phones, unified payment interface, SIM cards, wireless access routers and Aadhaar-enabled payment systems, the home ministry stated that it had roped in several organizations to make the country’s systems impenetrable.

    “Cyber security mock drills involving 148 organizations from different sectors including finance sector have been conducted to enable assessment of cyber security preparedness of organizations,” said a senior home ministry official.
    The home ministry also clarified that the government had taken several legal, policy and institutional measures to check cyber crime.

    “India is working for bilateral cooperation with around 15 countries for exchange of information on cyber crime. CERT-In also issues alerts against the latest cyber threats and countermeasures on a regular basis,” the official added.

    Experts stated that the sudden spike in cyber crimes had come about after demonetisation, simultaneously stressing the need for an appropriate cyber resilience policy.

    “The post-demonetisation era saw the absence of any deterrent by way of legal provision. Today, the Indian information technology law goes soft on cyber crime, especially after the 2008 amendment because except cyber terrorism and child pornography, all other cyber crime offences are bailable. This means that a person is free to come out and delete evidence,” said Pavan Duggal, cyber law expert at the Supreme Court.

    The problem however, spills over from financial crimes to terrorism as well. The National Investigation Agency (NIA) stated that it has been investigating at least 20 Islamic State (IS)-related cases where the internet has been used to radicalize people.

    “The handlers are not in India. They operate modules which are already in existence in India and assign the task of tracking vulnerable youths to some of their operatives,” said a senior NIA official.

    “These handlers of the IS operatives in India monitor the pages and the links that people share and like on platforms such as Facebook and Twitter. Based on that, they then contact the person over apps such as WhatsApp, Viber and Telegram and begin the process of radicalizing and inducting the person into IS,” the official added.

    With the Reserve Bank of India’s guidelines governing cyber security for banks, the home ministry has also embarked on various drives to tighten cyber security.

    “A separate research and development fund for cyber security of Rs1,000 crore has been created to be spent over five years for upgrading technological capacity. A central sector project namely Cyber Crime Prevention for Women and Children (CCPWC) with a total estimated cost of Rs195.83 crore has also been approved to provide infrastructure and capacity building to address cyber crimes,” minister of state for home affairs Hansraj Ahir informed the Lok Sabha earlier this month.

    First Published: Sun, Aug 13 2017. 11 53 PM IST

    Saturday, August 12, 2017

    11750 - India vulnerable to cyber crime, needs to upgrade tech: IIT-Kanpur study - Hindustan Times


    Cyber crimes had been rising constantly till 2013, when 71,780 such cases were registered in India. The number grew to 1.49 lakh in 2014 and three lakh in 2015, finally doubling in 2016.
    TECH Updated: Aug 09, 2017 08:55 Ist

    Haider Naqvi, Hindustan Times, Kanpur

    Danger of cyber crime is looming large(Representative Photo)

    A study conducted by IIT-Kanpur experts has revealed an alarming rise in cyber crimes across the country in the last one year.
    Senior scientists Manindra Agarwal and Sandeep Shukla, the brains behind the exercise, pointed out that the country needs to upgrade its defences “without any delay” because the risk of cyber crime has doubled. They have submitted the study to the central government, and briefed the parliamentary committee on finance in this regard.

    The study, which recommended the expedition of the Computer Emergency Response System (CERS) project for the financial sector, said: “Almost all financial institutions, banks and online transactions are vulnerable to cyber crime. Digital wallets like Paytm and BHIM, which gained prominence after demonetisation, were found unsafe during the research.”

    The CERS project was proposed in the Union budget unveiled by the central government.

    The experts said as the government was pushing for Aadhaar-based financial transactions, checking the unauthorised use of its database should be a priority. They termed recent leakages of Aadhaar data as a matter of concern.

    Cyber crimes had been rising constantly till 2013, when 71,780 such cases were registered in India. The number grew to 1.49 lakh in 2014 and three lakh in 2015, finally doubling in 2016.



    The report stated that the websites of financial institutions and government establishments were particularly vulnerable to attacks. “The danger of cyber crime is looming large on the defence, education and telecom sectors. Around 164 government websites were hacked in 2015,” it added.

    Agarwal and Shukla noted that while the government initiated a number of post-demonetisation programmes aimed at digitising the economy, the cyber-security centres set up by the Reserve Bank of India were found lacking on several fronts.

    The Reserve Bank of India has often approached premier technical institutes, including IIT-Kanpur, for expert opinion on cyber centres. However, they are unable to engage on cyber-security research due to lack of experts. Sources said there were just three to four cyber-security experts across all the IITs in India, and two of them were based at the Kanpur facility.
    “The government and private sector partnership system in cyber security also lacks experts. Such partnership centres require updated technology and highly skilled cyber experts,” the study said, advising Indian banks and government agencies to engage top cyber-security experts for creating a layer of advanced protection that was missing in most financial institutions.

    The report also pointed out that the Computer Emergency Response Team-India, formed to handle cyber exigencies, is in need of an immediate revamp because it does not have sufficient inter-disciplinary connections.