In 2009, I became extremely concerned with the concept of Unique Identity for various reasons. Connected with many like minded highly educated people who were all concerned.
On 18th May 2010, I started this Blog to capture anything and everything I came across on the topic. This blog with its million hits is a testament to my concerns about loss of privacy and fear of the ID being misused and possible Criminal activities it could lead to.
In 2017 the Supreme Court of India gave its verdict after one of the longest hearings on any issue. I did my bit and appealed to the Supreme Court Judges too through an On Line Petition.
In 2019 the Aadhaar Legislation has been revised and passed by the two houses of the Parliament of India making it Legal. I am no Legal Eagle so my Opinion carries no weight except with people opposed to the very concept.
In 2019, this Blog now just captures on a Daily Basis list of Articles Published on anything to do with Aadhaar as obtained from Daily Google Searches and nothing more. Cannot burn the midnight candle any longer.
"In Matters of Conscience, the Law of Majority has no place"- Mahatma Gandhi
Ram Krishnaswamy
Sydney, Australia.

Aadhaar

The UIDAI has taken two successive governments in India and the entire world for a ride. It identifies nothing. It is not unique. The entire UID data has never been verified and audited. The UID cannot be used for governance, financial databases or anything. It’s use is the biggest threat to national security since independence. – Anupam Saraph 2018

When I opposed Aadhaar in 2010 , I was called a BJP stooge. In 2016 I am still opposing Aadhaar for the same reasons and I am told I am a Congress die hard. No one wants to see why I oppose Aadhaar as it is too difficult. Plus Aadhaar is FREE so why not get one ? Ram Krishnaswamy

First they ignore you, then they laugh at you, then they fight you, then you win.-Mahatma Gandhi

In matters of conscience, the law of the majority has no place.Mahatma Gandhi

“The invasion of privacy is of no consequence because privacy is not a fundamental right and has no meaning under Article 21. The right to privacy is not a guaranteed under the constitution, because privacy is not a fundamental right.” Article 21 of the Indian constitution refers to the right to life and liberty -Attorney General Mukul Rohatgi

“There is merit in the complaints. You are unwittingly allowing snooping, harassment and commercial exploitation. The information about an individual obtained by the UIDAI while issuing an Aadhaar card shall not be used for any other purpose, save as above, except as may be directed by a court for the purpose of criminal investigation.”-A three judge bench headed by Justice J Chelameswar said in an interim order.

Legal scholar Usha Ramanathan describes UID as an inverse of sunshine laws like the Right to Information. While the RTI makes the state transparent to the citizen, the UID does the inverse: it makes the citizen transparent to the state, she says.

Good idea gone bad
I have written earlier that UID/Aadhaar was a poorly designed, unreliable and expensive solution to the really good idea of providing national identification for over a billion Indians. My petition contends that UID in its current form violates the right to privacy of a citizen, guaranteed under Article 21 of the Constitution. This is because sensitive biometric and demographic information of citizens are with enrolment agencies, registrars and sub-registrars who have no legal liability for any misuse of this data. This petition has opened up the larger discussion on privacy rights for Indians. The current Article 21 interpretation by the Supreme Court was done decades ago, before the advent of internet and today’s technology and all the new privacy challenges that have arisen as a consequence.

Rajeev Chandrasekhar, MP Rajya Sabha

“What is Aadhaar? There is enormous confusion. That Aadhaar will identify people who are entitled for subsidy. No. Aadhaar doesn’t determine who is eligible and who isn’t,” Jairam Ramesh

But Aadhaar has been mythologised during the previous government by its creators into some technology super force that will transform governance in a miraculous manner. I even read an article recently that compared Aadhaar to some revolution and quoted a 1930s historian, Will Durant.Rajeev Chandrasekhar, Rajya Sabha MP

“I know you will say that it is not mandatory. But, it is compulsorily mandatorily voluntary,” Jairam Ramesh, Rajya Saba April 2017.

August 24, 2017: The nine-judge Constitution Bench rules that right to privacy is “intrinsic to life and liberty”and is inherently protected under the various fundamental freedoms enshrined under Part III of the Indian Constitution

"Never doubt that a small group of thoughtful, committed citizens can change the World; indeed it's the only thing that ever has"

“Arguing that you don’t care about the right to privacy because you have nothing to hide is no different than saying you don’t care about free speech because you have nothing to say.” -Edward Snowden

In the Supreme Court, Meenakshi Arora, one of the senior counsel in the case, compared it to living under a general, perpetual, nation-wide criminal warrant.

Had never thought of it that way, but living in the Aadhaar universe is like living in a prison. All of us are treated like criminals with barely any rights or recourse and gatekeepers have absolute power on you and your life.

Announcing the launch of the # BreakAadhaarChainscampaign, culminating with events in multiple cities on 12th Jan. This is the last opportunity to make your voice heard before the Supreme Court hearings start on 17th Jan 2018. In collaboration with @no2uidand@rozi_roti.

UIDAI's security seems to be founded on four time tested pillars of security idiocy

1) Denial

2) Issue fiats and point finger

3) Shoot messenger

4) Bury head in sand.

God Save India

Showing posts with label data breaches. Show all posts
Showing posts with label data breaches. Show all posts

Sunday, May 20, 2018

13549 - Data breach is shameful, very dangerous, says Swara Bhasker - India Today

  • Vidya S.
  • May 15, 2018
  • UPDATED 16:17 IST

HIGHLIGHTS
  • In India too, the data leak had its impact with Facebook
  • Close to 5.2 lakh Indians were "potentially affected"
  • There was an outrage that ensued #DeleteFacebook witnessed in US

Facebook boss Mark Zuckerberg arrives to testify before the US Congress over data leak.

It may well be a tale of two democracies in the era of social media. Earlier this year, when scandal rocked Facebook in the form of Cambridge Analytica, hundreds of users in the US quit the social media platform accusing it of parting away personal information to a political consulting firm without their consent.
In India too, the data leak had its impact with Facebook admitting that close to 5.2 lakh Indians were "potentially affected" by the breach. While perfunctory verbal outrage ensued, there was no hashtag #DeleteFacebook campaign in India on a scale that witnessed the US, with many users dismissing privacy woes over obvious benefits such as reach, popularity and influence.

MAIL TODAY spoke to a section of social media enthusiasts and celebrities to find out what data privacy means to them.
"Privacy as a concept is still new to Indians. It's relatively a rich man's problem," says Deepak Manohar, a 33-year-old advertising professional. "It has gained some prominence with Aadhaar. But if you tell people that their data can be accessed any time, most of them would say, 'so what?'".
With 240 million users on Facebook, 10 million on Twitter (Twitter too had admitted, recently that it sold data to the same Cambridge researcher who improperly harvested private information from Facebook profiles.) and around 40 million on Instagram, India has one of the largest user bases for social media in the world.
Actor Swara Bhasker while expressing concern over the data scandal said that she has been contemplating to quit social media for a long time.
"Data breach is shameful and very dangerous. This is also my problem with Aadhaar," she says adding that as users we are trusting entities with zero accountability with all manner of personal and precious information. But then what prevents her from quitting? The fact that it helps her connect with her audience, hear their opinions and build across-mediaa reach, identity and brand.
The popularity of social media has also spawned career options for many. Prajakta Koli, a 24-year-old YouTube sensation who makes short videos on everyday problems, says, "Social media is one of the best mediums to connect to your audience directly." Gurpreet Singh's firm One Digital Entertainment helps artiste build a strong digital presence. His clientele includes the likes of rapper Badshah and singer Armaan Malik. Singh says some of his clients have sought advice about the safety of personal data after the Facebook scandal.
"But nobody has said they want to quit social media completely for these reasons."
Interestingly, even people who have abstained from social media, say that privacy concerns are not going to be a deterrent if they decide to get back on social networking sites. Indian's by nature, voluntarily give away so much information online, says 25-year-old Aishwarya, a tax consultant in Delhi who decided to quit social media several years ago after realising that it is a waste of time. "I am quite happy now," she says.

To compound things, India doesn't have a strong cyber security law. A committee has now been set up under former Supreme Court Justice BN Srikrishna to recommend a framework on data privacy laws.


Thursday, May 10, 2018

13499 - Worrying gaps - Telegraph India

May 09, 2018 00:00 IST

Data leaks and security breaches have become a part of 21st-century life. However, how organizations — especially the government — react to such events is important in assuring the citizen that this is something not to be condoned and something that must be made more infrequent through greater security. Taking away personal data (for whatever purpose) without the consent or knowledge of the individual is as good as property theft — both are violations of rights and constitute an act of coercion. The theft of information can be humiliating for the person whose data has been stolen. Personal data can be of various kinds and misuse could lead to substantial losses for the owner. This is often not realized.

In India too, data breaches are becoming more common. The reactions of the people who fail to prevent the breach and those of the government and the experts who know how certain security lapses lead to breaches can, at times, be shocking. Some time back, the government of Andhra Pradesh put up on its website the Aadhaar details of a large number of citizens. When the lapse was pointed out, the government hastily removed some of the details, but claimed that it was done to provide transparency regarding beneficiaries of certain publicly-funded projects. The more recent news about the Employees Provident Fund Organisation data breach is even scarier. 
Financial details could be widely misused. The government has chosen to remain silent, as have civil service experts. Transparency is not the opposite of privacy. Achieving transparency by the coercive violation of privacy is patently wrong. Silence on the part of the government can only be seen as a gradual and systematic blurring of the lines separating the private and the public spheres. This is an ominous sign; it portends greater control and manipulation on the part of agencies and institutions of the lives of ordinary citizens. Unlike in India, the Equifax data breach — it had taken place in the United States of America last year — had led to a quick apology and beefed-up security.



Friday, May 4, 2018

13450 - Bill Gates endorses Aadhaar scheme; says it doesn't pose privacy issues - Business Today


New Delhi     
Last Updated: May 3, 2018  | 16:52 IST

Aadhaar has been a boiling issue in India for the past few months. Data theft cases for as little as Rs 500, fake software to create Aadhaar cards, and alleged 'loopholes' in the unique identity scheme have left a dent on its credibility. It has been facing increased scrutiny over privacy concerns following several instances of breaches and misuse. Despite all this, Aadhaar as a scheme has been appreciated by many prominent people all over the world. Bill Gates, founder of one of the world's biggest tech companies, Microsoft, has been a staunch supporter of the Aadhaar scheme since the very beginning of its rollout. This time, he has again come out openly saying the Aadhaar technology does not pose any privacy issue. Not only that, he also appreciated Prime Minister Narendra Modi for fully "embracing" the scheme, which was initiated during the previous UPA regime.

The founder of Bill and Melinda Gates Foundation told PTI his organisation has funded the World Bank to "emulate" the project as it is worth doing so. Bill and Melinda want other countries to also adopt the scheme. "The bio-ID verification programme has multiple benefits," says Bill. To undertake this level of project in other countries, the World Bank and the Gates Foundation have reportedly roped in multi-billionaire Nandan Nilekani. The Infosys founder, who is also considered as the chief architect of Aadhaar, will consult and help the World Bank carry out the 'Aadhaar-like' project in other countries.
After the successful implantation of the Aadhaar scheme in India, other countries have also approached New Delhi for assistance in creating similar data base.

Appreciating India for successfully implementing the scheme, Gates said India's Aadhaar technology could be implemented across the world. Bill Gates thinks the Aadhaar-like scheme could help improve governance, which is directly linked to economic growth and the overall improvement in society.
"The benefits of that (basic ID -- Aadhaar) are very high. Yes, countries should adopt that approach because the quality of governance has a lot to do with how quickly countries are able to grow their economy and empower their people. Aadhaar in itself doesn't pose any privacy issue because it's just a bio ID verification scheme," said Gates.

One of the world's richest men, Bill Gates, also tried to sooth fears around the Aadhaar data misuse, saying individual application users need to properly check who can see information. He also defended financial institutions seeking Aadhaar details for opening an account. "Application by application, you have to make sure that's well-managed. In the case of the financial bank account, I think it's handled very well. (It uses) Aadhar to set up the accounts so that you can both get your cell phone and get your bank account," he said, reported the agency.

He said some of the initiatives carried out by the Narendra Modi government on digitisation could help improve the level of education in the country, and hence, the governance. Before this in 2016, Gates had said the Aadhaar is a scheme "never been done by any government before, not even in a rich country". The UIDAI's ambitious Aadhaar project is the world's largest biometric database with whopping 111 crore people of the total 125 crore Indians already connected with the identity scheme.


Thursday, May 3, 2018

13446 - EPFO discontinues services with Aadhaar seeding portal amid reports of data theft


PTI | Updated: May 2, 2018, 20:51 IST

HIGHLIGHTS
  • The reports were based on a letter by EPFO Central Provident Fund Commissioner V P Joy to CEO of CSC, Dinesh Tyagi
  • It said the report is related to the services through CSC and not about EPFO software or data centre

NEW DELHI: Retirement fund body EPFO on Wednesday said it has discontinued services provided through Common Service Centre "pending vulnerability checks" and ruled out any leakage of subscribers' data from a government website. 

EPFO's statement comes against the backdrop of reports suggesting theft of data of subscribers by hackers from 'aadhaar.epfoservices.com', a website operated by Common Service Centre (CSC) that comes under the Ministry of Electronics and IT. 

The reports were based on a letter by EPFO Central Provident Fund Commissioner V P Joy to CEO of CSC, Dinesh Tyagi. 

"Warnings regarding vulnerabilities in data or software is a routine administrative process based on which the services which were rendered through CSC have been discontinued from March 22, 2018," said an EPFO statement issued after the report went viral. 

It said the report is related to the services through CSC and not about EPFO software or data centre. 

"No confirmed data leakage has been established or observed so far. As part of the data security and protection, EPFO has taken advance action by closing the server and host service through CSC pending vulnerability checks," EPFO said.

It said there is nothing to be concerned about and EPFO has been taking all necessary measures to ensure that no data leakage takes place and will continue to be vigilant about it in the future. 

TOP COMMENT
there is total chaos in digital India .... Govt has no clue what is going on... always in denial.... and putting millions of Indian at risk....
Speak sense

The retirement fund body has been seeding Aadhaar with Universal Account (PF)Numbers of its subscribers to improve delivery of services. It has planned to go paperless by August this year. Thus, all its services would be provided online also.

When contacted, a senior IT ministry official said that as a vulnerability has been pointed out, the ministry will take action to plug the gaps, in case they exist.

"We will have it looked at. A vulnerability has been pointed out, and so we will (undertake) the exercise to plug the vulnerability, if it is there," said the official who did not wish to be named.


13445 - Millions of Indians’ financial information may have been stolen from an Aadhaar-linking site - Quartz

ANOTHER BREACH

Written by
May 02, 2018 Quartz india

A data breach at the Employees’ Provident Fund Organisation (EPFO), a retirement fund for salaried workers, may have exposed the personal information of millions of Indians.
On May 01, a letter from the central provident fund commissioner, V P Joy, to Dinesh Tyagi, the CEO of the government’s Common Services Centre (CSC), which provides digital services, was leaked on Twitter. Dated March 23, the letter said that the Intelligence Bureau had found that data had been “stolen by hackers exploiting the vulnerabilities prevailing in the website (aadhaar.epfoservices.com) of the EPFO.”
On the website, hosted at the National Data Centre but managed by the CSC, individuals could link their provident funds with Aadhaar, India’s biometric identity programme. While not mandatory, the EPFO had been encouraging subscribers to link their accounts with Aadhaar to improve the delivery of services.

Joy reportedly stated in the letter that the EPFO had stopped the servers of the site and discontinued its hosted services, and urged Tyagi to plug the security gaps. The website maintained confidential information such as Aadhaar and PAN numbers (taxpayer identification codes), as well as salary details.
It’s not clear how many Indians may have been affected but the EPFO has reportedly linked 34.5 million active provident fund accounts with Aadhaar. No one has claimed responsibility for the hack as yet. The Unique Identification Authority of India, which is responsible for the Aadhaar platform, has clarified that the affected website does not belong to it, and that no data breach has occured at its end.

On May 02, the EPFO released a statement saying “no confirmed data leakage has been established or observed so far.” A senior official told The Times of India newspaper that the data was completely secure and there was no need to panic.
@PIB_India An important Press Release from EPFO on certain falsehood being circulated in the Social Media platform about vulnerabilities in the EPFO data. pic.twitter.com/Hel91CW2f6
— EPF INDIA (@socialepfo) May 2, 2018
Nevertheless, a series of reported data breaches has raised concerns about the safety of personal information in the hands of the Indian government. In the period between April 2017 and January 2018 alone, 114 government portals were hacked, according to data provided to parliament by the minister of state for electronics and IT.

Over the past year, the authorities and private companies have stepped up efforts to get more and more Indians to link their Aadhaar numbers with everything from bank accounts to mutual funds to mobile phone services. This, despite several embarrassing breaches that have reportedly revealed the personal information of hundreds of thousands of people. In one instance, the private data of a billion Indians were reportedly offered for sale for as little as Rs500 (less than $8). The government has, however, denied that any such leaks have taken place.


India’s supreme court is hearing petitions against the forced linking of the controversial biometric programme with other services, but millions of Indians may have already lost control of their private information.

13427 - UPDATED: Security Sources Confirm Data Loss In Hack On EPFO Aadhaar Seeding Platform - Huffington Post



Security loophole open for "few weeks".

BLOOMBERG VIA GETTY IMAGES

Government sources have confirmed that a vulnerability in a government-run website meant to assist employees link their provident fund accounts with their Aadhaar numbers was targeted by hackers who made off with an unknown amount of sensitive personal data.

The website, the source said, was leaking data for "a few weeks" before it was detected and taken offline. Authorities are still trying to ascertain the nature, and quantity, of the data obtained by the hackers.

The data breach came to light earlier today, when a secret note, sent by Employee Provident Fund Organisation (EPFO)'s Chief Provident Fund Commissioner V.P. Joy, surfaced on Twitter.



EPFO data stolen by hackers exploiting the vulnerabilities prevailing in the website (http://aadhaar.epfoservices.com ) : VP Joy, Central Provident Fund Commissioner to MeitY.
Aadhaar case in SC at the last stage, how will the Govt defend this now ?


The note, marked "Secret" and dated 23 March 2018, was a rare instance of an attack on a vulnerable state data cache becoming public knowledge. The vulnerability was detected in the Aadhaar-seeding platform provided by the Common Services Centre (CSC) E-governance Services Ltd, a special purpose vehicle of MEITY.

EPFO is just one of many government departments that use this platform for Aadhaar-seeding various services. In February this year, the Unique Identification Authority of India (UIDAI) terminated its relationship with CSC, citing corruption and violations in the aadhaar-enrollment centres run by the company.

This security breach is the latest illustration of the vulnerabilities of India's ambitious e-governance push and, security analysts say, highlights the risks of the central government push to seed citizen aadhaar numbers in multiple state-maintained databases.

"It has been intimated that data has been stolen by hackers by exploiting the vulnerabilities prevailing in the website (aadhaar.epfoservices.com) of EPFO," the March 23 letter said, adding that the attack had been first spotted by the Intelligence Bureau.


SCREEN SHOT OF EPFO LETTER
An excerpt of a secret letter dated 23 March 2018 revealing details of a security breach in an Aadhaar-seeding portal maintained by the Ministry of Electronics and Information Technology

The website was since been taken down soon after the letter was sent, and is yet to come back online.
V.P. Joy, the Central Provident Fund Commissioner of the EPFO and author of the note, confirmed the authenticity of the letter in a phone call with HuffPost, but played down its significance.
"I am not aware of any data leak," Joy said. "We received a warning from the IB on March 22, and so I forwarded it to the relevant authorities the next day. This is a routine administrative matter."

A press release issued by his office, this afternoon, echoed Joy's comments, but seemingly contradicted his March 23 note. "No confirmed data leakage has been established or observed so far," the press release stated.

That the breach occurred from a portal seeding Aadhaar numbers with EPFO UAN numbers, suggests that the hackers are likely to have harvested some Aadhaar numbers. Thus far, the EPFO has linked 34.5 million out of a total of 47.1 million active provident fund accounts with Aadhaar according to news reports.But Joy was at pains to clarify that information about EPFO-Aadhaar linked accounts was maintained on a separate server, which was not compromised.

HuffPost has written to Dinesh Tyagi, CEO of the state-run Common Services Centre, and will update this copy with his comments once he replies.

Known Vulnerability
The March 23 2018 refers to two specific vulnerabilities: "Strut vulnerabilities" and "Backdoor Shells."
While "backdoor shells" refer to the possibility of hackers gaining control of a portal's administrator privileges, Struts refers to "Apache Struts", a widely used Java application with an established history of vulnerabilities, the best of known which is the 2017 Equifax data breach which exposed the personal details of 143 American citizens.

In April this year, the Minister of State for Electronics and Information Technology K.J. Alphons, told the Rajya Sabha that the UIDAI had audited Equifax in the aftermath of the data breach.

"It is a known vulnerability," said security researcher Srinivas Kodali. "Had UIDAI audited EPFIO like they audited Equifax, they would have found it."

A similar vulnerability was exploited by French security researcher Robert Baptiste to penetrate the Telangana MNRega website.

On Twitter, where the letter was first posted, security analyst Kiran Jonnalagadda, said it was likely that the vulnerability was spotted by hackers trawling the internet for sites running an insecure version of Struts.


Java Struts vulnerability. Likely caught up in a wide sweep of Struts-powered websites. The Aadhaar angle is incidental, but the leak of Aadhaar-linked data is almost certain. https://twitter.com/arvindgunasekar/status/991540003229454336 …

This story has been updated to reflect information passed on by government sources monitoring the data breach

Wednesday, May 2, 2018

13409 - 'Strengthen legal system to avoid data breach' - Indian Express


Panish Hangal, partner, Arka Advisory Services India, Bengaluru,  said our legal system must be further strengthened to tackle Aadhaar database leak.

Published: 30th April 2018 06:23 AM  
By Express News Service

KOCHI:Panish Hangal, partner, Arka Advisory Services India, Bengaluru,  said our legal system must be further strengthened to tackle Aadhaar database leak. Speaking at a seminar on  ‘Cyber Security for Business Resilience’ organized by Indo- American Chamber of Commerce here, he pointed out that in US and European countries, the legal system is so stringent that huge penalty has to be paid for a data breach.

“As the Facebook authorities didn’t give us any undertaking on the privacy of data, we are not in a position to go for legal remedy against the company for data breach”, Panish said, in a reply to a question.

In today’s scenario, data breach is the biggest threat a business can face. 

How one can protect his business from this risk? Many business owners feel that their company is too small to be at risk.  Figures revealed by Symantec show that over 43% of cyber attacks in the recent past were targeted towards small businesses. This shows why cyber security is all the more critical to small and medium-sized business than larger ones, who may have the resources to constantly upgrade their security systems from time to time.

Cyber security is not just about technology and computers. It involves people, information systems, processes, culture and physical surroundings as well as technology. It aims to create a secure environment where businesses can remain resilient in the event of a cyber breach. Email ‘phishing’ attacks regarding payment requests have impacted numerous clients in recent months resulting in millions of dollars of financial fraud. Laptops, desktops and handheld devices are being hacked using malicious software resulting in exfiltration of sensitive and confidential corporate documents.


Again disgruntled former employees are sabotaging information systems impacting the company’s business operations. Information Security Management System (ISMS) implementation leading to ISO 27000:2013 certification can help organisation’s with a structured approach for achieving or maintaining their objective, adds Panish Hangal.Indo- American Chamber of Commerce Kerala Chapter chairman  P  Ravindranath welcomed the gathering and Sujatha Sunil offered a vote of thanks.

Thursday, December 7, 2017

12469 - Spooked by data breaches, majority scared to use Aadhaar accounts to access digital wallet - Times Now

Spooked by data breaches, majority scared to use Aadhaar accounts to access digital wallet

Dec 05, 2017, 12:30 PM ISTSource : ANI
In the wake of recent reports on Aadhaar data breach by various sources, results from a survey revealed that a majority of the respondents were uncomfortable in using their Aadhaar accounts to access e-commerce accounts or digital wallets.
In the recent past, the government has laid a lot of emphasis on consumers to link their Aadhaar with all important documents like PAN, bank account, mobile number, insurance policies and so on. There have also been reports that some ecommerce sites have been asking consumers to link their website accounts with Aadhaar when they are trying to track a lost package. Many other internet-based businesses like payment wallets have also mandated Aadhaar for the consumers to avail their services.
Internet-based companies like AirBnb, Uber and Ola have also been asking the user to upload a copy of their Aadhaar while registering on the site as a safety measure, so that their true identity could be ascertained.
In this regard, a survey was conducted by LocalCircles on around 20,000 people, broadly on the subject of using Aadhaar details on the aforementioned platforms.
The first poll asked if the citizens would feel comfortable in linking their Aadhaar with their e-commerce site accounts. 61 percent said they would not be comfortable while 30 percent said they were fine with it.
When asked if they would be comfortable in linking Aadhaar with their payment wallet accounts, 49 percent refused, while 33 percent agreed, and 18 percent were neutral.
A related poll asked citizens if there should be a financial penalty for banks, telecom providers or any other organisations that compromise their Aadhaar, bank or call/data transaction details, to which 94 percent replied in an affirmative. They said that in case of data leakage, the respective bank or telecom operator should be severely penalised to ensure that they keep the data security measure to the optimum levels.
Recently, the Unique Identification Authority of India (UIDAI) while responding to some media reports which alleged that "210 Government sites made Aadhaar info public" assured that the Aadhaar data was fully safe and secure, and there has never been a breach or data leak at the UIDAI.
The UIDAI in a notification said the data on these mentioned websites was placed in a public domain as a measure of proactive disclosure under Right to Information (RTI) Act by government and institutional websites, which included the beneficiaries' name, address, bank account, and other details, which also included the Aadhaar number and were collected from the third party/users for various welfare schemes.
Meanwhile, LocalCircles is submitting this report to UIDAI and other stake holders, so that appropriate action could be taken, and cases of data leakage could be minimised.

Friday, August 25, 2017

11852 - Right to Privacy: Here's a Look at Four Major Data Breaches Since 2016 - News18

According to the 2015 Breach Level Index report by Gemalto, India had 20 data breaches in 2015 that resulted in 32.1 million records being exposed.
Updated:August 24, 2017, 10:05 AM IST


There have been several cases of data breaches in the last few cases. 

New Delhi: The threat of data breaches, where personal information of millions of internet users has been exposed, is real and there have been several instances over the last two years. According to the 2015 Breach Level Index report by Gemalto, India had 20 data breaches in 2015 that resulted in 32.1 million records being exposed. News18 looks at four major cases of data breaches over the last two years.

Indian Railways 

In May 2016, it was reported that the ticket-booking website of Indian Railways had been hacked and personal data of around 10 million customers was feared to have been stolen from the servers of the e-ticketing portal. It was reported that IRCTC officials also feared that personal details including phone numbers, date of birth and other such details of its customers had been sold on a CD for Rs 15,000. The Indian Railways Catering and Tourism Corporation (IRCTC) denied that their website had been hacked, and claimed that they had not received any indication that a data breach had taken place.

Aadhaar
In March this year, the government had confirmed that Aadhaar number and other sensitive information linked to the document were leaked to the public domain. The Centre for Internet and Society in May said information of as many 1.3 crore Aadhaar holders was leaked to websites, a claim denied by Aadhaar-issuing authority UIDAI. In July, around 210 websites of the central and state government departments were reported to have displayed personal details and Aadhaar numbers of many beneficiaries. The UIDAI removed the details and the government said the leak was not caused due to a breach of its servers. 

Hitachi Payment Services
In October 2016, malware reportedly introduced in systems of Hitachi Payment Services enabled criminals to steal financial information of customers of a number of banking institutions including Visa, MasterCard, ICICI Bank, Axis Bank and YES Bank. As many as 3.2 million cards were compromised as a result of the breach.

Zomato

In May 2017, a hacker reportedly stole email addresses and password details for 17 millon users of an Indian food delivery app, Zomato. In a statement, Zomato confirmed that no financial information was reportedly compromised.