4 ms·
Something related: it doesn't inspire confidence when the person who runs UIDAI (the government organization running the fingerprint program) says this: https:
by middleclick 9y ago
Something related: it doesn't inspire confidence when the person who runs UIDAI (the government organization running the fingerprint program) says this:
https://www.ndtv.com/india-news/aadhaar-data-safe-behind-5-inch-thick-15-feet-high-walls-centre-to-supreme-court-1826931 https://www.ndtv.com/india-news/aadhaar-data-safe-behind-5-i...
> Aadhaar Data Safe Behind 5 Feet Thick Walls: Centre to Supreme Court
This just shows how poor the understanding of digital security is...
- shripadk 9y agoThat's a biased article and is taking things out of context. A better understanding would be found at the UIDAI page itself: https://uidai.gov.in/component/fsf/?view=faq&catid=27 https://uidai.gov.in/component/fsf/?view=faq&catid=27 To their credit, the leaks that have happened until now haven't happened directly from UIDAI database but by partners who had poorly designed API endpoints which exposed citizen identity data. At the very least, biometric data has never been leaked/hacked into till date. The "5 feet thick walls" reference might be to the vault that is actually housing the biometric dataset which they mention in the above official page as well: "The UID database will be guarded both physically and electronically by a few select individuals with high clearance. It will not be available even for many members of the UID staff and will be secured with the best encryption, and in a highly secure data vault. All access details will be properly logged."
- captn3m0 9y agoAs a security researcher in india, Aadhaar is riddled with Security holes that are glaring. There is clear way to report these issues and nothing gets fixed. I've had a possible-RCE vulnerability reported to UIDAI since February-2017 and there has been no action. The CERT-IN (Indian equivalent of CERT-US) has been aware of the issue, but there is no fix in sight. The easiest to do exploits (fingerprint cloning) are already happening: https://www.medianama.com/2018/03/223-cloned-thumb-prints-used-to-spoof-biometrics-and-allow-proxies-to-answer-online-rajasthan-police-exam/ https://www.medianama.com/2018/03/223-cloned-thumb-prints-us...
- shripadk 9y agoNow that is news to me. I know UIDAI has handled the recent data leak from one of its partners horribly (even lodging an FIR against a news reporter). However, does the vulnerability you mention provide access to biometric data? For me personally, that is more of a concern than the metadata (name, address etc).
- captn3m0 9y agoIt is on a UIDAI-hosted system that has access to the CIDR, so it is possible.