11 ms·
India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm
- febin 8y agoUnfortunately our government doesn't accept the truth. If someone tries to educate people about the vulnerability, they are labelled anti-national.
- abhiminator 8y agoIronic, considering the fact that protecting the privacy of citizens is in a nation's interest.
- FroshKiller 8y agoI need you to show your work on that one, guy.
- known 8y agoGovt should recover $1 Billion from Nilekani
- iamshs 8y agoAbsolutely. That man should be behind bars for designing this atrocious system.
- lovelearning 8y agoThe current government possesses a type of thinking that considers reporting an embarrassing problem a bigger crime than those responsible for that problem.
- eklavya 8y agoI wonder if there is a way to detect/assess fraudulent entries or will this require massive re-enrolement. Total shitstorm, WTF!!!!
- allpratik 8y agoHe definitely has a very arrogant tone about aadhaar as well as his another body shop company. This massive massive data leak could cost Indian citizens very dearly. Everything is being forced to link with aadhaar. If some digital lord in future decides to colonize people in few secs, I believe Indian shores and as well as people sitting in capital might provide a very lucrative proposition! I just hope it isn't Jio! Jio phone itself has very intrusive OS!
- rohan1024 8y ago> In 2017, the UIDAI said it had blacklisted 49,000 enrolment centres for various violations, and in February 2018, the UIDAI terminated all contracts with common service centres as well. Seems like they are well aware of this hack. Skimming through the article, it seems the attacker can register himself in the system but not read data from the system. Also, there's no mention of 1.2B records being compromised.
- bhanu423 8y agoActually, the records are already public, remember the fiasco where Telecom Regulatory Authority of India’s Chairman RS Sharma had posted his Aadhar number online. The whole point of the Aadhar Challenge was to demonstrate leaked database/Aadhar number is not an issue. Apart from the curated datasets that can be bought even on Facebook groups, it is actually very easy to mine large datasets from Google itself.
- walterbell 8y agoAny references on this topic?
- bhanu423 8y agoI don't want to post any direct link to anything but you are google 'Aadhaar data leak through Google search' to vast amounts of links/references. Kinda Meta right, I know. If you want to know more about the incident you can google 'aadhaar challenge'.
- blazespin 8y ago¯\_(ツ)_/¯ I wish I could express some kind of outrage, really, I do. This should be awful and undermines what I believe a sincere attempt to make India a better place. But really, what could they or anyone possibly expect?
- lifeisstillgood 8y agoIf I get it: India has a biometric database with 1B people on it! ... wow ... just wow ... And adding new people to it is now compromised by a publically available hack, although getting 1B biometrics on board must have had an error rate that would be scary anyway. The UUID created is needed almost everywhere, like driving license numbers elsewhere. How much of the scare is "People can be added once but under incorrect names" perhaps wiping out criminal pasts? or "people can be added more than once" The second is surely a search problem?
- mtgx 8y agoGood luck to the government changing everyone's biometrics now. This is why biometrics should never be used for something like this, especially when it requires a centralized entity to store all the biometric data, making it a very appealing target to all the malicious hackers in the world. At least Apple, etc, keep the a hash of the biometric data in a secure enclave on each device. Storing biometric data in a centralized database is beyond reckless, no matter who does it.
- Freak_NL 8y agoThey don't use UUID do they? Just a 12-digit UID.
- lmcm82 8y agoMaybe I'm in the wrong here, but I imagine most civilised countries have a database with biometrics of all of its citizens, at least fingerprints.
- snaky 8y agoAnd not only of its citizens. https://en.wikipedia.org/wiki/Biometric_passport https://en.wikipedia.org/wiki/Biometric_passport
- captn3m0 8y agoNot a lot: https://en.wikipedia.org/wiki/Countries_applying_biometrics https://en.wikipedia.org/wiki/Countries_applying_biometrics There are restrictions on how vast this database is allowed to be and what all it can be linked to, in most cases.
- elyobo 8y agoUndeniably bad, but I'm fighting off a slight sense of schadenfreude here, due to their prior claims[1]. [1] https://www.troyhunt.com/is-indias-aadhaar-system-really-hack-proof-assessing-a-publicly-observable-security-posture/ https://www.troyhunt.com/is-indias-aadhaar-system-really-hac...
- zik 8y agoYes it looks like their security was really amateur hour stuff too, with a lot of the authentication done on the client side. This makes their claims that it was "hack-proof" look particularly embarrassing.
- bufferoverflow 8y agoIs this complete incompetence? Why wouldn't they generate these numbers on some centralized secured servers only for the verified individuals? Why give away the software that generates them at all? That's like giving away your signing servers.
- arachnids 8y agoThat is answered in the article > B. Regunath, a software architect who led the team at Mindtree that worked on the project, said a web-based enrolment software for Aadhaar was not practical at the time because many parts of the country had very poor Internet connectivity. Of course, anyone who put id generating software on these laptops with the expectation that it would somehow remain secret was being extremely foolish. The system should have been designed taking that into account.
- bufferoverflow 8y agoEven then, they could have batched the requests for IDs on the laptop, and then submitted them daily/weekly by driving the laptop to wherever the internet is. And of course, each such laptop must have a unique hardware key that would sign these requests, so copying the software wouldn't compromise anything.
- cm2187 8y agoIn a country of the scale of India, if your security relies on no laptop being compromised, you have no security. One is bound to be lost or stolen (or its user to accept bribes).
- bufferoverflow 8y agoYou didn't read my comment well. The security in my scenario doesn't rely on the laptop not being stolen. There's a hardware key. If it gets stolen, it gets blacklisted.
- 8y ago
- walterbell 8y agoApparently the breach is now being proxied by the fired private operators through government offices. Can this cashless money flow be traced? Even burner mobile phone numbers are linked to the same compromised national identity database. Who could benefit indirectly from the breach? Could the Indian government turn to Facebook and WhatsApp for help with identity profiling? Is Facebook Indian data held in Indian data centers? This story will find its way into future documentaries on the history of "Papers Please". > in February 2018, the UIDAI terminated all contracts with common service centres as well .. Henceforth, only banks and government institutions like the postal service can enrol Aadhaar users. As a consequence, tens of thousands of young men, with rudimentary education but great familiarity with the Aadhaar system, were put out of work. > In interviews, out-of-work operators claim they can still use the hacked enrolment software to generate enrolment ids (the first step in the Aadhaar registration process) and have tied up with sources working in authorised centres who complete the registration process for a fee. > ... creates a whole new set of problems and could defeat many of Aadhaar's purported aims, such as reducing corruption, tracking black money, eliminating fraud and identity theft. It also means that the Aadhaar database is vulnerable to the same problems of ghost entries as any other government database > the Indian government has sought to make Aadhaar numbers the gold standard for citizen identification, and mandatory for everything from using a mobile phone to accessing a bank account. > Sourcing the patch is as easy as gaining access to one of thousands of WhatsApp groups where the patch, and the usernames and passwords required to login to the UIDAI's enrolment gateway, are sold for as little as Rs 2,500. Payments are made through mobile wallets linked to phone numbers that quickly go dead after the transactions are complete.
- wiz21c 8y ago>>> Who could benefit indirectly from the breach? This and who will buy those data ? Everybody scream about the hack but I've never found a comprehensive study over how these personal data are sold, abused. Maybe to break gazillions of FaceBook/github/you-name-it accounts ? Then what, who will use those data ? Thieves ? Criminals ? If it's just that well, that's a minor inconvenience. If it's secret services of adversary powers, well, that's a whole lot different. Anybody has facts on that ?
- deafcalculus 8y agoThe biometric scanners probably have big security holes too. In fact, it won't surprise me if the JTAG is left enabled and anyone can read/write the firmware! Aadhaar needs something like TrustRank or a Web Of Trust where identity and citizenship isn't binary but a continuous number (probability) based on who and how many vouch for your identity. A lot of citizens, especially in rural areas, aren't documented very well. It's best to acknowledge that uncertainty in the system and deal with it. The public discussion around Aadhaar is very confused. There's hardly anything wrong with a universal ID for every citizen. There are already several in India (Driving License, Passport, Voter's ID, PAN card, etc.). The real privacy issue is around (a) the govt. collecting biometric data, and (b) how much the govt. / third-party service provider learns about you when you authenticate your identity using Aadhaar. The UIDAI doesn't even want to discuss the issue in the open ("trust us, your data is secure. No proof of hacking whatsoever."), and the use of non-open-source software and closed biometric hardware is troubling. If biometric scanners are using proper encryption, who holds the keys? (My guess, the manufacturers have it, and lots of people who shouldn't have it do have it). What's needed is consensus building, maybe through a public consultation, about what the majority of people are willing to disclose to the govt. Biometric isn't an absolute necessity for Aadhaar to achieve it's stated goals. That said, recent polls show that the percentage of Indians who trust their govt. is way higher than in the west, so the govt. can probably get what it wants while playing nice. There's also very little discussion about how secure the biometrics are. There's no info about what services are considered sensitive and need more than a fingerprint. Fingerprints maybe fine for 5 years, but I have a hard time believing they'll be constant enough for secure identity verification over 80 years. What happens when biometric fails and a significant chunk of the populace can't sign, don't remember their date-of-birth or any password, or even their full name? Again, something like a web of trust would've been helpful.
- vishaltelangre 8y agoIt is hard to believe by relying on just one source. I just checked other news sources in India, and no one has any news about any recent Aadhaar breach.
- ahamedirshad123 8y agoDo You think Times group, India Today and others will report this? They don't have backbone to do that. Maybe You should read the article first, before commenting.
- vishaltelangre 8y agoAnd why do you think exactly that they or any other news agency won't report if such an incidence has occurred?
- talonx 8y agoNot related to the topic under discussion, but see the media blackout during the Radia Tapes Controversy[1] [1]https://en.wikipedia.org/wiki/Radia_tapes_controversy#Media_blackout_and_reactions_in_social_media https://en.wikipedia.org/wiki/Radia_tapes_controversy#Media_...
- bhanu423 8y agoKindly understand this article seems to come out of investigative journalism where the author seemed to have gotten hold of the patch presumably by paying 2500 and then did in-person research to create the article. Once published, other newsrooms usually do their own pieces if they find it relevant. Since this article has just been published (only 2 hours ago at the time of writing this comment), I wouldn't refute the article just on the basis of this criteria. I would usually wait for 1-2 days before using the above criterion to evaluate the article.
- vishaltelangre 8y agoYou've actually reworded what I have already said. Since there is no official statement from UIDAI or multiple private news sources reporting the same incidence; this article/blog is not worth believing yet.
- person_of_color 8y agoSad face :(
- amrrs 8y agoTime and Time again Aadhar's privacy data have been compromised and Yet, Officials have strongly denied all those claims - only possible because still people believe all the false claims by those officials and government in terms of Aadhar. Even to the level that a guy once wrote a scraper (opensourced on github) that can fetch Aadhar info online. It's no doubt that Aadhar was a blatant copy of bringing an SSN-type ID in India but failed terribly as the Government was more interested using Aadhar to show their domination rather than put it for actual purpose. Eg: Govt made Aadhar mandatory for Tax filing, India's Top Supreme Court denied. The same thing happened in many instances. This is a nice lesson, why simply coping a solution from the US can't be made to work in a developing nation because the system and officials are so fragile that they need to be first fixed than the solution itself!
- signal11 8y agoAadhar is nothing like SSN. I wish it was. SSN doesn’t require biometrics — Aadhar takes fingerprints and iris scans. School kids don’t need SSNs to sit for their school boards. You can sit for university exams without SSNs. You can shop at Amazon without giving them your SSN[1]. [1] https://news.ycombinator.com/item?id=15796242 https://news.ycombinator.com/item?id=15796242 In fact SSN use has become more restricted over time, thanks to various pieces of privacy legislation. Meanwhile in India they still don’t have any privacy legislation last I checked, so it’s open season on your data. Aadhar is ambitious all right — an attempt to assign every every Indian resident a number and use that number as a unique key for almost everything (public or private). The surveillance opportunities this presents is breathtaking. Of course the good folk at India Stack love this because it enables them to build better apps. Move fast and break things, indeed.
- n_t 8y agowatch this (https://www.youtube.com/watch?v=Erp8IAUouus https://www.youtube.com/watch?v=Erp8IAUouus) and tell me if SSN is good for even US?
- amf12 8y ago> Time and Time again Aadhar's privacy data have been compromised. I hate the implementation of Aadhar as much as any person, and believe the architecture is terrible that a patch can allow authentication to be bypassed. And that there could be more vulnerabilities. However, at least in this instance, existing data has not been compromised.
- leni536 8y agoOff topic: I simply can't find how to opt out of tracking on HuffPost. I get a GDPR popup and the opting out path leads endless cycles (with occasional captcha solving).
- vishaltelangre 8y agoSounds like a scam to me.
- netsharc 8y agoI just keep using browser extensions like uBlock and Ghostery (caveat: it seems they also have a "we sell your data" opt-out) and every GDPR pop-up I just click "OK", knowing the extensions will block them. (Honestly, more believing than knowing, so maybe I'm not the best person to talk to about protecting data...)
- eqtn 8y agoHuffPost works without javascript. Use Quick Javascript Switcher or similar extension and disable js for the whole site.
- severine 8y agoWorks for me, don't know if my savior is uBlock Origin, uMatrix, or I Don't Care About Cookies... https://github.com/gorhill/uBlock https://github.com/gorhill/uBlock https://github.com/gorhill/uMatrix https://github.com/gorhill/uMatrix https://www.i-dont-care-about-cookies.eu/ https://www.i-dont-care-about-cookies.eu/
- jarym 8y agoWell if we needed one more datapoint on why government shouldn’t get involved in computer security then here we have it. Politicians don’t get technology - they believe they can order any design they can imagine and that it’ll just work. Secondly, I’ve worked with hundreds of Indian IT engineers. I’ve yet to meet one who didnt subscribe to the view that ‘the solution to all problems can be coded in software’ - maybe it’s just how they are educated at uni. However, put them next to politicians and you get a real recipe for disaster. So what next? Those who claimed they could make this system secure should pay a HEAVY price. There really isn’t a humane punishment strong enough - I’d go as far as firing them; stripping them of any retirement benefits and banning them from any paid position in the public sector.
- lovelearning 8y agoI have to admire the courage of the people who have investigated and reported this, given that the entire leadership of UIDAI and its backers in the central government are intolerant of any criticism and have been known to file police complaints[1] against journalists, critics and whistleblowers. Even its visionary and leading cheerleader from the private sector preferred to imagine conspiracies rather than acknowledging its weaknesses [2]. [1]: https://thewire.in/tech/uidai-files-fir-tribune-reporter-aadhaar-breach-story-report https://thewire.in/tech/uidai-files-fir-tribune-reporter-aad... [2]: https://timesofindia.indiatimes.com/india/theres-an-orchestrated-campaign-to-malign-aadhaar-nandan-nilekani/articleshow/62453569.cms https://timesofindia.indiatimes.com/india/theres-an-orchestr...
- throwaway_tvs1 8y agoThis can't be upvoted enough. The organization which outsources critical authentication to CIA-MI6 linked companies, and yet find the courage to indulge in the Orwellian-doublespeak of 'nationalism' is something that needs grave attention.
- deleted 8y ago[deleted]
- iamshs 8y agoThis is one of the main reasons that this report doesn’t touch upon read access of the database. Rachna Khaira, one of the reporters already has a police case against her for her previois reporting on Aadhar database compromise. Getting even one user record would have landed all three journalists behind bars. It is left for the reader to conclude, and validated by various experts, that whole database is hacked. If a $5 tool can give you write access to a database, it is obvious whole database can be accessed too.
- denzil_correa 8y agoBtw, 4 months ago the UIDAI had completely denied of existence of such a patch calling it as "totally baseless, false, misleading, and irresponsible" [0]. [0] https://twitter.com/UIDAI/status/991907169779011584 https://twitter.com/UIDAI/status/991907169779011584
- gammateam 8y agoits kind of weird that they call the vulnerability itself "a patch" I can be pedantic too and can see how there isn't really a distinction between an exploit and a patch as they both modify the software, but thats a weird colloquialism right?
- fellellor 8y agoIt sounds to me like a game crack which are basically patches since they make the software concerned more user friendly.
- sk_hazratali 8y agoGovernment have to improve security on public database. https://marketcapcoin.blogspot.com/2018/09/bitcoin-mutual-fund-launches-in-canada.html https://marketcapcoin.blogspot.com/2018/09/bitcoin-mutual-fu...
- DyslexicAtheist 8y agoIndian government site asking for aadhar data in Bihar: http://210.212.23.57/online/OnlineApply/Notice.aspx http://210.212.23.57/online/OnlineApply/Notice.aspx They just made aadhar mandatory for every school kid in Mumbai Maharashtra. Good luck to anyone who has to share share their childrens details on an insecure platform.
- amf12 8y ago> http://210.212.23.57/online/OnlineApply/Notice.aspx http://210.212.23.57/online/OnlineApply/Notice.aspx HTTP. FFS.
- pritambaral 8y agoIt's not like HTTPS would have helped much. It's an arbitrary IP address. How is a user supposed to verify an arbitrary IP address is not an attacker? This is what '.gov.in' is supposed to be for.
- eklavya 8y agoAccording to the article the database has not been compromised. It's a compromise of the client which can be used to add new Aadhar entries.
- fellellor 8y agoYeah, that means a lot of false data has been added into the system given how widely this patched client has been circulated. I don't know what about this tells you that the database hasn't been compromised?
- eklavya 8y agoThe first thing that came to my mind when I read the title was that all the biometrics and all were out. Which would have been much worse and which is not the case.
- fellellor 8y agoThis is equally bad, maybe even more so given there is a good chance that a substantial number of aadhaar accounts are fake. There is, quite simply, no reasonable defense for this state of affairs.
- Operyl 8y agoA compromise in this case being that illegitimate entries are being added when they should not be able to. You don’t need write to consider this specific case broken.
- Operyl 8y agoSorry, I meant to say "You don't need read to consider this specific case invalid." Didn't have my coffee yet!
- MrEldritch 8y agoThe database has also been compromised in the read direction. In fact, one of the authors of this article, Rachna Khaira, got in hot water with the police earlier this year for reporting on that breach. That's probably why this article doesn't mention it.
- eklavya 8y agoI don't know how many times this will have to be repeated. Aadhar, GST, all implemented by the worst possible companies in terms of talent. WTF is wrong here, there are plenty of talented people around. Or just crowdsource it or give it to the universities to build or something.
- black_puppydog 8y agoI want to say that maybe the really talented people / good companies have no interest in building a central database with such dystopian potential. But then again... fb, twitter, ...
- throwaway_tvs1 8y agoErm, Google, Microsoft, ... most of SV ?
- black_puppydog 8y agolike I said, I really want to say that. Sadly that wouldn't make it true...
- snaky 8y agoIs there any success story about crowdsource in India?
- kcsomisetty 8y agoI expected better discussion on HN (apart from sensationalist articles), the article does a poor job intentionally though. Summary 1. Existing data is not compromised 2. Duplicate data can't be entered or overwritten 3. BUT, ghost accounts can be created easily. Aadhar was introduced to fight ghost accounts who siphon off subsidies provided for poor. This hack/patch defeats that purpose. I still think this is not a big problem as it looks on surface, if Enrollment software is hacked to accept iris data from photograph, Can't the Aadhar DB (post enrollment) be scanned for all enrolled iris data with poor quality iris data and they be monitored and deleted ? Another problem is still there, what if the operators enroll citizens from a different country as indians, essentially creating ghost accounts (from citizens of different country). i dont know how to stop such a situation. Biometrics is never a good model for authentication, i dont know what these people were think when they designed it.
- iamshs 8y agoTwo points:- 1. Surprise, there's a separate $10 application which can access all the Aadhar database entries. Exposed by one of the journalists of this story, for which she got a police case filed against her. [a] 2. Aadhar has no way to verify double entries, one whistleblower to Supreme Court said the database has 40% bogus entries, i.e. 450 Million fake IDs. Yes, no verification backup documents, no signup forms exist for 40% entries in the database, and authority has no way to audit them. [b] a. https://www.tribuneindia.com/news/nation/rs-500-10-minutes-and-you-have-access-to-billion-aadhaar-details/523361.html https://www.tribuneindia.com/news/nation/rs-500-10-minutes-a... b. https://ia802809.us.archive.org/26/items/Aadhaar_Whistleblower_document_to_SC_Judges/40%20CRORE%20DUPLICATE%20AADHAAR%20CARD%20LETTER.pdf https://ia802809.us.archive.org/26/items/Aadhaar_Whistleblow... Bonus: Aadhar database was at one time hosted in US with FTP password being Admin$12. This is the state of this sham project. https://imgur.com/a/2sppFrm https://imgur.com/a/2sppFrm
- shripadk 8y ago> 1. Surprise, there's a separate $10 application which can access all the Aadhar database entries. Exposed by one of the journalists of this story. [a] Can the said journalist just release the application in public domain? If not, why not? > 2. Aadhar has no way to verify double entries, one whistleblower to Supreme Court said the database has 40% bogus entries, i.e. 450 Million fake IDs. Yes, no verification backup documents, no signup forms exist for 40% entries in the database, and authority has no way to audit them. [b] If authority has no way to audit them then how did the whistleblower arrive at this magical "40%" figure. What's worse than the 40% figure is the way the entire letter is written. No way a professional would write a letter with all caps, typographical errors, paragraphs upon paragraphs of sensationalism with little to show for "proof". Even the table which shows the details of "AadhaarCount v/s Aadhaar Records" is not something available in public domain so it cannot be validated as authentic. > Bonus: Aadhar database was at one time hosted in US with FTP password being Admin$12. This is the state of this sham project. https://imgur.com/a/2sppFrm https://imgur.com/a/2sppFrm I have seen this crop up in every discussion but no where in the screenshot does it say that the data hosted in US was the "Aadhaar database". All this screenshot details is some files were hosted by the UIDAI team on a US based server to share among themselves. The files could be anything. In fact, the email itself says the files are flat files with names: 1. Bill_Desk 2. Total_EXP How did you arrive at the fact that this is the Aadhaar database itself? I can easily assume that "Total_EXP" can mean total expenses and "Bill_Desk" to do something with bill desk. No where does it say "Aadhaar_DB" or something along those lines. This is laughable! Also, this same screenshot exists in the so called "whistleblower's letter" to Supreme Court judges as well. There is no confirmation of any such correspondence by the Supreme Court judges about being in receipt of any such letter. Sorry to say but the way the entire letter is written screams of fake news you typically forward through WhatsApp only to realise later that the entire story was fraudulent to begin with.
- Karupan 8y agoAs an Indian developer, I cringe every time the government claims a system is un-hackable. Especially when contracts are handed to one of the big Indian IT companies. Having started my career in one of those companies, I saw firsthand how most of the development process was just filling in gaps. Security through obscurity was thought to be “highly secure” and security experts were non existent. No surprises that the database was compromised. Aadhar is a fundamentally flawed system and nothing will ever be done about it.
- LeonM 8y agoThis happens in every country, not just India. And the database has not been compromised.
- andyjohnson0 8y ago> And the database has not been compromised. The database is not known to be compromised.
- DoofusOfDeath 8y ago> The database is not known to be compromised. The database is not known by the general public to be compromised.
- MrEldritch 8y agoThe database is known by the general public to be compromised. https://thewire.in/government/data-breach-aadhaar-details-grabs-just-rs-500 https://thewire.in/government/data-breach-aadhaar-details-gr... The reason this article didn't mention it is because one of the authors is still in hot water with the police for trying to report on it.
- kamaal 8y agoNo amount of 'security' will help here. That's because every one including the people don't give a dime about 'security' in India. In Aadhar enrollment centers, passwords are shared. You might like to introduce an OTP like concept, but phones are shared too. 2FA? nice try, but then people also share answers to security questions. Next what? DNA authentication? Biometrics? guess what none of those are any where near reliable and they are mostly identity related things and not authentication related things. There is also government policy. Which is lapse. Mostly run by civil servants who understand nothing about technology. IAS is largely a trivia testing exam with focus on things like meeting and group discussion skills. The head of UIDAI recently claimed that data could not have been possible stolen as the data was still in their database :) This is a phenomenal lapse at every level. Software is one thing, but if your people have decided to work around it, its basically all over.
- deleted 8y ago[deleted]
- n_t 8y agoOne of the reasons why India needs some kind of people authentication is rampant corruption! Corruption at a scale that most of people in Europe or US cant even imagine. Add to it the culture which celebrates corruption and eulogizes people who find loopholes in system. As soon as a policy or rule is implement, someone gets to work to find a loophole and profit. Schemes and subsidies for poor get siphoned by rich and powerful by creating fake people, less than 2% of citizen's pay taxes by just disappearing in records, billions of dollars of unnamed properties exist because owners are fake people on record, someone else appears for exam on a student. While I still dislike citizen's database, I can also see why some kind of person authenticator is needed for country like India. I sat through UIDAI architects presentations, and from what I could tell that substantial thought was given to design. So while I maintain skepticism for such database, I also believe India needs some way authenticate various transactions (monetary or otherwise). SSN is a joke, at least Aadhaar was given substantial thought.
- jace 8y agoYou seem to have sat through a presentation on Aadhaar. Have you sat through any presentations on corruption? On what basis are you making comparisons with other parts of the world?
- akudha 8y agosomeone gets to work to find a loophole and profit Please - this is pretty much how it works everywhere, nothing unique to India. Why do you think lawyers, accountants etc in the corporate world get paid so much? Do you remember the U.S president saying avoiding federal taxes makes him smart? the culture which celebrates corruption What are you basing this on? There is no question there is rampant corruption, but saying the culture celebrates it is taking it a bit far
- JumpCrisscross 8y ago> avoiding federal taxes makes him smart? I avoid taxes. I contribute to my IRA, donate to charities and deduct my home office space. What I don’t do is evade taxes by not declaring income.
- 8y ago
- inevitable2 8y agoHomepage of the Indian Army Careers page. http://joinindianarmy.nic.in/authentication.aspx http://joinindianarmy.nic.in/authentication.aspx Try double clicking that CAPTCHA. This same code for "CAPTCHA" is used in dozens of official government websites. None of this Aadhaar stuff is surprising.
- wtmt 8y ago[Note: I'm anti-Aadhaar, as documented in my profile. My comments below may sound harsh because of that. Also please note that Aadhaar is a resident number, and has nothing to do with citizenship.] Fantastic work! One of the authors of this investigative piece, Rachna Khaira, was key in exposing a major issue with the "last mile" software and how cheaply (just Rs.500/about USD 7) and easily someone could get the Aadhaar and demographic details of almost any resident in the country who's enrolled in the system. [1] UIDAI's response for her investigation was to file an FIR (First Information Report/police complaint) against her in an attempt to put her behind bars. [2] Activists have always argued that the lack of transparency and information could mean that there are many "ghosts" (or bogus enrollments) in the Aadhaar system (which claims that it cannot have "ghosts", ignoring technological as well as biometric limitations). Now there's no saying how many of the 1.1 billion entries in the Aadhaar system are bogus. As the article states, private agencies were used to handle the enrollment and capture of biometrics and recording of demographic information. All these agencies were paid on a per-enrollment basis. Guess what incentives they would have in a country with high levels of corruption at many levels? I'm certain that a bulk of the enrollments that have been issued Aadhaar numbers are bogus. While activists may feel vindicated that more and more holes are being exposed in the Aadhaar system (while UIDAI continues to always remain in denial mode), it's sad that hundreds of millions of people have been left vulnerable by this poorly designed and poorly implemented system. > B. Regunath, a software architect who led the team at Mindtree that worked on the project, said a web-based enrolment software for Aadhaar was not practical at the time because many parts of the country had very poor Internet connectivity. > "People were cranking up generators just to light up power and do the enrolment. How can they do an online upload of those packets?" asked Regunath, who has since moved to a senior technical position at Flipkart. What utter nonsense!!! I can't imagine someone calling themselves a software architect being so gullible and ignorant. The entire Aadhaar system is dependent on Internet access and connectivity. Post issuance, the authentication of anyone through biometrics needs real time Internet connectivity. There's no way around that (even where an OTP is generated, the initiation of the OTP sent over SMS by UIDAI has to happen by connecting to UIDAI's web based APIs). Even as recent as last year, people in some places were forced to climb trees because they couldn't get a good cellular signal and Internet connectivity. They were forced to do this because the central government pushed this system as a prerequisites for getting subsidized food (through what's called PDS or Public Distribution System). [3] UIDAI also had Windows XP as a recommended OS for these enrollment agencies. [4] > In 2017, the UIDAI said it had blacklisted 49,000 enrolment centres for various violations. The sheer hypocrisy and audacity of UIDAI here is that it has blacklisted all these agencies for violations without any legal action. From the time Aadhaar started in 2009/2010, this number averaged to about two agencies blacklisted every hour! But point out some security issue or a gap? You'll be facing a court case! _____ This whole system has been patchworks of patchworks of patchworks, continuously in denial mode when experts ask questions on security, audit, privacy, etc. I would prefer that it be completely thrown out, like how UK did with its national ID program several years ago. India doesn't need such enemies from within that/who make it easier for hostile entities/groups to disrupt or decimate the country! UIDAI needs to be shutdown as well, since nobody in-charge of the organization has shown technical or critical thinking ability, or has had the humility to face questions without getting into continuous denial. The verdict in the petitions against Aadhaar is pending from the Supreme Court. I hope the verdict comes to save all the residents of India, and to save the country itself. [1]: https://www.tribuneindia.com/news/nation/rs-500-10-minutes-and-you-have-access-to-billion-aadhaar-details/523361.html https://www.tribuneindia.com/news/nation/rs-500-10-minutes-a... [2]: https://www.firstpost.com/india/uidai-files-fir-against-the-tribune-reporter-rachna-khaira-for-aadhaar-data-breach-story-4291109.html https://www.firstpost.com/india/uidai-files-fir-against-the-... [3]: https://timesofindia.indiatimes.com/india/need-internet-to-buy-pds-rations-go-climb-a-tree/articleshow/57437975.cms https://timesofindia.indiatimes.com/india/need-internet-to-b... [4]: https://www.voltairenet.org/IMG/pdf/module3b_installation_configuration_of_aadhaar_enrolment_client_17122012.pdf https://www.voltairenet.org/IMG/pdf/module3b_installation_co...
- zaptheimpaler 8y agoThis is a true story - I went to a regional passport office to get my Aadhar card about 2 years ago. I sat in front of a desk with an employee - she was logged in to a website to that let her upload my picture/biometrics and info into the Aadhar system. The desk had a post-it 3 feet away from me with the login username/password written on it. Since the operators also need to verify biometrically to login, that alone wouldn't be enough to hack it. But if you think about the general level of understanding of IT among the public, and probably even the people who wrote the software, its pretty unsurprising to see it hacked. Even so, I don't think its really possible for a huge entity like the government (or even a large company) to learn all the practices around security/technology without making mistakes and learning under situations with real consequences. As long as they learn from these mistakes and accept failure, rather than trying to cover them up, we will get there in time.
- thisisit 8y agoI like how tough topics in India are discussed - everything is tied back to the central government. Either you a nationalist supporting the central government or you are a self proclaimed anti-nationalist who dislikes the current government and their agenda. One of the things people need to realize is this is a bigger bureaucratic problem. It has nothing to do with current or previous government. Previous government pushed this through because it was in their agenda and the current government cried foul. Now the tables have turned. What this tells me is that there are lot of private interests which are playing a huge role in Indian governance, irrespective of the government. And we as a people getting into petty fights about the nationalist/anti-nationalist debate are losing sight of the target.
- regunath_b 8y agoI am the guy (Regunath) quoted in this article. I had already vented out at how one of the journalists approached me with an intent to get a "balanced" view of the system and ended up writing what he wanted from a pre-determined agenda. See this : https://twitter.com/RegunathB/status/1039411036497956864 https://twitter.com/RegunathB/status/1039411036497956864 What is not covered in this article is that all data from client (even if compromised) is validated by a completely different system on the server-side (any decent system does this and so does Aadhaar) and the client too has undergone maybe 20 revisions to add features/fix issues - again typical of any software. The latest version of the client software, I am told, entirely boots off a secure external storage. Now, older versions might still be i use on the field. The Enrolment client software has provision to force upgrade the software and go to the extent of locking up and not allow any new enrolments. The server counterpart can also check and reject enrolments from previous versions of client software. All of this was shared to the same reporter and you can see how much (or how less) of it was actually covered in this fact finding exercise. Press has the ability to tell the truth or sensationalize, these guys chose the latter.