6 ms·
I expected better discussion on HN (apart from sensationalist articles), the article does a poor job intentionally though. Summary 1. Existing data is not com
by kcsomisetty 8y ago
I expected better discussion on HN (apart from sensationalist articles), the article does a poor job intentionally though.
Summary
1. Existing data is not compromised
2. Duplicate data can't be entered or overwritten
3. BUT, ghost accounts can be created easily.
Aadhar was introduced to fight ghost accounts who siphon off subsidies provided for poor. This hack/patch defeats that purpose.
I still think this is not a big problem as it looks on surface, if Enrollment software is hacked to accept iris data from photograph,
Can't the Aadhar DB (post enrollment) be scanned for all enrolled iris data with poor quality iris data and they be monitored and deleted ?
Another problem is still there, what if the operators enroll citizens from a different country as indians, essentially creating ghost accounts (from citizens of different country). i dont know how to stop such a situation.
Biometrics is never a good model for authentication, i dont know what these people were think when they designed it.
- iamshs 8y agoTwo points:- 1. Surprise, there's a separate $10 application which can access all the Aadhar database entries. Exposed by one of the journalists of this story, for which she got a police case filed against her. [a] 2. Aadhar has no way to verify double entries, one whistleblower to Supreme Court said the database has 40% bogus entries, i.e. 450 Million fake IDs. Yes, no verification backup documents, no signup forms exist for 40% entries in the database, and authority has no way to audit them. [b] a. https://www.tribuneindia.com/news/nation/rs-500-10-minutes-and-you-have-access-to-billion-aadhaar-details/523361.html https://www.tribuneindia.com/news/nation/rs-500-10-minutes-a... b. https://ia802809.us.archive.org/26/items/Aadhaar_Whistleblower_document_to_SC_Judges/40%20CRORE%20DUPLICATE%20AADHAAR%20CARD%20LETTER.pdf https://ia802809.us.archive.org/26/items/Aadhaar_Whistleblow... Bonus: Aadhar database was at one time hosted in US with FTP password being Admin$12. This is the state of this sham project. https://imgur.com/a/2sppFrm https://imgur.com/a/2sppFrm
- shripadk 8y ago> 1. Surprise, there's a separate $10 application which can access all the Aadhar database entries. Exposed by one of the journalists of this story. [a] Can the said journalist just release the application in public domain? If not, why not? > 2. Aadhar has no way to verify double entries, one whistleblower to Supreme Court said the database has 40% bogus entries, i.e. 450 Million fake IDs. Yes, no verification backup documents, no signup forms exist for 40% entries in the database, and authority has no way to audit them. [b] If authority has no way to audit them then how did the whistleblower arrive at this magical "40%" figure. What's worse than the 40% figure is the way the entire letter is written. No way a professional would write a letter with all caps, typographical errors, paragraphs upon paragraphs of sensationalism with little to show for "proof". Even the table which shows the details of "AadhaarCount v/s Aadhaar Records" is not something available in public domain so it cannot be validated as authentic. > Bonus: Aadhar database was at one time hosted in US with FTP password being Admin$12. This is the state of this sham project. https://imgur.com/a/2sppFrm https://imgur.com/a/2sppFrm I have seen this crop up in every discussion but no where in the screenshot does it say that the data hosted in US was the "Aadhaar database". All this screenshot details is some files were hosted by the UIDAI team on a US based server to share among themselves. The files could be anything. In fact, the email itself says the files are flat files with names: 1. Bill_Desk 2. Total_EXP How did you arrive at the fact that this is the Aadhaar database itself? I can easily assume that "Total_EXP" can mean total expenses and "Bill_Desk" to do something with bill desk. No where does it say "Aadhaar_DB" or something along those lines. This is laughable! Also, this same screenshot exists in the so called "whistleblower's letter" to Supreme Court judges as well. There is no confirmation of any such correspondence by the Supreme Court judges about being in receipt of any such letter. Sorry to say but the way the entire letter is written screams of fake news you typically forward through WhatsApp only to realise later that the entire story was fraudulent to begin with.
- iamshs 8y ago>Can the said journalist just release the application in public domain? If not, why not? Pretty simple. Do you want everyone in the world to have access to the database? Now at least it is hidden through obscurity. This is exactly why in this report the said journalist got it verified by three external experts, one of them a professor. >If authority has no way to audit them then how did the whistleblower arrive at this magical "40%" figure. Authority has no way to audit the fake accounts, authority does know for which entries backup documentation exists or not. In fact, he attaches official documentation later on as an evidence. Forget the grammar, typos it doesn't matter. Ignore the whole of his letter except the official correspondence that is attached and does in fact validate his/her point. I meant to write Aadhar data. So you are totally over loooking the fact that some of the Aadhar related data was on US servers, and more importantly the password is being relayed over E-mail? Also, no secure way to host the government data, except HP servers? Government has been so opaque regarding this project that we have to rely on journalists, researchers and whistleblowers to help us with any sliver of info. Do you have a conflict on interest with this project? I see on your Twitter that you have retweeted some posts from Ministry overlooking this project. Not casting doubt, just needing a clarification due to the tone of your posts in this thread. Sounds very government'ish.
- shripadk 8y ago> Pretty simple. Do you want everyone in the world to have access to the database? Now at least it is hidden through obscurity. This is exactly why in this report the said journalist got it verified by three external experts, one of them a professor. Don't you think this is pretty convenient an excuse? The report is also not in public domain nor is the exploit. We have to just rely on a journalist, a CTO, a professor and another person as "proof". Meltdown and Spectre are way more serious exploits as it affects pretty much the entire World and it was disclosed but this exploit is supposedly so much more heinous that it cannot be disclosed. > Do you have a conflict on interest with this project? I see on your Twitter that you have retweeted some posts from Ministry overlooking this project. Not casting doubt, just needing a clarification due to the tone of your posts in this thread. Sounds very government'ish. It always sounds government'ish to people who rely on conspiracy theories. I am an open supporter of the Government in many policies. As far as conflict of interest with this project I am no way connected to the UIDAI project. So don't try to find connections where there are none. > I see on your Twitter that you have retweeted some posts from Ministry overlooking this project. I haven't retweeted anything to do with Aadhaar. The retweets are GST related and another one to do with AI. It's ridiculous to assert that just because I support the government and I retweet some of the policy decisions I end up becoming a supporter of Aadhaar. Don't forget that Aadhaar was formulated and ratified by the previous government. Also, I dislike Nandan Nilekani for how he handled implementation of GST and Aadhaar itself. If at all there is something Aadhaar seriously lacks: it is proper communication with the people about how data is stored and stupid decisions by the UIDAI to link Aadhaar for anything and everything (including the recent one with requiring Aadhaar for sending posts overseas). I don't support such ridiculous decisions. > Forget the grammar, typos it doesn't matter. Ignore the whole of his letter except the official correspondence that is attached and does in fact validate his/her point. I am rational in my thinking and approach. When I see fake news I call it out. You relied on it not me. > Authority has no way to audit the fake accounts, authority does know for which entries backup documentation exists or not. In fact, he attaches official documentation later on as an evidence. Which official document? There is nothing in the letter that is "official document". Even the table that he mentions is not available in public domain to authenticate. I can create a table myself and call it "official document". Would that be sufficient evidence in the court of law? Also, if such a letter was indeed written, why haven't any Supreme Court judge confirmed receipt of such a letter? > I meant to write Aadhar data. So you are totally over loooking the fact that some of the Aadhar related data was on US servers, and more importantly the password is being relayed over E-mail? Also, no secure way to host the government data, except HP servers? You are assuming a lot here. There is no indication that the data on the US servers was Aadhaar related. > Government has been so opaque regarding this project that we have to rely on journalists, researchers and whistleblowers to help us with any sliver of info. No it's the other way around. The journalists, researchers and whistleblowers are the ones who are being opaque with their findings. At the end of the day, if you find a loophole, it's your responsibility to make it known to the public if the Government refuses to acknowledge it. Media is the fourth arm of democracy for a reason. If you know that the Government is deliberately trying to hide details of exploits from the public, it automatically becomes your responsibility to disclose the exploit itself. By withholding the details of the exploit, you are strengthening the hands of nefarious non-state actors because they know that the Government would turn away and reporters would never expose. You release the exploit in the public domain, it automatically creates pressure on the Government and force it to either fix the issue or accept responsibility.
- talonx 8y agoIt _is_ a big problem, because apart from the ones you mentioned above, it is unclear how many more vulnerabilities are possible.
- n_t 8y agoIsnt that true for every system?
- pritambaral 8y agoWhen a system is shown to have fundamental security flaws — this one uses client-side validation to authenticate biometric operators — it is natural one's trust in the system's robustness would drop low. Like when Intel's chips were shown to completely disregard security when speculatively executing instructions, it wasn't just a new vulnerability; it was a whole class of vulnerabilities that was now open
- kcsomisetty 8y agoAadhar is not a client side authentication, what is client side even mean in this context ?
- pritambaral 8y agoPlease read TFA: "The patch lets a user bypass critical security features such as biometric authentication of enrolment operators to generate unauthorised Aadhaar numbers." The client here is the enrollment software, not "Aadhar" (whatever you meant by that). The Aadhar service should haven been authenticating enrollment operators on the server side, instead of relying on the enrollment software to verify identity (that too by via biometrics, which is NOT authentication).
- kcsomisetty 8y agoThen why does the article claim that aadhar is hacked. why not just call it as aadhar enrollment hacked (which is more appropriate title).
- mathnmusic 8y ago> Can't the Aadhar DB (post enrollment) be scanned for all enrolled iris data with poor quality iris data and they be monitored and deleted ? Not so easy. Every effort that's made to reduce fraud (false positives), might affect genuine beneficiaries who depend on the system for food, healthcare and education - by increasing exclusion (false negatives). A probabilistic auth platform with a really wide scope is a recipe for failure.
- kcsomisetty 8y agowell, i am neither an expert in analyzing bio metric data, but i know that current government is hell bent on ploughing through our lives. i dont know what will be a better future.
- tchalla 8y ago> I expected better discussion on HN (apart from sensationalist articles) There are three people across three different parts of the world who corroborate the report - CTO of a global technology group, a security based analyst and a professor of Computer Science. I wonder how this is "sensationalist". > "Having looked at the patch code and the report presented by Anand, I feel pretty comfortable saying that the report is correct, and it could allow someone to circumvent security measures in the Aadhaar software, and create new entries. This is pretty feasible, and looks like something that would be possible to engineer," Wallach said.
- amf12 8y ago> There are three people across three different parts of the world who corroborate the report - CTO of a global technology group, a security based analyst and a professor of Computer Science. I wonder how this is "sensationalist". OP is not negating the problem. However, the title implies that the existing database has been breached, which is not true. Author could have given a better title which implies that ghost entries could be added and existing data has not been compromised.
- intended 8y agoThe whole point of the system is to give a single confirmed Identity for citizens of India. at this point the purpose of the exercise has been voided. Saying that "the data has not been compromised" is a red herring, thats the case for when our biomterics are lost and our privacy breached which is a whole different issue with this database, one among many of its other problems. At this point if the data is crud, whats the point of using this system?
- ppurka 8y agoActually, having an Aadhar number does not imply that the person is a citizen - this is one of the statements present in the application form itself. So, it is possible for non-citizens to have an Aadhar number.