Earlier quoted context omitted.
That's a biased article and is taking things out of context. A better understanding would be found at the UIDAI page itself: https://uidai.gov.in/component/fsf/?view=faq&catid=27 To their credit, the leaks that have happened until now haven't happened directly from UIDAI database but by partners who had poorly designed API endpoints which exposed citizen identity data. At the very least, biometric data has never been…
As a security researcher in india, Aadhaar is riddled with Security holes that are glaring. There is clear way to report these issues and nothing gets fixed. I've had a possible-RCE vulnerability reported to UIDAI since February-2017 and there has been no action. The CERT-IN (Indian equivalent of CERT-US) has been aware of the issue, but there is no fix in sight. The easiest to do exploits (fingerprint cloning) are a…
‘Big Brother’ in India Requires Fingerprint Scans for Food, Phones and Finances
81–90 of 172 posts
Re: ‘Big Brother’ in India Requires Fingerprint Scans for Food, Phones and Finances
#82Earlier quoted context omitted.
OK, thanks! Sounds like a massive business opportunity for banking. Your village may not have an ATM but I bet it has cellphone signal. Wasn't every Kenyan SMS-ing money around a decade ago?
We're trying this with "Payment Banks". The DBT scheme itself tries to solve it by directly debiting money from your account and crediting it to the shopkeeper's account on a monthly basis automatically, but the real implementation is still cash withdrawls as of now. The Kenyan-SMS has also led to a monopoly of mpesa in the market, which the RBI is trying to avoid by bringing some decent regulations in the space of d…
Re: ‘Big Brother’ in India Requires Fingerprint Scans for Food, Phones and Finances
#83Earlier quoted context omitted.
First of all, Aadhaar is not just being used for welfare schemes. It is a giant database getting linked to everything. I wouldn't be surprised if it will soon be mandatory for booking flights. Plus much of the database has leaked. You can find thousands of Aadhar cards online just by googling. As far as preventing 'leakage'--the best approach would be to not subsidize products but to move to direct benefits transfer…
Plus much of the database has leaked. Honest question: how much does this matter? For instance, I believe in Denmark your ID number is simply not a secret at all, no more than your name. While in the US, your SSN & address basically seems to let any crook empty your bank account.
Since paper-aadhaar is still very much accepted as a proof, just having the number is enough (in many cases) to take over someone's identity and get a new SIM issued, which you can then use for emptying the bank account.
There are also phishing scams happening with Aadhaar since it uses OTP as the authentication factor. We have OTPs as 2FA for bank transactions, and it works because the first factor is still secret (credit card number or your banking credentials). However, if your first factor is your Aadhaar number, the security goes down tremendously, since every organization under the sun is now asking your Aadhaar.
I'm tempted to wardrive Aadhaar OTPs sent over unencrypted SMS.
Re: ‘Big Brother’ in India Requires Fingerprint Scans for Food, Phones and Finances
#84Earlier quoted context omitted.
>The article mentions fraud is a big issue. When tackling fraud, you must look at 1)exclusions and 2)cost. In the case of aadhaar, we've seen the project baloon in cost and vision over the span of two different governments. There have been savings number reported by the government that have since been redacted by the World Bank (but the government keeps claiming them). At some point, you must take stock and consider…
What is your solution ? It kind of seems like Aadhar should be better managed... rather than reinvent another identity system, sure I am optimistic that Aadhar will improve (Its a very new system compared to SSN or other identity systems) Regarding ballooning costs, so many successful programs have had costs that exceeded the plan, so far with Aadhar there has been no evidence that the ballooning costs have been debi…
On balooning costs - Yes, the scope has vastly increased:
1. it was supposed to be a YES/NO boolean API, which has since become a complete eKYC API giving third parties access to your data
2. State resident data hubs that maintain a copy of your biometrics and data to enable state level surveillance
3. Pushing of mandatory linkages has cost us thousands of crores already.
(and more that I'm missing - this is early morning IST now and I'm getting sleepy). A lot of this should not have been allowed in a scheme that was passed in the parliament as a "Money Bill". The helping part is non-proportional to the expenditure which we've seen - this is under purview in the SC hearing as well.
Re: ‘Big Brother’ in India Requires Fingerprint Scans for Food, Phones and Finances
#85Earlier quoted context omitted.
Plus much of the database has leaked. Honest question: how much does this matter? For instance, I believe in Denmark your ID number is simply not a secret at all, no more than your name. While in the US, your SSN & address basically seems to let any crook empty your bank account.
Aadhaar number enables identity fraud. Since paper-aadhaar is still very much accepted as a proof, just having the number is enough (in many cases) to take over someone's identity and get a new SIM issued, which you can then use for emptying the bank account. There are also phishing scams happening with Aadhaar since it uses OTP as the authentication factor. We have OTPs as 2FA for bank transactions, and it works bec…
Re: ‘Big Brother’ in India Requires Fingerprint Scans for Food, Phones and Finances
#86Earlier quoted context omitted.
Plus much of the database has leaked. Honest question: how much does this matter? For instance, I believe in Denmark your ID number is simply not a secret at all, no more than your name. While in the US, your SSN & address basically seems to let any crook empty your bank account.
Aadhaar number enables identity fraud. Since paper-aadhaar is still very much accepted as a proof, just having the number is enough (in many cases) to take over someone's identity and get a new SIM issued, which you can then use for emptying the bank account. There are also phishing scams happening with Aadhaar since it uses OTP as the authentication factor. We have OTPs as 2FA for bank transactions, and it works bec…
Weird. Maybe it's different from state to state or probably area to area. Atleast where I reside (Telangana), getting a new SIM requires fingerprint authentication followed by SMS OTP to an existing mobile number. If you do not have an existing number linked to Aadhaar, only then a fingerprint scan would suffice. I have also opened a bank account here following the same procedure. I had to get one number ported and that required multiple authentication too.
Re: ‘Big Brother’ in India Requires Fingerprint Scans for Food, Phones and Finances
#87Earlier quoted context omitted.
I've filed my tax returns with just my PAN card and without using a DSC. This might be different for a registered organization where CAs must handle DSCs I think, but you could file your Individual taxes without printing/using a DSC/Aadhaar by just creating a new account linked to your PAN. The fact that they used OTP (and tout it as a security feature) is so disheartening. I am not the SIM card in my phone. Switchin…
> There is no recourse in the law for someone stealing your phone and signing away your entire property once e-Sign comes in force everywhere. I agree with you on this. Currently however, this is how it is with everything online. Take any 2-FA service. It's either SMS based or through Google authenticator/yubikey etc. To expect non tech savvy people to use yubikey or Google authenticator is going to be a hardsell. >…
Wardriving Plan:
1. Google for '"Mera Aadhaar, Meri Pehchaan" filetype:pdf'
2. Find someone working at UIDAI on that list
Re: ‘Big Brother’ in India Requires Fingerprint Scans for Food, Phones and Finances
#88Earlier quoted context omitted.
Yes, these have existed for quite some time. However, you could get one with varying different ID proofs earlier - Driving License, Ration Card, PAN (Tax) Card, Voter ID etc. Now, we're all being forced to link _everything_ to a single 12-digit Aadhaar.
What justification is given for this?
The events:
1. Supreme Court asks DoT in a regular about the status of KYC for telcos and asks for all SIMs to be compliant within a year
2. DoT (department of telco) rewords the above a "direction" (it was not binding till then) of the SC and makes Aadhaar-KYC mandatory (when the original order did not mention Aadhaar in any way, just KYC)
As for the original KYC-law, I'm not entirely sure, but it has existed for decades now.
[0]: https://www.huffingtonpost.in/chitranshul-sinha/no-the-supre...
Re: ‘Big Brother’ in India Requires Fingerprint Scans for Food, Phones and Finances
#89Earlier quoted context omitted.
Aadhaar number enables identity fraud. Since paper-aadhaar is still very much accepted as a proof, just having the number is enough (in many cases) to take over someone's identity and get a new SIM issued, which you can then use for emptying the bank account. There are also phishing scams happening with Aadhaar since it uses OTP as the authentication factor. We have OTPs as 2FA for bank transactions, and it works bec…
I think you need an OTP to get online Aadhar PDF. So you can't get paper Aadhaar just by knowing the Aadhar number.
Can you forge one with MS Word or is it somehow more secure than that?
Re: ‘Big Brother’ in India Requires Fingerprint Scans for Food, Phones and Finances
#90Given the title and article is sensationalized, does anyone else see that the greater reliance organizations and govnts put on mass-production of homogeneous survellience technology, the easier it will be to abuse, and the harder it will be to be detected. A double-edge sword it is.
And now we have https://en.wikipedia.org/wiki/DRDO_NETRA (India's version of PRISM)