SCREENSHOTS - http://imgur.com/a/k9mCf (read notes below) For people who have negative opinions about this, hold on. There's more to the DigitalLocker than you think. I tried using this the day it launched (a few weeks ago). Here are a few things for people who haven't tried it. 1.) Apart from storing documents, the other important feature is to share documents with entities (seems like both govt and private). Right…
India goes digital
21–30 of 44 posts
Re: India goes digital
#22SCREENSHOTS - http://imgur.com/a/k9mCf (read notes below) For people who have negative opinions about this, hold on. There's more to the DigitalLocker than you think. I tried using this the day it launched (a few weeks ago). Here are a few things for people who haven't tried it. 1.) Apart from storing documents, the other important feature is to share documents with entities (seems like both govt and private). Right…
Please change 'xerox copies' to 'photocopies', except Indians others might not understand :)
Cannot edit my comment anymore.
Re: India goes digital
#23For people having issues with CA - It is not the CA that is the problem (it is not a famous CA, but is known, at least by Chrome), the problem is that they probably shortened the domain too late and are still using the old configuration. Use the URL below, the certificate works fine. It's just for the wrong domain: https://digitallocker.gov.in/ Edit: I'm unable to login though. I get the OTP from Aadhaar just fine, b…
I am getting the certificate error even at the link you provided ( using Google Chrome on Ubunut 14.04 ).
They are using a relatively new sub-CA of e-Mudhra, so it will appear everywhere soon, I believe.
If you're really willing to use it now, SHA1 of verified certificate is 56 7F 2D B5 7E 31 BC E5 6C 5C 8C 3B 80 44 AA 2F 7C 13 D3 6D. Not ideal way at all, but might help paranoia. You shouldn't trust me though.
Re: India goes digital
#24Re: India goes digital
#25See the following question in the FAQ (I've edited it for brevity with ellipsis and emphasized important parts). [1]
>Q11 How can I share the e-documents in my digital locker?
>A11 For sharing your e-document...enter the email address of the recipient in the dialog box and click ‘Share’ button.
>The document will be shared with the recipient via email. ...email body will have the URI link of the document and the sender name and Aadhaar number. The recipient can access the document using the URI link provided in the email.
So:
1. You share your document, which is sent over plain text email.
2. The recipient can access it just with a link. There is no authentication or verification of any kind.
3. The recipient can forward the mail to data collectors so they can immediately get your name, your Aadhaar number and the document. There is no link expiry, which allows perpetual abuse of information by forwarding emails. This technology makes selling information a lot simpler and quicker.
4. Someone else's email account gets hacked? Thousands or millions of names, Aadhaar numbers and documents could be out on torrents soon enough. Talk about government enabling things through technology.
Even if you trust the government to store all your documents, even though some may be issued by local authorities, this looks more and more like a comprehensive and centralized data collection mechanism. The next step, which may or may not be disclosed, would be to provide access to every government entity to query this database without any control or limits or oversight. For a country without any privacy laws, they already have your biometric information, now they can completely own you. :)
[1]: https://digitallocker.gov.in/Resources/FAQ-Digital_Locker_v0...
Re: India goes digital
#26For people having issues with CA - It is not the CA that is the problem (it is not a famous CA, but is known, at least by Chrome), the problem is that they probably shortened the domain too late and are still using the old configuration. Use the URL below, the certificate works fine. It's just for the wrong domain: https://digitallocker.gov.in/ Edit: I'm unable to login though. I get the OTP from Aadhaar just fine, b…
I am getting the certificate error even at the link you provided ( using Google Chrome on Ubunut 14.04 ).
Re: India goes digital
#27I feel the Feedback page might need some work. Right now is seems like all the submitted feedback is made public with no approval. http://i.imgur.com/1qieQ03.png
Re: India goes digital
#28How does this work for NRIs? How do I get Aadhaar number?
I don't know how you can get one but you shouldn't get it. Do you really want to give all your fingerprints and retina scans to the government when you know how it can be misused in a country like India which is a police state? I bet there is no oversight in getting access to your information and there are tons of ways in which your information can be misused/exploited.
Re: India goes digital
#29I'm leaving aside the certificate issue for a moment since others have mentioned it. This solution is a great way for hackers and phishers to collect a lot of personal information. Perhaps this is done with very good intentions, but is really poorly thought out. I wonder who architects these solutions and how they think. See the following question in the FAQ (I've edited it for brevity with ellipsis and emphasized im…
The whole UID infrastructure is two-factor auth by default. Think of the URI like Facebook Graph API URLs. They are static, REST-ful endpoints that require two-factor authentication.
While there are no strong laws to protect scans of your IDs, the biometric data does come under The Privacy Bill, 2013. So does any identification typically used by financial institution. Your other IDs, like Voter ID are public information anyway, except for biometric identifiers.
Re: India goes digital
#30Earlier quoted context omitted.
I am getting the certificate error even at the link you provided ( using Google Chrome on Ubunut 14.04 ).
I investigated further. It works fine on Mac and Windows 8.1. Apparently your operating system doesn't support the CA yet. I don't have Ubuntu, but I do have a linux based system, and it fails there too. They are using a relatively new sub-CA of e-Mudhra, so it will appear everywhere soon, I believe. If you're really willing to use it now, SHA1 of verified certificate is 56 7F 2D B5 7E 31 BC E5 6C 5C 8C 3B 80 44 AA 2…