Live data from Hacker News

India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

huffingtonpost.in

1–10 of 163 posts

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#3
> In 2017, the UIDAI said it had blacklisted 49,000 enrolment centres for various violations, and in February 2018, the UIDAI terminated all contracts with common service centres as well.

Seems like they are well aware of this hack.

Skimming through the article, it seems the attacker can register himself in the system but not read data from the system. Also, there's no mention of 1.2B records being compromised.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#5
If I get it:

India has a biometric database with 1B people on it!

... wow ... just wow ...

And adding new people to it is now compromised by a publically available hack, although getting 1B biometrics on board must have had an error rate that would be scary anyway.

The UUID created is needed almost everywhere, like driving license numbers elsewhere.

How much of the scare is "People can be added once but under incorrect names" perhaps wiping out criminal pasts? or "people can be added more than once"

The second is surely a search problem?

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#7

If I get it: India has a biometric database with 1B people on it! ... wow ... just wow ... And adding new people to it is now compromised by a publically available hack, although getting 1B biometrics on board must have had an error rate that would be scary anyway. The UUID created is needed almost everywhere, like driving license numbers elsewhere. How much of the scare is "People can be added once but under incorre…

Good luck to the government changing everyone's biometrics now. This is why biometrics should never be used for something like this, especially when it requires a centralized entity to store all the biometric data, making it a very appealing target to all the malicious hackers in the world.

At least Apple, etc, keep the a hash of the biometric data in a secure enclave on each device. Storing biometric data in a centralized database is beyond reckless, no matter who does it.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#8

If I get it: India has a biometric database with 1B people on it! ... wow ... just wow ... And adding new people to it is now compromised by a publically available hack, although getting 1B biometrics on board must have had an error rate that would be scary anyway. The UUID created is needed almost everywhere, like driving license numbers elsewhere. How much of the scare is "People can be added once but under incorre…

They don't use UUID do they? Just a 12-digit UID.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#10
Is this complete incompetence? Why wouldn't they generate these numbers on some centralized secured servers only for the verified individuals? Why give away the software that generates them at all? That's like giving away your signing servers.
Post reply on HN