Live data from Hacker News

India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

huffingtonpost.in

11–20 of 163 posts

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#11

Is this complete incompetence? Why wouldn't they generate these numbers on some centralized secured servers only for the verified individuals? Why give away the software that generates them at all? That's like giving away your signing servers.

That is answered in the article

> B. Regunath, a software architect who led the team at Mindtree that worked on the project, said a web-based enrolment software for Aadhaar was not practical at the time because many parts of the country had very poor Internet connectivity.

Of course, anyone who put id generating software on these laptops with the expectation that it would somehow remain secret was being extremely foolish. The system should have been designed taking that into account.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#12
Apparently the breach is now being proxied by the fired private operators through government offices. Can this cashless money flow be traced? Even burner mobile phone numbers are linked to the same compromised national identity database.

Who could benefit indirectly from the breach? Could the Indian government turn to Facebook and WhatsApp for help with identity profiling? Is Facebook Indian data held in Indian data centers?

This story will find its way into future documentaries on the history of "Papers Please".

> in February 2018, the UIDAI terminated all contracts with common service centres as well .. Henceforth, only banks and government institutions like the postal service can enrol Aadhaar users. As a consequence, tens of thousands of young men, with rudimentary education but great familiarity with the Aadhaar system, were put out of work.

> In interviews, out-of-work operators claim they can still use the hacked enrolment software to generate enrolment ids (the first step in the Aadhaar registration process) and have tied up with sources working in authorised centres who complete the registration process for a fee.

> ... creates a whole new set of problems and could defeat many of Aadhaar's purported aims, such as reducing corruption, tracking black money, eliminating fraud and identity theft. It also means that the Aadhaar database is vulnerable to the same problems of ghost entries as any other government database

> the Indian government has sought to make Aadhaar numbers the gold standard for citizen identification, and mandatory for everything from using a mobile phone to accessing a bank account.

> Sourcing the patch is as easy as gaining access to one of thousands of WhatsApp groups where the patch, and the usernames and passwords required to login to the UIDAI's enrolment gateway, are sold for as little as Rs 2,500. Payments are made through mobile wallets linked to phone numbers that quickly go dead after the transactions are complete.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#13

Is this complete incompetence? Why wouldn't they generate these numbers on some centralized secured servers only for the verified individuals? Why give away the software that generates them at all? That's like giving away your signing servers.

You are assuming this is unintentional. Giving bureaucrats and criminals working with them power through incompetence of the central government ... forgive me for doubting that this was a design feature. It redivides the power between individuals and the state, including criminals working with (small parts of) the state. I believe anyone who can get a majority of 1.3 billion people to vote for him did not miss this.

I mean what's with the "Caesar can do no wrong" attitude on this site ?

States are evil. The best possible case is that they might be, at times, the lesser evil.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#14

> In 2017, the UIDAI said it had blacklisted 49,000 enrolment centres for various violations, and in February 2018, the UIDAI terminated all contracts with common service centres as well. Seems like they are well aware of this hack. Skimming through the article, it seems the attacker can register himself in the system but not read data from the system. Also, there's no mention of 1.2B records being compromised.

Actually, the records are already public, remember the fiasco where Telecom Regulatory Authority of India’s Chairman RS Sharma had posted his Aadhar number online. The whole point of the Aadhar Challenge was to demonstrate leaked database/Aadhar number is not an issue. Apart from the curated datasets that can be bought even on Facebook groups, it is actually very easy to mine large datasets from Google itself.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#15
post #6

Undeniably bad, but I'm fighting off a slight sense of schadenfreude here, due to their prior claims[1]. [1] https://www.troyhunt.com/is-indias-aadhaar-system-really-hac...

Yes it looks like their security was really amateur hour stuff too, with a lot of the authentication done on the client side. This makes their claims that it was "hack-proof" look particularly embarrassing.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#17

Is this complete incompetence? Why wouldn't they generate these numbers on some centralized secured servers only for the verified individuals? Why give away the software that generates them at all? That's like giving away your signing servers.

That is answered in the article > B. Regunath, a software architect who led the team at Mindtree that worked on the project, said a web-based enrolment software for Aadhaar was not practical at the time because many parts of the country had very poor Internet connectivity. Of course, anyone who put id generating software on these laptops with the expectation that it would somehow remain secret was being extremely foo…

Even then, they could have batched the requests for IDs on the laptop, and then submitted them daily/weekly by driving the laptop to wherever the internet is.

And of course, each such laptop must have a unique hardware key that would sign these requests, so copying the software wouldn't compromise anything.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#18

Is this complete incompetence? Why wouldn't they generate these numbers on some centralized secured servers only for the verified individuals? Why give away the software that generates them at all? That's like giving away your signing servers.

The numbers are not generated on the client side. An enrollment packet is, containing biometrics and demographics, for which a number will be generated using biometric deduplication server-side.

The catch: only residents (not citizens) of India are authorised to have a number. Because one person technically cannot have more than one Aadhaar number (reality: ha!), the theory is that a government subsidy database needs one unique Aadhaar number per beneficiary.

This theory breaks down when you enroll an individual who does not need an Aadhaar number because they are not a resident. That number can be misused by another resident to get a second entry into the database, and it's a perfectly legitimate number linked to an Indian phone number that can receive an OTP and behave indistinguishably from a resident.

Fake enrolments are the equivalent of a hack of the US SSN system that would allow anyone anywhere in the world to make an SSN for themselves. What could they possibly do with that?

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#20

If I get it: India has a biometric database with 1B people on it! ... wow ... just wow ... And adding new people to it is now compromised by a publically available hack, although getting 1B biometrics on board must have had an error rate that would be scary anyway. The UUID created is needed almost everywhere, like driving license numbers elsewhere. How much of the scare is "People can be added once but under incorre…

Maybe I'm in the wrong here, but I imagine most civilised countries have a database with biometrics of all of its citizens, at least fingerprints.
Post reply on HN