Live data from Hacker News

India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

huffingtonpost.in

101–110 of 163 posts

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#101
post #64

I expected better discussion on HN (apart from sensationalist articles), the article does a poor job intentionally though. Summary 1. Existing data is not compromised 2. Duplicate data can't be entered or overwritten 3. BUT, ghost accounts can be created easily. Aadhar was introduced to fight ghost accounts who siphon off subsidies provided for poor. This hack/patch defeats that purpose. I still think this is not a b…

It _is_ a big problem, because apart from the ones you mentioned above, it is unclear how many more vulnerabilities are possible.

Isnt that true for every thing around you? just because your bank is not hacked, does not mean it will not be in future.

this is an attitude a system designer should have, allways be on lookout of vulnerabilities.

if media starts writing articles on would be vulnerabilities, then it is just fear mongering.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#102

I expected better discussion on HN (apart from sensationalist articles), the article does a poor job intentionally though. Summary 1. Existing data is not compromised 2. Duplicate data can't be entered or overwritten 3. BUT, ghost accounts can be created easily. Aadhar was introduced to fight ghost accounts who siphon off subsidies provided for poor. This hack/patch defeats that purpose. I still think this is not a b…

> Can't the Aadhar DB (post enrollment) be scanned for all enrolled iris data with poor quality iris data and they be monitored and deleted ? Not so easy. Every effort that's made to reduce fraud (false positives), might affect genuine beneficiaries who depend on the system for food, healthcare and education - by increasing exclusion (false negatives). A probabilistic auth platform with a really wide scope is a recip…

well, i am neither an expert in analyzing bio metric data, but i know that current government is hell bent on ploughing through our lives. i dont know what will be a better future.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#103
post #75

I expected better discussion on HN (apart from sensationalist articles), the article does a poor job intentionally though. Summary 1. Existing data is not compromised 2. Duplicate data can't be entered or overwritten 3. BUT, ghost accounts can be created easily. Aadhar was introduced to fight ghost accounts who siphon off subsidies provided for poor. This hack/patch defeats that purpose. I still think this is not a b…

> I expected better discussion on HN (apart from sensationalist articles) There are three people across three different parts of the world who corroborate the report - CTO of a global technology group, a security based analyst and a professor of Computer Science. I wonder how this is "sensationalist". > "Having looked at the patch code and the report presented by Anand, I feel pretty comfortable saying that the repor…

I am not questioning authenticity of report, that is UIDAI to do.

i am questioning choice of title. offlate, i am seeing too many articles about aadhar breach, and when i study in detail, its mostly related to social engineering/phishing attacks stealing OTP/enrolling unsuspecting customers etc.,

I am worried that when an actual breach happens, the people will probably dont care. (cry the wolf?)

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#104
post #75

I expected better discussion on HN (apart from sensationalist articles), the article does a poor job intentionally though. Summary 1. Existing data is not compromised 2. Duplicate data can't be entered or overwritten 3. BUT, ghost accounts can be created easily. Aadhar was introduced to fight ghost accounts who siphon off subsidies provided for poor. This hack/patch defeats that purpose. I still think this is not a b…

> I expected better discussion on HN (apart from sensationalist articles) There are three people across three different parts of the world who corroborate the report - CTO of a global technology group, a security based analyst and a professor of Computer Science. I wonder how this is "sensationalist". > "Having looked at the patch code and the report presented by Anand, I feel pretty comfortable saying that the repor…

> There are three people across three different parts of the world who corroborate the report - CTO of a global technology group, a security based analyst and a professor of Computer Science. I wonder how this is "sensationalist".

Put out the patch in public domain or at least provide some technical information on the vulnerability itself (by making the said report public).

Every time a story of this sort comes out it inevitably ends in a lot of hand waving and sensationalism: how a reporter got access to a secret WhatsApp group that sells a patch in exchange for 2500 rupees and it allows access to the UIDAI system.

What makes it worse is that we are supposed to just accept whatever this CTO and his two other researcher friends have to say without any way to validate it ourselves. I don't see this happening with any other vulnerability disclosure: be it Spectre, Meltdown or plethora of other exploits which have detailed explanation of the exploit itself. Considering that it affects a billion plus people and as claimed by the article that Aadhaar is "compromised" and "cannot be fixed without requiring a fundamental change in the system" there is no reason now to hold back on technical details.

"This is pretty feasible, and looks like something that would be possible to engineer"

On the one hand you say the patch which can be bought for 2500 rupees already does this and at the same time you use words like "possible to engineer" and "feel pretty comfortable". Since when have feelings and possibilities gotten more prominence than technical explanations?

I'm not saying that the system is foolproof. On the other hand I am waiting for that one article that goes into technical details of the exploit than just sensationalism.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#105

Earlier quoted context omitted.

When a system is shown to have fundamental security flaws — this one uses client-side validation to authenticate biometric operators — it is natural one's trust in the system's robustness would drop low. Like when Intel's chips were shown to completely disregard security when speculatively executing instructions, it wasn't just a new vulnerability; it was a whole class of vulnerabilities that was now open

Aadhar is not a client side authentication, what is client side even mean in this context ?

Please read TFA: "The patch lets a user bypass critical security features such as biometric authentication of enrolment operators to generate unauthorised Aadhaar numbers."

The client here is the enrollment software, not "Aadhar" (whatever you meant by that). The Aadhar service should haven been authenticating enrollment operators on the server side, instead of relying on the enrollment software to verify identity (that too by via biometrics, which is NOT authentication).

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#106

Earlier quoted context omitted.

I want to say that maybe the really talented people / good companies have no interest in building a central database with such dystopian potential. But then again... fb, twitter, ...

Erm, Google, Microsoft, ... most of SV ?

like I said, I really want to say that. Sadly that wouldn't make it true...

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#107
post #78

Earlier quoted context omitted.

I am European. Just because it's a less popular opinion, it's not any less true. I don't even understand the logic itself. States are supposedly not evil, and we need them because ... well because people are more evil. That's the idea. But states are people. Isn't that by itself a massive contradiction ? The difference between, say, the Netherlands and Monsanto is the method of incorporation, and the legal authority…

You picked one of the countries with the most evil government (historically, I make no claim either way about the current situation) as an example. Of course it's going to look bad in that case.

Okay. Name one that's decent. A single one. And let's look up what they've done ... I mean perhaps the really tiny ones are better, but that's really more for lack of options, not lack of will to commit atrocities.

Recently there was -yet another- mental health (for children no less) scandal in the Netherlands. Yes, the government that supposedly fairly hosts the international court can't even respect basic human rights in it's own country. Which brings the question if either of these things is really their goal (where for instance mental health "care" is often accused to be about locking people out of sight, at any cost (to those mental patients), and the international court is about international politics, not justice (for instance the Jugoslavia tribunal only ever convicted people from one side of the conflict)).

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#108
post #68

Earlier quoted context omitted.

This happens in every country, not just India. And the database has not been compromised.

> And the database has not been compromised. The database is not known to be compromised.

> The database is not known to be compromised.

The database is not known by the general public to be compromised.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#109
post #64

Earlier quoted context omitted.

It _is_ a big problem, because apart from the ones you mentioned above, it is unclear how many more vulnerabilities are possible.

Isnt that true for every thing around you? just because your bank is not hacked, does not mean it will not be in future. this is an attitude a system designer should have, allways be on lookout of vulnerabilities. if media starts writing articles on would be vulnerabilities, then it is just fear mongering.

>> Isnt that true for every thing around you? just because your bank is not hacked, does not mean it will not be in future.

But if my bank is widely reported to be hacked, my trust in it would degrade. And I would probably not trust it with any more of my money. A lot also rides on how the bank responds to this in public.

>> this is an attitude a system designer should have, allways be on lookout of vulnerabilities.

Agree, but that is besides the point here.

>>if media starts writing articles on would be vulnerabilities, then it is just fear mongering.

This is something which has occurred, it's not "would be".

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#110

I have to admire the courage of the people who have investigated and reported this, given that the entire leadership of UIDAI and its backers in the central government are intolerant of any criticism and have been known to file police complaints[1] against journalists, critics and whistleblowers. Even its visionary and leading cheerleader from the private sector preferred to imagine conspiracies rather than acknowled…

This can't be upvoted enough. The organization which outsources critical authentication to CIA-MI6 linked companies, and yet find the courage to indulge in the Orwellian-doublespeak of 'nationalism' is something that needs grave attention.

[deleted]
Post reply on HN