Live data from Hacker News

India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

huffingtonpost.in

111–120 of 163 posts

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#111
post #84

I have to admire the courage of the people who have investigated and reported this, given that the entire leadership of UIDAI and its backers in the central government are intolerant of any criticism and have been known to file police complaints[1] against journalists, critics and whistleblowers. Even its visionary and leading cheerleader from the private sector preferred to imagine conspiracies rather than acknowled…

This is one of the main reasons that this report doesn’t touch upon read access of the database. Rachna Khaira, one of the reporters already has a police case against her for her previois reporting on Aadhar database compromise. Getting even one user record would have landed all three journalists behind bars. It is left for the reader to conclude, and validated by various experts, that whole database is hacked. If a…

I mean, you need a client to access it, and presumably having a patch for such means you have the client too...

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#112
[Note: I'm anti-Aadhaar, as documented in my profile. My comments below may sound harsh because of that. Also please note that Aadhaar is a resident number, and has nothing to do with citizenship.]

Fantastic work! One of the authors of this investigative piece, Rachna Khaira, was key in exposing a major issue with the "last mile" software and how cheaply (just Rs.500/about USD 7) and easily someone could get the Aadhaar and demographic details of almost any resident in the country who's enrolled in the system. [1] UIDAI's response for her investigation was to file an FIR (First Information Report/police complaint) against her in an attempt to put her behind bars. [2]

Activists have always argued that the lack of transparency and information could mean that there are many "ghosts" (or bogus enrollments) in the Aadhaar system (which claims that it cannot have "ghosts", ignoring technological as well as biometric limitations). Now there's no saying how many of the 1.1 billion entries in the Aadhaar system are bogus. As the article states, private agencies were used to handle the enrollment and capture of biometrics and recording of demographic information. All these agencies were paid on a per-enrollment basis. Guess what incentives they would have in a country with high levels of corruption at many levels? I'm certain that a bulk of the enrollments that have been issued Aadhaar numbers are bogus.

While activists may feel vindicated that more and more holes are being exposed in the Aadhaar system (while UIDAI continues to always remain in denial mode), it's sad that hundreds of millions of people have been left vulnerable by this poorly designed and poorly implemented system.

> B. Regunath, a software architect who led the team at Mindtree that worked on the project, said a web-based enrolment software for Aadhaar was not practical at the time because many parts of the country had very poor Internet connectivity.

> "People were cranking up generators just to light up power and do the enrolment. How can they do an online upload of those packets?" asked Regunath, who has since moved to a senior technical position at Flipkart.

What utter nonsense!!! I can't imagine someone calling themselves a software architect being so gullible and ignorant. The entire Aadhaar system is dependent on Internet access and connectivity. Post issuance, the authentication of anyone through biometrics needs real time Internet connectivity. There's no way around that (even where an OTP is generated, the initiation of the OTP sent over SMS by UIDAI has to happen by connecting to UIDAI's web based APIs). Even as recent as last year, people in some places were forced to climb trees because they couldn't get a good cellular signal and Internet connectivity. They were forced to do this because the central government pushed this system as a prerequisites for getting subsidized food (through what's called PDS or Public Distribution System). [3] UIDAI also had Windows XP as a recommended OS for these enrollment agencies. [4]

> In 2017, the UIDAI said it had blacklisted 49,000 enrolment centres for various violations.

The sheer hypocrisy and audacity of UIDAI here is that it has blacklisted all these agencies for violations without any legal action. From the time Aadhaar started in 2009/2010, this number averaged to about two agencies blacklisted every hour! But point out some security issue or a gap? You'll be facing a court case!

_____

This whole system has been patchworks of patchworks of patchworks, continuously in denial mode when experts ask questions on security, audit, privacy, etc. I would prefer that it be completely thrown out, like how UK did with its national ID program several years ago. India doesn't need such enemies from within that/who make it easier for hostile entities/groups to disrupt or decimate the country! UIDAI needs to be shutdown as well, since nobody in-charge of the organization has shown technical or critical thinking ability, or has had the humility to face questions without getting into continuous denial.

The verdict in the petitions against Aadhaar is pending from the Supreme Court. I hope the verdict comes to save all the residents of India, and to save the country itself.

[1]: https://www.tribuneindia.com/news/nation/rs-500-10-minutes-a...

[2]: https://www.firstpost.com/india/uidai-files-fir-against-the-...

[3]: https://timesofindia.indiatimes.com/india/need-internet-to-b...

[4]: https://www.voltairenet.org/IMG/pdf/module3b_installation_co...

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#113
post #79
post #53

According to the article the database has not been compromised. It's a compromise of the client which can be used to add new Aadhar entries.

A compromise in this case being that illegitimate entries are being added when they should not be able to. You don’t need write to consider this specific case broken.

Sorry, I meant to say "You don't need read to consider this specific case invalid." Didn't have my coffee yet!

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#114
post #76

One of the reasons why India needs some kind of people authentication is rampant corruption! Corruption at a scale that most of people in Europe or US cant even imagine. Add to it the culture which celebrates corruption and eulogizes people who find loopholes in system. As soon as a policy or rule is implement, someone gets to work to find a loophole and profit. Schemes and subsidies for poor get siphoned by rich and…

Giving something substantial thought does not necessarily guarantee that the thought was any good though.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#115
post #63

As an Indian developer, I cringe every time the government claims a system is un-hackable. Especially when contracts are handed to one of the big Indian IT companies. Having started my career in one of those companies, I saw firsthand how most of the development process was just filling in gaps. Security through obscurity was thought to be “highly secure” and security experts were non existent. No surprises that the…

You mean security experts were found all around, but patted themselves on the back after preventing a single SQL injection attack.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#116
post #76

One of the reasons why India needs some kind of people authentication is rampant corruption! Corruption at a scale that most of people in Europe or US cant even imagine. Add to it the culture which celebrates corruption and eulogizes people who find loopholes in system. As soon as a policy or rule is implement, someone gets to work to find a loophole and profit. Schemes and subsidies for poor get siphoned by rich and…

If your solution for corruption at higher levels is to make a billion (or hundreds of million, since we now know that there are ghost entries in the Aadhaar database too) people suffer, not have access to food, die of starvation, not get their pensions, etc., then it's a useless solution that has no place anywhere in the world, more so in a democracy!

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#117
post #56

I don't know how many times this will have to be repeated. Aadhar, GST, all implemented by the worst possible companies in terms of talent. WTF is wrong here, there are plenty of talented people around. Or just crowdsource it or give it to the universities to build or something.

Is there any success story about crowdsource in India?

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#118
post #60

Apparently the breach is now being proxied by the fired private operators through government offices. Can this cashless money flow be traced? Even burner mobile phone numbers are linked to the same compromised national identity database. Who could benefit indirectly from the breach? Could the Indian government turn to Facebook and WhatsApp for help with identity profiling? Is Facebook Indian data held in Indian data…

>>> Who could benefit indirectly from the breach? This and who will buy those data ? Everybody scream about the hack but I've never found a comprehensive study over how these personal data are sold, abused. Maybe to break gazillions of FaceBook/github/you-name-it accounts ? Then what, who will use those data ? Thieves ? Criminals ? If it's just that well, that's a minor inconvenience. If it's secret services of adver…

> Then what, who will use those data ? Thieves ? Criminals ? If it's just that well, that's a minor inconvenience.

It's only a minor inconvenience if you can sit in a comfortable place and pontificate on Hacker News about these things. Seems like you're not even aware that people have already lost their pension money or bank account balances or didn't get food that they were entitled to and died in the process — everything related to the coercion in the Aadhaar system and how it can be misused by others for fraudulent purposes.

Perhaps your privilege in life is standing in the way of understanding how bad things are with the Aadhaar system. Please search for #AadhaarFail on Twitter, look for articles on scroll.in and thewire.in (two sites that some people do hate) and rethinkaadhaar.in.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#119

I expected better discussion on HN (apart from sensationalist articles), the article does a poor job intentionally though. Summary 1. Existing data is not compromised 2. Duplicate data can't be entered or overwritten 3. BUT, ghost accounts can be created easily. Aadhar was introduced to fight ghost accounts who siphon off subsidies provided for poor. This hack/patch defeats that purpose. I still think this is not a b…

Two points:-

1. Surprise, there's a separate $10 application which can access all the Aadhar database entries. Exposed by one of the journalists of this story, for which she got a police case filed against her. [a]

2. Aadhar has no way to verify double entries, one whistleblower to Supreme Court said the database has 40% bogus entries, i.e. 450 Million fake IDs. Yes, no verification backup documents, no signup forms exist for 40% entries in the database, and authority has no way to audit them. [b]

a. https://www.tribuneindia.com/news/nation/rs-500-10-minutes-a...

b. https://ia802809.us.archive.org/26/items/Aadhaar_Whistleblow...

Bonus: Aadhar database was at one time hosted in US with FTP password being Admin$12. This is the state of this sham project. https://imgur.com/a/2sppFrm

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#120
post #20

If I get it: India has a biometric database with 1B people on it! ... wow ... just wow ... And adding new people to it is now compromised by a publically available hack, although getting 1B biometrics on board must have had an error rate that would be scary anyway. The UUID created is needed almost everywhere, like driving license numbers elsewhere. How much of the scare is "People can be added once but under incorre…

Maybe I'm in the wrong here, but I imagine most civilised countries have a database with biometrics of all of its citizens, at least fingerprints.

And not only of its citizens.

https://en.wikipedia.org/wiki/Biometric_passport

Post reply on HN