> Pretty simple. Do you want everyone in the world to have access to the database? Now at least it is hidden through obscurity. This is exactly why in this report the said journalist got it verified by three external experts, one of them a professor.
Don't you think this is pretty convenient an excuse? The report is also not in public domain nor is the exploit. We have to just rely on a journalist, a CTO, a professor and another person as "proof". Meltdown and Spectre are way more serious exploits as it affects pretty much the entire World and it was disclosed but this exploit is supposedly so much more heinous that it cannot be disclosed.
> Do you have a conflict on interest with this project? I see on your Twitter that you have retweeted some posts from Ministry overlooking this project. Not casting doubt, just needing a clarification due to the tone of your posts in this thread. Sounds very government'ish.
It always sounds government'ish to people who rely on conspiracy theories. I am an open supporter of the Government in many policies. As far as conflict of interest with this project I am no way connected to the UIDAI project. So don't try to find connections where there are none.
> I see on your Twitter that you have retweeted some posts from Ministry overlooking this project.
I haven't retweeted anything to do with Aadhaar. The retweets are GST related and another one to do with AI. It's ridiculous to assert that just because I support the government and I retweet some of the policy decisions I end up becoming a supporter of Aadhaar. Don't forget that Aadhaar was formulated and ratified by the previous government. Also, I dislike Nandan Nilekani for how he handled implementation of GST and Aadhaar itself. If at all there is something Aadhaar seriously lacks: it is proper communication with the people about how data is stored and stupid decisions by the UIDAI to link Aadhaar for anything and everything (including the recent one with requiring Aadhaar for sending posts overseas). I don't support such ridiculous decisions.
> Forget the grammar, typos it doesn't matter. Ignore the whole of his letter except the official correspondence that is attached and does in fact validate his/her point.
I am rational in my thinking and approach. When I see fake news I call it out. You relied on it not me.
> Authority has no way to audit the fake accounts, authority does know for which entries backup documentation exists or not. In fact, he attaches official documentation later on as an evidence.
Which official document? There is nothing in the letter that is "official document". Even the table that he mentions is not available in public domain to authenticate. I can create a table myself and call it "official document". Would that be sufficient evidence in the court of law?
Also, if such a letter was indeed written, why haven't any Supreme Court judge confirmed receipt of such a letter?
> I meant to write Aadhar data. So you are totally over loooking the fact that some of the Aadhar related data was on US servers, and more importantly the password is being relayed over E-mail? Also, no secure way to host the government data, except HP servers?
You are assuming a lot here. There is no indication that the data on the US servers was Aadhaar related.
> Government has been so opaque regarding this project that we have to rely on journalists, researchers and whistleblowers to help us with any sliver of info.
No it's the other way around. The journalists, researchers and whistleblowers are the ones who are being opaque with their findings. At the end of the day, if you find a loophole, it's your responsibility to make it known to the public if the Government refuses to acknowledge it. Media is the fourth arm of democracy for a reason. If you know that the Government is deliberately trying to hide details of exploits from the public, it automatically becomes your responsibility to disclose the exploit itself. By withholding the details of the exploit, you are strengthening the hands of nefarious non-state actors because they know that the Government would turn away and reporters would never expose. You release the exploit in the public domain, it automatically creates pressure on the Government and force it to either fix the issue or accept responsibility.