Live data from Hacker News

India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

huffingtonpost.in

121–130 of 163 posts

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#121
post #60

Earlier quoted context omitted.

>>> Who could benefit indirectly from the breach? This and who will buy those data ? Everybody scream about the hack but I've never found a comprehensive study over how these personal data are sold, abused. Maybe to break gazillions of FaceBook/github/you-name-it accounts ? Then what, who will use those data ? Thieves ? Criminals ? If it's just that well, that's a minor inconvenience. If it's secret services of adver…

I don't have facts/pointers but just an educated guess. The most probable beneficiaries are food/gas etc., distributors. Pre Adhaar days they used to create fake ration/gas cards and sell food at un-subsidised prices in black market. A prime (purported) driver for Adhaar to stop creation of these ghost people. Now that ghost Adhaar accounts can be created (per the report) these distributors will get back to their old…

> ghost people

Classics. https://www.quora.com/How-exactly-does-the-scam-in-Nikolai-G...

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#122
post #75

Earlier quoted context omitted.

> I expected better discussion on HN (apart from sensationalist articles) There are three people across three different parts of the world who corroborate the report - CTO of a global technology group, a security based analyst and a professor of Computer Science. I wonder how this is "sensationalist". > "Having looked at the patch code and the report presented by Anand, I feel pretty comfortable saying that the repor…

> There are three people across three different parts of the world who corroborate the report - CTO of a global technology group, a security based analyst and a professor of Computer Science. I wonder how this is "sensationalist". Put out the patch in public domain or at least provide some technical information on the vulnerability itself (by making the said report public). Every time a story of this sort comes out i…

There's a professor in there too who verified it. Putting the patch out is going to see reporters being jailed and the story being buried. Especially when with the patch we will see 4chan like flaming and the database being filled up with bogus entries from all around the world.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#123
post #16

Unfortunately our government doesn't accept the truth. If someone tries to educate people about the vulnerability, they are labelled anti-national.

Ironic, considering the fact that protecting the privacy of citizens is in a nation's interest.

I need you to show your work on that one, guy.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#124
post #88
post #75

Earlier quoted context omitted.

> I expected better discussion on HN (apart from sensationalist articles) There are three people across three different parts of the world who corroborate the report - CTO of a global technology group, a security based analyst and a professor of Computer Science. I wonder how this is "sensationalist". > "Having looked at the patch code and the report presented by Anand, I feel pretty comfortable saying that the repor…

> There are three people across three different parts of the world who corroborate the report - CTO of a global technology group, a security based analyst and a professor of Computer Science. I wonder how this is "sensationalist". OP is not negating the problem. However, the title implies that the existing database has been breached, which is not true. Author could have given a better title which implies that ghost e…

The whole point of the system is to give a single confirmed Identity for citizens of India.

at this point the purpose of the exercise has been voided.

Saying that "the data has not been compromised" is a red herring, thats the case for when our biomterics are lost and our privacy breached which is a whole different issue with this database, one among many of its other problems.

At this point if the data is crud, whats the point of using this system?

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#125
post #119

I expected better discussion on HN (apart from sensationalist articles), the article does a poor job intentionally though. Summary 1. Existing data is not compromised 2. Duplicate data can't be entered or overwritten 3. BUT, ghost accounts can be created easily. Aadhar was introduced to fight ghost accounts who siphon off subsidies provided for poor. This hack/patch defeats that purpose. I still think this is not a b…

Two points:- 1. Surprise, there's a separate $10 application which can access all the Aadhar database entries. Exposed by one of the journalists of this story, for which she got a police case filed against her. [a] 2. Aadhar has no way to verify double entries, one whistleblower to Supreme Court said the database has 40% bogus entries, i.e. 450 Million fake IDs. Yes, no verification backup documents, no signup forms…

> 1. Surprise, there's a separate $10 application which can access all the Aadhar database entries. Exposed by one of the journalists of this story. [a]

Can the said journalist just release the application in public domain? If not, why not?

> 2. Aadhar has no way to verify double entries, one whistleblower to Supreme Court said the database has 40% bogus entries, i.e. 450 Million fake IDs. Yes, no verification backup documents, no signup forms exist for 40% entries in the database, and authority has no way to audit them. [b]

If authority has no way to audit them then how did the whistleblower arrive at this magical "40%" figure.

What's worse than the 40% figure is the way the entire letter is written. No way a professional would write a letter with all caps, typographical errors, paragraphs upon paragraphs of sensationalism with little to show for "proof". Even the table which shows the details of "AadhaarCount v/s Aadhaar Records" is not something available in public domain so it cannot be validated as authentic.

> Bonus: Aadhar database was at one time hosted in US with FTP password being Admin$12. This is the state of this sham project. https://imgur.com/a/2sppFrm

I have seen this crop up in every discussion but no where in the screenshot does it say that the data hosted in US was the "Aadhaar database". All this screenshot details is some files were hosted by the UIDAI team on a US based server to share among themselves. The files could be anything. In fact, the email itself says the files are flat files with names:

1. Bill_Desk

2. Total_EXP

How did you arrive at the fact that this is the Aadhaar database itself? I can easily assume that "Total_EXP" can mean total expenses and "Bill_Desk" to do something with bill desk. No where does it say "Aadhaar_DB" or something along those lines. This is laughable!

Also, this same screenshot exists in the so called "whistleblower's letter" to Supreme Court judges as well. There is no confirmation of any such correspondence by the Supreme Court judges about being in receipt of any such letter.

Sorry to say but the way the entire letter is written screams of fake news you typically forward through WhatsApp only to realise later that the entire story was fraudulent to begin with.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#126
post #122

Earlier quoted context omitted.

> There are three people across three different parts of the world who corroborate the report - CTO of a global technology group, a security based analyst and a professor of Computer Science. I wonder how this is "sensationalist". Put out the patch in public domain or at least provide some technical information on the vulnerability itself (by making the said report public). Every time a story of this sort comes out i…

There's a professor in there too who verified it. Putting the patch out is going to see reporters being jailed and the story being buried. Especially when with the patch we will see 4chan like flaming and the database being filled up with bogus entries from all around the world.

Professor means nothing. I know a lot of professors who have plagiarised to obtain PhDs. So I would never accept a professor's word to technical details.

> Putting the patch out is going to see reporters being jailed and the story being buried

That's a ridiculous assertion. Wasn't a reporter from Tribune already booked for spreading the same nonsense a while back? Why so? Because she was unable to provide any evidence for the said software that could gain access to UIDAI database.

If you are going to be worried about being arrested then don't get into journalism. Journalism is all about taking risks. By putting out the patch in public domain the reporters are actually going to get immunity from arrests as everyone will know the facts and any arrest by the government would be seen in a negative light. Right now, the reporters have a higher probability of being arrested for indulging in spreading false information, to their own detriment.

> Especially when with the patch we will see 4chan like flaming and the database being filled up with bogus entries from all around the world.

What better proof of breach than having the entire database filled with bogus entries? That should make it amply clear to everyone involved including the public that the system is not secure. What is surprising is that reporters use the garb of national security when it pleases them. You can't have it both ways. If you truly believe in national security and that the entire database is compromised and that there is no way to fix the problem without fundamental change to the system then release the patch. Withholding the patch is detrimental to national security as you are deliberately allowing nefarious activities to take place unchecked and unhindered.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#127
The biometric scanners probably have big security holes too. In fact, it won't surprise me if the JTAG is left enabled and anyone can read/write the firmware!

Aadhaar needs something like TrustRank or a Web Of Trust where identity and citizenship isn't binary but a continuous number (probability) based on who and how many vouch for your identity. A lot of citizens, especially in rural areas, aren't documented very well. It's best to acknowledge that uncertainty in the system and deal with it.

The public discussion around Aadhaar is very confused. There's hardly anything wrong with a universal ID for every citizen. There are already several in India (Driving License, Passport, Voter's ID, PAN card, etc.). The real privacy issue is around (a) the govt. collecting biometric data, and (b) how much the govt. / third-party service provider learns about you when you authenticate your identity using Aadhaar. The UIDAI doesn't even want to discuss the issue in the open ("trust us, your data is secure. No proof of hacking whatsoever."), and the use of non-open-source software and closed biometric hardware is troubling. If biometric scanners are using proper encryption, who holds the keys? (My guess, the manufacturers have it, and lots of people who shouldn't have it do have it). What's needed is consensus building, maybe through a public consultation, about what the majority of people are willing to disclose to the govt. Biometric isn't an absolute necessity for Aadhaar to achieve it's stated goals. That said, recent polls show that the percentage of Indians who trust their govt. is way higher than in the west, so the govt. can probably get what it wants while playing nice.

There's also very little discussion about how secure the biometrics are. There's no info about what services are considered sensitive and need more than a fingerprint. Fingerprints maybe fine for 5 years, but I have a hard time believing they'll be constant enough for secure identity verification over 80 years. What happens when biometric fails and a significant chunk of the populace can't sign, don't remember their date-of-birth or any password, or even their full name? Again, something like a web of trust would've been helpful.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#128
This is a true story -

I went to a regional passport office to get my Aadhar card about 2 years ago. I sat in front of a desk with an employee - she was logged in to a website to that let her upload my picture/biometrics and info into the Aadhar system. The desk had a post-it 3 feet away from me with the login username/password written on it.

Since the operators also need to verify biometrically to login, that alone wouldn't be enough to hack it. But if you think about the general level of understanding of IT among the public, and probably even the people who wrote the software, its pretty unsurprising to see it hacked.

Even so, I don't think its really possible for a huge entity like the government (or even a large company) to learn all the practices around security/technology without making mistakes and learning under situations with real consequences. As long as they learn from these mistakes and accept failure, rather than trying to cover them up, we will get there in time.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#129
post #119

Earlier quoted context omitted.

Two points:- 1. Surprise, there's a separate $10 application which can access all the Aadhar database entries. Exposed by one of the journalists of this story, for which she got a police case filed against her. [a] 2. Aadhar has no way to verify double entries, one whistleblower to Supreme Court said the database has 40% bogus entries, i.e. 450 Million fake IDs. Yes, no verification backup documents, no signup forms…

> 1. Surprise, there's a separate $10 application which can access all the Aadhar database entries. Exposed by one of the journalists of this story. [a] Can the said journalist just release the application in public domain? If not, why not? > 2. Aadhar has no way to verify double entries, one whistleblower to Supreme Court said the database has 40% bogus entries, i.e. 450 Million fake IDs. Yes, no verification backup…

>Can the said journalist just release the application in public domain? If not, why not?

Pretty simple. Do you want everyone in the world to have access to the database? Now at least it is hidden through obscurity. This is exactly why in this report the said journalist got it verified by three external experts, one of them a professor.

>If authority has no way to audit them then how did the whistleblower arrive at this magical "40%" figure.

Authority has no way to audit the fake accounts, authority does know for which entries backup documentation exists or not. In fact, he attaches official documentation later on as an evidence.

Forget the grammar, typos it doesn't matter. Ignore the whole of his letter except the official correspondence that is attached and does in fact validate his/her point.

I meant to write Aadhar data. So you are totally over loooking the fact that some of the Aadhar related data was on US servers, and more importantly the password is being relayed over E-mail? Also, no secure way to host the government data, except HP servers?

Government has been so opaque regarding this project that we have to rely on journalists, researchers and whistleblowers to help us with any sliver of info.

Do you have a conflict on interest with this project? I see on your Twitter that you have retweeted some posts from Ministry overlooking this project. Not casting doubt, just needing a clarification due to the tone of your posts in this thread. Sounds very government'ish.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#130
post #129

Earlier quoted context omitted.

> 1. Surprise, there's a separate $10 application which can access all the Aadhar database entries. Exposed by one of the journalists of this story. [a] Can the said journalist just release the application in public domain? If not, why not? > 2. Aadhar has no way to verify double entries, one whistleblower to Supreme Court said the database has 40% bogus entries, i.e. 450 Million fake IDs. Yes, no verification backup…

>Can the said journalist just release the application in public domain? If not, why not? Pretty simple. Do you want everyone in the world to have access to the database? Now at least it is hidden through obscurity. This is exactly why in this report the said journalist got it verified by three external experts, one of them a professor. >If authority has no way to audit them then how did the whistleblower arrive at th…

> Pretty simple. Do you want everyone in the world to have access to the database? Now at least it is hidden through obscurity. This is exactly why in this report the said journalist got it verified by three external experts, one of them a professor.

Don't you think this is pretty convenient an excuse? The report is also not in public domain nor is the exploit. We have to just rely on a journalist, a CTO, a professor and another person as "proof". Meltdown and Spectre are way more serious exploits as it affects pretty much the entire World and it was disclosed but this exploit is supposedly so much more heinous that it cannot be disclosed.

> Do you have a conflict on interest with this project? I see on your Twitter that you have retweeted some posts from Ministry overlooking this project. Not casting doubt, just needing a clarification due to the tone of your posts in this thread. Sounds very government'ish.

It always sounds government'ish to people who rely on conspiracy theories. I am an open supporter of the Government in many policies. As far as conflict of interest with this project I am no way connected to the UIDAI project. So don't try to find connections where there are none.

> I see on your Twitter that you have retweeted some posts from Ministry overlooking this project.

I haven't retweeted anything to do with Aadhaar. The retweets are GST related and another one to do with AI. It's ridiculous to assert that just because I support the government and I retweet some of the policy decisions I end up becoming a supporter of Aadhaar. Don't forget that Aadhaar was formulated and ratified by the previous government. Also, I dislike Nandan Nilekani for how he handled implementation of GST and Aadhaar itself. If at all there is something Aadhaar seriously lacks: it is proper communication with the people about how data is stored and stupid decisions by the UIDAI to link Aadhaar for anything and everything (including the recent one with requiring Aadhaar for sending posts overseas). I don't support such ridiculous decisions.

> Forget the grammar, typos it doesn't matter. Ignore the whole of his letter except the official correspondence that is attached and does in fact validate his/her point.

I am rational in my thinking and approach. When I see fake news I call it out. You relied on it not me.

> Authority has no way to audit the fake accounts, authority does know for which entries backup documentation exists or not. In fact, he attaches official documentation later on as an evidence.

Which official document? There is nothing in the letter that is "official document". Even the table that he mentions is not available in public domain to authenticate. I can create a table myself and call it "official document". Would that be sufficient evidence in the court of law?

Also, if such a letter was indeed written, why haven't any Supreme Court judge confirmed receipt of such a letter?

> I meant to write Aadhar data. So you are totally over loooking the fact that some of the Aadhar related data was on US servers, and more importantly the password is being relayed over E-mail? Also, no secure way to host the government data, except HP servers?

You are assuming a lot here. There is no indication that the data on the US servers was Aadhaar related.

> Government has been so opaque regarding this project that we have to rely on journalists, researchers and whistleblowers to help us with any sliver of info.

No it's the other way around. The journalists, researchers and whistleblowers are the ones who are being opaque with their findings. At the end of the day, if you find a loophole, it's your responsibility to make it known to the public if the Government refuses to acknowledge it. Media is the fourth arm of democracy for a reason. If you know that the Government is deliberately trying to hide details of exploits from the public, it automatically becomes your responsibility to disclose the exploit itself. By withholding the details of the exploit, you are strengthening the hands of nefarious non-state actors because they know that the Government would turn away and reporters would never expose. You release the exploit in the public domain, it automatically creates pressure on the Government and force it to either fix the issue or accept responsibility.

Post reply on HN