Live data from Hacker News

India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

huffingtonpost.in

151–160 of 163 posts

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#151

Earlier quoted context omitted.

Aadhar is not a client side authentication, what is client side even mean in this context ?

Please read TFA: "The patch lets a user bypass critical security features such as biometric authentication of enrolment operators to generate unauthorised Aadhaar numbers." The client here is the enrollment software, not "Aadhar" (whatever you meant by that). The Aadhar service should haven been authenticating enrollment operators on the server side, instead of relying on the enrollment software to verify identity (t…

Then why does the article claim that aadhar is hacked. why not just call it as aadhar enrollment hacked (which is more appropriate title).

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#152

Earlier quoted context omitted.

> Pretty simple. Do you want everyone in the world to have access to the database? Now at least it is hidden through obscurity. This is exactly why in this report the said journalist got it verified by three external experts, one of them a professor. Don't you think this is pretty convenient an excuse? The report is also not in public domain nor is the exploit. We have to just rely on a journalist, a CTO, a professor…

>> Do you have a conflict on interest with this project? It's weird that you wrote a detailed point-by-point response to the parent post but dropped this one question.

Now I see why you might have had that doubt. My reply was flagged for no apparent reason.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#153
post #69
post #63

As an Indian developer, I cringe every time the government claims a system is un-hackable. Especially when contracts are handed to one of the big Indian IT companies. Having started my career in one of those companies, I saw firsthand how most of the development process was just filling in gaps. Security through obscurity was thought to be “highly secure” and security experts were non existent. No surprises that the…

No amount of 'security' will help here. That's because every one including the people don't give a dime about 'security' in India. In Aadhar enrollment centers, passwords are shared. You might like to introduce an OTP like concept, but phones are shared too. 2FA? nice try, but then people also share answers to security questions. Next what? DNA authentication? Biometrics? guess what none of those are any where near r…

[deleted]

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#154
post #2

Govt should recover $1 Billion from Nilekani

He definitely has a very arrogant tone about aadhaar as well as his another body shop company.

This massive massive data leak could cost Indian citizens very dearly. Everything is being forced to link with aadhaar.

If some digital lord in future decides to colonize people in few secs, I believe Indian shores and as well as people sitting in capital might provide a very lucrative proposition!

I just hope it isn't Jio! Jio phone itself has very intrusive OS!

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#155
post #88

Earlier quoted context omitted.

> There are three people across three different parts of the world who corroborate the report - CTO of a global technology group, a security based analyst and a professor of Computer Science. I wonder how this is "sensationalist". OP is not negating the problem. However, the title implies that the existing database has been breached, which is not true. Author could have given a better title which implies that ghost e…

The whole point of the system is to give a single confirmed Identity for citizens of India. at this point the purpose of the exercise has been voided. Saying that "the data has not been compromised" is a red herring, thats the case for when our biomterics are lost and our privacy breached which is a whole different issue with this database, one among many of its other problems. At this point if the data is crud, what…

Actually, having an Aadhar number does not imply that the person is a citizen - this is one of the statements present in the application form itself. So, it is possible for non-citizens to have an Aadhar number.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#156

Earlier quoted context omitted.

Please read TFA: "The patch lets a user bypass critical security features such as biometric authentication of enrolment operators to generate unauthorised Aadhaar numbers." The client here is the enrollment software, not "Aadhar" (whatever you meant by that). The Aadhar service should haven been authenticating enrollment operators on the server side, instead of relying on the enrollment software to verify identity (t…

Then why does the article claim that aadhar is hacked. why not just call it as aadhar enrollment hacked (which is more appropriate title).

While more specific titles are better for descriptive purposes, the title as it is is not wrong. The name "Aadhaar" does not unequivocally mean "The Aadhaar service backend".

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#157
post #111

Earlier quoted context omitted.

I mean, you need a client to access it, and presumably having a patch for such means you have the client too...

aadhar card operators get paid 30ruppees an hour. i'm sure you can get access to a client pretty easily

It’s actually even better. There is no server side authentication on the application. And this keygen type of crack removes the client side authentication too. Full firehose access.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#158

I have to admire the courage of the people who have investigated and reported this, given that the entire leadership of UIDAI and its backers in the central government are intolerant of any criticism and have been known to file police complaints[1] against journalists, critics and whistleblowers. Even its visionary and leading cheerleader from the private sector preferred to imagine conspiracies rather than acknowled…

you link anything to `thewire.in`, I would call it propaganda. The other commenter on the thread asked a question about why can't the said journalist back up the claims about a $10 app. Hate the govt all you want, but the Aadhar as you know is started by previous govt. It is if designed properly a good way to eradicate corruption for welfare schemes, so any ideas on how to do that are more appreciated than playing bl…

Calling it a propaganda is a bit too much. However, their quality of articles has decreased considerably:

https://thewire.in/caste/does-india-need-a-caste-based-quota...

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#159
post #155

Earlier quoted context omitted.

The whole point of the system is to give a single confirmed Identity for citizens of India. at this point the purpose of the exercise has been voided. Saying that "the data has not been compromised" is a red herring, thats the case for when our biomterics are lost and our privacy breached which is a whole different issue with this database, one among many of its other problems. At this point if the data is crud, what…

Actually, having an Aadhar number does not imply that the person is a citizen - this is one of the statements present in the application form itself. So, it is possible for non-citizens to have an Aadhar number.

So Aadhar is meant for the whole world including our neighbouring citizens (and Intelligence agencies) of Pakistan and China ? Thank you for educating me, I didn't know that. Its truly wonderful and neighbourly that they get the convenience of self-registration without providing proof and customizing their bio-metrics during upload. Only Indian citizens should be held to a higher standard.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#160
post #150
post #115

Earlier quoted context omitted.

You mean security experts were found all around, but patted themselves on the back after preventing a single SQL injection attack.

A single SQL Injection has pretty huge potential, specially if its in an application that deals with sensitive data. I would not downplay it.

I completely agree. But it is the absolute basic level at which you start to secure your application.

I’d expect security experts working on a government ID program to be a bit more distinguished.

Post reply on HN