Live data from Hacker News

India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

huffingtonpost.in

21–30 of 163 posts

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#21

If I get it: India has a biometric database with 1B people on it! ... wow ... just wow ... And adding new people to it is now compromised by a publically available hack, although getting 1B biometrics on board must have had an error rate that would be scary anyway. The UUID created is needed almost everywhere, like driving license numbers elsewhere. How much of the scare is "People can be added once but under incorre…

There is a court case pending judgement in the Supreme Court on the "needed almost everywhere" part. The judgement is expected soon. https://www.bloombergquint.com/aadhaar/2018/03/21/the-key-ar...

The ability to add people is problematic - once you have unverified additions, you can't trust whether even real biometrics were used for it, so it wouldn't even necessarily show up as a duplicate.

Search: Biometrics matching has a lot of failures (5% of 1billion is still a huge number).

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#22
post #20

If I get it: India has a biometric database with 1B people on it! ... wow ... just wow ... And adding new people to it is now compromised by a publically available hack, although getting 1B biometrics on board must have had an error rate that would be scary anyway. The UUID created is needed almost everywhere, like driving license numbers elsewhere. How much of the scare is "People can be added once but under incorre…

Maybe I'm in the wrong here, but I imagine most civilised countries have a database with biometrics of all of its citizens, at least fingerprints.

Not a lot: https://en.wikipedia.org/wiki/Countries_applying_biometrics

There are restrictions on how vast this database is allowed to be and what all it can be linked to, in most cases.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#23
post #20

If I get it: India has a biometric database with 1B people on it! ... wow ... just wow ... And adding new people to it is now compromised by a publically available hack, although getting 1B biometrics on board must have had an error rate that would be scary anyway. The UUID created is needed almost everywhere, like driving license numbers elsewhere. How much of the scare is "People can be added once but under incorre…

Maybe I'm in the wrong here, but I imagine most civilised countries have a database with biometrics of all of its citizens, at least fingerprints.

Biometric collection is always for specific purpose. General purpose, compulsory biometric ids exist only in Malaysia IIRC.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#24

It is hard to believe by relying on just one source. I just checked other news sources in India, and no one has any news about any recent Aadhaar breach.

Do You think Times group, India Today and others will report this? They don't have backbone to do that. Maybe You should read the article first, before commenting.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#25
post #20

Earlier quoted context omitted.

Maybe I'm in the wrong here, but I imagine most civilised countries have a database with biometrics of all of its citizens, at least fingerprints.

Not a lot: https://en.wikipedia.org/wiki/Countries_applying_biometrics There are restrictions on how vast this database is allowed to be and what all it can be linked to, in most cases.

I live in Spain and they take your fingerprint when they make your ID card. I'm pretty sure that goes into a database, so they have the fingerprints of all citizens.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#27
Time and Time again Aadhar's privacy data have been compromised and Yet, Officials have strongly denied all those claims - only possible because still people believe all the false claims by those officials and government in terms of Aadhar. Even to the level that a guy once wrote a scraper (opensourced on github) that can fetch Aadhar info online.

It's no doubt that Aadhar was a blatant copy of bringing an SSN-type ID in India but failed terribly as the Government was more interested using Aadhar to show their domination rather than put it for actual purpose. Eg: Govt made Aadhar mandatory for Tax filing, India's Top Supreme Court denied. The same thing happened in many instances.

This is a nice lesson, why simply coping a solution from the US can't be made to work in a developing nation because the system and officials are so fragile that they need to be first fixed than the solution itself!

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#28

> In 2017, the UIDAI said it had blacklisted 49,000 enrolment centres for various violations, and in February 2018, the UIDAI terminated all contracts with common service centres as well. Seems like they are well aware of this hack. Skimming through the article, it seems the attacker can register himself in the system but not read data from the system. Also, there's no mention of 1.2B records being compromised.

Actually, the records are already public, remember the fiasco where Telecom Regulatory Authority of India’s Chairman RS Sharma had posted his Aadhar number online. The whole point of the Aadhar Challenge was to demonstrate leaked database/Aadhar number is not an issue. Apart from the curated datasets that can be bought even on Facebook groups, it is actually very easy to mine large datasets from Google itself.

Any references on this topic?

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#30

It is hard to believe by relying on just one source. I just checked other news sources in India, and no one has any news about any recent Aadhaar breach.

Do You think Times group, India Today and others will report this? They don't have backbone to do that. Maybe You should read the article first, before commenting.

And why do you think exactly that they or any other news agency won't report if such an incidence has occurred?
Post reply on HN