Live data from Hacker News

India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

huffingtonpost.in

31–40 of 163 posts

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#31

It is hard to believe by relying on just one source. I just checked other news sources in India, and no one has any news about any recent Aadhaar breach.

Kindly understand this article seems to come out of investigative journalism where the author seemed to have gotten hold of the patch presumably by paying 2500 and then did in-person research to create the article. Once published, other newsrooms usually do their own pieces if they find it relevant. Since this article has just been published (only 2 hours ago at the time of writing this comment), I wouldn't refute the article just on the basis of this criteria. I would usually wait for 1-2 days before using the above criterion to evaluate the article.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#32

Earlier quoted context omitted.

That is answered in the article > B. Regunath, a software architect who led the team at Mindtree that worked on the project, said a web-based enrolment software for Aadhaar was not practical at the time because many parts of the country had very poor Internet connectivity. Of course, anyone who put id generating software on these laptops with the expectation that it would somehow remain secret was being extremely foo…

Even then, they could have batched the requests for IDs on the laptop, and then submitted them daily/weekly by driving the laptop to wherever the internet is. And of course, each such laptop must have a unique hardware key that would sign these requests, so copying the software wouldn't compromise anything.

In a country of the scale of India, if your security relies on no laptop being compromised, you have no security. One is bound to be lost or stolen (or its user to accept bribes).

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#33

It is hard to believe by relying on just one source. I just checked other news sources in India, and no one has any news about any recent Aadhaar breach.

Kindly understand this article seems to come out of investigative journalism where the author seemed to have gotten hold of the patch presumably by paying 2500 and then did in-person research to create the article. Once published, other newsrooms usually do their own pieces if they find it relevant. Since this article has just been published (only 2 hours ago at the time of writing this comment), I wouldn't refute th…

You've actually reworded what I have already said. Since there is no official statement from UIDAI or multiple private news sources reporting the same incidence; this article/blog is not worth believing yet.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#34

Earlier quoted context omitted.

Actually, the records are already public, remember the fiasco where Telecom Regulatory Authority of India’s Chairman RS Sharma had posted his Aadhar number online. The whole point of the Aadhar Challenge was to demonstrate leaked database/Aadhar number is not an issue. Apart from the curated datasets that can be bought even on Facebook groups, it is actually very easy to mine large datasets from Google itself.

Any references on this topic?

I don't want to post any direct link to anything but you are google 'Aadhaar data leak through Google search' to vast amounts of links/references. Kinda Meta right, I know. If you want to know more about the incident you can google 'aadhaar challenge'.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#35
Well if we needed one more datapoint on why government shouldn’t get involved in computer security then here we have it. Politicians don’t get technology - they believe they can order any design they can imagine and that it’ll just work.

Secondly, I’ve worked with hundreds of Indian IT engineers. I’ve yet to meet one who didnt subscribe to the view that ‘the solution to all problems can be coded in software’ - maybe it’s just how they are educated at uni.

However, put them next to politicians and you get a real recipe for disaster.

So what next? Those who claimed they could make this system secure should pay a HEAVY price. There really isn’t a humane punishment strong enough - I’d go as far as firing them; stripping them of any retirement benefits and banning them from any paid position in the public sector.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#37

Is this complete incompetence? Why wouldn't they generate these numbers on some centralized secured servers only for the verified individuals? Why give away the software that generates them at all? That's like giving away your signing servers.

You are assuming this is unintentional. Giving bureaucrats and criminals working with them power through incompetence of the central government ... forgive me for doubting that this was a design feature. It redivides the power between individuals and the state, including criminals working with (small parts of) the state. I believe anyone who can get a majority of 1.3 billion people to vote for him did not miss this.…

>States are evil. The best possible case is that they might be, at times, the lesser evil.

Calm down there American.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#38
I have to admire the courage of the people who have investigated and reported this, given that the entire leadership of UIDAI and its backers in the central government are intolerant of any criticism and have been known to file police complaints[1] against journalists, critics and whistleblowers. Even its visionary and leading cheerleader from the private sector preferred to imagine conspiracies rather than acknowledging its weaknesses [2].

[1]: https://thewire.in/tech/uidai-files-fir-tribune-reporter-aad...

[2]: https://timesofindia.indiatimes.com/india/theres-an-orchestr...

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#39
post #20

If I get it: India has a biometric database with 1B people on it! ... wow ... just wow ... And adding new people to it is now compromised by a publically available hack, although getting 1B biometrics on board must have had an error rate that would be scary anyway. The UUID created is needed almost everywhere, like driving license numbers elsewhere. How much of the scare is "People can be added once but under incorre…

Maybe I'm in the wrong here, but I imagine most civilised countries have a database with biometrics of all of its citizens, at least fingerprints.

In the Anglosphere we've traditionally been quite wary of national ID databases for our own citizens, for better or worse.

Most governments of foreign countries I have visited (US, many parts of Asia) have my fingerprints. The Australian government doesn't (to my knowledge, anyway).

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#40
its kind of weird that they call the vulnerability itself "a patch"

I can be pedantic too and can see how there isn't really a distinction between an exploit and a patch as they both modify the software, but thats a weird colloquialism right?

Post reply on HN