Live data from Hacker News

India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

huffingtonpost.in

41–50 of 163 posts

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#43
post #25

Earlier quoted context omitted.

Not a lot: https://en.wikipedia.org/wiki/Countries_applying_biometrics There are restrictions on how vast this database is allowed to be and what all it can be linked to, in most cases.

I live in Spain and they take your fingerprint when they make your ID card. I'm pretty sure that goes into a database, so they have the fingerprints of all citizens.

Same in Sweden, but in the UK there’s no national database of citizens, and therefore no fingerprints associated.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#44

Earlier quoted context omitted.

Kindly understand this article seems to come out of investigative journalism where the author seemed to have gotten hold of the patch presumably by paying 2500 and then did in-person research to create the article. Once published, other newsrooms usually do their own pieces if they find it relevant. Since this article has just been published (only 2 hours ago at the time of writing this comment), I wouldn't refute th…

You've actually reworded what I have already said. Since there is no official statement from UIDAI or multiple private news sources reporting the same incidence; this article/blog is not worth believing yet.

On the contrary. This was _investigated_ by a reporter(s) from the mentioned source and published. Other news publications need to verify it independently before publishing it themselves.

And on the "official statements" part, it's kind of naive to expect that they (UIDAI) would put out any statement given that in the past they have

- Not acknowledged security issues or made any efforts to do their own investigation in spite of the numerous reports

- Turned hostile towards entities who have exposed or reported weaknesses instead of rewarding them and plugging the loopholes

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#45
post #37

Earlier quoted context omitted.

You are assuming this is unintentional. Giving bureaucrats and criminals working with them power through incompetence of the central government ... forgive me for doubting that this was a design feature. It redivides the power between individuals and the state, including criminals working with (small parts of) the state. I believe anyone who can get a majority of 1.3 billion people to vote for him did not miss this.…

>States are evil. The best possible case is that they might be, at times, the lesser evil. Calm down there American.

I am European. Just because it's a less popular opinion, it's not any less true.

I don't even understand the logic itself. States are supposedly not evil, and we need them because ... well because people are more evil. That's the idea.

But states are people. Isn't that by itself a massive contradiction ?

The difference between, say, the Netherlands and Monsanto is the method of incorporation, and the legal authority it therefore has. Not the resulting decisions. That's, of course why the Netherlands got rich by having it's military protect and pay raping pirates, in trade for their loot, including of course, if they had to sell the passengers to prostitution houses and mines, and still does things like extracting money from it's poorest citizens through mental health "care".

Monsanto merely mass-poisons people.

But the big difference is:

1) the dutch state has never apologized

2) has never paid any restitution to anyone

3) never will

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#46

It is hard to believe by relying on just one source. I just checked other news sources in India, and no one has any news about any recent Aadhaar breach.

Did you read the article? It's not about a "Aadhar breach" in the sense of data being stolen. The news is about a software hack that has been doing the rounds among operators that allows them to compromise the aadhar database by introducing duplicate or weaker biometric information.

"The patch lets a user bypass critical security features such as biometric authentication of enrolment operators to generate unauthorised Aadhaar numbers.

The patch disables the enrolment software's in-built GPS security feature (used to identify the physical location of every enrolment centre), which means anyone anywhere in the world — say, Beijing, Karachi or Kabul — can use the software to enrol users.

The patch reduces the sensitivity of the enrolment software's iris-recognition system, making it easier to spoof the software with a photograph of a registered operator, rather than requiring the operator to be present in person."

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#48
Indian government site asking for aadhar data in Bihar:

http://210.212.23.57/online/OnlineApply/Notice.aspx

They just made aadhar mandatory for every school kid in Mumbai Maharashtra. Good luck to anyone who has to share share their childrens details on an insecure platform.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#49
post #29

Off topic: I simply can't find how to opt out of tracking on HuffPost. I get a GDPR popup and the opting out path leads endless cycles (with occasional captcha solving).

I just keep using browser extensions like uBlock and Ghostery (caveat: it seems they also have a "we sell your data" opt-out) and every GDPR pop-up I just click "OK", knowing the extensions will block them. (Honestly, more believing than knowing, so maybe I'm not the best person to talk to about protecting data...)

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#50

If I get it: India has a biometric database with 1B people on it! ... wow ... just wow ... And adding new people to it is now compromised by a publically available hack, although getting 1B biometrics on board must have had an error rate that would be scary anyway. The UUID created is needed almost everywhere, like driving license numbers elsewhere. How much of the scare is "People can be added once but under incorre…

without any hack, one person can be enrolled multiple times if it is done from different zones (mandal/district). There are brokers who can arrange this (and ofcourse charge upto 5k INR)

I guess the search is only limited to these zones.

Post reply on HN