Live data from Hacker News

India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

huffingtonpost.in

51–60 of 163 posts

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#51
post #27

Time and Time again Aadhar's privacy data have been compromised and Yet, Officials have strongly denied all those claims - only possible because still people believe all the false claims by those officials and government in terms of Aadhar. Even to the level that a guy once wrote a scraper (opensourced on github) that can fetch Aadhar info online. It's no doubt that Aadhar was a blatant copy of bringing an SSN-type I…

Aadhar is nothing like SSN. I wish it was. SSN doesn’t require biometrics — Aadhar takes fingerprints and iris scans. School kids don’t need SSNs to sit for their school boards. You can sit for university exams without SSNs. You can shop at Amazon without giving them your SSN[1].

[1] https://news.ycombinator.com/item?id=15796242

In fact SSN use has become more restricted over time, thanks to various pieces of privacy legislation. Meanwhile in India they still don’t have any privacy legislation last I checked, so it’s open season on your data.

Aadhar is ambitious all right — an attempt to assign every every Indian resident a number and use that number as a unique key for almost everything (public or private). The surveillance opportunities this presents is breathtaking.

Of course the good folk at India Stack love this because it enables them to build better apps. Move fast and break things, indeed.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#52
post #29

Off topic: I simply can't find how to opt out of tracking on HuffPost. I get a GDPR popup and the opting out path leads endless cycles (with occasional captcha solving).

HuffPost works without javascript. Use Quick Javascript Switcher or similar extension and disable js for the whole site.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#54
post #16

Unfortunately our government doesn't accept the truth. If someone tries to educate people about the vulnerability, they are labelled anti-national.

Ironic, considering the fact that protecting the privacy of citizens is in a nation's interest.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#55
post #20

Earlier quoted context omitted.

Maybe I'm in the wrong here, but I imagine most civilised countries have a database with biometrics of all of its citizens, at least fingerprints.

In the Anglosphere we've traditionally been quite wary of national ID databases for our own citizens, for better or worse. Most governments of foreign countries I have visited (US, many parts of Asia) have my fingerprints. The Australian government doesn't (to my knowledge, anyway).

Any Australian with a driver's license or passport most definitely has their facial biometrics stored. Any visitor to the country also is subject to it.

This has been in existence for over a decade and I'm astonished people aren't aware of that.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#56
I don't know how many times this will have to be repeated. Aadhar, GST, all implemented by the worst possible companies in terms of talent. WTF is wrong here, there are plenty of talented people around. Or just crowdsource it or give it to the universities to build or something.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#58
post #53

According to the article the database has not been compromised. It's a compromise of the client which can be used to add new Aadhar entries.

Yeah, that means a lot of false data has been added into the system given how widely this patched client has been circulated. I don't know what about this tells you that the database hasn't been compromised?

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#59
I expected better discussion on HN (apart from sensationalist articles), the article does a poor job intentionally though.

Summary

1. Existing data is not compromised

2. Duplicate data can't be entered or overwritten

3. BUT, ghost accounts can be created easily.

Aadhar was introduced to fight ghost accounts who siphon off subsidies provided for poor. This hack/patch defeats that purpose.

I still think this is not a big problem as it looks on surface, if Enrollment software is hacked to accept iris data from photograph,

Can't the Aadhar DB (post enrollment) be scanned for all enrolled iris data with poor quality iris data and they be monitored and deleted ?

Another problem is still there, what if the operators enroll citizens from a different country as indians, essentially creating ghost accounts (from citizens of different country). i dont know how to stop such a situation.

Biometrics is never a good model for authentication, i dont know what these people were think when they designed it.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#60

Apparently the breach is now being proxied by the fired private operators through government offices. Can this cashless money flow be traced? Even burner mobile phone numbers are linked to the same compromised national identity database. Who could benefit indirectly from the breach? Could the Indian government turn to Facebook and WhatsApp for help with identity profiling? Is Facebook Indian data held in Indian data…

>>> Who could benefit indirectly from the breach?

This and who will buy those data ?

Everybody scream about the hack but I've never found a comprehensive study over how these personal data are sold, abused. Maybe to break gazillions of FaceBook/github/you-name-it accounts ? Then what, who will use those data ? Thieves ? Criminals ? If it's just that well, that's a minor inconvenience.

If it's secret services of adversary powers, well, that's a whole lot different.

Anybody has facts on that ?

Post reply on HN