Live data from Hacker News

India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

huffingtonpost.in

61–70 of 163 posts

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#61

its kind of weird that they call the vulnerability itself "a patch" I can be pedantic too and can see how there isn't really a distinction between an exploit and a patch as they both modify the software, but thats a weird colloquialism right?

It sounds to me like a game crack which are basically patches since they make the software concerned more user friendly.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#62
post #56

I don't know how many times this will have to be repeated. Aadhar, GST, all implemented by the worst possible companies in terms of talent. WTF is wrong here, there are plenty of talented people around. Or just crowdsource it or give it to the universities to build or something.

I want to say that maybe the really talented people / good companies have no interest in building a central database with such dystopian potential. But then again... fb, twitter, ...

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#63
As an Indian developer, I cringe every time the government claims a system is un-hackable. Especially when contracts are handed to one of the big Indian IT companies. Having started my career in one of those companies, I saw firsthand how most of the development process was just filling in gaps. Security through obscurity was thought to be “highly secure” and security experts were non existent.

No surprises that the database was compromised. Aadhar is a fundamentally flawed system and nothing will ever be done about it.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#64

I expected better discussion on HN (apart from sensationalist articles), the article does a poor job intentionally though. Summary 1. Existing data is not compromised 2. Duplicate data can't be entered or overwritten 3. BUT, ghost accounts can be created easily. Aadhar was introduced to fight ghost accounts who siphon off subsidies provided for poor. This hack/patch defeats that purpose. I still think this is not a b…

It _is_ a big problem, because apart from the ones you mentioned above, it is unclear how many more vulnerabilities are possible.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#65

Earlier quoted context omitted.

Do You think Times group, India Today and others will report this? They don't have backbone to do that. Maybe You should read the article first, before commenting.

And why do you think exactly that they or any other news agency won't report if such an incidence has occurred?

Not related to the topic under discussion, but see the media blackout during the Radia Tapes Controversy[1]

[1]https://en.wikipedia.org/wiki/Radia_tapes_controversy#Media_...

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#66
post #64

I expected better discussion on HN (apart from sensationalist articles), the article does a poor job intentionally though. Summary 1. Existing data is not compromised 2. Duplicate data can't be entered or overwritten 3. BUT, ghost accounts can be created easily. Aadhar was introduced to fight ghost accounts who siphon off subsidies provided for poor. This hack/patch defeats that purpose. I still think this is not a b…

It _is_ a big problem, because apart from the ones you mentioned above, it is unclear how many more vulnerabilities are possible.

Isnt that true for every system?

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#67
post #27

Time and Time again Aadhar's privacy data have been compromised and Yet, Officials have strongly denied all those claims - only possible because still people believe all the false claims by those officials and government in terms of Aadhar. Even to the level that a guy once wrote a scraper (opensourced on github) that can fetch Aadhar info online. It's no doubt that Aadhar was a blatant copy of bringing an SSN-type I…

Aadhar is nothing like SSN. I wish it was. SSN doesn’t require biometrics — Aadhar takes fingerprints and iris scans. School kids don’t need SSNs to sit for their school boards. You can sit for university exams without SSNs. You can shop at Amazon without giving them your SSN[1]. [1] https://news.ycombinator.com/item?id=15796242 In fact SSN use has become more restricted over time, thanks to various pieces of privacy…

watch this (https://www.youtube.com/watch?v=Erp8IAUouus) and tell me if SSN is good for even US?

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#68
post #63

As an Indian developer, I cringe every time the government claims a system is un-hackable. Especially when contracts are handed to one of the big Indian IT companies. Having started my career in one of those companies, I saw firsthand how most of the development process was just filling in gaps. Security through obscurity was thought to be “highly secure” and security experts were non existent. No surprises that the…

This happens in every country, not just India. And the database has not been compromised.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#69
post #63

As an Indian developer, I cringe every time the government claims a system is un-hackable. Especially when contracts are handed to one of the big Indian IT companies. Having started my career in one of those companies, I saw firsthand how most of the development process was just filling in gaps. Security through obscurity was thought to be “highly secure” and security experts were non existent. No surprises that the…

No amount of 'security' will help here. That's because every one including the people don't give a dime about 'security' in India.

In Aadhar enrollment centers, passwords are shared. You might like to introduce an OTP like concept, but phones are shared too. 2FA? nice try, but then people also share answers to security questions. Next what? DNA authentication? Biometrics? guess what none of those are any where near reliable and they are mostly identity related things and not authentication related things.

There is also government policy. Which is lapse. Mostly run by civil servants who understand nothing about technology. IAS is largely a trivia testing exam with focus on things like meeting and group discussion skills. The head of UIDAI recently claimed that data could not have been possible stolen as the data was still in their database :)

This is a phenomenal lapse at every level.

Software is one thing, but if your people have decided to work around it, its basically all over.

Post reply on HN