its kind of weird that they call the vulnerability itself "a patch" I can be pedantic too and can see how there isn't really a distinction between an exploit and a patch as they both modify the software, but thats a weird colloquialism right?
India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm
61–70 of 163 posts
Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm
#62I don't know how many times this will have to be repeated. Aadhar, GST, all implemented by the worst possible companies in terms of talent. WTF is wrong here, there are plenty of talented people around. Or just crowdsource it or give it to the universities to build or something.
Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm
#63No surprises that the database was compromised. Aadhar is a fundamentally flawed system and nothing will ever be done about it.
Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm
#64I expected better discussion on HN (apart from sensationalist articles), the article does a poor job intentionally though. Summary 1. Existing data is not compromised 2. Duplicate data can't be entered or overwritten 3. BUT, ghost accounts can be created easily. Aadhar was introduced to fight ghost accounts who siphon off subsidies provided for poor. This hack/patch defeats that purpose. I still think this is not a b…
Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm
#65Earlier quoted context omitted.
Do You think Times group, India Today and others will report this? They don't have backbone to do that. Maybe You should read the article first, before commenting.
And why do you think exactly that they or any other news agency won't report if such an incidence has occurred?
[1]https://en.wikipedia.org/wiki/Radia_tapes_controversy#Media_...
Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm
#66I expected better discussion on HN (apart from sensationalist articles), the article does a poor job intentionally though. Summary 1. Existing data is not compromised 2. Duplicate data can't be entered or overwritten 3. BUT, ghost accounts can be created easily. Aadhar was introduced to fight ghost accounts who siphon off subsidies provided for poor. This hack/patch defeats that purpose. I still think this is not a b…
It _is_ a big problem, because apart from the ones you mentioned above, it is unclear how many more vulnerabilities are possible.
Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm
#67Time and Time again Aadhar's privacy data have been compromised and Yet, Officials have strongly denied all those claims - only possible because still people believe all the false claims by those officials and government in terms of Aadhar. Even to the level that a guy once wrote a scraper (opensourced on github) that can fetch Aadhar info online. It's no doubt that Aadhar was a blatant copy of bringing an SSN-type I…
Aadhar is nothing like SSN. I wish it was. SSN doesn’t require biometrics — Aadhar takes fingerprints and iris scans. School kids don’t need SSNs to sit for their school boards. You can sit for university exams without SSNs. You can shop at Amazon without giving them your SSN[1]. [1] https://news.ycombinator.com/item?id=15796242 In fact SSN use has become more restricted over time, thanks to various pieces of privacy…
Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm
#68As an Indian developer, I cringe every time the government claims a system is un-hackable. Especially when contracts are handed to one of the big Indian IT companies. Having started my career in one of those companies, I saw firsthand how most of the development process was just filling in gaps. Security through obscurity was thought to be “highly secure” and security experts were non existent. No surprises that the…
Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm
#69As an Indian developer, I cringe every time the government claims a system is un-hackable. Especially when contracts are handed to one of the big Indian IT companies. Having started my career in one of those companies, I saw firsthand how most of the development process was just filling in gaps. Security through obscurity was thought to be “highly secure” and security experts were non existent. No surprises that the…
In Aadhar enrollment centers, passwords are shared. You might like to introduce an OTP like concept, but phones are shared too. 2FA? nice try, but then people also share answers to security questions. Next what? DNA authentication? Biometrics? guess what none of those are any where near reliable and they are mostly identity related things and not authentication related things.
There is also government policy. Which is lapse. Mostly run by civil servants who understand nothing about technology. IAS is largely a trivia testing exam with focus on things like meeting and group discussion skills. The head of UIDAI recently claimed that data could not have been possible stolen as the data was still in their database :)
This is a phenomenal lapse at every level.
Software is one thing, but if your people have decided to work around it, its basically all over.