Live data from Hacker News

India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

huffingtonpost.in

71–80 of 163 posts

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#71
post #29

Off topic: I simply can't find how to opt out of tracking on HuffPost. I get a GDPR popup and the opting out path leads endless cycles (with occasional captcha solving).

Works for me, don't know if my savior is uBlock Origin, uMatrix, or I Don't Care About Cookies...

https://github.com/gorhill/uBlock

https://github.com/gorhill/uMatrix

https://www.i-dont-care-about-cookies.eu/

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#72
post #55

Earlier quoted context omitted.

In the Anglosphere we've traditionally been quite wary of national ID databases for our own citizens, for better or worse. Most governments of foreign countries I have visited (US, many parts of Asia) have my fingerprints. The Australian government doesn't (to my knowledge, anyway).

Any Australian with a driver's license or passport most definitely has their facial biometrics stored. Any visitor to the country also is subject to it. This has been in existence for over a decade and I'm astonished people aren't aware of that.

Right, I do know that (The Capability(tm)!) and for some reason I just mentally exclude facial recognition from the term "biometrics". OP specifically said "at least fingerprints" - it's good to have a reminder that facial biometrics still count as biometrics too, and they're lower on the hierarchy than fingerprints.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#73
post #68
post #63

As an Indian developer, I cringe every time the government claims a system is un-hackable. Especially when contracts are handed to one of the big Indian IT companies. Having started my career in one of those companies, I saw firsthand how most of the development process was just filling in gaps. Security through obscurity was thought to be “highly secure” and security experts were non existent. No surprises that the…

This happens in every country, not just India. And the database has not been compromised.

> And the database has not been compromised.

The database is not known to be compromised.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#74

I expected better discussion on HN (apart from sensationalist articles), the article does a poor job intentionally though. Summary 1. Existing data is not compromised 2. Duplicate data can't be entered or overwritten 3. BUT, ghost accounts can be created easily. Aadhar was introduced to fight ghost accounts who siphon off subsidies provided for poor. This hack/patch defeats that purpose. I still think this is not a b…

> Can't the Aadhar DB (post enrollment) be scanned for all enrolled iris data with poor quality iris data and they be monitored and deleted ?

Not so easy. Every effort that's made to reduce fraud (false positives), might affect genuine beneficiaries who depend on the system for food, healthcare and education - by increasing exclusion (false negatives). A probabilistic auth platform with a really wide scope is a recipe for failure.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#75

I expected better discussion on HN (apart from sensationalist articles), the article does a poor job intentionally though. Summary 1. Existing data is not compromised 2. Duplicate data can't be entered or overwritten 3. BUT, ghost accounts can be created easily. Aadhar was introduced to fight ghost accounts who siphon off subsidies provided for poor. This hack/patch defeats that purpose. I still think this is not a b…

> I expected better discussion on HN (apart from sensationalist articles)

There are three people across three different parts of the world who corroborate the report - CTO of a global technology group, a security based analyst and a professor of Computer Science. I wonder how this is "sensationalist".

> "Having looked at the patch code and the report presented by Anand, I feel pretty comfortable saying that the report is correct, and it could allow someone to circumvent security measures in the Aadhaar software, and create new entries. This is pretty feasible, and looks like something that would be possible to engineer," Wallach said.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#76
One of the reasons why India needs some kind of people authentication is rampant corruption! Corruption at a scale that most of people in Europe or US cant even imagine. Add to it the culture which celebrates corruption and eulogizes people who find loopholes in system. As soon as a policy or rule is implement, someone gets to work to find a loophole and profit. Schemes and subsidies for poor get siphoned by rich and powerful by creating fake people, less than 2% of citizen's pay taxes by just disappearing in records, billions of dollars of unnamed properties exist because owners are fake people on record, someone else appears for exam on a student.

While I still dislike citizen's database, I can also see why some kind of person authenticator is needed for country like India. I sat through UIDAI architects presentations, and from what I could tell that substantial thought was given to design. So while I maintain skepticism for such database, I also believe India needs some way authenticate various transactions (monetary or otherwise). SSN is a joke, at least Aadhaar was given substantial thought.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#77

I have to admire the courage of the people who have investigated and reported this, given that the entire leadership of UIDAI and its backers in the central government are intolerant of any criticism and have been known to file police complaints[1] against journalists, critics and whistleblowers. Even its visionary and leading cheerleader from the private sector preferred to imagine conspiracies rather than acknowled…

This can't be upvoted enough. The organization which outsources critical authentication to CIA-MI6 linked companies, and yet find the courage to indulge in the Orwellian-doublespeak of 'nationalism' is something that needs grave attention.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#78
post #37

Earlier quoted context omitted.

>States are evil. The best possible case is that they might be, at times, the lesser evil. Calm down there American.

I am European. Just because it's a less popular opinion, it's not any less true. I don't even understand the logic itself. States are supposedly not evil, and we need them because ... well because people are more evil. That's the idea. But states are people. Isn't that by itself a massive contradiction ? The difference between, say, the Netherlands and Monsanto is the method of incorporation, and the legal authority…

You picked one of the countries with the most evil government (historically, I make no claim either way about the current situation) as an example. Of course it's going to look bad in that case.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#79
post #53

According to the article the database has not been compromised. It's a compromise of the client which can be used to add new Aadhar entries.

A compromise in this case being that illegitimate entries are being added when they should not be able to. You don’t need write to consider this specific case broken.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#80
post #69
post #63

As an Indian developer, I cringe every time the government claims a system is un-hackable. Especially when contracts are handed to one of the big Indian IT companies. Having started my career in one of those companies, I saw firsthand how most of the development process was just filling in gaps. Security through obscurity was thought to be “highly secure” and security experts were non existent. No surprises that the…

No amount of 'security' will help here. That's because every one including the people don't give a dime about 'security' in India. In Aadhar enrollment centers, passwords are shared. You might like to introduce an OTP like concept, but phones are shared too. 2FA? nice try, but then people also share answers to security questions. Next what? DNA authentication? Biometrics? guess what none of those are any where near r…

Apparently, the bill passed in the Indian Parliament does not limit the right of the state apparatus to 'bio-authenticate' you. A scientist at CSIR apparently blurted out earlier that DNA authentication was under consideration. The amount of money spent on this BS project is absurd.
Post reply on HN