Live data from Hacker News

India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

huffingtonpost.in

81–90 of 163 posts

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#81
post #32

Earlier quoted context omitted.

Even then, they could have batched the requests for IDs on the laptop, and then submitted them daily/weekly by driving the laptop to wherever the internet is. And of course, each such laptop must have a unique hardware key that would sign these requests, so copying the software wouldn't compromise anything.

In a country of the scale of India, if your security relies on no laptop being compromised, you have no security. One is bound to be lost or stolen (or its user to accept bribes).

You didn't read my comment well. The security in my scenario doesn't rely on the laptop not being stolen. There's a hardware key. If it gets stolen, it gets blacklisted.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#82
post #56

I don't know how many times this will have to be repeated. Aadhar, GST, all implemented by the worst possible companies in terms of talent. WTF is wrong here, there are plenty of talented people around. Or just crowdsource it or give it to the universities to build or something.

I want to say that maybe the really talented people / good companies have no interest in building a central database with such dystopian potential. But then again... fb, twitter, ...

Erm, Google, Microsoft, ... most of SV ?

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#83
Homepage of the Indian Army Careers page. http://joinindianarmy.nic.in/authentication.aspx

Try double clicking that CAPTCHA. This same code for "CAPTCHA" is used in dozens of official government websites.

None of this Aadhaar stuff is surprising.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#84

I have to admire the courage of the people who have investigated and reported this, given that the entire leadership of UIDAI and its backers in the central government are intolerant of any criticism and have been known to file police complaints[1] against journalists, critics and whistleblowers. Even its visionary and leading cheerleader from the private sector preferred to imagine conspiracies rather than acknowled…

This is one of the main reasons that this report doesn’t touch upon read access of the database. Rachna Khaira, one of the reporters already has a police case against her for her previois reporting on Aadhar database compromise. Getting even one user record would have landed all three journalists behind bars. It is left for the reader to conclude, and validated by various experts, that whole database is hacked. If a $5 tool can give you write access to a database, it is obvious whole database can be accessed too.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#85
post #76

One of the reasons why India needs some kind of people authentication is rampant corruption! Corruption at a scale that most of people in Europe or US cant even imagine. Add to it the culture which celebrates corruption and eulogizes people who find loopholes in system. As soon as a policy or rule is implement, someone gets to work to find a loophole and profit. Schemes and subsidies for poor get siphoned by rich and…

You seem to have sat through a presentation on Aadhaar. Have you sat through any presentations on corruption? On what basis are you making comparisons with other parts of the world?

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#86
post #53

According to the article the database has not been compromised. It's a compromise of the client which can be used to add new Aadhar entries.

Yeah, that means a lot of false data has been added into the system given how widely this patched client has been circulated. I don't know what about this tells you that the database hasn't been compromised?

The first thing that came to my mind when I read the title was that all the biometrics and all were out. Which would have been much worse and which is not the case.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#87
post #76

One of the reasons why India needs some kind of people authentication is rampant corruption! Corruption at a scale that most of people in Europe or US cant even imagine. Add to it the culture which celebrates corruption and eulogizes people who find loopholes in system. As soon as a policy or rule is implement, someone gets to work to find a loophole and profit. Schemes and subsidies for poor get siphoned by rich and…

someone gets to work to find a loophole and profit

Please - this is pretty much how it works everywhere, nothing unique to India.

Why do you think lawyers, accountants etc in the corporate world get paid so much? Do you remember the U.S president saying avoiding federal taxes makes him smart?

the culture which celebrates corruption

What are you basing this on? There is no question there is rampant corruption, but saying the culture celebrates it is taking it a bit far

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#88
post #75

I expected better discussion on HN (apart from sensationalist articles), the article does a poor job intentionally though. Summary 1. Existing data is not compromised 2. Duplicate data can't be entered or overwritten 3. BUT, ghost accounts can be created easily. Aadhar was introduced to fight ghost accounts who siphon off subsidies provided for poor. This hack/patch defeats that purpose. I still think this is not a b…

> I expected better discussion on HN (apart from sensationalist articles) There are three people across three different parts of the world who corroborate the report - CTO of a global technology group, a security based analyst and a professor of Computer Science. I wonder how this is "sensationalist". > "Having looked at the patch code and the report presented by Anand, I feel pretty comfortable saying that the repor…

> There are three people across three different parts of the world who corroborate the report - CTO of a global technology group, a security based analyst and a professor of Computer Science. I wonder how this is "sensationalist".

OP is not negating the problem. However, the title implies that the existing database has been breached, which is not true. Author could have given a better title which implies that ghost entries could be added and existing data has not been compromised.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#89
post #32

Earlier quoted context omitted.

In a country of the scale of India, if your security relies on no laptop being compromised, you have no security. One is bound to be lost or stolen (or its user to accept bribes).

You didn't read my comment well. The security in my scenario doesn't rely on the laptop not being stolen. There's a hardware key. If it gets stolen, it gets blacklisted.

It will not work in India. The whole problem is that the govt pissed off the operators and incentivized them to create fake aadhar. He whole investment to setup aadhar enrollment centre was marketed as a good business which will make people decent sum of money. But that was a very optimistic approximate. Reality turned out to be far more different. Almost all operators went into a loss. To recuperate the losses, they started creating fake aadhar. Money earned for genuine aadhar is Rs. 20, vs Rs. 500+ for a fake aadhar. It was stupid for operators to not exploit the opportunity.

In this scenario a hardware key is not going to help. It'll only limit the ubiquity of the hack, but not much else.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#90
post #27

Time and Time again Aadhar's privacy data have been compromised and Yet, Officials have strongly denied all those claims - only possible because still people believe all the false claims by those officials and government in terms of Aadhar. Even to the level that a guy once wrote a scraper (opensourced on github) that can fetch Aadhar info online. It's no doubt that Aadhar was a blatant copy of bringing an SSN-type I…

> Time and Time again Aadhar's privacy data have been compromised.

I hate the implementation of Aadhar as much as any person, and believe the architecture is terrible that a patch can allow authentication to be bypassed. And that there could be more vulnerabilities. However, at least in this instance, existing data has not been compromised.

Post reply on HN