Live data from Hacker News

India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

huffingtonpost.in

91–100 of 163 posts

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#91

It is hard to believe by relying on just one source. I just checked other news sources in India, and no one has any news about any recent Aadhaar breach.

> I just checked other news sources in India, and no one has any news about any recent Aadhaar breach.

here you go

NDTV

https://gadgets.ndtv.com/internet/news/aadhaar-software-patc...

It is on the front page.

It takes mainstream sources a while to react to news. In 24-48 hours, all mainstream newspapers will have the news.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#92
post #84

I have to admire the courage of the people who have investigated and reported this, given that the entire leadership of UIDAI and its backers in the central government are intolerant of any criticism and have been known to file police complaints[1] against journalists, critics and whistleblowers. Even its visionary and leading cheerleader from the private sector preferred to imagine conspiracies rather than acknowled…

This is one of the main reasons that this report doesn’t touch upon read access of the database. Rachna Khaira, one of the reporters already has a police case against her for her previois reporting on Aadhar database compromise. Getting even one user record would have landed all three journalists behind bars. It is left for the reader to conclude, and validated by various experts, that whole database is hacked. If a…

Btw, 4 months ago the UIDAI had completely denied of existence of such a patch calling it as "totally baseless, false, misleading, and irresponsible" [0].

[0] https://twitter.com/UIDAI/status/991907169779011584

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#93
post #69
post #63

As an Indian developer, I cringe every time the government claims a system is un-hackable. Especially when contracts are handed to one of the big Indian IT companies. Having started my career in one of those companies, I saw firsthand how most of the development process was just filling in gaps. Security through obscurity was thought to be “highly secure” and security experts were non existent. No surprises that the…

No amount of 'security' will help here. That's because every one including the people don't give a dime about 'security' in India. In Aadhar enrollment centers, passwords are shared. You might like to introduce an OTP like concept, but phones are shared too. 2FA? nice try, but then people also share answers to security questions. Next what? DNA authentication? Biometrics? guess what none of those are any where near r…

+1.

We also need to consider the motivations for working around 2FA or any such authentication systems. One is convenience as you've pointed out.

The other, much bigger motivation IMO, is opportunity to make money. As the article points out once enrolment was outsourced (Rs30/enrolment) it was immediately seen a money making venture so a whole bunch of these centres with dubious credentials surfaced. They were entrusted with document verification too so they would happily accept just about any piece of paper as proof of address. Then there was a business of charging desperate people money to create Adhaar account without which they wouldn't get subsidies.

And then they shut down (50,000 or so) these enrolment centres. Did they expect that all those employed at those centres who lost their jobs to not do anything about it!? Of course they would figure out ways to enrol people!!

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#94
post #76

One of the reasons why India needs some kind of people authentication is rampant corruption! Corruption at a scale that most of people in Europe or US cant even imagine. Add to it the culture which celebrates corruption and eulogizes people who find loopholes in system. As soon as a policy or rule is implement, someone gets to work to find a loophole and profit. Schemes and subsidies for poor get siphoned by rich and…

You can't fix one problem to create other ones.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#95

Indian government site asking for aadhar data in Bihar: http://210.212.23.57/online/OnlineApply/Notice.aspx They just made aadhar mandatory for every school kid in Mumbai Maharashtra. Good luck to anyone who has to share share their childrens details on an insecure platform.

> http://210.212.23.57/online/OnlineApply/Notice.aspx

HTTP. FFS.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#96
post #66
post #64

Earlier quoted context omitted.

It _is_ a big problem, because apart from the ones you mentioned above, it is unclear how many more vulnerabilities are possible.

Isnt that true for every system?

When a system is shown to have fundamental security flaws — this one uses client-side validation to authenticate biometric operators — it is natural one's trust in the system's robustness would drop low.

Like when Intel's chips were shown to completely disregard security when speculatively executing instructions, it wasn't just a new vulnerability; it was a whole class of vulnerabilities that was now open

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#97
post #76

One of the reasons why India needs some kind of people authentication is rampant corruption! Corruption at a scale that most of people in Europe or US cant even imagine. Add to it the culture which celebrates corruption and eulogizes people who find loopholes in system. As soon as a policy or rule is implement, someone gets to work to find a loophole and profit. Schemes and subsidies for poor get siphoned by rich and…

While this is true, the primary engine of corruption is the government and its agencies. Officials soliciting bribes to move paperwork forward, kickbacks to land projects etc.

An honest assault on corruption should target the government and parties rather than individual citizens. The work in that department seems to be going the other way though. e.g. https://www.thehindu.com/opinion/op-ed/the-danger-of-elector...

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#98
post #95

Indian government site asking for aadhar data in Bihar: http://210.212.23.57/online/OnlineApply/Notice.aspx They just made aadhar mandatory for every school kid in Mumbai Maharashtra. Good luck to anyone who has to share share their childrens details on an insecure platform.

> http://210.212.23.57/online/OnlineApply/Notice.aspx HTTP. FFS.

It's not like HTTPS would have helped much. It's an arbitrary IP address. How is a user supposed to verify an arbitrary IP address is not an attacker? This is what '.gov.in' is supposed to be for.

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#99
post #60

Apparently the breach is now being proxied by the fired private operators through government offices. Can this cashless money flow be traced? Even burner mobile phone numbers are linked to the same compromised national identity database. Who could benefit indirectly from the breach? Could the Indian government turn to Facebook and WhatsApp for help with identity profiling? Is Facebook Indian data held in Indian data…

>>> Who could benefit indirectly from the breach? This and who will buy those data ? Everybody scream about the hack but I've never found a comprehensive study over how these personal data are sold, abused. Maybe to break gazillions of FaceBook/github/you-name-it accounts ? Then what, who will use those data ? Thieves ? Criminals ? If it's just that well, that's a minor inconvenience. If it's secret services of adver…

I don't have facts/pointers but just an educated guess.

The most probable beneficiaries are food/gas etc., distributors. Pre Adhaar days they used to create fake ration/gas cards and sell food at un-subsidised prices in black market.

A prime (purported) driver for Adhaar to stop creation of these ghost people. Now that ghost Adhaar accounts can be created (per the report) these distributors will get back to their old ways of making money.

India has lot of poor people so the threat vector isn't yet FB/github :-).

Re: India’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm

#100
post #66

Earlier quoted context omitted.

Isnt that true for every system?

When a system is shown to have fundamental security flaws — this one uses client-side validation to authenticate biometric operators — it is natural one's trust in the system's robustness would drop low. Like when Intel's chips were shown to completely disregard security when speculatively executing instructions, it wasn't just a new vulnerability; it was a whole class of vulnerabilities that was now open

Aadhar is not a client side authentication, what is client side even mean in this context ?
Post reply on HN