Asia

UIDAI denies reported security lapse in Aadhaar project

A woman goes through the process of finger scanning for the Unique Identification database system, also known as Aadhaar, at a registration centre in New Delhi

open view web desk

NEW DELHI – The semi-government agency behind Indiaโ€™s national identity card project on Saturday denied a report by news website ZDNet that the programme has been hit by another security lapse that allows access to private information.

ZDNet reported that a data leak on a system run by a state-owned utility company, which it did not name, could allow access to private information of holders of the biometric โ€œAadhaarโ€ ID cards, exposing their names, their unique 12-digit identity numbers, and their bank details.

But the Unique Identification Authority of India (UIDAI), which runs the Aadhaar programme, said โ€œthere is no truth in this storyโ€ and that they were โ€œcontemplating legal action against ZDNetโ€.

ZDNet could not immediately be contacted for comment on the UIDAIโ€™s response.

โ€œThere has been absolutely no breach of UIDAIโ€™s Aadhaar database. Aadhaar remains safe and secure,โ€ the agency said in a statement late on Saturday.

โ€œEven if the claim purported in the story were taken as true, it would raise security concerns on database of that utility company and has nothing to do with the security of UIDAIโ€™s Aadhaar database,โ€ it said.

MORE THAN BILLION USERS

ZDNet had reported that even though the security lapse had been flagged to some government agencies over a period of time, it has yet to be fixed. It said it was withholding the name of the utility and other details.

Karan Saini, a New Delhi-based security researcher, said that anyone with an Aadhaar number was affected.

โ€œThis is a security lapse. You donโ€™t have to be a consumer to access these details. You just need the Uniform Resource Locator where the Application Programming Interface is located. These can be found in less than 20 minutes,โ€ Saini told Reuters.

In recent months researchers and journalists who have identified loopholes in the identity project have said they have been slapped with criminal cases or harassed by government agencies because of their work.

Aadhaar, a biometric identification card with over 1.1 billion users, is the worldโ€™s biggest database.

But it has been facing increased scrutiny over privacy concerns following several instances of breaches and misuse.

Last Thursday, the CEO of the UIDAI said the biometric data attached to each Aadhaar was safe from hacking as the storage facility was not connected to the internet.

โ€œEach Aadhaar biometric is encrypted by a 2048-key combination and to decode it, the best and fastest computer of our era will take the age of the universe just to hack into one cardโ€™s biometric details,โ€ Ajay Bhushan Pandey said.

Reuters


Discover more from THE OPEN VIEW

Subscribe to get the latest posts sent to your email.

Categories: Asia

Tagged as: , , ,

Leave a Reply