Aadhaar data security - a hot topic since the introduction of the framework back in 2009 - is once again in the news. A three-month-long investigation claims to have uncovered a software patch that compromises the security of the data stored in Aadhaar identity database.

The patch, which isn't developed formally by the Unique Identification Authority of India (UIDAI), allegedly allows hackers to generate unauthorised Aadhaar numbers by disabling the security features of the official Aadhaar enrolment software. It is said to come at a one-time charge of as low as Rs. 2,500 and is reportedly already used by many enrolment operators across the country.

The new hack is believed to have its roots in the decision that UIDAI took back in 2010 to speed up the enrolment process by opening it for private operators. Notably, the report highlighting the fresh Aadhaar patch emerges just ahead of the launch of face recognition facility by the Aadhaar-issuing body. The facility will bring face recognition in addition to iris and fingerprint scan to verify users.

HuffPost India is claiming to have gained access to the patch that has been verified by multiple experts. The patch is said to let a user bypass critical security features as biometric authentication of enrolment operators and disables the enrolment software's pre-installed GPS security feature that is used to help UIDAI identify the physical location of enrolment centres. The removal of the GPS requirement would allow patch users to generate numbers from anywhere in the world.

Further, the unofficial patch reportedly reduces the sensitivity of the iris-recognition system of the enrolment software, allowing a photograph of a registered operator to be used for authentication. All this makes it easier for anyone who has access to the patch to generate Aadhaar numbers "at will".

"Whomever [sic] created the patch was highly motivated to compromise Aadhaar," said Gustaf Björksten, Chief Technologist at Access Now, as quoted by HuffPost India. Björksten was among the analysts who analysed the patch. According to the report, the patch came into circulation in early 2017. Björksten added that the patch was the work of more than one coder.

At the time of opening Aadhaar registrations through private enrolment operators in 2010, UIDAI brought a standardised enrolment software called the Enrolment Client Multi-Platform (ECMP). The software needs to be installed on each enrolment computer. Björksten noted the decision to offer an installation package instead of giving a cloud-based solution to private enrolment operators put the critical components of Aadhaar at risk.

This also eventually opened the avenue for a hack like the latest patch that is reportedly working on top of the enrolment software, and was created by "grafting code from older versions of Aadhaar enrolment software - which had fewer security features - onto newer versions of the software".

The HuffPost India team says that the Aadhaar patch (along with the usernames and passwords needed to access UIDAI's enrolment gateway) can be procured thousands from WhatsApp groups, and it comes at a charge of Rs. 2,500. It can be installed just as any other software on a computer, and by changing certain Java libraries using cut-paste commands.

Once installed, the patch reportedly helps enrolment operators to abandon the use of their fingerprints to access the enrolment software. It is also said to disable the GPS and reduce the sensitivity of the iris scanner as well as extends to the duration of each login session. Since the patch enables private operators to use the enrolment software without using their fingerprints, a single operator can log into multiple machines simultaneously. This helps reduce the cost per enrolment and thus increasing its adoption among enrolment operators who are reportedly paid as little as Rs. 30 per enrolment.

The report cites a former Aadhaar enrolment operator to say that other operators were using the patch to privately create Aadhaar entries for a higher fee, between Rs. 100 and Rs. 500. The operator was also cited to say he'd written to UIDAI CEO and others to inform them about the ongoing illegal access. The patch is reportedly still effective, and other out-of-work operators have colluded with sources in authorised Aadhaar centres to "complete the registration process for a fee."

The new software patch, doesn't giving read access to the Aadhaar database, but instead enables the addition of new information to the Aadhaar system. This means that using the patch, fake identities could be added to the Aadhaar database. "If anybody is able to create an entry in the Aadhaar database, then potentially the person can create multiple Aadhaar cards. Then the same person can siphon off rations of multiple people," said Rajendran Narayanan, Assistant Professor, Azim Premji University, Bengaluru, as quoted by HuffPost India.

HuffPost India claims that it provided a copy of the patch to National Critical Information Infrastructure Protection Centre (NCIIPC) earlier this year, but the government body that is the nodal agency responsible for Aadhaar security declined to share its findings. UIDAI also didn't respond to the communication made before publishing the development. Moreover, some evidence of the mass-usage of the patch can be seen from the YouTube videos showing "ecmp bypass" tutorials.

We've reached out to UIDAI for clarity on the patch and also emailed a questionnaire to UIDAI CEO to understand the future steps to ensure legit registrations. We'll update this space accordingly.

UIDAI is currently working on a face recognition facility that was delayed in the recent past. The facility is aimed to bolster security by verifying users through facial recognition alongside iris and fingerprint scan.

Courtesy: ndtv.com

Let the Truth be known. If you read VB and like VB, please be a VB Supporter and Help us deliver the Truth to one and all.



Bengaluru (PTI): Alleging a “criminal conspiracy” by BJP candidate D N Jeevaraj in the Sringeri Assembly poll recounting, Karnataka CM Siddaramaiah on Tuesday said the outcome was manipulated after valid postal ballot votes in favour of Congress leader T D Raje Gowda were tampered with during the recounting process.

Following a Karnataka High Court order on an election petition filed by Jeevaraj, challenging Raje Gowda’s election, the reverification and recounting were conducted on Saturday.

After the reverification and recount of postal ballots for the Sringeri Assembly constituency, votes polled in favour of Raje Gowda were reduced by 255, the returning officer said.

A report on the matter has been submitted to the Election Commission of India for further action, the officer added.

Congress leader Raje Gowda had won the 2023 Assembly polls from Sringeri by 201 votes, defeating his nearest rival Jeevaraj.

Addressing a press conference in Bengaluru, Siddaramaiah said the High Court had directed the recounting of postal ballots and that irregularities were noticed during the exercise conducted on May 2.

“This is a clear case of criminal conspiracy,” Siddaramaiah said, alleging that valid votes cast in favour of Raje Gowda were altered after being accepted by counting agents of all parties, including Congress, BJP, and JD(S).

He claimed that during the recounting of postal ballots, 255 votes were initially accepted as valid by all agents but were later tampered with by subordinate officials.

“There is a second mark on the votes polled in favour of Raje Gowda. They had accepted these as valid votes. Subsequently, another mark was made by officials. This is a clear case of criminal conspiracy,” he said.

When asked who was behind the alleged conspiracy, the CM replied, “It was hatched by Jeevaraj and others. It is planned.”

Siddaramaiah further alleged that the returning officer acted improperly by declaring the result despite the presence of an Election Commission observer during the recounting.

“Immediately after the counting, the returning officer announced the result. He should not have done so; this is against the law,” he said.

He pointed out that Raje Gowda had originally won by 201 votes, but after the recounting, the BJP candidate was declared the winner by 52 votes.

“The BJP has committed a criminal act of conspiracy. This is not vote chori but vote dacoity,” he alleged.

The CM said a police complaint had already been filed by Raje Gowda’s election agent, Sudhir Kumar, and emphasised the need for electoral integrity.

“We want transparency and free and fair elections. That is what our Constitution mandates,” he added.

Stating that the government would pursue legal remedies, Siddaramaiah said, “We are preparing an appeal challenging the returning officer’s announcement in a court of law.”

Responding to a separate query on elections in other states, the CM said there appeared to be an anti-incumbency factor in West Bengal, while results in Tamil Nadu were “surprising,” adding that Vijay’s party was emerging as the largest there.

Following the victory of party candidates in Bagalkote and Davanagere South, Siddaramaiah expressed confidence about future electoral prospects in Karnataka.

“Even in 2028, we will win the Assembly elections. We will come back,” the CM said.

Siddaramaiah added that he would order a forensic examination into the alleged tampering of postal ballots.