Bengaluru: 31-yr-old techie arrested for accessing Aadhaar data

coastaldigest.com news network
August 4, 2017

Bengaluru, Aug 4: Bengaluru city police has arrested a young techie on the charge of accessing Aadhaar data following a complaint filed by the Unique Identification Authority of India (UIDAI) last week.

The arrested is Abhinav Srivastav, 31, an IIT-Kharagpur graduate, who is currently employed by ANI Technologies, which owns the Ola brand, as a software development engineer. He has been accused of accessing Aadhaar information in January 2017 through an app named ‘Aadhaar e-KYC’, which was available on the Google Play store till recently.

Police said Srivastav had developed five apps and made ₹40,000 from advertisements displayed on them. Police are now scanning all his apps to see whether more violations were committed. The Aadhaar e-KYC app was downloaded over 50,000 times from the Google Play store since its launch in January, the police said.

City Police Commissioner T. Suneel Kumar said that based on the complaint, six teams of police comprising 26 personnel were formed to nab Srivastav and they tracked him down to Koramangala after a week. He has been accused of using the services of another app, ‘e-hospital’, which is listed as an authenticated user agency (AUA) authorised to access UIDAI data.

A senior police officer said there were around 400 entities that have been authorised to access the data for authentication. Srivastav’s company was not among those authorised.

A native of Kanpur, Srivastav completed his M.Sc. in Industrial Chemistry from IIT-Kharagpur and joined a private firm in 2010 as a security researcher. He launched Qarth technologies in 2012 and shut it down in 2016 owing to financial reasons. In March 2016, Ola announced that it had acquired Qarth and its mobile payments product, X-Pay. Srivastav then joined another private firm before joining ANI Technologies last year.

Investigation revealed that the e-hospital company is not aware of his activities. However, further probe is on to ascertain the facts.

The ability of a software engineer to bypass strict protocols set in place by the UIDAI to access critical data puts the spotlight firmly on the security measures employed to protect Aadhaar data.

Police investigation have revealed that Srivastav had piggy-backed on the infrastructure of another app for hacking the data base.

“Aadhaar related information, legally housed by the National Informatics Centre server, was illegally and without authorisation accessed and used to support this mobile application,” said the police statement.

Srivastav, in order to give his ‘Aadhaar e-KYC’ app an air of authenticity, hacked into the server of the NIC, which houses the e-hospital system, which is a solution for government hospitals to handle patient care and other services, including medical records management.

As part of its regulations, the UIDAI accords certain agencies the title of an AUA, which can then provide Aadhaar-enabled services to the cardholder. For authentication, these agencies have to connect to the Central Identities Data Repository (CIDR) through the services of a Authentication Service Agency (ASA). ASAs are bound by regulations that stipulate encryption of data and logging of access.

The 'e-hospital’ platform had access as a registered AUA. Srivastav used this server to route his app requests for data access and managed to steal the data, the police said.

Question raised

In 2016, a paper titled ‘Privacy and Security of Aadhaar: A Computer Science Perspective’ by the Computer Science and Engineering Department of IIT-Delhi raised the question of leakage of Aadhaar number from an AUA.

The paper, which also discusses several other possible threat scenarios, said, “This, however, does not fully mitigate the risks and the possibility of leakage of the Aadhaar number from an AUA, either from the database, or during “Know Your Customer” (KYC) processes, or even during availing services, cannot be ruled out. In particular, there appear to be no safeguards or even guidelines, either technical or legal, on how the Aadhaar number should be maintained and used by various AUAs in a cryptographically secure way, and how to prevent the Aadhaar number of an individual from becoming public.”

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
May 4,2024

Mangaluru, May 4: The Mangaluru International Airport was besieged with a harrowing message of terror recently, when an email, purportedly from malevolent elements, menacingly declared the planting of bombs within the airport premises. 

Addressed to the office of the airport authority, the missive, steeped in ominous overtones, bore the ominous signature of a terrorist faction, ominously named 'Terrorizers 111'.

The communication, disseminated in English, ominously detailed the clandestine emplacement of explosives in areas eluding facile detection, accompanied by a chilling warning of their imminent detonation. The threat, ominously looming over not only the infrastructure but also the airborne vessels, portended a catastrophic deluge of bloodshed and loss.

In response to this dire communiqué, airport authorities swiftly engaged the apparatus of law enforcement, dispatching urgent alerts to the vigilant guardians of public safety. Acting upon the dictates of higher echelons, a formal dossier of this menacing correspondence was meticulously compiled, cloaked in the veil of confidentiality to thwart any premature dissemination.

Mangaluru International Airport found itself in grim camaraderie with more than 30 counterparts under the aegis of the Airport Authority of India (AAI) and private domains, all recipients of this chilling electronic diatribe. A comprehensive net of precautionary measures was swiftly cast, fortifying the bastions of security in anticipation of any nefarious designs lurking within the shadows.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
May 5,2024

karkare.jpg

Maharashtra Leader of Opposition Vijay Namdevrao Wadettiwar waded into controversy after he alleged that an RSS-affiliated cop, and not terrorist Ajmal Kasab, killed former state anti-terrorism squad (ATS) chief Hemant Karkare during the 26/11 Mumbai terror attack.

In a video statement released on Saturday, the Congress leader alleged that the bullet that killed IPS officer Hemant Karkare did not come from the gun of Ajmal Kasab or any of the other nine Pakistani terrorists involved in the attacks.

Instead, he claimed it came from the weapon of a police officer allegedly "dedicated to" the Rashtriya Swayamsevak Sangh (RSS).

Wadettiwar also accused Ujjwal Nikam, the special public prosecutor in the case and a BJP Lok Sabha candidate from Mumbai North Central, of suppressing this information, labeling him a "traitor."

He questioned the BJP's decision to nominate Nikam for the Lok Sabha polls, accusing the party of protecting traitors.

“During the probe, key information was out. However, it was suppressed by Ujjwal Nikam, who is a traitor. My question is, why is BJP protecting a traitor and nominating such a person for Lok Sabha polls? By doing this, BJP is protecting traitors," Wadettiwar alleged, Times of India reported.

These allegations drew strong responses from Nikam and Deputy Chief Minister Devendra Fadnavis.

Nikam condemned Wadettiwar's statement as "baseless and irresponsible," expressing pain at the doubts raised over his integrity.

He emphasized the legal steps taken to convict Kasab, calling Wadettiwar's remarks an insult to the victims of the 26/11 attacks.

“What a reckless statement is being made. I am pained by such baseless allegations, raising doubts over my integrity. It clearly reflects the level of electoral politics. I never thought politicians will stoop to such low levels. For political gain? He (Wadettiwar) is insulting not me, but the 166 departed souls and all persons injured in the 26/11 attacks," Nikam said.

He added, “They (Congress) hold Kasab as innocent. Even Pakistan had accepted that Kasab was involved in the conspiracy and in the terror attack on India and was guilty".

He said Indians very well know the legal steps he had taken to ensure Kasab’s conviction.

Nikam said citizens of the nation would on 4 June, the day of results for Lok Sabha polls, give their reply to such allegations, adding he wished not to dignify the “desperate disinformation” with a further response.

Meanwhile, BJP leader and Deputy CM Fadnavis said, “Our alliance is with Nikam, while Congress has joined hands with Kasab".

Shiv Sena spokesperson Kiran Pawaskar said NIA should arrest Wadettiwar and ask him why he was defending Kasab.

Pawaskar criticized the Congress for allegedly supporting terrorists and expressed surprise at the silence of Shiv Sena chief Uddhav Thackeray on the matter.

“From Wadettiwar’s statement, it appears Congress is supporting terrorists who attacked Mumbai. More shocking is the fact that Sena (UBT) chief Uddhav Thackeray has maintained silence over the episode,” he said.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
May 8,2024

covid.jpg

AstraZeneca said on Tuesday it had initiated the worldwide withdrawal of its COVID-19 vaccine due to a "surplus of available updated vaccines" since the pandemic.

The company also said it would proceed to withdraw the vaccine Vaxzevria's marketing authorizations within Europe.

"As multiple, variant Covid-19 vaccines have since been developed there is a surplus of available updated vaccines," the company said, adding that this had led to a decline in demand for Vaxzevria, which is no longer being manufactured or supplied.

According to media reports, the Anglo-Swedish drugmaker has previously admitted in court documents that the vaccine causes side-effects such as blood clots and low blood platelet counts.

The firm's application to withdraw the vaccine was made on March 5 and came into effect on May 7, according to the Telegraph, which first reported the development.

London-listed AstraZeneca began moving into respiratory syncytial virus vaccines and obesity drugs through several deals last year after a slowdown in growth as COVID-19 medicine sales declined.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.