Bengaluru: 31-yr-old techie arrested for accessing Aadhaar data

coastaldigest.com news network
August 4, 2017

Bengaluru, Aug 4: Bengaluru city police has arrested a young techie on the charge of accessing Aadhaar data following a complaint filed by the Unique Identification Authority of India (UIDAI) last week.

The arrested is Abhinav Srivastav, 31, an IIT-Kharagpur graduate, who is currently employed by ANI Technologies, which owns the Ola brand, as a software development engineer. He has been accused of accessing Aadhaar information in January 2017 through an app named ‘Aadhaar e-KYC’, which was available on the Google Play store till recently.

Police said Srivastav had developed five apps and made ₹40,000 from advertisements displayed on them. Police are now scanning all his apps to see whether more violations were committed. The Aadhaar e-KYC app was downloaded over 50,000 times from the Google Play store since its launch in January, the police said.

City Police Commissioner T. Suneel Kumar said that based on the complaint, six teams of police comprising 26 personnel were formed to nab Srivastav and they tracked him down to Koramangala after a week. He has been accused of using the services of another app, ‘e-hospital’, which is listed as an authenticated user agency (AUA) authorised to access UIDAI data.

A senior police officer said there were around 400 entities that have been authorised to access the data for authentication. Srivastav’s company was not among those authorised.

A native of Kanpur, Srivastav completed his M.Sc. in Industrial Chemistry from IIT-Kharagpur and joined a private firm in 2010 as a security researcher. He launched Qarth technologies in 2012 and shut it down in 2016 owing to financial reasons. In March 2016, Ola announced that it had acquired Qarth and its mobile payments product, X-Pay. Srivastav then joined another private firm before joining ANI Technologies last year.

Investigation revealed that the e-hospital company is not aware of his activities. However, further probe is on to ascertain the facts.

The ability of a software engineer to bypass strict protocols set in place by the UIDAI to access critical data puts the spotlight firmly on the security measures employed to protect Aadhaar data.

Police investigation have revealed that Srivastav had piggy-backed on the infrastructure of another app for hacking the data base.

“Aadhaar related information, legally housed by the National Informatics Centre server, was illegally and without authorisation accessed and used to support this mobile application,” said the police statement.

Srivastav, in order to give his ‘Aadhaar e-KYC’ app an air of authenticity, hacked into the server of the NIC, which houses the e-hospital system, which is a solution for government hospitals to handle patient care and other services, including medical records management.

As part of its regulations, the UIDAI accords certain agencies the title of an AUA, which can then provide Aadhaar-enabled services to the cardholder. For authentication, these agencies have to connect to the Central Identities Data Repository (CIDR) through the services of a Authentication Service Agency (ASA). ASAs are bound by regulations that stipulate encryption of data and logging of access.

The 'e-hospital’ platform had access as a registered AUA. Srivastav used this server to route his app requests for data access and managed to steal the data, the police said.

Question raised

In 2016, a paper titled ‘Privacy and Security of Aadhaar: A Computer Science Perspective’ by the Computer Science and Engineering Department of IIT-Delhi raised the question of leakage of Aadhaar number from an AUA.

The paper, which also discusses several other possible threat scenarios, said, “This, however, does not fully mitigate the risks and the possibility of leakage of the Aadhaar number from an AUA, either from the database, or during “Know Your Customer” (KYC) processes, or even during availing services, cannot be ruled out. In particular, there appear to be no safeguards or even guidelines, either technical or legal, on how the Aadhaar number should be maintained and used by various AUAs in a cryptographically secure way, and how to prevent the Aadhaar number of an individual from becoming public.”

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
February 24,2020

Bengaluru/Kodagu, Feb 24: Three days after the sloganeering by 19-year-old college student Amulya Leona Norohna at an anti-CAA rally and her subsequent arrest on charges of sedition kicked up a storm, Karnataka minister BC Patil on Sunday advocated central legislation that enables authorities “to shoot at sight” those chanting pro-Pakistan slogans.

Responding to reporters’ queries on the ongoing fracas over the chants, Patil said he would appeal to Prime Minister Narendra Modi to bring in a law so that anti-national elements are “killed on the spot”.

“The Centre must promulgate a law that enables authorities to shoot those who do anything that is seen as anti-national and chant pro-Pakistan slogans,” Patil said. “These elements must be killed on the spot. I am appealing to the PM, through the media now, to bring in such a law. I will also write to the PM.”

In Kodagu, Union minister for chemicals and fertilizer, DV Sadananda Gowda, echoed state home minister home minister Basavaraj Bommai’s line that stringent action will be taken against those indulging in anti-national activity, saying there will be “no mercy” for those taking a pro-Pakistan stance.

“The Union government will assist in the police investigation in Amulya,” he said. Gowda went on to claim that many anti-national organizations have been using CAA protests for political gain.

“We will curb such incidents forever. We will not allow such incidents to happen in future. Organisers of such rallies should be thoroughly questioned,” Gowda said.

Bommai on Saturday had also claimed the government will initiate action against educational institutions and hostels it they fail to act against students indulging in such activity.

“The government will discuss ways to prevent such incidents in colleges and hostels. We will instruct heads of educational institutions and hostel wardens to initiate action against such students. If they fail, the government will take action against them,” Bommai said, without defining what constitutes anti-national activity.

However, despite Congress saying there is no room for anti-national activity and stringent action must be taken against those indulging in such activity, former minister and senior functionary DK Shivakumar suggested he found nothing in Amulya’s background to suggest she is anti-national.

“Let me make it absolutely clear that the Congress party will not support any person or persons who hail another country and bring shame to India,” Shivakumar said. “However, I have seen the girl’s [Amulya’s] previous posts on social media and read her statements on various forums. She has been making statements on an ideological ground. Let us not jump the gun, but investigate exactly what she meant to say.”

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
coastaldigest.com news network
June 2,2020

Kasaragod, June 2: As Kerala commenced fresh academic year with online classes from Monday, a ninth-standard student at Malappuram district in North Kerala ended life allegedly owing to lack of online study facilities like television connection and a smartphone at her house.

Devika, daughter of Balakrishnan, hailing from a Dalit community at Valancherry, about 25 kilometres from Malappuram town, ended her life.

Balakrishnan told the media that he could not recharge the television connection owing to financial crunches. He was working as a daily wage worker and owing to COVID-19 and lockdown, he was not having much work these days. 

The family also did not have a smartphone or computer. The family members alleged that Devika was quite upset as she could not attend the virtual class that began on Monday. She was a student of a nearby government school.

Local police said that Devika, who was the eldest among four children of Balakrishnan, was suspected to have self-immolated using kerosene at a premise close to her house on Monday evening. The cause and provocations were still being probed only. No suicide notes were recovered yet.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
March 9,2020

New Delhi, Mar 9: A war of words broke out between the BJP and the Congress on Sunday over the Yes Bank crisis with the ruling party seeking to link it with the Gandhi family, while the opposition wondered if the prime minister and finance minister were "complicit" as the bank's loan book grew manifold.

Posting on Twitter a clip of a news channel report that Rana Kapoor, the arrested Yes Bank founder, had bought a painting from Congress leader Priyanka Gandhi Vadra, BJP's information and technology wing in-charge Amit Malviya alleged that every financial crime in India has "deep links" with the Gandhis.

The Congress dismissed the charge "fake" and called it a "diversionary" tactic.

It said Priyanka Gandhi had sold an M F Hussain painting of her father Rajiv Gandhi to Kapoor for Rs 2 crore, and the entire amount was disclosed in her income tax return of 2010.

Malviya tweeted, "Every financial crime in India has deep link with the Gandhis. Mallya used to send flight upgrade tickets to Sonia Gandhi. Had access to MMS (Manmohan Singh) and PC (P Chidambaram). Is absconding. Rahul inaugurated Nirav Modi’s bridal jewellery collection, he defaulted. Rana bought Priyanka Vadra’s paintings."

Congress' chief spokesperson Randeep Surjewala asked how does an M F Hussain painting of Rajiv Gandhi sold 10 years ago by Priyanka Gandhi to Yes Bank owner Rana Kapoor and disclosed in her tax returns connect with unprecedented giving of loans of Rs 2,00,000 crore in five years of the Modi government.

"More so, when (Kapoor's) proximity to BJP leaders is well known," he said.

Rubbishing the BJP's allegation, Congress spokesperson Abhishek Manu Singhvi at a press conference said it was a "diversionary" tactic by the government.

He noted that the bank's loan book rose from Rs 55,633 crore in March 2014, the year Narendra Modi became prime minister, to Rs 2,41,499 crore in March 2019.

"Why did the loan book rise by 100 per cent in two years after demonetisation i.e from Rs 98,210 cr in March 2016 to Rs 2,03,534 ar in March 2018? Were PM and FM sleeping, ignorant or complicit?" he asked.

The entire amount Priyanka Gandhi had received was in cheque and was fully disclosed in the income tax return, Singhvi said.

Surjewala, taking to Twitter, said instead of diverting from the real issue of people's money sinking into a bad bank, should not the government answer questions like how did loans given by Yes Bank rise from Rs 55,633 crore in March 2014 to Rs 2,41,499 crore in March 2019, an increase of almost Rs 2,00,000 crore in fiver years of the Modi government.

Why did the loans given by Yes Bank rise by a whopping 100 per cent in just two years after demonetisation, he asked.

Surjewala also questioned why did the prime minister address a conference sponsored by Yes Bank on March 6 despite the RBI moratorium.

"Why did the Haryana BJP government deposit over Rs 1,000 crore in Yes Bank a month ago, knowing that it was sinking? Is this figure Rs 3,000 cr? Did Fadnavis government in Maharashtra make similar deposits?" Surjewala asked.

"Of course, the government's media proxies won't dare to ask these questions. But the nation wants to know!" he said in a series of tweets.

Kapoor, 62, was arrested by the Enforcement Directorate in Mumbai after charges of alleged financial irregularities and mismanagement in the bank's operations surfaced and the RBI and Union government initiated action to control its affairs.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.