Bengaluru: 31-yr-old techie arrested for accessing Aadhaar data

coastaldigest.com news network
August 4, 2017

Bengaluru, Aug 4: Bengaluru city police has arrested a young techie on the charge of accessing Aadhaar data following a complaint filed by the Unique Identification Authority of India (UIDAI) last week.

The arrested is Abhinav Srivastav, 31, an IIT-Kharagpur graduate, who is currently employed by ANI Technologies, which owns the Ola brand, as a software development engineer. He has been accused of accessing Aadhaar information in January 2017 through an app named ‘Aadhaar e-KYC’, which was available on the Google Play store till recently.

Police said Srivastav had developed five apps and made ₹40,000 from advertisements displayed on them. Police are now scanning all his apps to see whether more violations were committed. The Aadhaar e-KYC app was downloaded over 50,000 times from the Google Play store since its launch in January, the police said.

City Police Commissioner T. Suneel Kumar said that based on the complaint, six teams of police comprising 26 personnel were formed to nab Srivastav and they tracked him down to Koramangala after a week. He has been accused of using the services of another app, ‘e-hospital’, which is listed as an authenticated user agency (AUA) authorised to access UIDAI data.

A senior police officer said there were around 400 entities that have been authorised to access the data for authentication. Srivastav’s company was not among those authorised.

A native of Kanpur, Srivastav completed his M.Sc. in Industrial Chemistry from IIT-Kharagpur and joined a private firm in 2010 as a security researcher. He launched Qarth technologies in 2012 and shut it down in 2016 owing to financial reasons. In March 2016, Ola announced that it had acquired Qarth and its mobile payments product, X-Pay. Srivastav then joined another private firm before joining ANI Technologies last year.

Investigation revealed that the e-hospital company is not aware of his activities. However, further probe is on to ascertain the facts.

The ability of a software engineer to bypass strict protocols set in place by the UIDAI to access critical data puts the spotlight firmly on the security measures employed to protect Aadhaar data.

Police investigation have revealed that Srivastav had piggy-backed on the infrastructure of another app for hacking the data base.

“Aadhaar related information, legally housed by the National Informatics Centre server, was illegally and without authorisation accessed and used to support this mobile application,” said the police statement.

Srivastav, in order to give his ‘Aadhaar e-KYC’ app an air of authenticity, hacked into the server of the NIC, which houses the e-hospital system, which is a solution for government hospitals to handle patient care and other services, including medical records management.

As part of its regulations, the UIDAI accords certain agencies the title of an AUA, which can then provide Aadhaar-enabled services to the cardholder. For authentication, these agencies have to connect to the Central Identities Data Repository (CIDR) through the services of a Authentication Service Agency (ASA). ASAs are bound by regulations that stipulate encryption of data and logging of access.

The 'e-hospital’ platform had access as a registered AUA. Srivastav used this server to route his app requests for data access and managed to steal the data, the police said.

Question raised

In 2016, a paper titled ‘Privacy and Security of Aadhaar: A Computer Science Perspective’ by the Computer Science and Engineering Department of IIT-Delhi raised the question of leakage of Aadhaar number from an AUA.

The paper, which also discusses several other possible threat scenarios, said, “This, however, does not fully mitigate the risks and the possibility of leakage of the Aadhaar number from an AUA, either from the database, or during “Know Your Customer” (KYC) processes, or even during availing services, cannot be ruled out. In particular, there appear to be no safeguards or even guidelines, either technical or legal, on how the Aadhaar number should be maintained and used by various AUAs in a cryptographically secure way, and how to prevent the Aadhaar number of an individual from becoming public.”

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
February 6,2020

Thiruvananthapuram, Feb 6: The Kerala government on Wednesday said three foreign nationals were among the 2,528 people under observation in the state for the novel coronavirus infection and no new cases have been reported.

At least 93 people with minor symptoms of the virus have been lodged in isolation wards of various hospitals, state Health Minister KK Shailaja told reporters in Thiruvananthapuram.

India's three positive cases for the virus has been from the state's three districts of Thrissur, Alappuzha and Kasaragod.

All the three are students of China's Wuhan university, the epicentre of the virus.

"No new cases of coronavirus has been detected in the state today. At least 2,435 are under observation at home while 93 are in isolation wards at various hospital across the state," Mr Shailaja said.

The minister also said two foreigners have been quarantined in Ernakulam district and one foreign national at Thiruvananthapuram.

"The foreigner in Thiruvananthapuram has been kept at general hospital but not because he was showing symptoms but for observation as he travelled from China," an official said.

The health status of the three patients, who had tested positive for the virus, "remains satisfactory", the minister said.

After three cases were reported, the Left Democratic Front (LDF) government had declared the epidemic as a "state calamity" on Monday.

The health department has issued advisories to the education, tourism and the animal husbandry departments on taking precautions.

"The students, teachers, other staff members residing with families of Wuhan/China returnees who are already in home isolation should not attend classes...," an advisory issued to the education department read.

Rajan Khobragade, Principal Secretary (Health), said the health department has directed the District collectors to hold a meeting with the religious leaders of the district to create awareness during prayer meetings.

"We have directed district collectors to meet religious leaders and talk to them about the seriousness of the situation and create awareness among them and their followers on how to contain the spread of virus," the minister said.

Mr Shailaja also said the department got messages from some Kerala students studying in China, who returned to the state after the virus outbreak, that their Universities had asked them to return and attend classes.

"We have got some messages from the students that they were being recalled by the universities in China. We discussed the matter and it was decided that the centre will contact such universities and convey the message that it was not possible to send the students back to China until the epidemic was under control," the minister said.

Mr Shailaja also said even though there were no positive cases for the second consecutive day on Wednesday, the state needs to remain vigilant and reiterated the 28 days quarantine period for those returning from China.

Of the 2,528 people under observation, the maximum number is from Malappuram (383), followed by Ernakulam (333), Kozhikode (306) and Thrissur (241).

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
January 18,2020

Mangaluru, Jan 18: The Dakshina Kannada District Karavali Utsava Samiti has chosen senior Journalist and Assistant Editor on Udayavani Daily Manohar Prasad for the Karavali Gaurava Prashasti 2019-20.

The award will be presented to Manohar Prasad in recognition of his contribution in the field of Journalism.

He will be given the award during the valedictory of the Karavali Utsav at Panambur beach on January 19.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
April 27,2020

Thiruvananthapuram, Apr 27: Kerala Chief Minister Pinarayi Vijayan on Sunday said the issue of return of Non-Resident Keralites (NRKs) to the state has been taken up with the Centre and the state government is awaiting a favourable response.

Vijayan said this in a meeting with Non-Resident Keralites over steps taken by the state government for those wishing to return to the state from foreign countries.

The Chief Minister announced that the Department of Non-Resident Keralites Affairs has opened online registration for such NRKs.

"Those returning should undergo screening at airports. All those returning should undergo mandatory home quarantine for 14 days.

Arrangements of isolation wards will be provided for those unable to go home," said Vijayan.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.