Bengaluru: 31-yr-old techie arrested for accessing Aadhaar data

coastaldigest.com news network
August 4, 2017

Bengaluru, Aug 4: Bengaluru city police has arrested a young techie on the charge of accessing Aadhaar data following a complaint filed by the Unique Identification Authority of India (UIDAI) last week.

The arrested is Abhinav Srivastav, 31, an IIT-Kharagpur graduate, who is currently employed by ANI Technologies, which owns the Ola brand, as a software development engineer. He has been accused of accessing Aadhaar information in January 2017 through an app named ‘Aadhaar e-KYC’, which was available on the Google Play store till recently.

Police said Srivastav had developed five apps and made ₹40,000 from advertisements displayed on them. Police are now scanning all his apps to see whether more violations were committed. The Aadhaar e-KYC app was downloaded over 50,000 times from the Google Play store since its launch in January, the police said.

City Police Commissioner T. Suneel Kumar said that based on the complaint, six teams of police comprising 26 personnel were formed to nab Srivastav and they tracked him down to Koramangala after a week. He has been accused of using the services of another app, ‘e-hospital’, which is listed as an authenticated user agency (AUA) authorised to access UIDAI data.

A senior police officer said there were around 400 entities that have been authorised to access the data for authentication. Srivastav’s company was not among those authorised.

A native of Kanpur, Srivastav completed his M.Sc. in Industrial Chemistry from IIT-Kharagpur and joined a private firm in 2010 as a security researcher. He launched Qarth technologies in 2012 and shut it down in 2016 owing to financial reasons. In March 2016, Ola announced that it had acquired Qarth and its mobile payments product, X-Pay. Srivastav then joined another private firm before joining ANI Technologies last year.

Investigation revealed that the e-hospital company is not aware of his activities. However, further probe is on to ascertain the facts.

The ability of a software engineer to bypass strict protocols set in place by the UIDAI to access critical data puts the spotlight firmly on the security measures employed to protect Aadhaar data.

Police investigation have revealed that Srivastav had piggy-backed on the infrastructure of another app for hacking the data base.

“Aadhaar related information, legally housed by the National Informatics Centre server, was illegally and without authorisation accessed and used to support this mobile application,” said the police statement.

Srivastav, in order to give his ‘Aadhaar e-KYC’ app an air of authenticity, hacked into the server of the NIC, which houses the e-hospital system, which is a solution for government hospitals to handle patient care and other services, including medical records management.

As part of its regulations, the UIDAI accords certain agencies the title of an AUA, which can then provide Aadhaar-enabled services to the cardholder. For authentication, these agencies have to connect to the Central Identities Data Repository (CIDR) through the services of a Authentication Service Agency (ASA). ASAs are bound by regulations that stipulate encryption of data and logging of access.

The 'e-hospital’ platform had access as a registered AUA. Srivastav used this server to route his app requests for data access and managed to steal the data, the police said.

Question raised

In 2016, a paper titled ‘Privacy and Security of Aadhaar: A Computer Science Perspective’ by the Computer Science and Engineering Department of IIT-Delhi raised the question of leakage of Aadhaar number from an AUA.

The paper, which also discusses several other possible threat scenarios, said, “This, however, does not fully mitigate the risks and the possibility of leakage of the Aadhaar number from an AUA, either from the database, or during “Know Your Customer” (KYC) processes, or even during availing services, cannot be ruled out. In particular, there appear to be no safeguards or even guidelines, either technical or legal, on how the Aadhaar number should be maintained and used by various AUAs in a cryptographically secure way, and how to prevent the Aadhaar number of an individual from becoming public.”

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
January 30,2020

Bengaluru, Jan 30: A kidnap case in Bengaluru has proved that crime-based series on TV channels can inspire youth to commit crimes. 21-year-old Chirag R Mehta, who kidnapped a schoolboy and got arrested within an hour after demanding Rs 5 lakh ransom, has told police that he thought of abducting the boy after watching Crime Patrol, a popular Hindi crime anthology series created by Subramanian S. lyer for Sony TV. The kidnapped schoolboy was rescued by the police and reunited with his parents. Son of a gift shop owner from Basavanagudi area in Bengaluru, Chirag has reportedly told police that decided to make some quick money to spend on cricket betting and gambling after learning kidnap tricks from the ‘Crime Patrol’. According to police, Chirag reached a private school around 3pm on Tuesday on a Bounce rental bike and zeroed in on a fourth standard student who was walking out of school. He told the boy he was his father's friend and that he required help to search for a relative who had gone missing. The boy believed Chirag and rode pillion on the bike. Chirag then engaged the boy in conversation and learnt about his father's business and got his mobile phone number. He then made a call to the boy's father, demanded Rs 5 lakh and warned him against approaching cops. However, the boy's father alerted Cottonpet police and special teams were formed to crack the case. While Cottonpet inspector Venkatesh TC's squad verified CCTV footage in and around the school, Chamarajpet inspector BG Kumaraswamy's team started tracking the suspect's mobile phone movements. An hour later, the suspect's location was traced to a hotel on the Lavelle Road-St Mark's Road stretch. Police rushed there, rescued the boy and arrested Chirag.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
February 24,2020

New Delhi, Feb 24: The shared values between India and the US are "discrimination, bigotry, and hostility towards refugees and asylum seekers", Amnesty International USA said in a joint statement with Amnesty International India ahead of US President Donald Trump's visit to India on Monday.

Trump, accompanied by his wife Melania, daughter Ivanka and son-in-law Jared Kushner as well as senior officials of his administration, landed in Ahmedabad on the first leg of his two-day visit to India.

"Anti-Muslim sentiment permeates the policies of both U.S. and Indian leaders. For decades, the U.S.-India relationship was anchored by claims of shared values of human rights and human dignity. Now, those shared values are discrimination, bigotry, and hostility towards refugees and asylum seekers,” Margaret Huang, Amnesty International USA’s executive director, was quoted as saying in the statement.

It was a reference to the anti-CAA protests in India, the internet lockdown in Jammu and Kashmir and the Muslim ban expansion by President Trump affecting Nigeria, Eritrea, Myanmar, Kyrgyzstan, Sudan and Tanzania, the statement said.

It added that Amnesty International USA’s researchers travelled to Lebanon and Jordan to conduct nearly 50 interviews with refugees that as a result of the previous version of the ban have been stranded in countries where they face restrictive policies, increasingly hostile environments, and lack the same rights as permanent residents or citizens.

The statement also came down hard on the Indian government, hitting out at the Citizenship (Amendment) Act (CAA) 2019 and saying it legitimises discrimination based on religious grounds.

It criticised statements such as “identify them (the protestors) by their clothes” or “shoot the traitors” by Prime Minister Modi and his party workers. Such remarks "peddled the narrative of fear and division that has fuelled further violence", it said.

“The internet and political lockdown in Kashmir has lasted for months and the enactment of CAA and the crackdown on protests has shown a leadership that is lacking empathy and a willingness to engage. We call on President Trump and Prime Minister Modi to work with the international community and address our concerns in their bilateral conversations,” Avinash Kumar, executive director, Amnesty International India said in the statement.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
May 5,2020

Bengaluru, May 5: Karnataka Chief Minister BS Yediyurappa on Tuesday said that the coronavirus situation in the state is "under control" as compared to several other states in the country.

He also hinted that soon the construction and industrial activities would be allowed in the state except in the red zones.

"Coronavirus situation in the state is under control as compared to other states. Due to this, travel of migrant workers was prohibited. Now, trade, construction and industrial activities need to restart, except in the red zones," he told reporters.

According to the Karnataka Health Department, the state has so far recorded 659 COVID-19 cases, including 324 discharged and 28 deaths.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.