Bengaluru: 31-yr-old techie arrested for accessing Aadhaar data

coastaldigest.com news network
August 4, 2017

Bengaluru, Aug 4: Bengaluru city police has arrested a young techie on the charge of accessing Aadhaar data following a complaint filed by the Unique Identification Authority of India (UIDAI) last week.

The arrested is Abhinav Srivastav, 31, an IIT-Kharagpur graduate, who is currently employed by ANI Technologies, which owns the Ola brand, as a software development engineer. He has been accused of accessing Aadhaar information in January 2017 through an app named ‘Aadhaar e-KYC’, which was available on the Google Play store till recently.

Police said Srivastav had developed five apps and made ₹40,000 from advertisements displayed on them. Police are now scanning all his apps to see whether more violations were committed. The Aadhaar e-KYC app was downloaded over 50,000 times from the Google Play store since its launch in January, the police said.

City Police Commissioner T. Suneel Kumar said that based on the complaint, six teams of police comprising 26 personnel were formed to nab Srivastav and they tracked him down to Koramangala after a week. He has been accused of using the services of another app, ‘e-hospital’, which is listed as an authenticated user agency (AUA) authorised to access UIDAI data.

A senior police officer said there were around 400 entities that have been authorised to access the data for authentication. Srivastav’s company was not among those authorised.

A native of Kanpur, Srivastav completed his M.Sc. in Industrial Chemistry from IIT-Kharagpur and joined a private firm in 2010 as a security researcher. He launched Qarth technologies in 2012 and shut it down in 2016 owing to financial reasons. In March 2016, Ola announced that it had acquired Qarth and its mobile payments product, X-Pay. Srivastav then joined another private firm before joining ANI Technologies last year.

Investigation revealed that the e-hospital company is not aware of his activities. However, further probe is on to ascertain the facts.

The ability of a software engineer to bypass strict protocols set in place by the UIDAI to access critical data puts the spotlight firmly on the security measures employed to protect Aadhaar data.

Police investigation have revealed that Srivastav had piggy-backed on the infrastructure of another app for hacking the data base.

“Aadhaar related information, legally housed by the National Informatics Centre server, was illegally and without authorisation accessed and used to support this mobile application,” said the police statement.

Srivastav, in order to give his ‘Aadhaar e-KYC’ app an air of authenticity, hacked into the server of the NIC, which houses the e-hospital system, which is a solution for government hospitals to handle patient care and other services, including medical records management.

As part of its regulations, the UIDAI accords certain agencies the title of an AUA, which can then provide Aadhaar-enabled services to the cardholder. For authentication, these agencies have to connect to the Central Identities Data Repository (CIDR) through the services of a Authentication Service Agency (ASA). ASAs are bound by regulations that stipulate encryption of data and logging of access.

The 'e-hospital’ platform had access as a registered AUA. Srivastav used this server to route his app requests for data access and managed to steal the data, the police said.

Question raised

In 2016, a paper titled ‘Privacy and Security of Aadhaar: A Computer Science Perspective’ by the Computer Science and Engineering Department of IIT-Delhi raised the question of leakage of Aadhaar number from an AUA.

The paper, which also discusses several other possible threat scenarios, said, “This, however, does not fully mitigate the risks and the possibility of leakage of the Aadhaar number from an AUA, either from the database, or during “Know Your Customer” (KYC) processes, or even during availing services, cannot be ruled out. In particular, there appear to be no safeguards or even guidelines, either technical or legal, on how the Aadhaar number should be maintained and used by various AUAs in a cryptographically secure way, and how to prevent the Aadhaar number of an individual from becoming public.”

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
February 22,2020

Kalaburagi, Feb 22: All India Majlis-e-Ittehadul Muslimeen (AIMIM) leader Waris Pathan was booked for his alleged remark against the Hindu community in his speech during an anti-CAA rally held here recently, police sources said on Saturday.

According to police sources, the FIR was registered against the AIMIM leader, following a complaint lodged by a woman advocate on Friday evening.

Taking strongly about the incident, the Karnataka Home minister Basavaraj Bommai had directed the Kalaburagi city police commissioner to submit a report on the incident.

It may be recalled that the AIMIM leader, in his speech at a rally held in the city on February 15 had said that if all the 15 crore minority populations in the country stand united they could take on 100 crore Hindu population.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
coastaldigest.com news network
July 18,2020

 Mangaluru, July 18: The coastal districts of Dakshina Kannada and Udupi recorded a total of 346 covid positive cases in last 24 hours. Dakshina Kannada recorded 4 new deaths.

While DK recorded 237 positive cases, neighbouring Udupi saw 109 people testing positive. It may be recalled that DK and Udupi had reported a combined record spurt of 347 Covid-19 cases for a single day on Thursday. 

Dakshina Kannada 

As many as 26,368 samples have been sent for tests so far. Among them 23,096 have turned out negative, and 3,311 people have received positive report. Currently there are 1,848 active cases while 1,387 persons have recovered. 109 patients were discharged from Wenlock as well as private hospitals today. Including today’s four deaths, 75 people have succumbed to covid. Among them 12 are from other districts.

The patients whose deaths were reported today are a 74-year-old female from Puttur who was also suffering from heart disease and asthma, a 67-year-old male who was suffering from pneumonia and was on ventilator, and two females aged 49 and 61 from Mangaluru who suffered cardiac arrest.

Udupi

With 109 new cases, the total number of covid positive cases reported in the district mounted to 2088. Among new cases 58 belong to Udupi taluk, 40 are from Kundapur and 11 from Karkala. 

A total of 24,382 samples have been collected so far, including 524 on Saturday, out of which 17 are coronavirus suspects and 317 are COVID contacts. Out of them, 21,757 samples have turned out to be negative, including 292 on Saturday, and 537 reports are awaited.

As many as 1,586 patients have been discharged so far including 43 on Saturday, and 492 cases are currently active. Ten deaths have occurred so far. One positive case has been transferred to Dakshina Kannada.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
January 7,2020

Mangaluru, Jan 7: Kasturba Medical College Mangaluru, a constituent unit of Manipal Academy of Higher Education (MAHE), in association with Pai Family Endowment (in memory of Shri Suhas Gopal Pai) as its social initiative opens a newborn hearing assessment centre at Govt Lady Goshen Hospital on Tuesday.

Dr M Venkatraya Prabhu, Dean of KMC Mangaluru addressing the media persons said that the project is made possible by the generous philanthropic contribution of Mrs Anuradha (Shanthi)Gopal Pai and will be inaugurated by her in Presence of Dr H Vinod Bhat, Vice-Chancellor of MAHE.

Dr Deepak Madi, Deputy Medical Superintendent KMC Hospital Attavar explained that the facility will be managed by the departments from Audiology, ENT and Paediatrics of Kasturba Medical College, Mangaluru. The Centre aims to screen all the babies born in the hospital for hearing loss.

This is the maiden initiative of the MAHE-Pai Family endowment which has been set up to find solutions for the numerous challenges faced by the hearing handicapped in & around Dakshina Kannada district.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.