Bengaluru: 31-yr-old techie arrested for accessing Aadhaar data

coastaldigest.com news network
August 4, 2017

Bengaluru, Aug 4: Bengaluru city police has arrested a young techie on the charge of accessing Aadhaar data following a complaint filed by the Unique Identification Authority of India (UIDAI) last week.

The arrested is Abhinav Srivastav, 31, an IIT-Kharagpur graduate, who is currently employed by ANI Technologies, which owns the Ola brand, as a software development engineer. He has been accused of accessing Aadhaar information in January 2017 through an app named ‘Aadhaar e-KYC’, which was available on the Google Play store till recently.

Police said Srivastav had developed five apps and made ₹40,000 from advertisements displayed on them. Police are now scanning all his apps to see whether more violations were committed. The Aadhaar e-KYC app was downloaded over 50,000 times from the Google Play store since its launch in January, the police said.

City Police Commissioner T. Suneel Kumar said that based on the complaint, six teams of police comprising 26 personnel were formed to nab Srivastav and they tracked him down to Koramangala after a week. He has been accused of using the services of another app, ‘e-hospital’, which is listed as an authenticated user agency (AUA) authorised to access UIDAI data.

A senior police officer said there were around 400 entities that have been authorised to access the data for authentication. Srivastav’s company was not among those authorised.

A native of Kanpur, Srivastav completed his M.Sc. in Industrial Chemistry from IIT-Kharagpur and joined a private firm in 2010 as a security researcher. He launched Qarth technologies in 2012 and shut it down in 2016 owing to financial reasons. In March 2016, Ola announced that it had acquired Qarth and its mobile payments product, X-Pay. Srivastav then joined another private firm before joining ANI Technologies last year.

Investigation revealed that the e-hospital company is not aware of his activities. However, further probe is on to ascertain the facts.

The ability of a software engineer to bypass strict protocols set in place by the UIDAI to access critical data puts the spotlight firmly on the security measures employed to protect Aadhaar data.

Police investigation have revealed that Srivastav had piggy-backed on the infrastructure of another app for hacking the data base.

“Aadhaar related information, legally housed by the National Informatics Centre server, was illegally and without authorisation accessed and used to support this mobile application,” said the police statement.

Srivastav, in order to give his ‘Aadhaar e-KYC’ app an air of authenticity, hacked into the server of the NIC, which houses the e-hospital system, which is a solution for government hospitals to handle patient care and other services, including medical records management.

As part of its regulations, the UIDAI accords certain agencies the title of an AUA, which can then provide Aadhaar-enabled services to the cardholder. For authentication, these agencies have to connect to the Central Identities Data Repository (CIDR) through the services of a Authentication Service Agency (ASA). ASAs are bound by regulations that stipulate encryption of data and logging of access.

The 'e-hospital’ platform had access as a registered AUA. Srivastav used this server to route his app requests for data access and managed to steal the data, the police said.

Question raised

In 2016, a paper titled ‘Privacy and Security of Aadhaar: A Computer Science Perspective’ by the Computer Science and Engineering Department of IIT-Delhi raised the question of leakage of Aadhaar number from an AUA.

The paper, which also discusses several other possible threat scenarios, said, “This, however, does not fully mitigate the risks and the possibility of leakage of the Aadhaar number from an AUA, either from the database, or during “Know Your Customer” (KYC) processes, or even during availing services, cannot be ruled out. In particular, there appear to be no safeguards or even guidelines, either technical or legal, on how the Aadhaar number should be maintained and used by various AUAs in a cryptographically secure way, and how to prevent the Aadhaar number of an individual from becoming public.”

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
May 7,2024

tank.jpg

The Israeli military says it has taken full control of the Rafah crossing, which borders Egypt.

Israeli tanks took over the crossing after advancing during the night following heavy bombardment of residential areas.

The military said the crossing is now disconnected from the Salah a-Din road in eastern Rafah, which was seized before.

Tel Aviv said it would continue the operation in Rafah even after the Palestinian resistance movement Hamas said it had agreed to a proposal on ceasefire in Gaza put forward by Qatari and Egyptian mediators.

Earlier, Israeli military aircraft heavily bombed Rafah accompanied with ground advances shortly after Hamas said it had accepted the ceasefire proposal.

The official Palestinian news agency Wafa and Egyptian media said Israeli military vehicles advanced towards the Palestinian side of the Rafah crossing with Egypt, as well as the Karem Shalom crossing with the Israeli-occupied territories.

A Palestinian security official and an Egyptian authority have told the Associated Press news agency that Israeli tanks have entered Rafah, reaching as close as 200 meters from Rafah’s border crossing with neighboring Egypt.

The Israeli military has said it was conducting “targeted strikes” against Hamas in eastern Rafah.

Israeli prime minister Benjamin Netanyahu's office has also said "Israel is continuing the operation in Rafah to exert military pressure on Hamas" in order to advance the release of captives and what it called "the other objectives of the war."

In the meantime, it described the proposal on ceasefire as "far from Israel's essential demands," but added that it would send negotiators for talks "to exhaust the potential for arriving at an agreement."

The military strikes on Rafah came ahead of talks in Egypt on Tuesday aimed at sealing a truce proposal accepted by Hamas, which was put forward by Qatari and Egyptian mediators. 

According to a copy of the proposal, there will be three phases to ending Israel’s onslaught against Gaza.

The first phase calls for a complete withdrawal of Israeli troops from the Netzarim corridor and the return of displaced Palestinians to their homes. The second phase involves an announcement of a permanent cessation of military operations. In the last phase, there would be a complete end to the blockade of the Gaza Strip. 

In return, Israel would be required to release an unspecified number of Palestinian prisoners, withdraw its troops from certain regions of the Gaza Strip, and allow Palestinians to travel from the south of the coastal sliver to the north.

About 1.5 million Palestinians are sheltering in Rafah, once designated a “safe zone” by the Israeli military. Palestinians are now struggling to evacuate the city, after the Israeli military dropped leaflets ordering them to leave as a large-scale assault on the city is planned.

UN Secretary General Antonio Guterres has said that a ground invasion of Rafah would be “intolerable” and called on Israel and Hamas “to go an extra mile” to reach a truce deal.

“This is an opportunity that cannot be missed, and a ground invasion in Rafah would be intolerable because of its devastating humanitarian consequences, and because of its destabilizing impact in the region,” Guterres told reporters on Monday ahead of a meeting with Italian President Sergio Mattarella in New York.

Jordanian Foreign Minister Ayman Safadi has also warned that Israel is “jeopardizing the deal by bombing Rafah.”

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
May 7,2024

damudupi.jpg

Udupi: Udupi became the second city on the Karnataka coast after Mangaluru to launch water rationing, a senior official said on Tuesday.

Commissioner of the Udupi City Municipal Corporation Rayappa said that the rationing system will come into force from Wednesday and will continue till the water in the reservoir reaches comfortable levels.

The dam built across the Swarna river at a place called Baje, which is the only source of water for Udupi city, recorded 3.25 meters of water as against the top level of 6.30 meters.

The decision of water rationing will be reviewed periodically until the reservoir regains its fullest levels, the official said.

The Mangaluru City Corporation resorted to water rationing on Saturday following declining water levels in the reservoir built across the Nethravati river at Thumbe. 

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
May 10,2024

mustafapaichar.jpg

Mangaluru, June 10: The National Investigation Agency (NIA) has arrested another prime accused in 2022 BJP Yuva Morcha worker Praveen Nettaru murder case. 

32-year-old Jilla BJP Yuva Morcha committee member Nettaru was hacked to death in front of his broiler shop in Bellare of Dakshina Kannada by bike-borne miscreants in July 2022. The case is being investigated by the NIA and several arrests have been made so far.

Mustafa Paichar, accused number four in the case, was absconding after the murder and the NIA had declared a Rs 5 lakh reward to catch him. 

He was arrested at Sakleshpur in Hassan district by the NIA team led by Inspector Shanmugam. 

According to officials Mustafa was reportedly a member of now banned Popular Front of India and a resident of Shantinagar in Sullia in Dakshina Kannada.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.