Bengaluru: 31-yr-old techie arrested for accessing Aadhaar data

coastaldigest.com news network
August 4, 2017

Bengaluru, Aug 4: Bengaluru city police has arrested a young techie on the charge of accessing Aadhaar data following a complaint filed by the Unique Identification Authority of India (UIDAI) last week.

The arrested is Abhinav Srivastav, 31, an IIT-Kharagpur graduate, who is currently employed by ANI Technologies, which owns the Ola brand, as a software development engineer. He has been accused of accessing Aadhaar information in January 2017 through an app named ‘Aadhaar e-KYC’, which was available on the Google Play store till recently.

Police said Srivastav had developed five apps and made ₹40,000 from advertisements displayed on them. Police are now scanning all his apps to see whether more violations were committed. The Aadhaar e-KYC app was downloaded over 50,000 times from the Google Play store since its launch in January, the police said.

City Police Commissioner T. Suneel Kumar said that based on the complaint, six teams of police comprising 26 personnel were formed to nab Srivastav and they tracked him down to Koramangala after a week. He has been accused of using the services of another app, ‘e-hospital’, which is listed as an authenticated user agency (AUA) authorised to access UIDAI data.

A senior police officer said there were around 400 entities that have been authorised to access the data for authentication. Srivastav’s company was not among those authorised.

A native of Kanpur, Srivastav completed his M.Sc. in Industrial Chemistry from IIT-Kharagpur and joined a private firm in 2010 as a security researcher. He launched Qarth technologies in 2012 and shut it down in 2016 owing to financial reasons. In March 2016, Ola announced that it had acquired Qarth and its mobile payments product, X-Pay. Srivastav then joined another private firm before joining ANI Technologies last year.

Investigation revealed that the e-hospital company is not aware of his activities. However, further probe is on to ascertain the facts.

The ability of a software engineer to bypass strict protocols set in place by the UIDAI to access critical data puts the spotlight firmly on the security measures employed to protect Aadhaar data.

Police investigation have revealed that Srivastav had piggy-backed on the infrastructure of another app for hacking the data base.

“Aadhaar related information, legally housed by the National Informatics Centre server, was illegally and without authorisation accessed and used to support this mobile application,” said the police statement.

Srivastav, in order to give his ‘Aadhaar e-KYC’ app an air of authenticity, hacked into the server of the NIC, which houses the e-hospital system, which is a solution for government hospitals to handle patient care and other services, including medical records management.

As part of its regulations, the UIDAI accords certain agencies the title of an AUA, which can then provide Aadhaar-enabled services to the cardholder. For authentication, these agencies have to connect to the Central Identities Data Repository (CIDR) through the services of a Authentication Service Agency (ASA). ASAs are bound by regulations that stipulate encryption of data and logging of access.

The 'e-hospital’ platform had access as a registered AUA. Srivastav used this server to route his app requests for data access and managed to steal the data, the police said.

Question raised

In 2016, a paper titled ‘Privacy and Security of Aadhaar: A Computer Science Perspective’ by the Computer Science and Engineering Department of IIT-Delhi raised the question of leakage of Aadhaar number from an AUA.

The paper, which also discusses several other possible threat scenarios, said, “This, however, does not fully mitigate the risks and the possibility of leakage of the Aadhaar number from an AUA, either from the database, or during “Know Your Customer” (KYC) processes, or even during availing services, cannot be ruled out. In particular, there appear to be no safeguards or even guidelines, either technical or legal, on how the Aadhaar number should be maintained and used by various AUAs in a cryptographically secure way, and how to prevent the Aadhaar number of an individual from becoming public.”

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 14,2024

srirang.jpg

Bengaluru: The Prime Minister Narendra Modi led union government has requested the Karnataka High Court to direct the Mandya district administration and the state government to clear a madrasa operating within the premises of the historic Jama Masjid in Srirangapatna.

The Waqf Board, opposing this move, has claimed the mosque as its property and defended the right to conduct madrasa activities there.

The matter was brought before a division bench headed by Chief Justice N V Anjaria following a public interest litigation filed by a person named Abhishek Gowda from Kabbalu village in Kanakapura taluk. The petition alleged “unauthorised madrasa activities” within the mosque.

Representing the Central government, Additional Solicitor General of India for High Court of Karnataka, K Arvind Kamath argued that the Jama Masjid was designated as a protected monument in 1951, yet unauthorised madrasa operations continue there.

He noted that concerns over potential law and order issues have so far prevented any intervention. Kamath urged the court to direct the Mandya district administration to take action and vacate the madrasa from the mosque.

In defence, lawyers for the state government and the Waqf Board contested this request, stating that the Waqf Board had been recognised as the owner of the property since 1963 and, thus, conducting madrasa activities there is lawful.

After hearing both sides, the bench adjourned the case for further arguments, scheduling the next hearing for November 20.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 13,2024

voting.jpg

Bengaluru: An estimated overall 10.14 per cent voter turnout was recorded during the first two hours, since the voting began for bypolls to three Assembly segments in Karnataka on Wednesday, election officials said.

The voting began at 7 am and will go on till 6 pm.

More than seven lakh voters are eligible to cast their votes in about 770 polling stations in Shiggaon, Sandur and Channapatna, where a total of 45 candidates are in the fray.

While Channapatna recorded 10.34 per cent voter turnout till 9 am, it was 10.08 per cent in Shiggaon, and 9.99 per cent in Sandur, election officials said.

Voters, including women and elderly were seen queuing up in front of polling booths in these segments.

By-polls for Sandur, Shiggaon, and Channapatna are necessitated, as the seats fell vacant following the election of their respective representatives -- E Tukaram of Congress, former CM Basavaraj Bommai of BJP, and Union Minister H D Kumaraswamy of JD(S) -- to Lok Sabha in May elections.

As many as 31 candidates are in the fray from Channapatna, while Sandur and Shiggaon have six and eight contenders, respectively.

Elaborate security arrangements have been made in the three segments for the smooth conduct of the polls.

The by-polls will witness a straight fight between the ruling Congress and BJP in Sandur and Shiggaon segments, while in Channapatna, JD(S) which is part of the NDA alliance is in contest against the grand old party.

Among the three segments, Channapatna is considered to be a "high profile", where the contest is between C P Yogeeshwara, a five time MLA from the segment and former Minister, who joined the Congress quitting BJP ahead of nomination, and actor-turned -politician Nikhil Kumaraswamy, who is Kumaraswamy’s son and former PM H D Deve Gowda's grandson.

BJP's Bharath Bommai, son of Basavaraj Bommai, is fighting Congress Yasir Ahmed Khan Pathan, who had faced defeat against the former Chief Minister in the 2023 Assembly polls, in Shiggaon.

Bharath Bommai and his father cast their vote at a polling booth in Shiggaon segment.

In Sandur, Bellary MP Tukaram's wife E Annapurna of Congress is contesting from the seat vacated by her husband, against, BJP ST Morcha president Bangaru Hanumanthu, who is considered close to party leader and former mining barron G Janardhan Reddy.

Annapurna, Tukaram and other family members cast their votes at a booth in the segment.

With Nikhil Kumaraswamy and Bharath Bommai contesting, the third generation of Gowda and Bommai families are in the fray in this by-poll. Both their fathers and grandfathers have served as Karnataka's Chief Ministers in the past.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 14,2024

Bengaluru: Karnataka Deputy Chief Minister D K Shivakumar on Thursday backed Chief Minister Siddaramaiah over his claim that the BJP had offered Rs 50 crore each to 50 Congress MLAs in an attempt to "topple" the state government.

Addressing reporters here, Shivakumar, also the Congress state president, said, “The BJP indeed lured 50 Congress MLAs with Rs 50 crore each.”

He defended Siddaramaiah’s statement and said the Congress MLAs were briefed about the BJP’s alleged 'Operation Lotus', a term used to describe the BJP's attempts to destabilise ruling governments through horse-trading.

“Some of our MLAs informed the Chief Minister about this matter, and he, in turn, shared it with the media,” Shivakumar said.

At an event in Mysuru, Siddaramaiah reiterated the claim that "none of the Congress MLAs had accepted the offer".

He also accused the BJP of filing false cases against him in a bid to "remove him and overthrow his government".

The BJP has yet to respond to the allegations.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.