Bengaluru: 31-yr-old techie arrested for accessing Aadhaar data

coastaldigest.com news network
August 4, 2017

Bengaluru, Aug 4: Bengaluru city police has arrested a young techie on the charge of accessing Aadhaar data following a complaint filed by the Unique Identification Authority of India (UIDAI) last week.

The arrested is Abhinav Srivastav, 31, an IIT-Kharagpur graduate, who is currently employed by ANI Technologies, which owns the Ola brand, as a software development engineer. He has been accused of accessing Aadhaar information in January 2017 through an app named ‘Aadhaar e-KYC’, which was available on the Google Play store till recently.

Police said Srivastav had developed five apps and made ₹40,000 from advertisements displayed on them. Police are now scanning all his apps to see whether more violations were committed. The Aadhaar e-KYC app was downloaded over 50,000 times from the Google Play store since its launch in January, the police said.

City Police Commissioner T. Suneel Kumar said that based on the complaint, six teams of police comprising 26 personnel were formed to nab Srivastav and they tracked him down to Koramangala after a week. He has been accused of using the services of another app, ‘e-hospital’, which is listed as an authenticated user agency (AUA) authorised to access UIDAI data.

A senior police officer said there were around 400 entities that have been authorised to access the data for authentication. Srivastav’s company was not among those authorised.

A native of Kanpur, Srivastav completed his M.Sc. in Industrial Chemistry from IIT-Kharagpur and joined a private firm in 2010 as a security researcher. He launched Qarth technologies in 2012 and shut it down in 2016 owing to financial reasons. In March 2016, Ola announced that it had acquired Qarth and its mobile payments product, X-Pay. Srivastav then joined another private firm before joining ANI Technologies last year.

Investigation revealed that the e-hospital company is not aware of his activities. However, further probe is on to ascertain the facts.

The ability of a software engineer to bypass strict protocols set in place by the UIDAI to access critical data puts the spotlight firmly on the security measures employed to protect Aadhaar data.

Police investigation have revealed that Srivastav had piggy-backed on the infrastructure of another app for hacking the data base.

“Aadhaar related information, legally housed by the National Informatics Centre server, was illegally and without authorisation accessed and used to support this mobile application,” said the police statement.

Srivastav, in order to give his ‘Aadhaar e-KYC’ app an air of authenticity, hacked into the server of the NIC, which houses the e-hospital system, which is a solution for government hospitals to handle patient care and other services, including medical records management.

As part of its regulations, the UIDAI accords certain agencies the title of an AUA, which can then provide Aadhaar-enabled services to the cardholder. For authentication, these agencies have to connect to the Central Identities Data Repository (CIDR) through the services of a Authentication Service Agency (ASA). ASAs are bound by regulations that stipulate encryption of data and logging of access.

The 'e-hospital’ platform had access as a registered AUA. Srivastav used this server to route his app requests for data access and managed to steal the data, the police said.

Question raised

In 2016, a paper titled ‘Privacy and Security of Aadhaar: A Computer Science Perspective’ by the Computer Science and Engineering Department of IIT-Delhi raised the question of leakage of Aadhaar number from an AUA.

The paper, which also discusses several other possible threat scenarios, said, “This, however, does not fully mitigate the risks and the possibility of leakage of the Aadhaar number from an AUA, either from the database, or during “Know Your Customer” (KYC) processes, or even during availing services, cannot be ruled out. In particular, there appear to be no safeguards or even guidelines, either technical or legal, on how the Aadhaar number should be maintained and used by various AUAs in a cryptographically secure way, and how to prevent the Aadhaar number of an individual from becoming public.”

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 16,2024

Mangaluru: The Kavoor police in Mangaluru, Karnataka, have arrested three individuals from Kerala in connection with two separate cybercrime cases, including one involving extortion under the guise of a "digital arrest."

City Commissioner of Police Anupam Agrawal reported that one of the arrested individuals, Nisar, a resident of Ernakulam district, posed as a CBI officer. He allegedly threatened the complainant with arrest and extorted Rs 68 lakh. A case has been filed under sections 66 (C) and 66 (D) of the IT Act, and sections 308 (2) and 381 (4) of BNS.

In another case, the Kavoor police arrested two men, Sahil K P of Thiruvannur, Kozhikode, and Muhammad Nashath of Mappila Koyilandy, Kerala, in connection with a share trade fraud. The accused are alleged to have deceived the complainant by promising substantial profits from an investment in the stock market. Trusting the fraudsters, the complainant invested Rs 90 lakh, which was subsequently lost. A case has been registered under sections 66 (C) and 66 (D) of the IT Act, and sections 318 (4) and 3 (5) of BNS.

The accused were arrested in Koyilandi and presented before the court. The operation was carried out under the guidance of City Police Commissioner Anupam Agrawal, led by Mangaluru North Sub-Division ACP Srikanth K, Kavoor Inspector Raghavendra Byndoor, Kavoor PSI Mallikarjuna Biradara, and staff members Ramanna Shetty, Bhuvaneshwari, Rajappa Kashibai, Praveen N, and Malatesh. 

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 26,2024

DKudupi.jpg

Mangaluru: The coastal districts of Dakshina Kannada and Udupi are witnessing a fascinating weather pattern, with chilly early mornings giving way to dry, sweltering afternoons. Over the past two days, dense fog blanketed the rural landscapes, while urban centers like Mangaluru felt the stark contrast of brisk mornings and peak afternoon heat.

The India Meteorological Department (IMD) noted that in rural areas, the morning chill caused temperatures to dip by one to two degrees Celsius below the seasonal norm, intensifying the fog. Monday saw Mangaluru recording a maximum temperature of 33.3°C and a minimum of 22.6°C, reflective of the sharp day-night variation.

While mornings painted a serene picture with mist-covered trees and a cool ambiance, the afternoons proved relentless, with temperatures soaring between 11 am and 3 pm, offering little respite. Currently, there are no signs of rainfall, with forecasts predicting the continuation of this dual weather pattern for the coming days.

Local residents have mixed feelings about this weather trend. Farmers in rural areas appreciate the cool mornings that ease early chores but express concerns over the dry afternoons, which may affect crop irrigation if the dry spell prolongs. In contrast, urban dwellers are enjoying the foggy mornings but brace for the scorching afternoons.

Meteorologists attribute the sudden chill to shifts in atmospheric pressure along the coast, a precursor to possible weather transitions in December. Whether this pattern persists or leads to unexpected changes remains to be seen, but the twin districts are clearly caught in nature's dramatic play of contrasts.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 17,2024

ullalpool.jpg

Mangaluru: A tragic incident unfolded on Sunday, November 17, at Vazco Resort (VAZCO), situated at Battappadi Cross Road in Someshwara on the outskirts of the city, when three young women drowned in the resort’s swimming pool. 

Disturbingly, an iPhone recording and CCTV footage captured their final moments, providing insights into the heartbreaking accident.

According to City Police Commissioner Anupam Agrawal, the tragedy occurred at approximately 10:05 AM. The victims were identified as:

Keerthana N (21) from Devaraj Mohalla, Hebbal Second Stage, Vijayanagar Post.
Nishitha M.D (21) from 4th Cross, Kuribarahalli, Mysuru.
Parvathi S (20) from Ramanuja Road, K.R. Mohalla, Mysuru.

Sequence of Events

The three women had checked into Room No. 2 of the resort on the morning of November 16 and stayed overnight. On Sunday morning, around 10 AM, they entered the swimming pool to play. Reports suggest that they placed their clothes poolside and set an iPhone to record the activity.

Initial findings indicate one woman slipped underwater and began to struggle. When the second attempted a rescue, she too drowned, followed by the third woman. Within minutes, the tragedy claimed all three lives. CCTV footage from the resort corroborates the sequence, showing the young women struggling before succumbing to the water.

Investigation Underway

The resort staff discovered the lifeless bodies and immediately raised the alarm. Ullal Police Inspector H N Balakrishna and his team are conducting an investigation. Preliminary reports suggest the women were non-swimmers, and the lack of safety measures contributed to the tragedy.

The resort is owned by Manohar, as per police records. While the formal case is yet to be registered, the incident has raised serious questions about safety protocols at resorts offering pool facilities.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.