Bengaluru: 31-yr-old techie arrested for accessing Aadhaar data

coastaldigest.com news network
August 4, 2017

Bengaluru, Aug 4: Bengaluru city police has arrested a young techie on the charge of accessing Aadhaar data following a complaint filed by the Unique Identification Authority of India (UIDAI) last week.

The arrested is Abhinav Srivastav, 31, an IIT-Kharagpur graduate, who is currently employed by ANI Technologies, which owns the Ola brand, as a software development engineer. He has been accused of accessing Aadhaar information in January 2017 through an app named ‘Aadhaar e-KYC’, which was available on the Google Play store till recently.

Police said Srivastav had developed five apps and made ₹40,000 from advertisements displayed on them. Police are now scanning all his apps to see whether more violations were committed. The Aadhaar e-KYC app was downloaded over 50,000 times from the Google Play store since its launch in January, the police said.

City Police Commissioner T. Suneel Kumar said that based on the complaint, six teams of police comprising 26 personnel were formed to nab Srivastav and they tracked him down to Koramangala after a week. He has been accused of using the services of another app, ‘e-hospital’, which is listed as an authenticated user agency (AUA) authorised to access UIDAI data.

A senior police officer said there were around 400 entities that have been authorised to access the data for authentication. Srivastav’s company was not among those authorised.

A native of Kanpur, Srivastav completed his M.Sc. in Industrial Chemistry from IIT-Kharagpur and joined a private firm in 2010 as a security researcher. He launched Qarth technologies in 2012 and shut it down in 2016 owing to financial reasons. In March 2016, Ola announced that it had acquired Qarth and its mobile payments product, X-Pay. Srivastav then joined another private firm before joining ANI Technologies last year.

Investigation revealed that the e-hospital company is not aware of his activities. However, further probe is on to ascertain the facts.

The ability of a software engineer to bypass strict protocols set in place by the UIDAI to access critical data puts the spotlight firmly on the security measures employed to protect Aadhaar data.

Police investigation have revealed that Srivastav had piggy-backed on the infrastructure of another app for hacking the data base.

“Aadhaar related information, legally housed by the National Informatics Centre server, was illegally and without authorisation accessed and used to support this mobile application,” said the police statement.

Srivastav, in order to give his ‘Aadhaar e-KYC’ app an air of authenticity, hacked into the server of the NIC, which houses the e-hospital system, which is a solution for government hospitals to handle patient care and other services, including medical records management.

As part of its regulations, the UIDAI accords certain agencies the title of an AUA, which can then provide Aadhaar-enabled services to the cardholder. For authentication, these agencies have to connect to the Central Identities Data Repository (CIDR) through the services of a Authentication Service Agency (ASA). ASAs are bound by regulations that stipulate encryption of data and logging of access.

The 'e-hospital’ platform had access as a registered AUA. Srivastav used this server to route his app requests for data access and managed to steal the data, the police said.

Question raised

In 2016, a paper titled ‘Privacy and Security of Aadhaar: A Computer Science Perspective’ by the Computer Science and Engineering Department of IIT-Delhi raised the question of leakage of Aadhaar number from an AUA.

The paper, which also discusses several other possible threat scenarios, said, “This, however, does not fully mitigate the risks and the possibility of leakage of the Aadhaar number from an AUA, either from the database, or during “Know Your Customer” (KYC) processes, or even during availing services, cannot be ruled out. In particular, there appear to be no safeguards or even guidelines, either technical or legal, on how the Aadhaar number should be maintained and used by various AUAs in a cryptographically secure way, and how to prevent the Aadhaar number of an individual from becoming public.”

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 15,2024

amitshah.jpg

Union minister Amit Shah on Friday, November 15, said PM Narendra Modi will amend the Waqf Act despite opposition from leaders like Uddhav Thackeray and Sharad Pawar.

"Modi ji wants to change the Waqf Board law, but Uddhav ji, Sharad Pawar and Supriya Sule are opposing it," Shah said, addressing a rally at Umarkhed in Maharashtra's Yavatmal district.

"Uddhav ji, listen carefully, you all can protest as much as you want, but Modi ji will amend the Waqf Act," he said. Shah said there are two camps in the November 20 Maharashtra assembly polls, one of 'Pandavas' represented by the BJP-led Mahayuti and the other of 'Kauravas' represented by Maha Vikas Aghadi.

"Uddhav Thackeray claims that his Shiv Sena is the real one. Can the real Shiv Sena go against renaming Aurangabad to Sambhajinagar? Can the real Shiv Sena go against renaming Ahmednagar to Ahilyanagar? The real Shiv Sena stands with the BJP," Shah said.

"Rahul Baba used to say that his government would credit money in the accounts of the people instantly. You were unable to fulfil your promises in Himachal, Karnataka, and Telangana," he said.

Shah said the Mahayuti alliance has promised that women will get Rs 2,100 per month under the Ladki Bahin Yojana. "Kashmir is an integral part of India and no power in the world can snatch it away from us," Shah said.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 17,2024

Mangaluru: District-in-Charge Minister and Minister for Health and Family Welfare, Dinesh Gundu Rao, announced that a day-care chemotherapy centre will soon be established at District Wenlock Hospital. Speaking to mediapersons after reviewing the activities at Wenlock and Government Lady Goschen Hospital, he shared the government’s plans to enhance healthcare services in the region.

Key Initiatives Announced

•    Day-Care Chemotherapy Centre:

  • Ten beds will be reserved for cancer patients.
  • The government will collaborate with Yenepoya Hospital to provide chemotherapy treatments.
  • All required facilities for the centre are already in place, awaiting inauguration by the Chief Minister.

•    Wenlock Hospital Facelift:

  • Critical Care Block: To be built at a cost of ₹24 crore.
  • Integrated Public Health (IPH) Lab: Planned with a budget of ₹1 crore.
  • New OPD Block: As per a 2017 agreement, KMC Hospital will take up construction. Discussions with KMC management are underway.

•    Additional Requirements:

  • A new mortuary and post-mortem building.
  • Paramedical college building.
  • Modern kitchen.
  • Bridge connecting two buildings within the hospital.

•    Total facelift cost: ₹6 crore to ₹10 crore, utilizing funds from the Department of Health and Family Welfare and CSR contributions.

•    Timeline:
By December or January, priority works will be finalized. The superintendents of Wenlock and Lady Goschen Hospitals are scheduled to visit Bengaluru next week to discuss these projects.

•    MRI Fee Allegations:
The minister assured that allegations of patients being charged for MRI scans at Wenlock Hospital will be resolved at the earliest.
These measures aim to improve healthcare accessibility and infrastructure, positioning Wenlock Hospital as a state-of-the-art facility in the region.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 28,2024

DCoffice.jpg

Mangaluru: The iconic Old DC office, a building steeped in 400 years of history, will be the centerpiece of the Heritage Week celebrations in the city. Once the administrative hub of the erstwhile Canara district during the British era, the building now serves as a symbol of Mangaluru’s rich heritage and cultural significance.

Historic Significance

Initially built during the rule of the Bangas under the Vijayanagara Empire, the structure was later converted into the collector’s office. Following an agreement between Tipu Sultan and the British in 1784, the building came under Tipu’s possession until his death. Subsequently, Major Sir Thomas Munro used it as the office for the first district collector.

The building has also seen historical milestones, including the participation of 88 individuals from the district in World War I (1914–1919), as recorded on a commemorative plaque on its exterior.

Heritage Festival: Echoes

To celebrate the city’s history and tourism potential, the Dakshina Kannada district administration is organizing "Echoes," a heritage festival on November 30 and December 1 at the Old DC office premises. The event will feature:

  • A heritage exhibition (open from 10 AM to 6 PM).
  • An art contest for school students.
  • Guided mini heritage walks open to all.
  • An urban sketching contest for college students.
  • A panel discussion on sustainability, followed by a prize distribution ceremony.
  • A musical evening featuring Sur Safar, a fusion band.

A Gateway to Tourism

The festival aims to draw attention to Mangaluru’s untapped tourism potential by blending art, history, and culture. It invites residents and visitors to rediscover the region’s legacy while fostering a sense of pride in its historical landmarks.

This initiative not only commemorates the past but also looks to inspire future efforts in heritage preservation and sustainable tourism.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.