I/II. https://thewire.in/120922/aadhaar-supreme-court-uid/
Without Supreme Court Interference, the Aadhaar Project is a Ticking Time Bomb BY USHA RAMANATHAN ON 04/04/2017 The court must hear pending cases on Aadhaar urgently, before the government further inhibits people’s rights and liberties under the facade of ’empowerment’. George Mikes, who travelled to write about people and how they lived, described seeing a production of The Earth Spider at the Kabuki theatre in Japan. It is enough, for our purpose, to know that the Earth Spider was the villain and that a host of supporters of the protagonist set out to challenge it. What follows is a tale of “tremendous excitement, expressed by the fact that they all sit about quietly, almost motionless. They repeat: ‘Let us hurry, let us gallop. We have not a moment to lose!’ Whereupon they all go on sitting there.” Three men move about the stage declaring that “everything depends on speed” and they, “still motionless”, proclaim, “Let us not spare ourselves! … We have a sacred duty to perform.” More pursuers arrive on stage, all say that there cannot be a moment’s rest, and sit down. The show keeps going for a long time, till finally, tired of waiting for the promised life-and-death combat, the Earth Spider emerges from the cave where he had hidden himself in plain sight, dances to gain attention and, receiving none, collapses and dies. It is possible that, given the enormous porosity and magnitude of untried technologies being deployed in the unique identification (UID) project, it too may crumble or implode, not very differently from the Earth Spider. But, by then, many systems may be destroyed which will be difficult to resurrect, many vulnerabilities created, many people made into ghosts and duplicates, and many a problem erected as testimony to a project that should never have been. As we get closer to that possibility, the court has spoken once, twice, six times, even a seventh time in September 2016, to check, restrict and contain the Earth Spider UID project. But the Earth Spider project will allow no law, absence of a law or order from the apex court to cramp its exuberance and ambition. If the Supreme Court defers, delays or waits for the perfect moment in hearing the Aadhaar cases pending before it, we could be left with constitutional redundancy, threatening axioms such as these with an early demise: The constitution is not about the power of the state, but about the limits of the power of the state over the people. There can be no waiver of fundamental rights. Colonialism produced subjects; freedom made citizens of erstwhile subjects. The court is a bulwark against the erosion of the rights of the people. It is the state that is to be transparent to the people; not the people to the state. Surveillance is a violation of the personal liberty of the people, and the exception proves the rule. There is more in this catalogue which will have to be explored and debated in court. Counting the changes Even as challenges have been pending in court, the focus of the project has shifted from the citizen to the resident, and from the resident to the customer. Initially, the Unique Identification Authority of India (UIDAI) was set up to help standardise data elements in the various governmental databases and assist in their digitisation. The empowered group of ministers who met to decide the contours of the UIDAI were clear in their instruction: “UIDAI may not directly undertake creation of any additional database…” When the National Population Register (NPR) was started, that is how enrolment was to be done. However, soon after Nandan Nilekani took charge in July 2009, the rules were changed. The then prime minister, Manmohan Singh, constituted a cabinet committee on the UID which gave Nilekani permission to do ten crore enrolments. That was increased to 20 crore, at which stage the home ministry raised objections to the insecure manner in which people were being enrolled in the UID database and the unverified acceptance of documents that was part of this process. In January 2012 the conflict came to a head, and was strangely resolved by the Registrar General of India and the UIDAI sharing the country’s population 50-50. How the concerns of the home ministry were dealt with was not explained; we only know that it was at the intervention of the prime minister. There was a further stand-off between the two agencies, where too the compromise was brokered by the PM. In the run-up to the 2014 elections, Narendra Modi, Arun Jaitley and Ananth Kumar canvassed for the scrapping of the UID project if they came to power. In May 2014, home minister Rajnath Singh was reported to have taken the decision to go on with enrolling citizens for the NPR, and perhaps to amalgamate the UID database with the NPR database, after verification. That changed, inexplicably, in July, following a meeting between Nilekani and the newly-elected prime minister, Narendra Modi, and the UID project was restarted with unrestrained enthusiasm. All we have as explanation is Jaitley’s statement in the Rajya Sabha, where he said, “Earlier, some of us had doubts over Aadhaar…Some of your people (in Congress) also had doubts. Later, a presentation was made to the prime minister where the doubts were cleared.” The last nail in the coffin came in April 2016, after the Aadhaar Act had been passed by the Lok Sabha as a money Bill. A long-drawn battle over biometrics between the UIDAI and the CBI culminated in the Act of 2016 declaring that biometrics would not be shared by the UIDAI at all – not if national security demands it, nor if a court orders it (sections 27, 33). There is also no access to one’s own ‘core biometrics’ (all biometrics other than the photograph) (section 28(5) proviso). Relying on this clause, the UIDAI has declared that they will not share the biometric database with the Registrar General of India to construct the NPR. Last heard, the home ministry has been advised to seek the attorney general’s advice on the sourcing of biometric data from the UIDAI database; else the RGI faces the prospect of collecting, all over again, the biometrics of 70 crore people! A hundred crore people were enrolled before the definition of a ‘resident’ entered the law, so what is the value of the database as even a database of ‘residents’? Plainly, it does not matter. Because the game has already moved on – from the ‘resident’ to the ‘customer’. It is now the UIDAI’s database that is forming the basis of all governmental intervention. This is apparently a resident database – except it is not even that. The Aadhaar Act 2016 defines as a resident “an individual who has resided in India for a period or periods amounting in all to one hundred and eighty-two days or more in the twelve months immediately preceding the date of application for enrolment”. What alibis does one need to establish that one has been in the country for 182 days? Immigration stamps in passports may help in demonstrating absence from the country, but presence? How do NRIs get enrolled? Are there some exceptions to the rule that have been notified? A hundred crore people were enrolled before this definition entered the law and those enrolments are not being revisited, so what is the value of the database as even a database of ‘residents’? Plainly, it does not matter. Because the game has already moved on – from the ‘resident’ to the ‘customer’. When the project started, it was said that no information would leave the database, no matter the destination. It was to be used only for authentication. The UID was for people who were unable to access governmental services because they have no means of identifying themselves to the state. In the strategy overview document from 2010, the phrase used is ‘Know Your Resident’. By the time of the Aadhaar Act of 2016, the focus was on KYC – Know Your Customer. With e-KYC in the Act, the database is to be used not only for authentication – not just a yes or no answer – but the passing on of the data held by the UIDAI to ‘requesting entities’. And, according to section 57, ‘any corporate or person’ can use this database, decreed in a section that carries the sub-heading ‘Act not to prevent use of aadhaar number for other purposes under law’. Those uses have already swung into being: Jio, TrustID, OnGrid and the multiple advertisements beaming into our homes from banks, mobile phone companies and anyone else who is able to make a plan to leverage this database for their purpose. How did we get here? On what basis was policy made by the states and the Centre? On September 28, 2010, a statement issued by 17 eminent persons including Justice V.R. Krishna Iyer, Romila Thapar, S.R. Sankaran, Upendra Baxi, Bezwada Wilson, Justice A.P. Shah and Aruna Roy asked the government to pause and do what has to be done as a prelude to a project with such potential consequences. There was, for instance, no law. There was no feasibility study that investigated the different contours of the project and so no study of what the project would do to constitutional rights and liberties. It is, in fact, this that caused the Parliamentary Standing Committee on Finance to say, “The UID scheme has been conceptualised with no clarity of purpose and leaving many things to be sorted out during the course of its implementation; and is being implemented in a directionless way with a lot of confusion.” What to believe, with flip-flops like these? How then did the central and state governments make policy decisions around the UID project? What is on record is deeply disturbing. Rajasthan’s affidavits to the court are audacious in the changes it so easily adopts with such little explanation. On September 23, 2013, the Supreme Court passed the first of many orders saying that no one shall be denied any service to which they are entitled only because they are not enrolled for a UID. Oil marketing companies, the UIDAI and the central government rushed to the court to ask that the stay be lifted. The court refused to oblige. States then filed their papers in court. Round one: In a document dated December 5, 2013, Hansraj Yadav, additional director (UID), Department of Information Technology and Communication, said in an affidavit that “the state of Rajasthan is unambiguously in favour of implementation of UID scheme.” On that date, elections to the state assembly had been held but the results were not declared yet, the Congress was still in power in the state as well as in the Centre, and the Centre was promoting the project. Round two: Yadav’s second affidavit is dated February 10, 2014, by which time the BJP had formed the government in the state and the Congress was still in control in the Centre. This time round, the state said that a citizenship card was more relevant than the UID, especially since Rajasthan is a border state. Poor verification of residents’ credentials was cause for concern for the state government; they were concerned that poor delivery of Aadhaar numbers may result in the denial of benefits to the poor, especially in rural areas. Service delivery is the mandate of state governments and the project produces problems for federalism. “Therefore, the Aadhaar scheme is misconceived … UID scheme is clearly an infringement of the federal structure and spirit of the constitution,” the affidavit said. The software for biometrics is the property of L-1 Identity Solutions Operating Company, which is licensed to the UIDAI, and states do not have any control over it. This, the affidavit reads, is a “huge security risk” and the state government has “strong reservation against data not being transparently and fully shared with the states”. Round three: On October 15, 2015, a third affidavit was filed, again by Yadav. By now, the government at the Centre was the BJP, which had done a turnaround on the UID project, and BJP formed the government in the state too. By this time, the government at the Centre had said to the court that the people of this country do not have a right to privacy and the court had passed its order dated August 11, 2015. Various applications looking to expand the use of the UID beyond the public distribution system and LPG subsidies, permitted by the court, had been filed. This was one, and in this narration, the UID now became the one tool of empowerment for the poor and rural dwellers. These somersaults are on the record of the court. The non-application of mind provides one more reason that the court needs to hear the cases urgently. Usha Ramanathan is a legal researcher. This is the first in a series of articles on the UID that Usha Ramanathan will be writing for The Wire. II. http://www.hindustantimes.com/india-news/what-s-really-happening-when-you-swipe-your-aadhaar-card-to-make-a-payment/story-2fLTO5oNPhq1wyvZrwgNgJ.html Aadhaar marks a fundamental shift in citizen-state relations: From ‘We the People’ to ‘We the Government’ Your fingerprints, iris scans, details of where you shop. Compulsory Aadhaar means all this data is out there. And it’s still not clear who can view or use it Updated: Apr 03, 2017 12:34 IST Pranesh Prakash Hindustan Times Until recently, people were allowed to opt out of Aadhaar and withdraw consent to have their data stored. This is no longer going to be an option.(Siddhant Jumde / HT Illustration) Imagine you’re walking down the street and you point the camera on your phone at a crowd of people in front of you. An app superimposes on each person’s face a partially-redacted name, date of birth, address, whether she’s undergone police verification, and, of course, an obscured Aadhaar number. OnGrid, a company that bills itself as a “trust platform” and offers “to deliver verifications and background checks”, used that very imagery in an advertisement last month. Its website notes that “As per Government regulations, it is mandatory to take consent of the individual while using OnGrid”, but that is a legal requirement, not a technical one. Since every instance of use of Aadhaar for authentication or for financial transactions leaves behind logs in the Unique Identification Authority of India’s (UIDAI) databases, the government can potentially have very detailed information about everything from the your medical purchases to your use of video-chatting software. The space for digital identities as divorced from legal identities gets removed. Clearly, Aadhaar has immense potential for profiling and surveillance. Our only defence: law that is weak at best and non-existent at worst. The Aadhaar Act and Rules don’t limit the information that can be gathered from you by the enrolling agency; it doesn’t limit how Aadhaar can be used by third parties (a process called ‘seeding’) if they haven’t gathered their data from UIDAI; it doesn’t require your consent before third parties use your Aadhaar number to collate records about you (eg, a drug manufacturer buying data from various pharmacies, and creating profiles using Aadhaar). It even allows your biometrics to be shared if it is “in the interest of national security”. The law offers provisions for UIDAI to file cases (eg, for multiple enrollments), but it doesn’t allow citizens to file a case against private parties or the government for misuse of Aadhaar or identity fraud, or data breach. It is also clear that the government opposes any privacy-related improvements to the law. After debating the Aadhaar Bill in March 2016, the Rajya Sabha passed an amendment by MP Jairam Ramesh that allowed people to opt out of Aadhaar, and withdraw their consent to UIDAI storing their data, if they had other means of proving their identity (thus allowing Aadhaar to remain an enabler). Read more Government admits Aadhaar was ‘great initiative’ of Congress regime Over 1 billion Indians enrol for Aadhaar: How the govt plans to sign up the rest But that amendment, as with all amendments passed in the Rajya Sabha, was rejected by the Lok Sabha, allowing the government to make Aadhaar mandatory, and depriving citizens of consent. While the Aadhaar Act requires a person’s consent before collecting or using Aadhaar-provided details, it doesn’t allow for the revocation of that consent. In other countries, data security laws require that a person be notified if her data has been breached. In response to an RTI application asking whether UIDAI systems had ever been breached, the Authority responded that the information could not be disclosed for reasons of “national security”. The citizen must be transparent to the state, while the state will become more opaque to the citizen. HOW DID AADHAAR CHANGE? How did Aadhaar become the behemoth it is today, with it being mandatory for hundreds of government programmes, and even software like Skype enabling support for it? The first detailed look one had at the UID project was through an internal UIDAI document marked ‘Confidential’ that was leaked through WikiLeaks in November 2009. That 41-page dossier is markedly different from the 170-page ‘Technology and Architecture’ document that UIDAI has on its website now, but also similar in some ways. Read more MS Dhoni’s Aadhaar details leaked, wife Sakshi complains to Ravi Shankar Prasad Journalist uses fake IDs to get Aadhaar card in sting operation, booked by police In neither of those is the need for Aadhaar properly established. Only in November 2012 — after scholars like Reetika Khera pointed out UIDAI’s fundamental misunderstanding of leakages in the welfare delivery system — was the first cost-benefit analysis commissioned, by when UIDAI had already spent ₹28 billion. That same month, Justice KS Puttaswamy, a retired High Court judge, filed a PIL in the Supreme Court challenging Aadhaar’s constitutionality, wherein the government has argued privacy isn’t a fundamental right. Every time you use Aadhaar, you leave behind logs in the UIDAI databases. This means that the government can potentially have very detailed information about everything from the your medical purchases to your use of video-chatting software. Even today, whether the ‘deduplication’ process — using biometrics to ensure the same person can’t register twice — works properly is a mystery, since UIDAI hasn’t published data on this since 2012. Instead of welcoming researchers to try to find flaws in the system, UIDAI recently filed an FIR against a journalist doing so. At least in 2009, UIDAI stated it sought to prevent anyone from “[e]ngaging in or facilitating profiling of any nature for anyone or providing information for profiling of any nature for anyone”, whereas the 2014 document doesn’t. As OnGrid’s services show, the very profiling that the UIDAI said it would prohibit is now seen as a feature that all, including private companies, may exploit. UID has changed in other ways too. In 2009, it was as a system that never sent out any information other than ‘Yes’ or ‘No’, which it did in response to queries like ‘Is Pranesh Prakash the name attached to this UID number’ or ‘Is April 1, 1990 his date of birth’, or ‘Does this fingerprint match this UID number’. With the addition of e-KYC (wherein UIDAI provides your demographic details to the requester) and Aadhaar-enabled payments to the plan in 2012, the fundamentals of Aadhaar changed. This has made Aadhaar less secure. SECURITY CONCERNS With Aadhaar Pay, due to be launched on April 14, a merchant will ask you to enter your Aadhaar number into her device, and then for your biometrics — typically a fingerprint, which will serve as your ‘password’, resulting in money transfer from your Aadhaar-linked bank account. Basic information security theory requires that even if the identifier (username, Aadhaar number etc) is publicly known — millions of people names and Aadhaar numbers have been published on dozens of government portals — the password must be secret. That’s how most logins works, that’s how debit and credit cards work. How are you or UIDAI going to keep your biometrics secret? Read more If MS Dhoni’s personal Aadhaar data can be leaked, how safe is yours? Jaitley, Chidambaram clash in Parliament over MS Dhoni’s Aadhaar data leak In 2015, researchers in Carnegie Mellon captured the iris scans of a driver using car’s side-view mirror from distances of up to 40 feet. In 2013, German hackers fooled Apple iOS’s fingerprint sensors by replicating a fingerprint from a photo taken off a glass held by an individual. They even replicated the German Defence Minister’s fingerprints from photographs she herself had put online. Your biometrics can’t be kept secret. Typically, even if your username (in this case, Aadhaar number) is publicly known, your password must be secret. That’s how most logins works, that’s how debit and credit cards work. How are you or UIDAI going to keep your biometrics secret? In the US, in a security breach of 21.5 million government employees’ personnel records in 2015, 5.2 million employees’ fingerprints were copied. If that breach had happened in India, those fingerprints could be used in conjunction with Aadhaar numbers not only for large-scale identity fraud, but also to steal money from people’s bank accounts. All ‘passwords’ should be replaceable. If your credit card gets stolen, you can block it and get a new card. If your Aadhaar number and fingerprint are leaked, you can’t change it, you can’t block it. The answer for Aadhaar too is to choose not to use biometrics alone for authentication and authorisation, and to remove the centralised biometrics database. And this requires a fundamental overhaul of the UID project. Aadhaar marks a fundamental shift in citizen-state relations: from ‘We the People’ to ‘We the Government’. If the rampant misuse of electronic surveillance powers and wilful ignorance of the law by the state is any precedent, the future looks bleak. The only way to protect against us devolving into a total surveillance state is to improve rule of law, to strengthen our democratic institutions, and to fundamentally alter Aadhaar. Sadly, the political currents are not only not favourable, but dragging us in the opposite direction. Read more Aadhaar failed to stop corruption, denying elderly benefits: Activist Nikhil Dey Your bank account number could become common identity platform for financial products (Pranesh Prakash is policy director at the Centre for Internet and Society, and Affiliated Fellow at Yale Law School’s Information Society Project) -- Peace Is Doable -- You received this message because you are subscribed to the Google Groups "Green Youth Movement" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To post to this group, send an email to [email protected]. Visit this group at https://groups.google.com/group/greenyouth. For more options, visit https://groups.google.com/d/optout.
