[<<After the report appeared, the UIDAI had in a statement said that there
“has not been any Aadhaar data breach”.>>

<<Joint Commissioner of Police (Crime Branch) Alok Kumar confirmed that an
FIR had been registered and an investigation launched. The FIR has been
lodged with the Crime Branch’s cyber cell under IPC Sections 419
(punishment for cheating by impersonation), 420 (cheating), 468 (forgery)
and 471 (using as genuine a forged document), as well Section 66 of the IT
Act and Section 36/37 of the Aadhaar Act.>>

First comes the denial.
Then shoot the messenger!

***If there's no "breach", then what's precisely the "crime" here?***
The report is virtually silent on that. The IPC Sections are the only clues.
The MSM otherwise, except for this black swan report, is just mum.
However, a news portal tells us: <<The FIR reportedly states that the
journalist and her sources “have unauthorisedly accessed the Aadhaar
ecosystem in connivance of the criminal conspiracy”.>>
(Ref.: <
https://thewire.in/211333/uidai-files-fir-tribune-reporter-aadhaar-breach-story-report/
>.)

The Tribune expose was, however, picked up even by the global media (see: <
http://www.republicworld.com/s/18075/american-whistleblower-edward-snowden-hints-aadhaar-database-can-be-misused>,
<
http://www.ibtimes.co.uk/aadhaar-data-breach-indias-national-id-database-details-1-2-billion-citizens-leaked-1654014>,
<https://www.rt.com/news/415025-aadhaar-data-breach-denied/>, <
https://www.engadget.com/2018/01/04/india-citizen-aadhaar-database-breached/
>).]

I/II.
http://indianexpress.com/article/india/fir-against-tribune-reporter-over-aadhaar-data-breach-story-5014674/

FIR against Tribune reporter over Aadhaar data breach story
The FIR also names Anil Kumar, Sunil Kumar and Raj, all of whom were
mentioned in The Tribune report as people Khaira contacted in the course of
her reporting.

Written by Mahender Singh Manral |

New Delhi | Updated: January 7, 2018 7:35 am

The UIDAI’s media unit did not respond to calls and texts from The Sunday
Express. (AP Photo)

RELATED NEWS
All is not well with AadhaarAll is not well with Aadhaar
Money stops for leprosy patient in Bengaluru, UIDAI exempts biometrics
after doctor’s letterMoney stops for leprosy patient in Bengaluru, UIDAI
exempts biometrics after doctor’s letter
Aadhaar-based attendance system for rail employees by January
31Aadhaar-based attendance system for rail employees by January 31

A deputy director of the Unique Identification Authority of India (UIDAI)
has registered an FIR against The Tribune newspaper and its reporter Rachna
Khaira following her report on how anonymous sellers over WhatsApp were
allegedly providing access to Aadhaar numbers for a fee.

The FIR also names Anil Kumar, Sunil Kumar and Raj, all of whom were
mentioned in The Tribune report as people Khaira contacted in the course of
her reporting.

Joint Commissioner of Police (Crime Branch) Alok Kumar confirmed that an
FIR had been registered and an investigation launched. The FIR has been
lodged with the Crime Branch’s cyber cell under IPC Sections 419
(punishment for cheating by impersonation), 420 (cheating), 468 (forgery)
and 471 (using as genuine a forged document), as well Section 66 of the IT
Act and Section 36/37 of the Aadhaar Act.

When contacted, The Tribune’s editor-in-chief Harish Khare refused to
comment on the FIR. In the FIR, the complainant, B M Patnaik, who works
with UIDAI’s logistics and grievance redressal department, states: “An
input has been received through The Tribune dated January 3, 2018, that the
‘The Tribune purchased’ a service being offered by anonymous sellers over
WhatsApp that provided unrestricted access to details for any of the more
than 1 billion Aadhaar numbers created in India thus far.”

The FIR details how the reporter got in touch with the other persons named
in the FIR and goes on to state: “The above-mentioned persons have
unauthorisedly accessed the Aadhaar ecosystem in connivance of the criminal
conspiracy… The act of the aforesaid involved persons is in violation of
(the various sections mentioned in the FIR)… Hence, an FIR needs to be
filed at the cyber cell for the said violation.”

The UIDAI’s media unit did not respond to calls and texts from The Sunday
Express. The UIDAI CEO, when contacted, said he was in a meeting. The
Tribune report, dated January 3, had stated: “It took just Rs 500, paid
through Paytm, and 10 minutes in which an ‘agent’ of the group running the
racket created a ‘gateway’ for this correspondent and gave a login ID and
password. Lo and behold, you could enter any Aadhaar number in the portal,
and instantly get all particulars that an individual may have submitted to
the UIDAI (Unique Identification Authority of India), including name,
address, postal code (PIN), photo, phone number and email.”

Subramanian Swamy Says Aadhar A Threat To National Security

Late on Saturday, UIDAI’s Chandigarh regional office, wrote to The
Tribune’s Editor-in-Chief, asking if “was at all possible for your
correspondent to view or obtain Fingerprints and Iris scan of any person
through the aforesaid access to UIDAI portal” and “how many Aadhaar numbers
did the correspondent actually enter through the said login user id and
password and whom did those Aadhaar numbers belong to”. The letter asked
for these details to be sent by January 8, “failing which it will be
presumed that there was no access to any Fingerprints and/or Iris scan”.

After the report appeared, the UIDAI had in a statement said that there
“has not been any Aadhaar data breach”.

“The Aadhaar data, including biometric information, is fully safe and
secure,” it had said, adding, “There has not been any data breach of the
biometric database, which remains fully safe and secure with the highest
encryption at UIDAI and a mere display of demographic information cannot be
misused without biometrics.”

II.
http://www.tribuneindia.com/news/nation/rs-500-10-minutes-and-you-have-access-to-billion-aadhaar-details/523361.html

TRIBUNE INVESTIGATION — SECURITY BREACH

Rs 500, 10 minutes, and you have access to billion Aadhaar details
Group tapping UIDAI data may have sold access to 1 lakh service providers

Related Articles
UIDAI denies any breach of Aadhaar data
Aadhaar data breach finds mention in Parliament
Aadhaar data breach shocks Twitterati, top trend for the day
Also in this section
Lalu gets 3.5-yr jail in fodder scam case
Will challenge CBI verdict against father, says Tejaswi
2nd chargesheet against Misa, her husband
Naidu sends privilege notice against Rahul to LS Speaker
Potatoes dumped in front of UP CM’s Lucknow house
Rs 500, 10 minutes, and you have access to billion Aadhaar details
Rs 500, 10 minutes, and you have access to billion Aadhaar details
Previous ImageNext Image

.

Rachna Khaira

Tribune News Service

Jalandhar, January 3

It was only last November that the UIDAI asserted that “Aadhaar data is
fully safe and secure and there has been no data leak or breach at UIDAI.”
Today, The Tribune “purchased” a service being offered by anonymous sellers
over WhatsApp that provided unrestricted access to details for any of the
more than 1 billion Aadhaar numbers created in India thus far.
(Follow The Tribune on Facebook; and Twitter @thetribunechd)
It took just Rs 500, paid through Paytm, and 10 minutes in which an “agent”
of the group running the racket created a “gateway” for this correspondent
and gave a login ID and password. Lo and behold, you could enter any
Aadhaar number in the portal, and instantly get all particulars that an
individual may have submitted to the UIDAI (Unique Identification Authority
of India), including name, address, postal code (PIN), photo, phone number
and email.
What is more, The Tribune team paid another Rs 300, for which the agent
provided “software” that could facilitate the printing of the Aadhaar card
after entering the Aadhaar number of any individual.
When contacted, UIDAI officials in Chandigarh expressed shock over the full
data being accessed, and admitted it seemed to be a major national security
breach. They immediately took up the matter with the UIDAI technical
consultants in Bangaluru.
Sanjay Jindal, Additional Director-General, UIDAI Regional Centre,
Chandigarh, accepting that this was a lapse, told The Tribune: “Except the
Director-General and I, no third person in Punjab should have a login
access to our official portal. Anyone else having access is illegal, and is
a major national security breach.”
1 lakh illegal users

Investigations by The Tribune reveal that the racket may have started
around six months ago, when some anonymous groups were created on WhatsApp.
These groups targeted over 3 lakh village-level enterprise (VLE) operators
hired by the Ministry of Electronics and Information Technology (ME&IT)
under the Common Service Centres Scheme (CSCS) across India, offering them
access to UIDAI data.
CSCS operators, who were initially entrusted with the task of making
Aadhaar cards across India, were rendered idle after the job was withdrawn
from them. The service was restricted to post offices and designated banks
to avoid any security breach in November last year.
Spotting an opportunity to make a quick buck, more than one lakh VLEs are
now suspected to have gained this illegal access to UIDAI data to provide
“Aadhaar services” to common people for a charge, including the printing of
Aadhaar cards. However, in wrong hands, this access could provide an
opportunity for gross misuse of the data.
The hackers seemed to have gained access to the website of the Government
of Rajasthan, as the “software” provided access to “aadhaar.rajasthan.gov.in”,
through which one could access and print Aadhaar cards of any Indian
citizen. However, it could not be ascertained whether the “portals” were
genuinely of Rajasthan, or it was mentioned just to mislead.
Sanjay Jindal said all of this could be confirmed only after a technical
investigation was conducted by the UIDAI.
‘Privacy at risk’
“Leakage of Aadhaar data reveals that the project has failed the privacy
test. At the recently concluded 11th WTO Ministerial Conference, India
submitted a written position on e-commerce, opposing the demand for
negotiations on e-commerce by the US and its allies. The latter were
demanding access to citizens’ database for free. The revelation by The
Tribune also means that the proposed data protection law will now hold no
purpose, as the data has already been breached. The state governments must
immediately disassociate themselves and cancel the MoU signed with UIDAI,”
said Gopal Krishan, New Delhi-based convener of the Citizens Forum for
Civil Liberties, who appeared before the Special Parliamentary Committee
that examined the Aadhaar Bill in 2010.
A quick chat, and full access
12:30 pm: This correspondent posing as ‘Anamika’ contacted a person on
WhatsApp number 7610063464, who introduced himself as ‘Anil Kumar’. He was
asked to create an access portal.
12:32pm: Kumar asked for a name, email ID and mobile number, and also asked
for Rs 500 to be credited in his Paytm No. 7610063464.
12:35 pm: This correspondent created an email ID, [email protected],
and sent mobile number ******5852 to the anonymous agent.
12:48 pm: Rs 500 transferred through Paytm.
12:49 pm: This correspondent received an email saying, “You have been
enrolled as Enrolment Agency Administrator for ‘CSC SPV’. Your Enrolment
Agency Administrator ID is ‘Anamika_6677’.” Also, it was said that a
password would be sent in a separate mail, which followed shortly.
12:50 pm: This correspondent had access to the Aadhaar details of every
Indian citizen registered with the UIDAI.
Printing Aadhaar card
This correspondent later again approached Anil Kumar to ask for software to
print Aadhaar cards. He asked for Rs 300 through Paytm No. 8107888008 (in
the name of ‘Raj’). Once paid, a person identifying himself as Sunil Kumar
called from mobile number 7976243548, and installed software on this
correspondent’s computer by accessing it remotely through “TeamViewer”.
Once the job was done, he deleted the software drivers, even from the
recycle bin.
Possible misuse
Getting SIM cards, or bank accounts in anyone’s name. Last month, a man was
arrested in Jalandhar for withdrawing money from someone’s bank account by
submitting a fake Aadhaar card.

Sitaram Yechury
✔
@SitaramYechury
The perils of making Aadhaar mandatory and linking it to bank accounts, as
insisted upon by Modi govt, are visible here. Do we need more proof to stop
this madness?
http://www.tribuneindia.com/news/nation/rs-500-10-minutes-and-you-have-access-to-billion-aadhaar-details/523361.html
…

9:06 AM - Jan 4, 2018

Rs 500, 10 minutes, and you have access to billion Aadhaar details
JALANDHAR:It was only last November that the UIDAI asserted that “Aadhaar
data is fully safe and secure and there has been no data leak or breach at
UIDAI.

tribuneindia.com
 81 81 Replies   639 639 Retweets   814 814 likes
Twitter Ads info and privacy


Randeep S Surjewala
✔
@rssurjewala
‘AADHAR’ data breached yet again!

As every citizen’s personal information is exposed to hackers everyday &
‘Right to Privacy’ is mocked and flouted with impunity, Modi Govt remains
immune.

Is anyone listening?
http://www.tribuneindia.com/news/nation/rs-500-10-minutes-and-you-have-access-to-billion-aadhaar-details/523361.html
…

9:29 AM - Jan 4, 2018

Rs 500, 10 minutes, and you have access to billion Aadhaar details
JALANDHAR:It was only last November that the UIDAI asserted that “Aadhaar
data is fully safe and secure and there has been no data leak or breach at
UIDAI.

tribuneindia.com
 150 150 Replies   974 974 Retweets   2,032 2,032 likes
Twitter Ads info and privacy

Nitin A. Gokhale
✔
@nitingokhale
This is dangerous and criminal negligence of data security. Kudos to the
reporter for unveiling the racket. A crackdown on the culprits& a
corrective step is imperative: Rs 500, 10 minutes, and you have access to
billion Aadhaar details
http://www.tribuneindia.com/news/nation/rs-500-10-minutes-and-you-have-access-to-billion-aadhaar-details/523361.html
… via @thetribunechd

11:01 AM - Jan 4, 2018

Rs 500, 10 minutes, and you have access to billion Aadhaar details
JALANDHAR:It was only last November that the UIDAI asserted that “Aadhaar
data is fully safe and secure and there has been no data leak or breach at
UIDAI.

tribuneindia.com
 10 10 Replies   100 100 Retweets   81 81 likes
Twitter Ads info and privacy

Congress
✔
@INCIndia
Rs 500. That's all it takes for someone to steal the data of a billion
citizens. Envisioned by UPA as a tool for inclusion, #Aadhaar has become an
identity theft nightmare under the NDA.
http://www.tribuneindia.com/news/nation/rs-500-10-minutes-and-you-have-access-to-billion-aadhaar-details/523361.html
…

10:32 AM - Jan 4, 2018

Rs 500, 10 minutes, and you have access to billion Aadhaar details
JALANDHAR:It was only last November that the UIDAI asserted that “Aadhaar
data is fully safe and secure and there has been no data leak or breach at
UIDAI.

tribuneindia.com
 129 129 Replies   929 929 Retweets   1,629 1,629 likes


-- 
Peace Is Doable

-- 
You received this message because you are subscribed to the Google Groups 
"Green Youth Movement" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To post to this group, send an email to [email protected].
Visit this group at https://groups.google.com/group/greenyouth.
For more options, visit https://groups.google.com/d/optout.

Reply via email to