Re: Legal and technical reasons for biometric breech
rishi tarar <[email protected]> Thu, 11 Jan 2018 17:32:17 +0530
| Newsgroups | gmane.org.telecom.india-gii |
|---|---|
| Message-ID | <CANA6zZcL52T4jUL3HfA5jMc_+9S42BgPE=b4RC7PtSViBz297g@mail.gmail.com> |
--===============7709886091727219226== Content-Type: multipart/alternative; boundary="f403045e67be61720005627eeb90" --f403045e67be61720005627eeb90 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable There is no admin access granted to partners to access aadhar db. Organisation who have biometric access (other than bank) can only validate the identity and number by geting binary (yes/no) response from aadhar api/dB. Bank can access the demographic details of people from aadhar api.All this aadhar network which is extended to multiple partners in form of bank ,Telco and others are part of private IP network (dedicated link).There is no direct/single session allowed for authentication from public IP network. On Tuesday, January 9, 2018, Suresh Ramasubramanian <[email protected]> wrote: > Very well written. The issue is also that there=E2=80=99s very little ac= cess control to backdoors providing bulk admin access to the Aadhaar db, everything short of the core biometrics thank God for small mercies > > > > It isn=E2=80=99t just misuse by the custodians. It is the issue of vario= us custodians getting unfettered access and then having that access compromised by external third parties who then have that same unfettered access to Aadhaar data. > > > > > > From: India-gii <india-gii-bounces+suresh=3Dhserus.net-IAPFreCvJWP2/[email protected]= g> on behalf of Andy Oram <[email protected]> > Date: Tuesday, 9 January 2018 at 5:24 PM > To: <[email protected]> > Subject: [india-gii] Legal and technical reasons for biometric breech > > > > I haven't seen discussion of that scandal on this list--maybe I missed some email. Anyway, I thought this article a useful, concise description of the various facets of the problem: > > > > https://scroll.in/article/833230/explainer-aadhaar-is-vulnerable-to-identit= y-theft-because-of-its-design-and-the-way-it-is-used > > Andy Oram | Editor > O'Reilly Media, Inc. | 617-499-7479 | oreilly.com > > > > _______________________________________________ India-gii mailing list India-gii-IAPFreCvJWP2/[email protected] https://lists.india-gii.org/mailman/listinfo/india-gii --f403045e67be61720005627eeb90 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable There is no admin access granted to partners to access aadhar db. Organisat= ion who have biometric access (other than bank) can only validate the ident= ity and number by geting binary (yes/no) response from aadhar api/dB.<br>Ba= nk can access the demographic details of people from aadhar api.All this aa= dhar network which is extended to multiple partners in form of bank ,Telco = and others are part of private IP network (dedicated link).There is no dire= ct/single session allowed for authentication from public IP network.<br><br= >On Tuesday, January 9, 2018, Suresh Ramasubramanian <<a href=3D"mailto:= [email protected]">[email protected]</a>> wrote:<br>> Very well writt= en.=C2=A0 The issue is also that there=E2=80=99s very little access control= to backdoors providing bulk admin access to the Aadhaar db, everything sho= rt of the core biometrics thank God for small mercies<br>><br>> =C2= =A0<br>><br>> It isn=E2=80=99t just misuse by the custodians.=C2=A0 I= t is the issue of various custodians getting unfettered access and then hav= ing that access compromised by external third parties who then have that sa= me unfettered access to Aadhaar data.<br>><br>> =C2=A0<br>><br>>= ; =C2=A0<br>><br>> From: India-gii <india-gii-bounces+suresh=3D<a = href=3D"mailto:hserus.net-IAPFreCvJWP2/[email protected]">hserus.net-IAPFreCvJWP2/[email protected]= rg</a>> on behalf of Andy Oram <<a href=3D"mailto:[email protected]">= [email protected]</a>><br>> Date: Tuesday, 9 January 2018 at 5:24 PM<= br>> To: <<a href=3D"mailto:[email protected]">india-gii@india-= gii.org</a>><br>> Subject: [india-gii] Legal and technical reasons fo= r biometric breech<br>><br>> =C2=A0<br>><br>> I haven't see= n discussion of that scandal on this list--maybe I missed some email. Anywa= y, I thought this article a useful, concise description of the various face= ts of the problem:<br>><br>> =C2=A0<br>><br>> <a href=3D"https:= //scroll.in/article/833230/explainer-aadhaar-is-vulnerable-to-identity-thef= t-because-of-its-design-and-the-way-it-is-used">https://scroll.in/article/8= 33230/explainer-aadhaar-is-vulnerable-to-identity-theft-because-of-its-desi= gn-and-the-way-it-is-used</a><br>><br>> Andy Oram =C2=A0| =C2=A0Edito= r<br>> O'Reilly Media, Inc. =C2=A0| =C2=A0617-499-7479=C2=A0| =C2=A0= <a href=3D"http://oreilly.com">oreilly.com</a><br>><br>> =C2=A0<br>&g= t;<br>> _______________________________________________ India-gii mailin= g list <a href=3D"mailto:India-gii-IAPFreCvJWP2/[email protected]">[email protected]= ia-gii.org</a> <a href=3D"https://lists.india-gii.org/mailman/listinfo/indi= a-gii">https://lists.india-gii.org/mailman/listinfo/india-gii</a> --f403045e67be61720005627eeb90-- --===============7709886091727219226== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KSW5kaWEtZ2lp IG1haWxpbmcgbGlzdApJbmRpYS1naWlAbGlzdHMuaW5kaWEtZ2lpLm9yZwpodHRwczovL2xpc3Rz LmluZGlhLWdpaS5vcmcvbWFpbG1hbi9saXN0aW5mby9pbmRpYS1naWkK --===============7709886091727219226==--