Re: Legal and technical reasons for biometric breech
Suresh Ramasubramanian <[email protected]> Thu, 11 Jan 2018 12:27:59 +0000 (UTC)
| Newsgroups | gmane.org.telecom.india-gii |
|---|---|
| Message-ID | <11B9F4373F23BFE3.1E5C304A-E20C-429F-8A97-6E362AEAA0AD@mail.outlook.com> |
--===============1359350648381152570== Content-Type: multipart/alternative; boundary="----=_Part_3642_1110766141.1515673679119" ------=_Part_3642_1110766141.1515673679119 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable =09 =09=09 =09=09 =09 =09=09 =09=09Of course. And when a machine lets say a state govt department webser= ver has two IPs one a private or vpn connection to Aadhaar and another a pu= blic IP ... fun isn=E2=80=99t it. =09=09 =09=09=E2=80=94srs =09 On Thu, Jan 11, 2018 at 5:32 PM +0530, "rishi tarar" <[email protected]> = wrote: There is no admin access granted to partners to access aadhar db. Organisat= ion who have biometric access (other than bank) can only validate the ident= ity and number by geting binary (yes/no) response from aadhar api/dB. Bank can access the demographic details of people from aadhar api.All this = aadhar network which is extended to multiple partners in form of bank ,Telc= o and others are part of private IP network (dedicated link).There is no di= rect/single session allowed for authentication from public IP network. On Tuesday, January 9, 2018, Suresh Ramasubramanian <[email protected]> wro= te: > Very well written.=C2=A0 The issue is also that there=E2=80=99s very litt= le access control to backdoors providing bulk admin access to the Aadhaar d= b, everything short of the core biometrics thank God for small mercies > > =C2=A0 > > It isn=E2=80=99t just misuse by the custodians.=C2=A0 It is the issue of = various custodians getting unfettered access and then having that access co= mpromised by external third parties who then have that same unfettered acce= ss to Aadhaar data. > > =C2=A0 > > =C2=A0 > > From: India-gii <india-gii-bounces+suresh=3Dhserus.net-IAPFreCvJWP2/[email protected]= g> on behalf of Andy Oram <[email protected]> > Date: Tuesday, 9 January 2018 at 5:24 PM > To: <[email protected]> > Subject: [india-gii] Legal and technical reasons for biometric breech > > =C2=A0 > > I haven't seen discussion of that scandal on this list--maybe I missed so= me email. Anyway, I thought this article a useful, concise description of t= he various facets of the problem: > > =C2=A0 > > https://scroll.in/article/833230/explainer-aadhaar-is-vulnerable-to-ident= ity-theft-because-of-its-design-and-the-way-it-is-used > > Andy Oram =C2=A0| =C2=A0Editor > O'Reilly Media, Inc. =C2=A0| =C2=A0617-499-7479=C2=A0| =C2=A0oreilly.com > > =C2=A0 > > _______________________________________________ India-gii mailing list In= dia-gii-IAPFreCvJWP2/[email protected] https://lists.india-gii.org/mailman/listinfo/in= dia-gii ------=_Part_3642_1110766141.1515673679119 Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: quoted-printable <html><head></head><body><!-- This file has been automatically generated. S= ee web/README.md --> <div id=3D"compose-container" style=3D"direction: ltr" itemscope itemtype= =3D"https://schema.org/EmailMessage"> =09<span itemprop=3D"creator" itemscope itemtype=3D"https://schema.org/Orga= nization"> =09=09<span itemprop=3D"name" content=3D"Outlook Mobile for iOS"></span> =09</span>=09 =09<div> =09=09 =09=09<div style=3D"direction: ltr;">Of course. And when a machine lets say= a state govt department webserver has two IPs one a private or vpn connect= ion to Aadhaar and another a public IP ... fun isn=E2=80=99t it.</div> =09=09<div><br></div> =09=09<div class=3D"acompli_signature"><div style=3D"direction: ltr;">=E2= =80=94srs</div></div> =09</div> </div> <br><br><br> <div class=3D"gmail_quote">On Thu, Jan 11, 2018 at 5:32 PM +0530, "rishi ta= rar" <span dir=3D"ltr"><<a href=3D"mailto:[email protected]" target=3D= "_blank">[email protected]</a>></span> wrote:<br> <br> <blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p= x #ccc solid;padding-left:1ex"> <div dir=3D"3D"ltr""> There is no admin access granted to partners to access aadhar db. Organisat= ion who have biometric access (other than bank) can only validate the ident= ity and number by geting binary (yes/no) response from aadhar api/dB.<br>Ba= nk can access the demographic details of people from aadhar api.All this aa= dhar network which is extended to multiple partners in form of bank ,Telco = and others are part of private IP network (dedicated link).There is no dire= ct/single session allowed for authentication from public IP network.<br><br= >On Tuesday, January 9, 2018, Suresh Ramasubramanian <<a href=3D"mailto:= [email protected]">[email protected]</a>> wrote:<br>> Very well writt= en. The issue is also that there=E2=80=99s very little access control= to backdoors providing bulk admin access to the Aadhaar db, everything sho= rt of the core biometrics thank God for small mercies<br>><br>>  = ;<br>><br>> It isn=E2=80=99t just misuse by the custodians. It = is the issue of various custodians getting unfettered access and then havin= g that access compromised by external third parties who then have that same= unfettered access to Aadhaar data.<br>><br>> <br>><br>> = <br>><br>> From: India-gii <india-gii-bounces+suresh=3D<a hr= ef=3D"mailto:hserus.net-IAPFreCvJWP2/[email protected]">hserus.net-IAPFreCvJWP2/[email protected]= </a>> on behalf of Andy Oram <<a href=3D"mailto:[email protected]">an= [email protected]</a>><br>> Date: Tuesday, 9 January 2018 at 5:24 PM<br= >> To: <<a href=3D"mailto:[email protected]">india-gii@india-gi= i.org</a>><br>> Subject: [india-gii] Legal and technical reasons for = biometric breech<br>><br>> <br>><br>> I haven't seen disc= ussion of that scandal on this list--maybe I missed some email. Anyway, I t= hought this article a useful, concise description of the various facets of = the problem:<br>><br>> <br>><br>> <a href=3D"https://scro= ll.in/article/833230/explainer-aadhaar-is-vulnerable-to-identity-theft-beca= use-of-its-design-and-the-way-it-is-used">https://scroll.in/article/833230/= explainer-aadhaar-is-vulnerable-to-identity-theft-because-of-its-design-and= -the-way-it-is-used</a><br>><br>> Andy Oram | Editor<br>&= gt; O'Reilly Media, Inc. | 617-499-7479 | <a href=3D= "http://oreilly.com">oreilly.com</a><br>><br>> <br>><br>>= _______________________________________________ India-gii mailing list <a = href=3D"mailto:India-gii-IAPFreCvJWP2/[email protected]">India-gii-IAPFreCvJWP2/[email protected]= </a> <a href=3D"https://lists.india-gii.org/mailman/listinfo/india-gii">htt= ps://lists.india-gii.org/mailman/listinfo/india-gii</a> </div> </blockquote> </div> </body></html> ------=_Part_3642_1110766141.1515673679119-- --===============1359350648381152570== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KSW5kaWEtZ2lp IG1haWxpbmcgbGlzdApJbmRpYS1naWlAbGlzdHMuaW5kaWEtZ2lpLm9yZwpodHRwczovL2xpc3Rz LmluZGlhLWdpaS5vcmcvbWFpbG1hbi9saXN0aW5mby9pbmRpYS1naWkK --===============1359350648381152570==--