Re: Legal and technical reasons for biometric breech

Suresh Ramasubramanian <[email protected]> Thu, 11 Jan 2018 12:27:59 +0000 (UTC)
Newsgroups gmane.org.telecom.india-gii
Message-ID <11B9F4373F23BFE3.1E5C304A-E20C-429F-8A97-6E362AEAA0AD@mail.outlook.com>
--===============1359350648381152570==
Content-Type: multipart/alternative; 
	boundary="----=_Part_3642_1110766141.1515673679119"

------=_Part_3642_1110766141.1515673679119
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable




=09
=09=09
=09=09
=09
=09=09
=09=09Of course. And when a machine lets say a state govt department webser=
ver has two IPs one a private or vpn connection to Aadhaar and another a pu=
blic IP ... fun isn=E2=80=99t it.
=09=09

=09=09=E2=80=94srs
=09





On Thu, Jan 11, 2018 at 5:32 PM +0530, "rishi tarar" <[email protected]> =
wrote:










There is no admin access granted to partners to access aadhar db. Organisat=
ion who have biometric access (other than bank) can only validate the ident=
ity and number by geting binary (yes/no) response from aadhar api/dB.
Bank can access the demographic details of people from aadhar api.All this =
aadhar network which is extended to multiple partners in form of bank ,Telc=
o and others are part of private IP network (dedicated link).There is no di=
rect/single session allowed for authentication from public IP network.

On Tuesday, January 9, 2018, Suresh Ramasubramanian <[email protected]> wro=
te:
> Very well written.=C2=A0 The issue is also that there=E2=80=99s very litt=
le access control to backdoors providing bulk admin access to the Aadhaar d=
b, everything short of the core biometrics thank God for small mercies
>
> =C2=A0
>
> It isn=E2=80=99t just misuse by the custodians.=C2=A0 It is the issue of =
various custodians getting unfettered access and then having that access co=
mpromised by external third parties who then have that same unfettered acce=
ss to Aadhaar data.
>
> =C2=A0
>
> =C2=A0
>
> From: India-gii <india-gii-bounces+suresh=3Dhserus.net-IAPFreCvJWP2/[email protected]=
g> on behalf of Andy Oram <[email protected]>
> Date: Tuesday, 9 January 2018 at 5:24 PM
> To: <[email protected]>
> Subject: [india-gii] Legal and technical reasons for biometric breech
>
> =C2=A0
>
> I haven't seen discussion of that scandal on this list--maybe I missed so=
me email. Anyway, I thought this article a useful, concise description of t=
he various facets of the problem:
>
> =C2=A0
>
> https://scroll.in/article/833230/explainer-aadhaar-is-vulnerable-to-ident=
ity-theft-because-of-its-design-and-the-way-it-is-used
>
> Andy Oram =C2=A0| =C2=A0Editor
> O'Reilly Media, Inc. =C2=A0| =C2=A0617-499-7479=C2=A0| =C2=A0oreilly.com
>
> =C2=A0
>
> _______________________________________________ India-gii mailing list In=
dia-gii-IAPFreCvJWP2/[email protected] https://lists.india-gii.org/mailman/listinfo/in=
dia-gii






------=_Part_3642_1110766141.1515673679119
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: quoted-printable

<html><head></head><body><!-- This file has been automatically generated. S=
ee web/README.md -->

<div id=3D"compose-container" style=3D"direction: ltr" itemscope itemtype=
=3D"https://schema.org/EmailMessage">
=09<span itemprop=3D"creator" itemscope itemtype=3D"https://schema.org/Orga=
nization">
=09=09<span itemprop=3D"name" content=3D"Outlook Mobile for iOS"></span>
=09</span>=09
=09<div>
=09=09
=09=09<div style=3D"direction: ltr;">Of course. And when a machine lets say=
 a state govt department webserver has two IPs one a private or vpn connect=
ion to Aadhaar and another a public IP ... fun isn=E2=80=99t it.</div>
=09=09<div><br></div>
=09=09<div class=3D"acompli_signature"><div style=3D"direction: ltr;">=E2=
=80=94srs</div></div>
=09</div>
</div>
<br><br><br>
<div class=3D"gmail_quote">On Thu, Jan 11, 2018 at 5:32 PM +0530, "rishi ta=
rar" <span dir=3D"ltr">&lt;<a href=3D"mailto:[email protected]" target=3D=
"_blank">[email protected]</a>&gt;</span> wrote:<br>
<br>

<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">




<div dir=3D"3D&quot;ltr&quot;">
There is no admin access granted to partners to access aadhar db. Organisat=
ion who have biometric access (other than bank) can only validate the ident=
ity and number by geting binary (yes/no) response from aadhar api/dB.<br>Ba=
nk can access the demographic details of people from aadhar api.All this aa=
dhar network which is extended to multiple partners in form of bank ,Telco =
and others are part of private IP network (dedicated link).There is no dire=
ct/single session allowed for authentication from public IP network.<br><br=
>On Tuesday, January 9, 2018, Suresh Ramasubramanian &lt;<a href=3D"mailto:=
[email protected]">[email protected]</a>&gt; wrote:<br>&gt; Very well writt=
en.&nbsp; The issue is also that there=E2=80=99s very little access control=
 to backdoors providing bulk admin access to the Aadhaar db, everything sho=
rt of the core biometrics thank God for small mercies<br>&gt;<br>&gt; &nbsp=
;<br>&gt;<br>&gt; It isn=E2=80=99t just misuse by the custodians.&nbsp; It =
is the issue of various custodians getting unfettered access and then havin=
g that access compromised by external third parties who then have that same=
 unfettered access to Aadhaar data.<br>&gt;<br>&gt; &nbsp;<br>&gt;<br>&gt; =
&nbsp;<br>&gt;<br>&gt; From: India-gii &lt;india-gii-bounces+suresh=3D<a hr=
ef=3D"mailto:hserus.net-IAPFreCvJWP2/[email protected]">hserus.net-IAPFreCvJWP2/[email protected]=
</a>&gt; on behalf of Andy Oram &lt;<a href=3D"mailto:[email protected]">an=
[email protected]</a>&gt;<br>&gt; Date: Tuesday, 9 January 2018 at 5:24 PM<br=
>&gt; To: &lt;<a href=3D"mailto:[email protected]">india-gii@india-gi=
i.org</a>&gt;<br>&gt; Subject: [india-gii] Legal and technical reasons for =
biometric breech<br>&gt;<br>&gt; &nbsp;<br>&gt;<br>&gt; I haven't seen disc=
ussion of that scandal on this list--maybe I missed some email. Anyway, I t=
hought this article a useful, concise description of the various facets of =
the problem:<br>&gt;<br>&gt; &nbsp;<br>&gt;<br>&gt; <a href=3D"https://scro=
ll.in/article/833230/explainer-aadhaar-is-vulnerable-to-identity-theft-beca=
use-of-its-design-and-the-way-it-is-used">https://scroll.in/article/833230/=
explainer-aadhaar-is-vulnerable-to-identity-theft-because-of-its-design-and=
-the-way-it-is-used</a><br>&gt;<br>&gt; Andy Oram &nbsp;| &nbsp;Editor<br>&=
gt; O'Reilly Media, Inc. &nbsp;| &nbsp;617-499-7479&nbsp;| &nbsp;<a href=3D=
"http://oreilly.com">oreilly.com</a><br>&gt;<br>&gt; &nbsp;<br>&gt;<br>&gt;=
 _______________________________________________ India-gii mailing list <a =
href=3D"mailto:India-gii-IAPFreCvJWP2/[email protected]">India-gii-IAPFreCvJWP2/[email protected]=
</a> <a href=3D"https://lists.india-gii.org/mailman/listinfo/india-gii">htt=
ps://lists.india-gii.org/mailman/listinfo/india-gii</a>

</div>

</blockquote>
</div>
</body></html>
------=_Part_3642_1110766141.1515673679119--


--===============1359350648381152570==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KSW5kaWEtZ2lp
IG1haWxpbmcgbGlzdApJbmRpYS1naWlAbGlzdHMuaW5kaWEtZ2lpLm9yZwpodHRwczovL2xpc3Rz
LmluZGlhLWdpaS5vcmcvbWFpbG1hbi9saXN0aW5mby9pbmRpYS1naWkK

--===============1359350648381152570==--