기본 콘텐츠로 건너뛰기

The World's Largest Biometric ID System Keeps Getting Hacked

The personal data of many of India's citizens is for sale on WhatsApp for less than $10.

Critics of India’s Aadhaar—the world’s largest biometric identification system—have been vocal about its infrastructural flaws for years. Their fears have turned into reality as the list of security breaches into the system keeps growing. 
Access to the personal data of more than 1 billion people is for sale for less than $10 through WhatsApp. India’s The Tribune newspaper was able to buy the data and also claimed that it could buy software that would allow them to print fake Aadhaar cards for about $5 more. 
Image: Priyanka Parashar/Getty
Aadhaar data includes fingerprints, retina scans, names, addresses, and phone numbers through which SIM cards can be purchased, and important government services and bank accounts can be accessed. According to multiple reports, biometric data was not exposed on WhatsApp, but names, addresses, emails, photographs, and phone numbers were.
The Unique Identification Authority of India (UIDAI), which oversees Aadhaar, says over 1.19 billion people have enrolled in the system since it began in 2009.
Internet connectivity issues have led to people's fingerprints not going through at ration stations in rural India.
Even those who have been outspoken about Aadhaar’s privacy implications were caught off guard by the scale of the recent breach. “I’m not surprised by the breach, but I’m surprised at how widespread the access was,” Kiran Jonnalagadda, cofounder of the Internet Freedom Foundation, told Motherboard.
India’s ruling Bharatiya Janata Party has been quick to call the story ‘fake news.’ And the government agency that oversees Aadhaar has termed it a misuse of the program’s grievance redressal system rather than a breach.
But even before the WhatsApp story broke, Aadhaar’s security track record wasn’t good. In July, 210 government agencies published sensitive Aadhaar account information online. That came after as many as 600,000 children had their data leaked by another government website earlier in the year. And on the same day as the WhatsApp revelation, another local media report exposed a major loophole in Aadhaar’s security through which practically anyone can become an administrator for the entire system.
Telecommunications giants have also been at the center of Aadhaar controversies. Reliance Jio, which was launched by India’s richest man Mukesh Ambani, reportedly leaked the information of 120 million people online last summer. More recently, Airtel was accused of opening up bank accounts for customers without their consent when gathering Aadhaar biometrics to authenticate their mobile phone accounts. Almost $30 million in cooking gas subsidies were diverted into the Airtel accounts as a result. 
From the perspective of the government and other proponents of Aadhaar, though, these incidents are relatively minor hiccups for a program transforming the lives of Indians and improving the country’s efficiency. 
“It’s something which is doing much more good than harm,” Saket Modi, the CEO of Lucideus, a digital security services provider, told Motherboard. “These are small little bumps which have been over magnified.”
Ultimately, Aadhaar’s supporters champion the program as a way for the poor to easily obtain government subsidies, pensions, and food rations by using their fingerprints as ID. In August, the country’s Finance Minister Arun Jaitley described the linking of bank accounts to Aadhaar and mobile phone accounts as “nothing short of a social revolution.”
Modi, of Lucideus, agrees: “Let’s not forget this touches a billion people and there is no parallel program like this anywhere on the planet,” he said.
“It’s a broken, fundamentally wrong system."
But as the government moves to make Aadhaar mandatory for an increasing amount of important services, bureaucratic and technical impediments have actually prevented many from getting the welfare they need. Several people are even believed to have died because they were denied access to food rations, pensions, or even hospital treatment in the name of Aadhaar. 
Internet connectivity issues have led to people's fingerprints not going through at ration stations in rural India. Similar problems have been faced by people who have suffered injuries to their fingers, while others have faced authentication errors because of glitches or mistakes in the system. If people's Aadhaar biometrics are not being recognized, and Aadhaar is then made mandatory for them to get their pensions or even as an ID at a hospital, they're in trouble.
For Aadhaar’s critics, this is especially alarming. They say the program was always supposed to be voluntary, and point to several Supreme Court rulings that support their argument.
“It’s a broken, fundamentally wrong system,” Meghnad S., a public policy analyst who has worked for several members of parliament, told Motherboard.
“We are not saying scrap the whole thing…But fix the bugs first. Give us proof that 99.99 percent of it has been fixed and then, maybe, make it mandatory.” 
The final Supreme Court hearing on the issue is expected later this month. But in the meantime, Aadhaar is essentially becoming de facto compulsory, with more and more people linking it to services like bank and mobile phone accounts out of a fear of getting cut off from those accounts. 
“Basically [the government, phone companies and banks are] completely dependent on the confusion,” Meghnad said, adding that, because people think the program is compulsory, they sign up for it and associate many of their accounts with it: “People panic and they’re like, ‘Oh my god, we have to link it now, it’s mandatory.’”
In response to the ongoing pressure to jump on the Aadhaar train, Meghnad and Jonnalagadda launched speakforme.in, through which citizens can email Members of Parliament, banks and telephone companies about their concerns. Over 33,000 emails have been sent. Jonnalagadda says the campaign has had a direct impact on parliament, and has reinforced his faith in meaningful participation in democracy. 
Still, the UIDAI’s decision over the weekend to file a police report against The Tribuneand the reporter who broke the story, has been seen by many as “an attack on freedom of the press.” Jonnalagadda agrees and says this isn’t the first time the UIDAI has filed a police report against a journalist for exposing weaknesses in Aadhaar’s infrastructure.
“[The police report] is yet another instance of shooting the messenger,” he said. “In each case, someone reporting vulnerabilities in the system has been silenced instead of being acknowledged for their contribution.”

https://motherboard.vice.com/en_us/article/43q4jp/aadhaar-hack-insecure-biometric-id-system

댓글

이 블로그의 인기 게시물

지문 넘어 정맥·홍채로...4000억원 '생체인증' 선점경쟁

4000억원 규모 국내 생체인증 시장을 선점하기 위해 관련 업체 경쟁이 치열하다. 생체인증시스템이 현금자동입출금기( ATM )부터 공항 신분확인, 기업 출입관리까지 다양한 분야로 확대된다. 지문인증을 넘어 손바닥, 손가락 정맥(장정맥, 지정맥)과 안면, 홍채 등 다양한 신체 부위를 활용한 인증 솔루션이 각광 받는다. 25일 업계에 따르면  Sh 수협은행은 장정맥 기반 금융서비스를  ATM 에 먼저 적용한다. 자체 기기에 도입하는 데 그치지 않고, 장정맥 인증 확산을 위해 타행· GS 리테일과 제휴도 추진한다.  GS 25 편의점 내  ATM 에서 장정맥 인증으로 입·출금, 계좌이체 등이 가능해진다. 신협중앙회는 손가락 정맥패턴을 이용한 '지정맥' 인증 시스템을 고객 간편결제 서비스에 도입하는 방안을 검토한다. 지난해 시스템 통제와 임직원 확인용 지정맥 인증을 사내 도입했다. 생체인증은 금융권 중심으로  ATM 과 개인금고, 공항, 기업 출입 등 다양한 곳에 활용된다. 한국후지쯔는 신한은행 시작으로 국민은행, 우리은행,  NH 증권, 롯데카드, 케이뱅크 등에 장정맥 인증 서비스 '팜시큐어'를 공급했다. 제주·김포공항에 장정맥을 이용한 실명확인 시스템을 구축했다. 동서석유화학,  SK 텔링크 등 일반 기업도 도입했다. LG 히다찌는 지정맥 인증 서비스를 신협중앙회 사내통제시스템뿐 아니라  BNK 부산은행 스마트  ATM 에도 공급했다. 부산은행은  ATM 뿐 아니라 은행창구 등에도 지정맥을 활용한다.  LG 히다찌는 신한카드, 나이스정보통신 등과 업무협약을 맺고 오프라인 간편결제로 지정맥 활용 준비 작업에 나섰다. 계명대 동산의료원과도 업무협약을 맺고 병원 인증시스템 도입도 검토한다. 국내 스타트업 위닝아이는 카메라를 이용한 손바닥 인증 기술을 전북은행 '뉴스마트뱅킹', 한화손해보험 '스마트인슈', 신영증권 등에 공급했다. 현대모비스와 손잡고 차량용 인증 기술 개...

Cold Wallet Vs. Hot Wallet: What’s The Difference?

You may have heard about cold and hot digital wallets but do you know how they are different from each other? The simplest way to describe the difference between a cold wallet and a hot one is this: hot wallets are connected to the internet while cold wallets are not. Most people who hold digital assets have both cold and hot wallets because they are designed for different purposes. Hot wallets are like checking accounts while cold wallets are similar to savings accounts. People who have digital assets keep a small amount of money in their hot wallets for purchasing stuff. They keep the vast majority of their digital coins in their cold wallet. If you like Medium articles in video form, you’re in luck: SECURITY Q: Why do people keep most of their digital coins in a cold wallet? A: Hackers cannot steal digital assets that are not connected to the internet. Q: So then, how safe are hot wallets? A: The security of hot wallets is dependent upon the security ha...

Avoiding Cryptocurrency Scams

The Money Makers Club now has 6 of 15 available seats. Learn more here! Everyone is always focused on the potential upside of buying cryptocurrency, but they forget there are always going to be hidden downsides as well. The downside risk of investing in cryptocurrencies is huge. Not only do you need to worry about the high volatility of these assets, but you also need to bear in mind that theft is always a possibility, and the assets are poorly regulated.  Lack of Regulation Creates Opportunity for Thieves In the equity and debt markets, there are stringent controls on the way capital is invested and the rules that govern investors. The goal is to protect investors from any fraud or wrongdoing, and even though there are times where it takes regulators longer than normal to catch on (see: Bernie Madoff), the general effect is a safer investment marketplace.  Fraud can occur in a variety of ways. It can be the result of false claims by the company regarding the s...