Get all your news in one place.
100’s of premium titles.
One app.
Start reading
Reuters
Reuters
Politics
Malini Menon

Indian agency denies security lapse in ID card project; ZDNet defends report

A woman goes through the process of finger scanning for the Unique Identification (UID) database system, also known as Aadhaar, at a registration centre in New Delhi, India, January 17, 2018. Picture taken January 17, 2018. REUTERS/Saumya Khandelwal

NEW DELHI (Reuters) - Tech news site ZDNet said on Sunday it stood by its report that identified a security vulnerability in data-linked to Aadhaar - India's national identity card project, after a semi-government agency that manages the database sought to discredit the report.

ZDNet reported http://www.zdnet.com/article/another-data-leak-hits-india-aadhaar-biometric-database that a data leak on a system run by a state-owned utility company could allow access to private information of holders of the biometric "Aadhaar" ID cards, exposing their names, their unique 12-digit identity numbers, and their bank details.

The Unique Identification Authority of India (UIDAI), which manages the Aadhaar program, said "there is no truth in this story," in a statement late on Saturday.

ZDNet's global editor-in-chief Larry Dignan said in an email to Reuters on Sunday the publication stood by its report. Dignan said they spent weeks compiling evidence and verifying facts.

"We spent weeks reaching out to the Indian authorities, specifically UIDAI, to responsibly disclose the security issue, and we heard nothing back — and no action was taken until after we published our story," said Dignan.

UIDAI sought to downplay the report stating that even if the claims in the story were true, it would raise security concerns with the database of the utility company and not with the security of UIDAI's Aadhaar database. UIDAI said it is "contemplating legal action against ZDNet".

Multiple researchers and journalists, who have identified loopholes in India's massive national identity card project, say they have been harassed https://www.reuters.com/article/india-aadhaar-breach/update-1-critics-of-indias-id-card-project-say-they-have-been-harassed-put-under-surveillance-idUSL4N1Q44JS by some government agencies and slapped with criminal cases because of their work.

Aadhaar is a biometric identification card that is becoming integral to the digitisation of India's economy, with over 1.1 billion users it is the world's largest such database.

Indians have been asked to furnish their Aadhaar numbers for a host of transactions including accessing bank accounts, paying taxes, receiving subsidies, acquiring a mobile number, settling a property deal and registering a marriage.

The government's demands for Aadhaar linkage for multiple services is currently being challenged https://www.reuters.com/article/us-india-aadhaar/indian-court-extends-march-31-deadline-for-linking-of-biometric-ids-idUSKCN1GP1GX in India's Supreme Court.

At the same time, security researchers and journalists have highlighted multiple vulnerabilities and data leaks tied to the program. UIDAI has sought to downplay the reports and last week it said the biometric data was safe from hacking as the storage facility was not connected to the internet.

(Reporting by Malini Menon; Writing by Malini Menon and Krishna N. Das; Editing by Andrew Bolton, Euan Rocha and David Evans)

Sign up to read this article
Read news from 100’s of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.