Friday, January 5, 2018

massive India data breaches;India data architect speaks; genetic engineering in India

7-27-16    “There is a growing awareness around the importance of cybersecurity among Indian government organisations as well as enterprises.  However, India’s high economic growth also makes it a big target for attacks,” Iyer said. 
Iyer said the growth of cybersecurity insurance policies taken by enterprises in India highlights how they are trying everything to safeguard themselves from the impact of cyber attacks. 
  “Indian organisations are also not as well-equipped as maybe US companies, making them the most likely to experience a data breach caused by a system glitch or business process failure,” Iyer said.   http://www.thehindubusinessline.com/info-tech/india-the-most-targeted-country-for-data-breaches/article8907519.ece
.................................................................................................................................
11-20-17   After a Punjab government entity published the Aadhaar information of 20,100 citizens on its official website in August this year, the Unified Identification Authority of India (UIDAI) has reported another breach.  This time around, more than 200 central and state government websites have made private Aadhaar details such as names and addresses public. ...
In April 2017, the Aadhaar details of 1.4 Mn registered users were made public on the Jharkhand Directorate of Social Security.  These details included sensitive information such as names, addresses, bank account details and Aadhaar numbers....
Later in August, Qarth Technologies co-founder Abhinav Srivastava was arrested by Bengaluru’s Central Crime Branch on charges of data theft.  According to the complaint, Srivastava illegally accessed UIDAI data through an “Aadhaar e-KYC verification” mobile app that he developed himself.  Qarth workers were accused of developing an app and accessing details on the official website without authentication.
  During his interrogation, Srivastava gave a six-hour step-by-step demoto sleuths of how he managed to hack into the Aadhaar website.  In his demonstration, Srivastava said that he took advantage of the lack of Hypertext Transfer Protocol Secure (HTTPS) in the URL of the Aadhaar website.  Another report claimed that Abhinav used shortcuts to access data from various websites that used Aadhaar data.     https://inc42.com/buzz/aadhaar-uidai-government/

..........................................................................................................................
Jan 2018     Investigations by the English daily (The Tribune) revealed that the racket is six months old and was started as a WhatsApp group.  The group targeted operators of Common Service Centres Scheme (CSCS), offering them access to UIDAI data.
  CSCS operators were initially assigned the task of making Aadhaar cards, but in November last year the service was restricted to post offices and designated banks.   https://www.thequint.com/news/india/aadhaar-data-breached
............................................................................................................1-5-18
  Retweeting CBS journalist Zack Whittaker's response on a BuzzFeed report on the breach of Aadhaar database in India, Snowden said, "It is the natural tendency of government to desire perfect records of private lives.  History shows that no matter the laws, the result is abuse."   https://economictimes.indiatimes.com/articleshow/62379098.cms?utm_source=contentofinterest&utm_medium=text&utm_campaign=cppst
.....................................................................................................................................................
  (3 strong reasons to greatly oppose the UIDAI system in India:)  
 (1) Bill Gates, on a recent visit to India, hailed it as a “12-digit lie detector,” and the (2) World Bank's chief economist Paul Romer said “it could be good for the world if this became widely adopted.”  ...(3) Nandan Nilekani, the tech titan who designed the program
https://www.washingtonpost.com/news/worldviews/wp/2018/01/04/a-security-breach-in-india-has-left-a-billion-people-at-risk-of-identity-theft/?utm_term=.729a210737d0
.......................................................................................
Nandan Nilekani, billionaire  
 (born 2 June 1955) is an Indian entrepreneur, bureaucrat and politician--interview below:

4-11-17    
Quartz:  How do you feel about the Modi government’s push to make Aadhaar mandatory for a number of things, including now for filing income tax returns?
Nilekani:  The Aadhaar ID always was meant to be a platform and, obviously, reducing wastage and fraud in benefits was a key part of that. But it was also meant for other applications. 

Q:  I don’t have an Aadhaar number, and I’d like to believe that I’m an honest taxpayer.  But essentially now there is no way that I can pay tax without getting an Aadhaar number. 
NN:  Suppose you have to drive on the road, you have to get a driver’s licence.  Do you feel that is an imposition of the state?   Similarly, when you have to travel abroad, you have to get a passport.  Do you see that as an imposition of the state?
But I already have a PAN for my tax. 
NN:  See, if the government decides that there are a lot of duplicate PAN cards and many people are evading tax with that.  And if they use the Aadhaar number to remove duplicate PAN cards, what about that is bothering you?...
it’s not difficult to recreate what an Aadhaar ID looks like. 
NN:  That’s true of all documents.  Every document in India…If you heard Mr (Nitin) Gadkari’s statement that 30% of driver’s licences are fake.  So, when a guy uses a driver’s licence to enter the airport, the same thing applies, no?
So you don’t feel that the use of Aadhaar as a photo ID is a problem?
NN:  We have always said that the proper use of Aadhaar for authentication should be online.  I give it to you, if I just use a physical thing, you don’t know if it’s the real one or not.  That’s why we’ve always said that the right use of Aadhaar authentication is online, where, like when you go and get a Reliance Jio SIM connection, it actually does an online authentication using your biometrics.
NN... In a phone, the cost of putting a fingerprint reader is about $25.  The cost of putting an iris (of the eye) reader is about $6.   https://qz.com/957607/nandan-nilekani-aadhaar-is-being-demonised-because-its-so-transparent/
.................................................................


Kiran Mazumdar-Shaw
Chairperson & Managing Director,
Biocon Limited


No comments:

Post a Comment