FB pixel

Police suspect user agency insiders responsible for Aadhaar data leak

 

Indian police and Aadhaar officials suspect that insiders at an authentication user agency (AUA) and a KYC user agency (KUA) are responsible for last week’s Aadhaar data leak, according to sources cited in a report by Deccan Herald.

On July 29, the case was transferred from High Grounds police station to the cyber crime police station.

The leak was discovered when an app offered e-KYC (know your customer) certificates, allegedly by accessing an Aadhaar database without authorization.

The Unique Identification Authority of India (UIDAI) filed a complaint against two of its own authentication service agencies (ASUs), as well as the developer of the app, Qarth Technologies.

Although the complaint alleges that an authentication user agency (AUA) and a KYC user agency (KUA) were behind the data leak, it does not refer to the agencies by name.

The UIDAI said it had issued detailed instructions addressed to all such agencies to ensure the security of the authentication process.

The agencies were tasked with maintaining the confidentiality of Aadhaar information, according to an official source.

The UIDAI framework mandates that an AUA/KUA may be a government, public, private legal agency registered in India.

According to the Aadhaar Act of 2016, a registered authentication agency cannot allow another entity to perform authentication.

Agencies are not allowed to share a licence key, nor are they allowed to forward authentication requests as it would require the use of personal identity data captured by an unaudited application.

“Even for a sub-AUA, separate licence key is used,” a source said.

The complaint registered at the High Grounds police station names mobile app developer Abhinav Srivastava as the prime entity accused, followed by an AUA and a KUA.

Since no sharing of information is allowed without the use of the licence key, the investigation would involve determining which insider leaked the information.

“It looks like some agencies have shared information illegally in connivance with Abhinav Srivastava,’’ a police source said.

There are approximately 400 AUAs and KUAs in operation across India. An AUA provides Aadhaar-enabled services to Aadhaar holders, using authentication as facilitated by an Authentication Service Agency (ASA).

Last week, India’s Supreme Court heard from several petitions challenging the legality of the Aadhaar project in order to determine whether citizens are entitled to privacy as a fundamental right.

Article Topics

 |   |   |   | 

Latest Biometrics News

 

Face biometrics use cases outnumbered only by important considerations

With face biometrics now used regularly in many different sectors and areas of life, stakeholders are asking questions about a…

 

Biometric Update Podcast explores identification at scale using browser fingerprinting

“Browser fingerprinting is this idea that modern browsers are so complex.” So says Valentin Vasilyev, Chief Technology Officer of Fingerprint,…

 

Passkeys now pervasive but passwords persist in enterprise authentication

Passkeys are here; now about those passwords. Specifically, passkeys are now prevalent in the enterprise, the FIDO Alliance says, with…

 

Pornhub returns to UK, but only for iOS users who verify age with Apple

In the UK, “wanker” is not typically a term of endearment. However, the case may be different for Pornhub, which…

 

Europol operated ‘shadow’ IT systems without data safeguards: Report

Europol has operated secret data analysis platforms containing large amounts of personal information, such as identity documents, without the security…

 

EU pushes AI Act deadlines for high-risk systems, including biometrics

The EU has reached a provisional agreement on changes to the AI Act that postpone rules on high-risk AI systems,…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events