FB pixel

State government fixes bug exposing Aadhaar biometric records

Philippines responds to breach allegations
State government fixes bug exposing Aadhaar biometric records
 

Fingerprint biometrics submitted to India’s national ID system, Aadhaar, have been exposed by the West Bengal state government website, TechCrunch reports.

Security researcher Sourajeet Majumder found and reported a bug that exposed Aadhaar digital ID numbers, identity documents, photographs and images of fingerprints on the e-District web portal. Soon after he reported the bug to government cybersecurity body CERT-In and the West Bengal government, it was fixed, according to the report.

The bug allowed a prospective attacker to guess sequences of 16-digital deed application numbers, and publicly available tools enabled valid numbers to be identified based on responses from the server.

The fear is that a malicious attacker may have discovered the path to people’s biometrics before Majumder reported it and could use the data to mount spoof attacks. The Unique Identification Authority of India (UIDAI) recently implemented liveness detection for fingerprint biometrics to stem incidents of fraud carried out with presentation attacks against the Aadhaar-enabled Payment System.

The UIDAI has launched a bug bounty program to find and close security vulnerabilities in Aadhaar’s biometric database last year.

India has been plagued by data breaches from state government and private sector portals over the past decade, though the UIDAI has denied allegations that biometric data has been leaked from the centralized database.

Philippines denies details of data breach accusations

The Philippine Statistics Authority (PSA) has responded to allegations on social media of a data breach by assuring the public that biometric and digital ID data held by the Philippine Identification System (PhilSys) and the Civil Registration System (CRS) has not been stolen.

The allegations themselves are malware attempts, the agency says. However, an investigation by the PSA’s Data Breach Response Team found that personal data from the Community-Based Monitoring System, a local planning tool, may have been compromised.

Article Topics

 |   |   |   |   | 

Latest Biometrics News

 

Ambitious biometrics projects promise transformation, but struggle with messaging

Advances in biometrics and technologies behind digital identity are making previously unattainable goals possible. The top articles of the week…

 

ADVP, Tony Blair Institute debate UK digital ID plans: Biometric Update podcast

Two distinct sides have emerged in the debate over how to implement digital identity in the UK. One says a…

 

Neurotechnology wins UIDAI biometrics challenge for child fingerprint authentication

The latest biometrics challenge held by the Unique Identification Authority of India shows the improving viability of fingerprint matching for…

 

Hungarian IDV company acquisition attracts suspicion over alleged government ties

FaceKom, the identity verification company used by the Hungarian national digital identity program, has been acquired by major local IT…

 

Coalition of states hammers NetChoice in defense of Arkansas’ Social Media Safety Act

A new challenge in the U.S. court system cuts to the bone on the question of age assurance laws for…

 

UK gov’t plans tour to fix argument to public on national digital identity

UK government officials have admitted that the initial attempt to communicate a new policy for introducing national digital identity was…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis

DIGITAL ID for ALL NEWS

Featured Company

ID for ALL FEATURE REPORTS

BIOMETRICS WHITE PAPERS

BIOMETRICS EVENTS

EXPLAINING BIOMETRICS