FB pixel

Lax security, procurement alleged behind Indian police facial recognition app breach

Lax security, procurement alleged behind Indian police facial recognition app breach
 

A biometric data breach from a police system in Telangana, India that may have exposed the facial images of an unknown number of criminal suspects and police officers has been reported.

Police information-sharing app TSCOP, which includes a facial recognition capability, and HawkEye, an app for the public to report crimes to the police with, have both been breached, according to the reports. The apps were poorly protected, including with passwords visible in plain-text within TSCOP. The Telangana police SMS service portal was also recently breached.

Worse, The News Minute reports that Telangana police have been using the national network of police databases, the Crime and Criminal Tracking Network and Systems (CCTNS), to gather data from departments all over the country. It did not implement access control measures to protect this information, the publication claims.

News Minute suggests that the police contracted the app without the appropriate checks and balances.

A Telangana police representative denied “certain related media reports that appeared in newspapers” about breached hotel visitor data from TSCOP, the Deccan Chronicle reports.

Hyderabad, Telangana paper The Siasat Daily reviewed the data for sale on a popular forum for selling breached data, where Telangana’s police data was offered for $150. It found details of criminal records and police officials, including images, along with names and contact details for 200,000 HawkEye users. Aadhaar data that the Telangana police should not have had possession of was also included, according to the report.

Police have arrested a 20-year-old student they say is responsible, the Chronicle reports.

The procurement of an upgraded multi-biometric recognition system by Telangana police was carried out in an unusually short process in March, and the push by Indian police to adopt facial recognition in other states has come with data breaches and attendant criticism.

Related Posts

Article Topics

 |   |   |   |   |   | 

Latest Biometrics News

 

Facewatch, Forecourt Eye partner to tackle petrol theft at UK pumps with FRT, ANPR

“The price of gas keeps on rising,” says a song from UK indie band Bloc Party’s classic 2005 album, Silent…

 

UN moves to renew Palantir deal despite unresolved privacy, governance risks

The United Nations (U.N.) World Food Programme (WFP) is preparing to renew a five-year agreement with Palantir Technologies even though…

 

New Mexico ruling puts Meta on collision course with age assurance

Meta is feeling the regulatory pinch in New Mexico, where a judge has ordered the social media company to pay…

 

India warns Meta to curb AI-generated content or face enforcement

Meta has fallen afoul of India, after the platform temporarily removed a video posted by Indian Prime Minister Narendra Modi….

 

Cameroon: When birth certificates represent children who do not exist

In the world of legal identity, it is said that a child without a birth certificate does not exist, but…

 

SQR folds under funding pressure amid UK’s uncertain digital ID landscape

Isle of Man-based digital identity service provider SQR is winding down operations. The decision following a failure to secure funding…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Market Intelligence

Featured Company

Biometric Update Podcast

Most Read This Week

White Papers

Latest Webinars

Biometrics Industry Events