Identity Project

Security of Aadhaar's data is under question, but pointing to the gaps could lead to a police case

The official UIDAI has filed a criminal complaint against a writer-entrepreneur for an article demonstrating how stored biometric data could be misused.

In the past week, reports of two criminal complaints related to the security of the Aadhaar database – a centralised database of biometric scans of over 100 crore Indians – has raised concerns about a bigger data breach.

On February 24, the Times of India reported that the Unique Identification Authority of India – which issues the 12-digit Aadhaar numbers that ensure targeted delivery of subsidies, benefits and services – had on February 15 lodged a complaint with the Delhi Police Cyber Cell against Axis Bank Limited, its business correspondent Suvidha Infoserve, and esign provider eMudhra for illegally storing biometric data and performing unauthorised Aadhaar authentication.

The Authority alleged that the firms performed multiple transactions using replay of stored biometrics – for instance, one individual supposedly performed 397 biometric transactions between July 14, 2016 and February 19 this year. It described this as a violation of the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits, and Services) Act, 2016, as the law does not allow the storage of biometric data.

Announcing additional safety measures, Authority officials stated that they have submitted a proposal to the IT Ministry on February 22 that from now on till May, all biometric devices would be registered with it, and an Aadhaar encryption key would be introduced in their hardware to ensure the data received was “captured live”.

Gaps in the system

While the investigation into the complaint is still on, the Asian Age reported on February 28 that the Authority had registered a separate police complaint against an individual, Sameer Kochhar, who heads the Gurgaon think tank Skoch Development Foundation. The complaint was in connection with an article, “Is a Deep State at Work to Steal Digital India”, Kochhar had published on February 11 in his magazine, Inclusion, about security vulnerabilities in Aadhaar systems. The article included a video demonstrating how unauthorised transactions were possible using replay of stored biometrics – the same malpractice for which the Authority had taken action against Axis Bank, Suvidha and eMudhra.

Two days after the article was published, the Authority’s chief executive officer, ABP Pandey, responded to it on Twitter by calling it a fake video and asking Kochhar to stop spreading rumours. Two weeks later, the agency registered the police case against Kochchar.

Confirming this, Deputy Commissioner of Police (Crime-South) Bhisham Singh said, “We have received a complaint from UIDAI that an individual Sameer Kochhar had floated a video and an article on Google, saying Aadhaar was not foolproof, the UIDAI says this is against Aadhaar Act, and we have registered a First Information Report.” Singh added that the FIR was not yet public and the police had not contacted Kochhar. “UIDAI says his claims are false, and we will investigate if this is so,” he said.

Another senior police official, who did not wish to be identified, said the case against Kochhar was registered under Sections 37 of the Aadhaar Act and several other provisions of the Act as well as the Indian Penal Code.

Section 37 says:

Whoever, intentionally discloses, transmits, copies or otherwise disseminates any identity information collected in the course of enrolment or authentication to any person not authorised under this Act or regulations made thereunder or in contravention of any agreement or arrangement entered into pursuant to the provisions of this Act, shall be punishable with imprisonment for a term which may extend to three years or with a fine which may extend to ten thousand rupees or, in the case of a company, with a fine which may extend to one lakh rupees, or with both.

On February 22 – before the police complaint against Axis Bank and the two other firms were reported – Kochhar leaked a letter purportedly sent by the Authority to one registered authentication user agency (whose name was masked) asking how it had performed multiple concurrent Aadhaar authentications on January 11 through the unauthorised use of stored biometrics of one individual.

The letter also stated that the Authority had detected a firm that was illegally using a “licence key”. Section 15 (2) of the Authentication Regulations of the Aadhaar Act — the Aadhaar Regulations are currently in Parliament — say a requesting entity can permit another agency or entity to perform a yes/no authentication by generating a “separate licence key”. In this instance, the second entity performs electronic know-your-customer requirements for financial transactions, even though it had no permission to do so.

The letter leaked on Twitter by Sameer Kochhar on February 22.
The letter leaked on Twitter by Sameer Kochhar on February 22.

In an emailed response to Scroll.in, Kochhar said he had found out about the FIR against him from the Asian Age report, and that he had not yet been contacted by the Unique Identification Authority of India or the Delhi Police. “The story is available on www.inclusion.in and whatever other information and documents I have shared are on my Twitter timeline,” he stated. “I look forward to find out which parts of Aadhaar Act 2016 prohibit media reporting on its vulnerabilities.”

He also pointed out the Authority had not denied having issued the letter leaked by him.

Unique Identification Authority of India officials refused to share a copy of the police complaint or the basis of their action against Kochhar. “It may have been part of the original complaint against Axis Bank, and other, but we cannot share any details on this,” said Vikash Shuka, senior manager, communications and public outreach, at the Authority’s headquarters in Delhi. Shukla added that the Authority did not have a spokesperson who could publicly comment on the details of the complaint against Kochhar.

Shooting the messenger?

Prasanna S – a lawyer for petitioners who have challenged Aadhaar in the Supreme Court – said it was not clear that what Kochhar demonstrated was related to information gathered in authentication or enrollment, as Section 37 of the Aadhaar Act, which has been mentioned in the FIR against him, suggests. He accused the Unique Identification Authority of India of using Section 37 to stifle criticism and curtail speech. “If you criticise Aadhaar project, the government says ‘you are just saying so, you do not understand the project’,” the lawyer said. “Here, someone has demonstrated evidence of a security flaw and they are saying ‘how dare you expose its vulnerability’.”

“Do we now have to be worried about sedition against UIDAI?” he added, expressing concern at the Authority registering an FIR against a citizen for exposing a security vulnerability in Aadhaar.

Chinmayi Arun, executive director of the Centre for Communications Governance at the National Law University, Delhi said that “threatening concerned citizens who identify holes and errors that the authority should be fixing is foolish”. She added, “The UIDAI should be rewarding those who find its breaches – instead, we have attempts to intimidate them into silence through the abuse of the state’s police powers. The Aadhaar Act enables this intimidation and it is high time the Supreme Court put a stop to it.”

Kiran Jonnalgadda, co-founder of HasGeek, a community for start-ups for software development in Bengaluru, said Kochhar’s complaint and the Authority’s action against the three firms showed it had failed to provide sufficient technical protection against such attacks. “Replay attacks are a well-known problem, and the Application Programming Interface should not be storing the fingerprint on the device itself,” he said.

“The irregularities detected show they did not have sufficient technical protection, only legal protection against this,” he added. “The UIDAI provides for SMS, email alerts on authentication, but even this is optional.”

Jonnalgadda pointed out that new technical protection — of introducing registration of biometrics devices — was, in fact, added after Kochhar’s article. “The new technical protection kicked in after Kochar, a high profile individual, made an accusation, the video went public and UIDAI CEO replied on Twitter publicly saying, ‘Aadhaar is secure, do not spread rumours’, and then, after all this, they bothered to investigate,” he said.

He, too, said that someone raising a security issue in the system should be rewarded and not punished.

We welcome your comments at letters@scroll.in.
Sponsored Content BY 

How sustainable farming practices can secure India's food for the future

India is home to 15% of the world’s undernourished population.

Food security is a pressing problem in India and in the world. According to the Food and Agriculture Organization of the UN (FAO), it is estimated that over 190 million people go hungry every day in the country.

Evidence for India’s food challenge can be found in the fact that the yield per hectare of rice, one of India’s principal crops, is 2177 kgs per hectare, lagging behind countries such as China and Brazil that have yield rates of 4263 kgs/hectare and 3265 kgs/hectare respectively. The cereal yield per hectare in the country is also 2,981 kgs per hectare, lagging far behind countries such as China, Japan and the US.

The slow growth of agricultural production in India can be attributed to an inefficient rural transport system, lack of awareness about the treatment of crops, limited access to modern farming technology and the shrinking agricultural land due to urbanization. Add to that, an irregular monsoon and the fact that 63% of agricultural land is dependent on rainfall further increase the difficulties we face.

Despite these odds, there is huge potential for India to increase its agricultural productivity to meet the food requirements of its growing population.

The good news is that experience in India and other countries shows that the adoption of sustainable farming practices can increase both productivity and reduce ecological harm.

Sustainable agriculture techniques enable higher resource efficiency – they help produce greater agricultural output while using lesser land, water and energy, ensuring profitability for the farmer. These essentially include methods that, among other things, protect and enhance the crops and the soil, improve water absorption and use efficient seed treatments. While Indian farmers have traditionally followed these principles, new technology now makes them more effective.

For example, for soil enhancement, certified biodegradable mulch films are now available. A mulch film is a layer of protective material applied to soil to conserve moisture and fertility. Most mulch films used in agriculture today are made of polyethylene (PE), which has the unwanted overhead of disposal. It is a labour intensive and time-consuming process to remove the PE mulch film after usage. If not done, it affects soil quality and hence, crop yield. An independently certified biodegradable mulch film, on the other hand, is directly absorbed by the microorganisms in the soil. It conserves the soil properties, eliminates soil contamination, and saves the labor cost that comes with PE mulch films.

The other perpetual challenge for India’s farms is the availability of water. Many food crops like rice and sugarcane have a high-water requirement. In a country like India, where majority of the agricultural land is rain-fed, low rainfall years can wreak havoc for crops and cause a slew of other problems - a surge in crop prices and a reduction in access to essential food items. Again, Indian farmers have long experience in water conservation that can now be enhanced through technology.

Seeds can now be treated with enhancements that help them improve their root systems. This leads to more efficient water absorption.

In addition to soil and water management, the third big factor, better seed treatment, can also significantly improve crop health and boost productivity. These solutions include application of fungicides and insecticides that protect the seed from unwanted fungi and parasites that can damage crops or hinder growth, and increase productivity.

While sustainable agriculture through soil, water and seed management can increase crop yields, an efficient warehousing and distribution system is also necessary to ensure that the output reaches the consumers. According to a study by CIPHET, Indian government’s harvest-research body, up to 67 million tons of food get wasted every year — a quantity equivalent to that consumed by the entire state of Bihar in a year. Perishables, such as fruits and vegetables, end up rotting in store houses or during transportation due to pests, erratic weather and the lack of modern storage facilities. In fact, simply bringing down food wastage and increasing the efficiency in distribution alone can significantly help improve food security. Innovations such as special tarpaulins, that keep perishables cool during transit, and more efficient insulation solutions can reduce rotting and reduce energy usage in cold storage.

Thus, all three aspects — production, storage, and distribution — need to be optimized if India is to feed its ever-growing population.

One company working to drive increased sustainability down the entire agriculture value chain is BASF. For example, the company offers cutting edge seed treatments that protect crops from disease and provide plant health benefits such as enhanced vitality and better tolerance for stress and cold. In addition, BASF has developed a biodegradable mulch film from its ecovio® bioplastic that is certified compostable – meaning farmers can reap the benefits of better soil without risk of contamination or increased labor costs. These and more of the company’s innovations are helping farmers in India achieve higher and more sustainable yields.

Of course, products are only one part of the solution. The company also recognizes the importance of training farmers in sustainable farming practices and in the safe use of its products. To this end, BASF engaged in a widespread farmer outreach program called Samruddhi from 2007 to 2014. Their ‘Suraksha Hamesha’ (safety always) program reached over 23,000 farmers and 4,000 spray men across India in 2016 alone. In addition to training, the company also offers a ‘Sanrakshan® Kit’ to farmers that includes personal protection tools and equipment. All these efforts serve to spread awareness about the sustainable and responsible use of crop protection products – ensuring that farmers stay safe while producing good quality food.

Interested in learning more about BASF’s work in sustainable agriculture? See here.

This article was produced by the Scroll marketing team on behalf of BASF and not by the Scroll editorial team.