Skip to content

Comment on Access to India's Aadhaar citizen database selling for under USD $10

Comments

The main problem is that the government wants provide access to this data to all its departments without any say from the citizens. So they ended up creating login based system for departments that has only crude access controls (view/update etc). They didn't segregate and secure the data by state/village etc. So a single corrupt low level official of any department can just 'share' his login with anyone else (assuming the login is even secure to start with).

If I had to design this, I would have added a two factor access to each citizens data which can only be accessed with their consent. But this model doesn't let the government departments access all the data at will.

If you could do it with 2FA, you wouldnt need to make Aadhar in the first place.

I've followed the program from inception. The real genius lies in 2 things, little of which have to do with tech.

The first genius lies in the design of responsibility and liability of the Aadhar authority.

The authority is impervious to assault legally - it is the only person who can mount a legal challenge on the misuse of aadhar numbers.

The authority also farms out all responsibility of usage of aadhar to "other entities". Thus it can never be held accountable since it only "provides other people a tool". What they do with it, is not the Agency's issue.

This is how its engineers can talk on various privacy channels as being fully for privacy and security, the agency itself can be a secure keeper for the biometric information - but the actual harm being done is farmed out to other agencies who can then take the blame.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.