Advertisement
Sections
Jharkhand govt website exposes Aadhaar numbers of over 100,000 employees
This is yet another case of government agencies using Aadhaar as a verification system, and not taking enough measures to secure the database online

There is really no stopping irresponsible use of Aadhaar data.In the latest incident, Aadhaar details of thousands of govt of Jharkhand employees have been exposed thanks to a lapse in security. Employees using the Aadhaar biometric attendance system to mark their attendance, have their details exposed as the servers holding this information have been without a password since 2014. The details available, for anyone looking in the right place, include Aadhaar numbers, names, job titles, email IDs and partial phone numbers. Around 166,000 employees' data has been left exposed according to the report in TechCrunch.
Representational image.The photos that have been uploaded on this attendance system use the person's Aadhaar number as the file name. The central biometric database seems to be secure according to the report.This is yet another case of government agencies using Aadhaar as a verification system, and not taking enough measures to secure the database online. According to TechCrunch, the site was found on a subdomain on the Jharkhand government's website. It looks like not enough security has been put in place, as the site has not only been indexed by Google but also the attendance record pages which have the Aadhaar numbers of the employees are visible.Robert Baptiste, who goes by the handle @ElliotAlderson, claimed that with less than hundred lines of Python code, one could easily scrape the entire data from the site in batches and match employee photos with their Aadhaar numbers.Neither UIDAI or the Jharkhand govt have commented on the matter. The UIDAI which uses its Twitter handle to 'debunk' allegations hasn't seen any update since the last 24 hours. According to the report, the website which has these details has been taken offline.[caption id="attachment_4364419" align="alignnone" width="1280"]
A man goes through the process of eye scanning for the Unique Identification (UID) database system, Aadhaar, at a registration centre in New Delhi, India. Image: Reuters[/caption]In the past, we have seen how the Unique Identification Authority of India (UIDAI) has not taken any criticism of lapses in Aadhaar security in the right spirit. We all know how UIDAI went after the journalist from The Tribune who exposed an Aadhaar racket which involved getting complete access to Aadhaar database for Rs 500. There have also been ridiculous claims by UIDAI on how the biometric database is protected by 5-foot-thick walls. Here's a whole list of Aadhaar-related data breaches that have happened over the years. Whether it's the Aadhaar app, government websites (as was the case with the above story), third party leaks, duplication of Aadhaar cards, and so on, no clear measures have come forthwith.Thankfully, after the massive 38-day hearing on Aadhaar, the Supreme Court bench ruled that using Aadhaar card for verification would not be compulsory for things such getting a mobile SIM card, bank enrollment, registering for exams such as NEET, JEE and while enrolling for admissions in universities, among other things. An Aadhaar number or proof of enrolment is however compulsory for individuals to avail certain government benefits, services, or subsidies being given by either the Centre or any of the states.
Representational image.The photos that have been uploaded on this attendance system use the person's Aadhaar number as the file name. The central biometric database seems to be secure according to the report.This is yet another case of government agencies using Aadhaar as a verification system, and not taking enough measures to secure the database online. According to TechCrunch, the site was found on a subdomain on the Jharkhand government's website. It looks like not enough security has been put in place, as the site has not only been indexed by Google but also the attendance record pages which have the Aadhaar numbers of the employees are visible.Robert Baptiste, who goes by the handle @ElliotAlderson, claimed that with less than hundred lines of Python code, one could easily scrape the entire data from the site in batches and match employee photos with their Aadhaar numbers.Neither UIDAI or the Jharkhand govt have commented on the matter. The UIDAI which uses its Twitter handle to 'debunk' allegations hasn't seen any update since the last 24 hours. According to the report, the website which has these details has been taken offline.[caption id="attachment_4364419" align="alignnone" width="1280"]
A man goes through the process of eye scanning for the Unique Identification (UID) database system, Aadhaar, at a registration centre in New Delhi, India. Image: Reuters[/caption]In the past, we have seen how the Unique Identification Authority of India (UIDAI) has not taken any criticism of lapses in Aadhaar security in the right spirit. We all know how UIDAI went after the journalist from The Tribune who exposed an Aadhaar racket which involved getting complete access to Aadhaar database for Rs 500. There have also been ridiculous claims by UIDAI on how the biometric database is protected by 5-foot-thick walls. Here's a whole list of Aadhaar-related data breaches that have happened over the years. Whether it's the Aadhaar app, government websites (as was the case with the above story), third party leaks, duplication of Aadhaar cards, and so on, no clear measures have come forthwith.Thankfully, after the massive 38-day hearing on Aadhaar, the Supreme Court bench ruled that using Aadhaar card for verification would not be compulsory for things such getting a mobile SIM card, bank enrollment, registering for exams such as NEET, JEE and while enrolling for admissions in universities, among other things. An Aadhaar number or proof of enrolment is however compulsory for individuals to avail certain government benefits, services, or subsidies being given by either the Centre or any of the states.First Published:Feb 01, 2019, 12:26:28 IST
Advertisement
Advertisement

Why AI notetakers are raising serious privacy and security concerns
AI notetakers promise effortless meeting summaries, but experts warn they could expose confidential conversations, corporate secrets and personal voiceprints. As businesses increasingly adopt AI-powered meeting assistants, questions over data storage, privacy, consent and legal risks are becoming impossible to ignore
5 min read
China's low-cost AI models are changing the global AI race. Here's why Silicon Valley is worried
As Chinese firms continue to improve performance while keeping prices low, the AI race is no longer just about building the smartest model—it is increasingly becoming a battle over who can deliver the best value
2 min read
China's Kimi K3 challenges US AI leaders with frontier-level performance at lower cost
Chinese artificial intelligence startup Moonshot AI has unveiled its latest open-weight AI model, Kimi K3, with early results suggesting it could compete with some of the world's most advanced AI systems developed by leading US companies
2 min read
How did Instagram run ads promoting child abuse in India?
India has issued a notice to Meta after an investigation alleged that Instagram displayed paid advertisements promoting child sexual abuse material. MeitY ordered Meta to remove such Instagram ads and explain within seven days how they were approved
8 min read
Why has India halted WhatsApp’s username feature before launch?
India has halted WhatsApp’s planned username feature, citing concerns about cybercrime, impersonation, and law enforcement challenges. As Meta races to address security concerns, here’s why MeitY has paused the rollout, what the feature does, and how it could influence privacy and online safety in India
3 min read
Advertisement
Advertisement
