UIDAI Aadhaar software hacked using a patch that disabled critical security: Report
UIDAI Aadhaar software used to enrol new users may have been subjected to a hack using a software patch that disables critical security features


Woman using an iris scanner for UIDAI Aadhaar registration. Image: Reuters[/caption]This software patch basically compromises the inbuilt security features on the Aadhaar enrolment software on three fronts. First, it bypasses the need for authentication of the person using the software to enrol new people. Secondly, the patch disables the software's inbuilt GPS security feature, letting anyone from anywhere access this software and enrol people. And finally, the patch reduces the sensitivity of the Aadhaar enrolment software's iris recognition feature, thereby making it easier to manipulate the software using a photograph of the registered operator.HuffPost India consulted with five experts to analyse and confirm the working mechanism of the patch. To prevent any more violations of the Aadhaar enrolment software via this patch, the entire enrolment system would have to be redesigned according to one expert.The report states that the vulnerability may have been inserted in the patch, during the time when Aadhaar enrolment software was used by private agencies to enrol people. According to a software architect at MindTree, a Bengaluru-based firm who worked on making the first Aadhaar enrolment software, which would be used by private Aadhaar operators registering citizens. Security measures such as biometric authentication, GPS location and more were added to the software back in 2010. But subsequent software patches introduced vulnerabilities around 2017 which would bypass these security measures.The UIDAI has responded to these allegations by saying: "Unique Identification Authority of India dismisses a news report appearing in social & online media about Aadhaar Enrolment Software being allegedly hacked as completely incorrect and irresponsible. The claims lack substance and are baseless".
You can read the complete investigation on HuffPost India.This is yet another addition to the various vulnerabilities we have seen with regards to the Aadhaar database.
Why AI notetakers are raising serious privacy and security concerns
China's low-cost AI models are changing the global AI race. Here's why Silicon Valley is worried
China's Kimi K3 challenges US AI leaders with frontier-level performance at lower cost
How did Instagram run ads promoting child abuse in India?
Why has India halted WhatsApp’s username feature before launch?
