NewsBytes Stage
    Hindi
    More
    In the news
    Narendra Modi
    Amit Shah
    Box Office Collection
    Bharatiya Janata Party (BJP)
    OTT releases
    Hindi
    NewsBytes Stage
    India
    Business
    World
    Politics
    Sports
    Technology
    Entertainment
    Auto
    Lifestyle
    Career
    Visual Stories
    Find Cricket Statistics

    Download Android App

    Follow us on
    • Facebook
    • Twitter
    • Linkedin
    Home / News / India News / UIDAI denies claims of Aadhaar data breach on Indane's systems
    Next Article
    UIDAI denies claims of Aadhaar data breach on Indane's systems

    UIDAI denies claims of Aadhaar data breach on Indane's systems

    By Bhavika Bhuwalka
    Mar 25, 2018
    01:34 pm

    What's the story

    The UIDAI has denied the claims of an Aadhaar data breach on the systems run by state-owned utility company Indane.

    Earlier, a ZDNet.com/article/another-data-leak-hits-india-aadhaar-biometric-database/">report by ZDNet suggested that the Aadhaar details of all registered Indane customers were exposed online and could be accessed by anyone.

    UIDAI said that "there is no truth in this story" and that they were "contemplating legal action against ZDNet."

    Context

    Report claimed Indane's unsecured API put Aadhaar data at risk

    The report claimed that Indane's API wasn't secure, allowing access to personal information like names, unique 12-digit Aadhaar numbers, and bank names related to those Aadhaar numbers.

    "The affected endpoint uses a hardcoded access token, which, when decoded, translates to 'INDAADHAARSECURESTATUS,' allowing anyone to query Aadhaar numbers against the database without any additional authentication," the report said.

    Quote

    Aadhaar biometric data not easy to hack: UIDAI

    Last week, UIDAI CEO Ajay Bhushan Pandey said, "Each Aadhaar biometric is encrypted by a 2048-key combination and to decode it, the best and fastest computer of our era will take the age of the universe just to hack into one card's biometric details."

    Response

    UIDAI threatens legal action against ZDNet

    "One must understand that the Aadhaar number is not a secret number," UIDAI explained.

    "Mere availability of Aadhaar number with a third person will not be a security threat to the Aadhaar holder or will not lead to financial/other fraud, as for any transaction, a successful authentication through fingerprint, Iris or OTP of the Aadhaar holder is required," it added.

    Background

    Indane's endpoint vulnerability discovered by Delhi-based security researcher

    The ZDNet report said the endpoint vulnerability was discovered by Delhi-based security researcher Karan Saini.

    He claimed that since Indane has access to the entire Aadhaar database through an unsecured API, information of all Aadhaar holders was at risk.

    Hackers can go through endless permutations to guess an Aadhaar number and steal its corresponding information since the API doesn't employ rate limiting, Saini added.

    Claims

    Informed government of the data breach a month ago: ZDNet

    ZDNet said that it had informed the government of the alleged data breach a month ago but received no response regarding the same.

    It then contacted the Indian Consulate in New York and Devi Prasad Misra, consul for trade and customs, but to no avail.

    However, ZDNet claims that within hours of publishing the story, the affected endpoint was taken offline.

    Information

    Earlier, security researcher hacked Aadhaar to access 22,000 card details

    Aadhaar has been continuously in the news regarding security vulnerabilities. Earlier, French security researcher Elliot Alderson hacked into the Aadhaar Android app within a minute and reportedly gained access to 22,000 card details. Notably, Aadhaar is the world's biggest database with over 1.1 billion users.

    Facebook
    Whatsapp
    Twitter
    Linkedin
    Related News
    Latest
    Aadhaar Card
    Data Leak
    Unique Identification Authority of India
    ZDNet

    Latest

    Bangladesh Cricket Board pondering over Bangladesh's tour of Pakistan Bangladesh Cricket Board
    Why Virat Kohli's presence could lift India in England? Stats Virat Kohli
    Google Workspace accounts gain access to Gemini Live feature Google
    Adani Group deploys India's 1st hydrogen-powered truck in Chhattisgarh Adani Group

    Aadhaar Card

    Linking Aadhaar with SIM cost this man Rs. 1 lakh India
    Lost your Aadhaar Card? Here's how you can retrieve details India
    UIDAI adds another security feature to Aadhaar: Facial recognition India
    Advocate to SC: Aadhaar will cause death of civil rights India

    Data Leak

    Ludhiana government website publishes details of 20,000 Aadhaar holders Ludhiana
    Aadhaar poses security challenges, admits Nandan Nilekani Aadhaar Card
    81 lakh Aadhaar numbers deactivated: Is yours one of them? India
    Is UC Browser leaking your mobile data? India

    Unique Identification Authority of India

    After banks' objection, UIDAI relaxes Aadhaar enrolment rules Aadhaar Card
    Three new ways for you to re-verify SIM with Aadhaar India
    SIM re-verification: SMS method "not safe", use IVR or website Aadhaar Card
    SBI may block your account if you don't link Aadhaar! Aadhaar Card

    ZDNet

    711 million email accounts susceptible to malignant spambot Malware
    Indian Premier League (IPL) Celebrity Hollywood Bollywood UEFA Champions League Tennis Football Smartphones Cryptocurrency Upcoming Movies Premier League Cricket News Latest automobiles Latest Cars Upcoming Cars Latest Bikes Upcoming Tablets
    About Us Privacy Policy Terms & Conditions Contact Us Ethical Conduct Grievance Redressal News News Archive Topics Archive Download DevBytes Find Cricket Statistics
    Follow us on
    Facebook Twitter Linkedin
    All rights reserved © NewsBytes 2025