UIDAI dismisses report of data leak, says Aadhaar remains safe

| Updated: Mar 24, 2018, 22:09 IST

Highlights

  • The UIDAI asserted that there has been "absolutely no breach" of its database
  • A report had claimed that "a data leak on a system run by a state-owned utility company can allow anyone to download private information on all Aadhaar holders
File photo used for representational purposeFile photo used for representational purpose
NEW DELHI: The Unique Identification Authority of India (UIDAI) on Saturday refuted reports about a fresh data leak of Aadhaar holders, and asserted that there has been "absolutely no breach" of its database.

The statement comes after a technology news portal cited a security researcher's claim to state that a system of state-owned utility firm was allegedly leaking information on Aadhaar holders.

In a statement issued here, UIDAI, the Aadhaar-issuing body, said: "there is no truth in this story as there has been absolutely no breach of UIDAIs Aadhaar database. Aadhaar remains safe and secure".

It termed the data breach claims as "totally baseless, false and irresponsible".

"UIDAI today has refuted reports in a certain section of media sourced from the news website ZDNet which has quoted a person purportedly claiming to be a security researcher that a state-owned utility company has vulnerability which can be used to access a huge amount of Aadhaar data including banking details," UIDAI said in its statement.

The UIDAI has argued that even if the report claims were taken to be true, the security related concerns should be around the database of utility company in question.

It has "nothing to do with security of UIDAIs Aadhaar database", it said.

Going by the logic of the report, since the utility company's database also had bank account numbers of its customers, would bank databases also be considered to have been breached, UIDAI questioned.

"The answer would obviously be in negative," it added.


UIDAI argued that mere availability of Aadhaar number with a third person "will not be a security threat to the Aadhaar holder" nor will it lead to financial or other fraud. This is because a transaction is contingent upon a successful authentication through fingerprint, Iris or OTP of the Aadhaar holder, UIDAI said.


The ZDNet report had claimed that "a data leak on a system run by a state-owned utility company can allow anyone to download private information on all Aadhaar holders, exposing their names, their unique 12-digit identity numbers, and information about services they are connected to, such as their bank details and other private information."


The report of the alleged security lapse comes at a time when a Constitutional bench of the Supreme Court is hearing a clutch of petitions challenging the Aadhaar Act and the use of biometric identifier in various government and non-government services.


Earlier this week, UIDAI CEO Ajay Bhushan Pandey had made a powerpoint presentation in the Supreme Court to defend the government's ambitious Aadhaar scheme. He had said that breaking Aadhaar encryption may take "more than the age of the universe for the fastest computer on earth."

Get latest news & live updates on the go on your pc with News App. Download The Times of India news app for your device. Read more India news in English and other languages.
RELATED

From the Web

More From The Times of India

From around the web

Catch Usha Uthap Live in the US. Book tickets now!

Gaana Music Fest

My Husband and I Tried Blue Apron, Here's What Happened

Blue Apron

Plastic Surgeon Reveals: “You Can Fill In Wrinkles At Ho..

Beverly Hills MD

More from The Times of India

Know your CWG athlete - Ankur Mittal

Know your CWG athlete - Neeraj Chopra

UIDAI CEO admits lapses and lacunae in Aadhaar system