Don't shoot the messenger

UIDAI must review its security set-up

Image
Business Standard Editorial Comment
Last Updated : Jan 09 2018 | 10:31 PM IST
On January 4, The Tribune newspaper carried a report on how anonymous sellers over WhatsApp were allegedly providing access to Aadhaar numbers for a paltry sum of Rs 500. The report claimed that personal details such as names, addresses, phone numbers, etc of a whole host of people could be easily accessed by logging into the portal of the Unique Identification Authority of India (UIDAI), and that printouts of all these details were being made available for another Rs 300. This was shocking enough; what was appalling was the response of the UIDAI, which first accepted this was a massive breach, and then denied it, and finally settled on filing a first information report (FIR) against the newspaper and the reporter.

According to the FIR, the newspaper "purchased" a service being offered illegally and which provided unrestricted access to details for any of the more than 1 billion Aadhaar numbers created in India. The FIR also details how the reporter got in touch with a few persons who unauthorisedly accessed the Aadhaar ecosystem, and concludes this was all part of a criminal conspiracy. While the so-called sting journalism does raise some ethical questions, the fact is that the report report focuses on a critical issue concerning millions of India’s citizens — how the Aadhaar numbers are being mined for money. The report also sought and received a response from the UIDAI before going to print and did not publish any of the Aadhaar numbers or other details.

The UIDAI’s decision, thus, is a desperate reaction by an organisation refusing to face the facts. Most importantly, the FIR is a direct attack on the freedom of the press, contrary to the UIDAI’s claim that it should not be viewed as such. The minimum the UIDAI should have done is to withdraw the FIR and order a thorough internal investigation into the alleged breach and make its findings public. Union Law and Justice Minister Ravi Shankar Prasad’s tweet that the central government is fully committed to media freedom, a day after various press bodies condemned the lodging of the FIR, is a welcome move, though it has still not been withdrawn by the UIDAI for some inexplicable reasons.

Since its foundation, the UIDAI has repeatedly held that Aadhaar data is secure. In fact, in this present case also, the UIDAI is correct in stating that mere information such as phone numbers and addresses — most of it is already available to telemarketers and others from other databases — cannot be misused without biometric data. However, many have always been sceptical about such claims as technology changes rapidly, allowing for the possibility of a hack. Moreover, even as this data is being collected, India still does not have an effective private data protection regime. Overall, the UIDAI’s ham-fisted response to the newspaper report only betrays its disregard for personal data and its possible abuse. The UIDAI has been entrusted with the most personal identification data of a billion-strong people, most of whom have linked their other details, such as bank accounts, to the Aadhaar number. The whole system is based on the people’s trust in the UIDAI. It must not fail them.

One subscription. Two world-class reads.

Already subscribed? Log in

Subscribe to read the full story →
*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

Next Story