<?xml version="1.0" encoding="utf-8" ?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns="http://purl.org/rss/1.0/">




    



<channel rdf:about="http://editors.cis-india.org/search_rss">
  <title>Centre for Internet and Society</title>
  <link>http://editors.cis-india.org</link>
  
  <description>
    
            These are the search results for the query, showing results 171 to 185.
        
  </description>
  
  
  
  
  <image rdf:resource="http://editors.cis-india.org/logo.png"/>

  <items>
    <rdf:Seq>
        
            <rdf:li rdf:resource="http://editors.cis-india.org/internet-governance/news/vidushi-marda-selected-for-internet-of-rights-fellowship"/>
        
        
            <rdf:li rdf:resource="http://editors.cis-india.org/internet-governance/news/livemint-may-2-2017-komal-gupta-govt-may-have-made-135-million-aadhaar-numbers-public-cis-report"/>
        
        
            <rdf:li rdf:resource="http://editors.cis-india.org/internet-governance/news/the-wire-may-1-2015-130-million-aadhaar-numbers-were-made-public-says-new-report"/>
        
        
            <rdf:li rdf:resource="http://editors.cis-india.org/internet-governance/news/scroll-may-2-2017-around-13-crore-aadhaar-numbers-easily-available-on-government-portals-says-report"/>
        
        
            <rdf:li rdf:resource="http://editors.cis-india.org/internet-governance/news/new-indian-express-may-2-2017-akram-mohammed-13-crore-aadhaar-numbers-on-four-government-websites-compromised"/>
        
        
            <rdf:li rdf:resource="http://editors.cis-india.org/internet-governance/news/one-india-may-2-2017-anusha-ravi-what-privacy-13-crore-aadhaar-numbers-accessible-on-governmental-portals"/>
        
        
            <rdf:li rdf:resource="http://editors.cis-india.org/internet-governance/news/manorama-may-2-2017-jikku-varghese-jacob-biggest-blast-on-aadhaar-leak-so-far-govt-sites-leaked-data-of-13-crore-people"/>
        
        
            <rdf:li rdf:resource="http://editors.cis-india.org/accessibility/events/global-accessibility-awareness-day-2017"/>
        
        
            <rdf:li rdf:resource="http://editors.cis-india.org/internet-governance/news/the-register-richard-chirgwin-may-3-2017-135-million-indian-government-payment-card-details-leaked"/>
        
        
            <rdf:li rdf:resource="http://editors.cis-india.org/internet-governance/news/hindu-krishnadas-rajagopal-may-3-2017-aadhaar-data-leaks-not-from-uidai"/>
        
        
            <rdf:li rdf:resource="http://editors.cis-india.org/internet-governance/news/medianama-nikhil-pahwa-may-4-2017-around-130-135-m-aadhaar-numbers-published-on-four-sites-alone"/>
        
        
            <rdf:li rdf:resource="http://editors.cis-india.org/internet-governance/news/dna-may-2-2017-report-aadhaar-numbers-of-135-mn-may-have-leaked-claims-cis-report"/>
        
        
            <rdf:li rdf:resource="http://editors.cis-india.org/internet-governance/news/amar-bazar-patrika-may-2-2017-13-crore-aadhaar-leaked-due-to-poor-security-in-4-govt-websites"/>
        
        
            <rdf:li rdf:resource="http://editors.cis-india.org/internet-governance/news/newslaundry-shruti-menon-may-2-2017-uidai-remains-silent-on-aadhaar-leaks-of-users-through-govt-portals"/>
        
        
            <rdf:li rdf:resource="http://editors.cis-india.org/internet-governance/news/hindustan-times-may-2-2017-details-of-135-million-aadhaar-card-holders-may-have-leaked-claims-cis-report"/>
        
    </rdf:Seq>
  </items>

</channel>


    <item rdf:about="http://editors.cis-india.org/internet-governance/news/vidushi-marda-selected-for-internet-of-rights-fellowship">
    <title>Vidushi Marda selected for Internet of Rights Fellowship</title>
    <link>http://editors.cis-india.org/internet-governance/news/vidushi-marda-selected-for-internet-of-rights-fellowship</link>
    <description>
        &lt;b&gt;Article 19 had put out a call for applications for its Internet of Rights Fellowship in February 2017. Vidushi has been selected to be part of the 2017-2018 cohort.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;This fellowship aims to "facilitate stronger considerations for human rights within Internet governance processes and to shape the human rights agenda for the Internet". As a Fellow, Vidushi will be primarily working on AI and ethics. The IEEE is developing a document on "Ethically Aligned Design: A Vision for Prioritizing Human Wellbeing with Artificial Intelligence and Autonomous Systems". The development process includes various committees, my work will focus on:&lt;/p&gt;
&lt;ol&gt;
&lt;li style="text-align: justify; "&gt;General Principles Committee: This Committee is currently deliberating on how to ensure that AI/AS can be designed and operated to respect human rights, and how to make AI/AS transparent, and accountable.&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;Law Committee: Working on the aspects of legal accountability and transparency, closely connected to ethics.&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;EPIC AI/AS Committee (new): Working on adoption of AI/AS in public services, and focussing on ethical principles guiding such adoption.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;
&lt;/ol&gt;
        &lt;p&gt;
        For more details visit &lt;a href='http://editors.cis-india.org/internet-governance/news/vidushi-marda-selected-for-internet-of-rights-fellowship'&gt;http://editors.cis-india.org/internet-governance/news/vidushi-marda-selected-for-internet-of-rights-fellowship&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    

   <dc:date>2017-05-03T15:48:58Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="http://editors.cis-india.org/internet-governance/news/livemint-may-2-2017-komal-gupta-govt-may-have-made-135-million-aadhaar-numbers-public-cis-report">
    <title>Govt may have made 135 million Aadhaar numbers public: CIS report</title>
    <link>http://editors.cis-india.org/internet-governance/news/livemint-may-2-2017-komal-gupta-govt-may-have-made-135-million-aadhaar-numbers-public-cis-report</link>
    <description>
        &lt;b&gt;CIS report says Aadhaar numbers leaked through government databases could be 100-135 million and bank accounts numbers leaked about 100 million.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by Komal Gupta was &lt;a href="http://www.livemint.com/Politics/oj7ky556p6vdljXpRw8gPP/135-million-Aadhaar-numbers-made-public-by-government-author.html"&gt;published in Livemint&lt;/a&gt; on May 2, 2017.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;A central government ministry and a state government may have       made public up to 135 million Aadhaar numbers, according to a       research report issued by Bengaluru-based think tank Centre for       Internet and Society (CIS) late on Monday.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The &lt;a href="http://cis-india.org/internet-governance/information-security-practices-of-aadhaar-or-lack-thereof-a-documentation-of-public-availability-of-aadhaar-numbers-with-sensitive-personal-financial-information-1" target="_blank"&gt;report&lt;/a&gt; titled &lt;i&gt;Information Security         Practices of Aadhaar (or lack thereof): A documentation of         public availability of Aadhaar numbers with sensitive personal         financial information&lt;/i&gt; studied four government databases.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The first two belong to the rural development ministry—the       National Social Assistance Programme (NSAP)’s dashboard and the       National Rural Employment Guarantee Act’s (NREGA) portal.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The other two databases deal with Andhra Pradesh—the state’s own       NREGA portal and the online dashboard of a government scheme       called “Chandranna Bima”.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“Based on the numbers available on the websites looked at, the       estimated number of Aadhaar numbers leaked through these four       portals could be around 130-135 million and the number of bank       account numbers leaked at around 100 million from the specific       portals we looked at,” said Amber Sinha and Srinivas Kodali, the       authors of the research report.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The report claims these government dashboards and databases       revealed personally identifiable information (PII) due to a lack       of proper controls exercised by the departments.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“While the availability of aggregate information on the Dashboard       may play a role in making government functioning more transparent,       the fact that granular details about individuals including       sensitive PII such as Aadhaar number, caste, religion, address,       photographs and financial information are only a few clicks away       suggest how poorly conceived these initiatives are,” said the       report.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The report said the NSAP portal lists 94,32,605 bank accounts and       14,98,919 post office accounts linked with Aadhaar.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“While the UIDAI (Unique Identification Authority of India) has       been involved in proactively pushing for other databases to get       seeded with Aadhaar numbers, they take little responsibility in       ensuring the security and privacy of such data,” said the report.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;UIDAI did not respond to an email from &lt;i&gt;Mint&lt;/i&gt; seeking       comments.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='http://editors.cis-india.org/internet-governance/news/livemint-may-2-2017-komal-gupta-govt-may-have-made-135-million-aadhaar-numbers-public-cis-report'&gt;http://editors.cis-india.org/internet-governance/news/livemint-may-2-2017-komal-gupta-govt-may-have-made-135-million-aadhaar-numbers-public-cis-report&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-03T15:43:37Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="http://editors.cis-india.org/internet-governance/news/the-wire-may-1-2015-130-million-aadhaar-numbers-were-made-public-says-new-report">
    <title>130 Million Aadhaar Numbers Were Made Public, Says New Report</title>
    <link>http://editors.cis-india.org/internet-governance/news/the-wire-may-1-2015-130-million-aadhaar-numbers-were-made-public-says-new-report</link>
    <description>
        &lt;b&gt;The research report looks at four major government portals whose poor information security practices have exposed personal data including bank account details.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article was &lt;a href="https://thewire.in/130948/aadhaar-card-details-leaked/"&gt;published in the Wire&lt;/a&gt; on May 1, 2017. This was also mirrored on &lt;a class="external-link" href="http://www.mensxp.com/technology/latest/36661-over-130-million-aadhaar-numbers-bank-details-were-leaked-way-are-not-surprised.html"&gt;MensXP.com&lt;/a&gt; on May 5, 2017.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;Irresponsible         information security practices by a major central government         ministry and a state government may have exposed up to 135         million Aadhaar numbers, according to a new research report         released on Monday.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;The&lt;a href="https://thewire.in/118250/government-expose-personal-data-thousands-indians/" rel="noopener           noreferrer" target="_blank" title=" last two months "&gt; last two months &lt;/a&gt;have seen a wave of data         leaks, mostly due improper information security practices, from         various central government and state government departments.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;This &lt;a rel="noopener noreferrer" target="_blank" title="new report"&gt;new report&lt;/a&gt;, released by the Centre       for Internet and Society, studied four government databases. The       first two belong to the rural development ministry: the National       Social Assistance Programme (NSAP)’s dashboard and the National       Rural Employment Guarantee Act (NREGA)’s portal.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The second two databases deal with the state of       Andhra Pradesh: namely, the state government’s own NREGA portal       and the online dashboard of a state government scheme called       “Chandranna Bima”.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“Based on the numbers available on the websites       looked at, estimated number of Aadhaar numbers leaked through       these 4 portals could be around 130-135 million and the number of       bank accounts numbers leaked at around 100 million from the       specific portals we looked at,” the report’s authors, Amber Sinha       and Srinivas Kodali, state.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The data leaks come, in part, from the       government’s decision to provide online dashboards that were       likely meant for general transparency and easy administration.       However, as the report notes, while open data portals are a       laudable goal, if there aren’t any proper safeguards, the results       can be downright disastrous.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“While availability of aggregate information on       the dashboard may play a role in making government functioning       more transparent, the fact that granular details about individuals       including sensitive PII such as Aadhaar number, caste, religion,       address, photographs and financial information are only a few       clicks away suggest how poorly conceived these initiatives are,”       the report says.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Consider the NSAP portal for instance. The       dashboard allows users to explore a list of pensioners, whose       personally identifiable information include bank account number,       name and Aadhaar number. While these details are “masked for       public view”, the CIS report points out that if “one of the URL       query parameters of the website… was modified from ‘nologin’ to       ‘login'”, it became easy to gain access to the unmasked details       without a password.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“It is entirely unclear to us what the the       purpose behind making available a data download pption on the NSAP       website is. This feature allows download of beneficiary details       mentioned above such as Beneficiary No., Name, Father’s/Husband’s       Name, Age, Gender, Bank or Post Office Account No. for       beneficiaries receiving disbursement via bank transfer and Aadhaar       Numbers for each area, district and state,” the report states.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;UIDAI role?&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Kodali and Sinha also prominently finger the role       of the Unique Identification Authority of India (UIDAI), the       government agency that manages the Aadhaar initiative, in the data       leaks.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“While the UIDAI has been involved in proactively       pushing for other databases to get seeded with Aadhaar numbers,       they take little responsibility in ensuring the security and       privacy of such data.With countless databases seeded with Aadhaar       numbers, we would argue that it is extremely irresponsible on the       part of the UIDAI, the sole governing body for this massive       project, to turn a blind eye to the lack of standards prescribed       for how other bodies shall deal with such data, such cases of       massive public disclosures of this data, and the myriad ways in       which it may used for mischief,” the report states.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Still public?&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;A crucial question that arises is whether these       government databases are still leaking data. Over the last two       months, some of information has been masked.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“It must be stated that since we began reviewing       and documenting these portals, we have noticed that some of the       pages with sensitive PII (personally identifiable information)       have now been masked, presumably in response to growing reports       about Aadhaar leaks,” the report notes.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='http://editors.cis-india.org/internet-governance/news/the-wire-may-1-2015-130-million-aadhaar-numbers-were-made-public-says-new-report'&gt;http://editors.cis-india.org/internet-governance/news/the-wire-may-1-2015-130-million-aadhaar-numbers-were-made-public-says-new-report&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-20T06:32:32Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="http://editors.cis-india.org/internet-governance/news/scroll-may-2-2017-around-13-crore-aadhaar-numbers-easily-available-on-government-portals-says-report">
    <title>Around 13 crore Aadhaar numbers easily available on government portals, says report</title>
    <link>http://editors.cis-india.org/internet-governance/news/scroll-may-2-2017-around-13-crore-aadhaar-numbers-easily-available-on-government-portals-says-report</link>
    <description>
        &lt;b&gt;A report by The Centre for Internet and Society claimed that around 13 crore Aadhaar numbers and 10 crore bank account numbers were easily accessible on four government portals built to oversee welfare schemes. The document, released on Monday, pointed out that though it is illegal to reveal Aadhaar numbers, the government portals examined made it easy for anyone to access them, as well as other data about beneficiaries of welfare schemes including in many cases their bank account numbers. &lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;This was &lt;a href="https://scroll.in/latest/836271/around-13-crore-aadhaar-numbers-easily-available-on-government-portals-says-report"&gt;published by Scroll.in&lt;/a&gt; on May 2, 2017.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;&lt;a class="external-link" href="http://cis-india.org/internet-governance/information-security-practices-of-aadhaar-or-lack-thereof-a-documentation-of-public-availability-of-aadhaar-numbers-with-sensitive-personal-financial-information-1"&gt;The report&lt;/a&gt; suggests that the Aadhaar numbers       leaked could actually be closer to 23 crore, if most of the       government portals connected to direct benefit transfers used the       same negligent standards for storing data as the ones examined.       “It is extremely irresponsible on the part of the UIDAI [Unique       Identification Authority of India], the sole governing body for       this massive project, to turn a blind eye to the lack of standards       prescribed for how other bodies shall deal with such data, such       cases of massive public disclosures of this data, and the myriad       ways in which it may used for mischief,” the authors of the report       said.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The document also pointed out that the breaches       are an indicator of “potentially irreversible privacy harm” and       said the data could be used for financial fraud. The report       authored by Amber Sinha and Srinivas Kodali studied the National       Social Assistance Programme, National Rural Employment Guarantee       Scheme, Andhra Pradesh government’s Chandranna Bima Scheme and       Andhra Pradesh’s Daily Online Payment Reports of NREGA.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;While the report said the Aadhaar initiative as a       concept may be praiseworthy, the absence of adequate security       could prove disastrous. “Sensitive personal identity information       such as Aadhaar number, caste, religion, address, photographs and       financial information are only a few clicks away and suggest how       poorly conceived these initiatives are,” the report said.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The Centre had, on April 25, cautioned states &lt;a href="https://scroll.in/latest/835658/centre-cautions-states-against-leak-of-aadhaar-data"&gt;against         leaking Aadhaar information&lt;/a&gt;, after it emerged that a &lt;a href="https://scroll.in/article/835546/the-centres-casual-response-to-aadhaar-data-breaches-spells-trouble"&gt;number         of government websites&lt;/a&gt; were making it easy for people to       access individuals’ Aadhaar numbers. The Unique Identification       Authority of India also &lt;a href="https://scroll.in/latest/835056/uidai-files-firs-against-eight-websites-for-offering-aadhaar-enrolment-services-illegally"&gt;filed&lt;/a&gt; First Information Reports against eight private websites for       collecting Aadhaar-related data from citizens in an unauthorised       manner on April 19, but no such action appears to have been taken       against government websites so far.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;According to government data, the UIDAI has       issued 112 crore Aadhaar numbers so far and has maintained that       its biometrics database is tamper-proof, although it is up to       various other authorities to maintain the secrecy of Aadhaar data       collected or kept by them.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;On April 21, the Supreme Court had questioned the       Centre for making the Aadhaar card mandatory for a number of       central schemes despite its repeated orders that the unique       identification programme cannot be made mandatory. The government       has nevertheless been expanding the scope of the Unique Identity       project over the past few months by introducing it for initiatives       such as the midday meal scheme of school lunches for children,       and, most recently, requiring Aadhaar to file income tax returns.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In March, an Aadhaar enrolment agency had been       de-registered for leaking the personal data of cricketer Mahendra       Singh Dhoni.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='http://editors.cis-india.org/internet-governance/news/scroll-may-2-2017-around-13-crore-aadhaar-numbers-easily-available-on-government-portals-says-report'&gt;http://editors.cis-india.org/internet-governance/news/scroll-may-2-2017-around-13-crore-aadhaar-numbers-easily-available-on-government-portals-says-report&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-03T15:29:12Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="http://editors.cis-india.org/internet-governance/news/new-indian-express-may-2-2017-akram-mohammed-13-crore-aadhaar-numbers-on-four-government-websites-compromised">
    <title>13 crore Aadhaar numbers on four government websites compromised: Report</title>
    <link>http://editors.cis-india.org/internet-governance/news/new-indian-express-may-2-2017-akram-mohammed-13-crore-aadhaar-numbers-on-four-government-websites-compromised</link>
    <description>
        &lt;b&gt;The lack of information security practices in key government websites which hosts Personally Identifiable Information (PII) has left citizens of the country more vulnerable to identity theft and financial fraud, a research paper has argued. &lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by Akram Mohammed was &lt;a href="http://www.newindianexpress.com/nation/2017/may/02/13-crore-aadhaar-numbers-on-four-government-websites-compromised-report-1599999.html"&gt;published by the New Indian Express&lt;/a&gt; on May 2, 2017.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;A paper by Amber Sinha and Srinivas       Kodali of Centre for Internet and Society analysed four government       websites and found that more than 13 crore Aadhaar numbers with       related PII were available on the websites, exposing lax security       features.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The paper published under Creative       Commons is titled ‘Information Security Practices of Aadhaar (or       lack thereof): A documentation of public availability of Aadhaar       Numbers with sensitive personal financial information’ and was       released on Monday.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Sinha and Kodali looked at databases       on four government portals -- National Social Assistance       Programme, National Rural Employment Guarantee Scheme, Chandranna       Bima Scheme, Govt. of Andhra Pradesh and Daily Online Payment       Reports website of NREGA, Govt. of Andhra Pradesh.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“We chose major government       programmes that use Aadhaar for payments and banking transactions.       We found sensitive and personal data and information accessible on       these portals,” the report said.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Leaked through portals&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“Based on the numbers available on       the websites, estimated number of Aadhaar numbers leaked through       these 4 portals could be around 130-135 million and the number of       bank account numbers leaked at around 100 million.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;While these numbers are only from       two major government programmes of pensions and rural employment       schemes, other major schemes, that have also used Aadhaar for DBT,       could have leaked PII similarly due to lack of information       security practices,” it said.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;They fear that data of over 23 crore       beneficiaries under DBT of LPG subsidies could be leaked also.       Identity theft and financial fraud “risks increase multifold in       India...,” they said.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Aadhaar payments unsafe&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In case a financial fraud takes       place through Aadhaar enabled Payment System (AePS), the consumer       may not be able to assert his claims for compensation due to the       terms and conditions around liabilities.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“These terms force the consumer to       take liabilities onto oneself than the payment provider.....       Regulations and standards around Aadhaar are at a very early and       nascent stage causing (an) increase in financial risk for both       consumers and banks to venture into AePS,” they added. The authors       also pulled up UIDAI for their inability in providing strong       legislation against such leaks.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Leaky govt portals&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;National Social Assistance Programme&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;PII available - Access to Aadhaar no., name, bank account number, account frozen status  94,32,605 bank accounts linked with Aadhaar&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;14,98,919  post office accounts linked with Aadhaar numbers.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Though total Aadhaar number is  1,56,42,083, not all are linked to bank accounts&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;NREGA&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;PII Details available: Job card no., Aadhaar number, bank/postal account number, no. of days worked, registration no., account frozen status&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;78,74,315  post office accounts of individual workers seeded with Aadhaar numbers,&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;8,24,22,161 bank accounts of individual workers with Aadhaar numbers.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;10,96,41,502 total number of Aadhaar numbers stored by portal&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Other websites&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Chandranna Bima Scheme, Govt. of Andhra Pradesh&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Daily Online Payment Reports website of NREGA, Govt. of Andhra Pradesh&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='http://editors.cis-india.org/internet-governance/news/new-indian-express-may-2-2017-akram-mohammed-13-crore-aadhaar-numbers-on-four-government-websites-compromised'&gt;http://editors.cis-india.org/internet-governance/news/new-indian-express-may-2-2017-akram-mohammed-13-crore-aadhaar-numbers-on-four-government-websites-compromised&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-03T15:19:52Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="http://editors.cis-india.org/internet-governance/news/one-india-may-2-2017-anusha-ravi-what-privacy-13-crore-aadhaar-numbers-accessible-on-governmental-portals">
    <title>What privacy? 13 crore Aadhaar numbers accessible on government portals</title>
    <link>http://editors.cis-india.org/internet-governance/news/one-india-may-2-2017-anusha-ravi-what-privacy-13-crore-aadhaar-numbers-accessible-on-governmental-portals</link>
    <description>
        &lt;b&gt;At least 13 crore Aadhaar numbers and 10 crore bank account numbers are readily accessible on government portals, a report claims.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The blog post by Anusha Ravi was &lt;a href="http://www.oneindia.com/india/what-privacy-13-crore-aadhaar-numbers-accessible-on-government-portals-2422904.html"&gt;published         in Oneindia&lt;/a&gt; on May 2, 2017.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;The centre for internet and society, in       its report, has claimed that Aadhaar numbers with sensitive       personal financial information were publicly available on four       government portals built to oversee &lt;a href="http://www.oneindia.com/topic/welfare" title="Topic: welfare schemes"&gt;welfare schemes&lt;/a&gt;. The       report said that the government portals made it easy to access       sensitive details, despite it being &lt;a href="http://www.oneindia.com/topic/illegal" title="Topic: illegal"&gt;illegal&lt;/a&gt;.     "It is extremely irresponsible on the part of       the UIDAI [Unique Identification Authority of India], the sole       governing body for this massive project, to turn a blind eye to       the lack of standards prescribed for how other bodies shall deal       with such data, such cases of massive public disclosures of this       data, and the myriad ways in which it may be used for mischief,"       said Amber Sinha and Srinivas Kodali, the authors of the report.&lt;br /&gt; &lt;br /&gt; Apart from accessing a person's details, the portals made it         possible for anyone to get data on beneficiaries of welfare         schemes. In many cases, it included bank account numbers of         beneficiaries. The report suggests that close to 23 crore         Aadhaar number could have been leaked if most of the government         portals connected to direct benefit transfers used the 'same         negligent standards for storing data as the ones examined'.         "The document shows that the breaches are an indicator of         potentially irreversible privacy harm and the data could be used         for financial fraud," the authors said in the report. The report         was documented after authors studied the National Social         Assistance Programme, National Rural Employment Guarantee         Scheme, Andhra Pradesh government's Chandranna Bima Scheme and         Andhra Pradesh's Daily Online Payment Reports of NREGA.         &lt;br /&gt; &lt;br /&gt; The report said that sensitive personal identity information         such as Aadhaar number, caste, religion, address, photographs         and financial information were easily available with a few         clicks and suggested how poorly conceived these initiatives         were. The report highlights that it was illegal to make personal         data public and also refers to # #AadhaarLeaks, a campaign on         twitter aimed at exposing the loopholes in the Aadhaar system.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='http://editors.cis-india.org/internet-governance/news/one-india-may-2-2017-anusha-ravi-what-privacy-13-crore-aadhaar-numbers-accessible-on-governmental-portals'&gt;http://editors.cis-india.org/internet-governance/news/one-india-may-2-2017-anusha-ravi-what-privacy-13-crore-aadhaar-numbers-accessible-on-governmental-portals&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-03T14:39:46Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="http://editors.cis-india.org/internet-governance/news/manorama-may-2-2017-jikku-varghese-jacob-biggest-blast-on-aadhaar-leak-so-far-govt-sites-leaked-data-of-13-crore-people">
    <title>Biggest blast on Aadhaar leak so far: govt sites leaked data of 13 crore people</title>
    <link>http://editors.cis-india.org/internet-governance/news/manorama-may-2-2017-jikku-varghese-jacob-biggest-blast-on-aadhaar-leak-so-far-govt-sites-leaked-data-of-13-crore-people</link>
    <description>
        &lt;b&gt;In yet another shocking report of personal data breach in India, it has emerged that Aadhaar data of 13 crore people was put out on websites of four major government projects in the country. The leaked data include bank account details of over one crore people linked to Aadhar numbers under the direct benefit scheme. Over eight crore people lost their private data on the national job guarantee scheme website alone.&lt;/b&gt;
        &lt;p&gt;The article by Jikku Varghese Jacob was &lt;a href="http://english.manoramaonline.com/news/nation/2017/05/01/government-sites-leaked-aadhaar-data-of-13-crore-cis-report.html"&gt;published by Manorama&lt;/a&gt; on May 2, 2017.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;The shocking details have surfaced in a report released by the       Center for Internet Society (CIS) which deals with the publication       of Aadhaar data and their security. It appears to be the biggest       blast on Aadhaar data leak yet. The report says these pieces of       information were available on Internet since last November. Once       detected, the CIS officials had initiated steps to remove them.&lt;/p&gt;
&lt;p&gt;The CIS report cites two central government portals and websites       from Andhra Pradesh as violators. Following are the websites that       published the data:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;National Social Assistance Programme (under the Ministry of       Rural Development).&lt;/li&gt;
&lt;li&gt;The national portal of the job guarantee scheme.&lt;/li&gt;
&lt;li&gt;Daily online payment reports (Government of Andhra Pradesh)&lt;/li&gt;
&lt;li&gt;Chandranna Bheema project (Government of Andhra Pradesh)&lt;/li&gt;
&lt;/ol&gt;
&lt;p style="text-align: justify; "&gt;Private data of 1,59,42,083 people were leaked on the social       assistance scheme site. The two Andhra Pradesh sites breached the       privacy of three crore people.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Information leaked on most of the sites could be downloaded as       Excel sheet. It is estimated that data on 23 crore people is       linked to Aadhaar under the direct benefit scheme.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The CIS fears that if other government sites have also handled       such data without care there could have occurred a massive data       base breach. The CIS put in months of effort before finalizing       this report.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;It was recently found that Aadhaar data on 35 lakh people in       Kerala was found disclosed on the state's Sevana Pension website.       In Jharkhand, 14 lakh people had their privacy violated when their       Aadhaar information was put out on a government website.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Such leaks of Aadhaar data is a crime that can fetch up to three       years of imprisonment. Complaints have arisen that government       departments did not bother to comply with an IT ministry directive       last month to remove the Aadhaar data from websites.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Experts point out that criminals can misuse personal data on       Aadhaar and bank account. The data could be used to obtain SIM       cards and carry out transactions online.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Aadhaar, the world's largest bio-metric enrolment in India, will       enrol 1.2 billion people in a 12-digit unique number for each       person to be issued to each resident in the country. The number       with its biometric information – photograph, fingerprints and iris       scan – of each individual is easily verifiable in an online.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='http://editors.cis-india.org/internet-governance/news/manorama-may-2-2017-jikku-varghese-jacob-biggest-blast-on-aadhaar-leak-so-far-govt-sites-leaked-data-of-13-crore-people'&gt;http://editors.cis-india.org/internet-governance/news/manorama-may-2-2017-jikku-varghese-jacob-biggest-blast-on-aadhaar-leak-so-far-govt-sites-leaked-data-of-13-crore-people&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-03T14:35:23Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="http://editors.cis-india.org/accessibility/events/global-accessibility-awareness-day-2017">
    <title>Global Accessibility Awareness Day 2017</title>
    <link>http://editors.cis-india.org/accessibility/events/global-accessibility-awareness-day-2017</link>
    <description>
        &lt;b&gt;The Centre for Internet &amp; Society along with Prakat Solutions and Mitra Jyothi is co-hosting the Global Accessibility Awareness Day in Bengaluru on May 18, 2017. &lt;/b&gt;
        
&lt;p style="text-align: justify;"&gt;&lt;strong&gt;Global Accessibility Awareness Day &lt;/strong&gt;is celebrated  across the world on the 3rd Thursday in May every  						year to create an awareness in making technology accessible and  usable by persons with disabilities. While people may be interested in  the topic  						of making technology accessible and inclusive, the reality is that  they often do not know how or where to start,  Awareness comes first.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;The purpose of GAAD is to get everyone talking, thinking and learning about digital  						(web, software, mobile, etc.) access/inclusion and people with different disabilities.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;To mark this day, Prakat Solutions will be hosting an event  filled with lightning talks, 						workshops and a lot of other activities. You can also view a  series of short videos about why accessibility is important with  contributions 						from some of the greatest minds in accessibility today.For us as a  company, Global Accessibility Awareness Day is  						quite special. Other awareness days that we participate in focus  on a specific group of people.  						Today, is not about a specific group of people, today is about  each and every one of us.&lt;/p&gt;
&lt;h3 style="text-align: justify;"&gt;Watch the Video on What is GAAD&lt;/h3&gt;
&lt;p&gt;&lt;iframe src="https://www.youtube.com/embed/M9Ac5PAIKWo" frameborder="0" height="315" width="560"&gt;&lt;/iframe&gt;&lt;/p&gt;

        &lt;p&gt;
        For more details visit &lt;a href='http://editors.cis-india.org/accessibility/events/global-accessibility-awareness-day-2017'&gt;http://editors.cis-india.org/accessibility/events/global-accessibility-awareness-day-2017&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Featured</dc:subject>
    
    
        <dc:subject>Homepage</dc:subject>
    
    
        <dc:subject>Accessibility</dc:subject>
    
    
        <dc:subject>Event</dc:subject>
    

   <dc:date>2017-05-16T05:51:45Z</dc:date>
   <dc:type>Event</dc:type>
   </item>


    <item rdf:about="http://editors.cis-india.org/internet-governance/news/the-register-richard-chirgwin-may-3-2017-135-million-indian-government-payment-card-details-leaked">
    <title>135 MEELLION Indian government payment card details leaked</title>
    <link>http://editors.cis-india.org/internet-governance/news/the-register-richard-chirgwin-may-3-2017-135-million-indian-government-payment-card-details-leaked</link>
    <description>
        &lt;b&gt;Legislation coming to beef up Aadhaar card privacy, security.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by Richard Chirgwin was &lt;a class="external-link" href="https://www.theregister.co.uk/2017/05/03/135_million_aadhaar_indian_government_payment_card_details_leaked/"&gt;published in the Register &lt;/a&gt;on May 3, 2017.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;If you're enthused about governments operating large-scale online  identity projects, here's a cautionary tale: the Indian government's  eight-year-old Aadhaar payment card project has leaked a stunning 130 &lt;i&gt;million&lt;/i&gt; records.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Aadhaar's role in authenticating and authorising  transactions, and as the basis of the country's UID (unique  identification database) makes any breach a privacy nightmare.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;India's Centre for Internet and Society (CIS) made their estimate public in a &lt;a href="http://cis-india.org/internet-governance/information-security-practices-of-aadhaar-or-lack-thereof-a-documentation-of-public-availability-of-aadhaar-numbers-with-sensitive-personal-financial-information-1" target="_blank"&gt;report&lt;/a&gt; published on Monday.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;It's not that there was a breach related to Aahdaar  itself: rather, other government agencies were leaking Aadhaar and  related data they'd collected for their own purposes.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The research paper drilled down on four  government-operated projects: Andhra Pradesh's Mahatma Gandhi National  Rural Employment Scheme; the same state's workers' compensation scheme  known as Chandranna Bima; the National Social Assistance Program; and an  Andhra Pradesh portal of Daily “Online Payment Reports under NREGA”  maintained by the National Informatics Centre.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In total, the CIS says, the portals leaked 135 million Aadhaar card records linked to around 100 million bank account numbers.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Given India's enthusiasm to try and eliminate cash,  it's a big deal: the Aadhaar card funnels benefits to recipients' linked  bank accounts. As the report states: “To allow banking and payments  using Aadhaar, banks and government departments are seeding Aadhaar  numbers along with bank account details”.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The centre says the leaks represent significant and  “potentially irreversible privacy harm”, but worse they also open up a  fraud-ready source of personal information.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Online databases examined by the CIS included “numerous instances” of Aadhaar Numbers, associated with personal information.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The Indian government responded through Aruna  Sundararajan, secretary at the Union Electronics and Information  Technology Ministry, who announced amendments to the country's IT  legislation to beef up the system's privacy and security.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“Aadhaar has very strong privacy regulation built into it”, she &lt;a class="external-link" href="http://www.thehindu.com/news/national/new-it-rules-to-beef-up-aadhaar/article18357619.ece"&gt;told the Hindu&lt;/a&gt;, but it needs better enforcement.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Sundararajan said those issues will be addressed in the legislative amendments.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='http://editors.cis-india.org/internet-governance/news/the-register-richard-chirgwin-may-3-2017-135-million-indian-government-payment-card-details-leaked'&gt;http://editors.cis-india.org/internet-governance/news/the-register-richard-chirgwin-may-3-2017-135-million-indian-government-payment-card-details-leaked&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-20T11:51:14Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="http://editors.cis-india.org/internet-governance/news/hindu-krishnadas-rajagopal-may-3-2017-aadhaar-data-leaks-not-from-uidai">
    <title>Aadhaar data leaks not from UIDAI: Centre </title>
    <link>http://editors.cis-india.org/internet-governance/news/hindu-krishnadas-rajagopal-may-3-2017-aadhaar-data-leaks-not-from-uidai</link>
    <description>
        &lt;b&gt;Aadhaar is foolproof, it tells SC &lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by Krishnadas Rajagopal was &lt;a class="external-link" href="http://www.thehindu.com/news/national/aadhaar-data-leaks-not-from-uidai-centre/article18379074.ece"&gt;published in the Hindu &lt;/a&gt;on May 3, 2017.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;Leaks of Aadhaar card details are not from the UIDAI, but at the State level, the Union government told the Supreme Court on Wednesday.&lt;br /&gt;&lt;br /&gt;“As of today, Aadhaar is foolproof. Biometric technology is the best system in 2016. There has not been a single leak from the UIDAI. The leaks of details may have been from the States... their offices and agencies,” advocate Arghya Sengupta, counsel for the Centre, submitted in the court.&lt;br /&gt;&lt;br /&gt;The Centre’s clarification comes in the midst of reports that data of over 130 million Aadhaar cardholders have been leaked from four government websites.&lt;br /&gt;&lt;br /&gt;Reports, based on a study conducted by the Centre for Internet and Society (CIS), a Bengaluru-based organisation, said Aadhaar numbers, names and other personal details of people have been leaked.&lt;br /&gt;&lt;br /&gt;The Centre was washing its hands of the alleged leaks for the second consecutive day in the Supreme Court.&lt;br /&gt;&lt;b&gt;&lt;br /&gt;A-G’s assurance&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;On Tuesday, Attorney-General Mukul Rohatgi had emphatically assured the Supreme Court that biometrics of Aadhaar cardholders were safe and had not fallen into other hands. He said the biometric details were kept in a central database run by the Centre.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='http://editors.cis-india.org/internet-governance/news/hindu-krishnadas-rajagopal-may-3-2017-aadhaar-data-leaks-not-from-uidai'&gt;http://editors.cis-india.org/internet-governance/news/hindu-krishnadas-rajagopal-may-3-2017-aadhaar-data-leaks-not-from-uidai&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>UID</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>UIDAI</dc:subject>
    
    
        <dc:subject>Aadhaar</dc:subject>
    

   <dc:date>2017-05-20T08:27:28Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="http://editors.cis-india.org/internet-governance/news/medianama-nikhil-pahwa-may-4-2017-around-130-135-m-aadhaar-numbers-published-on-four-sites-alone">
    <title>Around 130-135M Aadhaar Numbers published on 4 sites alone</title>
    <link>http://editors.cis-india.org/internet-governance/news/medianama-nikhil-pahwa-may-4-2017-around-130-135-m-aadhaar-numbers-published-on-four-sites-alone</link>
    <description>
        &lt;b&gt;“Therefore, there is no data leak, there is no systematic problem, but, if any one tries to be smart, the law ignites into action.” – Ravi Shankar Prasad, IT Minister, in the Rajya Sabha, on 10th April 2017.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The blog post by Nikhil Pahwa was &lt;a class="external-link" href="http://www.medianama.com/2017/05/223-aadhaar-numbers-data-leak/"&gt;published by Medianama&lt;/a&gt; on May 4, 2017.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;Details of around 130-135 million Aadhaar Numbers, and around 100  million bank numbers have been leaked online by just four government  schemes alone: the National Social Assistance Programme, the National  Rural Employment Guarantee Scheme (NREGA), Daily Online Payments Reports  under NREGA (Govt of Andhra Pradesh), and the Chandranna Bima Scheme  (Govt of Andhra Pradesh), as per a research report from the Centre for  Internet and Society.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Download the report &lt;a href="http://cis-india.org/internet-governance/information-security-practices-of-aadhaar-or-lack-thereof-a-documentation-of-public-availability-of-aadhaar-numbers-with-sensitive-personal-financial-information/at_download/file" rel="noopener noreferrer"&gt;here&lt;/a&gt;.&lt;/b&gt; Read full story on &lt;a class="external-link" href="http://www.medianama.com/2017/05/223-aadhaar-numbers-data-leak/"&gt;Medianama website&lt;/a&gt;.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='http://editors.cis-india.org/internet-governance/news/medianama-nikhil-pahwa-may-4-2017-around-130-135-m-aadhaar-numbers-published-on-four-sites-alone'&gt;http://editors.cis-india.org/internet-governance/news/medianama-nikhil-pahwa-may-4-2017-around-130-135-m-aadhaar-numbers-published-on-four-sites-alone&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-20T10:52:26Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="http://editors.cis-india.org/internet-governance/news/dna-may-2-2017-report-aadhaar-numbers-of-135-mn-may-have-leaked-claims-cis-report">
    <title>Aadhaar numbers of 135 mn may have leaked, claims CIS report</title>
    <link>http://editors.cis-india.org/internet-governance/news/dna-may-2-2017-report-aadhaar-numbers-of-135-mn-may-have-leaked-claims-cis-report</link>
    <description>
        &lt;b&gt;Aadhaar numbers and personal information of as many as 135 million Indians could have been leaked from four government portals due to lack of IT security practices, the Centre for Internet and Society has claimed. &lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article was published by &lt;a class="external-link" href="http://www.dnaindia.com/india/report-aadhaar-numbers-of-135-mn-may-have-leaked-claims-cis-report-2425384"&gt;DNA&lt;/a&gt; on May 2, 2017.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;"Based on the numbers available on the websites looked at, estimated  number of Aadhaar numbers leaked through these four portals could be  around 130-135 million," the report by CIS said.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Further, as many as 100 million bank account numbers could have been "leaked" from the four portals, it added.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The portals where the purported leaks happened were those of  National Social Assistance Programme, National Rural Employment  Guarantee Scheme, as well as two websites of the Andhra Pradesh  government.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;"Over 23 crore beneficiaries have been brought under Aadhaar  programme for DBT (Direct Benefit Transfer), and if a significant number  of schemes have mishandled data in a similar way, we could be looking  at a data leak closer to that number," it cautioned.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The disclosure came as part of a CIS report titled 'Information  Security Practices of Aadhaar (or lack thereof): A Documentation of  Public Availability of Aadhaar Numbers with Sensitive Personal Financial  Information'.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;When contaced, a senior official of the Unique Identification  Authority of India (UIDAI) said that there was no breach in its own  database. The UIDAI issues Aadhaar to citizens.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The CIS report claimed that the absence of "proper controls" in  populating the databases could have disastrous results as it may divulge  sensitive information about individuals, including details about  address, photographs and financial data.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;"The lack of consistency of data masking and de- identification  standard is an issue of great concern...the masking of Aadhaar numbers  does not follow a consistent pattern," the report added.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='http://editors.cis-india.org/internet-governance/news/dna-may-2-2017-report-aadhaar-numbers-of-135-mn-may-have-leaked-claims-cis-report'&gt;http://editors.cis-india.org/internet-governance/news/dna-may-2-2017-report-aadhaar-numbers-of-135-mn-may-have-leaked-claims-cis-report&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-20T11:10:37Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="http://editors.cis-india.org/internet-governance/news/amar-bazar-patrika-may-2-2017-13-crore-aadhaar-leaked-due-to-poor-security-in-4-govt-websites">
    <title>১৩ কোটি আধার তথ্য ফাঁস চার সরকারি পোর্টাল থেকে! বিস্ফোরক দাবি রিপোর্টে </title>
    <link>http://editors.cis-india.org/internet-governance/news/amar-bazar-patrika-may-2-2017-13-crore-aadhaar-leaked-due-to-poor-security-in-4-govt-websites</link>
    <description>
        &lt;b&gt;খোদ সরকারি পোর্টাল থেকে কয়েক কোটি আধার নম্বর ও যাবতীয় তথ্য ‘ফাঁস’!&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;This was published by &lt;a class="external-link" href="http://abpananda.abplive.in/india-news/13-crore-aadhaar-leaked-due-to-poor-security-in-4-govt-websites-334778"&gt;Amar Bazar Patrika&lt;/a&gt; on May 2, 2017.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;অভিযোগ, গত কয়েক মাসে প্রায় ১৩ কোটি আধার  নম্বরের যাবতীয় ব্যক্তিগত ও সংবেদনশীল তথ্য ফাঁস হওয়ার ঘটনা ঘটেছে। আর এসবই  হয়েছে চারটি সরকারি পোর্টাল থেকে তথ্যপ্রযুক্তি সুরক্ষার ঘাটতির জেরে! যা  ঘিরে এখন তোলপাড় দেশ।&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;সম্প্রতি, এমনই বিস্ফোরক রিপোর্ট প্রকাশ  করেছে অলাভদায়ক সংগঠন সেন্টার ফর ইন্টারনেট অ্যান্ড সোসাইটি (সিআইএস)।  তাদের আশঙ্কা, চারটি সরকারি পোর্টালের মাধ্যমে ১০ কোটি মানুষের ব্যাঙ্ক  অ্যাকাউন্ট নম্বরও ফাঁস হয়ে থাকতে পারে।&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;সংস্থার দাবি, যে চারটি পোর্টাল থেকে এই  সব তথ্য ফাঁসের অভিযোগ, তার মধ্যে দু’টি অন্ধ্রপ্রদেশ সরকারের ওয়েবসাইট।  বাকি দুটি পোর্টাল হল ন্যাশনাল সোশ্যাল অ্যাসিস্ট্যান্স প্রোগ্রাম এবং  ন্যাশনাল রুরাল এমপ্লয়মেন্ট গ্যারান্টি স্কিম-এর।&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;এই গোটা ঘটনার জন্য ইউনিক আইডেন্টিফিকেশন  অথরিটি অফ ইন্ডিয়া বা ইউআইডিএআই–কেই দায়ী করেছে সিআইএস। তাদের দাবি, আধার  নিয়ন্ত্রক সংস্থার ‘দায়িত্বজ্ঞানহীনতার’ জন্যই এই উদ্ভুত পরিস্থিত সৃষ্টি  হয়েছে।&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;সিএনআই-এর আরও দাবি, বিভিন্ন সরকারি ও  বেসরকারি পোর্টাল—যারা আধার তথ্য ব্যবহার করে থাকে, তাদের নিজস্ব  সুরক্ষা-ব্যবস্থা খতিয়ে দেখেনি ইউআইডিএআই। ফলত, এই বিপত্তির সম্মুখীন কয়েক  কোটি মানুষ।&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;যদিও, ইউআইডিএআই -এর দাবি, তাদের ডেটাবেস থেকে কোনও তথ্য ফাঁস হয়নি।&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='http://editors.cis-india.org/internet-governance/news/amar-bazar-patrika-may-2-2017-13-crore-aadhaar-leaked-due-to-poor-security-in-4-govt-websites'&gt;http://editors.cis-india.org/internet-governance/news/amar-bazar-patrika-may-2-2017-13-crore-aadhaar-leaked-due-to-poor-security-in-4-govt-websites&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-20T11:45:42Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="http://editors.cis-india.org/internet-governance/news/newslaundry-shruti-menon-may-2-2017-uidai-remains-silent-on-aadhaar-leaks-of-users-through-govt-portals">
    <title>UIDAI remains silent on #Aadhaarleaks of 13 crore users through government portals</title>
    <link>http://editors.cis-india.org/internet-governance/news/newslaundry-shruti-menon-may-2-2017-uidai-remains-silent-on-aadhaar-leaks-of-users-through-govt-portals</link>
    <description>
        &lt;b&gt;As the arguments for making Aadhaar mandatory go on, is there any way to stem the leaks and identify who exactly has all this information.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The blog post by Shruti Menon was &lt;a class="external-link" href="https://www.newslaundry.com/2017/05/02/uidai-remains-silent-on-aadhaarleaks-of-13-crore-users-through-government-portals"&gt;published by Newslaundry&lt;/a&gt; on May 2, 2017&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;The verdict on linking Aadhaar with Permanent Account Number (PAN) and  making it mandatory for filing income tax returns (ITRs) will be out  soon. Attorney General Mukul Rohatgi had a tough challenge ahead of him  in the Supreme Court as the state presented its argument today. Rohatgi  defended the &lt;a href="http://www.livemint.com/Politics/3FcQ9lHm7TWX5B0Hn7ZXiO/Aadhaar-to-be-mandatory-for-income-tax-returns-getting-PAN.html" target="_blank"&gt;amendment in income tax law&lt;/a&gt; allowing this after senior lawyer Shyam Divan made a &lt;a href="http://www.livemint.com/Politics/sN0S5mYYx641tgrctGf03H/Shyam-Divan-concludes-arguments-in-Aadhaar-case-in-Supreme-C.html" target="_blank"&gt;strong case&lt;/a&gt; against  it on April 26 and 27. Divan became a hero to many overnight after he  presented compelling arguments against the amendment citing facets of  right to privacy - informational self-determination, personal autonomy,  and bodily integrity - as he did so. Though the court has &lt;a href="https://www.thequint.com/opinion/2017/05/01/aadhaar-case-privacy-and-bodily-integrity" target="_blank"&gt;refused to entertain&lt;/a&gt; arguments pertaining to privacy, he managed to argue these concerns without couching them under right to privacy laws.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Advocate Gautam Bhatia posted &lt;a href="https://barandbench.com/aadhar-hearing-number-tagging-nazi-concentration-camps/" target="_blank"&gt;minute-by-minute developments from the courtroom&lt;/a&gt;, and soon, #ThankYouMrDivan became one of the top trends on Twitter.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;A day before the state presented its arguments, the Centre for Internet and Society (CIS) published a &lt;a href="http://cis-india.org/internet-governance/information-security-practices-of-aadhaar-or-lack-thereof-a-documentation-of-public-availability-of-aadhaar-numbers-with-sensitive-personal-financial-information-1" target="_blank"&gt;report &lt;/a&gt;titled  “Information, Security Practices of Aadhaar (or lack thereof): A  documentation of public availability of Aadhaar numbers with sensitive  personal financial information” late on Monday. Authored by Amber Sinha  and Srinivas Kodali, the report documents the leaks of over 13 crore  Aadhaar numbers and resulting information of beneficiaries through four  government portals-two at the centre and two at the state. “We are  primarily talking of lack of standards and data fact-checking, storage  and how all of this information- account numbers, phone numbers plus,  Aadhaar numbers- in public domain increases the nature of risk of the  backbone of digital payments,” Kodali told &lt;i&gt;Newslaundry. &lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The four portals studied by the two are National Social Assistance  Programme (NSAP), National Rural Employment Guarantee Act (NREGA) and  two databases of Andhra Pradesh- NREGA and their scheme called Chandranna Bima.  The report claims that the aforementioned public portals compromised  personally identifiable information (PII) including “Aadhaar numbers and  financial details such as bank account numbers” of 13 crore people due  to a lack of security controls.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“While the details were masked for public view, someone with login  access could get the details,” the report read. “When one of the url  query parameters of the website showing the masked personal details was  modified from ‘nologin’ to ‘login’, that is, control access to login  based pages were allowed providing unmasked details without the need for  a password.” What this essentially means is that these portals allow  people to explore lists organised by states, districts, area,  sub-district, and municipalities which contain the personal information  of the people who are enrolled into the schemes.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The report also  cites legal framework under the Aadhaar Act that allows the government  or private entities to store Aadhaar numbers on the grounds that they  won’t be used for purposes other than those listed in the act. CIS’s  study, however, reveals that information pertaining to religion, caste,  race, tribe or even income is sometimes collected and published on such  portals with little in the way of security checks.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Speaking to &lt;i&gt;Newslaundry,&lt;/i&gt; Anupam Saraph, professor and former governance and IT advisor to Goa’s  Chief Minister, Manohar Parrikar, said that the data exposed could be  significantly more than what the report shows. “Many more Aadhaar  numbers have been exposed on websites relating to Pension Schemes, PDS,  Ministry of Water and Sanitation, Ministry of Human Resource  Development, Scholarships, Schools, Colleges, Universities, Kendriya  Sainik board, PM Avas Yojana to name a few,” he said. “Besides this  Registrars to the UIDAI (State Governments and various ministries of the  Central government, some Public Sector undertakings) were allowed to  retain the Aadhaar number, demographic and biometric data (associated  with the Aadhaar number). While this may not be exposed on websites, it  is unsecured and possibly accessible to data brokers within and outside  government,” said Saraph who has designed delivery channels and ID  schemes for better governance.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;What’s worth noting is that the  people whose data has been breached are unaware that their information  is available on public platforms and vulnerable to data theft. “It is  UIDAI’s [Unique Identification Authority of India] job to investigate  and inform them,” Kodali told &lt;i&gt;Newslaundry. “&lt;/i&gt;At some point of time, everybody is going to have everybody’s information,” he added.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Currently, the government has an &lt;a href="https://data.gov.in/" target="_blank"&gt;open data portal&lt;/a&gt;. It  describes itself as a platform “intended to be used by Government  Ministries/Departments and their organisation to publish datasets,  documents, services, tools and applications collected by them for public  use”.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;So is it feasible to have open data portals for  transparency and accountability? “Having certain government data being  publicly accessible is certainly desirable.” Saraph continued that the  problem was, data on public expenditure should ideally be openly  accessible but it’s also where the most leakage occurs. “Making Aadhaar  mandatory is meaningless,” he said, as India does not have a policy on  open data portals yet, which can subject Aadhaar data to “misuse”.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Given  that the UIDAI is responsible for investigating and making people aware  of any data breach or theft, they have remained silent for an oddly  long time. It is unclear whether the UIDAI is itself aware of who has  accessed the data that is insecurely published on these government  portals. “They’re letting everybody collect this information but they  were not aware themselves that who had access to this information,  that’s the main problem,” Kodali said. While the Aadhaar ecosystem was  to ensure social inclusion and transparency, in its current form, the  system looks so opaque that the people who are running it may not be  aware themselves of what is going on.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;What does it mean to have access to someone else’s Aadhaar?&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;With  an increasing number of social welfare schemes being linked to Aadhaar,  it was touted as an attempt to remove the middlemen, frauds and  corruption with the government. According to the report, "A cumulative  amount of Rs 1,78,694.75 has been transferred using DBT for 138 schemes  under 27 ministries since 2013. Various financial frameworks like  Aadhaar Payments Bridge (APB) and Aadhaar Enabled Payment Systems (AePS)  have been built by National Payment Corporation of India to support DBT  and also to allow individuals use Aadhaar for payments."&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Given  that such systems are in place to ensure easier and accessible banking,  research shows that the Aadhaar seeding process led to government  portals putting personal information of so many people under various  schemes in the "absence of information security practices to handle so  much PII", as per the research. This is not only a breach of privacy but  also makes a person vulnerable to financial fraud in cases where their  bank details are public. "One of the prime examples is individuals  receiving phone calls from someone claiming to be from the bank. Aadhaar  data makes this process much easier for fraud and increases the risk  around transactions," the report reads.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;UIDAI on silent mode&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Unfortunately,  UIDAI has not addressed this concern, let alone acknowledge it. It has  been cracking down on people by filing first information reports (FIRs)  against those tracking and exposing the vulnerabilities of the Aadhaar  system. Recently, UIDAI’s Chief Executive Officer (CEO), ABP Pandey was  accused of blocking twitter handles of prominent security researchers  and analysts who have been extensively reporting about vulnerabilities  in the Aadhaar system.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;One of the handles was blocked was Saraph’s. “I do not know why they  blocked me. I have been vocal about the problems associated with the UID  and its use,” he said&lt;i&gt;. &lt;/i&gt;He added that he served several &lt;a href="http://www.moneylife.in/article/resisting-violations-of-the-supreme-court-orders-on-aadhaar/49121.html," target="_blank"&gt;notices&lt;/a&gt; of  contempt of court to the CEO of UIDAI and has been questioning the  verification and audit of UID database. “Perhaps [he] was annoyed with  my efforts to make them accountable and responsible,” he said.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;On  April 18, however, in a response to Right to Information (RTI) query  filed by Sushil Kambampati, UIDAI denied having blocked any twitter  handles. Almost immediately, it was called out on twitter for ‘lying’ in  the RTI response as many users claimed it had.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Saraph declared that such a move, the blocking of users asking  questions, was indicative of UIDAI’s cluelessness. Apar Gupta, a  Delhi-based lawyer working on cyber security, had told &lt;i&gt;Newslaundry &lt;/i&gt;that  it was unethical and unconstitutional of government bodies (such as the  UIDAI) to block people. He reiterated that in one of his tweets  recently.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Today, however, the Pandey’s individual twitter profile no longer  exists. It has now been changed to “ceo_office”. CIS’s report states  that the UIDAI has been pushing for more databases to get in sync with  Aadhaar, but with little or no accountability. “While the UIDAI has been  involved in proactively pushing for other databases to get seeded with  Aadhaar numbers, they take a little responsibility in ensuring the  security and privacy of such data,” the report reads. Kodali, however,  told &lt;i&gt;Newslaundry &lt;/i&gt;that the report was not aimed at questioning the  security of such seeding. “We’re not saying it is not really secure but  we’re just saying it increases the risk factors,” he said.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;UIDAI has also not responded to several queries filed by vulnerability testers.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;i&gt;Newslaundry &lt;/i&gt;reached out to the UIDAI with the following questions:&lt;/p&gt;
&lt;ol style="text-align: justify; "&gt;
&lt;p&gt; &lt;/p&gt;
&lt;li&gt;&lt;i&gt; According to the report published, four government portals have  personally identifiable information of about 13 crore people including  their Aadhaar numbers and bank account details. What is being done about  this?&lt;/i&gt;&lt;/li&gt;
&lt;p&gt; &lt;/p&gt;
&lt;li&gt;&lt;i&gt; If a person's privacy has been breached, what are the steps UIDAI would take for redressal?&lt;/i&gt;&lt;/li&gt;
&lt;p&gt; &lt;/p&gt;
&lt;li&gt;&lt;i&gt; Is UIDAI investigating the 13 crore Aadhaar leaks?&lt;/i&gt;&lt;/li&gt;
&lt;p&gt; &lt;/p&gt;
&lt;li&gt;&lt;i&gt; The report states "When one of the url query parameters of website  showing the masked personal details was modified from “nologin” to  “login”, that is control access to login based pages were allowed  providing unmasked details without the need for a password." Is this  true, and if so, what is your statement?&lt;/i&gt;&lt;/li&gt;
&lt;p&gt; &lt;/p&gt;
&lt;li&gt;&lt;i&gt; How do you ensure data security on open data portals?&lt;/i&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p style="text-align: justify; "&gt;This piece will be updated if and when they respond.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;While  UIDAI remains silent, A-G Rohatgi argued today that close to 10 lakh  PAN cards were found to be fake. "Are they propagating a general public  interest or propagating the fraud (fake PANs) which is going in," he  said at the court today while suggesting that Aadhaar was the only way  of preventing fake or duplicate cards.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Senior advocate Arvind  Datar, who is also appearing for one of the three petitioners in the  case said that the government could not take away his right to chose  whether or nor to have an Aadhaar. "The Supreme Court had directed them  that they cannot make it mandatory. The mandate of the Supreme Court can  not be undone. My right of not to have an Aadhaar can not be taken away  indirectly."&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Though there are problems with the Aadhaar system  and apparently very little redressal at the citizen’s end, Aadhaar is  here to stay. As Divan and Rohatgi argue the constitutionality of making  Aadhaar mandatory at the Supreme Court, the pertinent question that  only the UIDAI can answer is whether they are technologically capable of  keeping data secure given how aggressively Aadhaar linkage is being  promoted.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;However, Rohatgi's argument in court today, according to  a Business Standard report was that the government cannot destroy the  Aadhaar cards of people even after their death. Instead of being  reassuring, this only seems to increase the possibilities for identity  theft, as if there is little in the way of redressal mechanisms in life,  what choices do the dead have?&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;The author can be contacted on Twitter &lt;a href="https://twitter.com/shrutimenon10" target="_blank"&gt;@shrutimenon10&lt;/a&gt;.&lt;/b&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='http://editors.cis-india.org/internet-governance/news/newslaundry-shruti-menon-may-2-2017-uidai-remains-silent-on-aadhaar-leaks-of-users-through-govt-portals'&gt;http://editors.cis-india.org/internet-governance/news/newslaundry-shruti-menon-may-2-2017-uidai-remains-silent-on-aadhaar-leaks-of-users-through-govt-portals&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-20T11:06:16Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="http://editors.cis-india.org/internet-governance/news/hindustan-times-may-2-2017-details-of-135-million-aadhaar-card-holders-may-have-leaked-claims-cis-report">
    <title>Details of 135 million Aadhaar card holders may have leaked, claims CIS report</title>
    <link>http://editors.cis-india.org/internet-governance/news/hindustan-times-may-2-2017-details-of-135-million-aadhaar-card-holders-may-have-leaked-claims-cis-report</link>
    <description>
        &lt;b&gt;The disclosure came as part of a CIS report titled ‘Information Security Practices of Aadhaar (or lack thereof): A Documentation of Public Availability of Aadhaar Numbers with Sensitive Personal Financial Information’.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The news from the Press Trust of India was published in the &lt;a class="external-link" href="http://www.hindustantimes.com/india-news/details-of-135-million-aadhaar-card-holders-may-have-leaked-claims-cis-report/story-39nojShtnAmr3EruCKbdrL.html"&gt;Hindustan Times&lt;/a&gt; on May 2, 2017.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;Aadhaar numbers and personal information of as many as 135 million Indians could have been leaked from four government portals due to lack of IT security practices, the Centre for Internet and Society has claimed.&lt;br /&gt;&lt;br /&gt;“Based on the numbers available on the websites looked at, estimated number of Aadhaar numbers leaked through these four portals could be around 130-135 million,” the report by CIS said.&lt;br /&gt;&lt;br /&gt;Further, as many as 100 million bank account numbers could have been “leaked” from the four portals, it added.&lt;br /&gt;&lt;br /&gt;The portals where the purported leaks happened were those of National Social Assistance Programme, National Rural Employment Guarantee Scheme, as well as two websites of the Andhra Pradesh government.&lt;br /&gt;&lt;br /&gt;“Over 23 crore beneficiaries have been brought under Aadhaar programme for DBT (Direct Benefit Transfer), and if a significant number of schemes have mishandled data in a similar way, we could be looking at a data leak closer to that number,” it cautioned.&lt;br /&gt;&lt;br /&gt;The disclosure came as part of a CIS report titled ‘Information Security Practices of Aadhaar (or lack thereof): A Documentation of Public Availability of Aadhaar Numbers with Sensitive Personal Financial Information’.&lt;br /&gt;&lt;br /&gt;When contaced, a senior official of the Unique Identification Authority of India (UIDAI) said that there was no breach in its own database. The UIDAI issues Aadhaar to citizens.&lt;br /&gt;&lt;br /&gt;The CIS report claimed that the absence of “proper controls” in populating the databases could have disastrous results as it may divulge sensitive information about individuals, including details about address, photographs and financial data.&lt;br /&gt;&lt;br /&gt;“The lack of consistency of data masking and de- identification standard is an issue of great concern...the masking of Aadhaar numbers does not follow a consistent pattern,” the report added.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='http://editors.cis-india.org/internet-governance/news/hindustan-times-may-2-2017-details-of-135-million-aadhaar-card-holders-may-have-leaked-claims-cis-report'&gt;http://editors.cis-india.org/internet-governance/news/hindustan-times-may-2-2017-details-of-135-million-aadhaar-card-holders-may-have-leaked-claims-cis-report&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-20T08:42:57Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>




</rdf:RDF>
