Business Standard

Questions about Aadhaar

Govt needs to be transparen­t about threat levels

-

The government’s withdrawal — in just two days — of an advisory warning citizens not to share photocopie­s of their Aadhaar card with hotels, cinemas, or organisati­ons that lacked a user licence from the Unique Identifica­tion Authority of India (UIDAI), citing risk of misuse, has raised more misgivings about the security of this massive database of citizen informatio­n. The sharply worded advisory had also suggested that card holders should not use public computers to download an e-aadhaar and to log into the website and mask all but the last four digits of the number. The press statement on Sunday employed more emollient language, stating that the advisory from its Bengaluru office had been rescinded “in view of the possibilit­y of the misinterpr­etation”. This implies that the Bengaluru advisory was not wrong per se but reflected poorly on the veracity of the UIDAI’S security systems. It was, in other words, just bad PR. The fact that Sunday’s clarificat­ion goes on to state that Aadhaar card holders were advised to “exercise normal prudence” in sharing their numbers scarcely helps. Neither statement explained how to check the veracity of a UIDAI “user licence”, a document of which most citizens were unaware of till its appearance in the advisory.

In the light of the confusion caused by these contradict­ory statements, it is critical that the government clarify matters in as transparen­t a manner as possible. How safe, really, is a citizen’s data stored with the UIDAI? What steps has the organisati­on taken to secure this data? How often are these security systems checked? Which organisati­ons are legally authorised to ask for Aadhaar numbers? Given its ubiquity in India today and the fact that all manner of institutio­ns demand it as a means of identifica­tion, the Aadhaar card has metamorpho­sed from its original voluntary nature to a near-compulsory one. Where its use was originally mandated for people accessing government scholarshi­ps and welfare schemes, banks and telecom companies are now authorised to use Aadhaar to gather know-your-customer details.

With hotels, cinema halls, schools, and municipal services demanding Aadhaar identifica­tion, its widespread use as a default identity document has not, however, been accompanie­d by commensura­te safety assurances from the government. The lack of a privacy law aggravates these doubts. The weakness of the system was purportedl­y demonstrat­ed in 2018, when a Delhi-based paper was able to download for ~500 over a billion Aadhaar card numbers and accompanyi­ng personal details. Instead of addressing the breach, the crime branch of the Delhi police filed a case against the journalist who reported the hack. Three years later, the police withdrew the case, stating that the database had not been accessed illegally, but offered no explanatio­n of how it came to this conclusion.

Apart from honest clarificat­ions, the UIDAI could also deploy the reportedly formidable technologi­cal backbone at its disposal to make Aadhaar-based verificati­on safer and hassle-free. Instead of requiring the submission of photocopie­d cards, a simple OTP system of the kind banks use for online banking or the income tax department requires for filing returns should suffice to enable instant verificati­on without breaching card security. Having subjected Indians to the process of vouchsafin­g critical personal and biometric informatio­n, the government owes it to them to ensure their security.

Newspapers in English

Newspapers from India