Hindustan Times (Amritsar)

Engineer developed app from database

- Vikram Gopal letters@hindustant­imes.com

BENGALURU: Police are investigat­ing how a Bengaluru-based engineer gained access to the Aadhaar database to develop an Android applicatio­n that seemed to be able to pull out confidenti­al details using the 12-digit unique identity numbers.

Activists have criticised the A ad ha ar programme for impinging on privacy, and a number of cases where government websites leaked people’s 12-digit ID numbers have mounted worries that flaws in the system could make it vulnerable to abuse and crimes like identity theft.

The engineer, Abhinav Srivastava, has been accused illegally accessing the Aadhaar database and sources say that the way he did it could involve either the collusion of others who had access or a hack.

Srivastava has been booked under sections of Aadhaar Act that outlaws access and distributi­on of Aadhaar data, and sections of Informatio­n Technology Act that deal with hacking.

The USP of his applicatio­n — named A ad ha ar KY C, which was taken down from Google’s Play Store—was to provide KYC verificati­on using Aadhaar data.

An official of the UIDAI at the headquarte­rs in Delhi denied its servers could have been hacked, and suggested the informatio­n may have been leaked from National Informatic­s Centre, or any of the agencies authorised to provide KYC services.

“The UIDAI database is very secure,” the official said. “This seems to have happened at the level of the Authentica­tion User Agency (AUA) or e-KYC User Agency (KUA).”

“The matter is now with police and let us wait for the investigat­ion to be completed,” the official added. Staff at the regional UIDAI office in Bengaluru, which also houses the technical centre where data from across the country is stored, said this was the first such case in the city.

Srivastava headed Qarth Technologi­es, which built a mobile payments app called X-Pay acquired by Ola in March 2016. Sources said the app Aadhaar KYC was developed in his personal capacity.

A statement issued by Ola said: “Ola has neither commission­ed nor is involved in any such activity. No such complaint has been brought to our notice.” Bengaluru Police commission­er Praveen Sood said two people had been identified, and no arrests had been made till Thursday evening.

THE USP OF HIS APPLICATIO­N — NAMED AADHAAR KYC, WHICH WAS TAKEN DOWN FROM GOOGLE’S PLAY STORE —WAS TO PROVIDE KYC VERIFICATI­ON USING AADHAAR DATA

Newspapers in English

Newspapers from India