Aadhaar Can't Be Hacked, Vested Interests Spreading Lies: UIDAI

Advertisement
By Indo-Asian News Service | Updated: 12 September 2018 09:55 IST
Highlights
  • Such reports are "completely incorrect and irresponsible", said UIDAI
  • "Vested interests deliberately trying to create confusion among people"
  • Any person can generate Aadhaar ID using the patch for Rs. 2,500: report

The Unique Identification Authority of India (UIDAI) on Tuesday dismissed reports of hacking of Aadhaar enrolment software as "completely incorrect and irresponsible" and said some vested interests were deliberately trying to create confusion among people.

The denial came after an investigation by HuffPost India revealed that the Aadhaar database, which contains the biometrics and personal information of over one billion Indians, "had been compromised by a software patch which disables critical security features of the software used to enrol new Aadhaar users".

Advertisement

According to the report, any unauthorised person from anywhere in the world can generate Aadhaar ID using the patch which is freely available for Rs. 2,500.

The UIDAI said the claims about Aadhaar being vulnerable to tampering lacked substance and were totally baseless.

Advertisement

"Certain vested interests are deliberately trying to create confusion in the minds of people which is completely unwarranted," a statement issued by the organisation said.

It added that the UIDAI matches all the biometric (10 fingerprints and both iris) of a resident enrolling for Aadhaar with the biometrics of all Aadhaar holders before issuing the unique ID.

Advertisement

"UIDAI has taken all necessary safeguard measures spanning from providing standardized software that encrypts entire data even before saving to any disk, protecting data using tamper proofing, identifying every one of the operators in every enrolment, identifying every one of thousands of machines using a unique machine registration process, which ensures every encrypted packet is tracked," the statement said.

It said all measures to ensure end-to-end security of resident data were taken including full encryption of resident data at the time of capture, tamper resistance, physical security, access control, network security, stringent audit mechanism, 24x7 security and fraud management system monitoring.

Advertisement

Earlier, a report by the HuffPost said a software patch available for as little as Rs 2,500 lets a user bypass critical security features such as biometric authentication of enrolment operators to generate unauthorised Aadhaar numbers. It said the patch also disables the GPS security feature of the software allowing anyone from any location to enrol users.

UIDAI clarified that no operator can make or update Aadhaar unless resident himself gives his biometric.

"Any enrolment or update request is processed only after biometrics of the operator is authenticated and resident's biometrics is de-duplicated at the backend of UIDAI system," it said.

It added that as part of its "stringent" enrolment and updation process, UIDAI checks enrolment operator's biometric and other parameters before processing the enrolment or updates and only after all checks are found to be successful, enrolment or update of resident is further processed.

"Therefore it is not possible to introduce ghost entries into Aadhaar database."

UIDAI said that even in a hypothetical situation where a ghost enrolment or update packet is sent to the UIDAI by some "manipulative attempt", the same is identified by the robust back-end system and all such enrolment packets get rejected and no Aadhaar is generated.

"Also, the concerned enrolment machines and the operators are identified, blocked and blacklisted permanently from the UIDAI system. In appropriate cases, police complaints are also filed for such fraudulent attempts," it said.

UIDAI said that the reported claim of "anybody is able to create an entry into Aadhaar database, then the person can create multiple Aadhaar cards" is completely false.

"If an operator is found violating UIDAI's strict enrolment and update processes or if one indulges in any type of fraudulent or corrupt practices, UIDAI blocks and blacklists them and imposes financial penalty upto Rs. 1 lakh per instance. It is because of this stringent and robust system that as on date more than 50,000 operators have been blacklisted," UIDAI added.

It said that it keeps adding new security features in its system as required from time-to-time to thwart new security threats by unscrupulous elements.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: UIDAI, Aadhaar
Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo Find X10 Pro Max Among First Phones to Launch With 2nm Dimensity 9600 Pro
  2. Redmi Note 17 Pro Series With Up to 10,000mAh Battery Debuts in India
  3. Vivo V80 India Launch Officially Confirmed, Design Teased
  1. Ethereum Wallet Exploit Drains $7.8 Million in rsETH Tokens, Security Firms Warn
  2. Vivo Buds Clip Launch Date Confirmed for September 21, Colour Options Revealed
  3. Oppo Find X10 Pro Max to Be Among First Phones With MediaTek's 2nm Dimensity 9600 Pro Chip
  4. Delta Exchange Lands Global Sponsor Slot for India-Afghanistan T20I Series
  5. Apple iCloud+ Plans in India Now Include Apple TV and Arcade at No Extra Cost
  6. Googlebook Laptops to Open for Pre-Orders on September 21, Google Confirms
  7. CoinEx Set to Close Exchange After Almost Nine Years in Operation
  8. iQOO 16 Launch Date Confirmed for September 29 in China, Three Colours Revealed
  9. Mac Mini M6 Geekbench Listing Reportedly Reveals Performance Gains Over M5 Chip
  10. Vivo V80, S2 FE Reportedly Get BIS Certification Hinting at Imminent India Launch; X500 Pro Max Appears on NBTC
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.