DigiLocker Flaw Put Over 3.8 Crore Accounts at Risk: Researcher

The DigiLocker team has now fixed the issue.

Advertisement
By Jagmeet Singh | Updated: 3 June 2020 10:07 IST
Highlights
  • DigiLocker was found to have a flaw in its authentication mechanism
  • It allowed anyone to gain access to user accounts
  • DigiLocker team was told about the vulnerability last month

DigiLocker has over 3.84 crore registered users

DigiLocker, an online service from the government that allows individuals to store documents digitally, was found to have an authentication flaw, putting the data of crores of users at risk. The issue was first discovered by a researcher last month and existed in the sign-in process of the service. This could have allowed bad actors to bypass the two-factor authentication and access sensitive personal information. The flaw has now been fixed. Notably, the online facility by the government has over 3.84 crore users.

A security researcher, Ashish Gahlot, discovered the vulnerability in the DigiLocker system while analysing its authentication mechanism. The researcher found that although the default mechanism asks for a one-time password (OTP) and a PIN to log in to the digital storage, he was able to bypass the authentication after adding an Aadhaar number and intercepting the connection to DigiLocker and changing the parameters, as explained by the researcher in a post on Medium.

The authentication flaw allowed anyone with sufficient technical skills to set up a new PIN and even access the DigiLocker account, without requiring any passwords. The flaw could also allow attackers to acquire a user profile by bypassing the OTP process and modifying the response using an interception tool.

Advertisement

Gahlot discovered the vulnerability last month and reported it to the DigiLocker team shortly. The team fixed the PIN bypassing issue in a couple of days, however, the OTP bypass issue was resolved on Monday.

Advertisement

In a statement released late-Tuesday, DigiLocker team acknowledged the vulnerability and said that it had "crept" in the code when new features were added to the platform recently. The team also claimed an attacker could only compromise the account of a DigiLocker user if they had the username of that account. Further, the team mentioned that no data was compromised because of the said vulnerability. As we mentioned earlier, the flaw is now patched.

As per the latest statistics available on the DigiLocker site, there are more than 3.84 crore registered users on the platform. It also issued over 375 authentic documents and has a total of 155 issuer organisations and 45 requestor organisations. The platform is used to store documents such as Aadhaar card, insurance letters, income tax (IT) returns, mark sheets by various state and central boards, and driving licence issued by state governments. Moreover, it is handled by the National e-Governance Division (NeGD), led by the Ministry of Electronics and Information Technology (MeitY).

Advertisement

Editor's Note: Updated with response from DigiLocker team.


In 2020, will WhatsApp get the killer feature that every Indian is waiting for? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts or RSS, download the episode, or just hit the play button below.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. Realme 16 Pro+ 5G Retail Box Reveals Price in India Weeks Before Launch
  2. iPhone Fold Seen in Leaked Renders With Pixel-Fold Like Design
  3. Realme Pad 3 5G to Launch Alongside the Realme 16 Pro Series
  4. Why Apple Might Pay a 230 Percent Premium for iPhone 17 Pro RAM in 2026
  5. De De Pyaar De 2 OTT Release: Know Everything About This Ajay Devgan Starrer Romance Comed
  6. Red Magic 11 Air Launch Confirmed; Could Feature This Snapdragon Chip
  7. OnePlus Nord 6 Visits Certification Website, Could Launch Soon
  8. Middle Class Now Streaming Online: What You Need to Know About This Tamil Movie
  9. Oppo Find N6, Find X9 Ultra Could Launch in China Early Next Year
  10. Global Warming May Overshoot and Trigger the Next Ice Age, Say Scientists
  1. Vritta OTT Release Date Revealed: Know When and Where to Watch it Online
  2. Rajini Gaang OTT Release Date: Know When and Where to Watch it Online
  3. De De Pyaar De 2 OTT Release Update: Know Everything About Streaming, Plot, Cast, and More
  4. Baahubali: The Epic Now Available for Streaming Online: Everything You Need to Know
  5. Global Warming May Overshoot and Trigger the Next Ice Age, Say Scientists
  6. Weapons OTT Release Date: When and Where to Watch it Online?
  7. Paradise (2024) Now Streaming Online: What You Need to Know
  8. Red Magic 11 Air Launch Confirmed; Tipster Hints at Presence of Snapdragon 8 Elite Chip
  9. Samsung Reportedly Plans to Expand India Manufacturing With Focus on Phone Displays, May Source Chips From India
  10. Realme 16 Pro+ 5G Price in India Leaked as Tipster Reveals Retail Box Ahead of Launch on January 6
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.