<?xml version="1.0" encoding="utf-8" ?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns="http://purl.org/rss/1.0/">




    



<channel rdf:about="https://cis-india.org/search_rss">
  <title>Centre for Internet and Society</title>
  <link>https://cis-india.org</link>
  
  <description>
    
            These are the search results for the query, showing results 331 to 345.
        
  </description>
  
  
  
  
  <image rdf:resource="https://cis-india.org/logo.png"/>

  <items>
    <rdf:Seq>
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/new-indian-express-may-6-2017-experts-stress-on-need-for-enhanced-security"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/the-indian-express-may-11-2017-aadhaar-data-leak-take-precautions-while-sharing-info-on-websites-meity-tells-all-depts"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/the-wire-may-10-2017-shreyashi-roy-taking-cognisance-of-the-deeply-flawed-system-that-is-aadhaar"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/revisiting-aadhaar-law-tech-and-beyond"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/business-standard-sanjay-kumar-singh-aadhaar-security-here-is-how-your-private-information-can-be-protected"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/business-standard-may-13-2017-alnoor-peermohamed-and-raghu-krishnan-aadhaar-has-become-a-whipping-boy-nandan-nilekani"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/financial-express-may-19-2017-pti-uidai-puts-posers-to-cis-over-aadhaar-data-leak-claim"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/bloomber-quint-may-19-2017-aayush-ailawadi-whats-hard-to-digest-about-the-zomato-hacking"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/business-standard-alnoor-peermohamed-may-19-2017-hack-exposes-zomatos-weak-protection-of-customer-data-say-cyber-experts"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/economic-times-may-18-2017-mahendra-singh-uidai-asks-centre-for-internet-and-society-to-provide-hacker-details"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/the-times-of-india-mahendra-singh-may-18-2017-provide-hacker-details-outfit-that-claimed-data-leak-told"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/deccan-herald-may-11-2017-plug-data-leak-before-imposing-aadhaar"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/medianama-vivek-pai-may-4-2017-indian-govt-says-it-is-still-drafting-privacy-law"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/events/meeting-on-proactive-disclosure-and-personal-data-delhi-may-13"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/los-angeles-times-shashank-bengali-may-12-2017-india-is-building-a-biometric-database-for-1.3-billion-people-and-enrollment-is-mandatory"/>
        
    </rdf:Seq>
  </items>

</channel>


    <item rdf:about="https://cis-india.org/internet-governance/news/new-indian-express-may-6-2017-experts-stress-on-need-for-enhanced-security">
    <title>Experts stress on need for enhanced security</title>
    <link>https://cis-india.org/internet-governance/news/new-indian-express-may-6-2017-experts-stress-on-need-for-enhanced-security</link>
    <description>
        &lt;b&gt;With more and more people falling prey to phishing scams, experts believe that lack of adequate security features in online payment systems will only increase the number of such cases in the coming days. While admitting that the rise in such crimes would be hard to stop or control, cyber security consultants also blame the lack of preparedness before taking the digital economy route as a cause for such problems.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article was &lt;a class="external-link" href="http://www.newindianexpress.com/cities/bengaluru/2017/may/06/experts-stress-on-need-for-enhanced-security-1601631.html"&gt;published in the New Indian Express&lt;/a&gt; on May 6, 2017. Pranesh Prakash was quoted.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;Speaking to Express, Dr A Nagarathna of  the Advanced Centre on Cyber Law and Forensics, National Law School of  India University, said that apart from the push for digital payment  solutions, the merger of various State Bank entities also provided  chances for criminals to exploit gullible people.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“People tend to give away critical information since cyber criminals  seem so convincing. But they should remember that banks never collect  such information over phone,” she said.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The cyber security features of banks and e-wallets are also  questionable. Banks and e-wallet service providers should be held  accountable for such crimes, so that they make an effort to ensure  necessary safety measures, she said.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Pranesh Prakash, Policy Director at the Centre for Internet and Society,  noted that there were security concerns with e-wallets. “Many e-wallet  apps compromise on security in favour of convenience, but, at the same  time, have terms of service that hold customers liable for financial  losses.  There have been many reports of criminals working with rogue  telecom company employees to clone SIM cards and steal money via UPI and  BHIM,” he said.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;He also criticised the use of biometrics as the only factor for  authorising payments to merchants using Aadhaar Pay.  He noted, “Your  fingerprints cannot be changed, unlike a PIN. So, if a merchant clones  your fingerprint, you cannot revoke it or replace it the way you can  with a debit card and a PIN.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Another activist said the recommendations of Watal Committee, which  looked into digital payments, should be implemented. “As of now, the law  does not focus on the need for consumer protection in digital payments.  The Payment and Settlement Systems Act, 2007, needs to be updated,” he  said.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/new-indian-express-may-6-2017-experts-stress-on-need-for-enhanced-security'&gt;https://cis-india.org/internet-governance/news/new-indian-express-may-6-2017-experts-stress-on-need-for-enhanced-security&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Cyber Security</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-20T06:13:19Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/the-indian-express-may-11-2017-aadhaar-data-leak-take-precautions-while-sharing-info-on-websites-meity-tells-all-depts">
    <title>Aadhaar data leak: Take precautions while sharing info on websites, MEITy tells all depts</title>
    <link>https://cis-india.org/internet-governance/news/the-indian-express-may-11-2017-aadhaar-data-leak-take-precautions-while-sharing-info-on-websites-meity-tells-all-depts</link>
    <description>
        &lt;b&gt;‘Publishing identity info is in clear contravention of the provisions of the Aadhaar Act, 2016’&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article was &lt;a class="external-link" href="http://indianexpress.com/article/business/economy/aadhaar-data-leak-take-precautions-while-sharing-info-on-websites-meity-tells-all-depts-4650295/"&gt;published in the Indian Express&lt;/a&gt; on May 11, 2017.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;In light of various Central and state government departments making  public Aadhaar information of several users on their websites, the  Ministry of Electronics and Information Technology (MEITy) has written  to secretaries of all government departments asking them to sensitise  the officials and take precautions while publishing or sharing data on  their websites.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“It has come to notice that there have been instances wherein  personal identity or information of residents, alongwith Aadhaar numbers  and demographic information and other sensitive personal data such as  bank details collected by ministries/departments, state departments for  administration of welfare schemes etc. have been&lt;br /&gt; published online,” IT secretary Aruna Sundararajan wrote in the letter dated April 24.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“Publishing identity information i.e. Aadhaar number along with  demographic information is in clear contravention of the provisions of  the Aadhaar Act, 2016 and constitutes an offence punishable with  imprisonment up to three years. Further, publishing of financial  information including bank details, being sensitive personal data, is  also in contravention of provision under IT Act, 2000 with violations  liable to pay damages by way of compensation to persons affected,” she  noted.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;According to media reports, Aadhaar numbers of hundreds of thousands  of pension beneficiaries were published on a state government website,  and was followed by Chandigarh’s Food and Civil Supplies Department  revealing the Aadhaar information of beneficiaries of public  distribution system. Following Sundararajan’s letter, various central  government ministries have issued advisories to sensitise the officials  and the web information managers to comply with the IT Act.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Earlier this month, a report by non-profit organisation The Centre  for Internet and Society noted that up to 13.5 crore Aadhaar numbers  were exposed and were publicly available on government websites, with  about 10 crore of these being linked to bank account details. The  27-paged report — Information Security Practices of Aadhaar (or lack  thereof): A documentation of public availability of Aadhaar Numbers with  sensitive personal financial information — has collected Aadhaar data  from four government portals.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Two of these are national portals: National Social Assistance Programme and &lt;a href="http://indianexpress.com/about/mahatma-gandhi"&gt;Mahatma Gandhi&lt;/a&gt; National Rural Employment Guarantee Act, both under the rural  development ministry. The other two studied by the report’s authors,  Srinivas Kodali and Amber Sinha, are run by the AP government: a daily  online payments report under MGNREGA by the state government, and  Chandranna Bima Scheme.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“Based on the numbers available on the websites looked at, the  estimated number of Aadhaar numbers leaked through these 4 portals could  be around 130-135 million (13-13.5 crore) and the number of bank  accounts numbers leaked at around 100 million (10 crore) from the  specific portals we looked at,” the report stated.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;The letter&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“It has come to notice that there have been instances  wherein…information of residents, alongwith Aadhaar numbers and  demographic information…have been published online,” IT secretary Aruna  Sundararajan wrote in the letter dated April 24&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/the-indian-express-may-11-2017-aadhaar-data-leak-take-precautions-while-sharing-info-on-websites-meity-tells-all-depts'&gt;https://cis-india.org/internet-governance/news/the-indian-express-may-11-2017-aadhaar-data-leak-take-precautions-while-sharing-info-on-websites-meity-tells-all-depts&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-19T14:59:38Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/the-wire-may-10-2017-shreyashi-roy-taking-cognisance-of-the-deeply-flawed-system-that-is-aadhaar">
    <title>Taking Cognisance of the Deeply Flawed System That Is Aadhaar</title>
    <link>https://cis-india.org/internet-governance/news/the-wire-may-10-2017-shreyashi-roy-taking-cognisance-of-the-deeply-flawed-system-that-is-aadhaar</link>
    <description>
        &lt;b&gt;Aadhaar and its many connotations have grown to be among the most burning issues on the Indian fore today, that every citizen aware of their rights should be taking note of.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by Shreyashi Roy was &lt;a class="external-link" href="https://thewire.in/133916/taking-cognisance-of-the-deeply-flawed-system-that-is-aadhaar/"&gt;published in the Wire&lt;/a&gt; on May 10, 2017.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;With the &lt;a href="https://thewire.in/130948/aadhaar-card-details-leaked/" rel="noopener noreferrer" target="_blank" title="leak of 130 million Aadhaar numbers"&gt;leak of 130 million Aadhaar numbers&lt;/a&gt; recently coming to light, several activists, lawyers and ordinary  citizens are up in arms about what is increasingly being viewed as a  government surveillance system. Keeping this in mind, on Tuesday, May 9,  Software Freedom Law Centre India (SFLC) hosted an event that brought  together a panel to clearly articulate the dangers of Aadhaar and to  discuss whether the biometric identification system is capable of being  reformed.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;SFLC is a donor-supported legal services organisation that calls itself a protector of civil liberties in the digital age.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Titled ‘Revisiting Aadhaar: Law, Tech and Beyond’, the discussion, with several eminent personalities who have in-depth knowledge of Aadhaar and its working, threw light on the various problems that have cropped up with regard to India’s unique identification system. The discussion was moderated by Saikat Datta, policy director at Centre for Internet and Society, which published the report that studied the third-party leaks of Aadhaar numbers and other personal data.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;The leaks&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The discussion took off from the point of the leaks, with Srinivas  Kodali, a panelist and one of the authors of the report, explaining his  methodology for the study that proved that the Aadhaar database lacked  the security required when dealing with private information of people.  He highlighted the fact that during the course of his research, he had  noticed several leaks from government websites and notified the Unique  Identification Authority of India (UIDAI) about the same. Yet, at every  step, UIDAI continued to deny and reject the possibility of this  happening. Kodali says, however, that he had noticed that the websites  that were unknowingly leaking data were, in fact, fixing the leaks after  being notified without acknowledging that the leak had happened in the  first place. Kodali reiterated at the discussion, as in his report, that  a simple tweaking of URL query parameters of the National Social  Assistance Programme website could unmask and display private  information. Unfortunately, UIDAI cannot be brought to task for  unknowingly leaking information because there is no such provision.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;He also addressed the question of the conflict of interest that  existed in the entire system of building Aadhaar, which was created by  developers who later left the UIDAI and built their own private  companies, monetising the mine of private information that they were  sitting on. Kodali blames UIDAI for this even being allowed, since the  developers, though clearly lacking ethics, were in fact, merely  volunteers.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;The system&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;One of the glaring issues with the technology behind Aadhaar is that  the software is not open source. Anivar Aravind, a panelist, called it  “defected by design” and “bound to fail” because not only is the  technology completely untested but there are very obvious leaks that are  taking place. Moreover, UIDAI does not allow any third-party audits or  any other persons to look at the technology. Datta pointed to the fact  that this is unheard of in other nations, where software is routinely  subjected to penetration testing and hacking experts are called upon to  check how secure a database is.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Anupam Saraph, another panelist and future designer, illuminated  the creation of the Aadhaar database, pointing out that this is a system  less about identification and more about verification. All of the  verification, moreover, has been done by private parties, making the  database itself suspect and leaving everyone’s private information loose  at the time of enrolment. In addition, Aadhaar was meant for all  residents and not just citizens. But now there is a mix of  both, creating confusion in many aspects. Saraph also brought up how one  rogue agency with access to all this information could pose an actual  national security threat, unlike all the requests for information on  breaches that the government keeps pointing fingers at. Referring to  Nandan Nilekani’s statement about Aadhaar not being like AIDS, Saraph  pointed out that it was exactly like it because much like the body,  which cannot distinguish between an invasion and itself, the Aadhaar  system is not being able to distinguish between aliens and citizens and  has begun denying the latter benefits.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The Supreme Court has declared time and again that Aadhaar cannot be  made mandatory, but the government continues to – in complete disregard  of the apex court’s judgment – insist on Aadhaar for a multitude of  schemes. More and more schemes are being made unavailable without the  existence of an Aadhaar number as the government continues to function  in a complete lack of cognisance of the fact that the poor are losing  out on something as basic as their food because of a number. Prasanna  S., an advocate and a panelist, called it a “voluntary but mandatory”  system that is becoming an evidence collection mechanism. Moreover,  everything is connected through this one number, making many options  like financial fraud, selective treatment of citizens and other horrors  possible. The collection of all this information is not dangerous,  screams the government. Maybe not in the hands of this one. But what of  the next? What of rogues?&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;The legal aspect&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;One of the panelists was Shyam Divan, a senior advocate of the  Supreme Court, who has represented petitioners fighting against Aadhaar.  Divan spoke about how along with a group of advocates he has been  trying to get the apex court to rule on the issue but has been met with  long queues before a ruling can be procured. He addressed the right to  privacy aspect of the system and the recent declaration that the citizen  does not have the absolute right to the body. He emphasised that the  government cannot own the body and that for a free and democratic  society, a limited government, instead of an all-knowing and all-seeing  government, is essential. Unfortunately for India, there is no express  right to privacy in the constitution, but that does not mean that rights  can be taken away in exchange for a fingerprint. It is the government’s  duty to respect privacy. For him, Aadhaar has become an instrument of  oppression and exclusion, a point that Prasanna also agreed with,  calling it a “systematic attack on consent”.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;There is complete agreement that there has been a railroading of  consent in this entire matter if Aadhaar being passed forcibly through  the Lok Sabha as a money bill is anything to go by. If parliament’s  consent can be disregarded in that fashion, what is an ordinary citizen  to do in the face of this complete imbalance of power in the state’s  hand?&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Usha Ramanathan, a legal researcher and a long-time critic of  Aadhaar, spoke about how India has turned into a state where there are  more restrictions than fundamental rights, rather than the other way  around. She related how there was no clarity at the beginning of Aadhaar  of how it would be a card or a number and was never a government  project in the first place. This is a private sector ambition that the  government has jumped on board with, without considering that the  private sector does not concern itself with civil liberties. As other  panelists also pointed out, the private sector cannot and will not  protect public interest. This is the job of the government, especially  in an age of digitisation. But Aadhaar compromises the ability of the  state to stand up for its citizens.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;With June 30 approaching fast, many of those who have so far  abstained from enrolling in the system are considering giving up their  rebellion and going like sheep to get themselves registered in the  database. In the words of Divan, they will have to “volunteer  compulsorily for an Aadhaar”. The government is probably counting on  this. Turning to the Supreme Court has been of no help, although a  verdict can be hoped for in a couple of weeks. But what can we do if  they rule for the government?&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Some of the panelists are on board with the idea of a civil  disobedience movement, a kind of a rebellion against Aadhaar. Some  suggested thinking of out-of-the-box ways to register one’s protest and  dissent against what is clearly becoming the architecture of a  surveillance state. Saraph was particularly vehement about the need to  completely destroy the Aadhaar database – “shred it”.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;What all the panelists emphasised repeatedly was that there can be no  improvements to a system that is so deeply flawed and that has had so  many “teething problems” that are making millions suffer. The main  takeaway from the discussion was that Aadhaar must see a speedy demise  because it cannot be saved and cannot persist in its current state.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/the-wire-may-10-2017-shreyashi-roy-taking-cognisance-of-the-deeply-flawed-system-that-is-aadhaar'&gt;https://cis-india.org/internet-governance/news/the-wire-may-10-2017-shreyashi-roy-taking-cognisance-of-the-deeply-flawed-system-that-is-aadhaar&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-19T14:52:58Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/revisiting-aadhaar-law-tech-and-beyond">
    <title>Revisiting Aadhaar: Law, Tech and Beyond</title>
    <link>https://cis-india.org/internet-governance/news/revisiting-aadhaar-law-tech-and-beyond</link>
    <description>
        &lt;b&gt;Udbhav Tiwari attended a panel on "Revisiting Aadhaar: Law, Tech and Beyond" held at the India International Centre Annexe on May 9, 2017 in New Delhi, organised by the Software Freedom Law Centre (SFLC.in) in collaboration with Digital Empowerment Foundation and IT for Change.&lt;/b&gt;
        &lt;div style="text-align: justify; "&gt;The panel consisted of:&lt;/div&gt;
&lt;div style="text-align: justify; "&gt;
&lt;ul&gt;
&lt;li&gt;Saikat Datta; Policy Director, Centre for Internet and Society (Moderator) &lt;/li&gt;
&lt;li&gt;Anivar Aravind; Founder/Director at Indic Project &lt;/li&gt;
&lt;li&gt;Anupam Saraph; Professor and Future Designer &lt;/li&gt;
&lt;li&gt;Prasanna S; Advocate &lt;/li&gt;
&lt;li&gt;Shyam Divan; Senior Advocate, Supreme Court &lt;/li&gt;
&lt;li&gt;Srinivas Kodali; Co-founder at Open Stats &lt;/li&gt;
&lt;li&gt;Osama Manzar; Founder and Director, Digital Empowerment Foundation &lt;/li&gt;
&lt;li&gt;Usha Ramanathan; Legal Researcher&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;p style="text-align: justify; "&gt;The  panel was quite enlightening (and Saikat was a stellar moderator), with  Mr. Divan's elucidation on the arguments made in the court for the  Aadhaar case in particular being a great learning experience. Benjamin  and Sheetal (both interns in the Delhi office) along with Sumandro also  attended the event.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The other learning was that  for people who have attended multiple such panels/seminars and meetings  on Aadhaar, they can have a lot of repeated content. I passed on the  feedback to SFLC about how they could possibly include a small 10 to 15  minute session in future such panels on developments since the previous  such event on the Aadhaar and include practical aspects about what  people can do about minimising the harms that we are all slowly being co  opted into facing with the system.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;More info about the event &lt;a class="external-link" href="http://sflc.in/panel-discussion-revisiting-aadhaar-law-tech-and-beyond-may-9-2017-new-delhi/"&gt;here&lt;/a&gt;.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/revisiting-aadhaar-law-tech-and-beyond'&gt;https://cis-india.org/internet-governance/news/revisiting-aadhaar-law-tech-and-beyond&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-19T14:47:32Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/business-standard-sanjay-kumar-singh-aadhaar-security-here-is-how-your-private-information-can-be-protected">
    <title>Aadhaar security: Here's how your private information can be protected</title>
    <link>https://cis-india.org/internet-governance/news/business-standard-sanjay-kumar-singh-aadhaar-security-here-is-how-your-private-information-can-be-protected</link>
    <description>
        &lt;b&gt;Lock Aadhaar, and notify UIDAI if you get a one-time-password for a transaction you did not initiate&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by Sanjay Kumar Singh was published in the &lt;a class="external-link" href="http://www.business-standard.com/article/current-affairs/aadhaar-security-here-s-how-your-private-information-can-be-protected-117051000611_1.html"&gt;Business Standard&lt;/a&gt; on May 11, 2017. Udbhav Tiwari was quoted.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;&lt;span class="p-content"&gt;The linking of Aadhaar — the 12-digit unique  identification number for Indian residents — across various benefits is  going through a roller-coaster ride. On one hand, the government, keen  to make it mandatory, is linking it with filing of income-tax returns  and benefits. But, on the other, many are uncomfortable with it because  of privacy issues and leakages that have been reported recently. The  Supreme Court, on Tuesday, referred another fresh plea challenging the  Aadhaar Act and its mandatory use in government schemes to a larger  Constitution bench. &lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span class="p-content"&gt;There has been several reports that say that Aadhaar numbers and other  personal data are being leaked. Bengaluru-based Centre for Internet and  Society (CIS) has published a report (titled Information security  practices of Aadhaar, or lack thereof) where it lists four government  departments that have posted Aadhaar numbers and other personal  information of people. According to the report, an estimated 130-135  million Aadhaar numbers and 100 million bank account numbers were posted  on the four portals that the CIS researchers checked. Normally such  data should be kept on the government’s intranet, where only authorised  people can access it. However, a few government departments have  uploaded this data on their websites. In many cases, the data was in  excel format, making it all the more easy for people to download and  misuse it. The worst part: If your data is stolen, you cannot file even a  First Information Report with the police. Only the nodal body, the  Unique Identification Authority of India (UIDAI), can file a police  complaint.&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Your data can be misused:&lt;/b&gt; Experts say that leakage  of Aadhaar numbers and other personal information into the public domain  violates peoples’ privacy. “Your name, phone number, address, bank  account number and Aadhaar number are personal information. Only you  have the right to decide whether to release such information to others.  Such data shouldn’t be complied in excel sheets in large numbers and be  freely accessible on the internet to everyone," says Udbhav Tiwari,  policy officer at the Centre for Internet and Society, Bengaluru.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Tele-marketers  and advertisers will have access to the personal information of all  those people. More serious problems such as identity theft can occur.  Says Smitha Krishna Prasad, project manager, Centre for Communication  Governance at National Law University, Delhi: “The more sensitive  information a person has about you, the easier it becomes to impersonate  you when that person is speaking to, say, a bank." The impersonator  could open a bank account or even take a loan in your name.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Suppose  a hacker gets your email ID. “He will use the ‘password reset or forgot  password’ feature to change your password and get access to your  account. This feature poses questions based on personal info about you.  Any such data collected about you comes useful here. Such hackers mine a  lot of data about potential victims from all possible sources," says  Shomiron Das Gupta of NetMonastery, a threat management provider. In the  email, he could find info about your bank account, credit card account,  etc, and cause financial losses to you.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Serious risks can  also arise if someone manages to breach the biometric authentication or  one-time password (OTP) required for using the Aadhaar system. “It is  possible to copy an individual’s fingerprints, and replicate them using  very commonly available resins. It is also possible for hackers to  capture the data being communicated between a telephone tower and a  mobile phone, especially if it is poorly encrypted. This will allow the  hacker to see the OTP. Admittedly, this does require expertise and a  targeted effort vis-a-vis an individual," says Tiwari. Now that the  Aadhaar numbers of so many people have been divulged, someone could  utilise their identities to steal their government-granted benefits, or  obtain a SIM card, which could then be misused. Raman Jit Singh Chima,  policy director, Access Now, says at many places where the Aadhaar  number is required today, no biometric authentication is done. So just  the number can be used to impersonate you.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Lock your biometrics:&lt;/b&gt; If your Aadhaar number and  other personal information have been leaked, here are a few steps you  can take to safeguard yourself. One, be wary of any calls you receive  asking for additional details, which may not have been leaked already.  Be equally wary if you receive a call wherein someone rattles off your  personal data and asks you to verify it. The caller could pretend to be  calling from your bank. It is best not to reveal or confirm any  information over the phone at all. Two, you have the option to lock your  biometric data online. Even if someone manages to steal your  fingerprint, he will not be able to use it if you have locked your  biometric data (see table). Also, if you get an OTP on your phone for an  Aadhaar utilisation that you did not initiate, notify the UIDAI, and  thus ensure that no transaction is carried out using your Aadhaar  account.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Need for a privacy law: &lt;/b&gt;To  prevent data leaks in the future, the government needs to sensitise  state government officials who work with Aadhaar data about the need to  protect the its privacy. More importantly, India needs a comprehensive  data protection law. At present, there is limited provision in the  Information Technology Act of 2008 under which you can file a civil case  against a corporate that has leaked your personal information. “The  person affected by data leakage has to show that he has suffered  wrongful loss, or somebody else has enjoyed a wrongful gain, and then  claim compensation," says Prasad.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;After the Radia tapes  incident, the government had said it would pass a comprehensive privacy  law. “This law would lead to the creation of a data protection authority  with enforcement powers, which would be able to penalise both companies  and government bodies violating privacy principles. Despite the process  beginning in 2012-13, and multiple drafts being leaked into the public  domain, there has not been much progress on this count," says Chima. He  adds that when the privacy law becomes a reality, any part of the  Aadhaar Act that is contrary to it should also be amended.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;How to lock your biometric data online&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Go  to the UIDAI web site: https://uidai.gov.inGo to Aadhaar services, then  Lock/Unlock Biometrics Enter Aadhaar number Enter security code that  appears below the Aadhaar numberYou will receive an OTP on your  registered mobile number. Enter it Click ‘Verify’Click box against  ‘Enable biometric lock’Click on Submit buttonSame procedure can be  repeated to disable biometric lock.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/business-standard-sanjay-kumar-singh-aadhaar-security-here-is-how-your-private-information-can-be-protected'&gt;https://cis-india.org/internet-governance/news/business-standard-sanjay-kumar-singh-aadhaar-security-here-is-how-your-private-information-can-be-protected&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-19T10:05:25Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/business-standard-may-13-2017-alnoor-peermohamed-and-raghu-krishnan-aadhaar-has-become-a-whipping-boy-nandan-nilekani">
    <title>Watch: Aadhaar has become a whipping boy: Nandan Nilekani </title>
    <link>https://cis-india.org/internet-governance/news/business-standard-may-13-2017-alnoor-peermohamed-and-raghu-krishnan-aadhaar-has-become-a-whipping-boy-nandan-nilekani</link>
    <description>
        &lt;b&gt;India certainly needs a modern data privacy and protection law, Nilekani said in an interview.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The Alnoor Peermohamed and Raghu Krishnan was &lt;a class="external-link" href="http://www.business-standard.com/article/economy-policy/aadhaar-has-become-a-whipping-boy-nandan-nilekani-117051201521_1.html"&gt;published in the Business Standard&lt;/a&gt; on May 13, 2017.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;As debate rages over &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar &lt;/a&gt;being a &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Privacy" target="_blank"&gt;privacy &lt;/a&gt;and surveillance liability, its architect &lt;b&gt;Nandan Nilekani &lt;/b&gt;says the unique identity programme has become a “whipping ward”.  In an interview with &lt;i&gt;Alnoor Peermohamed &lt;/i&gt;and &lt;i&gt;Raghu Krishnan&lt;/i&gt;, he says we need a data protection and &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Privacy" target="_blank"&gt;privacy &lt;/a&gt;law with adequate judicial and parliamentary oversight. Edited excerpts:&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;There is concern we are losing our &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Privacy" target="_blank"&gt;privacy &lt;/a&gt;because of &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar.&lt;/a&gt;..&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Privacy" target="_blank"&gt;Privacy &lt;/a&gt;is  an issue the whole world is facing, thanks to digitisation. The day you  went from a feature phone to a smartphone the amount of digital  footprint you left behind went up dramatically. The phone records your  messages, it knows what you are saying, it has a GPS so it can tell  anybody where you are, the towers can tell anybody where you are because  they are constantly pinging the phone. There are accelerometers and  gyroscopes in the phone that detect movement.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Internet companies essentially make money from data. They use data to  sell you things or advertisements. And that data is not even in India,  it is in some country in some unaccountable server and accessible to the  government of that foreign country, not ours.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Then increasingly there is the Internet of Things. Your car has so many  sensors, wearables have sensors and all of them are recording data and  beaming it to somebody else. Then there are CCTV cameras everywhere, and  today they are all IP-enabled.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;So &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Privacy" target="_blank"&gt;privacy &lt;/a&gt;is a global issue, caused by digitisation. &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar &lt;/a&gt;is one small part of that. The system is designed not to collect information, because the first risk to &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Privacy" target="_blank"&gt;privacy &lt;/a&gt;is if someone is collecting information. &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar &lt;/a&gt;is  a passive ID system, it just sits there and when you go somewhere and  invoke it, it authenticates your identity. By design itself, it is built  for &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Privacy" target="_blank"&gt;privacy.&lt;/a&gt; I believe India needs a modern data &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Privacy" target="_blank"&gt;privacy &lt;/a&gt;and &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Protection+Law" target="_blank"&gt;protection law.&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Why is &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar &lt;/a&gt;being used as a proxy for the &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Privacy" target="_blank"&gt;privacy &lt;/a&gt;and data protection issues?&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;It is a motivated campaign by people who are trying to find different ways to say something about it. &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Privacy" target="_blank"&gt;Privacy &lt;/a&gt;is a much bigger issue. I have been talking about &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Privacy" target="_blank"&gt;privacy &lt;/a&gt;much  before anyone else. In 2010, when it was not such a big issue, I had  written to Prime Minister Manmohan Singh saying we needed a data &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Protection+Law" target="_blank"&gt;protection law.&lt;/a&gt; You could see what was happening, the iPhone came out on June 30, 2007,  Android phones came around the time we started Aadhaar, so we could see  the trend. I asked Rahul Matthan, a top intellectual property and data  lawyer, to help and we worked with the government to come out with a  draft law. And then there was the AP Shah Committee. The UIDAI’s DDG  Ashok Pal Singh was a part of that committee, so we helped shape that  policy.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;When a banking application uses Aadhaar, the system does not know what  the bank does. It is deliberately designed so that data is kept away  from the core system.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;I am all for a data &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Protection+Law" target="_blank"&gt;protection law &lt;/a&gt;but we should look at it in context, look at the big picture. If people want to work together to create a data &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Privacy" target="_blank"&gt;privacy &lt;/a&gt;law then it is a great thing. But if they want to use it to just attack Aadhaar, then there is some other interest at work.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Now that the government is linking &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar &lt;/a&gt;to PAN and driver’s licences, will that not lead to &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar &lt;/a&gt;being used as a surveillance tool?&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Surveillance is conducted through a 24x7 system that knows what you are  doing, so from a technology perspective the best surveillance device is  your phone. The phone is the device you should worry about.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar &lt;/a&gt;is  not a 24x7 product. I buy one SIM card a year and do an e-KYC, the  driver’s licence sits in my pocket and only sometimes someone asks for  it. With the PAN card I file my returns only once a year.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;But with all that data being linked, can the government not use it?&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;It is a valid concern and has to be addressed through a legal and oversight process. &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar &lt;/a&gt;is just one technology. You do not attack the technology, you look at the overall picture.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The US has the Foreign Intelligence Surveillance Act under which  special courts issue warrants to the FBI for surveillance. This is  absolutely required and it should be a part of the data &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Protection+Law" target="_blank"&gt;protection law &lt;/a&gt;(in India) which says under what circumstances the government can authorise surveillance.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Today mobile phones are being tapped by so many agencies. In the US,  the FBI is under the oversight of the Senate. In India, Parliament does  not have oversight of any intelligence agency. I remember (former Union  minister) Manish Tewari had introduced a Bill six or seven years ago  saying Intelligence agencies needed to be under the oversight of the  Parliament, but nothing happened.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Is there any way to stop &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar &lt;/a&gt;being used as a surveillance tool?&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Today a person can be identified with or without &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar.&lt;/a&gt; US systems can identify a person in a few milliseconds using big data. All that is part of what we have to protect. &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar &lt;/a&gt;by  itself is not going to add anything to that. What is important is that  the infrastructure of surveillance comes under judicial oversight as  well as parliamentary oversight.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Would the &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar &lt;/a&gt;narrative have been different if this were a Congress-led government?&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;I think most people making this noise are against the government, so it is a political argument and &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar &lt;/a&gt;has  become a convenient whipping ward. Lots of different agendas are at  work here. But my understanding is this - whether it is data protection  and privacy, surveillance or security, these are all broad issues that  apply to technology in general and if you are serious about solving the  issues you should fix it at the highest level and have a data protection  and &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Privacy" target="_blank"&gt;privacy &lt;/a&gt;law which includes, mobile phones, CCTV cameras and &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar.&lt;/a&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;A report by the Centre for Internet and Society says 130 million &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar &lt;/a&gt;identities have been leaked...&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;It is because of the transparency movement in the last 10 years. In  2006, we passed the RTI Act and MNREGA Act. Section 4 of the RTI Act  says that data about benefits should be made public. At that time it was  all about transparency. Since then, governments have been publishing  lists of MNREGA beneficiaries and how much money is being put into their  bank accounts. At that time it was applauded. Now the same thing is  coming back as &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Privacy" target="_blank"&gt;privacy &lt;/a&gt;being affected.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;These are not leaks; governments have been consciously putting out the  data in the interest of transparency. The message from this is we have  to strike a balance between transparency and &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Privacy" target="_blank"&gt;privacy.&lt;/a&gt; And that is a difficult balance because Section 4 of the RTI Act says  if a benefit is provided by the government it is public information, so  the names of beneficiaries should be published because it is taxpayers’  money.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;There is something called personally identifiable information. You  should strike a balance between transparency and not revealing  personally identifiable information. That is a delicate balance, and  people will have to figure this out. The risk you have now is  governments will stop publishing data - look, you guys have made a big  fuss about privacy, we will not publish. In fact, the transparency guys  are now worried that all the gains are being lost.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;If &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar &lt;/a&gt;is voluntary, why is the government forcing it on to various schemes?&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;There are two things, benefits and entitlements and government-issued documents. There the government has passed a law, the &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar &lt;/a&gt;Bill of 2016, which is signed by the President. In that, there is a clear protocol that the government can use &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar &lt;/a&gt;for benefits and what process they should follow.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The second thing is &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar &lt;/a&gt;for government documents. There are three examples - PAN cards, driver’s licences and SIM cards.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The government has modified the Finance Bill and made &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar &lt;/a&gt;mandatory  for a PAN card. Why has it done that? Because India has a large number  of duplicate PAN cards. India has something like over 250 million PAN  cards and only 40 million taxpayers. Some of those may be people who  have taken PAN cards just as ID but not for tax purposes, but frankly it  is also because a lot of people have duplicate PAN cards. Why do people  have duplicates?  That is a way of tax evasion. The only way you can  eliminate duplicate PAN cards is by having &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar &lt;/a&gt;as a way of establishing uniqueness.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The second thing is mobile phones. Here the mobile phone requirement  came from the Supreme Court, where somebody filed a PIL saying so many  mobile phones are being given to terrorists and therefore you need to do  an e-KYC when the SIM is cut and the government said they would use &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar &lt;/a&gt;and they have been asked to do it by 2018.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The third thing is driver’s licences. As (Union Transport Minister  Nitin Gadkari has said, 30 per cent of all driver’s licences are fakes.  Now why is this important? Because when you have fake driver’s licences  or multiple drivers’ licences, even if you are caught, you can give your  fake licence and continue to drive. Today India is the country with the  largest number of deaths on highways. Lack of enforcement, fake  licences are all a problem.  So in the latest Motor Vehicle Bill which  was passed the government said &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar &lt;/a&gt;was  necessary to get a licence. So that you have just one driver’s licence,  whether it is issued in Karnataka or Bihar, you have just one.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;The government is also talking about using &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar &lt;/a&gt;for the mid-day meal scheme...&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;If you talk to people on the ground, and I have spoken to people on the  ground, a big part of the leakage is mid-day meals. It is not reaching  children. So it is important that all this has to happen so children get  what they need.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;You engaged with governments and civil servants when you initiated the &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar &lt;/a&gt;process. In hindsight, would you say you should have also engaged with civil society?&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;I do not think there is any other programme in history which reached out to every stakeholder in the country. When we started &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar &lt;/a&gt;we  met governments, regulators and even parliamentarians. I gave a talk in  Parliament and we engaged deeply with civil society. In fact, we had  one volunteer only to engage with civil society.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;You said you were engaged with the previous government about the data &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Protection+Law" target="_blank"&gt;protection law.&lt;/a&gt; Are you engaging with the current one too?&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;I am not really engaging. I know that people are working on it and  recently the attorney-general has made a statement in the Supreme Court  that the government will bring in a data &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Protection+Law" target="_blank"&gt;protection law &lt;/a&gt;by Diwali.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;We have heard of several instances of people not being able to get their biometric authentication done. Is there a problem with &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar?&lt;/a&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The seeding of data in the &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar &lt;/a&gt;database  has to be done properly and that is a process. Authentication has been  proven at scale in Andhra Pradesh. Millions of people receive food with &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar &lt;/a&gt;authentication  in 29,000 PDS outlets. In fact, now they have portability -- a person  from Guntur can go to Vijayawada and get his rations. It is empowering.  We keep forgetting about the empowering value.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;What has the Andhra Pradesh government done? They have used  fingerprints, but they also have used iris scans, OTP on phone, and they  have a village revenue officer if none of the above works. When you  design the system, you have to design it in a way that 100 per cent of  the beneficiaries genuinely get the benefit.  Andhra Pradesh has shown  it can be done.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The government needs to package the learning and best practices of  Andhra Pradesh and take it to every other state. It is an execution  issue.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Activists have raised concerns over the centralised &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar &lt;/a&gt;database...&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;How else would you establish uniqueness? If you are going to give a  billion people a number, how else would you do it? Is there any other  way of doing it? Every cloud is centralised, then we should not have  cloud systems.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;How do you ensure security standards and software are updated?&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;There are very good people there. The CEO is very good. There is a  three-member executive board with chairman Satyanarayana and two  members, Anand Deshpande and Rajesh Jain. I have no doubt that they will  continue to improve things.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;On security, you keep improving. It is a constant race everywhere in  the world. They are now coming out with registered devices that will  make it more difficult to spoof.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;But without a centralised database, how do you establish that an  identity is not two people? If you look at the team that designed this,  cumulatively they have a few hundred years of experience of designing  large systems around the world. Every design decision has been taken  consciously looking at the pros and cons. Why did we have both  fingerprints and iris scans? There are two reasons. One is to ensure  uniqueness. The second is inclusion. We knew that fingerprints in India  do not work all the time because of age and manual labour. So we  included iris scans. I can give you a document from 2009 that says all  of this. All of these things were thought through.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;If you are given a chance to design &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar &lt;/a&gt;today what would you do differently?&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;I would do exactly the same thing. Go back and look at the design  document. Every design has been articulated, the pros and cons are  written down, published on our website, and it is a highly transparent  exercise. It is the appropriate design for the problem we are trying to  solve. We are forgetting about the huge benefits people are getting.  Crores of people are getting direct benefit transfer without hassle.  They can go to a village business correspondent and withdraw money using  &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Aadhaar" target="_blank"&gt;Aadhaar.&lt;/a&gt; They can get their SIM card and open a bank account using e-KYC.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;You are also forgetting that people are getting empowered. That  portability has ensured the bargaining power has shifted from the PDS  shop owner to the individual. If a PDS guy treats him badly, the  individual can choose another shop, earlier he could not do that. The  empowerment of millions of people to buy rations at the shop of their  choice is extraordinary.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/business-standard-may-13-2017-alnoor-peermohamed-and-raghu-krishnan-aadhaar-has-become-a-whipping-boy-nandan-nilekani'&gt;https://cis-india.org/internet-governance/news/business-standard-may-13-2017-alnoor-peermohamed-and-raghu-krishnan-aadhaar-has-become-a-whipping-boy-nandan-nilekani&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-19T09:54:52Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/financial-express-may-19-2017-pti-uidai-puts-posers-to-cis-over-aadhaar-data-leak-claim">
    <title>UIDAI puts posers to CIS over Aadhaar data leak claim</title>
    <link>https://cis-india.org/internet-governance/news/financial-express-may-19-2017-pti-uidai-puts-posers-to-cis-over-aadhaar-data-leak-claim</link>
    <description>
        &lt;b&gt;Aadhaar-issuing authority UIDAI has asked research firm Centre for Internet and Society (CIS) to explain its sensational claim that 13 crore Aadhaar numbers were "leaked" and provide details of servers where they are stored.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article originally published by PTI was also &lt;a class="external-link" href="http://www.financialexpress.com/economy/uidai-puts-posers-to-cis-over-aadhaar-data-leak-claim/675814/"&gt;published by the Financial Express&lt;/a&gt; on May 19, 2017.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;Aadhaar-issuing authority UIDAI has asked research firm Centre for  Internet and Society (CIS) to explain its sensational claim that 13  crore Aadhaar numbers were “leaked” and provide details of servers where  they are stored. In a precursor to initiating a probe into the matter,  the Unique Identification Authority of India (UIDAI) also wants CIS to  clarify just how much of such “sensitive data” are still with it or  anyone else. The UIDAI — which has vehemently denied any breach of its  database — shot off a letter to CIS yesterday asking for the details,  including the servers where the downloaded “sensitive data” are residing  and information about usage or sharing of such data.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Underscoring the importance of bringing to justice those involved in  “hacking such sensitive information”, the UIDAI sought CIS’ “assistance”  in this regard and has given it time till May 30 to revert on the  issue. “Your report mentions 13 crore people’s data have been leaked.  Please specify how much (of) this data have been downloaded by you or  are in your possession, or in the possession of any other persons that  you know,” the UIDAI said in its communication to CIS.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Interestingly, in what market watchers described as an apparent  flip-flop, CIS has now clarified that there was no leak’ or ‘breach’ of  Aadhaar numbers, but rather ‘public disclosure’. Meanwhile, the UIDAI  has quoted sections of the Information Technology Act, 2000, and the  Aadhaar Act to emphasise that violation of the clauses are punishable  with rigorous imprisonment of up to 10 years. “While your report  suggests that there is a need to strengthen IT security of the  government websites, it is also important that persons involved in  hacking such sensitive information are brought to justice for which your  assistance is required under the law,” it said.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The UIDAI has  also sought technical details on how access was gained for the National  Social Assistance Programme (NSAP) site — one of the four portals where  the alleged leak happened. When contacted, UIDAI CEO Ajay Bhushan Pandey  said, “We do not comment on individual matters.” The UIDAI has also  asked for details of systems that were involved in downloading and  storing of the sensitive data so that forensic examination of such  machines can be conducted to assess the quantum and extent of damage to  privacy of data.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The UIDAI letter comes after a CIS’ report early this month which  claimed that Aadhaar numbers and personal information of as many as 135  million Indians could have been leaked from four government portals due  to lack of IT security practices. “Based on the numbers available on the  websites looked at, estimated number of Aadhaar numbers leaked through  these four portals could be around 130-135 million,” the report had  said.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;However, in a apparent course correction on May 16, a day before the  UIDAI’s letter went out — CIS updated its report and clarified that  although the term ‘leak’ was originally used 22 times in its report, it  is “best characterised as an illegal data disclosure or publication and  not a breach or a leak”. CIS has also claimed that some of its findings  were “misunderstood or misinterpreted” by the media, and that it never  suggested that the biometric database had been breached. “We completely  agree with both Dr Pandey (UIDAI CEO) and Sharma (Trai Chairman R S  Sharma) that CIDR (Aadhaar central repository) has not been breached,  nor is it suggested anywhere in the report,” CIS said in its latest  update.&lt;/p&gt;
&lt;div class="youmaylike" style="text-align: justify; "&gt;&lt;/div&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/financial-express-may-19-2017-pti-uidai-puts-posers-to-cis-over-aadhaar-data-leak-claim'&gt;https://cis-india.org/internet-governance/news/financial-express-may-19-2017-pti-uidai-puts-posers-to-cis-over-aadhaar-data-leak-claim&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>UIDAI</dc:subject>
    
    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-19T09:28:33Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/bloomber-quint-may-19-2017-aayush-ailawadi-whats-hard-to-digest-about-the-zomato-hacking">
    <title>What’s Hard To Digest About The Zomato Hacking</title>
    <link>https://cis-india.org/internet-governance/news/bloomber-quint-may-19-2017-aayush-ailawadi-whats-hard-to-digest-about-the-zomato-hacking</link>
    <description>
        &lt;b&gt;Yet another day, yet another major security breach. But, this time it’s not a presidential candidate in the U.S. or the U.K.’s National Health Service. Instead. it’s Zomato, the popular Indian online food delivery and restaurant search service.&lt;/b&gt;
        &lt;div class="story__element__wrapper" style="text-align: justify; "&gt;
&lt;div class="story__element__text story__element"&gt;
&lt;div class="story-element-"&gt;
&lt;p&gt;The blog post by Aayush Ailawadi was published by &lt;a class="external-link" href="https://www.bloombergquint.com/technology/2017/05/18/whats-hard-to-digest-about-the-zomato-hacking"&gt;Bloomberg Quint&lt;/a&gt; on May 19, 2017. Pranesh Prakash was quoted.&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;The company disclosed that data from 17 million user accounts was stolen in a security breach. It said in &lt;a href="http://blog.zomato.com/post/160791675411/security-notice" target="_blank"&gt;its blog&lt;/a&gt; that no financial details were at risk and only user IDs, usernames,  names, email addresses and password hashes had been compromised.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="story__element__wrapper" style="text-align: justify; "&gt;
&lt;div class="story__element__text story__element"&gt;
&lt;div class="story-element-"&gt;
&lt;p&gt;Throughout the course of the day, the company kept updating its  blog post and offered different sets of advice to its users. In an  earlier post, it only recommended changing one’s password on other sites  if you are “paranoid about security like us”. Later, that post  mentioned that the passwords were “salted” and hence had an extra layer  of security but it still “strongly advises” customers to change  passwords.&lt;/p&gt;
&lt;div class="story__element__wrapper"&gt;
&lt;div class="story__element__text story__element"&gt;
&lt;div class="story-element-"&gt;
&lt;p&gt;In an emailed response, the company explained to BloombergQuint,  “We made our disclosure very early, soon after we discovered that it  happened. We wanted to be proactive in communicating to our users. As we  found more details about the leak, we updated the information”&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="story__element__wrapper"&gt;
&lt;div class="story__element__text story__element"&gt;
&lt;div class="story-element-"&gt;
&lt;p&gt;But, that wasn’t the only problem. The data was put up on the  dark web for sale by the hacker, and the seller was apparently charging  0.5521 bitcoins, or $1001.45, for the data. According to the post, the  passwords were stored by Zomato using MD5 encryption, which according to  security experts is antiquated and unsuitable for password encryption.&lt;/p&gt;
&lt;div class="__container"&gt;
&lt;div class="story__element__wrapper"&gt;
&lt;div class="story__element__text story__element"&gt;
&lt;div class="story-element-"&gt;
&lt;p&gt;Late on Thursday night, the story took an interesting turn when the company updated &lt;a href="http://blog.zomato.com/post/160807042556/security-notice-update" target="_blank"&gt;its blog post yet again&lt;/a&gt;.  It said that it had gotten in touch with the hacker who was selling the  data on the dark web and that apparently the hacker had been very  cooperative and helpful. “He/she wanted us to acknowledge security  vulnerabilities in our system and work with the ethical hacker community  to plug the gaps. His/her key request was that we run a healthy bug  bounty program for security researchers,” the company said.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="story__element__wrapper"&gt;
&lt;div class="story__element__text story__element"&gt;
&lt;div class="story-element-"&gt;
&lt;p&gt;Usually, when hackers around the world attack with ransomware,  they demand a massive amount of bitcoins as ransom. But, in this case  the company claims that all the hacker wants is the assurance that the  company will introduce a bug bounty program on Hackerone soon. In  return, the hacker has agreed to destroy all copies of the stolen data  and take the data off the dark web marketplace.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="card-block-qsection-technology card"&gt;
&lt;div class="__container"&gt;
&lt;div class="story__element__wrapper"&gt;
&lt;div class="story__element__text story__element"&gt;
&lt;div class="story-element-"&gt;
&lt;p&gt;But, while it may seem like the storm has passed for Zomato,  cybersecurity experts like Pranesh Prakash at the Centre for Internet  &amp;amp; Society believe that a lot more could have been done by the  company in such a case.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="story__element__wrapper"&gt;
&lt;div class="story__element__text story__element"&gt;
&lt;div class="story-element-"&gt;
&lt;h3&gt;&lt;b&gt;Disclose To Confuse?&lt;/b&gt;&lt;/h3&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="story__element__wrapper"&gt;
&lt;div class="story__element__text story__element"&gt;
&lt;div class="story-element-"&gt;
&lt;p&gt;Concern #1: Prakash feels that Zomato got it all wrong by issuing  multiple disclosures and not addressing the problem at hand, which was  to clearly explain what happened and immediately request customers to  change similar passwords on other websites.&lt;/p&gt;
&lt;div class="story__element__wrapper"&gt;
&lt;div class="story__element__text story__element"&gt;
&lt;div class="story-element-"&gt;
&lt;h3&gt;&lt;b&gt;What’s So Scary About The Zomato Hacking?&lt;/b&gt;&lt;/h3&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="story__element__wrapper"&gt;
&lt;div class="story__element__text story__element"&gt;
&lt;div class="story-element-"&gt;
&lt;p&gt;Concern #2: BloombergQuint reached out to Zomato to confirm  whether the passwords were encrypted with “MD5”, a hashing algorithm  that Prakash and other Twitter users who accessed the seller’s page on  the dark web believe was used by the company. But, the tech company  didn’t respond to that specific question.&lt;/p&gt;
&lt;p&gt;What’s worse is that  Prakash adds that not only is this algorithm antiquated but it is also  highly unsuitable for password encryption, as it can be cracked quickly.&lt;/p&gt;
&lt;div class="story__element__wrapper"&gt;
&lt;div class="story__element__text story__element"&gt;
&lt;div class="story-element-"&gt;
&lt;h3&gt;&lt;b&gt;Genuine Disclosures Vs False Promises&lt;/b&gt;&lt;/h3&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="story__element__wrapper"&gt;
&lt;div class="story__element__text story__element"&gt;
&lt;div class="story-element-"&gt;
&lt;p&gt;Concern #3: Prakash suspects that the company wasn’t honest and  forthright with its users during this episode. According to him, the  company could learn a thing or two about honest disclosures from  companies like CloudFlare and LastPass, which fell victim to similar  attacks in the past year.&lt;/p&gt;
&lt;div class="story__element__wrapper"&gt;
&lt;div class="story__element__text story__element"&gt;
&lt;div class="story-element-"&gt;
&lt;h3&gt;&lt;b&gt;Where’s My Privacy And Security?&lt;/b&gt;&lt;/h3&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="story__element__wrapper"&gt;
&lt;div class="story__element__text story__element"&gt;
&lt;div class="story-element-"&gt;
&lt;p&gt;Concern #4: According to Prakash, it’s not just about privacy,  but also one’s security that has been compromised in this instance. He  says that the Zomato hack is like a reminder that an odd section in the  Information Technology Act is not sufficient when it comes to data  protection. Instead, India needs a robust data protection law where bad  security practices can actually be prosecuted and companies can be  penalised if they don’t follow standard and reasonable security  practices.&lt;/p&gt;
&lt;p&gt;Zomato also told BloombergQuint that it has understood how the breach  happened but couldn’t share exact details at the moment. The company  said, “Our team is working to make sure we have the vulnerability  patched. All we can say right now is that it started with a password  leak on some other site. We will share more details on our blog over the  next few days.”&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/bloomber-quint-may-19-2017-aayush-ailawadi-whats-hard-to-digest-about-the-zomato-hacking'&gt;https://cis-india.org/internet-governance/news/bloomber-quint-may-19-2017-aayush-ailawadi-whats-hard-to-digest-about-the-zomato-hacking&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Cyber Security</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-19T09:22:37Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/business-standard-alnoor-peermohamed-may-19-2017-hack-exposes-zomatos-weak-protection-of-customer-data-say-cyber-experts">
    <title>Hack exposes Zomato's weak protection of customer data, say Cyber experts </title>
    <link>https://cis-india.org/internet-governance/news/business-standard-alnoor-peermohamed-may-19-2017-hack-exposes-zomatos-weak-protection-of-customer-data-say-cyber-experts</link>
    <description>
        &lt;b&gt;Online restaurant aggregator says it will beef up security after 17 million user details were stolen.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by &lt;span&gt;&lt;a href="http://www.business-standard.com/author/search/keyword/alnoor-peermohamed" target="_blank"&gt;Alnoor Peermohamed&lt;/a&gt; was published in the Business Standard on May 19, 2017. Pranesh Prakash was quoted.&lt;/span&gt;&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;&lt;span&gt;&lt;span class="p-content"&gt;After details of over 17 million users was stolen and sold online, restaurants discovery and food ordering service &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Zomato" target="_blank"&gt;Zomato &lt;/a&gt;has vowed to beef up security measures, including adding a layer of authentication for its own employees to access user data. &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span class="p-content"&gt;
&lt;p&gt;The company in a blog post claimed that the leak appeared to be an  internal (human) security breach with an employee's development account  getting compromised.&lt;/p&gt;
&lt;p&gt;However, &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Cyber+Security" target="_blank"&gt;cyber security &lt;/a&gt;experts pointed out that &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Zomato" target="_blank"&gt;Zomato &lt;/a&gt;was clearly lacking in its technique to protect customer data from unwanted elements .&lt;/p&gt;
&lt;div class="article-middle-banner" id="div-gpt-ad-1490771277198-0"&gt;&lt;/div&gt;
&lt;p&gt;Sajal Thomas, a &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Cyber+Security" target="_blank"&gt;cyber security &lt;/a&gt;consultant, claimed on Twitter that he verified the sample data being sold on the dark web and found that &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Zomato" target="_blank"&gt;Zomato &lt;/a&gt;had  used MD5 to hash passwords. MD5 is neither encryption nor encoding, and  was known to be easily cracked by attacks and suffered from major  vulnerabilities.&lt;/p&gt;
&lt;p&gt;Further, he said &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Zomato" target="_blank"&gt;Zomato &lt;/a&gt;had  not used salting, a technique where random data was used as additional  input to make cracking a hashed password much harder. Thomas said that  it took just a few seconds to crack the hashed passwords to turn them  into plain text.&lt;/p&gt;
&lt;p&gt;&lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Zomato" target="_blank"&gt;Zomato &lt;/a&gt;in  its blog post, however, claimed that it protected "passwords with a  one-way hashing algorithm, with multiple hashing iterations and  individual salt per password."&lt;/p&gt;
&lt;p&gt;It said that this was to ensure that passwords could not be easily  converted back to plain text. The firm claimed no credit or debit card  information of users were leaked.&lt;/p&gt;
&lt;p&gt;While &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Zomato" target="_blank"&gt;Zomato &lt;/a&gt;says it has reset passwords of all the affected accounts, experts say that users whose data were leaked are still under threat.&lt;/p&gt;
&lt;p&gt;"If you had a password for &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Zomato" target="_blank"&gt;Zomato &lt;/a&gt;that  you used elsewhere (on facebook or email), immediately change that  password across all those accounts," tweeted Pranesh Prakash, policy  director at the Centre for Internet and Society.&lt;/p&gt;
&lt;blockquote class="twitter-tweet"&gt;
&lt;p dir="ltr"&gt;If you had a password for &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Zomato" target="_blank"&gt;Zomato &lt;/a&gt;that you used elsewhere, then IMMEDIATELY change that password across ALL those accounts. Use a pw manager! &lt;a href="https://t.co/CbhtxCwlnD"&gt;https://t.co/CbhtxCwlnD&lt;/a&gt;&lt;/p&gt;
— Pranesh Prakash (@pranesh) &lt;a href="https://twitter.com/pranesh/status/865136966190288896"&gt;May 18, 2017&lt;/a&gt;&lt;/blockquote&gt;
According to Prakash, a statement by &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Zomato" target="_blank"&gt;Zomato &lt;/a&gt;misled people on how serious the security breach was by providing a false sense of security.&lt;br /&gt; &lt;br /&gt; Subsequently, the company reworded its blog post to prompt users to  change passwords of other services where they might have used the same  password as their &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Zomato" target="_blank"&gt;Zomato &lt;/a&gt;account.
&lt;p&gt;The leak was first detected by security blog &lt;i&gt;HackRead&lt;/i&gt; when it  came across an online handle going by the name of "nclay" claiming to  have hacked Zomato's database and selling its data on the dark web. Upon  testing some of the data made public by the hacker, &lt;i&gt;HackRead&lt;/i&gt; found that each account actually existed on &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Zomato" target="_blank"&gt;Zomato.&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;"The database includes emails and password hashes of registered &lt;a class="storyTags" href="http://www.business-standard.com/search?type=news&amp;amp;q=Zomato" target="_blank"&gt;Zomato &lt;/a&gt;users  while the price set for the whole package is $1,001.43 (BTC 0.5587).  The vendor also shared a trove of sample data to prove that the data is  legit," &lt;i&gt;HackRead &lt;/i&gt;wrote in its post.&lt;/p&gt;
&lt;/span&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/business-standard-alnoor-peermohamed-may-19-2017-hack-exposes-zomatos-weak-protection-of-customer-data-say-cyber-experts'&gt;https://cis-india.org/internet-governance/news/business-standard-alnoor-peermohamed-may-19-2017-hack-exposes-zomatos-weak-protection-of-customer-data-say-cyber-experts&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Cyber Security</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-19T09:11:40Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/economic-times-may-18-2017-mahendra-singh-uidai-asks-centre-for-internet-and-society-to-provide-hacker-details">
    <title>UIDAI asks Centre for Internet &amp; Society to provide hacker details</title>
    <link>https://cis-india.org/internet-governance/news/economic-times-may-18-2017-mahendra-singh-uidai-asks-centre-for-internet-and-society-to-provide-hacker-details</link>
    <description>
        &lt;b&gt;The Unique Identification Authority of India (UIDAI), the regulatory authority for Aadhaar, has written to a Bengaluru-based research organisation, Centre for Internet &amp; Society (CIS), seeking details about a suspected hack attack on government websites that led to the leak of information about 13 crore users.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by Mahendra Singh was published in the &lt;a class="external-link" href="http://tech.economictimes.indiatimes.com/news/technology/uidai-asks-centre-for-internet-society-to-provide-hacker-details/58731336"&gt;Times of India&lt;/a&gt; on May 18, 2017.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;The Unique Identification Authority of India (UIDAI), the regulatory authority for Aadhaar, has written to a Bengaluru-based research organisation, Centre for Internet &amp;amp; Society (CIS), seeking details about a suspected hack attack on government websites that led to the leak of information about 13 crore users.&lt;br /&gt;&lt;br /&gt;In a recent report, CIS had highlighted that websites run by various government departments, owing to a poor security framework, had publicly displayed sensitive personal financial information and Aadhaar numbers of beneficiaries of certainprojects.&lt;br /&gt;&lt;br /&gt;In its letter, UIDAI argued that the data downloaded from one of the websites could not have been accessed unless the website was hacked. As hacking is a grave offence under the law, the UIDAI has asked CIS to provide details of the persons involved in the data theft.&lt;br /&gt;&lt;br /&gt;According to a source, the UIDAI said that access to data on the website for the 'National Social Assistance Program' was only possible for someone in possession of authorised login details, or if the site (http://nsap.nic.in) was hacked or breached. The UIDAI said in its letter that such illegal access was against the provisions of the Aadhaar Act, 2016, and the IT Act, 2000, and that the persons involved had committed a grave offence.&lt;br /&gt;&lt;br /&gt;Asking the CIS to reply before May 30, the UIDAI also said, "Aadhaar system is a protected system under Section 70 of the IT Act, 2000, the violation of which is punishable with rigorous imprisonment for a period up to 10 years." It added that the penalty clauses for violations are also provided in Section 36, Section 38 and Section 39 of the Aadhaar Act.&lt;br /&gt;The UIDAI, however, maintained that even if the Aadhaar details were known to someone it did not pose a real threat to the people whose information was publicly available because the Aadhaar number could not be misused without biometrics.&lt;br /&gt;&lt;br /&gt;The UIDAI letter said, "While, as your report suggests, there is a need to strengthen IT security of government websites, it is also important that the persons involved in hacking such sensitive information are brought to justice for which your assistance is required under the law."&lt;br /&gt;&lt;br /&gt;"Your report mentions 13 crore people's data has been 'leaked'. Please specify how much of this data had been downloaded by you or are in your possession or in the possession of any other persons that you know. Please provide the details," the UIDAI added in its letter. The UIDAI also urged CIS to provide the details of the persons/organisations with whom it shared the data, if it did.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/economic-times-may-18-2017-mahendra-singh-uidai-asks-centre-for-internet-and-society-to-provide-hacker-details'&gt;https://cis-india.org/internet-governance/news/economic-times-may-18-2017-mahendra-singh-uidai-asks-centre-for-internet-and-society-to-provide-hacker-details&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-06-07T12:21:47Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/the-times-of-india-mahendra-singh-may-18-2017-provide-hacker-details-outfit-that-claimed-data-leak-told">
    <title>Provide hacker details, outfit that claimed data leak told</title>
    <link>https://cis-india.org/internet-governance/news/the-times-of-india-mahendra-singh-may-18-2017-provide-hacker-details-outfit-that-claimed-data-leak-told</link>
    <description>
        &lt;b&gt;The Unique Identification Authority of India (UIDAI), the regulatory authority for Aadhaar, has written to a Bengaluru-based research organisation, Centre for Internet &amp; Society (CIS), seeking details about a suspected hack attack on government websites that led to the leak of information about 13 crore users.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by Mahendra Singh was &lt;a class="external-link" href="http://timesofindia.indiatimes.com/india/provide-hacker-details-outfit-that-claimed-data-leak-told/articleshow/58725132.cms"&gt;published in the Times of India&lt;/a&gt; on May 18, 2017.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;In a recent report, CIS had highlighted that websites run by various  government departments, owing to a poor security framework, had publicly  displayed sensitive personal financial information and Aadhaar numbers  of beneficiaries of certainprojects.   &lt;br /&gt; &lt;br /&gt; In its letter, UIDAI argued that the data downloaded from one of the  websites could not have been accessed unless the website was hacked. As  hacking is a grave offence under the law, the UIDAI has asked CIS to  provide details of the persons involved in the data theft.   &lt;br /&gt; &lt;br /&gt; According to a source, the UIDAI said that access to data on the  website for the 'National Social Assistance Program' was only possible  for someone in possession of authorised login details, or if the site  (http://nsap.nic.in) was hacked or breached. The UIDAI said in its  letter that such illegal access was against the provisions of the  Aadhaar Act, 2016, and the IT Act, 2000, and that the persons involved  had committed a grave offence.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Asking the CIS to reply before May 30, the UIDAI also said, "Aadhaar system is a protected system under Section 70 of the IT Act, 2000, the violation of which is punishable with rigorous imprisonment for a period up to 10 years." It added that the penalty clauses for violations are also provided in Section 36, Section 38 and Section 39 of the Aadhaar Act.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The UIDAI, however, maintained that even if the Aadhaar details were known to someone it did not pose a real threat to the people whose information was publicly available because the Aadhaar number could not be misused without biometrics.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The UIDAI letter said, "While, as your report suggests, there is a need to strengthen IT security of government websites, it is also important that the persons involved in hacking such sensitive information are brought to justice for which your assistance is required under the law."&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;"Your report mentions 13 crore people's data has been 'leaked'. Please specify how much of this data had been downloaded by you or are in your possession or in the possession of any other persons that you know. Please provide the details," the UIDAI added in its letter. The UIDAI also urged CIS to provide the details of the persons/organisations with whom it shared the data, if it did.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/the-times-of-india-mahendra-singh-may-18-2017-provide-hacker-details-outfit-that-claimed-data-leak-told'&gt;https://cis-india.org/internet-governance/news/the-times-of-india-mahendra-singh-may-18-2017-provide-hacker-details-outfit-that-claimed-data-leak-told&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-06-07T12:14:13Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/deccan-herald-may-11-2017-plug-data-leak-before-imposing-aadhaar">
    <title>Plug data leak before imposing Aadhaar</title>
    <link>https://cis-india.org/internet-governance/news/deccan-herald-may-11-2017-plug-data-leak-before-imposing-aadhaar</link>
    <description>
        &lt;b&gt;As the Central government continues to expand the scope and boundaries of the applicability of Aadhaar, the unique identification number, even before the Supreme Court’s verdict on its constitutional validity, reports suggesting that millions of Aadhaar numbers may have been leaked deliberately or inadvertently are a matter of grave concern.&lt;/b&gt;
        &lt;p&gt;The article was published in the &lt;a class="external-link" href="http://www.deccanherald.com/content/611047/plug-data-leak-imposing-aadhaar.html"&gt;Deccan Herald&lt;/a&gt; on May 11, 2017.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;The Centre for Internet and Society, a Bengaluru-based organisation, has  claimed that close to 135 million Aadhaar numbers and 100 million bank  account numbers have been exposed by government portals dealing with  pension, social welfare and employment guarantee schemes. The report  says that with Aadhaar being used or planned to be used for  authenticating and authorising several transactions, the financial risks  of the disclosure of such data are greatly exacerbated. Virtually  confirming that some ‘over-enthusiastic’ government agencies have been  making the Aadhaar data public, Aruna Sundararajan, secretary, Union  Electronics and Information Technology Ministry, has said that the  Centre is in the process of ‘educating officials’ about the sanctity of  the material collected, besides drafting amendments to the Information  Technology Act to ensure data protection and secrecy. That’s indeed a  late realisation, and hopefully, not a case of locking the stables once  the horses have bolted.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The Supreme Court is also rightly concerned about the invasion of a citizen’s body in obtaining fingerprints and iris impressions for Aadhaar and the violation of an individual’s privacy. Attorney General Mukul Rohatgi raised several eyebrows by arguing that “citizens don’t have an absolute right over their own bodies” and there was nothing illegal about obtaining biometric details. He may be legally right, but as the court pointed out, it is the duty of the state to maintain the liberty and dignity of all individuals. As almost 98% of the population has already been covered by Aadhaar, the question of privacy is now more academic, though making Aadhaar mandatory for the filing of income tax along with PAN card is not. As the government is unable to come to grips with millions of benami transactions and largescale evasion of income tax in the country, if the linking of Aadhaar is going to bring down such cases, it needs to be welcomed.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;However, Aadhaar is not a magic bullet that has a solution for every problem. The government shoulddrop the idea of making it mandatory for social welfare programmes such as children availing midday mealsin schools, supply of nutrition under ICDS programme and provision of scholarship for the disabled. The government certainly has a responsibility to prevent misuse of the schemes, while making sure that welfare measures are not denied to the needy on technical grounds.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/deccan-herald-may-11-2017-plug-data-leak-before-imposing-aadhaar'&gt;https://cis-india.org/internet-governance/news/deccan-herald-may-11-2017-plug-data-leak-before-imposing-aadhaar&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-17T02:10:37Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/medianama-vivek-pai-may-4-2017-indian-govt-says-it-is-still-drafting-privacy-law">
    <title>Indian Government says it is still drafting privacy law, but doesn’t give timelines</title>
    <link>https://cis-india.org/internet-governance/news/medianama-vivek-pai-may-4-2017-indian-govt-says-it-is-still-drafting-privacy-law</link>
    <description>
        &lt;b&gt;&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;Read the original published by Medianama &lt;a class="external-link" href="http://www.medianama.com/2016/05/223-government-privacy-draft-policy/"&gt;here&lt;/a&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;The Government is drafting a legislation to protect privacy of  individuals breached through unlawful means in consultation with  stakeholders, the minister for communications and information technology  Ravi Shankar Prasad &lt;a href="http://164.100.47.234/question/annex/239/Au706.pdf"&gt;said&lt;/a&gt; in the Rajya Sabha. However, no timeline was provided, which is really  the problem: Is the Indian government even interested in a privacy law?&lt;/p&gt;
&lt;ul style="text-align: justify; "&gt;
&lt;li&gt;In August last year, the Government of India had said in the Supreme Court of India that had said that “&lt;a href="http://www.medianama.com/2015/08/223-privacy-india-aadhaar/"&gt;violation of privacy doesn’t mean anything because privacy is not a guaranteed right”&lt;/a&gt;, actually arguing that the citizens of India do not have a fundamental right to privacy.&lt;/li&gt;
&lt;li&gt;In September last year, the DeitY had also sought to make encryption (and personal and business security) weaker via a &lt;a href="http://www.medianama.com/2015/09/223-india-draft-encryption-policy/"&gt;draft policy on encryption&lt;/a&gt;,  requiring all users to store the plaintexts of the corresponding  encrypted information for 90 days from the date of transaction and  provide the verifiable plain-text to Law and Enforcement Agencies if  required. After a public outcry, the paper was &lt;a href="http://www.medianama.com/2015/09/223-draft-national-encryption-policy-paper-withdrawn-says-telecom-minister-r-s-prasad/"&gt;withdrawn&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Last month, the DoT made it &lt;a href="http://www.medianama.com/2016/04/223-dot-mandatory-gps-panic-button/"&gt;mandatory&lt;/a&gt; to have GPS on all phones by 2018.&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="text-align: justify; "&gt;We’re in a situation where the country doesn’t have a privacy law on  one hand, and is setting up surveillance systems like the Centralized  Monitoring System, NETRA, NATGRID (for collecting data from across  databases), and linking citizens and databases across the unique  identity number in Aadhaar on the other.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;What happened to the old Privacy bill?&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;While India does not yet have a comprehensive privacy policy, back in  2014, the Centre for Internet and Society received a leaked version of  the draft Privacy Bill 2014 that the Department of Personnel and  Training, Government of India had drafted. A comparison of the draft  bill from 2014 and the draft privacy bill of 2011 can be found &lt;a href="http://www.medianama.com/2014/04/223-leaked-privacy-bill-2014-vs-2011-cis-india/"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;As per Prasad, as of now, the Section 43, 43A and 72A of the IT Act  of 2000 provide the legal framework for digital privacy and security,  mandating that agencies collecting personal data must provide a privacy  policy, and compensations must be paid to the victim in case of  unauthorized access or leakage of information.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;span class="message_body"&gt;&lt;b&gt;Questions asked in Rajya Sabha&lt;/b&gt;: &lt;/span&gt;&lt;/p&gt;
&lt;blockquote style="text-align: justify; "&gt;
&lt;p&gt;&lt;span class="message_body"&gt;Whether Government  intends   to  bring  a  specific  legislation  to  address  the  concerns  regarding privacy in the country, if so, the details thereof, if not,  the reason therefore; and &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span class="message_body"&gt;Whether the legislation would provide for  protection of ‘personal data’ along the lines of the European Union’s  Data Protection Directive, if so, the details thereof, if not, the  reasons therefor&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;EU Privacy Bill&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Interestingly, the question posed to the minister asked if the  legislation would provide for protection of personal data along the  lines of European Union’s General Data Protection Directive (GDRP),  which were approved just &lt;a href="http://www.allenovery.com/publications/en-gb/data-protection/Pages/Timetable.aspx"&gt;last month&lt;/a&gt;.  EU’s directive defines “any information relating to an identified or  identifiable natural person directly or indirectly, in particular by  reference to an identification number or to one or more factors specific  to his physical, physiological, mental, economic, cultural or social  identity”, as personal data.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The GDRP has a pretty wide scope and is pretty consumer friendly. The  laws require users to provide explicit consent for data collection,  companies to report as soon as they have a data breach, and a ‘right to  erasure’ that lets users request all personal data related to them to be  deleted. It also imposes a significant fine of up to 4% of annual  worldwide turnover of a company in the previous financial year, in case  of non compliance. For a comprehensive overview of the policy read  handbook on European data protection law (&lt;a href="http://www.echr.coe.int/Documents/Handbook_data_protection_ENG.pdf"&gt;pdf&lt;/a&gt;).&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;Email privacy bill US&lt;/b&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The US does not have a comprehensive digital privacy law like the EU  and mostly relies on the the privacy act of 1974. However, recently the  US House of Representatives &lt;a href="https://nakedsecurity.sophos.com/2016/04/29/us-house-unanimously-passes-email-privacy-act/"&gt;unanimously passed the Email Privacy Act&lt;/a&gt; that would require investigators to get a warrant before forcing  companies to hand over customer email or other electronic  communications, no matter how old the communication.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/medianama-vivek-pai-may-4-2017-indian-govt-says-it-is-still-drafting-privacy-law'&gt;https://cis-india.org/internet-governance/news/medianama-vivek-pai-may-4-2017-indian-govt-says-it-is-still-drafting-privacy-law&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-15T02:10:26Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/events/meeting-on-proactive-disclosure-and-personal-data-delhi-may-13">
    <title>Meeting on Proactive Disclosure and Personal Data (Delhi, May 13, 5:30 pm)</title>
    <link>https://cis-india.org/internet-governance/events/meeting-on-proactive-disclosure-and-personal-data-delhi-may-13</link>
    <description>
        &lt;b&gt;CIS is organising an informal discussion on topics related to proactive disclosure and personal data thrown up by the recently published report by Amber Sinha and Srinivas Kodali titled "Information Security Practices of Aadhaar (or lack thereof)". Please join us at 5:30 pm today, May 13, at the CIS office.&lt;/b&gt;
        
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h4&gt;Read the report: &lt;a href="http://cis-india.org/internet-governance/information-security-practices-of-aadhaar-or-lack-thereof-a-documentation-of-public-availability-of-aadhaar-numbers-with-sensitive-personal-financial-information-1"&gt;PDF&lt;/a&gt;&lt;/h4&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;&lt;strong&gt;Location&lt;/strong&gt;&lt;/h3&gt;
&lt;iframe src="https://www.google.com/maps/embed?pb=!1m18!1m12!1m3!1d876.157470894426!2d77.20553462919722!3d28.550842498903158!2m3!1f0!2f0!3f0!3m2!1i1024!2i768!4f13.1!3m3!1m2!1s0x0%3A0x834072df81ffcb39!2sCentre+for+Internet+and+Society!5e0!3m2!1sen!2sin!4v1493818109951" frameborder="0" height="450" width="600"&gt;&lt;/iframe&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;

        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/events/meeting-on-proactive-disclosure-and-personal-data-delhi-may-13'&gt;https://cis-india.org/internet-governance/events/meeting-on-proactive-disclosure-and-personal-data-delhi-may-13&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>sumandro</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Privacy</dc:subject>
    
    
        <dc:subject>Open Data</dc:subject>
    
    
        <dc:subject>Open Government Data</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Public Accountability</dc:subject>
    

   <dc:date>2017-05-13T04:32:41Z</dc:date>
   <dc:type>Event</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/los-angeles-times-shashank-bengali-may-12-2017-india-is-building-a-biometric-database-for-1.3-billion-people-and-enrollment-is-mandatory">
    <title>India is building a biometric database for 1.3 billion people — and enrollment is mandatory</title>
    <link>https://cis-india.org/internet-governance/news/los-angeles-times-shashank-bengali-may-12-2017-india-is-building-a-biometric-database-for-1.3-billion-people-and-enrollment-is-mandatory</link>
    <description>
        &lt;b&gt;Inside the buzzing enrollment agency, young professionals wearing slim-fitting jeans and lanyards around their necks tapped away at keyboards and fiddled with fingerprint scanning devices as they helped build the biggest and most ambitious biometric database ever conceived.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by Shashank Bengali was published in the &lt;a class="external-link" href="http://www.latimes.com/world/la-fg-india-database-2017-story.html"&gt;Los Angeles Times&lt;/a&gt; on May 12, 2017.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;Into the office stepped Vimal Gawde, an impoverished 75-year-old widow  dressed in a floral print sari. She had come to secure her ticket to  India’s digital future — to enroll in the identity program, called  Aadhaar, or “foundation,” that aims to record the fingerprints and  irises of all 1.3 billion Indian residents.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Nearly 9 out of 10 Indians have registered, each assigned a  unique 12-digit number that serves as a digital identity that can be  verified with the scan of a thumb or an eye. But Gawde came to the  enrollment office less out of excitement than desperation: If she didn’t  get a number, she worried that she wouldn’t be able to eat.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Designed  as a showcase of India’s technological prowess — offering identity  proof to the poor and reducing waste in welfare programs — Aadhaar’s  grand promises have been muddied by controversy as the government makes  enrollment mandatory for a growing number of essential services.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Indians  now need an Aadhaar number to pay taxes, collect pensions and obtain  certain welfare benefits. The rapid expansion of a program that was  originally described as voluntary has sparked criticism that India is  vacuuming up citizens’ personal information with few privacy safeguards  and creating hardship for the very people the initiative was supposed to  help.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Like many Indians living in poverty, Gawde uses a  ration card to purchase her monthly allotment of subsidized rice and  cooking gas. But the shopkeeper told her that starting next month, he  would sell to her only if she produced an Aadhaar number.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;She  had visited the enrollment agency three times but had yet to be  approved, for reasons she did not understand. (Enrollment agents would  not comment on individual cases.)&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Reaching into her  canvas bag, Gawde pulled out the familiar panoply of documents — ration  card, voter card, electricity bill, income tax ID — that Indians use to  navigate a dizzying bureaucracy. Aadhaar, she was told, would supplant  all these papers.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;But she had to get the number first.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“I’m  nervous,” Gawde said outside the enrollment office on a sweltering  morning. “I first applied three years ago and submitted all my  documents, but didn’t follow up. Now that it’s becoming compulsory, I’m  doing everything I can to get it.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Indian  Prime Minister Narendra Modi, who had criticized Aadhaar as a  “political gimmick” before he took office, has embraced the futuristic  idea of an all-in-one digital identity. His party pushed through a law  last year that paved the way for a dramatic expansion of Aadhaar,  allowing&lt;b&gt; &lt;/b&gt;government entities and private businesses  wide latitude to access the database, which collects not just people’s  names and birth dates but also phone numbers, email addresses and other  information.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Soon, as more private companies use the  database, it could become difficult to open a bank account, get a new  cellphone number or buy plane or train tickets without being enrolled.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Supporters  say the program, which has cost about $1 billion to implement, will  save multiples of that by curbing tax evasion and ensuring that welfare  subsidies are not stolen by middlemen.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“Aadhaar was  always meant to be an instrument of inclusion,” Nandan Nilekani, a tech  billionaire and the program’s first chairman, said in an interview. “I’m  really happy that the current government is completely endorsing  Aadhaar and using it for a wide variety of services that will transform  governance.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Nilekani calls Aadhaar “hugely empowering” for the poor, but&lt;b&gt; &lt;/b&gt;not long ago even he &lt;a href="http://www.thehindu.com/todays-paper/AADHAR-not-mandatory-says-Nilekani/article16034138.ece"&gt;argued&lt;/a&gt; that enrollment&lt;b&gt; &lt;/b&gt;should  remain optional so that no Indians were prevented from accessing  essential services. India’s Supreme Court agreed, ruling in 2015 that  the government could not require Aadhaar for any benefit to which a  person was otherwise entitled, as long as they could prove their  identity by some other means.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Yet the court has stayed silent as Aadhaar creeps into every facet of Indian life, even for children.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;A  12-year-old girl named Saiba is a case in point. After the girl’s  grandmother passed away in their family’s ancestral village in northern  India, Saiba’s mother moved her and her four siblings to a crowded  neighborhood on the rough fringes of New Delhi, near a car parts market  thick with the smell of grease.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;When Saiba’s mother,  Rani, went to the local school in April to register her for the sixth  grade, administrators turned her down, saying every student must have an  Aadhaar number.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;But to get a number, a child usually  needs a birth certificate — and like one-quarter of children born in  this country, Saiba and her siblings did not have them because their  village did not routinely register births.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Sitting with  her mother in the cramped offices of the local advocacy group  Pardarshita, above a noisy street lined with vegetable sellers, the girl  puffed her round cheeks in an expression of helplessness.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“I don’t know anything about this,” said Saiba, who, like many Indians, has only one name. “I just want to go to school.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Rakesh Thakur, a board member of Pardarshita, is trying to obtain Aadhaar numbers for&lt;b&gt; &lt;/b&gt;dozens  of children barred from Delhi schools. He called the policy “a clear  violation” by the municipal government of both the Supreme Court order  and India’s Right to Education Act, which guarantees every child younger  than 14 free schooling.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;A Twitter account called  “Rethink Aadhaar” logs new instances almost daily of Indians who have  suffered because scanners couldn’t read their fingerprints or because of  errors in the database.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;In  Jawhar, a forested zone about 60 miles north of Mumbai, administrators  have told local tribal communities that they will soon use Aadhaar to  distribute welfare rations and school lunches. But the area lies outside  cellphone range, leading residents to wonder how scanners will connect  to the Internet to verify their identities.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“The idea of  Aadhaar and the technology may be good, but do we have the  infrastructure to make it mandatory?” said Vivek Pandit, a former  lawmaker who runs a nonprofit group in the area. “The law is  city-centric, and it would only lead to the social exclusion of rural  India.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;This month lawyers opposing Aadhaar argued before  the Supreme Court that the government could not force Indians to share  their biometric data. Atty. Gen. Mukul Rohatgi countered that Indians  had no constitutional right to privacy and could not claim an “absolute  right” over their bodies.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Without privacy protections, activists worry that as Aadhaar numbers are linked to more and more services, intelligence agencies could use the database to more easily track Indians’ calls, travels and purchases.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“It’s become very clear that this is not a project about the  poor,” said Usha Ramanathan, a lawyer and anti-Aadhaar activist. “The  government’s ambitions have gotten greater over time.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;This month, the Center for Internet and Society, a New Delhi think tank, &lt;a href="http://cis-india.org/internet-governance/information-security-practices-of-aadhaar-or-lack-thereof-a-documentation-of-public-availability-of-aadhaar-numbers-with-sensitive-personal-financial-information-1" target="_blank"&gt;reported&lt;/a&gt; that federal and state agencies had published up to 135 million Aadhaar  numbers — some including sensitive information such as a person’s caste  and religion, or details of pension payments — on unsecured websites  accessible through just a few clicks.&lt;/p&gt;
&lt;p class="callout" style="text-align: justify; "&gt;&lt;span class="trb_pullquote_text"&gt;It’s become very clear that this is not a project about the poor.&lt;/span&gt; &lt;span class="trb_pullquote_credit"&gt;— Usha Ramanathan, a lawyer and anti-Aadhaar activist&lt;/span&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Pranesh Prakash, the center’s policy director, said that  when Indian authorities can’t even keep Aadhaar numbers private, as the  law requires, it suggests the entire database is vulnerable —  particularly after sensitive information involving 22 million Americans  was exposed when federal databases were &lt;a href="http://www.latimes.com/nation/la-na-government-personnel-hack-20150709-story.html"&gt;hacked&lt;/a&gt; in 2015.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“When  these kinds of leaks are happening, it’s rather foolhardy to maintain a  database of 1.2 billion people’s biometrics, because once this gets  breached, it becomes completely unusable,” Prakash said.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“If your PIN number or password leaks, you can change it. You can’t change your fingerprints.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Praveen  Chakravarty, a former investment banker who worked with Nilekani to  launch Aadhaar, believes the lack of safeguards undermines the project’s  ideals of efficiency and empowerment. He said many Indians were right  to worry that Modi’s government, which has cracked down on &lt;a href="http://www.latimes.com/world/asia/la-fg-india-crackdown-greenpeace-20150113-story.html"&gt;political activists&lt;/a&gt; and &lt;a href="http://www.latimes.com/world/la-fg-india-charity-2017-story.html"&gt;nonprofit groups&lt;/a&gt; it opposes, could use Aadhaar to snoop on citizens.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“Maybe  Aadhaar didn’t need to be this big,” Chakravarty said, adding that the  government could simply have worked to fix inefficiencies in individual  welfare programs.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“People could ask, ‘Did we need this at all?’” he said. “It’s a good question.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;For  Gawde, the widow, Aadhaar remained an idea of the future. She left the  enrollment agency that day empty-handed, told by a young employee that  her number had not been assigned. But she retained hope that the new ID  would make life easier.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“We are just poor people,” she said. “We have to trust what the government tells us.”&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/los-angeles-times-shashank-bengali-may-12-2017-india-is-building-a-biometric-database-for-1.3-billion-people-and-enrollment-is-mandatory'&gt;https://cis-india.org/internet-governance/news/los-angeles-times-shashank-bengali-may-12-2017-india-is-building-a-biometric-database-for-1.3-billion-people-and-enrollment-is-mandatory&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Aadhaar</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2017-05-12T16:22:35Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>




</rdf:RDF>
