HCL and HP named in unflattering audit of India’s biometric ID system
- Reference: 1649746632
- News link: https://www.theregister.co.uk/2022/04/12/aadhaar_uadai_audit/
- Source link:
The Authority (UADAI) oversees “Aadhaar” – a twelve-digit ID issued as a national identity number. Aadhaar is essential to access government services but can also be used by third parties – banks and mobile carriers use it to verify the identity of applicants for new accounts. UADAI arranges for collection of the biometrics needed to create an Aadhaar - ten fingerprints, two iris scans, and a facial photograph – through enrollment agencies and registrars and provides authentication-as-a-service using Aadhaar numbers.
More than a billion Aadhaar IDs have been issued and over 99 per cent of India adults have enrolled in the scheme.
Aadhaar lacked a data archiving policy
The [1]audit report found plenty of problems with the project, among them around 475,000 Aadhaars with the same biometric data used to describe different people. De-duplication efforts proved so poor that staff reverted to manual processes to address the problem. Many Aadhaar ID cards didn’t work as a result – attempts to authenticate users failed.
Infosec types never tire of pointing out that an entity’s security is only as good as its partners’. Yet UIDAI “did not carry out verification of the infrastructure and technical support” of organisations that sought to join its third-party ecosystem. The audit found that UAIDI was lax in requiring participants to complete security checks – which is problematic because that left the organisation unsure of devices used to capture biometrics conformed to its security requirements.
[2]
Whatever devices were used, capture of biometrics was often ineffective and some of the resulting data was unusable. Other biometric data captured but not paired to any person.
[3]
[4]
Third-party users of Aadhaar-as-a-service were not billed – despite revenue raising being an integral part of UAIDI’s mission.
UAIDAI also lacked a data archiving policy for several years. The audit explains the rudiments of tiered storage and the very good reasons to retire some data and points out that the organization therefore cost itself money and may have created compliance problems.
[5]Sri Lanka to adopt India’s Aadhaar digital identity scheme
[6]India uses controversial Aadhaar facial biometrics to identify COVID vaccination recipients
[7]India makes buying a used cow easier than buying a used car
At this point readers may be wondering who ran UAIDI’s technology, because not archiving data or checking stakeholder security suggests they did not do it brilliantly.
The answer is HCL – the Indian services giant was awarded a contract to manage UAIDI tech in 2012 and still has a role today.
[8]
The audit report found the company selected the provider of Automatic Biometric Identification Systems, but service levels were not met – possibly the reason for duplicate Aadhaar numbers and the other messes mentioned above.
UAIDI chose not to penalize HCL for those failures, and even restructured contracts so it could waive requirements to seek liquidated damages.
HP’s role in the mess was providing a document management system that stored Aadhaar enrolment data digitally and on paper but was plagued by inconsistent data delivery that saw the creation of many incomplete records.
[9]
The audit concludes that the failure to enforce security standards across the Aadhaar ecosystem means the scheme poses a privacy risk to Indians, while waiving penalties to underperforming suppliers sent the message that sub-standard work was acceptable.
The document concludes with a strong recommendation that UAIDI take heed of the recommendations in the audit – especially those pertaining to information security.
Get our [10]Tech Resources
[1] https://cag.gov.in/en/audit-report/download/116042
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YlVN1c1@c6X14bEYfCzzegAAAAE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YlVN1c1@c6X14bEYfCzzegAAAAE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YlVN1c1@c6X14bEYfCzzegAAAAE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2022/02/09/sri_lanka_to_adopt_indias/
[6] https://www.theregister.com/2021/04/09/india_facial_id_covid_vaccinations/
[7] https://www.theregister.com/2020/09/11/india_launches_cowmart_app_to/
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YlVN1c1@c6X14bEYfCzzegAAAAE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YlVN1c1@c6X14bEYfCzzegAAAAE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[10] https://whitepapers.theregister.com/
Re: should have chosen ............
UAIDI chose not to penalize[sic] HCL for those failures, and even restructured contracts so it could waive requirements to seek liquidated damages.
Here's a bit of the problem...
I have the solution
Give the contract to Capita.
I'm sure that'll work out fine.
Re: I have the solution
And get Dido Harding in to lead the project too...
Fingerprints
You know how everyone's fingerprints are totally unique, right?
Yeah, actually not so much. That's a bit of 19th century science that worked well enough when you were comparing fingerprints from a few hundred or even thousands of records. But it's only very recently that we've started to record them by the tens of millions. And in that use scenario, it turns out there's a very high chance of misidentifying people.
We need to stop thinking of fingerprints as the gold standard of positive ID.
I don't know what the story is with iris scans, but I wouldn't be surprised if it's similar.
At this point readers may be wondering who ran UAIDI’s technology, because not archiving data or checking stakeholder security suggests they did not do it brilliantly.
The answer is HCL – the Indian services giant was awarded a contract to manage UAIDI tech in 2012 and still has a role today.
Sounds like HCL didn't use an ACID-compliant database
should have chosen ............
complex government requested IT project gone wrong and the vendors profited handsomely, where have we seen that before?
prospective buyers, of outsourced services, beware!!