Honest question: how much does this matter?
For instance, I believe in Denmark your ID number is simply not a secret at all, no more than your name. While in the US, your SSN & address basically seems to let any crook empty your bank account.
Honest question: how much does this matter?
For instance, I believe in Denmark your ID number is simply not a secret at all, no more than your name. While in the US, your SSN & address basically seems to let any crook empty your bank account.
Since paper-aadhaar is still very much accepted as a proof, just having the number is enough (in many cases) to take over someone's identity and get a new SIM issued, which you can then use for emptying the bank account.
There are also phishing scams happening with Aadhaar since it uses OTP as the authentication factor. We have OTPs as 2FA for bank transactions, and it works because the first factor is still secret (credit card number or your banking credentials). However, if your first factor is your Aadhaar number, the security goes down tremendously, since every organization under the sun is now asking your Aadhaar.
I'm tempted to wardrive Aadhaar OTPs sent over unencrypted SMS.
Can you forge one with MS Word or is it somehow more secure than that?
Weird. Maybe it's different from state to state or probably area to area. Atleast where I reside (Telangana), getting a new SIM requires fingerprint authentication followed by SMS OTP to an existing mobile number. If you do not have an existing number linked to Aadhaar, only then a fingerprint scan would suffice. I have also opened a bank account here following the same procedure. I had to get one number ported and that required multiple authentication too.
What do you mean by unencrypted SMS. How do you sms is unencrypted?
Add to this that the legal encryption limit for GSM is India is just 40 bits and you can easily wardrive SMSs
The known attacks I have come across in India include the hacker somehow coming across your sim card number and using that to get a new sim card issued in your name. A lot of people have had their bank accounts drained this way (source: social media posts)
There was another thread in an yesterday on this where someone mentioned they could just rent a cell tower in Malaysia at $10 an hour and broadcast your number as roaming there to get your messages. Also mentioned were mobile number porting attacks though I don't know how viable that would be in India.
There are so many apps with the permission to read your messages on Android. I wonder how many of these upload your messages to the cloud. An attacker could simply get the OTP from there. By creating a malicious app or attacking the database of another app uploading your messages. Also possibly your sim card number which I have seen apps broadcasting in the open, unencrypted.
Another scenario - let's say you have a prepaid connection. You go abroad on a vacation without this number or get sick or whatever, and forget to recharge your phone. The provider can stop your services and give your sim to a new user. The new user now gets all your OTPs.
There are probably more attacks. Messages to your phone are just not a safe choice for 2-factor authentication, but sadly that is the base on which aadhar is built upon. Even today one can open a bank account with just an aadhar number and an OTP. Wait till people start taking loans in others' names.
I dont know how people are ok with Aadhar. Recently the aadhar data of widows in Delhi was leaked. You can find their address and various details.
I've been to the local than to register a cyber crime. Their words: "You are lucky you lost only a few tens of thousands of RS. People are losing lakhs and the Cyber cell cant help them."