Like when Intel's chips were shown to completely disregard security when speculatively executing instructions, it wasn't just a new vulnerability; it was a whole class of vulnerabilities that was now open
The client here is the enrollment software, not "Aadhar" (whatever you meant by that). The Aadhar service should haven been authenticating enrollment operators on the server side, instead of relying on the enrollment software to verify identity (that too by via biometrics, which is NOT authentication).
this is an attitude a system designer should have, allways be on lookout of vulnerabilities.
if media starts writing articles on would be vulnerabilities, then it is just fear mongering.
But if my bank is widely reported to be hacked, my trust in it would degrade. And I would probably not trust it with any more of my money. A lot also rides on how the bank responds to this in public.
>> this is an attitude a system designer should have, allways be on lookout of vulnerabilities.
Agree, but that is besides the point here.
>>if media starts writing articles on would be vulnerabilities, then it is just fear mongering.
This is something which has occurred, it's not "would be".