I/II.
https://thewire.in/120922/aadhaar-supreme-court-uid/

Without Supreme Court Interference, the Aadhaar Project is a Ticking Time Bomb
BY USHA RAMANATHAN ON 04/04/2017

The court must hear pending cases on Aadhaar urgently, before the
government further inhibits people’s rights and liberties under the
facade of ’empowerment’.

George Mikes, who travelled to write about people and how they lived,
described seeing a production of The Earth Spider at the Kabuki
theatre in Japan. It is enough, for our purpose, to know that the
Earth Spider was the villain and that a host of supporters of the
protagonist set out to challenge it. What follows is a tale of
“tremendous excitement, expressed by the fact that they all sit about
quietly, almost motionless. They repeat: ‘Let us hurry, let us gallop.
We have not a moment to lose!’ Whereupon they all go on sitting
there.” Three men move about the stage declaring that “everything
depends on speed” and they, “still motionless”, proclaim, “Let us not
spare ourselves! … We have a sacred duty to perform.” More pursuers
arrive on stage, all say that there cannot be a moment’s rest, and sit
down. The show keeps going for a long time, till finally, tired of
waiting for the promised life-and-death combat, the Earth Spider
emerges from the cave where he had hidden himself in plain sight,
dances to gain attention and, receiving none, collapses and dies.

It is possible that, given the enormous porosity and magnitude of
untried technologies being deployed in the unique identification (UID)
project, it too may crumble or implode, not very differently from the
Earth Spider. But, by then, many systems may be destroyed which will
be difficult to resurrect, many vulnerabilities created, many people
made into ghosts and duplicates, and many a problem erected as
testimony to a project that should never have been. As we get closer
to that possibility, the court has spoken once, twice, six times, even
a seventh time in September 2016, to check, restrict and contain the
Earth Spider UID project. But the Earth Spider project will allow no
law, absence of a law or order from the apex court to cramp its
exuberance and ambition.

If the Supreme Court defers, delays or waits for the perfect moment in
hearing the Aadhaar cases pending before it, we could be left with
constitutional redundancy, threatening axioms such as these with an
early demise:

The constitution is not about the power of the state, but about the
limits of the power of the state over the people.
There can be no waiver of fundamental rights.
Colonialism produced subjects; freedom made citizens of erstwhile subjects.
The court is a bulwark against the erosion of the rights of the people.
It is the state that is to be transparent to the people; not the
people to the state.
Surveillance is a violation of the personal liberty of the people, and
the exception proves the rule.
There is more in this catalogue which will have to be explored and
debated in court.

Counting the changes

Even as challenges have been pending in court, the focus of the
project has shifted from the citizen to the resident, and from the
resident to the customer. Initially, the Unique Identification
Authority of India (UIDAI) was set up to help standardise data
elements in the various governmental databases and assist in their
digitisation. The empowered group of ministers who met to decide the
contours of the UIDAI were clear in their instruction: “UIDAI may not
directly undertake creation of any additional database…” When the
National Population Register (NPR) was started, that is how enrolment
was to be done.

However, soon after Nandan Nilekani took charge in July 2009, the
rules were changed. The then prime minister, Manmohan Singh,
constituted a cabinet committee on the UID which gave Nilekani
permission to do ten crore enrolments. That was increased to 20 crore,
at which stage the home ministry raised objections to the insecure
manner in which people were being enrolled in the UID database and the
unverified acceptance of documents that was part of this process. In
January 2012 the conflict came to a head, and was strangely resolved
by the Registrar General of India and the UIDAI sharing the country’s
population 50-50. How the concerns of the home ministry were dealt
with was not explained; we only know that it was at the intervention
of the prime minister. There was a further stand-off between the two
agencies, where too the compromise was brokered by the PM.

In the run-up to the 2014 elections, Narendra Modi, Arun Jaitley and
Ananth Kumar canvassed for the scrapping of the UID project if they
came to power. In May 2014, home minister Rajnath Singh was reported
to have taken the decision to go on with enrolling citizens for the
NPR, and perhaps to amalgamate the UID database with the NPR database,
after verification. That changed, inexplicably, in July, following a
meeting between Nilekani and the newly-elected prime minister,
Narendra Modi, and the UID project was restarted with unrestrained
enthusiasm. All we have as explanation is Jaitley’s statement in the
Rajya Sabha, where he said, “Earlier, some of us had doubts over
Aadhaar…Some of your people (in Congress) also had doubts. Later, a
presentation was made to the prime minister where the doubts were
cleared.”

The last nail in the coffin came in April 2016, after the Aadhaar Act
had been passed by the Lok Sabha as a money Bill. A long-drawn battle
over biometrics between the UIDAI and the CBI culminated in the Act of
2016 declaring that biometrics would not be shared by the UIDAI at all
– not if national security demands it, nor if a court orders it
(sections 27, 33). There is also no access to one’s own ‘core
biometrics’ (all biometrics other than the photograph) (section 28(5)
proviso). Relying on this clause, the UIDAI has declared that they
will not share the biometric database with the Registrar General of
India to construct the NPR. Last heard, the home ministry has been
advised to seek the attorney general’s advice on the sourcing of
biometric data from the UIDAI database; else the RGI faces the
prospect of collecting, all over again, the biometrics of 70 crore
people!

A hundred crore people were enrolled before the definition of a
‘resident’ entered the law, so what is the value of the database as
even a database of ‘residents’? Plainly, it does not matter. Because
the game has already moved on – from the ‘resident’ to the ‘customer’.
It is now the UIDAI’s database that is forming the basis of all
governmental intervention. This is apparently a resident database –
except it is not even that. The Aadhaar Act 2016 defines as a resident
“an individual who has resided in India for a period or periods
amounting in all to one hundred and eighty-two days or more in the
twelve months immediately preceding the date of application for
enrolment”. What alibis does one need to establish that one has been
in the country for 182 days? Immigration stamps in passports may help
in demonstrating absence from the country, but presence? How do NRIs
get enrolled? Are there some exceptions to the rule that have been
notified? A hundred crore people were enrolled before this definition
entered the law and those enrolments are not being revisited, so what
is the value of the database as even a database of ‘residents’?
Plainly, it does not matter. Because the game has already moved on –
from the ‘resident’ to the ‘customer’.

When the project started, it was said that no information would leave
the database, no matter the destination. It was to be used only for
authentication. The UID was for people who were unable to access
governmental services because they have no means of identifying
themselves to the state. In the strategy overview document from 2010,
the phrase used is ‘Know Your Resident’. By the time of the Aadhaar
Act of 2016, the focus was on KYC – Know Your Customer. With e-KYC in
the Act, the database is to be used not only for authentication – not
just a yes or no answer – but the passing on of the data held by the
UIDAI to ‘requesting entities’. And, according to section 57, ‘any
corporate or person’ can use this database, decreed in a section that
carries the sub-heading ‘Act not to prevent use of aadhaar number for
other purposes under law’. Those uses have already swung into being:
Jio, TrustID, OnGrid and the multiple advertisements beaming into our
homes from banks, mobile phone companies and anyone else who is able
to make a plan to leverage this database for their purpose.

How did we get here? On what basis was policy made by the states and
the Centre? On September 28, 2010, a statement issued by 17 eminent
persons including Justice V.R. Krishna Iyer, Romila Thapar, S.R.
Sankaran, Upendra Baxi, Bezwada Wilson, Justice A.P. Shah and Aruna
Roy asked the government to pause and do what has to be done as a
prelude to a project with such potential consequences. There was, for
instance, no law. There was no feasibility study that investigated the
different contours of the project and so no study of what the project
would do to constitutional rights and liberties. It is, in fact, this
that caused the Parliamentary Standing Committee on Finance to say,
“The UID scheme has been conceptualised with no clarity of purpose and
leaving many things to be sorted out during the course of its
implementation; and is being implemented in a directionless way with a
lot of confusion.”

What to believe, with flip-flops like these?

How then did the central and state governments make policy decisions
around the UID project? What is on record is deeply disturbing.
Rajasthan’s affidavits to the court are audacious in the changes it so
easily adopts with such little explanation.

On September 23, 2013, the Supreme Court passed the first of many
orders saying that no one shall be denied any service to which they
are entitled only because they are not enrolled for a UID. Oil
marketing companies, the UIDAI and the central government rushed to
the court to ask that the stay be lifted. The court refused to oblige.
States then filed their papers in court. Round one: In a document
dated December 5, 2013, Hansraj Yadav, additional director (UID),
Department of Information Technology and Communication, said in an
affidavit that “the state of Rajasthan is unambiguously in favour of
implementation of UID scheme.” On that date, elections to the state
assembly had been held but the results were not declared yet, the
Congress was still in power in the state as well as in the Centre, and
the Centre was promoting the project.

Round two: Yadav’s second affidavit is dated February 10, 2014, by
which time the BJP had formed the government in the state and the
Congress was still in control in the Centre. This time round, the
state said that a citizenship card was more relevant than the UID,
especially since Rajasthan is a border state. Poor verification of
residents’ credentials was cause for concern for the state government;
they were concerned that poor delivery of Aadhaar numbers may result
in the denial of benefits to the poor, especially in rural areas.
Service delivery is the mandate of state governments and the project
produces problems for federalism. “Therefore, the Aadhaar scheme is
misconceived … UID scheme is clearly an infringement of the federal
structure and spirit of the constitution,” the affidavit said. The
software for biometrics is the property of L-1 Identity Solutions
Operating Company, which is licensed to the UIDAI, and states do not
have any control over it. This, the affidavit reads, is a “huge
security risk” and the state government has “strong reservation
against data not being transparently and fully shared with the
states”.

Round three: On October 15, 2015, a third affidavit was filed, again
by Yadav. By now, the government at the Centre was the BJP, which had
done a turnaround on the UID project, and BJP formed the government in
the state too. By this time, the government at the Centre had said to
the court that the people of this country do not have a right to
privacy and the court had passed its order dated August 11, 2015.
Various applications looking to expand the use of the UID beyond the
public distribution system and LPG subsidies, permitted by the court,
had been filed. This was one, and in this narration, the UID now
became the one tool of empowerment for the poor and rural dwellers.

These somersaults are on the record of the court. The non-application
of mind provides one more reason that the court needs to hear the
cases urgently.

Usha Ramanathan is a legal researcher.

This is the first in a series of articles on the UID that Usha
Ramanathan will be writing for The Wire.

II.
http://www.hindustantimes.com/india-news/what-s-really-happening-when-you-swipe-your-aadhaar-card-to-make-a-payment/story-2fLTO5oNPhq1wyvZrwgNgJ.html

Aadhaar marks a fundamental shift in citizen-state relations: From ‘We
the People’ to ‘We the Government’

Your fingerprints, iris scans, details of where you shop. Compulsory
Aadhaar means all this data is out there. And it’s still not clear who
can view or use it

Updated: Apr 03, 2017 12:34 IST
Pranesh Prakash
Hindustan Times

Until recently, people were allowed to opt out of Aadhaar and withdraw
consent to have their data stored. This is no longer going to be an
option.(Siddhant Jumde / HT Illustration)

Imagine you’re walking down the street and you point the camera on
your phone at a crowd of people in front of you. An app superimposes
on each person’s face a partially-redacted name, date of birth,
address, whether she’s undergone police verification, and, of course,
an obscured Aadhaar number.

OnGrid, a company that bills itself as a “trust platform” and offers
“to deliver verifications and background checks”, used that very
imagery in an advertisement last month. Its website notes that “As per
Government regulations, it is mandatory to take consent of the
individual while using OnGrid”, but that is a legal requirement, not a
technical one.

Since every instance of use of Aadhaar for authentication or for
financial transactions leaves behind logs in the Unique Identification
Authority of India’s (UIDAI) databases, the government can potentially
have very detailed information about everything from the your medical
purchases to your use of video-chatting software. The space for
digital identities as divorced from legal identities gets removed.
Clearly, Aadhaar has immense potential for profiling and surveillance.
Our only defence: law that is weak at best and non-existent at worst.


The Aadhaar Act and Rules don’t limit the information that can be
gathered from you by the enrolling agency; it doesn’t limit how
Aadhaar can be used by third parties (a process called ‘seeding’) if
they haven’t gathered their data from UIDAI; it doesn’t require your
consent before third parties use your Aadhaar number to collate
records about you (eg, a drug manufacturer buying data from various
pharmacies, and creating profiles using Aadhaar).

It even allows your biometrics to be shared if it is “in the interest
of national security”. The law offers provisions for UIDAI to file
cases (eg, for multiple enrollments), but it doesn’t allow citizens to
file a case against private parties or the government for misuse of
Aadhaar or identity fraud, or data breach.

It is also clear that the government opposes any privacy-related
improvements to the law. After debating the Aadhaar Bill in March
2016, the Rajya Sabha passed an amendment by MP Jairam Ramesh that
allowed people to opt out of Aadhaar, and withdraw their consent to
UIDAI storing their data, if they had other means of proving their
identity (thus allowing Aadhaar to remain an enabler).

Read more

Government admits Aadhaar was ‘great initiative’ of Congress regime

Over 1 billion Indians enrol for Aadhaar: How the govt plans to sign up the rest
But that amendment, as with all amendments passed in the Rajya Sabha,
was rejected by the Lok Sabha, allowing the government to make Aadhaar
mandatory, and depriving citizens of consent. While the Aadhaar Act
requires a person’s consent before collecting or using
Aadhaar-provided details, it doesn’t allow for the revocation of that
consent.

In other countries, data security laws require that a person be
notified if her data has been breached. In response to an RTI
application asking whether UIDAI systems had ever been breached, the
Authority responded that the information could not be disclosed for
reasons of “national security”.

The citizen must be transparent to the state, while the state will
become more opaque to the citizen.


HOW DID AADHAAR CHANGE?

How did Aadhaar become the behemoth it is today, with it being
mandatory for hundreds of government programmes, and even software
like Skype enabling support for it?

The first detailed look one had at the UID project was through an
internal UIDAI document marked ‘Confidential’ that was leaked through
WikiLeaks in November 2009. That 41-page dossier is markedly different
from the 170-page ‘Technology and Architecture’ document that UIDAI
has on its website now, but also similar in some ways.

Read more

MS Dhoni’s Aadhaar details leaked, wife Sakshi complains to Ravi Shankar Prasad

Journalist uses fake IDs to get Aadhaar card in sting operation,
booked by police
In neither of those is the need for Aadhaar properly established. Only
in November 2012 — after scholars like Reetika Khera pointed out
UIDAI’s fundamental misunderstanding of leakages in the welfare
delivery system — was the first cost-benefit analysis commissioned, by
when UIDAI had already spent ₹28 billion. That same month, Justice KS
Puttaswamy, a retired High Court judge, filed a PIL in the Supreme
Court challenging Aadhaar’s constitutionality, wherein the government
has argued privacy isn’t a fundamental right.

Every time you use Aadhaar, you leave behind logs in the UIDAI
databases. This means that the government can potentially have very
detailed information about everything from the your medical purchases
to your use of video-chatting software.

Even today, whether the ‘deduplication’ process — using biometrics to
ensure the same person can’t register twice — works properly is a
mystery, since UIDAI hasn’t published data on this since 2012. Instead
of welcoming researchers to try to find flaws in the system, UIDAI
recently filed an FIR against a journalist doing so.

At least in 2009, UIDAI stated it sought to prevent anyone from
“[e]ngaging in or facilitating profiling of any nature for anyone or
providing information for profiling of any nature for anyone”, whereas
the 2014 document doesn’t. As OnGrid’s services show, the very
profiling that the UIDAI said it would prohibit is now seen as a
feature that all, including private companies, may exploit.

UID has changed in other ways too. In 2009, it was as a system that
never sent out any information other than ‘Yes’ or ‘No’, which it did
in response to queries like ‘Is Pranesh Prakash the name attached to
this UID number’ or ‘Is April 1, 1990 his date of birth’, or ‘Does
this fingerprint match this UID number’.

With the addition of e-KYC (wherein UIDAI provides your demographic
details to the requester) and Aadhaar-enabled payments to the plan in
2012, the fundamentals of Aadhaar changed. This has made Aadhaar less
secure.

SECURITY CONCERNS

With Aadhaar Pay, due to be launched on April 14, a merchant will ask
you to enter your Aadhaar number into her device, and then for your
biometrics — typically a fingerprint, which will serve as your
‘password’, resulting in money transfer from your Aadhaar-linked bank
account.

Basic information security theory requires that even if the identifier
(username, Aadhaar number etc) is publicly known — millions of people
names and Aadhaar numbers have been published on dozens of government
portals — the password must be secret. That’s how most logins works,
that’s how debit and credit cards work. How are you or UIDAI going to
keep your biometrics secret?

Read more

If MS Dhoni’s personal Aadhaar data can be leaked, how safe is yours?

Jaitley, Chidambaram clash in Parliament over MS Dhoni’s Aadhaar data leak
In 2015, researchers in Carnegie Mellon captured the iris scans of a
driver using car’s side-view mirror from distances of up to 40 feet.
In 2013, German hackers fooled Apple iOS’s fingerprint sensors by
replicating a fingerprint from a photo taken off a glass held by an
individual. They even replicated the German Defence Minister’s
fingerprints from photographs she herself had put online. Your
biometrics can’t be kept secret.

Typically, even if your username (in this case, Aadhaar number) is
publicly known, your password must be secret. That’s how most logins
works, that’s how debit and credit cards work. How are you or UIDAI
going to keep your biometrics secret?

In the US, in a security breach of 21.5 million government employees’
personnel records in 2015, 5.2 million employees’ fingerprints were
copied. If that breach had happened in India, those fingerprints could
be used in conjunction with Aadhaar numbers not only for large-scale
identity fraud, but also to steal money from people’s bank accounts.

All ‘passwords’ should be replaceable. If your credit card gets
stolen, you can block it and get a new card. If your Aadhaar number
and fingerprint are leaked, you can’t change it, you can’t block it.

The answer for Aadhaar too is to choose not to use biometrics alone
for authentication and authorisation, and to remove the centralised
biometrics database. And this requires a fundamental overhaul of the
UID project.

Aadhaar marks a fundamental shift in citizen-state relations: from ‘We
the People’ to ‘We the Government’. If the rampant misuse of
electronic surveillance powers and wilful ignorance of the law by the
state is any precedent, the future looks bleak. The only way to
protect against us devolving into a total surveillance state is to
improve rule of law, to strengthen our democratic institutions, and to
fundamentally alter Aadhaar. Sadly, the political currents are not
only not favourable, but dragging us in the opposite direction.

Read more

Aadhaar failed to stop corruption, denying elderly benefits: Activist Nikhil Dey

Your bank account number could become common identity platform for
financial products

(Pranesh Prakash is policy director at the Centre for Internet and
Society, and Affiliated Fellow at Yale Law School’s Information
Society Project)

-- 
Peace Is Doable

-- 
You received this message because you are subscribed to the Google Groups 
"Green Youth Movement" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To post to this group, send an email to [email protected].
Visit this group at https://groups.google.com/group/greenyouth.
For more options, visit https://groups.google.com/d/optout.

Reply via email to