HomeLatest NewsCyber SecuritySecurity flaw in mAadhaar app can allow hackers to steal your Aadhaar data: Security researcher

Security flaw in mAadhaar app can allow hackers to steal your Aadhaar data: Security researcher

A Security researcher alias Elliot Alderson has tweeted a serious security vulnerability in UIDAI’s mAadhaar app for Android devices.

Preferred Source of Google

A Security researcher alias Elliot Alderson has tweeted a serious security vulnerability in UIDAI‘s mAadhaar app for Android devices. According to the researcher, the Aadhaar mobile app is saving user sensitive including the biometric data in a password protected local database. The password for the database is generated using a random number “123456789 as seed” and a hardcoded string db_password_123 which remains same for every .

Besides this, Elliot has also uploaded a proof-of-concept on to demonstrate the flaw. He made an application with the exact same code as it was written in the Aadhaar app to prove that even if you run it multiple times, it will give you the same password over and over again instead of the randomised password the app is supposed to generate.

The researcher has stated that if a person is able to crack the password, they can access the entire Aadhaar account details of the user. He further said that as per the documentation for the mAadhaar app, the app will store personal details and the user’s photo in their local database.

Advertisement
Digital Senate
Digital Senate
Digital Senate is a premier conference uniting government leaders, technologists and innovators to share ideas, success stories and strategies on digital governance, public sector transformation, cybersecurity and emerging technologies in India.
Register Now →
CIO Prism
CIO Prism
CIO Prism unites forward-thinking technology leaders to exchange transformative insights, shape digital strategies, and foster innovation, empowering enterprises to excel in an era of rapid technological change.
Register Now →

UIDAI has however confirmed that the app creates a local database with innocuous data like user preferences. Further, they said that since the app doesn’t ask for any biometric data, such data can’t be compromised.

According to Ankush Johar, Director at Infosec Ventures, although the exploitability of this issue is pretty low, nonetheless, information as critical as Biometrics along with other PII is something that should not be exposed to even the slightest risk.

Advertisement

“Recently, with alleged leakage of Aadhaar details of over a billion citizens, hackers might already have access to every information printed on our Aadhaar cards and can easily replicate it. Even though a person has replicated your Aadhaar card, he/she will still need your Biometric info for authentication. If by any chance the hackers are able to gain the biometric data as well, then it will catastrophic,” said Johar.

He further said, “As the UP cloning fraud showed that making a physical clone of the fingerprints is not too difficult, such leakage could do irreversible damage as you can change your passwords but you cannot change your fingerprints.”

Get the day's headlines from Tech Observer straight in your inbox

By subscribing you agree to our Privacy Policy, T&C and consent to receive newsletters and other important communications.
Sanjay Singh
Sanjay Singh
Sanjay Singh covers startups, consumer electronics and telecom for TechObserver.in
- Advertisement -
Powered By Veeam Logo
- Advertisement -

Subscribe to our Newsletter

By subscribing you agree to our Privacy Policy, T&C and consent to receive newsletters and other important communications.
- Advertisement -

Uttar Pradesh must build cybersecurity products, not just consume them: Former STPI DG Omkar Rai

Omkar Rai, former STPI director general, urged Uttar Pradesh to build indigenous cybersecurity products capability and startups rather than remaining dependent on imported solutions. He called for innovation platforms connecting students, startups and government.

RELATED ARTICLES