Just In
- 8 hrs ago Dell Introduces AI-Powered Laptops and Mobile Workstations for Enterprises in India
- 10 hrs ago Meta AI Powered by Llama 3 Takes Aim at ChatGPT and Gemini: All You Need to Know!
- 10 hrs ago OnePlus Ace 3 Pro Leak Hints at New Design; Expected Launch, Specifications We Know So Far
- 11 hrs ago Vivo V30e Launch Date in India set for May 2: Flipkart Availability Confirmed
Don't Miss
- Movies Chief Detective 1958 Episode 2 OTT Release Date, Time, Platform: When & Where To Watch? What To Expect? DEETS
- Lifestyle Golden Rules To Follow For Happy Marriage For A Long Lasting Relationship
- Sports IPL 2024: LSG vs CSK Award Winners, Man of The Match, Post-Match Presentation, Scorecard & Records
- News Chinese President Xi Jinping Orders Biggest Military Reorganisation Since 2015
- Education Exam Pressure Does Not Exist; Studying Punctually is Crucial; Says Aditi, the PSEB 2024 Topper
- Finance Reliance, ONGC, Tata, Adanis: Energy Stocks Didn't Get The Memo Of Bears, Up 12% In 30-Days; 10 Stocks To BUY
- Automobiles Suzuki Swift Hatchback Scores 4 Star Safety Rating At JNCAP – ADAS, New Engine & More
- Travel Journey From Delhi To Ooty: Top Transport Options And Attractions
mAadhaar Android app security flaw lets anyone steal your Aadhaar details
mAadhaar app for Android devices is likely plagued by a security flaw that will let anyone access your Aadhaar details. The debug feature of this app is claimed to be the reason.
Ever since the mandatory Aadhaar linking practice came into existence, several reports have started highlighting the dangerous consequences of the same. We say dangerous as the Aadhaar details will be linked to your mobile number and bank account, and with the leak of one of these details, all your sensitive information will be exposed to others. In the meantime, a security flaw in the mAadhaar app has been discovered by a French security researcher.
According to the tweets posted by Elliot Alderson, the mAadhaar app has a security flaw that will make it easy for anyone having physical access to any user's phone to get the Aadhaar card details of that person. He has explained this flaw in a series of tweets and has raised the issues those have plagued the mAadhaar app available for Android devices.
The researcher says that it is very easy to get the password of the local database as the mAadhaar app saves all the biometric settings in a local database that is protected with just a password. To generate the password, they tried a random number 1233456789 as the seed and db_password_123 as the hardcoded string.
He goes on stating that the debug feature enabled in the app by default allows anyone repack the mAadhaar application with the logging activated and send it so that all the Aadhaar data will be saved on the SD card in the device. From there, the attackers can upload the log file to their servers. He also states that it is not a good idea to keep the debug feature in the Android app that UIDAI released a few months back.
UIDAI immediately responded to him stating that mAadhaar uses a local database to store the user preferences on the user's device itself. It claims that the app does not capture, store or take biometric inputs. And, that there is no compromise being done in protecting the user data.
In response, Alderson has clarified stating that app code of mAadhaar suggests that it stores eKYC data such as name, Aadhaar number, address and photograph on the user's device. To prove his claims, he has also released a proof-of-concept Aadhaar database password generation and states that it generates the same password every time, making it easier for attackers to crack the password. But the authenticity of the password generator remains unconfirmed for now. Notably, this security flaw will not work remotely as it needs the physical access to the user's device.
Back in the last week, we came across a report alleging that the Aadhaar database has a flaw that will let anyone access the database for just Rs. 500. As an aftermath, UIDAI came up with a restricting letting only 5,000 officials to access the Aadhaar portal.
-
99,999
-
1,29,999
-
69,999
-
41,999
-
64,999
-
99,999
-
29,999
-
63,999
-
39,999
-
1,56,900
-
79,900
-
1,39,900
-
1,29,900
-
65,900
-
1,56,900
-
1,30,990
-
76,990
-
16,499
-
30,700
-
12,999
-
62,425
-
1,15,909
-
93,635
-
75,804
-
9,999
-
11,999
-
3,999
-
2,500
-
3,599
-
8,893