Skip to content

mAadhaar security flaw makes stealing Aadhaar data easier

The Aadhaar card security concerns don’t seem to end. Now, a French security researcher has reportedly found a security flaw in the mAadhaar app. As per his report, the flaw makes it easier for someone with physical access to any user’s phone to acquire their Aadhaar card details.

The researcher named Elliot Alderson took to Twitter to explain the security flaw in the Aadhaar app. He pointed out the issues that would cause security issues in the Android app. He writes in his tweet to UIDAI that it is super easy to get the password of the local database of Aadhaar.

However, UIDAI in a response Tweet mentioned that “mAadhaar uses a local db to store the user preferences on the user’s device. This data is application preferences as created by the user on his/her phone. The app does not capture, store or take any biometric inputs. So the question of biometrics being compromised does not arise.”

To explain the issue, the mAadhaar app saves all the biometric settings in a local database which is protected with a password and, to generate the password, UIDAI uses a random number with 123456789 as seed and a hardcoded string db_password_123 which makes it easy for anyone to crack it.


He, in a later tweet, explained that debug feature that is enabled in the app by default lets someone repack the app with the logging activated and distribute it. So, all the Aadhaar data will be available to the hacker and the attacker can easily upload the log file to his server. He also mentioned a hacker is already stealing the data.

https://twitter.com/fs0c131y/status/951965819801567232

This is not the first time when someone has raised a question about Aadhaar’s privacy. Earlier, there was a report last week that a major security loophole in the Aadhaar database made the unrestricted access to the database and Aadhaar data is available just for Rs. 500. UIDAI, however, issued a restriction to some official to the Aadhaar portal. The authority will also release some new Aadhaar security features in March this year.

Satyendra Pal Singh

Satyendra Pal Singh

Satyendra explores the latest happenings in the tech world and writes stories about those. He likes to play around with the latest gadgets and shares his views through articles. In his free time, you can find him watching movies/TV shows and/or reading books.View Author posts