Skip to main content

Posts

Showing posts from January 13, 2018

Loopholes in Aadhaar authentication API services

Loopholes in Aadhaar authentication API services Aadhar Logo Using this loophole anybody can use Aadhaar demographic authentication API by piggybacking my requests through NSDL servers and bypass the checks at place by UIDAI.  This story is going to be about how just about anyone can access the API that Aadhaar provides to third party services. What is Aadhaar? Aadhaar is the world’s largest  biometric ID system , with over 1.19 billion enrolled members as of 30 Nov 2017. As of this date, over 99% of Indians aged 18 and above had been enrolled in Aadhaar. What is Aadhaar API? UIDAI  (Unique Identification Authority of India) provides different APIs (application programming interface) which can be used to perform various actions like authentication (demographic and biometric), e-KYC (know your customer), e-sign etc. We are discussing about   Aadhaar Authentication API  for now. Going further, you have to know what AUA and SA are Authenticat