Draft Aadhaar (Authentication and Offline Verification) Regulations, 2021 - uidai.gov.in/images/Draft_A…

Draft put for consultation 'silently' by @UIDAI on May 20, 2021 and closing by June 2, 2021.

Some highlights on thread.

@SFLCin @internetfreedom @nixxin
The proposed regulations will supersede the Aadhaar (Authentication) Regulations, 2016 uidai.gov.in/images/regulat…

Context : This is the regulation relating to Authentication coming after #Aadhaar Amendments and the Aadhaar Good Governance Rules 2020
TLDR - This regulations is around authentication framework, including offline verification appointment of requesting entities and AUA/ASA, Obligations of Offline Verification Seeking Entities (OVSE), eKYC guidelines, regulations around logs, audit, transaction data
On definitions - ANCS - #Aadhaar Number Capture Service is a new tech getting a mention. There are very references technical details of this service, which will run by @UIDAI. At the outset, does seem like OAuth endpoint being run.

Regulations without sufficient details is bad
Offline verification gets regulatory recognition.
4 types of offline verification. They are allowing paper copy to be collected, which is deeply problematic.

But regulations now seek redaction / black out of first 8 digits. Will we see this in reality? Take your guess
Authentication types - such careful wording to allow facial authentication, without explicitly mentioning that in regulations.

#CoWIN is the first large scale app to perform facial authentication.
#OVSE must tell the Aadhaar holder - the nature of information received during auth / verification, its use - in local language *AND* must provide alternate viable means of identification, and cannot deny / refuse any service.
Upon withdrawing consent, Aadhaar data shall be deleted by the requesting entity in a verifiable manner and an acknowledgement of the same to be shared with resident.
Capturing biometrics. It is to be noted that @AyushmanNHA is capturing facial data for #CoWIN facial authentication pilot - without the processes and specification laid down by the authority in public domain.
Side stepping a bit on facial authentication guidelines by volunteers. Yeah, you will not see any reference to UIDAI, but this is how all #Aadhaar tech was built.

cryptpad.fr/file/#/3/file/…
Coming back - "In all modes, Aadhaar number is mandatory and is submitted along with input parameters" - is such a disregard to #VID. But this is where we see - #ANCS Token eventually replacing, but there are no technical details of the same available, while the regulation has it
Notification about authentication / verification to Aadhaar holder, including the case of offline verification, where OVSE should notify about verification. through email and/or SMS on mobile number and/or paper based
acknowledgement. Basically, get a slip when you share #Aadhaar
Chapter III is about licensing of service providers. Basically, any private entity fulfilling the criteria (regulated financial sector entities / telcos) + OTHERS(!) are eligible. Chapter also deals with responsibilities of ASAs
#OVSE - This is pratically every amar-akbar-antony entity in India that demands #Aadhaar.

1 (b) makes no sense, after allowing to collect paper copies of Aadhaar at the top.
Log maintainence -- While @UIDAI itself will keep logs only for 6 months, per SC judgement, @UIDAI is now regulating that private entities / AUAs will have to keep them for 2 + 5 = 7 years! #SaveOurPrivacy
ASA too will have to maintain logs for 2 + 5 = 7 years.

Missed a key point on consent. Unless explicitly opted-out, you have presumed to have consented to modified purpose!!!

This is #ConsentWashing #AutoTickBox by regulation
What the above means - Unless one explicitly opts-out of anything @AyushmanNHA brings - one is deemed to have consented for any purpose they modify - after one gave #Aadhaar for vaccination.

This has grave implications on health ID + tracking.

1.3 is specifically for @AyushmanNHA - Remember NHA is an authority *WITHOUT* Centre / State Act.

"Special Purpose Organization" is a new phrasing.

2 is all regulated entities in financial / telecom sector.

3.1.7 is strange - What is "Any other entity"?
Category 3 -- Any other entity of national importance as determined by the Authority - for #ASA (which are directly connected to #CIDR) access is BS.

Does the authority have powers to determine entity of national importance in base act @apar1984 @prasanna_s @PrasanthTweets?
That's a wrap on the draft. There are few provisions "on paper" which tries to gives better rights to holders (Like OVSE notification) - but sweepingly bad provisions undermine everything else.
#ANCS token reference from Aadhaar Authentication Application Security Standard (of JH SRDH) aadhaar.jharkhand.gov.in/Aadhaar_Authen…
#ANCS - There is very little technical detail on this OAuth(?) like implementation. "Please note that your Aadhaar number will be captured by the UIDAI’s ANCS (Aadhaar Number Capture Service) on their website" -- tells another search result.

Need more technical documentation

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Srikanth.CashlessConsumer | ஸ்‌ரீகாந்த்

Srikanth.CashlessConsumer | ஸ்‌ரீகாந்த் Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @logic

Dec 22, 2023
Request for Proposal (RFP) for selection of a CONSULTING FIRM to operate Program Management Unit(PMU) in @MtcChennai opens today. Lets look the scope of privatization of #MTC Is this what for Dr Alby John IAS was appointed as MD? 🧵

#SaveMTC #SaveChernnai #ChennaiCityPartnership Image
A. Support #ChennaiCityPartnership

i) Management of Public Transport Service Contract

A PTSC without autonomy to set fares (revenue mobilisation) - will result in increased privatisation of services - as the target will be meet KPIs
Image
Image
ii) Management of GCC procurement and management.

Right - A private consultant will manage the private operator run GCC. Image
Read 10 tweets
Jun 19, 2023
#Killer DPI - Firstly for #KillerLoanApps

Neither API health, not interoperability will substitute responsible behaviour in #DigitalLending #DPIDisaster
Both #PAN and #Aadhaar are tired of the billion transformations since 2017 and the only people who gave made money is KYC startups (not even fintechs)



The top priority for railways has to be @digilocker integration, not track maintenance.

Oh please push all those auto issued insurance from IRCTC so when people die, their relatives don't need to run around.
Read 6 tweets
Jun 12, 2023
💣💣 The inevitable has happened. #CoWINDataLeak reported by @thefourthlive @ManoramaDaily is a largest #DigitalPublicInfrastructure disaster.

Thread on some impacts.
1. What happened? What data points are exposed?

A : A telegram bot allows to query - what possibly appears entire #CoWIN database by mobile number / #Aadhaar & returns vaccination details if exists.

Name, Mobile, Gender, ID Proof used (Aadhaar/Passport), Vax centre address
If a single number of used for entire family, it returns all members who used the same number.

RS Sharma, Meenakshi Lekhi, KC Venugopal are some of whose data was available.

Read 35 tweets
Mar 29, 2023
There is a lot of confusion on this #UPI charges and its being made to spread multiple 'fake news' in a area where there is clarity. This directly stems from fact - who is allowed to price on what?

#CashlessConsumer will attempt to decode this in a 🧵
1. What is being announced?

NPCI will charges #MDR for transactions above ₹2000 - when the payment mode by user is a wallet.

Note - this is not the same as using PhonePe / GPay.

It is applicable only when you use Wallet - PhonePe / PayTM are popular wallets still exist.
It is not applicable when you use UPI via banks.

2. Who is making this announcement?

NPCI.

3. Can NPCI make this announcement?
All Payment operators are at liberty to price payment products - except ATM interchange - which @RBI actively regulates.
Read 13 tweets
Aug 11, 2022
#UPI #AppUpdate PhonePe UPI, Payment, Recharge play.google.com/store/apps/det… Get. Set. Gold! <br><br>You can now accumulate Gold at regular intervals by setting up a Gold SIP on PhonePe! <br><br> P.S: Without worry about market risks and fluc...
#UPI #AppUpdate Pockets- Bill Payment, Recharge, UPI on wallet play.google.com/store/apps/det… Security update...
#UPI #AppUpdate Truecaller: Caller ID & Block play.google.com/store/apps/det… We keep updating our App to make it better. <br>This version brings:<br>- Our redesigned profile will show you the number of spam calls, messages and unknown numbers ...
Read 5 tweets
Aug 9, 2022
Vaccination data is shared equally between UNDP, BMGF, eGov - That all 3 is funded by @BillGates is connecting thread. #CoWIN #VaccinationCertificate #HealthData loot. -- Also #Modi photo to appease the political head of state to keep the loot silent.
$ 3.9 M - That is how much was 'donated' by GAVI to UNDP for hosting #CoWIN system. Don't be a fool to think that data hasn't gone back to funders. Image
Another $3M Image
Read 4 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(