The Fourth yesterday reported about a huge #CoWinDataLeak yesterday. There was a telegram Not which allowed to search against phone numbers or aadhaar for vaccine data. Exposed details includes

Family details(who took vaccination under the same number) and below fields Image
This is potentially one among the largest data leaks so far and looks like everyone who took vaccination via #Cowin is part of this database. They could verify many in this DB

@b_sreejan from The Fourth done a thread here
Today @Onmanorama covers this as front page lead story , after independently verifying the same. They also carry information hidden in the screenshot of health secretary Rajesh Bhushan and family ImageImage
Thread by @Onmanorama reporter @Jikkuvarghese here.

The magnitude of this data leak is so big and it contains identity data of almost all who trusted system to get vaccination including me. Possibly this might be only such data set with family expose

I like to point out there was significant outcry by myself in tweet threads , many civil society organizations and individuals to ensure privacy of Indian citizens in vaccination. Most of them got ignored and data security seems to be neglected totally

There was news on #CowinDataleak in 2021 June too but that later got denied by some cyber security experts. Is this from same leak or new ? No idea

ciso.economictimes.indiatimes.com/news/cowin-not…
Similarly we have seen claims like this from @rssharma3 when another #CoWinDataLeak news came up . but now there is a leak double verified by 2 independent news outlets including his vaccination data

Remember , this is one Telegram bot someone built using that data set. Many copies of data must be out there .

If all Indians took vaccination, this is a 1.4 billion database exposing Aadhaar/ voterID/passport , date of birth , phone number , vaccination center with family .
And this is the leaky tech India sharing as Digital Public Infrastructure to poor countries. @UNDP @UNDP_India you should look at this information and analyze.

Privacy risks on the same is highlighted by many in 2021 itself
Samples @TheKenWeb @no2uid @SFLCin @internetfreedom ImageImage
The deactivated aadhaar of Lord Hanuman got 5+ vaccinations.

Same with deactivated aadhaar of Pakistani Spy

Here is the Video proof of the leak data.

From @thefourthlive 's first report

The list includes every indians who got vaccinations. @SaketGokhale lusts some among them on his tweets

Polititions Journalists top leaders

No one is exempted

@thenewsminute also independently verified by checking details of TN political leaders

That makes it 3 media house verification on #DPIDisaster
And Remember this cartoon from @WorldOfHalahala ?
@rssharma3 proves HARM is in his middle name affects all Indians in every system he built with @NandanNilekani

Porous Digital Infrastructure they built compromised the data security of a generation

A journo asked what I demand?

I am not demanding anything. I am just sad seeing all this data compromise. When CoWin is building, we tried to warn and correct all for one purpose. Better data security and privacy along with Access to Vaccination. Now this is irreversible
But as a country, instead of learning from mistakes, we delay our Data protection law, State demands blanket trust with user data, while they are incapable to handle it, bringing more and more centralization systems without taking responsibility. This needs an accountability fix.

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with 𝗔𝗻𝗶𝘃𝗮𝗿 𝗔𝗿𝗮𝘃𝗶𝗻𝗱

𝗔𝗻𝗶𝘃𝗮𝗿 𝗔𝗿𝗮𝘃𝗶𝗻𝗱 Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @anivar

Jan 29, 2021
India makes worlds biggest #Covid19 Vaccination drive as a Peoples registry building #surveillance Project. This is the consent collected by a temporary contract employee on a desktop when someone getting vaccinated. The Consent Collection noti...
The above notice is on the view more link on this screen, for verifying users at a vaccination centre Image
There is non Aadhaar Flow built in, But operator level direction is for Aadhaar based process. ImageImage
Read 6 tweets
Oct 20, 2020
Mitron, aap chronology samajhiye

Vaccination and exclusion threat is a "Killer application" marketing possibility for Aadhaar linked Health ID

1. NN pitches
2. Takshashila preparing slide deck expanding NN's talk
3. NEGVAC and PIB release
4. Exclusive NN interview
5. This 👇
This slide deck includes using election infra for vaccination and a stealth linking of voter-Aadhaar database takshashila.org.in/takshashila-di…
Read 6 tweets
Apr 12, 2020
Starting a new thread for #ArogyaSetuApp watch
Since this is emerging as a same aadhaar like voluntary mandatory push, via PMO & Nitiayog involvement.
Baseline
1. There is no success story for contract tracing via mobile will work.
2. Contact tracing is an experiment initiated by countries with high smartphone penetration
3. India's smartphone penetration is ~25% and max upto 35% (not counting people with multiple devices) .
Bluetooth or GPS tracing with the help of an app makes it as a Smartphone only facility. There is no way a feature phone can do these. (Because we will soon hear about feature phone support just for the sake of inclusion claims, as we have seen USSD based UPI push as inclusion).
Read 13 tweets
Jan 29, 2020
Say this loudly

@kunalkamra88's Arnab video is the first mainstream use of #Counterspeech in Indian politics.

Arnab has an active role in making violence acceptable. Kunal addressing viewers in an Arnab method keeping him as a live visual object is sparkling #counterspeech
It took some time for me to remind the term, since we never used counter speech much as a way to fight dangerous speech.

There is significant research on this domain. Very relevant to India . eg. How Internetshutdowns amplify dangerous speech

Follow dangerousspeech.org
For more reading

CONSIDERATIONS FOR SUCCESSFUL COUNTERSPEECH

Also mention how fact checks fails to counter dangerous speech

dangerousspeech.org/wp-content/upl…
Read 6 tweets
Jan 4, 2020
Yesterday I was thrown out of a Anti-CAA counter missed call planning group for opposing that idea tooth and nail.

Doing an Anti-CAA missed call initiative is foolishness and stupidity. It exposes all protestor data to Govt via centralized number call records.
The rationale i heard there was , if we don't do this "someone else" will do this.

Does it help the campaign . No
Does it protect people calling . No
Does it expose people - Yes
Does it provide verifiability - No

So avoid missed calls. You may end up in voter targeting DBs.
Pointing now because I spotted some such missed call initiatives.

Any responsible Anti CAA NRC NPR Aadhaar campaigners should stay away from such initiatives risking peoples lives.

Aiding Database state efforts is not a campaign
Read 5 tweets
Dec 14, 2019
States should decide they won't collect any parameters other than what is defined in Citizenship act for NPR updation.

Let's understand Citizenship Registry for CAB will be derived from #Census2020 possibly via an algorithmic operation. So refuse anything more than these.
In 2011 census, many of us refused Biometrics based on this and saved ourselves from enrolling for illegal Aadhaar , while giving data to census.
This census is app driven. Take a look and audit census apps play.google.com/store/apps/dev…
And default password is here
Read 4 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us on Twitter!

:(