Skip to main content

Aadhaar could also be a security feature to check data theft: UIDAI

To draw the right lessons from the largest ever leak of debit and credit card data from several Indian banks that happened last week, the Aadhaar authorities feel it is time to integrate the same with bank account numbers.
Ajay Bhushan Pandey, director-general of Unique Identification Authority of India (UIDAI), says the Aadhaar authentication protocol can be overlaid on the card systems. Talking with Business Standard , he said it would mean every time a person swipes her debit card on relatively insecure points such as automated teller machines (ATMs), she will be prompted to provide the Aadhaar number along with her PIN provided by the bank. The two will act as double verification for her.
Pandey said he would discuss this option with the finance ministry. The ministry will have to engage in talks with the National Payments Corporation of India and the Reserve Bank of India (RBI), subsequently. Right now, while banks do insist on Aadhaar number for opening of savings accounts, they do not insist on the same when they offer customers netbanking rights or credit and debit cards.
Since there are nearly 1,070 million Indians, who already have an Aadhaar number and each is seeded with their biometric details, including iris and fingerprints, Pandey said matching of the card population with those holding Aadhaar should not be difficult. “It need not be essential but an additional option every time a transaction is carried out by the card owner, as a safety device.” He said with a massive influx of Indians into the digital age, adding the security provided by the Aadhaar network with the ramped-up checks banks are introducing would be seen as a powerful safety net for the population.
“Adding Aadhaar could, however, add to the time for processing each transaction,” says Shefali Dash, former deputy director-general of National Informatics Centre. She said the two-stage authentication would have to work, as it does for identification of government employees rolled out across the nation over the past two years. It will take a few seconds more, she said, even as she agreed the proposal was viable.
One problem with the addition of Aadhaar is that as of now, ATMs are not Aadhaarenabled. Yet, they are the points where people use their debit card the most and security breaches happen the most since there is no provision for a one-time password (OTP) to secure the transaction. The PIN numbers are subject to copying by malware in the systems since they are used repeatedly. In the present case, it is suspected that some of the ATMs of a private banking network were invaded first by the malware, which then spread through the financial system.
From January 2017, RBI has mandated making all ATMs across the nation Aadhaarenabled. But, that has been done to make life easy for the Jan-Dhan account holders. To match the ATMs with the card environment would need the banks to do further tinkering with them. It will cost money.
“In fact, if Aadhaar is added to the current soup, costs will rise for everyone. The banks will have to make changes in their software and even the UIDAI will have to make their system ready to face the sharp spike in transactions, which will happen,” said Dash. Each of them has a cost.
Banks use 128-bit Secure Sockets Layer encryption to secure the net environment for their customers, and technically it is impossible as of now to break the lock. But the weakness like in this case stems from ATMs, which are not as secure. Pandey said the asymmetric encryption standards of Aadhaar are suitable for the weaker security environment of ATMs and other places where OTP is not used, to block theft of security.
Business Standard New Delhi,27th October 2016

Comments

Popular posts from this blog

Credit card spending growth declines on RBI gaze, stress build-up

  Credit card spends have further slowed down to 16.6 per cent in the current financial year (FY25), following the Reserve Bank of India’s tightening of unsecured lending norms and rising delinquencies, and increased stress in the portfolio.Typically, during the festival season (September–December), credit card spends peak as several credit card-issuing banks offer discounts and cashbacks on e-commerce and other platforms. This is a reversal of trend in the past three financial years stretching to FY21 due to RBI’s restrictions.In the previous financial year (FY24), credit card spends rose by 27.8 per cent, but were low compared to FY23 which surged by 47.5 per cent. In FY22, the spending increased 54.1 per cent, according to data compiled by Macquarie Research.ICICI Bank recorded 4.4 per cent gross credit losses in its FY24 credit card portfolio as against 3.2 per cent year-on-year. SBI Cards’ credit losses in the segment stood at 7.4 per cent in FY24 and 6.2 per cent in FY23, the...

SFBs should be vigilant, proactive to mitigate risks: RBI deputy guv

  The Reserve Bank of India’s Deputy Governor Swaminathan J on Friday instructed the directors of small finance banks (SFBs) to be vigilant and proactive in identifying emerging risks in the sector.Speaking at a conference for directors on the boards of SFBs, Swaminathan highlighted the role of governance in guiding SFBs towards sustainable growth with stability. He also emphasised the importance of sustainable business models.Additionally, he highlighted the need for strengthening cybersecurity to protect the entities against digital threats and urged for a stronger focus on financial inclusion, customer service, and grievance redressal to ensure a broader reach of banking services.Executive Directors S C Murmu, Rohit Jain, and R L K Rao, along with other senior officials representing the Supervision, Regulation, and Enforcement Departments of the RBI, also participated in the conference.   -  Business Standard  30 th  September, 2024

Brigade Hotel Ventures files draft papers with Sebi for Rs 900 crore IPO

  Brigade Hotel Ventures Ltd, owner and developer of hotels in South India, has filed draft papers with capital markets regulator Sebi to raise Rs 900 crore through an initial public offering (IPO).The proposed IPO is entirely a fresh issue of equity shares with no Offer-for-Sale (OFS) component, according to the draft red herring prospectus (DRHP).Proceeds from the issue to the tune of Rs 481 crore will go towards payment of debt, Rs 412 crore will be allocated to the company and Rs 69 crore to its material subsidiary, SRP Prosperita Hotel Ventures Ltd.Additionally, Rs 107.52 crore will be used to purchase an undivided share of land from the Promoter, BEL, and the remaining funds will support acquisitions, other strategic initiatives, and general corporate purposes.The company may raise up to Rs 180 crore through a Pre-IPO Placement.   If the placement is undertaken, the issue size will be reduced.Brigade Hotel Ventures Ltd is a wholly-owned subsidiary of Brigade Enterprises ...