Biometric authentication using Aadhaar is great boon for identifying people who
are physically present. It's great to see how Aadhaar is easing the KYC process for
mobile sim card activation, which is great step forward from the present
photocopy of ID proof based methods.
However, Aadhaar cannot be a safe method for remote authentication using
untrusted devices, since biometric authentication is clearly vulnerable to replay attack.
Here's a case where it was detected.
http://economictimes.indiatimes.com/news/economy/policy/probe-against-3-firms-for-illegal-use-of-aadhaar-biometrics/articleshow/57325951.cms
It's good to see from the article that Aadhaar does have a mechanism to detect replay attacks.
But it cannot be 100% safe since attackers can store multiple scans for later attacks.
Or even just introduce minor distortions/noise into the readings, which will fool
duplicate detection.
For the longer term, even for in person authentication, one depends on trusting
the agent who is doing the verification. Since they cannot always be trusted,
safeguards are needed to ensure the agent is also securely identified in each transaction,
and their identity (e.g via joint photos to establish physical presence)
stored, so in case of replay attack by an agent, the identity theft victim
has some way to show that their identity was stolen. Without it a victim will
be in deep trouble, since there is no way to show they were not present.
UIDAI badly needs to issue guidelines for this task.
They do have some guidelines regarding trusted devices:
http://economictimes.indiatimes.com/news/economy/policy/uidai-registration-for-all-aadhaar-authentication-devices-soon/articleshow/56734738.cms
but I don't see how they can verify if malware infects such a device.
Backup mechanisms are needed.
No comments:
Post a Comment