Deprecated (16384): The ArrayAccess methods will be removed in 4.0.0.Use getParam(), getData() and getQuery() instead. - /home/brlfuser/public_html/src/Controller/ArtileDetailController.php, line: 73 You can disable deprecation warnings by setting `Error.errorLevel` to `E_ALL & ~E_USER_DEPRECATED` in your config/app.php. [CORE/src/Core/functions.php, line 311]Code Context
trigger_error($message, E_USER_DEPRECATED);
}
$message = 'The ArrayAccess methods will be removed in 4.0.0.Use getParam(), getData() and getQuery() instead. - /home/brlfuser/public_html/src/Controller/ArtileDetailController.php, line: 73 You can disable deprecation warnings by setting `Error.errorLevel` to `E_ALL & ~E_USER_DEPRECATED` in your config/app.php.' $stackFrame = (int) 1 $trace = [ (int) 0 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/ServerRequest.php', 'line' => (int) 2421, 'function' => 'deprecationWarning', 'args' => [ (int) 0 => 'The ArrayAccess methods will be removed in 4.0.0.Use getParam(), getData() and getQuery() instead.' ] ], (int) 1 => [ 'file' => '/home/brlfuser/public_html/src/Controller/ArtileDetailController.php', 'line' => (int) 73, 'function' => 'offsetGet', 'class' => 'Cake\Http\ServerRequest', 'object' => object(Cake\Http\ServerRequest) {}, 'type' => '->', 'args' => [ (int) 0 => 'catslug' ] ], (int) 2 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Controller/Controller.php', 'line' => (int) 610, 'function' => 'printArticle', 'class' => 'App\Controller\ArtileDetailController', 'object' => object(App\Controller\ArtileDetailController) {}, 'type' => '->', 'args' => [] ], (int) 3 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/ActionDispatcher.php', 'line' => (int) 120, 'function' => 'invokeAction', 'class' => 'Cake\Controller\Controller', 'object' => object(App\Controller\ArtileDetailController) {}, 'type' => '->', 'args' => [] ], (int) 4 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/ActionDispatcher.php', 'line' => (int) 94, 'function' => '_invoke', 'class' => 'Cake\Http\ActionDispatcher', 'object' => object(Cake\Http\ActionDispatcher) {}, 'type' => '->', 'args' => [ (int) 0 => object(App\Controller\ArtileDetailController) {} ] ], (int) 5 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/BaseApplication.php', 'line' => (int) 235, 'function' => 'dispatch', 'class' => 'Cake\Http\ActionDispatcher', 'object' => object(Cake\Http\ActionDispatcher) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {} ] ], (int) 6 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/Runner.php', 'line' => (int) 65, 'function' => '__invoke', 'class' => 'Cake\Http\BaseApplication', 'object' => object(App\Application) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {}, (int) 2 => object(Cake\Http\Runner) {} ] ], (int) 7 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Routing/Middleware/RoutingMiddleware.php', 'line' => (int) 162, 'function' => '__invoke', 'class' => 'Cake\Http\Runner', 'object' => object(Cake\Http\Runner) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {} ] ], (int) 8 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/Runner.php', 'line' => (int) 65, 'function' => '__invoke', 'class' => 'Cake\Routing\Middleware\RoutingMiddleware', 'object' => object(Cake\Routing\Middleware\RoutingMiddleware) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {}, (int) 2 => object(Cake\Http\Runner) {} ] ], (int) 9 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Routing/Middleware/AssetMiddleware.php', 'line' => (int) 88, 'function' => '__invoke', 'class' => 'Cake\Http\Runner', 'object' => object(Cake\Http\Runner) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {} ] ], (int) 10 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/Runner.php', 'line' => (int) 65, 'function' => '__invoke', 'class' => 'Cake\Routing\Middleware\AssetMiddleware', 'object' => object(Cake\Routing\Middleware\AssetMiddleware) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {}, (int) 2 => object(Cake\Http\Runner) {} ] ], (int) 11 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Error/Middleware/ErrorHandlerMiddleware.php', 'line' => (int) 96, 'function' => '__invoke', 'class' => 'Cake\Http\Runner', 'object' => object(Cake\Http\Runner) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {} ] ], (int) 12 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/Runner.php', 'line' => (int) 65, 'function' => '__invoke', 'class' => 'Cake\Error\Middleware\ErrorHandlerMiddleware', 'object' => object(Cake\Error\Middleware\ErrorHandlerMiddleware) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {}, (int) 2 => object(Cake\Http\Runner) {} ] ], (int) 13 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/Runner.php', 'line' => (int) 51, 'function' => '__invoke', 'class' => 'Cake\Http\Runner', 'object' => object(Cake\Http\Runner) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {} ] ], (int) 14 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/Server.php', 'line' => (int) 98, 'function' => 'run', 'class' => 'Cake\Http\Runner', 'object' => object(Cake\Http\Runner) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\MiddlewareQueue) {}, (int) 1 => object(Cake\Http\ServerRequest) {}, (int) 2 => object(Cake\Http\Response) {} ] ], (int) 15 => [ 'file' => '/home/brlfuser/public_html/webroot/index.php', 'line' => (int) 39, 'function' => 'run', 'class' => 'Cake\Http\Server', 'object' => object(Cake\Http\Server) {}, 'type' => '->', 'args' => [] ] ] $frame = [ 'file' => '/home/brlfuser/public_html/src/Controller/ArtileDetailController.php', 'line' => (int) 73, 'function' => 'offsetGet', 'class' => 'Cake\Http\ServerRequest', 'object' => object(Cake\Http\ServerRequest) { trustProxy => false [protected] params => [ [maximum depth reached] ] [protected] data => [[maximum depth reached]] [protected] query => [[maximum depth reached]] [protected] cookies => [ [maximum depth reached] ] [protected] _environment => [ [maximum depth reached] ] [protected] url => 'latest-news-updates/a-tale-of-errors-r-ramakumar-16029/print' [protected] base => '' [protected] webroot => '/' [protected] here => '/latest-news-updates/a-tale-of-errors-r-ramakumar-16029/print' [protected] trustedProxies => [[maximum depth reached]] [protected] _input => null [protected] _detectors => [ [maximum depth reached] ] [protected] _detectorCache => [ [maximum depth reached] ] [protected] stream => object(Zend\Diactoros\PhpInputStream) {} [protected] uri => object(Zend\Diactoros\Uri) {} [protected] session => object(Cake\Http\Session) {} [protected] attributes => [[maximum depth reached]] [protected] emulatedAttributes => [ [maximum depth reached] ] [protected] uploadedFiles => [[maximum depth reached]] [protected] protocol => null [protected] requestTarget => null [private] deprecatedProperties => [ [maximum depth reached] ] }, 'type' => '->', 'args' => [ (int) 0 => 'catslug' ] ]deprecationWarning - CORE/src/Core/functions.php, line 311 Cake\Http\ServerRequest::offsetGet() - CORE/src/Http/ServerRequest.php, line 2421 App\Controller\ArtileDetailController::printArticle() - APP/Controller/ArtileDetailController.php, line 73 Cake\Controller\Controller::invokeAction() - CORE/src/Controller/Controller.php, line 610 Cake\Http\ActionDispatcher::_invoke() - CORE/src/Http/ActionDispatcher.php, line 120 Cake\Http\ActionDispatcher::dispatch() - CORE/src/Http/ActionDispatcher.php, line 94 Cake\Http\BaseApplication::__invoke() - CORE/src/Http/BaseApplication.php, line 235 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Routing\Middleware\RoutingMiddleware::__invoke() - CORE/src/Routing/Middleware/RoutingMiddleware.php, line 162 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Routing\Middleware\AssetMiddleware::__invoke() - CORE/src/Routing/Middleware/AssetMiddleware.php, line 88 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Error\Middleware\ErrorHandlerMiddleware::__invoke() - CORE/src/Error/Middleware/ErrorHandlerMiddleware.php, line 96 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Http\Runner::run() - CORE/src/Http/Runner.php, line 51 Cake\Http\Server::run() - CORE/src/Http/Server.php, line 98
Deprecated (16384): The ArrayAccess methods will be removed in 4.0.0.Use getParam(), getData() and getQuery() instead. - /home/brlfuser/public_html/src/Controller/ArtileDetailController.php, line: 74 You can disable deprecation warnings by setting `Error.errorLevel` to `E_ALL & ~E_USER_DEPRECATED` in your config/app.php. [CORE/src/Core/functions.php, line 311]Code Context
trigger_error($message, E_USER_DEPRECATED);
}
$message = 'The ArrayAccess methods will be removed in 4.0.0.Use getParam(), getData() and getQuery() instead. - /home/brlfuser/public_html/src/Controller/ArtileDetailController.php, line: 74 You can disable deprecation warnings by setting `Error.errorLevel` to `E_ALL & ~E_USER_DEPRECATED` in your config/app.php.' $stackFrame = (int) 1 $trace = [ (int) 0 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/ServerRequest.php', 'line' => (int) 2421, 'function' => 'deprecationWarning', 'args' => [ (int) 0 => 'The ArrayAccess methods will be removed in 4.0.0.Use getParam(), getData() and getQuery() instead.' ] ], (int) 1 => [ 'file' => '/home/brlfuser/public_html/src/Controller/ArtileDetailController.php', 'line' => (int) 74, 'function' => 'offsetGet', 'class' => 'Cake\Http\ServerRequest', 'object' => object(Cake\Http\ServerRequest) {}, 'type' => '->', 'args' => [ (int) 0 => 'artileslug' ] ], (int) 2 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Controller/Controller.php', 'line' => (int) 610, 'function' => 'printArticle', 'class' => 'App\Controller\ArtileDetailController', 'object' => object(App\Controller\ArtileDetailController) {}, 'type' => '->', 'args' => [] ], (int) 3 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/ActionDispatcher.php', 'line' => (int) 120, 'function' => 'invokeAction', 'class' => 'Cake\Controller\Controller', 'object' => object(App\Controller\ArtileDetailController) {}, 'type' => '->', 'args' => [] ], (int) 4 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/ActionDispatcher.php', 'line' => (int) 94, 'function' => '_invoke', 'class' => 'Cake\Http\ActionDispatcher', 'object' => object(Cake\Http\ActionDispatcher) {}, 'type' => '->', 'args' => [ (int) 0 => object(App\Controller\ArtileDetailController) {} ] ], (int) 5 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/BaseApplication.php', 'line' => (int) 235, 'function' => 'dispatch', 'class' => 'Cake\Http\ActionDispatcher', 'object' => object(Cake\Http\ActionDispatcher) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {} ] ], (int) 6 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/Runner.php', 'line' => (int) 65, 'function' => '__invoke', 'class' => 'Cake\Http\BaseApplication', 'object' => object(App\Application) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {}, (int) 2 => object(Cake\Http\Runner) {} ] ], (int) 7 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Routing/Middleware/RoutingMiddleware.php', 'line' => (int) 162, 'function' => '__invoke', 'class' => 'Cake\Http\Runner', 'object' => object(Cake\Http\Runner) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {} ] ], (int) 8 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/Runner.php', 'line' => (int) 65, 'function' => '__invoke', 'class' => 'Cake\Routing\Middleware\RoutingMiddleware', 'object' => object(Cake\Routing\Middleware\RoutingMiddleware) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {}, (int) 2 => object(Cake\Http\Runner) {} ] ], (int) 9 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Routing/Middleware/AssetMiddleware.php', 'line' => (int) 88, 'function' => '__invoke', 'class' => 'Cake\Http\Runner', 'object' => object(Cake\Http\Runner) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {} ] ], (int) 10 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/Runner.php', 'line' => (int) 65, 'function' => '__invoke', 'class' => 'Cake\Routing\Middleware\AssetMiddleware', 'object' => object(Cake\Routing\Middleware\AssetMiddleware) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {}, (int) 2 => object(Cake\Http\Runner) {} ] ], (int) 11 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Error/Middleware/ErrorHandlerMiddleware.php', 'line' => (int) 96, 'function' => '__invoke', 'class' => 'Cake\Http\Runner', 'object' => object(Cake\Http\Runner) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {} ] ], (int) 12 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/Runner.php', 'line' => (int) 65, 'function' => '__invoke', 'class' => 'Cake\Error\Middleware\ErrorHandlerMiddleware', 'object' => object(Cake\Error\Middleware\ErrorHandlerMiddleware) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {}, (int) 2 => object(Cake\Http\Runner) {} ] ], (int) 13 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/Runner.php', 'line' => (int) 51, 'function' => '__invoke', 'class' => 'Cake\Http\Runner', 'object' => object(Cake\Http\Runner) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {} ] ], (int) 14 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/Server.php', 'line' => (int) 98, 'function' => 'run', 'class' => 'Cake\Http\Runner', 'object' => object(Cake\Http\Runner) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\MiddlewareQueue) {}, (int) 1 => object(Cake\Http\ServerRequest) {}, (int) 2 => object(Cake\Http\Response) {} ] ], (int) 15 => [ 'file' => '/home/brlfuser/public_html/webroot/index.php', 'line' => (int) 39, 'function' => 'run', 'class' => 'Cake\Http\Server', 'object' => object(Cake\Http\Server) {}, 'type' => '->', 'args' => [] ] ] $frame = [ 'file' => '/home/brlfuser/public_html/src/Controller/ArtileDetailController.php', 'line' => (int) 74, 'function' => 'offsetGet', 'class' => 'Cake\Http\ServerRequest', 'object' => object(Cake\Http\ServerRequest) { trustProxy => false [protected] params => [ [maximum depth reached] ] [protected] data => [[maximum depth reached]] [protected] query => [[maximum depth reached]] [protected] cookies => [ [maximum depth reached] ] [protected] _environment => [ [maximum depth reached] ] [protected] url => 'latest-news-updates/a-tale-of-errors-r-ramakumar-16029/print' [protected] base => '' [protected] webroot => '/' [protected] here => '/latest-news-updates/a-tale-of-errors-r-ramakumar-16029/print' [protected] trustedProxies => [[maximum depth reached]] [protected] _input => null [protected] _detectors => [ [maximum depth reached] ] [protected] _detectorCache => [ [maximum depth reached] ] [protected] stream => object(Zend\Diactoros\PhpInputStream) {} [protected] uri => object(Zend\Diactoros\Uri) {} [protected] session => object(Cake\Http\Session) {} [protected] attributes => [[maximum depth reached]] [protected] emulatedAttributes => [ [maximum depth reached] ] [protected] uploadedFiles => [[maximum depth reached]] [protected] protocol => null [protected] requestTarget => null [private] deprecatedProperties => [ [maximum depth reached] ] }, 'type' => '->', 'args' => [ (int) 0 => 'artileslug' ] ]deprecationWarning - CORE/src/Core/functions.php, line 311 Cake\Http\ServerRequest::offsetGet() - CORE/src/Http/ServerRequest.php, line 2421 App\Controller\ArtileDetailController::printArticle() - APP/Controller/ArtileDetailController.php, line 74 Cake\Controller\Controller::invokeAction() - CORE/src/Controller/Controller.php, line 610 Cake\Http\ActionDispatcher::_invoke() - CORE/src/Http/ActionDispatcher.php, line 120 Cake\Http\ActionDispatcher::dispatch() - CORE/src/Http/ActionDispatcher.php, line 94 Cake\Http\BaseApplication::__invoke() - CORE/src/Http/BaseApplication.php, line 235 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Routing\Middleware\RoutingMiddleware::__invoke() - CORE/src/Routing/Middleware/RoutingMiddleware.php, line 162 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Routing\Middleware\AssetMiddleware::__invoke() - CORE/src/Routing/Middleware/AssetMiddleware.php, line 88 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Error\Middleware\ErrorHandlerMiddleware::__invoke() - CORE/src/Error/Middleware/ErrorHandlerMiddleware.php, line 96 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Http\Runner::run() - CORE/src/Http/Runner.php, line 51 Cake\Http\Server::run() - CORE/src/Http/Server.php, line 98
Warning (512): Unable to emit headers. Headers sent in file=/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Error/Debugger.php line=853 [CORE/src/Http/ResponseEmitter.php, line 48]Code Contextif (Configure::read('debug')) {
trigger_error($message, E_USER_WARNING);
} else {
$response = object(Cake\Http\Response) { 'status' => (int) 200, 'contentType' => 'text/html', 'headers' => [ 'Content-Type' => [ [maximum depth reached] ] ], 'file' => null, 'fileRange' => [], 'cookies' => object(Cake\Http\Cookie\CookieCollection) {}, 'cacheDirectives' => [], 'body' => '<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <link rel="canonical" href="https://im4change.in/<pre class="cake-error"><a href="javascript:void(0);" onclick="document.getElementById('cakeErr67f22b79047f1-trace').style.display = (document.getElementById('cakeErr67f22b79047f1-trace').style.display == 'none' ? '' : 'none');"><b>Notice</b> (8)</a>: Undefined variable: urlPrefix [<b>APP/Template/Layout/printlayout.ctp</b>, line <b>8</b>]<div id="cakeErr67f22b79047f1-trace" class="cake-stack-trace" style="display: none;"><a href="javascript:void(0);" onclick="document.getElementById('cakeErr67f22b79047f1-code').style.display = (document.getElementById('cakeErr67f22b79047f1-code').style.display == 'none' ? '' : 'none')">Code</a> <a href="javascript:void(0);" onclick="document.getElementById('cakeErr67f22b79047f1-context').style.display = (document.getElementById('cakeErr67f22b79047f1-context').style.display == 'none' ? '' : 'none')">Context</a><pre id="cakeErr67f22b79047f1-code" class="cake-code-dump" style="display: none;"><code><span style="color: #000000"><span style="color: #0000BB"></span><span style="color: #007700"><</span><span style="color: #0000BB">head</span><span style="color: #007700">> </span></span></code> <span class="code-highlight"><code><span style="color: #000000"> <link rel="canonical" href="<span style="color: #0000BB"><?php </span><span style="color: #007700">echo </span><span style="color: #0000BB">Configure</span><span style="color: #007700">::</span><span style="color: #0000BB">read</span><span style="color: #007700">(</span><span style="color: #DD0000">'SITE_URL'</span><span style="color: #007700">); </span><span style="color: #0000BB">?><?php </span><span style="color: #007700">echo </span><span style="color: #0000BB">$urlPrefix</span><span style="color: #007700">;</span><span style="color: #0000BB">?><?php </span><span style="color: #007700">echo </span><span style="color: #0000BB">$article_current</span><span style="color: #007700">-></span><span style="color: #0000BB">category</span><span style="color: #007700">-></span><span style="color: #0000BB">slug</span><span style="color: #007700">; </span><span style="color: #0000BB">?></span>/<span style="color: #0000BB"><?php </span><span style="color: #007700">echo </span><span style="color: #0000BB">$article_current</span><span style="color: #007700">-></span><span style="color: #0000BB">seo_url</span><span style="color: #007700">; </span><span style="color: #0000BB">?></span>.html"/> </span></code></span> <code><span style="color: #000000"><span style="color: #0000BB"> </span><span style="color: #007700"><</span><span style="color: #0000BB">meta http</span><span style="color: #007700">-</span><span style="color: #0000BB">equiv</span><span style="color: #007700">=</span><span style="color: #DD0000">"Content-Type" </span><span style="color: #0000BB">content</span><span style="color: #007700">=</span><span style="color: #DD0000">"text/html; charset=utf-8"</span><span style="color: #007700">/> </span></span></code></pre><pre id="cakeErr67f22b79047f1-context" class="cake-context" style="display: none;">$viewFile = '/home/brlfuser/public_html/src/Template/Layout/printlayout.ctp' $dataForView = [ 'article_current' => object(App\Model\Entity\Article) { 'id' => (int) 15902, 'title' => 'A tale of errors-R Ramakumar', 'subheading' => '', 'description' => '<div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> <em>Contrary to the claims of the UIDAI, fingerprints are a highly inappropriate tool to uniquely identify individuals.</em> </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Case 1: &ldquo;There are nine checks on visa nationals arriving into the U.K. [United Kingdom]. The fingerprint matching check is the most recent. It is the least reliable. It is the least effective in terms of delivering against our requirements&hellip;.&rdquo; </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> So stated Brodie Clark, the former head of the United Kingdom Border Force, to a stunned Home Affairs Committee on November 15, 2011. Clark was giving oral evidence to the committee on why he had authorised the suspension of fingerprint checks during busy hours at U.K. airports. Pressed further, Clark said, &ldquo;I knew of it, and I approved it because it was a very sensible thing.&rdquo; </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Case 2: &ldquo;The FBI [Federal Bureau of Investigation] apologises to Mr Mayfield and his family for the hardships that this matter has caused.&rdquo; </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The FBI&rsquo;s apology came in a public statement, dated May 24, 2004. Brandon Mayfield was an attorney in Oregon and a Muslim convert who was held as a material witness in the Madrid bombing of March 11, 2004. The Spanish police had located a latent fingerprint on a bag that contained explosives and sent it to the FBI. The FBI shortlisted potential matches from its fingerprint database. Two fingerprint experts, one internal and another external, concluded that the latent fingerprint belonged to Mayfield; one expert termed the match as &ldquo;100% identification&rdquo;. Mayfield was jailed on the basis of the fingerprint match. Two weeks later, the Spanish police informed the FBI that they had independently matched the latent print with Ouhnane Daoud, an Algerian national living in Spain. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The FBI&rsquo;s fingerprint gaffe on Mayfield was not the first in the U.S. A few years earlier, Stephen Cowans had to serve a jail sentence of more than six years in Boston on the basis of a false fingerprint match. He was exonerated on the basis of DNA evidence. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> For years, the infallibility of fingerprints as a mark of uniqueness has been some sort of a fairy tale. But with increasing cases of fingerprint mismatches leading to human rights violations like prison detentions, the confidence is waning. Indeed, it was such loss of confidence that contributed to the shelving of national identity projects in the U.K. and many other countries. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> If the confidence is waning globally, in India there appears to be a deeply intriguing faith in the use of fingerprints in establishing unique identity for a population of 120 crore. The Aadhaar project is a classic example. Biometrics &ndash; particularly fingerprints &ndash; is a central feature of the Aadhaar project. That a Parliamentary Standing Committee had torn apart the robustness of the fingerprint technology &ndash; calling it &ldquo;untested and unreliable&rdquo; &ndash; is dismissed by the government. While time will indeed prove this faith misplaced, some immediate respect for the sceptical voice appears to be long overdue. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The entry of biometrics into Aadhaar is characteristic of how governments evade laws and misrepresent expert opinion to insert untested ideas into policy. In 2009 itself, the Biometric Standards Committee (BSC) of the Unique Identification Authority of India (UIDAI) was circumspect about using fingerprints in Aadhaar. It had stated that &ldquo;retaining efficacy while scaling the database size&hellip; to a billion has not been adequately analysed&rdquo;. The BSC also stated that &ldquo;fingerprint quality, the most important variable for determining de-duplication accuracy, has not been studied in depth in the Indian context&rdquo;. The reason: a large share of the population is dependent on hard manual labour, leading to worn-out fingerprints. This was an early note of caution, which the UIDAI ignored. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Even the BSC had failed to list out the problems of fingerprints comprehensively. For instance, the BSC was silent on the issue of &ldquo;template ageing&rdquo;, that is, an increase in &ldquo;false rejection rates&rdquo; as people age and sensor characteristics of fingerprint devices change. According to Kevin Bowyer of the University of Notre Dame, physical ageing of fingers results in decreased suppleness of the skin, more wrinkles, lesser flexibility of joints, and accumulated cuts and scars, all of which change the fingerprint itself. This implies the need to re-enrol a large proportion of people almost annually, making the system vulnerable to fraud. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> There was another note of caution on fingerprints, which too was ignored. A report from 4G Identity Solutions, a supplier and consultant for the UIDAI, had mentioned in 2009 itself that about 15 per cent of the Indian population may fail to enrol because of unreadable fingerprints. It specifically noted that &ldquo;people above 60 years and young children below 12 years may have difficulty enrolling in a fingerprinting system&rdquo;. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> On iris scans, the BSC was even more circumspect. It did not even provide error estimates for iris scans owing to the &ldquo;absence of empirical Indian data&rdquo;. It suggested the use of iris scans only &ldquo;if they [UIDAI] feel it is required&rdquo;. This stance of the BSC did not dissuade the UIDAI from deciding to scan irises too at enrolment. In fact, in a clear case of fudge, UIDAI Chairman Nandan Nilekani stated in an interview to PlanetBiometrics (July 5, 2010) that the BSC had &ldquo; recommended the inclusion of iris to the biometric modalities&rdquo;. This was wrong; the BSC never made such a recommendation. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> It is becoming increasingly clear that the decision to include biometrics in Aadhaar had no scientific basis and flew in the face of available evidence (see &ldquo;How Reliable is UID?&rdquo;, Frontline, November 19, 2011). Recent evidence suggests that the chickens are indeed coming home to roost. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Biometrics appears at two stages in the Aadhaar project. The first stage is &ldquo;enrolment&rdquo;, where three sets of biometrics are collected from each resident: a photograph, fingerprints of all 10 fingers and iris scans of both eyes. The fingerprints and iris scans are used to uniquely identify (or &ldquo;de-duplicate&rdquo;) each resident and allot a unique Aadhaar number. The second stage is &ldquo;authentication&rdquo;; here, a service would be provided to residents only upon confirmation that his/her fingerprint &ldquo;matches&rdquo; the fingerprint stored against his/her name in the enrolment database. Iris scans are not used at the stage of authentication. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> I shall try to argue here that at both the stages &ndash; enrolment and authentication &ndash; the quantum of errors associated with biometrics is too large to be ignored. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> <em>Errors in enrolment</em> </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Let us first take enrolment. Facts emerging from the ground reveal that there have been widespread errors at this stage and that biometrics has been of little help. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> First, in Hyderabad, a data entry supervisor by the name of Mohammed Ali &ndash; a former employee of the Infrastructure Leasing and Financial Services Limited (IL&amp;FS) &ndash; was shown to have enrolled more than 30,000 residents in a short span of three months. According to reports, all the 30,000 applicants had been issued Aadhaar numbers. There were two interesting aspects with respect to biometrics in this scam. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> (a) Out of the 30,000 residents enrolled, about 870 people were enrolled as physically disabled (&ldquo;biometric exceptions&rdquo; in the UIDAI parlance). Their biometric information was not recorded. It is unclear as to how many of these 870 were actually disabled because most of their addresses were fake. It is also unclear as to how many thousands of such fake enrolments have already taken place across India. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> (b) A large proportion of the 30,000 residents enrolled were not enrolled by Ali (because Ali had left IL&amp;FS in between). Instead, these enrolments were done across 17 enrolment centres by other supervisors who used Ali&rsquo;s login and password. While logging into the system, along with the login and password, supervisors have to submit their fingerprints. Typically, if the supervisor&rsquo;s fingerprints were not matched as Ali&rsquo;s, the system should have rejected access. Yet, all the supervisors could gain access to the system using their fingerprints. Clearly, the system was not able to identify the supplied fingerprints as not Ali&rsquo;s. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Secondly, in what has been the most hilarious Aadhaar number provision to date, one Aadhaar number (4991-1866-5246) was issued in Anantapur district of Andhra Pradesh to a person named Mr Kothimeera (that is, coriander), with his father&rsquo;s name as Mr Palav (biryani) and address as Gongura Tota, Mamidikaya Vooru (Mango village), Jambuladinne, Anantapur, Andhra Pradesh - 515731. To top it, the date of birth of Mr Kothimeera was recorded as 1887, and the photograph on the card was that of a mobile phone. It is as yet unclear as to what biometric records were supplied with &ldquo;Mr Kothimeera&rsquo;s&rdquo; demographic details and how it passed the test of biometric de-duplication. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Thirdly, the Department of Posts is on record that across India, as on April 20, 6.46 lakh Aadhaar letters posted were returned because the addresses did not exist. In Andhra Pradesh itself, about 50,000 Aadhaar letters were lying undelivered because the addresses were fake. In Karwar, Ankola, Kumta, Honnavar and Bhatkal taluks of Karnataka, about 7,000 Aadhaar letters were lying undelivered because the addresses were fake. While fake addresses have nothing to do with biometrics per se, they provide corroborative evidence to the widespread fraud that takes place at enrolment. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> In sum, biometrics has not been able to prevent large-scale errors at the enrolment stage itself. Available evidence itself is persuasive, and it may be logically suspected that unreported errors are of a far larger magnitude. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> <em>Errors in authentication</em> </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Interestingly, while three sets of biometrics are collected at the time of enrolment, only one set &ndash; fingerprints &ndash; is used for authentication. As R.S. Sharma, the Mission Director of the UIDAI, confirmed in an interview to Frontline in 2011, &ldquo;fingerprint is the basic mode of authentication&rdquo;. According to Nandan Nilekani, iris scans are not used at authentication because &ldquo;it&rsquo;s not a mature technology&rdquo;. For the moment, we shall postpone asking the reasons for tweaking expert opinion and deciding to use an immature technology at the stage of enrolment. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> In his Frontline interview, Sharma admitted that the &ldquo;quality of fingerprints&hellip; poses a challenge for later authentication&rdquo;. He also stated that &ldquo;for manual labourers, this authentication will be difficult because only one or two of the 10 fingerprints may be good&rdquo;. It would appear that Sharma was foretelling what the UIDAI&rsquo;s Proof of Concept (PoC) studies published in 2012 were to reveal. The PoC studies reveal that fingerprint-based authentication of large populations is largely a non-starter, and point towards enormous risks of exclusion. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The PoC studies were internal studies on small populations conducted by the UIDAI to test the robustness of real-time, fingerprint-based authentication. There was no external review. In Phase 1, a small sample of 14,220 residents was studied in Tumkur district of Karnataka. In Phase 2, about 35,000 Aadhaar holders were covered across four States. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> First, the results confirm the fear that most people in rural areas have unreadable fingerprints. There was also significant variation of quality across the fingerprints of each individual. However, the UIDAI does not admit this in as many words. Instead, the PoC report says: &ldquo;Certain fingers were observed to provide better authentication accuracy due to good fingerprint ridges and hence better image quality.&rdquo; Further, it says that &ldquo;providing multiple attempts of the same finger was seen to improve resident&rsquo;s chances of successful authentication&rdquo;. Finally, &ldquo;senior residents (60+) had the highest rejection rates&rdquo;; age-wise rejection rates, however, are not provided. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Let us paraphrase the above three results: (a) only some fingers of residents showed best authentication accuracy; (b) even when fingerprint quality was good, authentication was not always successful at the first try; and (c) residents above the age of 60 years showed poor authentication accuracy. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Secondly, to bypass the pervasive problem of poor fingerprint quality, the PoC study defines a &ldquo;best finger&rdquo;. It is the finger that &ldquo;provides the highest chance of successful authentication&rdquo;. The idea of a &ldquo;best finger&rdquo; is a cop-out from the real problem of poor fingerprint quality. Only 93.6 per cent of the residents possessed at least one best finger. Thus, for 6.4 per cent of the residents authentication was not possible with a single finger. In absolute terms, when extrapolated to the population of 120 crore, a 6.4 per cent share translates to 7.2 crore persons. While the use of more than one finger improves authentication accuracy, the figure of 93.6 per cent provides an insight into the potential extent of exclusion due to fingerprint authentication. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Thirdly, authentication was possible only in the case of 93.5 per cent of residents with a single finger at the first attempt itself (see figure). In other words, in the case of about 6.5 per cent of residents (translating to 7.8 crore residents, when applied to 120 crore) authentication was not possible at the first attempt with a single finger. Even when three attempts were allowed, only 96.5 per cent of residents were able to be authenticated. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> In India, even a small share of exclusion from authentication can imply the actual exclusion of crores of individuals. Further, when applied to larger populations, the share of residents without one best finger is likely to rise sharply. At 120 crore people, it is impossible to forecast what this share would explode into. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Contrary to the claims of the UIDAI, fingerprints will be a highly inappropriate tool to uniquely identify individuals. Given multiple errors during enrolment and the potentially high error rates at authentication, the use of fingerprint authentication is likely to foster a regime of misidentification and exclusion. Worse still, exclusion will be most acute among poor manual labourers. The poor record of fingerprint readers in U.K. airports and frequent fingerprint mismatches in the U.S. were also a result of fallibilities in the fingerprint technology. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The elderly is another group that would be massively excluded. As the PoC reports admit, those above 60 years had the &ldquo;highest rejection rates&rdquo; at authentication. Yet, the Mid-Term Review of the Eleventh Plan by the Planning Commission has recommended the use of Aadhaar fingerprints to pay pension to the elderly through the National Social Assistance Programme (NSAP). The recommendation is to use &ldquo;banking correspondents&rdquo;, who would carry handheld fingerprint devices, to make &ldquo;payments at the doorstep&rdquo;. A sure recipe for exclusion, it would appear. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> In fact, the only group that appears certain to gain from the Aadhaar project is the global biometric industry. As Nandan Nilekani suggested in an interview, &ldquo;the Unique Identification Project is creating new opportunities for biometric technology&hellip;. Our success can, therefore, determine the course the industry will take, since these technologies will be tested in India on an unprecedented scale.&rdquo; On the other hand, the losses are likely to be felt mostly by the poor. It would be an irony that a project that is marketed in the name of &ldquo;including the poor&rdquo; would end up excluding them massively from whatever meagre provisions they obtain from the state today. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> <em>R. Ramakumar is Associate Professor at the Tata Institute of Social Sciences, Mumbai.</em> </div>', 'credit_writer' => 'Frontline, Volume 29, Issue 13, 30 June-13 July, 2012, http://www.frontline.in/stories/20120713291303400.htm', 'article_img' => '', 'article_img_thumb' => '', 'status' => (int) 1, 'show_on_home' => (int) 1, 'lang' => 'EN', 'category_id' => (int) 16, 'tag_keyword' => '', 'seo_url' => 'a-tale-of-errors-r-ramakumar-16029', 'meta_title' => null, 'meta_keywords' => null, 'meta_description' => null, 'noindex' => (int) 0, 'publish_date' => object(Cake\I18n\FrozenDate) {}, 'most_visit_section_id' => null, 'article_big_img' => null, 'liveid' => (int) 16029, 'created' => object(Cake\I18n\FrozenTime) {}, 'modified' => object(Cake\I18n\FrozenTime) {}, 'edate' => '', 'tags' => [ [maximum depth reached] ], 'category' => object(App\Model\Entity\Category) {}, '[new]' => false, '[accessible]' => [ [maximum depth reached] ], '[dirty]' => [[maximum depth reached]], '[original]' => [[maximum depth reached]], '[virtual]' => [[maximum depth reached]], '[hasErrors]' => false, '[errors]' => [[maximum depth reached]], '[invalid]' => [[maximum depth reached]], '[repository]' => 'Articles' }, 'articleid' => (int) 15902, 'metaTitle' => 'LATEST NEWS UPDATES | A tale of errors-R Ramakumar', 'metaKeywords' => 'aadhaar,uid,ICTs', 'metaDesc' => ' Contrary to the claims of the UIDAI, fingerprints are a highly inappropriate tool to uniquely identify individuals. Case 1: &ldquo;There are nine checks on visa nationals arriving into the U.K. [United Kingdom]. The fingerprint matching check is the most recent. It...', 'disp' => '<div style="text-align: justify"><br /></div><div style="text-align: justify"><em>Contrary to the claims of the UIDAI, fingerprints are a highly inappropriate tool to uniquely identify individuals.</em></div><div style="text-align: justify"><br /></div><div style="text-align: justify">Case 1: &ldquo;There are nine checks on visa nationals arriving into the U.K. [United Kingdom]. The fingerprint matching check is the most recent. It is the least reliable. It is the least effective in terms of delivering against our requirements&hellip;.&rdquo;</div><div style="text-align: justify"><br /></div><div style="text-align: justify">So stated Brodie Clark, the former head of the United Kingdom Border Force, to a stunned Home Affairs Committee on November 15, 2011. Clark was giving oral evidence to the committee on why he had authorised the suspension of fingerprint checks during busy hours at U.K. airports. Pressed further, Clark said, &ldquo;I knew of it, and I approved it because it was a very sensible thing.&rdquo;</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Case 2: &ldquo;The FBI [Federal Bureau of Investigation] apologises to Mr Mayfield and his family for the hardships that this matter has caused.&rdquo;</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The FBI&rsquo;s apology came in a public statement, dated May 24, 2004. Brandon Mayfield was an attorney in Oregon and a Muslim convert who was held as a material witness in the Madrid bombing of March 11, 2004. The Spanish police had located a latent fingerprint on a bag that contained explosives and sent it to the FBI. The FBI shortlisted potential matches from its fingerprint database. Two fingerprint experts, one internal and another external, concluded that the latent fingerprint belonged to Mayfield; one expert termed the match as &ldquo;100% identification&rdquo;. Mayfield was jailed on the basis of the fingerprint match. Two weeks later, the Spanish police informed the FBI that they had independently matched the latent print with Ouhnane Daoud, an Algerian national living in Spain.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The FBI&rsquo;s fingerprint gaffe on Mayfield was not the first in the U.S. A few years earlier, Stephen Cowans had to serve a jail sentence of more than six years in Boston on the basis of a false fingerprint match. He was exonerated on the basis of DNA evidence.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">For years, the infallibility of fingerprints as a mark of uniqueness has been some sort of a fairy tale. But with increasing cases of fingerprint mismatches leading to human rights violations like prison detentions, the confidence is waning. Indeed, it was such loss of confidence that contributed to the shelving of national identity projects in the U.K. and many other countries.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">If the confidence is waning globally, in India there appears to be a deeply intriguing faith in the use of fingerprints in establishing unique identity for a population of 120 crore. The Aadhaar project is a classic example. Biometrics &ndash; particularly fingerprints &ndash; is a central feature of the Aadhaar project. That a Parliamentary Standing Committee had torn apart the robustness of the fingerprint technology &ndash; calling it &ldquo;untested and unreliable&rdquo; &ndash; is dismissed by the government. While time will indeed prove this faith misplaced, some immediate respect for the sceptical voice appears to be long overdue.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The entry of biometrics into Aadhaar is characteristic of how governments evade laws and misrepresent expert opinion to insert untested ideas into policy. In 2009 itself, the Biometric Standards Committee (BSC) of the Unique Identification Authority of India (UIDAI) was circumspect about using fingerprints in Aadhaar. It had stated that &ldquo;retaining efficacy while scaling the database size&hellip; to a billion has not been adequately analysed&rdquo;. The BSC also stated that &ldquo;fingerprint quality, the most important variable for determining de-duplication accuracy, has not been studied in depth in the Indian context&rdquo;. The reason: a large share of the population is dependent on hard manual labour, leading to worn-out fingerprints. This was an early note of caution, which the UIDAI ignored.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Even the BSC had failed to list out the problems of fingerprints comprehensively. For instance, the BSC was silent on the issue of &ldquo;template ageing&rdquo;, that is, an increase in &ldquo;false rejection rates&rdquo; as people age and sensor characteristics of fingerprint devices change. According to Kevin Bowyer of the University of Notre Dame, physical ageing of fingers results in decreased suppleness of the skin, more wrinkles, lesser flexibility of joints, and accumulated cuts and scars, all of which change the fingerprint itself. This implies the need to re-enrol a large proportion of people almost annually, making the system vulnerable to fraud.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">There was another note of caution on fingerprints, which too was ignored. A report from 4G Identity Solutions, a supplier and consultant for the UIDAI, had mentioned in 2009 itself that about 15 per cent of the Indian population may fail to enrol because of unreadable fingerprints. It specifically noted that &ldquo;people above 60 years and young children below 12 years may have difficulty enrolling in a fingerprinting system&rdquo;.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">On iris scans, the BSC was even more circumspect. It did not even provide error estimates for iris scans owing to the &ldquo;absence of empirical Indian data&rdquo;. It suggested the use of iris scans only &ldquo;if they [UIDAI] feel it is required&rdquo;. This stance of the BSC did not dissuade the UIDAI from deciding to scan irises too at enrolment. In fact, in a clear case of fudge, UIDAI Chairman Nandan Nilekani stated in an interview to PlanetBiometrics (July 5, 2010) that the BSC had &ldquo; recommended the inclusion of iris to the biometric modalities&rdquo;. This was wrong; the BSC never made such a recommendation.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">It is becoming increasingly clear that the decision to include biometrics in Aadhaar had no scientific basis and flew in the face of available evidence (see &ldquo;How Reliable is UID?&rdquo;, Frontline, November 19, 2011). Recent evidence suggests that the chickens are indeed coming home to roost.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Biometrics appears at two stages in the Aadhaar project. The first stage is &ldquo;enrolment&rdquo;, where three sets of biometrics are collected from each resident: a photograph, fingerprints of all 10 fingers and iris scans of both eyes. The fingerprints and iris scans are used to uniquely identify (or &ldquo;de-duplicate&rdquo;) each resident and allot a unique Aadhaar number. The second stage is &ldquo;authentication&rdquo;; here, a service would be provided to residents only upon confirmation that his/her fingerprint &ldquo;matches&rdquo; the fingerprint stored against his/her name in the enrolment database. Iris scans are not used at the stage of authentication.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">I shall try to argue here that at both the stages &ndash; enrolment and authentication &ndash; the quantum of errors associated with biometrics is too large to be ignored.</div><div style="text-align: justify"><br /></div><div style="text-align: justify"><em>Errors in enrolment</em></div><div style="text-align: justify"><br /></div><div style="text-align: justify">Let us first take enrolment. Facts emerging from the ground reveal that there have been widespread errors at this stage and that biometrics has been of little help.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">First, in Hyderabad, a data entry supervisor by the name of Mohammed Ali &ndash; a former employee of the Infrastructure Leasing and Financial Services Limited (IL&amp;FS) &ndash; was shown to have enrolled more than 30,000 residents in a short span of three months. According to reports, all the 30,000 applicants had been issued Aadhaar numbers. There were two interesting aspects with respect to biometrics in this scam.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">(a) Out of the 30,000 residents enrolled, about 870 people were enrolled as physically disabled (&ldquo;biometric exceptions&rdquo; in the UIDAI parlance). Their biometric information was not recorded. It is unclear as to how many of these 870 were actually disabled because most of their addresses were fake. It is also unclear as to how many thousands of such fake enrolments have already taken place across India.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">(b) A large proportion of the 30,000 residents enrolled were not enrolled by Ali (because Ali had left IL&amp;FS in between). Instead, these enrolments were done across 17 enrolment centres by other supervisors who used Ali&rsquo;s login and password. While logging into the system, along with the login and password, supervisors have to submit their fingerprints. Typically, if the supervisor&rsquo;s fingerprints were not matched as Ali&rsquo;s, the system should have rejected access. Yet, all the supervisors could gain access to the system using their fingerprints. Clearly, the system was not able to identify the supplied fingerprints as not Ali&rsquo;s.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Secondly, in what has been the most hilarious Aadhaar number provision to date, one Aadhaar number (4991-1866-5246) was issued in Anantapur district of Andhra Pradesh to a person named Mr Kothimeera (that is, coriander), with his father&rsquo;s name as Mr Palav (biryani) and address as Gongura Tota, Mamidikaya Vooru (Mango village), Jambuladinne, Anantapur, Andhra Pradesh - 515731. To top it, the date of birth of Mr Kothimeera was recorded as 1887, and the photograph on the card was that of a mobile phone. It is as yet unclear as to what biometric records were supplied with &ldquo;Mr Kothimeera&rsquo;s&rdquo; demographic details and how it passed the test of biometric de-duplication.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Thirdly, the Department of Posts is on record that across India, as on April 20, 6.46 lakh Aadhaar letters posted were returned because the addresses did not exist. In Andhra Pradesh itself, about 50,000 Aadhaar letters were lying undelivered because the addresses were fake. In Karwar, Ankola, Kumta, Honnavar and Bhatkal taluks of Karnataka, about 7,000 Aadhaar letters were lying undelivered because the addresses were fake. While fake addresses have nothing to do with biometrics per se, they provide corroborative evidence to the widespread fraud that takes place at enrolment.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In sum, biometrics has not been able to prevent large-scale errors at the enrolment stage itself. Available evidence itself is persuasive, and it may be logically suspected that unreported errors are of a far larger magnitude.</div><div style="text-align: justify"><br /></div><div style="text-align: justify"><em>Errors in authentication</em></div><div style="text-align: justify"><br /></div><div style="text-align: justify">Interestingly, while three sets of biometrics are collected at the time of enrolment, only one set &ndash; fingerprints &ndash; is used for authentication. As R.S. Sharma, the Mission Director of the UIDAI, confirmed in an interview to Frontline in 2011, &ldquo;fingerprint is the basic mode of authentication&rdquo;. According to Nandan Nilekani, iris scans are not used at authentication because &ldquo;it&rsquo;s not a mature technology&rdquo;. For the moment, we shall postpone asking the reasons for tweaking expert opinion and deciding to use an immature technology at the stage of enrolment.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In his Frontline interview, Sharma admitted that the &ldquo;quality of fingerprints&hellip; poses a challenge for later authentication&rdquo;. He also stated that &ldquo;for manual labourers, this authentication will be difficult because only one or two of the 10 fingerprints may be good&rdquo;. It would appear that Sharma was foretelling what the UIDAI&rsquo;s Proof of Concept (PoC) studies published in 2012 were to reveal. The PoC studies reveal that fingerprint-based authentication of large populations is largely a non-starter, and point towards enormous risks of exclusion.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The PoC studies were internal studies on small populations conducted by the UIDAI to test the robustness of real-time, fingerprint-based authentication. There was no external review. In Phase 1, a small sample of 14,220 residents was studied in Tumkur district of Karnataka. In Phase 2, about 35,000 Aadhaar holders were covered across four States.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">First, the results confirm the fear that most people in rural areas have unreadable fingerprints. There was also significant variation of quality across the fingerprints of each individual. However, the UIDAI does not admit this in as many words. Instead, the PoC report says: &ldquo;Certain fingers were observed to provide better authentication accuracy due to good fingerprint ridges and hence better image quality.&rdquo; Further, it says that &ldquo;providing multiple attempts of the same finger was seen to improve resident&rsquo;s chances of successful authentication&rdquo;. Finally, &ldquo;senior residents (60+) had the highest rejection rates&rdquo;; age-wise rejection rates, however, are not provided.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Let us paraphrase the above three results: (a) only some fingers of residents showed best authentication accuracy; (b) even when fingerprint quality was good, authentication was not always successful at the first try; and (c) residents above the age of 60 years showed poor authentication accuracy.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Secondly, to bypass the pervasive problem of poor fingerprint quality, the PoC study defines a &ldquo;best finger&rdquo;. It is the finger that &ldquo;provides the highest chance of successful authentication&rdquo;. The idea of a &ldquo;best finger&rdquo; is a cop-out from the real problem of poor fingerprint quality. Only 93.6 per cent of the residents possessed at least one best finger. Thus, for 6.4 per cent of the residents authentication was not possible with a single finger. In absolute terms, when extrapolated to the population of 120 crore, a 6.4 per cent share translates to 7.2 crore persons. While the use of more than one finger improves authentication accuracy, the figure of 93.6 per cent provides an insight into the potential extent of exclusion due to fingerprint authentication.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Thirdly, authentication was possible only in the case of 93.5 per cent of residents with a single finger at the first attempt itself (see figure). In other words, in the case of about 6.5 per cent of residents (translating to 7.8 crore residents, when applied to 120 crore) authentication was not possible at the first attempt with a single finger. Even when three attempts were allowed, only 96.5 per cent of residents were able to be authenticated.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In India, even a small share of exclusion from authentication can imply the actual exclusion of crores of individuals. Further, when applied to larger populations, the share of residents without one best finger is likely to rise sharply. At 120 crore people, it is impossible to forecast what this share would explode into.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Contrary to the claims of the UIDAI, fingerprints will be a highly inappropriate tool to uniquely identify individuals. Given multiple errors during enrolment and the potentially high error rates at authentication, the use of fingerprint authentication is likely to foster a regime of misidentification and exclusion. Worse still, exclusion will be most acute among poor manual labourers. The poor record of fingerprint readers in U.K. airports and frequent fingerprint mismatches in the U.S. were also a result of fallibilities in the fingerprint technology.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The elderly is another group that would be massively excluded. As the PoC reports admit, those above 60 years had the &ldquo;highest rejection rates&rdquo; at authentication. Yet, the Mid-Term Review of the Eleventh Plan by the Planning Commission has recommended the use of Aadhaar fingerprints to pay pension to the elderly through the National Social Assistance Programme (NSAP). The recommendation is to use &ldquo;banking correspondents&rdquo;, who would carry handheld fingerprint devices, to make &ldquo;payments at the doorstep&rdquo;. A sure recipe for exclusion, it would appear.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In fact, the only group that appears certain to gain from the Aadhaar project is the global biometric industry. As Nandan Nilekani suggested in an interview, &ldquo;the Unique Identification Project is creating new opportunities for biometric technology&hellip;. Our success can, therefore, determine the course the industry will take, since these technologies will be tested in India on an unprecedented scale.&rdquo; On the other hand, the losses are likely to be felt mostly by the poor. It would be an irony that a project that is marketed in the name of &ldquo;including the poor&rdquo; would end up excluding them massively from whatever meagre provisions they obtain from the state today.</div><div style="text-align: justify"><br /></div><div style="text-align: justify"><em>R. Ramakumar is Associate Professor at the Tata Institute of Social Sciences, Mumbai.</em></div>', 'lang' => 'English', 'SITE_URL' => 'https://im4change.in/', 'site_title' => 'im4change', 'adminprix' => 'admin' ] $article_current = object(App\Model\Entity\Article) { 'id' => (int) 15902, 'title' => 'A tale of errors-R Ramakumar', 'subheading' => '', 'description' => '<div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> <em>Contrary to the claims of the UIDAI, fingerprints are a highly inappropriate tool to uniquely identify individuals.</em> </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Case 1: &ldquo;There are nine checks on visa nationals arriving into the U.K. [United Kingdom]. The fingerprint matching check is the most recent. It is the least reliable. It is the least effective in terms of delivering against our requirements&hellip;.&rdquo; </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> So stated Brodie Clark, the former head of the United Kingdom Border Force, to a stunned Home Affairs Committee on November 15, 2011. Clark was giving oral evidence to the committee on why he had authorised the suspension of fingerprint checks during busy hours at U.K. airports. Pressed further, Clark said, &ldquo;I knew of it, and I approved it because it was a very sensible thing.&rdquo; </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Case 2: &ldquo;The FBI [Federal Bureau of Investigation] apologises to Mr Mayfield and his family for the hardships that this matter has caused.&rdquo; </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The FBI&rsquo;s apology came in a public statement, dated May 24, 2004. Brandon Mayfield was an attorney in Oregon and a Muslim convert who was held as a material witness in the Madrid bombing of March 11, 2004. The Spanish police had located a latent fingerprint on a bag that contained explosives and sent it to the FBI. The FBI shortlisted potential matches from its fingerprint database. Two fingerprint experts, one internal and another external, concluded that the latent fingerprint belonged to Mayfield; one expert termed the match as &ldquo;100% identification&rdquo;. Mayfield was jailed on the basis of the fingerprint match. Two weeks later, the Spanish police informed the FBI that they had independently matched the latent print with Ouhnane Daoud, an Algerian national living in Spain. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The FBI&rsquo;s fingerprint gaffe on Mayfield was not the first in the U.S. A few years earlier, Stephen Cowans had to serve a jail sentence of more than six years in Boston on the basis of a false fingerprint match. He was exonerated on the basis of DNA evidence. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> For years, the infallibility of fingerprints as a mark of uniqueness has been some sort of a fairy tale. But with increasing cases of fingerprint mismatches leading to human rights violations like prison detentions, the confidence is waning. Indeed, it was such loss of confidence that contributed to the shelving of national identity projects in the U.K. and many other countries. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> If the confidence is waning globally, in India there appears to be a deeply intriguing faith in the use of fingerprints in establishing unique identity for a population of 120 crore. The Aadhaar project is a classic example. Biometrics &ndash; particularly fingerprints &ndash; is a central feature of the Aadhaar project. That a Parliamentary Standing Committee had torn apart the robustness of the fingerprint technology &ndash; calling it &ldquo;untested and unreliable&rdquo; &ndash; is dismissed by the government. While time will indeed prove this faith misplaced, some immediate respect for the sceptical voice appears to be long overdue. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The entry of biometrics into Aadhaar is characteristic of how governments evade laws and misrepresent expert opinion to insert untested ideas into policy. In 2009 itself, the Biometric Standards Committee (BSC) of the Unique Identification Authority of India (UIDAI) was circumspect about using fingerprints in Aadhaar. It had stated that &ldquo;retaining efficacy while scaling the database size&hellip; to a billion has not been adequately analysed&rdquo;. The BSC also stated that &ldquo;fingerprint quality, the most important variable for determining de-duplication accuracy, has not been studied in depth in the Indian context&rdquo;. The reason: a large share of the population is dependent on hard manual labour, leading to worn-out fingerprints. This was an early note of caution, which the UIDAI ignored. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Even the BSC had failed to list out the problems of fingerprints comprehensively. For instance, the BSC was silent on the issue of &ldquo;template ageing&rdquo;, that is, an increase in &ldquo;false rejection rates&rdquo; as people age and sensor characteristics of fingerprint devices change. According to Kevin Bowyer of the University of Notre Dame, physical ageing of fingers results in decreased suppleness of the skin, more wrinkles, lesser flexibility of joints, and accumulated cuts and scars, all of which change the fingerprint itself. This implies the need to re-enrol a large proportion of people almost annually, making the system vulnerable to fraud. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> There was another note of caution on fingerprints, which too was ignored. A report from 4G Identity Solutions, a supplier and consultant for the UIDAI, had mentioned in 2009 itself that about 15 per cent of the Indian population may fail to enrol because of unreadable fingerprints. It specifically noted that &ldquo;people above 60 years and young children below 12 years may have difficulty enrolling in a fingerprinting system&rdquo;. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> On iris scans, the BSC was even more circumspect. It did not even provide error estimates for iris scans owing to the &ldquo;absence of empirical Indian data&rdquo;. It suggested the use of iris scans only &ldquo;if they [UIDAI] feel it is required&rdquo;. This stance of the BSC did not dissuade the UIDAI from deciding to scan irises too at enrolment. In fact, in a clear case of fudge, UIDAI Chairman Nandan Nilekani stated in an interview to PlanetBiometrics (July 5, 2010) that the BSC had &ldquo; recommended the inclusion of iris to the biometric modalities&rdquo;. This was wrong; the BSC never made such a recommendation. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> It is becoming increasingly clear that the decision to include biometrics in Aadhaar had no scientific basis and flew in the face of available evidence (see &ldquo;How Reliable is UID?&rdquo;, Frontline, November 19, 2011). Recent evidence suggests that the chickens are indeed coming home to roost. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Biometrics appears at two stages in the Aadhaar project. The first stage is &ldquo;enrolment&rdquo;, where three sets of biometrics are collected from each resident: a photograph, fingerprints of all 10 fingers and iris scans of both eyes. The fingerprints and iris scans are used to uniquely identify (or &ldquo;de-duplicate&rdquo;) each resident and allot a unique Aadhaar number. The second stage is &ldquo;authentication&rdquo;; here, a service would be provided to residents only upon confirmation that his/her fingerprint &ldquo;matches&rdquo; the fingerprint stored against his/her name in the enrolment database. Iris scans are not used at the stage of authentication. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> I shall try to argue here that at both the stages &ndash; enrolment and authentication &ndash; the quantum of errors associated with biometrics is too large to be ignored. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> <em>Errors in enrolment</em> </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Let us first take enrolment. Facts emerging from the ground reveal that there have been widespread errors at this stage and that biometrics has been of little help. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> First, in Hyderabad, a data entry supervisor by the name of Mohammed Ali &ndash; a former employee of the Infrastructure Leasing and Financial Services Limited (IL&amp;FS) &ndash; was shown to have enrolled more than 30,000 residents in a short span of three months. According to reports, all the 30,000 applicants had been issued Aadhaar numbers. There were two interesting aspects with respect to biometrics in this scam. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> (a) Out of the 30,000 residents enrolled, about 870 people were enrolled as physically disabled (&ldquo;biometric exceptions&rdquo; in the UIDAI parlance). Their biometric information was not recorded. It is unclear as to how many of these 870 were actually disabled because most of their addresses were fake. It is also unclear as to how many thousands of such fake enrolments have already taken place across India. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> (b) A large proportion of the 30,000 residents enrolled were not enrolled by Ali (because Ali had left IL&amp;FS in between). Instead, these enrolments were done across 17 enrolment centres by other supervisors who used Ali&rsquo;s login and password. While logging into the system, along with the login and password, supervisors have to submit their fingerprints. Typically, if the supervisor&rsquo;s fingerprints were not matched as Ali&rsquo;s, the system should have rejected access. Yet, all the supervisors could gain access to the system using their fingerprints. Clearly, the system was not able to identify the supplied fingerprints as not Ali&rsquo;s. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Secondly, in what has been the most hilarious Aadhaar number provision to date, one Aadhaar number (4991-1866-5246) was issued in Anantapur district of Andhra Pradesh to a person named Mr Kothimeera (that is, coriander), with his father&rsquo;s name as Mr Palav (biryani) and address as Gongura Tota, Mamidikaya Vooru (Mango village), Jambuladinne, Anantapur, Andhra Pradesh - 515731. To top it, the date of birth of Mr Kothimeera was recorded as 1887, and the photograph on the card was that of a mobile phone. It is as yet unclear as to what biometric records were supplied with &ldquo;Mr Kothimeera&rsquo;s&rdquo; demographic details and how it passed the test of biometric de-duplication. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Thirdly, the Department of Posts is on record that across India, as on April 20, 6.46 lakh Aadhaar letters posted were returned because the addresses did not exist. In Andhra Pradesh itself, about 50,000 Aadhaar letters were lying undelivered because the addresses were fake. In Karwar, Ankola, Kumta, Honnavar and Bhatkal taluks of Karnataka, about 7,000 Aadhaar letters were lying undelivered because the addresses were fake. While fake addresses have nothing to do with biometrics per se, they provide corroborative evidence to the widespread fraud that takes place at enrolment. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> In sum, biometrics has not been able to prevent large-scale errors at the enrolment stage itself. Available evidence itself is persuasive, and it may be logically suspected that unreported errors are of a far larger magnitude. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> <em>Errors in authentication</em> </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Interestingly, while three sets of biometrics are collected at the time of enrolment, only one set &ndash; fingerprints &ndash; is used for authentication. As R.S. Sharma, the Mission Director of the UIDAI, confirmed in an interview to Frontline in 2011, &ldquo;fingerprint is the basic mode of authentication&rdquo;. According to Nandan Nilekani, iris scans are not used at authentication because &ldquo;it&rsquo;s not a mature technology&rdquo;. For the moment, we shall postpone asking the reasons for tweaking expert opinion and deciding to use an immature technology at the stage of enrolment. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> In his Frontline interview, Sharma admitted that the &ldquo;quality of fingerprints&hellip; poses a challenge for later authentication&rdquo;. He also stated that &ldquo;for manual labourers, this authentication will be difficult because only one or two of the 10 fingerprints may be good&rdquo;. It would appear that Sharma was foretelling what the UIDAI&rsquo;s Proof of Concept (PoC) studies published in 2012 were to reveal. The PoC studies reveal that fingerprint-based authentication of large populations is largely a non-starter, and point towards enormous risks of exclusion. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The PoC studies were internal studies on small populations conducted by the UIDAI to test the robustness of real-time, fingerprint-based authentication. There was no external review. In Phase 1, a small sample of 14,220 residents was studied in Tumkur district of Karnataka. In Phase 2, about 35,000 Aadhaar holders were covered across four States. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> First, the results confirm the fear that most people in rural areas have unreadable fingerprints. There was also significant variation of quality across the fingerprints of each individual. However, the UIDAI does not admit this in as many words. Instead, the PoC report says: &ldquo;Certain fingers were observed to provide better authentication accuracy due to good fingerprint ridges and hence better image quality.&rdquo; Further, it says that &ldquo;providing multiple attempts of the same finger was seen to improve resident&rsquo;s chances of successful authentication&rdquo;. Finally, &ldquo;senior residents (60+) had the highest rejection rates&rdquo;; age-wise rejection rates, however, are not provided. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Let us paraphrase the above three results: (a) only some fingers of residents showed best authentication accuracy; (b) even when fingerprint quality was good, authentication was not always successful at the first try; and (c) residents above the age of 60 years showed poor authentication accuracy. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Secondly, to bypass the pervasive problem of poor fingerprint quality, the PoC study defines a &ldquo;best finger&rdquo;. It is the finger that &ldquo;provides the highest chance of successful authentication&rdquo;. The idea of a &ldquo;best finger&rdquo; is a cop-out from the real problem of poor fingerprint quality. Only 93.6 per cent of the residents possessed at least one best finger. Thus, for 6.4 per cent of the residents authentication was not possible with a single finger. In absolute terms, when extrapolated to the population of 120 crore, a 6.4 per cent share translates to 7.2 crore persons. While the use of more than one finger improves authentication accuracy, the figure of 93.6 per cent provides an insight into the potential extent of exclusion due to fingerprint authentication. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Thirdly, authentication was possible only in the case of 93.5 per cent of residents with a single finger at the first attempt itself (see figure). In other words, in the case of about 6.5 per cent of residents (translating to 7.8 crore residents, when applied to 120 crore) authentication was not possible at the first attempt with a single finger. Even when three attempts were allowed, only 96.5 per cent of residents were able to be authenticated. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> In India, even a small share of exclusion from authentication can imply the actual exclusion of crores of individuals. Further, when applied to larger populations, the share of residents without one best finger is likely to rise sharply. At 120 crore people, it is impossible to forecast what this share would explode into. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Contrary to the claims of the UIDAI, fingerprints will be a highly inappropriate tool to uniquely identify individuals. Given multiple errors during enrolment and the potentially high error rates at authentication, the use of fingerprint authentication is likely to foster a regime of misidentification and exclusion. Worse still, exclusion will be most acute among poor manual labourers. The poor record of fingerprint readers in U.K. airports and frequent fingerprint mismatches in the U.S. were also a result of fallibilities in the fingerprint technology. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The elderly is another group that would be massively excluded. As the PoC reports admit, those above 60 years had the &ldquo;highest rejection rates&rdquo; at authentication. Yet, the Mid-Term Review of the Eleventh Plan by the Planning Commission has recommended the use of Aadhaar fingerprints to pay pension to the elderly through the National Social Assistance Programme (NSAP). The recommendation is to use &ldquo;banking correspondents&rdquo;, who would carry handheld fingerprint devices, to make &ldquo;payments at the doorstep&rdquo;. A sure recipe for exclusion, it would appear. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> In fact, the only group that appears certain to gain from the Aadhaar project is the global biometric industry. As Nandan Nilekani suggested in an interview, &ldquo;the Unique Identification Project is creating new opportunities for biometric technology&hellip;. Our success can, therefore, determine the course the industry will take, since these technologies will be tested in India on an unprecedented scale.&rdquo; On the other hand, the losses are likely to be felt mostly by the poor. It would be an irony that a project that is marketed in the name of &ldquo;including the poor&rdquo; would end up excluding them massively from whatever meagre provisions they obtain from the state today. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> <em>R. Ramakumar is Associate Professor at the Tata Institute of Social Sciences, Mumbai.</em> </div>', 'credit_writer' => 'Frontline, Volume 29, Issue 13, 30 June-13 July, 2012, http://www.frontline.in/stories/20120713291303400.htm', 'article_img' => '', 'article_img_thumb' => '', 'status' => (int) 1, 'show_on_home' => (int) 1, 'lang' => 'EN', 'category_id' => (int) 16, 'tag_keyword' => '', 'seo_url' => 'a-tale-of-errors-r-ramakumar-16029', 'meta_title' => null, 'meta_keywords' => null, 'meta_description' => null, 'noindex' => (int) 0, 'publish_date' => object(Cake\I18n\FrozenDate) {}, 'most_visit_section_id' => null, 'article_big_img' => null, 'liveid' => (int) 16029, 'created' => object(Cake\I18n\FrozenTime) {}, 'modified' => object(Cake\I18n\FrozenTime) {}, 'edate' => '', 'tags' => [ (int) 0 => object(Cake\ORM\Entity) {}, (int) 1 => object(Cake\ORM\Entity) {}, (int) 2 => object(Cake\ORM\Entity) {} ], 'category' => object(App\Model\Entity\Category) {}, '[new]' => false, '[accessible]' => [ '*' => true, 'id' => false ], '[dirty]' => [], '[original]' => [], '[virtual]' => [], '[hasErrors]' => false, '[errors]' => [], '[invalid]' => [], '[repository]' => 'Articles' } $articleid = (int) 15902 $metaTitle = 'LATEST NEWS UPDATES | A tale of errors-R Ramakumar' $metaKeywords = 'aadhaar,uid,ICTs' $metaDesc = ' Contrary to the claims of the UIDAI, fingerprints are a highly inappropriate tool to uniquely identify individuals. Case 1: &ldquo;There are nine checks on visa nationals arriving into the U.K. [United Kingdom]. The fingerprint matching check is the most recent. It...' $disp = '<div style="text-align: justify"><br /></div><div style="text-align: justify"><em>Contrary to the claims of the UIDAI, fingerprints are a highly inappropriate tool to uniquely identify individuals.</em></div><div style="text-align: justify"><br /></div><div style="text-align: justify">Case 1: &ldquo;There are nine checks on visa nationals arriving into the U.K. [United Kingdom]. The fingerprint matching check is the most recent. It is the least reliable. It is the least effective in terms of delivering against our requirements&hellip;.&rdquo;</div><div style="text-align: justify"><br /></div><div style="text-align: justify">So stated Brodie Clark, the former head of the United Kingdom Border Force, to a stunned Home Affairs Committee on November 15, 2011. Clark was giving oral evidence to the committee on why he had authorised the suspension of fingerprint checks during busy hours at U.K. airports. Pressed further, Clark said, &ldquo;I knew of it, and I approved it because it was a very sensible thing.&rdquo;</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Case 2: &ldquo;The FBI [Federal Bureau of Investigation] apologises to Mr Mayfield and his family for the hardships that this matter has caused.&rdquo;</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The FBI&rsquo;s apology came in a public statement, dated May 24, 2004. Brandon Mayfield was an attorney in Oregon and a Muslim convert who was held as a material witness in the Madrid bombing of March 11, 2004. The Spanish police had located a latent fingerprint on a bag that contained explosives and sent it to the FBI. The FBI shortlisted potential matches from its fingerprint database. Two fingerprint experts, one internal and another external, concluded that the latent fingerprint belonged to Mayfield; one expert termed the match as &ldquo;100% identification&rdquo;. Mayfield was jailed on the basis of the fingerprint match. Two weeks later, the Spanish police informed the FBI that they had independently matched the latent print with Ouhnane Daoud, an Algerian national living in Spain.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The FBI&rsquo;s fingerprint gaffe on Mayfield was not the first in the U.S. A few years earlier, Stephen Cowans had to serve a jail sentence of more than six years in Boston on the basis of a false fingerprint match. He was exonerated on the basis of DNA evidence.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">For years, the infallibility of fingerprints as a mark of uniqueness has been some sort of a fairy tale. But with increasing cases of fingerprint mismatches leading to human rights violations like prison detentions, the confidence is waning. Indeed, it was such loss of confidence that contributed to the shelving of national identity projects in the U.K. and many other countries.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">If the confidence is waning globally, in India there appears to be a deeply intriguing faith in the use of fingerprints in establishing unique identity for a population of 120 crore. The Aadhaar project is a classic example. Biometrics &ndash; particularly fingerprints &ndash; is a central feature of the Aadhaar project. That a Parliamentary Standing Committee had torn apart the robustness of the fingerprint technology &ndash; calling it &ldquo;untested and unreliable&rdquo; &ndash; is dismissed by the government. While time will indeed prove this faith misplaced, some immediate respect for the sceptical voice appears to be long overdue.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The entry of biometrics into Aadhaar is characteristic of how governments evade laws and misrepresent expert opinion to insert untested ideas into policy. In 2009 itself, the Biometric Standards Committee (BSC) of the Unique Identification Authority of India (UIDAI) was circumspect about using fingerprints in Aadhaar. It had stated that &ldquo;retaining efficacy while scaling the database size&hellip; to a billion has not been adequately analysed&rdquo;. The BSC also stated that &ldquo;fingerprint quality, the most important variable for determining de-duplication accuracy, has not been studied in depth in the Indian context&rdquo;. The reason: a large share of the population is dependent on hard manual labour, leading to worn-out fingerprints. This was an early note of caution, which the UIDAI ignored.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Even the BSC had failed to list out the problems of fingerprints comprehensively. For instance, the BSC was silent on the issue of &ldquo;template ageing&rdquo;, that is, an increase in &ldquo;false rejection rates&rdquo; as people age and sensor characteristics of fingerprint devices change. According to Kevin Bowyer of the University of Notre Dame, physical ageing of fingers results in decreased suppleness of the skin, more wrinkles, lesser flexibility of joints, and accumulated cuts and scars, all of which change the fingerprint itself. This implies the need to re-enrol a large proportion of people almost annually, making the system vulnerable to fraud.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">There was another note of caution on fingerprints, which too was ignored. A report from 4G Identity Solutions, a supplier and consultant for the UIDAI, had mentioned in 2009 itself that about 15 per cent of the Indian population may fail to enrol because of unreadable fingerprints. It specifically noted that &ldquo;people above 60 years and young children below 12 years may have difficulty enrolling in a fingerprinting system&rdquo;.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">On iris scans, the BSC was even more circumspect. It did not even provide error estimates for iris scans owing to the &ldquo;absence of empirical Indian data&rdquo;. It suggested the use of iris scans only &ldquo;if they [UIDAI] feel it is required&rdquo;. This stance of the BSC did not dissuade the UIDAI from deciding to scan irises too at enrolment. In fact, in a clear case of fudge, UIDAI Chairman Nandan Nilekani stated in an interview to PlanetBiometrics (July 5, 2010) that the BSC had &ldquo; recommended the inclusion of iris to the biometric modalities&rdquo;. This was wrong; the BSC never made such a recommendation.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">It is becoming increasingly clear that the decision to include biometrics in Aadhaar had no scientific basis and flew in the face of available evidence (see &ldquo;How Reliable is UID?&rdquo;, Frontline, November 19, 2011). Recent evidence suggests that the chickens are indeed coming home to roost.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Biometrics appears at two stages in the Aadhaar project. The first stage is &ldquo;enrolment&rdquo;, where three sets of biometrics are collected from each resident: a photograph, fingerprints of all 10 fingers and iris scans of both eyes. The fingerprints and iris scans are used to uniquely identify (or &ldquo;de-duplicate&rdquo;) each resident and allot a unique Aadhaar number. The second stage is &ldquo;authentication&rdquo;; here, a service would be provided to residents only upon confirmation that his/her fingerprint &ldquo;matches&rdquo; the fingerprint stored against his/her name in the enrolment database. Iris scans are not used at the stage of authentication.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">I shall try to argue here that at both the stages &ndash; enrolment and authentication &ndash; the quantum of errors associated with biometrics is too large to be ignored.</div><div style="text-align: justify"><br /></div><div style="text-align: justify"><em>Errors in enrolment</em></div><div style="text-align: justify"><br /></div><div style="text-align: justify">Let us first take enrolment. Facts emerging from the ground reveal that there have been widespread errors at this stage and that biometrics has been of little help.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">First, in Hyderabad, a data entry supervisor by the name of Mohammed Ali &ndash; a former employee of the Infrastructure Leasing and Financial Services Limited (IL&amp;FS) &ndash; was shown to have enrolled more than 30,000 residents in a short span of three months. According to reports, all the 30,000 applicants had been issued Aadhaar numbers. There were two interesting aspects with respect to biometrics in this scam.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">(a) Out of the 30,000 residents enrolled, about 870 people were enrolled as physically disabled (&ldquo;biometric exceptions&rdquo; in the UIDAI parlance). Their biometric information was not recorded. It is unclear as to how many of these 870 were actually disabled because most of their addresses were fake. It is also unclear as to how many thousands of such fake enrolments have already taken place across India.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">(b) A large proportion of the 30,000 residents enrolled were not enrolled by Ali (because Ali had left IL&amp;FS in between). Instead, these enrolments were done across 17 enrolment centres by other supervisors who used Ali&rsquo;s login and password. While logging into the system, along with the login and password, supervisors have to submit their fingerprints. Typically, if the supervisor&rsquo;s fingerprints were not matched as Ali&rsquo;s, the system should have rejected access. Yet, all the supervisors could gain access to the system using their fingerprints. Clearly, the system was not able to identify the supplied fingerprints as not Ali&rsquo;s.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Secondly, in what has been the most hilarious Aadhaar number provision to date, one Aadhaar number (4991-1866-5246) was issued in Anantapur district of Andhra Pradesh to a person named Mr Kothimeera (that is, coriander), with his father&rsquo;s name as Mr Palav (biryani) and address as Gongura Tota, Mamidikaya Vooru (Mango village), Jambuladinne, Anantapur, Andhra Pradesh - 515731. To top it, the date of birth of Mr Kothimeera was recorded as 1887, and the photograph on the card was that of a mobile phone. It is as yet unclear as to what biometric records were supplied with &ldquo;Mr Kothimeera&rsquo;s&rdquo; demographic details and how it passed the test of biometric de-duplication.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Thirdly, the Department of Posts is on record that across India, as on April 20, 6.46 lakh Aadhaar letters posted were returned because the addresses did not exist. In Andhra Pradesh itself, about 50,000 Aadhaar letters were lying undelivered because the addresses were fake. In Karwar, Ankola, Kumta, Honnavar and Bhatkal taluks of Karnataka, about 7,000 Aadhaar letters were lying undelivered because the addresses were fake. While fake addresses have nothing to do with biometrics per se, they provide corroborative evidence to the widespread fraud that takes place at enrolment.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In sum, biometrics has not been able to prevent large-scale errors at the enrolment stage itself. Available evidence itself is persuasive, and it may be logically suspected that unreported errors are of a far larger magnitude.</div><div style="text-align: justify"><br /></div><div style="text-align: justify"><em>Errors in authentication</em></div><div style="text-align: justify"><br /></div><div style="text-align: justify">Interestingly, while three sets of biometrics are collected at the time of enrolment, only one set &ndash; fingerprints &ndash; is used for authentication. As R.S. Sharma, the Mission Director of the UIDAI, confirmed in an interview to Frontline in 2011, &ldquo;fingerprint is the basic mode of authentication&rdquo;. According to Nandan Nilekani, iris scans are not used at authentication because &ldquo;it&rsquo;s not a mature technology&rdquo;. For the moment, we shall postpone asking the reasons for tweaking expert opinion and deciding to use an immature technology at the stage of enrolment.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In his Frontline interview, Sharma admitted that the &ldquo;quality of fingerprints&hellip; poses a challenge for later authentication&rdquo;. He also stated that &ldquo;for manual labourers, this authentication will be difficult because only one or two of the 10 fingerprints may be good&rdquo;. It would appear that Sharma was foretelling what the UIDAI&rsquo;s Proof of Concept (PoC) studies published in 2012 were to reveal. The PoC studies reveal that fingerprint-based authentication of large populations is largely a non-starter, and point towards enormous risks of exclusion.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The PoC studies were internal studies on small populations conducted by the UIDAI to test the robustness of real-time, fingerprint-based authentication. There was no external review. In Phase 1, a small sample of 14,220 residents was studied in Tumkur district of Karnataka. In Phase 2, about 35,000 Aadhaar holders were covered across four States.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">First, the results confirm the fear that most people in rural areas have unreadable fingerprints. There was also significant variation of quality across the fingerprints of each individual. However, the UIDAI does not admit this in as many words. Instead, the PoC report says: &ldquo;Certain fingers were observed to provide better authentication accuracy due to good fingerprint ridges and hence better image quality.&rdquo; Further, it says that &ldquo;providing multiple attempts of the same finger was seen to improve resident&rsquo;s chances of successful authentication&rdquo;. Finally, &ldquo;senior residents (60+) had the highest rejection rates&rdquo;; age-wise rejection rates, however, are not provided.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Let us paraphrase the above three results: (a) only some fingers of residents showed best authentication accuracy; (b) even when fingerprint quality was good, authentication was not always successful at the first try; and (c) residents above the age of 60 years showed poor authentication accuracy.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Secondly, to bypass the pervasive problem of poor fingerprint quality, the PoC study defines a &ldquo;best finger&rdquo;. It is the finger that &ldquo;provides the highest chance of successful authentication&rdquo;. The idea of a &ldquo;best finger&rdquo; is a cop-out from the real problem of poor fingerprint quality. Only 93.6 per cent of the residents possessed at least one best finger. Thus, for 6.4 per cent of the residents authentication was not possible with a single finger. In absolute terms, when extrapolated to the population of 120 crore, a 6.4 per cent share translates to 7.2 crore persons. While the use of more than one finger improves authentication accuracy, the figure of 93.6 per cent provides an insight into the potential extent of exclusion due to fingerprint authentication.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Thirdly, authentication was possible only in the case of 93.5 per cent of residents with a single finger at the first attempt itself (see figure). In other words, in the case of about 6.5 per cent of residents (translating to 7.8 crore residents, when applied to 120 crore) authentication was not possible at the first attempt with a single finger. Even when three attempts were allowed, only 96.5 per cent of residents were able to be authenticated.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In India, even a small share of exclusion from authentication can imply the actual exclusion of crores of individuals. Further, when applied to larger populations, the share of residents without one best finger is likely to rise sharply. At 120 crore people, it is impossible to forecast what this share would explode into.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Contrary to the claims of the UIDAI, fingerprints will be a highly inappropriate tool to uniquely identify individuals. Given multiple errors during enrolment and the potentially high error rates at authentication, the use of fingerprint authentication is likely to foster a regime of misidentification and exclusion. Worse still, exclusion will be most acute among poor manual labourers. The poor record of fingerprint readers in U.K. airports and frequent fingerprint mismatches in the U.S. were also a result of fallibilities in the fingerprint technology.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The elderly is another group that would be massively excluded. As the PoC reports admit, those above 60 years had the &ldquo;highest rejection rates&rdquo; at authentication. Yet, the Mid-Term Review of the Eleventh Plan by the Planning Commission has recommended the use of Aadhaar fingerprints to pay pension to the elderly through the National Social Assistance Programme (NSAP). The recommendation is to use &ldquo;banking correspondents&rdquo;, who would carry handheld fingerprint devices, to make &ldquo;payments at the doorstep&rdquo;. A sure recipe for exclusion, it would appear.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In fact, the only group that appears certain to gain from the Aadhaar project is the global biometric industry. As Nandan Nilekani suggested in an interview, &ldquo;the Unique Identification Project is creating new opportunities for biometric technology&hellip;. Our success can, therefore, determine the course the industry will take, since these technologies will be tested in India on an unprecedented scale.&rdquo; On the other hand, the losses are likely to be felt mostly by the poor. It would be an irony that a project that is marketed in the name of &ldquo;including the poor&rdquo; would end up excluding them massively from whatever meagre provisions they obtain from the state today.</div><div style="text-align: justify"><br /></div><div style="text-align: justify"><em>R. Ramakumar is Associate Professor at the Tata Institute of Social Sciences, Mumbai.</em></div>' $lang = 'English' $SITE_URL = 'https://im4change.in/' $site_title = 'im4change' $adminprix = 'admin'</pre><pre class="stack-trace">include - APP/Template/Layout/printlayout.ctp, line 8 Cake\View\View::_evaluate() - CORE/src/View/View.php, line 1413 Cake\View\View::_render() - CORE/src/View/View.php, line 1374 Cake\View\View::renderLayout() - CORE/src/View/View.php, line 927 Cake\View\View::render() - CORE/src/View/View.php, line 885 Cake\Controller\Controller::render() - CORE/src/Controller/Controller.php, line 791 Cake\Http\ActionDispatcher::_invoke() - CORE/src/Http/ActionDispatcher.php, line 126 Cake\Http\ActionDispatcher::dispatch() - CORE/src/Http/ActionDispatcher.php, line 94 Cake\Http\BaseApplication::__invoke() - CORE/src/Http/BaseApplication.php, line 235 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Routing\Middleware\RoutingMiddleware::__invoke() - CORE/src/Routing/Middleware/RoutingMiddleware.php, line 162 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Routing\Middleware\AssetMiddleware::__invoke() - CORE/src/Routing/Middleware/AssetMiddleware.php, line 88 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Error\Middleware\ErrorHandlerMiddleware::__invoke() - CORE/src/Error/Middleware/ErrorHandlerMiddleware.php, line 96 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Http\Runner::run() - CORE/src/Http/Runner.php, line 51</pre></div></pre>latest-news-updates/a-tale-of-errors-r-ramakumar-16029.html"/> <meta http-equiv="Content-Type" content="text/html; charset=utf-8"/> <link href="https://im4change.in/css/control.css" rel="stylesheet" type="text/css" media="all"/> <title>LATEST NEWS UPDATES | A tale of errors-R Ramakumar | Im4change.org</title> <meta name="description" content=" Contrary to the claims of the UIDAI, fingerprints are a highly inappropriate tool to uniquely identify individuals. Case 1: “There are nine checks on visa nationals arriving into the U.K. [United Kingdom]. The fingerprint matching check is the most recent. It..."/> <script src="https://im4change.in/js/jquery-1.10.2.js"></script> <script type="text/javascript" src="https://im4change.in/js/jquery-migrate.min.js"></script> <script language="javascript" type="text/javascript"> $(document).ready(function () { var img = $("img")[0]; // Get my img elem var pic_real_width, pic_real_height; $("<img/>") // Make in memory copy of image to avoid css issues .attr("src", $(img).attr("src")) .load(function () { pic_real_width = this.width; // Note: $(this).width() will not pic_real_height = this.height; // work for in memory images. }); }); </script> <style type="text/css"> @media screen { div.divFooter { display: block; } } @media print { .printbutton { display: none !important; } } </style> </head> <body> <table cellpadding="0" cellspacing="0" border="0" width="98%" align="center"> <tr> <td class="top_bg"> <div class="divFooter"> <img src="https://im4change.in/images/logo1.jpg" height="59" border="0" alt="Resource centre on India's rural distress" style="padding-top:14px;"/> </div> </td> </tr> <tr> <td id="topspace"> </td> </tr> <tr id="topspace"> <td> </td> </tr> <tr> <td height="50" style="border-bottom:1px solid #000; padding-top:10px;" class="printbutton"> <form><input type="button" value=" Print this page " onclick="window.print();return false;"/></form> </td> </tr> <tr> <td width="100%"> <h1 class="news_headlines" style="font-style:normal"> <strong>A tale of errors-R Ramakumar</strong></h1> </td> </tr> <tr> <td width="100%" style="font-family:Arial, 'Segoe Script', 'Segoe UI', sans-serif, serif"><font size="3"> <div style="text-align: justify"><br /></div><div style="text-align: justify"><em>Contrary to the claims of the UIDAI, fingerprints are a highly inappropriate tool to uniquely identify individuals.</em></div><div style="text-align: justify"><br /></div><div style="text-align: justify">Case 1: “There are nine checks on visa nationals arriving into the U.K. [United Kingdom]. The fingerprint matching check is the most recent. It is the least reliable. It is the least effective in terms of delivering against our requirements….”</div><div style="text-align: justify"><br /></div><div style="text-align: justify">So stated Brodie Clark, the former head of the United Kingdom Border Force, to a stunned Home Affairs Committee on November 15, 2011. Clark was giving oral evidence to the committee on why he had authorised the suspension of fingerprint checks during busy hours at U.K. airports. Pressed further, Clark said, “I knew of it, and I approved it because it was a very sensible thing.”</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Case 2: “The FBI [Federal Bureau of Investigation] apologises to Mr Mayfield and his family for the hardships that this matter has caused.”</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The FBI’s apology came in a public statement, dated May 24, 2004. Brandon Mayfield was an attorney in Oregon and a Muslim convert who was held as a material witness in the Madrid bombing of March 11, 2004. The Spanish police had located a latent fingerprint on a bag that contained explosives and sent it to the FBI. The FBI shortlisted potential matches from its fingerprint database. Two fingerprint experts, one internal and another external, concluded that the latent fingerprint belonged to Mayfield; one expert termed the match as “100% identification”. Mayfield was jailed on the basis of the fingerprint match. Two weeks later, the Spanish police informed the FBI that they had independently matched the latent print with Ouhnane Daoud, an Algerian national living in Spain.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The FBI’s fingerprint gaffe on Mayfield was not the first in the U.S. A few years earlier, Stephen Cowans had to serve a jail sentence of more than six years in Boston on the basis of a false fingerprint match. He was exonerated on the basis of DNA evidence.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">For years, the infallibility of fingerprints as a mark of uniqueness has been some sort of a fairy tale. But with increasing cases of fingerprint mismatches leading to human rights violations like prison detentions, the confidence is waning. Indeed, it was such loss of confidence that contributed to the shelving of national identity projects in the U.K. and many other countries.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">If the confidence is waning globally, in India there appears to be a deeply intriguing faith in the use of fingerprints in establishing unique identity for a population of 120 crore. The Aadhaar project is a classic example. Biometrics – particularly fingerprints – is a central feature of the Aadhaar project. That a Parliamentary Standing Committee had torn apart the robustness of the fingerprint technology – calling it “untested and unreliable” – is dismissed by the government. While time will indeed prove this faith misplaced, some immediate respect for the sceptical voice appears to be long overdue.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The entry of biometrics into Aadhaar is characteristic of how governments evade laws and misrepresent expert opinion to insert untested ideas into policy. In 2009 itself, the Biometric Standards Committee (BSC) of the Unique Identification Authority of India (UIDAI) was circumspect about using fingerprints in Aadhaar. It had stated that “retaining efficacy while scaling the database size… to a billion has not been adequately analysed”. The BSC also stated that “fingerprint quality, the most important variable for determining de-duplication accuracy, has not been studied in depth in the Indian context”. The reason: a large share of the population is dependent on hard manual labour, leading to worn-out fingerprints. This was an early note of caution, which the UIDAI ignored.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Even the BSC had failed to list out the problems of fingerprints comprehensively. For instance, the BSC was silent on the issue of “template ageing”, that is, an increase in “false rejection rates” as people age and sensor characteristics of fingerprint devices change. According to Kevin Bowyer of the University of Notre Dame, physical ageing of fingers results in decreased suppleness of the skin, more wrinkles, lesser flexibility of joints, and accumulated cuts and scars, all of which change the fingerprint itself. This implies the need to re-enrol a large proportion of people almost annually, making the system vulnerable to fraud.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">There was another note of caution on fingerprints, which too was ignored. A report from 4G Identity Solutions, a supplier and consultant for the UIDAI, had mentioned in 2009 itself that about 15 per cent of the Indian population may fail to enrol because of unreadable fingerprints. It specifically noted that “people above 60 years and young children below 12 years may have difficulty enrolling in a fingerprinting system”.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">On iris scans, the BSC was even more circumspect. It did not even provide error estimates for iris scans owing to the “absence of empirical Indian data”. It suggested the use of iris scans only “if they [UIDAI] feel it is required”. This stance of the BSC did not dissuade the UIDAI from deciding to scan irises too at enrolment. In fact, in a clear case of fudge, UIDAI Chairman Nandan Nilekani stated in an interview to PlanetBiometrics (July 5, 2010) that the BSC had “ recommended the inclusion of iris to the biometric modalities”. This was wrong; the BSC never made such a recommendation.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">It is becoming increasingly clear that the decision to include biometrics in Aadhaar had no scientific basis and flew in the face of available evidence (see “How Reliable is UID?”, Frontline, November 19, 2011). Recent evidence suggests that the chickens are indeed coming home to roost.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Biometrics appears at two stages in the Aadhaar project. The first stage is “enrolment”, where three sets of biometrics are collected from each resident: a photograph, fingerprints of all 10 fingers and iris scans of both eyes. The fingerprints and iris scans are used to uniquely identify (or “de-duplicate”) each resident and allot a unique Aadhaar number. The second stage is “authentication”; here, a service would be provided to residents only upon confirmation that his/her fingerprint “matches” the fingerprint stored against his/her name in the enrolment database. Iris scans are not used at the stage of authentication.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">I shall try to argue here that at both the stages – enrolment and authentication – the quantum of errors associated with biometrics is too large to be ignored.</div><div style="text-align: justify"><br /></div><div style="text-align: justify"><em>Errors in enrolment</em></div><div style="text-align: justify"><br /></div><div style="text-align: justify">Let us first take enrolment. Facts emerging from the ground reveal that there have been widespread errors at this stage and that biometrics has been of little help.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">First, in Hyderabad, a data entry supervisor by the name of Mohammed Ali – a former employee of the Infrastructure Leasing and Financial Services Limited (IL&FS) – was shown to have enrolled more than 30,000 residents in a short span of three months. According to reports, all the 30,000 applicants had been issued Aadhaar numbers. There were two interesting aspects with respect to biometrics in this scam.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">(a) Out of the 30,000 residents enrolled, about 870 people were enrolled as physically disabled (“biometric exceptions” in the UIDAI parlance). Their biometric information was not recorded. It is unclear as to how many of these 870 were actually disabled because most of their addresses were fake. It is also unclear as to how many thousands of such fake enrolments have already taken place across India.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">(b) A large proportion of the 30,000 residents enrolled were not enrolled by Ali (because Ali had left IL&FS in between). Instead, these enrolments were done across 17 enrolment centres by other supervisors who used Ali’s login and password. While logging into the system, along with the login and password, supervisors have to submit their fingerprints. Typically, if the supervisor’s fingerprints were not matched as Ali’s, the system should have rejected access. Yet, all the supervisors could gain access to the system using their fingerprints. Clearly, the system was not able to identify the supplied fingerprints as not Ali’s.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Secondly, in what has been the most hilarious Aadhaar number provision to date, one Aadhaar number (4991-1866-5246) was issued in Anantapur district of Andhra Pradesh to a person named Mr Kothimeera (that is, coriander), with his father’s name as Mr Palav (biryani) and address as Gongura Tota, Mamidikaya Vooru (Mango village), Jambuladinne, Anantapur, Andhra Pradesh - 515731. To top it, the date of birth of Mr Kothimeera was recorded as 1887, and the photograph on the card was that of a mobile phone. It is as yet unclear as to what biometric records were supplied with “Mr Kothimeera’s” demographic details and how it passed the test of biometric de-duplication.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Thirdly, the Department of Posts is on record that across India, as on April 20, 6.46 lakh Aadhaar letters posted were returned because the addresses did not exist. In Andhra Pradesh itself, about 50,000 Aadhaar letters were lying undelivered because the addresses were fake. In Karwar, Ankola, Kumta, Honnavar and Bhatkal taluks of Karnataka, about 7,000 Aadhaar letters were lying undelivered because the addresses were fake. While fake addresses have nothing to do with biometrics per se, they provide corroborative evidence to the widespread fraud that takes place at enrolment.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In sum, biometrics has not been able to prevent large-scale errors at the enrolment stage itself. Available evidence itself is persuasive, and it may be logically suspected that unreported errors are of a far larger magnitude.</div><div style="text-align: justify"><br /></div><div style="text-align: justify"><em>Errors in authentication</em></div><div style="text-align: justify"><br /></div><div style="text-align: justify">Interestingly, while three sets of biometrics are collected at the time of enrolment, only one set – fingerprints – is used for authentication. As R.S. Sharma, the Mission Director of the UIDAI, confirmed in an interview to Frontline in 2011, “fingerprint is the basic mode of authentication”. According to Nandan Nilekani, iris scans are not used at authentication because “it’s not a mature technology”. For the moment, we shall postpone asking the reasons for tweaking expert opinion and deciding to use an immature technology at the stage of enrolment.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In his Frontline interview, Sharma admitted that the “quality of fingerprints… poses a challenge for later authentication”. He also stated that “for manual labourers, this authentication will be difficult because only one or two of the 10 fingerprints may be good”. It would appear that Sharma was foretelling what the UIDAI’s Proof of Concept (PoC) studies published in 2012 were to reveal. The PoC studies reveal that fingerprint-based authentication of large populations is largely a non-starter, and point towards enormous risks of exclusion.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The PoC studies were internal studies on small populations conducted by the UIDAI to test the robustness of real-time, fingerprint-based authentication. There was no external review. In Phase 1, a small sample of 14,220 residents was studied in Tumkur district of Karnataka. In Phase 2, about 35,000 Aadhaar holders were covered across four States.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">First, the results confirm the fear that most people in rural areas have unreadable fingerprints. There was also significant variation of quality across the fingerprints of each individual. However, the UIDAI does not admit this in as many words. Instead, the PoC report says: “Certain fingers were observed to provide better authentication accuracy due to good fingerprint ridges and hence better image quality.” Further, it says that “providing multiple attempts of the same finger was seen to improve resident’s chances of successful authentication”. Finally, “senior residents (60+) had the highest rejection rates”; age-wise rejection rates, however, are not provided.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Let us paraphrase the above three results: (a) only some fingers of residents showed best authentication accuracy; (b) even when fingerprint quality was good, authentication was not always successful at the first try; and (c) residents above the age of 60 years showed poor authentication accuracy.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Secondly, to bypass the pervasive problem of poor fingerprint quality, the PoC study defines a “best finger”. It is the finger that “provides the highest chance of successful authentication”. The idea of a “best finger” is a cop-out from the real problem of poor fingerprint quality. Only 93.6 per cent of the residents possessed at least one best finger. Thus, for 6.4 per cent of the residents authentication was not possible with a single finger. In absolute terms, when extrapolated to the population of 120 crore, a 6.4 per cent share translates to 7.2 crore persons. While the use of more than one finger improves authentication accuracy, the figure of 93.6 per cent provides an insight into the potential extent of exclusion due to fingerprint authentication.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Thirdly, authentication was possible only in the case of 93.5 per cent of residents with a single finger at the first attempt itself (see figure). In other words, in the case of about 6.5 per cent of residents (translating to 7.8 crore residents, when applied to 120 crore) authentication was not possible at the first attempt with a single finger. Even when three attempts were allowed, only 96.5 per cent of residents were able to be authenticated.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In India, even a small share of exclusion from authentication can imply the actual exclusion of crores of individuals. Further, when applied to larger populations, the share of residents without one best finger is likely to rise sharply. At 120 crore people, it is impossible to forecast what this share would explode into.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Contrary to the claims of the UIDAI, fingerprints will be a highly inappropriate tool to uniquely identify individuals. Given multiple errors during enrolment and the potentially high error rates at authentication, the use of fingerprint authentication is likely to foster a regime of misidentification and exclusion. Worse still, exclusion will be most acute among poor manual labourers. The poor record of fingerprint readers in U.K. airports and frequent fingerprint mismatches in the U.S. were also a result of fallibilities in the fingerprint technology.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The elderly is another group that would be massively excluded. As the PoC reports admit, those above 60 years had the “highest rejection rates” at authentication. Yet, the Mid-Term Review of the Eleventh Plan by the Planning Commission has recommended the use of Aadhaar fingerprints to pay pension to the elderly through the National Social Assistance Programme (NSAP). The recommendation is to use “banking correspondents”, who would carry handheld fingerprint devices, to make “payments at the doorstep”. A sure recipe for exclusion, it would appear.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In fact, the only group that appears certain to gain from the Aadhaar project is the global biometric industry. As Nandan Nilekani suggested in an interview, “the Unique Identification Project is creating new opportunities for biometric technology…. Our success can, therefore, determine the course the industry will take, since these technologies will be tested in India on an unprecedented scale.” On the other hand, the losses are likely to be felt mostly by the poor. It would be an irony that a project that is marketed in the name of “including the poor” would end up excluding them massively from whatever meagre provisions they obtain from the state today.</div><div style="text-align: justify"><br /></div><div style="text-align: justify"><em>R. Ramakumar is Associate Professor at the Tata Institute of Social Sciences, Mumbai.</em></div> </font> </td> </tr> <tr> <td> </td> </tr> <tr> <td height="50" style="border-top:1px solid #000; border-bottom:1px solid #000;padding-top:10px;"> <form><input type="button" value=" Print this page " onclick="window.print();return false;"/></form> </td> </tr> </table></body> </html>' } $maxBufferLength = (int) 8192 $file = '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Error/Debugger.php' $line = (int) 853 $message = 'Unable to emit headers. Headers sent in file=/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Error/Debugger.php line=853'Cake\Http\ResponseEmitter::emit() - CORE/src/Http/ResponseEmitter.php, line 48 Cake\Http\Server::emit() - CORE/src/Http/Server.php, line 141 [main] - ROOT/webroot/index.php, line 39
Warning (2): Cannot modify header information - headers already sent by (output started at /home/brlfuser/public_html/vendor/cakephp/cakephp/src/Error/Debugger.php:853) [CORE/src/Http/ResponseEmitter.php, line 148]Code Context$response->getStatusCode(),
($reasonPhrase ? ' ' . $reasonPhrase : '')
));
$response = object(Cake\Http\Response) { 'status' => (int) 200, 'contentType' => 'text/html', 'headers' => [ 'Content-Type' => [ [maximum depth reached] ] ], 'file' => null, 'fileRange' => [], 'cookies' => object(Cake\Http\Cookie\CookieCollection) {}, 'cacheDirectives' => [], 'body' => '<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <link rel="canonical" href="https://im4change.in/<pre class="cake-error"><a href="javascript:void(0);" onclick="document.getElementById('cakeErr67f22b79047f1-trace').style.display = (document.getElementById('cakeErr67f22b79047f1-trace').style.display == 'none' ? '' : 'none');"><b>Notice</b> (8)</a>: Undefined variable: urlPrefix [<b>APP/Template/Layout/printlayout.ctp</b>, line <b>8</b>]<div id="cakeErr67f22b79047f1-trace" class="cake-stack-trace" style="display: none;"><a href="javascript:void(0);" onclick="document.getElementById('cakeErr67f22b79047f1-code').style.display = (document.getElementById('cakeErr67f22b79047f1-code').style.display == 'none' ? '' : 'none')">Code</a> <a href="javascript:void(0);" onclick="document.getElementById('cakeErr67f22b79047f1-context').style.display = (document.getElementById('cakeErr67f22b79047f1-context').style.display == 'none' ? '' : 'none')">Context</a><pre id="cakeErr67f22b79047f1-code" class="cake-code-dump" style="display: none;"><code><span style="color: #000000"><span style="color: #0000BB"></span><span style="color: #007700"><</span><span style="color: #0000BB">head</span><span style="color: #007700">> </span></span></code> <span class="code-highlight"><code><span style="color: #000000"> <link rel="canonical" href="<span style="color: #0000BB"><?php </span><span style="color: #007700">echo </span><span style="color: #0000BB">Configure</span><span style="color: #007700">::</span><span style="color: #0000BB">read</span><span style="color: #007700">(</span><span style="color: #DD0000">'SITE_URL'</span><span style="color: #007700">); </span><span style="color: #0000BB">?><?php </span><span style="color: #007700">echo </span><span style="color: #0000BB">$urlPrefix</span><span style="color: #007700">;</span><span style="color: #0000BB">?><?php </span><span style="color: #007700">echo </span><span style="color: #0000BB">$article_current</span><span style="color: #007700">-></span><span style="color: #0000BB">category</span><span style="color: #007700">-></span><span style="color: #0000BB">slug</span><span style="color: #007700">; </span><span style="color: #0000BB">?></span>/<span style="color: #0000BB"><?php </span><span style="color: #007700">echo </span><span style="color: #0000BB">$article_current</span><span style="color: #007700">-></span><span style="color: #0000BB">seo_url</span><span style="color: #007700">; </span><span style="color: #0000BB">?></span>.html"/> </span></code></span> <code><span style="color: #000000"><span style="color: #0000BB"> </span><span style="color: #007700"><</span><span style="color: #0000BB">meta http</span><span style="color: #007700">-</span><span style="color: #0000BB">equiv</span><span style="color: #007700">=</span><span style="color: #DD0000">"Content-Type" </span><span style="color: #0000BB">content</span><span style="color: #007700">=</span><span style="color: #DD0000">"text/html; charset=utf-8"</span><span style="color: #007700">/> </span></span></code></pre><pre id="cakeErr67f22b79047f1-context" class="cake-context" style="display: none;">$viewFile = '/home/brlfuser/public_html/src/Template/Layout/printlayout.ctp' $dataForView = [ 'article_current' => object(App\Model\Entity\Article) { 'id' => (int) 15902, 'title' => 'A tale of errors-R Ramakumar', 'subheading' => '', 'description' => '<div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> <em>Contrary to the claims of the UIDAI, fingerprints are a highly inappropriate tool to uniquely identify individuals.</em> </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Case 1: &ldquo;There are nine checks on visa nationals arriving into the U.K. [United Kingdom]. The fingerprint matching check is the most recent. It is the least reliable. It is the least effective in terms of delivering against our requirements&hellip;.&rdquo; </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> So stated Brodie Clark, the former head of the United Kingdom Border Force, to a stunned Home Affairs Committee on November 15, 2011. Clark was giving oral evidence to the committee on why he had authorised the suspension of fingerprint checks during busy hours at U.K. airports. Pressed further, Clark said, &ldquo;I knew of it, and I approved it because it was a very sensible thing.&rdquo; </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Case 2: &ldquo;The FBI [Federal Bureau of Investigation] apologises to Mr Mayfield and his family for the hardships that this matter has caused.&rdquo; </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The FBI&rsquo;s apology came in a public statement, dated May 24, 2004. Brandon Mayfield was an attorney in Oregon and a Muslim convert who was held as a material witness in the Madrid bombing of March 11, 2004. The Spanish police had located a latent fingerprint on a bag that contained explosives and sent it to the FBI. The FBI shortlisted potential matches from its fingerprint database. Two fingerprint experts, one internal and another external, concluded that the latent fingerprint belonged to Mayfield; one expert termed the match as &ldquo;100% identification&rdquo;. Mayfield was jailed on the basis of the fingerprint match. Two weeks later, the Spanish police informed the FBI that they had independently matched the latent print with Ouhnane Daoud, an Algerian national living in Spain. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The FBI&rsquo;s fingerprint gaffe on Mayfield was not the first in the U.S. A few years earlier, Stephen Cowans had to serve a jail sentence of more than six years in Boston on the basis of a false fingerprint match. He was exonerated on the basis of DNA evidence. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> For years, the infallibility of fingerprints as a mark of uniqueness has been some sort of a fairy tale. But with increasing cases of fingerprint mismatches leading to human rights violations like prison detentions, the confidence is waning. Indeed, it was such loss of confidence that contributed to the shelving of national identity projects in the U.K. and many other countries. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> If the confidence is waning globally, in India there appears to be a deeply intriguing faith in the use of fingerprints in establishing unique identity for a population of 120 crore. The Aadhaar project is a classic example. Biometrics &ndash; particularly fingerprints &ndash; is a central feature of the Aadhaar project. That a Parliamentary Standing Committee had torn apart the robustness of the fingerprint technology &ndash; calling it &ldquo;untested and unreliable&rdquo; &ndash; is dismissed by the government. While time will indeed prove this faith misplaced, some immediate respect for the sceptical voice appears to be long overdue. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The entry of biometrics into Aadhaar is characteristic of how governments evade laws and misrepresent expert opinion to insert untested ideas into policy. In 2009 itself, the Biometric Standards Committee (BSC) of the Unique Identification Authority of India (UIDAI) was circumspect about using fingerprints in Aadhaar. It had stated that &ldquo;retaining efficacy while scaling the database size&hellip; to a billion has not been adequately analysed&rdquo;. The BSC also stated that &ldquo;fingerprint quality, the most important variable for determining de-duplication accuracy, has not been studied in depth in the Indian context&rdquo;. The reason: a large share of the population is dependent on hard manual labour, leading to worn-out fingerprints. This was an early note of caution, which the UIDAI ignored. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Even the BSC had failed to list out the problems of fingerprints comprehensively. For instance, the BSC was silent on the issue of &ldquo;template ageing&rdquo;, that is, an increase in &ldquo;false rejection rates&rdquo; as people age and sensor characteristics of fingerprint devices change. According to Kevin Bowyer of the University of Notre Dame, physical ageing of fingers results in decreased suppleness of the skin, more wrinkles, lesser flexibility of joints, and accumulated cuts and scars, all of which change the fingerprint itself. This implies the need to re-enrol a large proportion of people almost annually, making the system vulnerable to fraud. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> There was another note of caution on fingerprints, which too was ignored. A report from 4G Identity Solutions, a supplier and consultant for the UIDAI, had mentioned in 2009 itself that about 15 per cent of the Indian population may fail to enrol because of unreadable fingerprints. It specifically noted that &ldquo;people above 60 years and young children below 12 years may have difficulty enrolling in a fingerprinting system&rdquo;. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> On iris scans, the BSC was even more circumspect. It did not even provide error estimates for iris scans owing to the &ldquo;absence of empirical Indian data&rdquo;. It suggested the use of iris scans only &ldquo;if they [UIDAI] feel it is required&rdquo;. This stance of the BSC did not dissuade the UIDAI from deciding to scan irises too at enrolment. In fact, in a clear case of fudge, UIDAI Chairman Nandan Nilekani stated in an interview to PlanetBiometrics (July 5, 2010) that the BSC had &ldquo; recommended the inclusion of iris to the biometric modalities&rdquo;. This was wrong; the BSC never made such a recommendation. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> It is becoming increasingly clear that the decision to include biometrics in Aadhaar had no scientific basis and flew in the face of available evidence (see &ldquo;How Reliable is UID?&rdquo;, Frontline, November 19, 2011). Recent evidence suggests that the chickens are indeed coming home to roost. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Biometrics appears at two stages in the Aadhaar project. The first stage is &ldquo;enrolment&rdquo;, where three sets of biometrics are collected from each resident: a photograph, fingerprints of all 10 fingers and iris scans of both eyes. The fingerprints and iris scans are used to uniquely identify (or &ldquo;de-duplicate&rdquo;) each resident and allot a unique Aadhaar number. The second stage is &ldquo;authentication&rdquo;; here, a service would be provided to residents only upon confirmation that his/her fingerprint &ldquo;matches&rdquo; the fingerprint stored against his/her name in the enrolment database. Iris scans are not used at the stage of authentication. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> I shall try to argue here that at both the stages &ndash; enrolment and authentication &ndash; the quantum of errors associated with biometrics is too large to be ignored. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> <em>Errors in enrolment</em> </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Let us first take enrolment. Facts emerging from the ground reveal that there have been widespread errors at this stage and that biometrics has been of little help. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> First, in Hyderabad, a data entry supervisor by the name of Mohammed Ali &ndash; a former employee of the Infrastructure Leasing and Financial Services Limited (IL&amp;FS) &ndash; was shown to have enrolled more than 30,000 residents in a short span of three months. According to reports, all the 30,000 applicants had been issued Aadhaar numbers. There were two interesting aspects with respect to biometrics in this scam. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> (a) Out of the 30,000 residents enrolled, about 870 people were enrolled as physically disabled (&ldquo;biometric exceptions&rdquo; in the UIDAI parlance). Their biometric information was not recorded. It is unclear as to how many of these 870 were actually disabled because most of their addresses were fake. It is also unclear as to how many thousands of such fake enrolments have already taken place across India. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> (b) A large proportion of the 30,000 residents enrolled were not enrolled by Ali (because Ali had left IL&amp;FS in between). Instead, these enrolments were done across 17 enrolment centres by other supervisors who used Ali&rsquo;s login and password. While logging into the system, along with the login and password, supervisors have to submit their fingerprints. Typically, if the supervisor&rsquo;s fingerprints were not matched as Ali&rsquo;s, the system should have rejected access. Yet, all the supervisors could gain access to the system using their fingerprints. Clearly, the system was not able to identify the supplied fingerprints as not Ali&rsquo;s. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Secondly, in what has been the most hilarious Aadhaar number provision to date, one Aadhaar number (4991-1866-5246) was issued in Anantapur district of Andhra Pradesh to a person named Mr Kothimeera (that is, coriander), with his father&rsquo;s name as Mr Palav (biryani) and address as Gongura Tota, Mamidikaya Vooru (Mango village), Jambuladinne, Anantapur, Andhra Pradesh - 515731. To top it, the date of birth of Mr Kothimeera was recorded as 1887, and the photograph on the card was that of a mobile phone. It is as yet unclear as to what biometric records were supplied with &ldquo;Mr Kothimeera&rsquo;s&rdquo; demographic details and how it passed the test of biometric de-duplication. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Thirdly, the Department of Posts is on record that across India, as on April 20, 6.46 lakh Aadhaar letters posted were returned because the addresses did not exist. In Andhra Pradesh itself, about 50,000 Aadhaar letters were lying undelivered because the addresses were fake. In Karwar, Ankola, Kumta, Honnavar and Bhatkal taluks of Karnataka, about 7,000 Aadhaar letters were lying undelivered because the addresses were fake. While fake addresses have nothing to do with biometrics per se, they provide corroborative evidence to the widespread fraud that takes place at enrolment. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> In sum, biometrics has not been able to prevent large-scale errors at the enrolment stage itself. Available evidence itself is persuasive, and it may be logically suspected that unreported errors are of a far larger magnitude. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> <em>Errors in authentication</em> </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Interestingly, while three sets of biometrics are collected at the time of enrolment, only one set &ndash; fingerprints &ndash; is used for authentication. As R.S. Sharma, the Mission Director of the UIDAI, confirmed in an interview to Frontline in 2011, &ldquo;fingerprint is the basic mode of authentication&rdquo;. According to Nandan Nilekani, iris scans are not used at authentication because &ldquo;it&rsquo;s not a mature technology&rdquo;. For the moment, we shall postpone asking the reasons for tweaking expert opinion and deciding to use an immature technology at the stage of enrolment. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> In his Frontline interview, Sharma admitted that the &ldquo;quality of fingerprints&hellip; poses a challenge for later authentication&rdquo;. He also stated that &ldquo;for manual labourers, this authentication will be difficult because only one or two of the 10 fingerprints may be good&rdquo;. It would appear that Sharma was foretelling what the UIDAI&rsquo;s Proof of Concept (PoC) studies published in 2012 were to reveal. The PoC studies reveal that fingerprint-based authentication of large populations is largely a non-starter, and point towards enormous risks of exclusion. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The PoC studies were internal studies on small populations conducted by the UIDAI to test the robustness of real-time, fingerprint-based authentication. There was no external review. In Phase 1, a small sample of 14,220 residents was studied in Tumkur district of Karnataka. In Phase 2, about 35,000 Aadhaar holders were covered across four States. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> First, the results confirm the fear that most people in rural areas have unreadable fingerprints. There was also significant variation of quality across the fingerprints of each individual. However, the UIDAI does not admit this in as many words. Instead, the PoC report says: &ldquo;Certain fingers were observed to provide better authentication accuracy due to good fingerprint ridges and hence better image quality.&rdquo; Further, it says that &ldquo;providing multiple attempts of the same finger was seen to improve resident&rsquo;s chances of successful authentication&rdquo;. Finally, &ldquo;senior residents (60+) had the highest rejection rates&rdquo;; age-wise rejection rates, however, are not provided. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Let us paraphrase the above three results: (a) only some fingers of residents showed best authentication accuracy; (b) even when fingerprint quality was good, authentication was not always successful at the first try; and (c) residents above the age of 60 years showed poor authentication accuracy. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Secondly, to bypass the pervasive problem of poor fingerprint quality, the PoC study defines a &ldquo;best finger&rdquo;. It is the finger that &ldquo;provides the highest chance of successful authentication&rdquo;. The idea of a &ldquo;best finger&rdquo; is a cop-out from the real problem of poor fingerprint quality. Only 93.6 per cent of the residents possessed at least one best finger. Thus, for 6.4 per cent of the residents authentication was not possible with a single finger. In absolute terms, when extrapolated to the population of 120 crore, a 6.4 per cent share translates to 7.2 crore persons. While the use of more than one finger improves authentication accuracy, the figure of 93.6 per cent provides an insight into the potential extent of exclusion due to fingerprint authentication. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Thirdly, authentication was possible only in the case of 93.5 per cent of residents with a single finger at the first attempt itself (see figure). In other words, in the case of about 6.5 per cent of residents (translating to 7.8 crore residents, when applied to 120 crore) authentication was not possible at the first attempt with a single finger. Even when three attempts were allowed, only 96.5 per cent of residents were able to be authenticated. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> In India, even a small share of exclusion from authentication can imply the actual exclusion of crores of individuals. Further, when applied to larger populations, the share of residents without one best finger is likely to rise sharply. At 120 crore people, it is impossible to forecast what this share would explode into. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Contrary to the claims of the UIDAI, fingerprints will be a highly inappropriate tool to uniquely identify individuals. Given multiple errors during enrolment and the potentially high error rates at authentication, the use of fingerprint authentication is likely to foster a regime of misidentification and exclusion. Worse still, exclusion will be most acute among poor manual labourers. The poor record of fingerprint readers in U.K. airports and frequent fingerprint mismatches in the U.S. were also a result of fallibilities in the fingerprint technology. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The elderly is another group that would be massively excluded. As the PoC reports admit, those above 60 years had the &ldquo;highest rejection rates&rdquo; at authentication. Yet, the Mid-Term Review of the Eleventh Plan by the Planning Commission has recommended the use of Aadhaar fingerprints to pay pension to the elderly through the National Social Assistance Programme (NSAP). The recommendation is to use &ldquo;banking correspondents&rdquo;, who would carry handheld fingerprint devices, to make &ldquo;payments at the doorstep&rdquo;. A sure recipe for exclusion, it would appear. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> In fact, the only group that appears certain to gain from the Aadhaar project is the global biometric industry. As Nandan Nilekani suggested in an interview, &ldquo;the Unique Identification Project is creating new opportunities for biometric technology&hellip;. Our success can, therefore, determine the course the industry will take, since these technologies will be tested in India on an unprecedented scale.&rdquo; On the other hand, the losses are likely to be felt mostly by the poor. It would be an irony that a project that is marketed in the name of &ldquo;including the poor&rdquo; would end up excluding them massively from whatever meagre provisions they obtain from the state today. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> <em>R. Ramakumar is Associate Professor at the Tata Institute of Social Sciences, Mumbai.</em> </div>', 'credit_writer' => 'Frontline, Volume 29, Issue 13, 30 June-13 July, 2012, http://www.frontline.in/stories/20120713291303400.htm', 'article_img' => '', 'article_img_thumb' => '', 'status' => (int) 1, 'show_on_home' => (int) 1, 'lang' => 'EN', 'category_id' => (int) 16, 'tag_keyword' => '', 'seo_url' => 'a-tale-of-errors-r-ramakumar-16029', 'meta_title' => null, 'meta_keywords' => null, 'meta_description' => null, 'noindex' => (int) 0, 'publish_date' => object(Cake\I18n\FrozenDate) {}, 'most_visit_section_id' => null, 'article_big_img' => null, 'liveid' => (int) 16029, 'created' => object(Cake\I18n\FrozenTime) {}, 'modified' => object(Cake\I18n\FrozenTime) {}, 'edate' => '', 'tags' => [ [maximum depth reached] ], 'category' => object(App\Model\Entity\Category) {}, '[new]' => false, '[accessible]' => [ [maximum depth reached] ], '[dirty]' => [[maximum depth reached]], '[original]' => [[maximum depth reached]], '[virtual]' => [[maximum depth reached]], '[hasErrors]' => false, '[errors]' => [[maximum depth reached]], '[invalid]' => [[maximum depth reached]], '[repository]' => 'Articles' }, 'articleid' => (int) 15902, 'metaTitle' => 'LATEST NEWS UPDATES | A tale of errors-R Ramakumar', 'metaKeywords' => 'aadhaar,uid,ICTs', 'metaDesc' => ' Contrary to the claims of the UIDAI, fingerprints are a highly inappropriate tool to uniquely identify individuals. Case 1: &ldquo;There are nine checks on visa nationals arriving into the U.K. [United Kingdom]. The fingerprint matching check is the most recent. It...', 'disp' => '<div style="text-align: justify"><br /></div><div style="text-align: justify"><em>Contrary to the claims of the UIDAI, fingerprints are a highly inappropriate tool to uniquely identify individuals.</em></div><div style="text-align: justify"><br /></div><div style="text-align: justify">Case 1: &ldquo;There are nine checks on visa nationals arriving into the U.K. [United Kingdom]. The fingerprint matching check is the most recent. It is the least reliable. It is the least effective in terms of delivering against our requirements&hellip;.&rdquo;</div><div style="text-align: justify"><br /></div><div style="text-align: justify">So stated Brodie Clark, the former head of the United Kingdom Border Force, to a stunned Home Affairs Committee on November 15, 2011. Clark was giving oral evidence to the committee on why he had authorised the suspension of fingerprint checks during busy hours at U.K. airports. Pressed further, Clark said, &ldquo;I knew of it, and I approved it because it was a very sensible thing.&rdquo;</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Case 2: &ldquo;The FBI [Federal Bureau of Investigation] apologises to Mr Mayfield and his family for the hardships that this matter has caused.&rdquo;</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The FBI&rsquo;s apology came in a public statement, dated May 24, 2004. Brandon Mayfield was an attorney in Oregon and a Muslim convert who was held as a material witness in the Madrid bombing of March 11, 2004. The Spanish police had located a latent fingerprint on a bag that contained explosives and sent it to the FBI. The FBI shortlisted potential matches from its fingerprint database. Two fingerprint experts, one internal and another external, concluded that the latent fingerprint belonged to Mayfield; one expert termed the match as &ldquo;100% identification&rdquo;. Mayfield was jailed on the basis of the fingerprint match. Two weeks later, the Spanish police informed the FBI that they had independently matched the latent print with Ouhnane Daoud, an Algerian national living in Spain.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The FBI&rsquo;s fingerprint gaffe on Mayfield was not the first in the U.S. A few years earlier, Stephen Cowans had to serve a jail sentence of more than six years in Boston on the basis of a false fingerprint match. He was exonerated on the basis of DNA evidence.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">For years, the infallibility of fingerprints as a mark of uniqueness has been some sort of a fairy tale. But with increasing cases of fingerprint mismatches leading to human rights violations like prison detentions, the confidence is waning. Indeed, it was such loss of confidence that contributed to the shelving of national identity projects in the U.K. and many other countries.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">If the confidence is waning globally, in India there appears to be a deeply intriguing faith in the use of fingerprints in establishing unique identity for a population of 120 crore. The Aadhaar project is a classic example. Biometrics &ndash; particularly fingerprints &ndash; is a central feature of the Aadhaar project. That a Parliamentary Standing Committee had torn apart the robustness of the fingerprint technology &ndash; calling it &ldquo;untested and unreliable&rdquo; &ndash; is dismissed by the government. While time will indeed prove this faith misplaced, some immediate respect for the sceptical voice appears to be long overdue.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The entry of biometrics into Aadhaar is characteristic of how governments evade laws and misrepresent expert opinion to insert untested ideas into policy. In 2009 itself, the Biometric Standards Committee (BSC) of the Unique Identification Authority of India (UIDAI) was circumspect about using fingerprints in Aadhaar. It had stated that &ldquo;retaining efficacy while scaling the database size&hellip; to a billion has not been adequately analysed&rdquo;. The BSC also stated that &ldquo;fingerprint quality, the most important variable for determining de-duplication accuracy, has not been studied in depth in the Indian context&rdquo;. The reason: a large share of the population is dependent on hard manual labour, leading to worn-out fingerprints. This was an early note of caution, which the UIDAI ignored.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Even the BSC had failed to list out the problems of fingerprints comprehensively. For instance, the BSC was silent on the issue of &ldquo;template ageing&rdquo;, that is, an increase in &ldquo;false rejection rates&rdquo; as people age and sensor characteristics of fingerprint devices change. According to Kevin Bowyer of the University of Notre Dame, physical ageing of fingers results in decreased suppleness of the skin, more wrinkles, lesser flexibility of joints, and accumulated cuts and scars, all of which change the fingerprint itself. This implies the need to re-enrol a large proportion of people almost annually, making the system vulnerable to fraud.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">There was another note of caution on fingerprints, which too was ignored. A report from 4G Identity Solutions, a supplier and consultant for the UIDAI, had mentioned in 2009 itself that about 15 per cent of the Indian population may fail to enrol because of unreadable fingerprints. It specifically noted that &ldquo;people above 60 years and young children below 12 years may have difficulty enrolling in a fingerprinting system&rdquo;.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">On iris scans, the BSC was even more circumspect. It did not even provide error estimates for iris scans owing to the &ldquo;absence of empirical Indian data&rdquo;. It suggested the use of iris scans only &ldquo;if they [UIDAI] feel it is required&rdquo;. This stance of the BSC did not dissuade the UIDAI from deciding to scan irises too at enrolment. In fact, in a clear case of fudge, UIDAI Chairman Nandan Nilekani stated in an interview to PlanetBiometrics (July 5, 2010) that the BSC had &ldquo; recommended the inclusion of iris to the biometric modalities&rdquo;. This was wrong; the BSC never made such a recommendation.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">It is becoming increasingly clear that the decision to include biometrics in Aadhaar had no scientific basis and flew in the face of available evidence (see &ldquo;How Reliable is UID?&rdquo;, Frontline, November 19, 2011). Recent evidence suggests that the chickens are indeed coming home to roost.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Biometrics appears at two stages in the Aadhaar project. The first stage is &ldquo;enrolment&rdquo;, where three sets of biometrics are collected from each resident: a photograph, fingerprints of all 10 fingers and iris scans of both eyes. The fingerprints and iris scans are used to uniquely identify (or &ldquo;de-duplicate&rdquo;) each resident and allot a unique Aadhaar number. The second stage is &ldquo;authentication&rdquo;; here, a service would be provided to residents only upon confirmation that his/her fingerprint &ldquo;matches&rdquo; the fingerprint stored against his/her name in the enrolment database. Iris scans are not used at the stage of authentication.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">I shall try to argue here that at both the stages &ndash; enrolment and authentication &ndash; the quantum of errors associated with biometrics is too large to be ignored.</div><div style="text-align: justify"><br /></div><div style="text-align: justify"><em>Errors in enrolment</em></div><div style="text-align: justify"><br /></div><div style="text-align: justify">Let us first take enrolment. Facts emerging from the ground reveal that there have been widespread errors at this stage and that biometrics has been of little help.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">First, in Hyderabad, a data entry supervisor by the name of Mohammed Ali &ndash; a former employee of the Infrastructure Leasing and Financial Services Limited (IL&amp;FS) &ndash; was shown to have enrolled more than 30,000 residents in a short span of three months. According to reports, all the 30,000 applicants had been issued Aadhaar numbers. There were two interesting aspects with respect to biometrics in this scam.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">(a) Out of the 30,000 residents enrolled, about 870 people were enrolled as physically disabled (&ldquo;biometric exceptions&rdquo; in the UIDAI parlance). Their biometric information was not recorded. It is unclear as to how many of these 870 were actually disabled because most of their addresses were fake. It is also unclear as to how many thousands of such fake enrolments have already taken place across India.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">(b) A large proportion of the 30,000 residents enrolled were not enrolled by Ali (because Ali had left IL&amp;FS in between). Instead, these enrolments were done across 17 enrolment centres by other supervisors who used Ali&rsquo;s login and password. While logging into the system, along with the login and password, supervisors have to submit their fingerprints. Typically, if the supervisor&rsquo;s fingerprints were not matched as Ali&rsquo;s, the system should have rejected access. Yet, all the supervisors could gain access to the system using their fingerprints. Clearly, the system was not able to identify the supplied fingerprints as not Ali&rsquo;s.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Secondly, in what has been the most hilarious Aadhaar number provision to date, one Aadhaar number (4991-1866-5246) was issued in Anantapur district of Andhra Pradesh to a person named Mr Kothimeera (that is, coriander), with his father&rsquo;s name as Mr Palav (biryani) and address as Gongura Tota, Mamidikaya Vooru (Mango village), Jambuladinne, Anantapur, Andhra Pradesh - 515731. To top it, the date of birth of Mr Kothimeera was recorded as 1887, and the photograph on the card was that of a mobile phone. It is as yet unclear as to what biometric records were supplied with &ldquo;Mr Kothimeera&rsquo;s&rdquo; demographic details and how it passed the test of biometric de-duplication.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Thirdly, the Department of Posts is on record that across India, as on April 20, 6.46 lakh Aadhaar letters posted were returned because the addresses did not exist. In Andhra Pradesh itself, about 50,000 Aadhaar letters were lying undelivered because the addresses were fake. In Karwar, Ankola, Kumta, Honnavar and Bhatkal taluks of Karnataka, about 7,000 Aadhaar letters were lying undelivered because the addresses were fake. While fake addresses have nothing to do with biometrics per se, they provide corroborative evidence to the widespread fraud that takes place at enrolment.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In sum, biometrics has not been able to prevent large-scale errors at the enrolment stage itself. Available evidence itself is persuasive, and it may be logically suspected that unreported errors are of a far larger magnitude.</div><div style="text-align: justify"><br /></div><div style="text-align: justify"><em>Errors in authentication</em></div><div style="text-align: justify"><br /></div><div style="text-align: justify">Interestingly, while three sets of biometrics are collected at the time of enrolment, only one set &ndash; fingerprints &ndash; is used for authentication. As R.S. Sharma, the Mission Director of the UIDAI, confirmed in an interview to Frontline in 2011, &ldquo;fingerprint is the basic mode of authentication&rdquo;. According to Nandan Nilekani, iris scans are not used at authentication because &ldquo;it&rsquo;s not a mature technology&rdquo;. For the moment, we shall postpone asking the reasons for tweaking expert opinion and deciding to use an immature technology at the stage of enrolment.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In his Frontline interview, Sharma admitted that the &ldquo;quality of fingerprints&hellip; poses a challenge for later authentication&rdquo;. He also stated that &ldquo;for manual labourers, this authentication will be difficult because only one or two of the 10 fingerprints may be good&rdquo;. It would appear that Sharma was foretelling what the UIDAI&rsquo;s Proof of Concept (PoC) studies published in 2012 were to reveal. The PoC studies reveal that fingerprint-based authentication of large populations is largely a non-starter, and point towards enormous risks of exclusion.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The PoC studies were internal studies on small populations conducted by the UIDAI to test the robustness of real-time, fingerprint-based authentication. There was no external review. In Phase 1, a small sample of 14,220 residents was studied in Tumkur district of Karnataka. In Phase 2, about 35,000 Aadhaar holders were covered across four States.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">First, the results confirm the fear that most people in rural areas have unreadable fingerprints. There was also significant variation of quality across the fingerprints of each individual. However, the UIDAI does not admit this in as many words. Instead, the PoC report says: &ldquo;Certain fingers were observed to provide better authentication accuracy due to good fingerprint ridges and hence better image quality.&rdquo; Further, it says that &ldquo;providing multiple attempts of the same finger was seen to improve resident&rsquo;s chances of successful authentication&rdquo;. Finally, &ldquo;senior residents (60+) had the highest rejection rates&rdquo;; age-wise rejection rates, however, are not provided.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Let us paraphrase the above three results: (a) only some fingers of residents showed best authentication accuracy; (b) even when fingerprint quality was good, authentication was not always successful at the first try; and (c) residents above the age of 60 years showed poor authentication accuracy.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Secondly, to bypass the pervasive problem of poor fingerprint quality, the PoC study defines a &ldquo;best finger&rdquo;. It is the finger that &ldquo;provides the highest chance of successful authentication&rdquo;. The idea of a &ldquo;best finger&rdquo; is a cop-out from the real problem of poor fingerprint quality. Only 93.6 per cent of the residents possessed at least one best finger. Thus, for 6.4 per cent of the residents authentication was not possible with a single finger. In absolute terms, when extrapolated to the population of 120 crore, a 6.4 per cent share translates to 7.2 crore persons. While the use of more than one finger improves authentication accuracy, the figure of 93.6 per cent provides an insight into the potential extent of exclusion due to fingerprint authentication.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Thirdly, authentication was possible only in the case of 93.5 per cent of residents with a single finger at the first attempt itself (see figure). In other words, in the case of about 6.5 per cent of residents (translating to 7.8 crore residents, when applied to 120 crore) authentication was not possible at the first attempt with a single finger. Even when three attempts were allowed, only 96.5 per cent of residents were able to be authenticated.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In India, even a small share of exclusion from authentication can imply the actual exclusion of crores of individuals. Further, when applied to larger populations, the share of residents without one best finger is likely to rise sharply. At 120 crore people, it is impossible to forecast what this share would explode into.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Contrary to the claims of the UIDAI, fingerprints will be a highly inappropriate tool to uniquely identify individuals. Given multiple errors during enrolment and the potentially high error rates at authentication, the use of fingerprint authentication is likely to foster a regime of misidentification and exclusion. Worse still, exclusion will be most acute among poor manual labourers. The poor record of fingerprint readers in U.K. airports and frequent fingerprint mismatches in the U.S. were also a result of fallibilities in the fingerprint technology.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The elderly is another group that would be massively excluded. As the PoC reports admit, those above 60 years had the &ldquo;highest rejection rates&rdquo; at authentication. Yet, the Mid-Term Review of the Eleventh Plan by the Planning Commission has recommended the use of Aadhaar fingerprints to pay pension to the elderly through the National Social Assistance Programme (NSAP). The recommendation is to use &ldquo;banking correspondents&rdquo;, who would carry handheld fingerprint devices, to make &ldquo;payments at the doorstep&rdquo;. A sure recipe for exclusion, it would appear.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In fact, the only group that appears certain to gain from the Aadhaar project is the global biometric industry. As Nandan Nilekani suggested in an interview, &ldquo;the Unique Identification Project is creating new opportunities for biometric technology&hellip;. Our success can, therefore, determine the course the industry will take, since these technologies will be tested in India on an unprecedented scale.&rdquo; On the other hand, the losses are likely to be felt mostly by the poor. It would be an irony that a project that is marketed in the name of &ldquo;including the poor&rdquo; would end up excluding them massively from whatever meagre provisions they obtain from the state today.</div><div style="text-align: justify"><br /></div><div style="text-align: justify"><em>R. Ramakumar is Associate Professor at the Tata Institute of Social Sciences, Mumbai.</em></div>', 'lang' => 'English', 'SITE_URL' => 'https://im4change.in/', 'site_title' => 'im4change', 'adminprix' => 'admin' ] $article_current = object(App\Model\Entity\Article) { 'id' => (int) 15902, 'title' => 'A tale of errors-R Ramakumar', 'subheading' => '', 'description' => '<div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> <em>Contrary to the claims of the UIDAI, fingerprints are a highly inappropriate tool to uniquely identify individuals.</em> </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Case 1: &ldquo;There are nine checks on visa nationals arriving into the U.K. [United Kingdom]. The fingerprint matching check is the most recent. It is the least reliable. It is the least effective in terms of delivering against our requirements&hellip;.&rdquo; </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> So stated Brodie Clark, the former head of the United Kingdom Border Force, to a stunned Home Affairs Committee on November 15, 2011. Clark was giving oral evidence to the committee on why he had authorised the suspension of fingerprint checks during busy hours at U.K. airports. Pressed further, Clark said, &ldquo;I knew of it, and I approved it because it was a very sensible thing.&rdquo; </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Case 2: &ldquo;The FBI [Federal Bureau of Investigation] apologises to Mr Mayfield and his family for the hardships that this matter has caused.&rdquo; </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The FBI&rsquo;s apology came in a public statement, dated May 24, 2004. Brandon Mayfield was an attorney in Oregon and a Muslim convert who was held as a material witness in the Madrid bombing of March 11, 2004. The Spanish police had located a latent fingerprint on a bag that contained explosives and sent it to the FBI. The FBI shortlisted potential matches from its fingerprint database. Two fingerprint experts, one internal and another external, concluded that the latent fingerprint belonged to Mayfield; one expert termed the match as &ldquo;100% identification&rdquo;. Mayfield was jailed on the basis of the fingerprint match. Two weeks later, the Spanish police informed the FBI that they had independently matched the latent print with Ouhnane Daoud, an Algerian national living in Spain. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The FBI&rsquo;s fingerprint gaffe on Mayfield was not the first in the U.S. A few years earlier, Stephen Cowans had to serve a jail sentence of more than six years in Boston on the basis of a false fingerprint match. He was exonerated on the basis of DNA evidence. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> For years, the infallibility of fingerprints as a mark of uniqueness has been some sort of a fairy tale. But with increasing cases of fingerprint mismatches leading to human rights violations like prison detentions, the confidence is waning. Indeed, it was such loss of confidence that contributed to the shelving of national identity projects in the U.K. and many other countries. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> If the confidence is waning globally, in India there appears to be a deeply intriguing faith in the use of fingerprints in establishing unique identity for a population of 120 crore. The Aadhaar project is a classic example. Biometrics &ndash; particularly fingerprints &ndash; is a central feature of the Aadhaar project. That a Parliamentary Standing Committee had torn apart the robustness of the fingerprint technology &ndash; calling it &ldquo;untested and unreliable&rdquo; &ndash; is dismissed by the government. While time will indeed prove this faith misplaced, some immediate respect for the sceptical voice appears to be long overdue. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The entry of biometrics into Aadhaar is characteristic of how governments evade laws and misrepresent expert opinion to insert untested ideas into policy. In 2009 itself, the Biometric Standards Committee (BSC) of the Unique Identification Authority of India (UIDAI) was circumspect about using fingerprints in Aadhaar. It had stated that &ldquo;retaining efficacy while scaling the database size&hellip; to a billion has not been adequately analysed&rdquo;. The BSC also stated that &ldquo;fingerprint quality, the most important variable for determining de-duplication accuracy, has not been studied in depth in the Indian context&rdquo;. The reason: a large share of the population is dependent on hard manual labour, leading to worn-out fingerprints. This was an early note of caution, which the UIDAI ignored. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Even the BSC had failed to list out the problems of fingerprints comprehensively. For instance, the BSC was silent on the issue of &ldquo;template ageing&rdquo;, that is, an increase in &ldquo;false rejection rates&rdquo; as people age and sensor characteristics of fingerprint devices change. According to Kevin Bowyer of the University of Notre Dame, physical ageing of fingers results in decreased suppleness of the skin, more wrinkles, lesser flexibility of joints, and accumulated cuts and scars, all of which change the fingerprint itself. This implies the need to re-enrol a large proportion of people almost annually, making the system vulnerable to fraud. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> There was another note of caution on fingerprints, which too was ignored. A report from 4G Identity Solutions, a supplier and consultant for the UIDAI, had mentioned in 2009 itself that about 15 per cent of the Indian population may fail to enrol because of unreadable fingerprints. It specifically noted that &ldquo;people above 60 years and young children below 12 years may have difficulty enrolling in a fingerprinting system&rdquo;. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> On iris scans, the BSC was even more circumspect. It did not even provide error estimates for iris scans owing to the &ldquo;absence of empirical Indian data&rdquo;. It suggested the use of iris scans only &ldquo;if they [UIDAI] feel it is required&rdquo;. This stance of the BSC did not dissuade the UIDAI from deciding to scan irises too at enrolment. In fact, in a clear case of fudge, UIDAI Chairman Nandan Nilekani stated in an interview to PlanetBiometrics (July 5, 2010) that the BSC had &ldquo; recommended the inclusion of iris to the biometric modalities&rdquo;. This was wrong; the BSC never made such a recommendation. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> It is becoming increasingly clear that the decision to include biometrics in Aadhaar had no scientific basis and flew in the face of available evidence (see &ldquo;How Reliable is UID?&rdquo;, Frontline, November 19, 2011). Recent evidence suggests that the chickens are indeed coming home to roost. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Biometrics appears at two stages in the Aadhaar project. The first stage is &ldquo;enrolment&rdquo;, where three sets of biometrics are collected from each resident: a photograph, fingerprints of all 10 fingers and iris scans of both eyes. The fingerprints and iris scans are used to uniquely identify (or &ldquo;de-duplicate&rdquo;) each resident and allot a unique Aadhaar number. The second stage is &ldquo;authentication&rdquo;; here, a service would be provided to residents only upon confirmation that his/her fingerprint &ldquo;matches&rdquo; the fingerprint stored against his/her name in the enrolment database. Iris scans are not used at the stage of authentication. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> I shall try to argue here that at both the stages &ndash; enrolment and authentication &ndash; the quantum of errors associated with biometrics is too large to be ignored. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> <em>Errors in enrolment</em> </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Let us first take enrolment. Facts emerging from the ground reveal that there have been widespread errors at this stage and that biometrics has been of little help. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> First, in Hyderabad, a data entry supervisor by the name of Mohammed Ali &ndash; a former employee of the Infrastructure Leasing and Financial Services Limited (IL&amp;FS) &ndash; was shown to have enrolled more than 30,000 residents in a short span of three months. According to reports, all the 30,000 applicants had been issued Aadhaar numbers. There were two interesting aspects with respect to biometrics in this scam. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> (a) Out of the 30,000 residents enrolled, about 870 people were enrolled as physically disabled (&ldquo;biometric exceptions&rdquo; in the UIDAI parlance). Their biometric information was not recorded. It is unclear as to how many of these 870 were actually disabled because most of their addresses were fake. It is also unclear as to how many thousands of such fake enrolments have already taken place across India. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> (b) A large proportion of the 30,000 residents enrolled were not enrolled by Ali (because Ali had left IL&amp;FS in between). Instead, these enrolments were done across 17 enrolment centres by other supervisors who used Ali&rsquo;s login and password. While logging into the system, along with the login and password, supervisors have to submit their fingerprints. Typically, if the supervisor&rsquo;s fingerprints were not matched as Ali&rsquo;s, the system should have rejected access. Yet, all the supervisors could gain access to the system using their fingerprints. Clearly, the system was not able to identify the supplied fingerprints as not Ali&rsquo;s. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Secondly, in what has been the most hilarious Aadhaar number provision to date, one Aadhaar number (4991-1866-5246) was issued in Anantapur district of Andhra Pradesh to a person named Mr Kothimeera (that is, coriander), with his father&rsquo;s name as Mr Palav (biryani) and address as Gongura Tota, Mamidikaya Vooru (Mango village), Jambuladinne, Anantapur, Andhra Pradesh - 515731. To top it, the date of birth of Mr Kothimeera was recorded as 1887, and the photograph on the card was that of a mobile phone. It is as yet unclear as to what biometric records were supplied with &ldquo;Mr Kothimeera&rsquo;s&rdquo; demographic details and how it passed the test of biometric de-duplication. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Thirdly, the Department of Posts is on record that across India, as on April 20, 6.46 lakh Aadhaar letters posted were returned because the addresses did not exist. In Andhra Pradesh itself, about 50,000 Aadhaar letters were lying undelivered because the addresses were fake. In Karwar, Ankola, Kumta, Honnavar and Bhatkal taluks of Karnataka, about 7,000 Aadhaar letters were lying undelivered because the addresses were fake. While fake addresses have nothing to do with biometrics per se, they provide corroborative evidence to the widespread fraud that takes place at enrolment. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> In sum, biometrics has not been able to prevent large-scale errors at the enrolment stage itself. Available evidence itself is persuasive, and it may be logically suspected that unreported errors are of a far larger magnitude. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> <em>Errors in authentication</em> </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Interestingly, while three sets of biometrics are collected at the time of enrolment, only one set &ndash; fingerprints &ndash; is used for authentication. As R.S. Sharma, the Mission Director of the UIDAI, confirmed in an interview to Frontline in 2011, &ldquo;fingerprint is the basic mode of authentication&rdquo;. According to Nandan Nilekani, iris scans are not used at authentication because &ldquo;it&rsquo;s not a mature technology&rdquo;. For the moment, we shall postpone asking the reasons for tweaking expert opinion and deciding to use an immature technology at the stage of enrolment. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> In his Frontline interview, Sharma admitted that the &ldquo;quality of fingerprints&hellip; poses a challenge for later authentication&rdquo;. He also stated that &ldquo;for manual labourers, this authentication will be difficult because only one or two of the 10 fingerprints may be good&rdquo;. It would appear that Sharma was foretelling what the UIDAI&rsquo;s Proof of Concept (PoC) studies published in 2012 were to reveal. The PoC studies reveal that fingerprint-based authentication of large populations is largely a non-starter, and point towards enormous risks of exclusion. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The PoC studies were internal studies on small populations conducted by the UIDAI to test the robustness of real-time, fingerprint-based authentication. There was no external review. In Phase 1, a small sample of 14,220 residents was studied in Tumkur district of Karnataka. In Phase 2, about 35,000 Aadhaar holders were covered across four States. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> First, the results confirm the fear that most people in rural areas have unreadable fingerprints. There was also significant variation of quality across the fingerprints of each individual. However, the UIDAI does not admit this in as many words. Instead, the PoC report says: &ldquo;Certain fingers were observed to provide better authentication accuracy due to good fingerprint ridges and hence better image quality.&rdquo; Further, it says that &ldquo;providing multiple attempts of the same finger was seen to improve resident&rsquo;s chances of successful authentication&rdquo;. Finally, &ldquo;senior residents (60+) had the highest rejection rates&rdquo;; age-wise rejection rates, however, are not provided. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Let us paraphrase the above three results: (a) only some fingers of residents showed best authentication accuracy; (b) even when fingerprint quality was good, authentication was not always successful at the first try; and (c) residents above the age of 60 years showed poor authentication accuracy. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Secondly, to bypass the pervasive problem of poor fingerprint quality, the PoC study defines a &ldquo;best finger&rdquo;. It is the finger that &ldquo;provides the highest chance of successful authentication&rdquo;. The idea of a &ldquo;best finger&rdquo; is a cop-out from the real problem of poor fingerprint quality. Only 93.6 per cent of the residents possessed at least one best finger. Thus, for 6.4 per cent of the residents authentication was not possible with a single finger. In absolute terms, when extrapolated to the population of 120 crore, a 6.4 per cent share translates to 7.2 crore persons. While the use of more than one finger improves authentication accuracy, the figure of 93.6 per cent provides an insight into the potential extent of exclusion due to fingerprint authentication. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Thirdly, authentication was possible only in the case of 93.5 per cent of residents with a single finger at the first attempt itself (see figure). In other words, in the case of about 6.5 per cent of residents (translating to 7.8 crore residents, when applied to 120 crore) authentication was not possible at the first attempt with a single finger. Even when three attempts were allowed, only 96.5 per cent of residents were able to be authenticated. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> In India, even a small share of exclusion from authentication can imply the actual exclusion of crores of individuals. Further, when applied to larger populations, the share of residents without one best finger is likely to rise sharply. At 120 crore people, it is impossible to forecast what this share would explode into. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Contrary to the claims of the UIDAI, fingerprints will be a highly inappropriate tool to uniquely identify individuals. Given multiple errors during enrolment and the potentially high error rates at authentication, the use of fingerprint authentication is likely to foster a regime of misidentification and exclusion. Worse still, exclusion will be most acute among poor manual labourers. The poor record of fingerprint readers in U.K. airports and frequent fingerprint mismatches in the U.S. were also a result of fallibilities in the fingerprint technology. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The elderly is another group that would be massively excluded. As the PoC reports admit, those above 60 years had the &ldquo;highest rejection rates&rdquo; at authentication. Yet, the Mid-Term Review of the Eleventh Plan by the Planning Commission has recommended the use of Aadhaar fingerprints to pay pension to the elderly through the National Social Assistance Programme (NSAP). The recommendation is to use &ldquo;banking correspondents&rdquo;, who would carry handheld fingerprint devices, to make &ldquo;payments at the doorstep&rdquo;. A sure recipe for exclusion, it would appear. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> In fact, the only group that appears certain to gain from the Aadhaar project is the global biometric industry. As Nandan Nilekani suggested in an interview, &ldquo;the Unique Identification Project is creating new opportunities for biometric technology&hellip;. Our success can, therefore, determine the course the industry will take, since these technologies will be tested in India on an unprecedented scale.&rdquo; On the other hand, the losses are likely to be felt mostly by the poor. It would be an irony that a project that is marketed in the name of &ldquo;including the poor&rdquo; would end up excluding them massively from whatever meagre provisions they obtain from the state today. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> <em>R. Ramakumar is Associate Professor at the Tata Institute of Social Sciences, Mumbai.</em> </div>', 'credit_writer' => 'Frontline, Volume 29, Issue 13, 30 June-13 July, 2012, http://www.frontline.in/stories/20120713291303400.htm', 'article_img' => '', 'article_img_thumb' => '', 'status' => (int) 1, 'show_on_home' => (int) 1, 'lang' => 'EN', 'category_id' => (int) 16, 'tag_keyword' => '', 'seo_url' => 'a-tale-of-errors-r-ramakumar-16029', 'meta_title' => null, 'meta_keywords' => null, 'meta_description' => null, 'noindex' => (int) 0, 'publish_date' => object(Cake\I18n\FrozenDate) {}, 'most_visit_section_id' => null, 'article_big_img' => null, 'liveid' => (int) 16029, 'created' => object(Cake\I18n\FrozenTime) {}, 'modified' => object(Cake\I18n\FrozenTime) {}, 'edate' => '', 'tags' => [ (int) 0 => object(Cake\ORM\Entity) {}, (int) 1 => object(Cake\ORM\Entity) {}, (int) 2 => object(Cake\ORM\Entity) {} ], 'category' => object(App\Model\Entity\Category) {}, '[new]' => false, '[accessible]' => [ '*' => true, 'id' => false ], '[dirty]' => [], '[original]' => [], '[virtual]' => [], '[hasErrors]' => false, '[errors]' => [], '[invalid]' => [], '[repository]' => 'Articles' } $articleid = (int) 15902 $metaTitle = 'LATEST NEWS UPDATES | A tale of errors-R Ramakumar' $metaKeywords = 'aadhaar,uid,ICTs' $metaDesc = ' Contrary to the claims of the UIDAI, fingerprints are a highly inappropriate tool to uniquely identify individuals. Case 1: &ldquo;There are nine checks on visa nationals arriving into the U.K. [United Kingdom]. The fingerprint matching check is the most recent. It...' $disp = '<div style="text-align: justify"><br /></div><div style="text-align: justify"><em>Contrary to the claims of the UIDAI, fingerprints are a highly inappropriate tool to uniquely identify individuals.</em></div><div style="text-align: justify"><br /></div><div style="text-align: justify">Case 1: &ldquo;There are nine checks on visa nationals arriving into the U.K. [United Kingdom]. The fingerprint matching check is the most recent. It is the least reliable. It is the least effective in terms of delivering against our requirements&hellip;.&rdquo;</div><div style="text-align: justify"><br /></div><div style="text-align: justify">So stated Brodie Clark, the former head of the United Kingdom Border Force, to a stunned Home Affairs Committee on November 15, 2011. Clark was giving oral evidence to the committee on why he had authorised the suspension of fingerprint checks during busy hours at U.K. airports. Pressed further, Clark said, &ldquo;I knew of it, and I approved it because it was a very sensible thing.&rdquo;</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Case 2: &ldquo;The FBI [Federal Bureau of Investigation] apologises to Mr Mayfield and his family for the hardships that this matter has caused.&rdquo;</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The FBI&rsquo;s apology came in a public statement, dated May 24, 2004. Brandon Mayfield was an attorney in Oregon and a Muslim convert who was held as a material witness in the Madrid bombing of March 11, 2004. The Spanish police had located a latent fingerprint on a bag that contained explosives and sent it to the FBI. The FBI shortlisted potential matches from its fingerprint database. Two fingerprint experts, one internal and another external, concluded that the latent fingerprint belonged to Mayfield; one expert termed the match as &ldquo;100% identification&rdquo;. Mayfield was jailed on the basis of the fingerprint match. Two weeks later, the Spanish police informed the FBI that they had independently matched the latent print with Ouhnane Daoud, an Algerian national living in Spain.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The FBI&rsquo;s fingerprint gaffe on Mayfield was not the first in the U.S. A few years earlier, Stephen Cowans had to serve a jail sentence of more than six years in Boston on the basis of a false fingerprint match. He was exonerated on the basis of DNA evidence.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">For years, the infallibility of fingerprints as a mark of uniqueness has been some sort of a fairy tale. But with increasing cases of fingerprint mismatches leading to human rights violations like prison detentions, the confidence is waning. Indeed, it was such loss of confidence that contributed to the shelving of national identity projects in the U.K. and many other countries.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">If the confidence is waning globally, in India there appears to be a deeply intriguing faith in the use of fingerprints in establishing unique identity for a population of 120 crore. The Aadhaar project is a classic example. Biometrics &ndash; particularly fingerprints &ndash; is a central feature of the Aadhaar project. That a Parliamentary Standing Committee had torn apart the robustness of the fingerprint technology &ndash; calling it &ldquo;untested and unreliable&rdquo; &ndash; is dismissed by the government. While time will indeed prove this faith misplaced, some immediate respect for the sceptical voice appears to be long overdue.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The entry of biometrics into Aadhaar is characteristic of how governments evade laws and misrepresent expert opinion to insert untested ideas into policy. In 2009 itself, the Biometric Standards Committee (BSC) of the Unique Identification Authority of India (UIDAI) was circumspect about using fingerprints in Aadhaar. It had stated that &ldquo;retaining efficacy while scaling the database size&hellip; to a billion has not been adequately analysed&rdquo;. The BSC also stated that &ldquo;fingerprint quality, the most important variable for determining de-duplication accuracy, has not been studied in depth in the Indian context&rdquo;. The reason: a large share of the population is dependent on hard manual labour, leading to worn-out fingerprints. This was an early note of caution, which the UIDAI ignored.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Even the BSC had failed to list out the problems of fingerprints comprehensively. For instance, the BSC was silent on the issue of &ldquo;template ageing&rdquo;, that is, an increase in &ldquo;false rejection rates&rdquo; as people age and sensor characteristics of fingerprint devices change. According to Kevin Bowyer of the University of Notre Dame, physical ageing of fingers results in decreased suppleness of the skin, more wrinkles, lesser flexibility of joints, and accumulated cuts and scars, all of which change the fingerprint itself. This implies the need to re-enrol a large proportion of people almost annually, making the system vulnerable to fraud.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">There was another note of caution on fingerprints, which too was ignored. A report from 4G Identity Solutions, a supplier and consultant for the UIDAI, had mentioned in 2009 itself that about 15 per cent of the Indian population may fail to enrol because of unreadable fingerprints. It specifically noted that &ldquo;people above 60 years and young children below 12 years may have difficulty enrolling in a fingerprinting system&rdquo;.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">On iris scans, the BSC was even more circumspect. It did not even provide error estimates for iris scans owing to the &ldquo;absence of empirical Indian data&rdquo;. It suggested the use of iris scans only &ldquo;if they [UIDAI] feel it is required&rdquo;. This stance of the BSC did not dissuade the UIDAI from deciding to scan irises too at enrolment. In fact, in a clear case of fudge, UIDAI Chairman Nandan Nilekani stated in an interview to PlanetBiometrics (July 5, 2010) that the BSC had &ldquo; recommended the inclusion of iris to the biometric modalities&rdquo;. This was wrong; the BSC never made such a recommendation.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">It is becoming increasingly clear that the decision to include biometrics in Aadhaar had no scientific basis and flew in the face of available evidence (see &ldquo;How Reliable is UID?&rdquo;, Frontline, November 19, 2011). Recent evidence suggests that the chickens are indeed coming home to roost.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Biometrics appears at two stages in the Aadhaar project. The first stage is &ldquo;enrolment&rdquo;, where three sets of biometrics are collected from each resident: a photograph, fingerprints of all 10 fingers and iris scans of both eyes. The fingerprints and iris scans are used to uniquely identify (or &ldquo;de-duplicate&rdquo;) each resident and allot a unique Aadhaar number. The second stage is &ldquo;authentication&rdquo;; here, a service would be provided to residents only upon confirmation that his/her fingerprint &ldquo;matches&rdquo; the fingerprint stored against his/her name in the enrolment database. Iris scans are not used at the stage of authentication.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">I shall try to argue here that at both the stages &ndash; enrolment and authentication &ndash; the quantum of errors associated with biometrics is too large to be ignored.</div><div style="text-align: justify"><br /></div><div style="text-align: justify"><em>Errors in enrolment</em></div><div style="text-align: justify"><br /></div><div style="text-align: justify">Let us first take enrolment. Facts emerging from the ground reveal that there have been widespread errors at this stage and that biometrics has been of little help.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">First, in Hyderabad, a data entry supervisor by the name of Mohammed Ali &ndash; a former employee of the Infrastructure Leasing and Financial Services Limited (IL&amp;FS) &ndash; was shown to have enrolled more than 30,000 residents in a short span of three months. According to reports, all the 30,000 applicants had been issued Aadhaar numbers. There were two interesting aspects with respect to biometrics in this scam.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">(a) Out of the 30,000 residents enrolled, about 870 people were enrolled as physically disabled (&ldquo;biometric exceptions&rdquo; in the UIDAI parlance). Their biometric information was not recorded. It is unclear as to how many of these 870 were actually disabled because most of their addresses were fake. It is also unclear as to how many thousands of such fake enrolments have already taken place across India.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">(b) A large proportion of the 30,000 residents enrolled were not enrolled by Ali (because Ali had left IL&amp;FS in between). Instead, these enrolments were done across 17 enrolment centres by other supervisors who used Ali&rsquo;s login and password. While logging into the system, along with the login and password, supervisors have to submit their fingerprints. Typically, if the supervisor&rsquo;s fingerprints were not matched as Ali&rsquo;s, the system should have rejected access. Yet, all the supervisors could gain access to the system using their fingerprints. Clearly, the system was not able to identify the supplied fingerprints as not Ali&rsquo;s.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Secondly, in what has been the most hilarious Aadhaar number provision to date, one Aadhaar number (4991-1866-5246) was issued in Anantapur district of Andhra Pradesh to a person named Mr Kothimeera (that is, coriander), with his father&rsquo;s name as Mr Palav (biryani) and address as Gongura Tota, Mamidikaya Vooru (Mango village), Jambuladinne, Anantapur, Andhra Pradesh - 515731. To top it, the date of birth of Mr Kothimeera was recorded as 1887, and the photograph on the card was that of a mobile phone. It is as yet unclear as to what biometric records were supplied with &ldquo;Mr Kothimeera&rsquo;s&rdquo; demographic details and how it passed the test of biometric de-duplication.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Thirdly, the Department of Posts is on record that across India, as on April 20, 6.46 lakh Aadhaar letters posted were returned because the addresses did not exist. In Andhra Pradesh itself, about 50,000 Aadhaar letters were lying undelivered because the addresses were fake. In Karwar, Ankola, Kumta, Honnavar and Bhatkal taluks of Karnataka, about 7,000 Aadhaar letters were lying undelivered because the addresses were fake. While fake addresses have nothing to do with biometrics per se, they provide corroborative evidence to the widespread fraud that takes place at enrolment.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In sum, biometrics has not been able to prevent large-scale errors at the enrolment stage itself. Available evidence itself is persuasive, and it may be logically suspected that unreported errors are of a far larger magnitude.</div><div style="text-align: justify"><br /></div><div style="text-align: justify"><em>Errors in authentication</em></div><div style="text-align: justify"><br /></div><div style="text-align: justify">Interestingly, while three sets of biometrics are collected at the time of enrolment, only one set &ndash; fingerprints &ndash; is used for authentication. As R.S. Sharma, the Mission Director of the UIDAI, confirmed in an interview to Frontline in 2011, &ldquo;fingerprint is the basic mode of authentication&rdquo;. According to Nandan Nilekani, iris scans are not used at authentication because &ldquo;it&rsquo;s not a mature technology&rdquo;. For the moment, we shall postpone asking the reasons for tweaking expert opinion and deciding to use an immature technology at the stage of enrolment.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In his Frontline interview, Sharma admitted that the &ldquo;quality of fingerprints&hellip; poses a challenge for later authentication&rdquo;. He also stated that &ldquo;for manual labourers, this authentication will be difficult because only one or two of the 10 fingerprints may be good&rdquo;. It would appear that Sharma was foretelling what the UIDAI&rsquo;s Proof of Concept (PoC) studies published in 2012 were to reveal. The PoC studies reveal that fingerprint-based authentication of large populations is largely a non-starter, and point towards enormous risks of exclusion.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The PoC studies were internal studies on small populations conducted by the UIDAI to test the robustness of real-time, fingerprint-based authentication. There was no external review. In Phase 1, a small sample of 14,220 residents was studied in Tumkur district of Karnataka. In Phase 2, about 35,000 Aadhaar holders were covered across four States.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">First, the results confirm the fear that most people in rural areas have unreadable fingerprints. There was also significant variation of quality across the fingerprints of each individual. However, the UIDAI does not admit this in as many words. Instead, the PoC report says: &ldquo;Certain fingers were observed to provide better authentication accuracy due to good fingerprint ridges and hence better image quality.&rdquo; Further, it says that &ldquo;providing multiple attempts of the same finger was seen to improve resident&rsquo;s chances of successful authentication&rdquo;. Finally, &ldquo;senior residents (60+) had the highest rejection rates&rdquo;; age-wise rejection rates, however, are not provided.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Let us paraphrase the above three results: (a) only some fingers of residents showed best authentication accuracy; (b) even when fingerprint quality was good, authentication was not always successful at the first try; and (c) residents above the age of 60 years showed poor authentication accuracy.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Secondly, to bypass the pervasive problem of poor fingerprint quality, the PoC study defines a &ldquo;best finger&rdquo;. It is the finger that &ldquo;provides the highest chance of successful authentication&rdquo;. The idea of a &ldquo;best finger&rdquo; is a cop-out from the real problem of poor fingerprint quality. Only 93.6 per cent of the residents possessed at least one best finger. Thus, for 6.4 per cent of the residents authentication was not possible with a single finger. In absolute terms, when extrapolated to the population of 120 crore, a 6.4 per cent share translates to 7.2 crore persons. While the use of more than one finger improves authentication accuracy, the figure of 93.6 per cent provides an insight into the potential extent of exclusion due to fingerprint authentication.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Thirdly, authentication was possible only in the case of 93.5 per cent of residents with a single finger at the first attempt itself (see figure). In other words, in the case of about 6.5 per cent of residents (translating to 7.8 crore residents, when applied to 120 crore) authentication was not possible at the first attempt with a single finger. Even when three attempts were allowed, only 96.5 per cent of residents were able to be authenticated.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In India, even a small share of exclusion from authentication can imply the actual exclusion of crores of individuals. Further, when applied to larger populations, the share of residents without one best finger is likely to rise sharply. At 120 crore people, it is impossible to forecast what this share would explode into.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Contrary to the claims of the UIDAI, fingerprints will be a highly inappropriate tool to uniquely identify individuals. Given multiple errors during enrolment and the potentially high error rates at authentication, the use of fingerprint authentication is likely to foster a regime of misidentification and exclusion. Worse still, exclusion will be most acute among poor manual labourers. The poor record of fingerprint readers in U.K. airports and frequent fingerprint mismatches in the U.S. were also a result of fallibilities in the fingerprint technology.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The elderly is another group that would be massively excluded. As the PoC reports admit, those above 60 years had the &ldquo;highest rejection rates&rdquo; at authentication. Yet, the Mid-Term Review of the Eleventh Plan by the Planning Commission has recommended the use of Aadhaar fingerprints to pay pension to the elderly through the National Social Assistance Programme (NSAP). The recommendation is to use &ldquo;banking correspondents&rdquo;, who would carry handheld fingerprint devices, to make &ldquo;payments at the doorstep&rdquo;. A sure recipe for exclusion, it would appear.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In fact, the only group that appears certain to gain from the Aadhaar project is the global biometric industry. As Nandan Nilekani suggested in an interview, &ldquo;the Unique Identification Project is creating new opportunities for biometric technology&hellip;. Our success can, therefore, determine the course the industry will take, since these technologies will be tested in India on an unprecedented scale.&rdquo; On the other hand, the losses are likely to be felt mostly by the poor. It would be an irony that a project that is marketed in the name of &ldquo;including the poor&rdquo; would end up excluding them massively from whatever meagre provisions they obtain from the state today.</div><div style="text-align: justify"><br /></div><div style="text-align: justify"><em>R. Ramakumar is Associate Professor at the Tata Institute of Social Sciences, Mumbai.</em></div>' $lang = 'English' $SITE_URL = 'https://im4change.in/' $site_title = 'im4change' $adminprix = 'admin'</pre><pre class="stack-trace">include - APP/Template/Layout/printlayout.ctp, line 8 Cake\View\View::_evaluate() - CORE/src/View/View.php, line 1413 Cake\View\View::_render() - CORE/src/View/View.php, line 1374 Cake\View\View::renderLayout() - CORE/src/View/View.php, line 927 Cake\View\View::render() - CORE/src/View/View.php, line 885 Cake\Controller\Controller::render() - CORE/src/Controller/Controller.php, line 791 Cake\Http\ActionDispatcher::_invoke() - CORE/src/Http/ActionDispatcher.php, line 126 Cake\Http\ActionDispatcher::dispatch() - CORE/src/Http/ActionDispatcher.php, line 94 Cake\Http\BaseApplication::__invoke() - CORE/src/Http/BaseApplication.php, line 235 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Routing\Middleware\RoutingMiddleware::__invoke() - CORE/src/Routing/Middleware/RoutingMiddleware.php, line 162 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Routing\Middleware\AssetMiddleware::__invoke() - CORE/src/Routing/Middleware/AssetMiddleware.php, line 88 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Error\Middleware\ErrorHandlerMiddleware::__invoke() - CORE/src/Error/Middleware/ErrorHandlerMiddleware.php, line 96 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Http\Runner::run() - CORE/src/Http/Runner.php, line 51</pre></div></pre>latest-news-updates/a-tale-of-errors-r-ramakumar-16029.html"/> <meta http-equiv="Content-Type" content="text/html; charset=utf-8"/> <link href="https://im4change.in/css/control.css" rel="stylesheet" type="text/css" media="all"/> <title>LATEST NEWS UPDATES | A tale of errors-R Ramakumar | Im4change.org</title> <meta name="description" content=" Contrary to the claims of the UIDAI, fingerprints are a highly inappropriate tool to uniquely identify individuals. Case 1: “There are nine checks on visa nationals arriving into the U.K. [United Kingdom]. The fingerprint matching check is the most recent. It..."/> <script src="https://im4change.in/js/jquery-1.10.2.js"></script> <script type="text/javascript" src="https://im4change.in/js/jquery-migrate.min.js"></script> <script language="javascript" type="text/javascript"> $(document).ready(function () { var img = $("img")[0]; // Get my img elem var pic_real_width, pic_real_height; $("<img/>") // Make in memory copy of image to avoid css issues .attr("src", $(img).attr("src")) .load(function () { pic_real_width = this.width; // Note: $(this).width() will not pic_real_height = this.height; // work for in memory images. }); }); </script> <style type="text/css"> @media screen { div.divFooter { display: block; } } @media print { .printbutton { display: none !important; } } </style> </head> <body> <table cellpadding="0" cellspacing="0" border="0" width="98%" align="center"> <tr> <td class="top_bg"> <div class="divFooter"> <img src="https://im4change.in/images/logo1.jpg" height="59" border="0" alt="Resource centre on India's rural distress" style="padding-top:14px;"/> </div> </td> </tr> <tr> <td id="topspace"> </td> </tr> <tr id="topspace"> <td> </td> </tr> <tr> <td height="50" style="border-bottom:1px solid #000; padding-top:10px;" class="printbutton"> <form><input type="button" value=" Print this page " onclick="window.print();return false;"/></form> </td> </tr> <tr> <td width="100%"> <h1 class="news_headlines" style="font-style:normal"> <strong>A tale of errors-R Ramakumar</strong></h1> </td> </tr> <tr> <td width="100%" style="font-family:Arial, 'Segoe Script', 'Segoe UI', sans-serif, serif"><font size="3"> <div style="text-align: justify"><br /></div><div style="text-align: justify"><em>Contrary to the claims of the UIDAI, fingerprints are a highly inappropriate tool to uniquely identify individuals.</em></div><div style="text-align: justify"><br /></div><div style="text-align: justify">Case 1: “There are nine checks on visa nationals arriving into the U.K. [United Kingdom]. The fingerprint matching check is the most recent. It is the least reliable. It is the least effective in terms of delivering against our requirements….”</div><div style="text-align: justify"><br /></div><div style="text-align: justify">So stated Brodie Clark, the former head of the United Kingdom Border Force, to a stunned Home Affairs Committee on November 15, 2011. Clark was giving oral evidence to the committee on why he had authorised the suspension of fingerprint checks during busy hours at U.K. airports. Pressed further, Clark said, “I knew of it, and I approved it because it was a very sensible thing.”</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Case 2: “The FBI [Federal Bureau of Investigation] apologises to Mr Mayfield and his family for the hardships that this matter has caused.”</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The FBI’s apology came in a public statement, dated May 24, 2004. Brandon Mayfield was an attorney in Oregon and a Muslim convert who was held as a material witness in the Madrid bombing of March 11, 2004. The Spanish police had located a latent fingerprint on a bag that contained explosives and sent it to the FBI. The FBI shortlisted potential matches from its fingerprint database. Two fingerprint experts, one internal and another external, concluded that the latent fingerprint belonged to Mayfield; one expert termed the match as “100% identification”. Mayfield was jailed on the basis of the fingerprint match. Two weeks later, the Spanish police informed the FBI that they had independently matched the latent print with Ouhnane Daoud, an Algerian national living in Spain.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The FBI’s fingerprint gaffe on Mayfield was not the first in the U.S. A few years earlier, Stephen Cowans had to serve a jail sentence of more than six years in Boston on the basis of a false fingerprint match. He was exonerated on the basis of DNA evidence.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">For years, the infallibility of fingerprints as a mark of uniqueness has been some sort of a fairy tale. But with increasing cases of fingerprint mismatches leading to human rights violations like prison detentions, the confidence is waning. Indeed, it was such loss of confidence that contributed to the shelving of national identity projects in the U.K. and many other countries.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">If the confidence is waning globally, in India there appears to be a deeply intriguing faith in the use of fingerprints in establishing unique identity for a population of 120 crore. The Aadhaar project is a classic example. Biometrics – particularly fingerprints – is a central feature of the Aadhaar project. That a Parliamentary Standing Committee had torn apart the robustness of the fingerprint technology – calling it “untested and unreliable” – is dismissed by the government. While time will indeed prove this faith misplaced, some immediate respect for the sceptical voice appears to be long overdue.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The entry of biometrics into Aadhaar is characteristic of how governments evade laws and misrepresent expert opinion to insert untested ideas into policy. In 2009 itself, the Biometric Standards Committee (BSC) of the Unique Identification Authority of India (UIDAI) was circumspect about using fingerprints in Aadhaar. It had stated that “retaining efficacy while scaling the database size… to a billion has not been adequately analysed”. The BSC also stated that “fingerprint quality, the most important variable for determining de-duplication accuracy, has not been studied in depth in the Indian context”. The reason: a large share of the population is dependent on hard manual labour, leading to worn-out fingerprints. This was an early note of caution, which the UIDAI ignored.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Even the BSC had failed to list out the problems of fingerprints comprehensively. For instance, the BSC was silent on the issue of “template ageing”, that is, an increase in “false rejection rates” as people age and sensor characteristics of fingerprint devices change. According to Kevin Bowyer of the University of Notre Dame, physical ageing of fingers results in decreased suppleness of the skin, more wrinkles, lesser flexibility of joints, and accumulated cuts and scars, all of which change the fingerprint itself. This implies the need to re-enrol a large proportion of people almost annually, making the system vulnerable to fraud.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">There was another note of caution on fingerprints, which too was ignored. A report from 4G Identity Solutions, a supplier and consultant for the UIDAI, had mentioned in 2009 itself that about 15 per cent of the Indian population may fail to enrol because of unreadable fingerprints. It specifically noted that “people above 60 years and young children below 12 years may have difficulty enrolling in a fingerprinting system”.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">On iris scans, the BSC was even more circumspect. It did not even provide error estimates for iris scans owing to the “absence of empirical Indian data”. It suggested the use of iris scans only “if they [UIDAI] feel it is required”. This stance of the BSC did not dissuade the UIDAI from deciding to scan irises too at enrolment. In fact, in a clear case of fudge, UIDAI Chairman Nandan Nilekani stated in an interview to PlanetBiometrics (July 5, 2010) that the BSC had “ recommended the inclusion of iris to the biometric modalities”. This was wrong; the BSC never made such a recommendation.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">It is becoming increasingly clear that the decision to include biometrics in Aadhaar had no scientific basis and flew in the face of available evidence (see “How Reliable is UID?”, Frontline, November 19, 2011). Recent evidence suggests that the chickens are indeed coming home to roost.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Biometrics appears at two stages in the Aadhaar project. The first stage is “enrolment”, where three sets of biometrics are collected from each resident: a photograph, fingerprints of all 10 fingers and iris scans of both eyes. The fingerprints and iris scans are used to uniquely identify (or “de-duplicate”) each resident and allot a unique Aadhaar number. The second stage is “authentication”; here, a service would be provided to residents only upon confirmation that his/her fingerprint “matches” the fingerprint stored against his/her name in the enrolment database. Iris scans are not used at the stage of authentication.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">I shall try to argue here that at both the stages – enrolment and authentication – the quantum of errors associated with biometrics is too large to be ignored.</div><div style="text-align: justify"><br /></div><div style="text-align: justify"><em>Errors in enrolment</em></div><div style="text-align: justify"><br /></div><div style="text-align: justify">Let us first take enrolment. Facts emerging from the ground reveal that there have been widespread errors at this stage and that biometrics has been of little help.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">First, in Hyderabad, a data entry supervisor by the name of Mohammed Ali – a former employee of the Infrastructure Leasing and Financial Services Limited (IL&FS) – was shown to have enrolled more than 30,000 residents in a short span of three months. According to reports, all the 30,000 applicants had been issued Aadhaar numbers. There were two interesting aspects with respect to biometrics in this scam.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">(a) Out of the 30,000 residents enrolled, about 870 people were enrolled as physically disabled (“biometric exceptions” in the UIDAI parlance). Their biometric information was not recorded. It is unclear as to how many of these 870 were actually disabled because most of their addresses were fake. It is also unclear as to how many thousands of such fake enrolments have already taken place across India.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">(b) A large proportion of the 30,000 residents enrolled were not enrolled by Ali (because Ali had left IL&FS in between). Instead, these enrolments were done across 17 enrolment centres by other supervisors who used Ali’s login and password. While logging into the system, along with the login and password, supervisors have to submit their fingerprints. Typically, if the supervisor’s fingerprints were not matched as Ali’s, the system should have rejected access. Yet, all the supervisors could gain access to the system using their fingerprints. Clearly, the system was not able to identify the supplied fingerprints as not Ali’s.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Secondly, in what has been the most hilarious Aadhaar number provision to date, one Aadhaar number (4991-1866-5246) was issued in Anantapur district of Andhra Pradesh to a person named Mr Kothimeera (that is, coriander), with his father’s name as Mr Palav (biryani) and address as Gongura Tota, Mamidikaya Vooru (Mango village), Jambuladinne, Anantapur, Andhra Pradesh - 515731. To top it, the date of birth of Mr Kothimeera was recorded as 1887, and the photograph on the card was that of a mobile phone. It is as yet unclear as to what biometric records were supplied with “Mr Kothimeera’s” demographic details and how it passed the test of biometric de-duplication.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Thirdly, the Department of Posts is on record that across India, as on April 20, 6.46 lakh Aadhaar letters posted were returned because the addresses did not exist. In Andhra Pradesh itself, about 50,000 Aadhaar letters were lying undelivered because the addresses were fake. In Karwar, Ankola, Kumta, Honnavar and Bhatkal taluks of Karnataka, about 7,000 Aadhaar letters were lying undelivered because the addresses were fake. While fake addresses have nothing to do with biometrics per se, they provide corroborative evidence to the widespread fraud that takes place at enrolment.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In sum, biometrics has not been able to prevent large-scale errors at the enrolment stage itself. Available evidence itself is persuasive, and it may be logically suspected that unreported errors are of a far larger magnitude.</div><div style="text-align: justify"><br /></div><div style="text-align: justify"><em>Errors in authentication</em></div><div style="text-align: justify"><br /></div><div style="text-align: justify">Interestingly, while three sets of biometrics are collected at the time of enrolment, only one set – fingerprints – is used for authentication. As R.S. Sharma, the Mission Director of the UIDAI, confirmed in an interview to Frontline in 2011, “fingerprint is the basic mode of authentication”. According to Nandan Nilekani, iris scans are not used at authentication because “it’s not a mature technology”. For the moment, we shall postpone asking the reasons for tweaking expert opinion and deciding to use an immature technology at the stage of enrolment.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In his Frontline interview, Sharma admitted that the “quality of fingerprints… poses a challenge for later authentication”. He also stated that “for manual labourers, this authentication will be difficult because only one or two of the 10 fingerprints may be good”. It would appear that Sharma was foretelling what the UIDAI’s Proof of Concept (PoC) studies published in 2012 were to reveal. The PoC studies reveal that fingerprint-based authentication of large populations is largely a non-starter, and point towards enormous risks of exclusion.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The PoC studies were internal studies on small populations conducted by the UIDAI to test the robustness of real-time, fingerprint-based authentication. There was no external review. In Phase 1, a small sample of 14,220 residents was studied in Tumkur district of Karnataka. In Phase 2, about 35,000 Aadhaar holders were covered across four States.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">First, the results confirm the fear that most people in rural areas have unreadable fingerprints. There was also significant variation of quality across the fingerprints of each individual. However, the UIDAI does not admit this in as many words. Instead, the PoC report says: “Certain fingers were observed to provide better authentication accuracy due to good fingerprint ridges and hence better image quality.” Further, it says that “providing multiple attempts of the same finger was seen to improve resident’s chances of successful authentication”. Finally, “senior residents (60+) had the highest rejection rates”; age-wise rejection rates, however, are not provided.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Let us paraphrase the above three results: (a) only some fingers of residents showed best authentication accuracy; (b) even when fingerprint quality was good, authentication was not always successful at the first try; and (c) residents above the age of 60 years showed poor authentication accuracy.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Secondly, to bypass the pervasive problem of poor fingerprint quality, the PoC study defines a “best finger”. It is the finger that “provides the highest chance of successful authentication”. The idea of a “best finger” is a cop-out from the real problem of poor fingerprint quality. Only 93.6 per cent of the residents possessed at least one best finger. Thus, for 6.4 per cent of the residents authentication was not possible with a single finger. In absolute terms, when extrapolated to the population of 120 crore, a 6.4 per cent share translates to 7.2 crore persons. While the use of more than one finger improves authentication accuracy, the figure of 93.6 per cent provides an insight into the potential extent of exclusion due to fingerprint authentication.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Thirdly, authentication was possible only in the case of 93.5 per cent of residents with a single finger at the first attempt itself (see figure). In other words, in the case of about 6.5 per cent of residents (translating to 7.8 crore residents, when applied to 120 crore) authentication was not possible at the first attempt with a single finger. Even when three attempts were allowed, only 96.5 per cent of residents were able to be authenticated.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In India, even a small share of exclusion from authentication can imply the actual exclusion of crores of individuals. Further, when applied to larger populations, the share of residents without one best finger is likely to rise sharply. At 120 crore people, it is impossible to forecast what this share would explode into.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Contrary to the claims of the UIDAI, fingerprints will be a highly inappropriate tool to uniquely identify individuals. Given multiple errors during enrolment and the potentially high error rates at authentication, the use of fingerprint authentication is likely to foster a regime of misidentification and exclusion. Worse still, exclusion will be most acute among poor manual labourers. The poor record of fingerprint readers in U.K. airports and frequent fingerprint mismatches in the U.S. were also a result of fallibilities in the fingerprint technology.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The elderly is another group that would be massively excluded. As the PoC reports admit, those above 60 years had the “highest rejection rates” at authentication. Yet, the Mid-Term Review of the Eleventh Plan by the Planning Commission has recommended the use of Aadhaar fingerprints to pay pension to the elderly through the National Social Assistance Programme (NSAP). The recommendation is to use “banking correspondents”, who would carry handheld fingerprint devices, to make “payments at the doorstep”. A sure recipe for exclusion, it would appear.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In fact, the only group that appears certain to gain from the Aadhaar project is the global biometric industry. As Nandan Nilekani suggested in an interview, “the Unique Identification Project is creating new opportunities for biometric technology…. Our success can, therefore, determine the course the industry will take, since these technologies will be tested in India on an unprecedented scale.” On the other hand, the losses are likely to be felt mostly by the poor. It would be an irony that a project that is marketed in the name of “including the poor” would end up excluding them massively from whatever meagre provisions they obtain from the state today.</div><div style="text-align: justify"><br /></div><div style="text-align: justify"><em>R. Ramakumar is Associate Professor at the Tata Institute of Social Sciences, Mumbai.</em></div> </font> </td> </tr> <tr> <td> </td> </tr> <tr> <td height="50" style="border-top:1px solid #000; border-bottom:1px solid #000;padding-top:10px;"> <form><input type="button" value=" Print this page " onclick="window.print();return false;"/></form> </td> </tr> </table></body> </html>' } $reasonPhrase = 'OK'header - [internal], line ?? Cake\Http\ResponseEmitter::emitStatusLine() - CORE/src/Http/ResponseEmitter.php, line 148 Cake\Http\ResponseEmitter::emit() - CORE/src/Http/ResponseEmitter.php, line 54 Cake\Http\Server::emit() - CORE/src/Http/Server.php, line 141 [main] - ROOT/webroot/index.php, line 39
Warning (2): Cannot modify header information - headers already sent by (output started at /home/brlfuser/public_html/vendor/cakephp/cakephp/src/Error/Debugger.php:853) [CORE/src/Http/ResponseEmitter.php, line 181]Notice (8): Undefined variable: urlPrefix [APP/Template/Layout/printlayout.ctp, line 8]Code Context$value
), $first);
$first = false;
$response = object(Cake\Http\Response) { 'status' => (int) 200, 'contentType' => 'text/html', 'headers' => [ 'Content-Type' => [ [maximum depth reached] ] ], 'file' => null, 'fileRange' => [], 'cookies' => object(Cake\Http\Cookie\CookieCollection) {}, 'cacheDirectives' => [], 'body' => '<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <link rel="canonical" href="https://im4change.in/<pre class="cake-error"><a href="javascript:void(0);" onclick="document.getElementById('cakeErr67f22b79047f1-trace').style.display = (document.getElementById('cakeErr67f22b79047f1-trace').style.display == 'none' ? '' : 'none');"><b>Notice</b> (8)</a>: Undefined variable: urlPrefix [<b>APP/Template/Layout/printlayout.ctp</b>, line <b>8</b>]<div id="cakeErr67f22b79047f1-trace" class="cake-stack-trace" style="display: none;"><a href="javascript:void(0);" onclick="document.getElementById('cakeErr67f22b79047f1-code').style.display = (document.getElementById('cakeErr67f22b79047f1-code').style.display == 'none' ? '' : 'none')">Code</a> <a href="javascript:void(0);" onclick="document.getElementById('cakeErr67f22b79047f1-context').style.display = (document.getElementById('cakeErr67f22b79047f1-context').style.display == 'none' ? '' : 'none')">Context</a><pre id="cakeErr67f22b79047f1-code" class="cake-code-dump" style="display: none;"><code><span style="color: #000000"><span style="color: #0000BB"></span><span style="color: #007700"><</span><span style="color: #0000BB">head</span><span style="color: #007700">> </span></span></code> <span class="code-highlight"><code><span style="color: #000000"> <link rel="canonical" href="<span style="color: #0000BB"><?php </span><span style="color: #007700">echo </span><span style="color: #0000BB">Configure</span><span style="color: #007700">::</span><span style="color: #0000BB">read</span><span style="color: #007700">(</span><span style="color: #DD0000">'SITE_URL'</span><span style="color: #007700">); </span><span style="color: #0000BB">?><?php </span><span style="color: #007700">echo </span><span style="color: #0000BB">$urlPrefix</span><span style="color: #007700">;</span><span style="color: #0000BB">?><?php </span><span style="color: #007700">echo </span><span style="color: #0000BB">$article_current</span><span style="color: #007700">-></span><span style="color: #0000BB">category</span><span style="color: #007700">-></span><span style="color: #0000BB">slug</span><span style="color: #007700">; </span><span style="color: #0000BB">?></span>/<span style="color: #0000BB"><?php </span><span style="color: #007700">echo </span><span style="color: #0000BB">$article_current</span><span style="color: #007700">-></span><span style="color: #0000BB">seo_url</span><span style="color: #007700">; </span><span style="color: #0000BB">?></span>.html"/> </span></code></span> <code><span style="color: #000000"><span style="color: #0000BB"> </span><span style="color: #007700"><</span><span style="color: #0000BB">meta http</span><span style="color: #007700">-</span><span style="color: #0000BB">equiv</span><span style="color: #007700">=</span><span style="color: #DD0000">"Content-Type" </span><span style="color: #0000BB">content</span><span style="color: #007700">=</span><span style="color: #DD0000">"text/html; charset=utf-8"</span><span style="color: #007700">/> </span></span></code></pre><pre id="cakeErr67f22b79047f1-context" class="cake-context" style="display: none;">$viewFile = '/home/brlfuser/public_html/src/Template/Layout/printlayout.ctp' $dataForView = [ 'article_current' => object(App\Model\Entity\Article) { 'id' => (int) 15902, 'title' => 'A tale of errors-R Ramakumar', 'subheading' => '', 'description' => '<div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> <em>Contrary to the claims of the UIDAI, fingerprints are a highly inappropriate tool to uniquely identify individuals.</em> </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Case 1: &ldquo;There are nine checks on visa nationals arriving into the U.K. [United Kingdom]. The fingerprint matching check is the most recent. It is the least reliable. It is the least effective in terms of delivering against our requirements&hellip;.&rdquo; </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> So stated Brodie Clark, the former head of the United Kingdom Border Force, to a stunned Home Affairs Committee on November 15, 2011. Clark was giving oral evidence to the committee on why he had authorised the suspension of fingerprint checks during busy hours at U.K. airports. Pressed further, Clark said, &ldquo;I knew of it, and I approved it because it was a very sensible thing.&rdquo; </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Case 2: &ldquo;The FBI [Federal Bureau of Investigation] apologises to Mr Mayfield and his family for the hardships that this matter has caused.&rdquo; </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The FBI&rsquo;s apology came in a public statement, dated May 24, 2004. Brandon Mayfield was an attorney in Oregon and a Muslim convert who was held as a material witness in the Madrid bombing of March 11, 2004. The Spanish police had located a latent fingerprint on a bag that contained explosives and sent it to the FBI. The FBI shortlisted potential matches from its fingerprint database. Two fingerprint experts, one internal and another external, concluded that the latent fingerprint belonged to Mayfield; one expert termed the match as &ldquo;100% identification&rdquo;. Mayfield was jailed on the basis of the fingerprint match. Two weeks later, the Spanish police informed the FBI that they had independently matched the latent print with Ouhnane Daoud, an Algerian national living in Spain. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The FBI&rsquo;s fingerprint gaffe on Mayfield was not the first in the U.S. A few years earlier, Stephen Cowans had to serve a jail sentence of more than six years in Boston on the basis of a false fingerprint match. He was exonerated on the basis of DNA evidence. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> For years, the infallibility of fingerprints as a mark of uniqueness has been some sort of a fairy tale. But with increasing cases of fingerprint mismatches leading to human rights violations like prison detentions, the confidence is waning. Indeed, it was such loss of confidence that contributed to the shelving of national identity projects in the U.K. and many other countries. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> If the confidence is waning globally, in India there appears to be a deeply intriguing faith in the use of fingerprints in establishing unique identity for a population of 120 crore. The Aadhaar project is a classic example. Biometrics &ndash; particularly fingerprints &ndash; is a central feature of the Aadhaar project. That a Parliamentary Standing Committee had torn apart the robustness of the fingerprint technology &ndash; calling it &ldquo;untested and unreliable&rdquo; &ndash; is dismissed by the government. While time will indeed prove this faith misplaced, some immediate respect for the sceptical voice appears to be long overdue. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The entry of biometrics into Aadhaar is characteristic of how governments evade laws and misrepresent expert opinion to insert untested ideas into policy. In 2009 itself, the Biometric Standards Committee (BSC) of the Unique Identification Authority of India (UIDAI) was circumspect about using fingerprints in Aadhaar. It had stated that &ldquo;retaining efficacy while scaling the database size&hellip; to a billion has not been adequately analysed&rdquo;. The BSC also stated that &ldquo;fingerprint quality, the most important variable for determining de-duplication accuracy, has not been studied in depth in the Indian context&rdquo;. The reason: a large share of the population is dependent on hard manual labour, leading to worn-out fingerprints. This was an early note of caution, which the UIDAI ignored. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Even the BSC had failed to list out the problems of fingerprints comprehensively. For instance, the BSC was silent on the issue of &ldquo;template ageing&rdquo;, that is, an increase in &ldquo;false rejection rates&rdquo; as people age and sensor characteristics of fingerprint devices change. According to Kevin Bowyer of the University of Notre Dame, physical ageing of fingers results in decreased suppleness of the skin, more wrinkles, lesser flexibility of joints, and accumulated cuts and scars, all of which change the fingerprint itself. This implies the need to re-enrol a large proportion of people almost annually, making the system vulnerable to fraud. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> There was another note of caution on fingerprints, which too was ignored. A report from 4G Identity Solutions, a supplier and consultant for the UIDAI, had mentioned in 2009 itself that about 15 per cent of the Indian population may fail to enrol because of unreadable fingerprints. It specifically noted that &ldquo;people above 60 years and young children below 12 years may have difficulty enrolling in a fingerprinting system&rdquo;. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> On iris scans, the BSC was even more circumspect. It did not even provide error estimates for iris scans owing to the &ldquo;absence of empirical Indian data&rdquo;. It suggested the use of iris scans only &ldquo;if they [UIDAI] feel it is required&rdquo;. This stance of the BSC did not dissuade the UIDAI from deciding to scan irises too at enrolment. In fact, in a clear case of fudge, UIDAI Chairman Nandan Nilekani stated in an interview to PlanetBiometrics (July 5, 2010) that the BSC had &ldquo; recommended the inclusion of iris to the biometric modalities&rdquo;. This was wrong; the BSC never made such a recommendation. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> It is becoming increasingly clear that the decision to include biometrics in Aadhaar had no scientific basis and flew in the face of available evidence (see &ldquo;How Reliable is UID?&rdquo;, Frontline, November 19, 2011). Recent evidence suggests that the chickens are indeed coming home to roost. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Biometrics appears at two stages in the Aadhaar project. The first stage is &ldquo;enrolment&rdquo;, where three sets of biometrics are collected from each resident: a photograph, fingerprints of all 10 fingers and iris scans of both eyes. The fingerprints and iris scans are used to uniquely identify (or &ldquo;de-duplicate&rdquo;) each resident and allot a unique Aadhaar number. The second stage is &ldquo;authentication&rdquo;; here, a service would be provided to residents only upon confirmation that his/her fingerprint &ldquo;matches&rdquo; the fingerprint stored against his/her name in the enrolment database. Iris scans are not used at the stage of authentication. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> I shall try to argue here that at both the stages &ndash; enrolment and authentication &ndash; the quantum of errors associated with biometrics is too large to be ignored. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> <em>Errors in enrolment</em> </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Let us first take enrolment. Facts emerging from the ground reveal that there have been widespread errors at this stage and that biometrics has been of little help. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> First, in Hyderabad, a data entry supervisor by the name of Mohammed Ali &ndash; a former employee of the Infrastructure Leasing and Financial Services Limited (IL&amp;FS) &ndash; was shown to have enrolled more than 30,000 residents in a short span of three months. According to reports, all the 30,000 applicants had been issued Aadhaar numbers. There were two interesting aspects with respect to biometrics in this scam. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> (a) Out of the 30,000 residents enrolled, about 870 people were enrolled as physically disabled (&ldquo;biometric exceptions&rdquo; in the UIDAI parlance). Their biometric information was not recorded. It is unclear as to how many of these 870 were actually disabled because most of their addresses were fake. It is also unclear as to how many thousands of such fake enrolments have already taken place across India. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> (b) A large proportion of the 30,000 residents enrolled were not enrolled by Ali (because Ali had left IL&amp;FS in between). Instead, these enrolments were done across 17 enrolment centres by other supervisors who used Ali&rsquo;s login and password. While logging into the system, along with the login and password, supervisors have to submit their fingerprints. Typically, if the supervisor&rsquo;s fingerprints were not matched as Ali&rsquo;s, the system should have rejected access. Yet, all the supervisors could gain access to the system using their fingerprints. Clearly, the system was not able to identify the supplied fingerprints as not Ali&rsquo;s. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Secondly, in what has been the most hilarious Aadhaar number provision to date, one Aadhaar number (4991-1866-5246) was issued in Anantapur district of Andhra Pradesh to a person named Mr Kothimeera (that is, coriander), with his father&rsquo;s name as Mr Palav (biryani) and address as Gongura Tota, Mamidikaya Vooru (Mango village), Jambuladinne, Anantapur, Andhra Pradesh - 515731. To top it, the date of birth of Mr Kothimeera was recorded as 1887, and the photograph on the card was that of a mobile phone. It is as yet unclear as to what biometric records were supplied with &ldquo;Mr Kothimeera&rsquo;s&rdquo; demographic details and how it passed the test of biometric de-duplication. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Thirdly, the Department of Posts is on record that across India, as on April 20, 6.46 lakh Aadhaar letters posted were returned because the addresses did not exist. In Andhra Pradesh itself, about 50,000 Aadhaar letters were lying undelivered because the addresses were fake. In Karwar, Ankola, Kumta, Honnavar and Bhatkal taluks of Karnataka, about 7,000 Aadhaar letters were lying undelivered because the addresses were fake. While fake addresses have nothing to do with biometrics per se, they provide corroborative evidence to the widespread fraud that takes place at enrolment. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> In sum, biometrics has not been able to prevent large-scale errors at the enrolment stage itself. Available evidence itself is persuasive, and it may be logically suspected that unreported errors are of a far larger magnitude. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> <em>Errors in authentication</em> </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Interestingly, while three sets of biometrics are collected at the time of enrolment, only one set &ndash; fingerprints &ndash; is used for authentication. As R.S. Sharma, the Mission Director of the UIDAI, confirmed in an interview to Frontline in 2011, &ldquo;fingerprint is the basic mode of authentication&rdquo;. According to Nandan Nilekani, iris scans are not used at authentication because &ldquo;it&rsquo;s not a mature technology&rdquo;. For the moment, we shall postpone asking the reasons for tweaking expert opinion and deciding to use an immature technology at the stage of enrolment. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> In his Frontline interview, Sharma admitted that the &ldquo;quality of fingerprints&hellip; poses a challenge for later authentication&rdquo;. He also stated that &ldquo;for manual labourers, this authentication will be difficult because only one or two of the 10 fingerprints may be good&rdquo;. It would appear that Sharma was foretelling what the UIDAI&rsquo;s Proof of Concept (PoC) studies published in 2012 were to reveal. The PoC studies reveal that fingerprint-based authentication of large populations is largely a non-starter, and point towards enormous risks of exclusion. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The PoC studies were internal studies on small populations conducted by the UIDAI to test the robustness of real-time, fingerprint-based authentication. There was no external review. In Phase 1, a small sample of 14,220 residents was studied in Tumkur district of Karnataka. In Phase 2, about 35,000 Aadhaar holders were covered across four States. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> First, the results confirm the fear that most people in rural areas have unreadable fingerprints. There was also significant variation of quality across the fingerprints of each individual. However, the UIDAI does not admit this in as many words. Instead, the PoC report says: &ldquo;Certain fingers were observed to provide better authentication accuracy due to good fingerprint ridges and hence better image quality.&rdquo; Further, it says that &ldquo;providing multiple attempts of the same finger was seen to improve resident&rsquo;s chances of successful authentication&rdquo;. Finally, &ldquo;senior residents (60+) had the highest rejection rates&rdquo;; age-wise rejection rates, however, are not provided. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Let us paraphrase the above three results: (a) only some fingers of residents showed best authentication accuracy; (b) even when fingerprint quality was good, authentication was not always successful at the first try; and (c) residents above the age of 60 years showed poor authentication accuracy. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Secondly, to bypass the pervasive problem of poor fingerprint quality, the PoC study defines a &ldquo;best finger&rdquo;. It is the finger that &ldquo;provides the highest chance of successful authentication&rdquo;. The idea of a &ldquo;best finger&rdquo; is a cop-out from the real problem of poor fingerprint quality. Only 93.6 per cent of the residents possessed at least one best finger. Thus, for 6.4 per cent of the residents authentication was not possible with a single finger. In absolute terms, when extrapolated to the population of 120 crore, a 6.4 per cent share translates to 7.2 crore persons. While the use of more than one finger improves authentication accuracy, the figure of 93.6 per cent provides an insight into the potential extent of exclusion due to fingerprint authentication. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Thirdly, authentication was possible only in the case of 93.5 per cent of residents with a single finger at the first attempt itself (see figure). In other words, in the case of about 6.5 per cent of residents (translating to 7.8 crore residents, when applied to 120 crore) authentication was not possible at the first attempt with a single finger. Even when three attempts were allowed, only 96.5 per cent of residents were able to be authenticated. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> In India, even a small share of exclusion from authentication can imply the actual exclusion of crores of individuals. Further, when applied to larger populations, the share of residents without one best finger is likely to rise sharply. At 120 crore people, it is impossible to forecast what this share would explode into. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Contrary to the claims of the UIDAI, fingerprints will be a highly inappropriate tool to uniquely identify individuals. Given multiple errors during enrolment and the potentially high error rates at authentication, the use of fingerprint authentication is likely to foster a regime of misidentification and exclusion. Worse still, exclusion will be most acute among poor manual labourers. The poor record of fingerprint readers in U.K. airports and frequent fingerprint mismatches in the U.S. were also a result of fallibilities in the fingerprint technology. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The elderly is another group that would be massively excluded. As the PoC reports admit, those above 60 years had the &ldquo;highest rejection rates&rdquo; at authentication. Yet, the Mid-Term Review of the Eleventh Plan by the Planning Commission has recommended the use of Aadhaar fingerprints to pay pension to the elderly through the National Social Assistance Programme (NSAP). The recommendation is to use &ldquo;banking correspondents&rdquo;, who would carry handheld fingerprint devices, to make &ldquo;payments at the doorstep&rdquo;. A sure recipe for exclusion, it would appear. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> In fact, the only group that appears certain to gain from the Aadhaar project is the global biometric industry. As Nandan Nilekani suggested in an interview, &ldquo;the Unique Identification Project is creating new opportunities for biometric technology&hellip;. Our success can, therefore, determine the course the industry will take, since these technologies will be tested in India on an unprecedented scale.&rdquo; On the other hand, the losses are likely to be felt mostly by the poor. It would be an irony that a project that is marketed in the name of &ldquo;including the poor&rdquo; would end up excluding them massively from whatever meagre provisions they obtain from the state today. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> <em>R. Ramakumar is Associate Professor at the Tata Institute of Social Sciences, Mumbai.</em> </div>', 'credit_writer' => 'Frontline, Volume 29, Issue 13, 30 June-13 July, 2012, http://www.frontline.in/stories/20120713291303400.htm', 'article_img' => '', 'article_img_thumb' => '', 'status' => (int) 1, 'show_on_home' => (int) 1, 'lang' => 'EN', 'category_id' => (int) 16, 'tag_keyword' => '', 'seo_url' => 'a-tale-of-errors-r-ramakumar-16029', 'meta_title' => null, 'meta_keywords' => null, 'meta_description' => null, 'noindex' => (int) 0, 'publish_date' => object(Cake\I18n\FrozenDate) {}, 'most_visit_section_id' => null, 'article_big_img' => null, 'liveid' => (int) 16029, 'created' => object(Cake\I18n\FrozenTime) {}, 'modified' => object(Cake\I18n\FrozenTime) {}, 'edate' => '', 'tags' => [ [maximum depth reached] ], 'category' => object(App\Model\Entity\Category) {}, '[new]' => false, '[accessible]' => [ [maximum depth reached] ], '[dirty]' => [[maximum depth reached]], '[original]' => [[maximum depth reached]], '[virtual]' => [[maximum depth reached]], '[hasErrors]' => false, '[errors]' => [[maximum depth reached]], '[invalid]' => [[maximum depth reached]], '[repository]' => 'Articles' }, 'articleid' => (int) 15902, 'metaTitle' => 'LATEST NEWS UPDATES | A tale of errors-R Ramakumar', 'metaKeywords' => 'aadhaar,uid,ICTs', 'metaDesc' => ' Contrary to the claims of the UIDAI, fingerprints are a highly inappropriate tool to uniquely identify individuals. Case 1: &ldquo;There are nine checks on visa nationals arriving into the U.K. [United Kingdom]. The fingerprint matching check is the most recent. It...', 'disp' => '<div style="text-align: justify"><br /></div><div style="text-align: justify"><em>Contrary to the claims of the UIDAI, fingerprints are a highly inappropriate tool to uniquely identify individuals.</em></div><div style="text-align: justify"><br /></div><div style="text-align: justify">Case 1: &ldquo;There are nine checks on visa nationals arriving into the U.K. [United Kingdom]. The fingerprint matching check is the most recent. It is the least reliable. It is the least effective in terms of delivering against our requirements&hellip;.&rdquo;</div><div style="text-align: justify"><br /></div><div style="text-align: justify">So stated Brodie Clark, the former head of the United Kingdom Border Force, to a stunned Home Affairs Committee on November 15, 2011. Clark was giving oral evidence to the committee on why he had authorised the suspension of fingerprint checks during busy hours at U.K. airports. Pressed further, Clark said, &ldquo;I knew of it, and I approved it because it was a very sensible thing.&rdquo;</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Case 2: &ldquo;The FBI [Federal Bureau of Investigation] apologises to Mr Mayfield and his family for the hardships that this matter has caused.&rdquo;</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The FBI&rsquo;s apology came in a public statement, dated May 24, 2004. Brandon Mayfield was an attorney in Oregon and a Muslim convert who was held as a material witness in the Madrid bombing of March 11, 2004. The Spanish police had located a latent fingerprint on a bag that contained explosives and sent it to the FBI. The FBI shortlisted potential matches from its fingerprint database. Two fingerprint experts, one internal and another external, concluded that the latent fingerprint belonged to Mayfield; one expert termed the match as &ldquo;100% identification&rdquo;. Mayfield was jailed on the basis of the fingerprint match. Two weeks later, the Spanish police informed the FBI that they had independently matched the latent print with Ouhnane Daoud, an Algerian national living in Spain.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The FBI&rsquo;s fingerprint gaffe on Mayfield was not the first in the U.S. A few years earlier, Stephen Cowans had to serve a jail sentence of more than six years in Boston on the basis of a false fingerprint match. He was exonerated on the basis of DNA evidence.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">For years, the infallibility of fingerprints as a mark of uniqueness has been some sort of a fairy tale. But with increasing cases of fingerprint mismatches leading to human rights violations like prison detentions, the confidence is waning. Indeed, it was such loss of confidence that contributed to the shelving of national identity projects in the U.K. and many other countries.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">If the confidence is waning globally, in India there appears to be a deeply intriguing faith in the use of fingerprints in establishing unique identity for a population of 120 crore. The Aadhaar project is a classic example. Biometrics &ndash; particularly fingerprints &ndash; is a central feature of the Aadhaar project. That a Parliamentary Standing Committee had torn apart the robustness of the fingerprint technology &ndash; calling it &ldquo;untested and unreliable&rdquo; &ndash; is dismissed by the government. While time will indeed prove this faith misplaced, some immediate respect for the sceptical voice appears to be long overdue.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The entry of biometrics into Aadhaar is characteristic of how governments evade laws and misrepresent expert opinion to insert untested ideas into policy. In 2009 itself, the Biometric Standards Committee (BSC) of the Unique Identification Authority of India (UIDAI) was circumspect about using fingerprints in Aadhaar. It had stated that &ldquo;retaining efficacy while scaling the database size&hellip; to a billion has not been adequately analysed&rdquo;. The BSC also stated that &ldquo;fingerprint quality, the most important variable for determining de-duplication accuracy, has not been studied in depth in the Indian context&rdquo;. The reason: a large share of the population is dependent on hard manual labour, leading to worn-out fingerprints. This was an early note of caution, which the UIDAI ignored.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Even the BSC had failed to list out the problems of fingerprints comprehensively. For instance, the BSC was silent on the issue of &ldquo;template ageing&rdquo;, that is, an increase in &ldquo;false rejection rates&rdquo; as people age and sensor characteristics of fingerprint devices change. According to Kevin Bowyer of the University of Notre Dame, physical ageing of fingers results in decreased suppleness of the skin, more wrinkles, lesser flexibility of joints, and accumulated cuts and scars, all of which change the fingerprint itself. This implies the need to re-enrol a large proportion of people almost annually, making the system vulnerable to fraud.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">There was another note of caution on fingerprints, which too was ignored. A report from 4G Identity Solutions, a supplier and consultant for the UIDAI, had mentioned in 2009 itself that about 15 per cent of the Indian population may fail to enrol because of unreadable fingerprints. It specifically noted that &ldquo;people above 60 years and young children below 12 years may have difficulty enrolling in a fingerprinting system&rdquo;.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">On iris scans, the BSC was even more circumspect. It did not even provide error estimates for iris scans owing to the &ldquo;absence of empirical Indian data&rdquo;. It suggested the use of iris scans only &ldquo;if they [UIDAI] feel it is required&rdquo;. This stance of the BSC did not dissuade the UIDAI from deciding to scan irises too at enrolment. In fact, in a clear case of fudge, UIDAI Chairman Nandan Nilekani stated in an interview to PlanetBiometrics (July 5, 2010) that the BSC had &ldquo; recommended the inclusion of iris to the biometric modalities&rdquo;. This was wrong; the BSC never made such a recommendation.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">It is becoming increasingly clear that the decision to include biometrics in Aadhaar had no scientific basis and flew in the face of available evidence (see &ldquo;How Reliable is UID?&rdquo;, Frontline, November 19, 2011). Recent evidence suggests that the chickens are indeed coming home to roost.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Biometrics appears at two stages in the Aadhaar project. The first stage is &ldquo;enrolment&rdquo;, where three sets of biometrics are collected from each resident: a photograph, fingerprints of all 10 fingers and iris scans of both eyes. The fingerprints and iris scans are used to uniquely identify (or &ldquo;de-duplicate&rdquo;) each resident and allot a unique Aadhaar number. The second stage is &ldquo;authentication&rdquo;; here, a service would be provided to residents only upon confirmation that his/her fingerprint &ldquo;matches&rdquo; the fingerprint stored against his/her name in the enrolment database. Iris scans are not used at the stage of authentication.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">I shall try to argue here that at both the stages &ndash; enrolment and authentication &ndash; the quantum of errors associated with biometrics is too large to be ignored.</div><div style="text-align: justify"><br /></div><div style="text-align: justify"><em>Errors in enrolment</em></div><div style="text-align: justify"><br /></div><div style="text-align: justify">Let us first take enrolment. Facts emerging from the ground reveal that there have been widespread errors at this stage and that biometrics has been of little help.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">First, in Hyderabad, a data entry supervisor by the name of Mohammed Ali &ndash; a former employee of the Infrastructure Leasing and Financial Services Limited (IL&amp;FS) &ndash; was shown to have enrolled more than 30,000 residents in a short span of three months. According to reports, all the 30,000 applicants had been issued Aadhaar numbers. There were two interesting aspects with respect to biometrics in this scam.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">(a) Out of the 30,000 residents enrolled, about 870 people were enrolled as physically disabled (&ldquo;biometric exceptions&rdquo; in the UIDAI parlance). Their biometric information was not recorded. It is unclear as to how many of these 870 were actually disabled because most of their addresses were fake. It is also unclear as to how many thousands of such fake enrolments have already taken place across India.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">(b) A large proportion of the 30,000 residents enrolled were not enrolled by Ali (because Ali had left IL&amp;FS in between). Instead, these enrolments were done across 17 enrolment centres by other supervisors who used Ali&rsquo;s login and password. While logging into the system, along with the login and password, supervisors have to submit their fingerprints. Typically, if the supervisor&rsquo;s fingerprints were not matched as Ali&rsquo;s, the system should have rejected access. Yet, all the supervisors could gain access to the system using their fingerprints. Clearly, the system was not able to identify the supplied fingerprints as not Ali&rsquo;s.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Secondly, in what has been the most hilarious Aadhaar number provision to date, one Aadhaar number (4991-1866-5246) was issued in Anantapur district of Andhra Pradesh to a person named Mr Kothimeera (that is, coriander), with his father&rsquo;s name as Mr Palav (biryani) and address as Gongura Tota, Mamidikaya Vooru (Mango village), Jambuladinne, Anantapur, Andhra Pradesh - 515731. To top it, the date of birth of Mr Kothimeera was recorded as 1887, and the photograph on the card was that of a mobile phone. It is as yet unclear as to what biometric records were supplied with &ldquo;Mr Kothimeera&rsquo;s&rdquo; demographic details and how it passed the test of biometric de-duplication.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Thirdly, the Department of Posts is on record that across India, as on April 20, 6.46 lakh Aadhaar letters posted were returned because the addresses did not exist. In Andhra Pradesh itself, about 50,000 Aadhaar letters were lying undelivered because the addresses were fake. In Karwar, Ankola, Kumta, Honnavar and Bhatkal taluks of Karnataka, about 7,000 Aadhaar letters were lying undelivered because the addresses were fake. While fake addresses have nothing to do with biometrics per se, they provide corroborative evidence to the widespread fraud that takes place at enrolment.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In sum, biometrics has not been able to prevent large-scale errors at the enrolment stage itself. Available evidence itself is persuasive, and it may be logically suspected that unreported errors are of a far larger magnitude.</div><div style="text-align: justify"><br /></div><div style="text-align: justify"><em>Errors in authentication</em></div><div style="text-align: justify"><br /></div><div style="text-align: justify">Interestingly, while three sets of biometrics are collected at the time of enrolment, only one set &ndash; fingerprints &ndash; is used for authentication. As R.S. Sharma, the Mission Director of the UIDAI, confirmed in an interview to Frontline in 2011, &ldquo;fingerprint is the basic mode of authentication&rdquo;. According to Nandan Nilekani, iris scans are not used at authentication because &ldquo;it&rsquo;s not a mature technology&rdquo;. For the moment, we shall postpone asking the reasons for tweaking expert opinion and deciding to use an immature technology at the stage of enrolment.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In his Frontline interview, Sharma admitted that the &ldquo;quality of fingerprints&hellip; poses a challenge for later authentication&rdquo;. He also stated that &ldquo;for manual labourers, this authentication will be difficult because only one or two of the 10 fingerprints may be good&rdquo;. It would appear that Sharma was foretelling what the UIDAI&rsquo;s Proof of Concept (PoC) studies published in 2012 were to reveal. The PoC studies reveal that fingerprint-based authentication of large populations is largely a non-starter, and point towards enormous risks of exclusion.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The PoC studies were internal studies on small populations conducted by the UIDAI to test the robustness of real-time, fingerprint-based authentication. There was no external review. In Phase 1, a small sample of 14,220 residents was studied in Tumkur district of Karnataka. In Phase 2, about 35,000 Aadhaar holders were covered across four States.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">First, the results confirm the fear that most people in rural areas have unreadable fingerprints. There was also significant variation of quality across the fingerprints of each individual. However, the UIDAI does not admit this in as many words. Instead, the PoC report says: &ldquo;Certain fingers were observed to provide better authentication accuracy due to good fingerprint ridges and hence better image quality.&rdquo; Further, it says that &ldquo;providing multiple attempts of the same finger was seen to improve resident&rsquo;s chances of successful authentication&rdquo;. Finally, &ldquo;senior residents (60+) had the highest rejection rates&rdquo;; age-wise rejection rates, however, are not provided.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Let us paraphrase the above three results: (a) only some fingers of residents showed best authentication accuracy; (b) even when fingerprint quality was good, authentication was not always successful at the first try; and (c) residents above the age of 60 years showed poor authentication accuracy.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Secondly, to bypass the pervasive problem of poor fingerprint quality, the PoC study defines a &ldquo;best finger&rdquo;. It is the finger that &ldquo;provides the highest chance of successful authentication&rdquo;. The idea of a &ldquo;best finger&rdquo; is a cop-out from the real problem of poor fingerprint quality. Only 93.6 per cent of the residents possessed at least one best finger. Thus, for 6.4 per cent of the residents authentication was not possible with a single finger. In absolute terms, when extrapolated to the population of 120 crore, a 6.4 per cent share translates to 7.2 crore persons. While the use of more than one finger improves authentication accuracy, the figure of 93.6 per cent provides an insight into the potential extent of exclusion due to fingerprint authentication.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Thirdly, authentication was possible only in the case of 93.5 per cent of residents with a single finger at the first attempt itself (see figure). In other words, in the case of about 6.5 per cent of residents (translating to 7.8 crore residents, when applied to 120 crore) authentication was not possible at the first attempt with a single finger. Even when three attempts were allowed, only 96.5 per cent of residents were able to be authenticated.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In India, even a small share of exclusion from authentication can imply the actual exclusion of crores of individuals. Further, when applied to larger populations, the share of residents without one best finger is likely to rise sharply. At 120 crore people, it is impossible to forecast what this share would explode into.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Contrary to the claims of the UIDAI, fingerprints will be a highly inappropriate tool to uniquely identify individuals. Given multiple errors during enrolment and the potentially high error rates at authentication, the use of fingerprint authentication is likely to foster a regime of misidentification and exclusion. Worse still, exclusion will be most acute among poor manual labourers. The poor record of fingerprint readers in U.K. airports and frequent fingerprint mismatches in the U.S. were also a result of fallibilities in the fingerprint technology.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The elderly is another group that would be massively excluded. As the PoC reports admit, those above 60 years had the &ldquo;highest rejection rates&rdquo; at authentication. Yet, the Mid-Term Review of the Eleventh Plan by the Planning Commission has recommended the use of Aadhaar fingerprints to pay pension to the elderly through the National Social Assistance Programme (NSAP). The recommendation is to use &ldquo;banking correspondents&rdquo;, who would carry handheld fingerprint devices, to make &ldquo;payments at the doorstep&rdquo;. A sure recipe for exclusion, it would appear.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In fact, the only group that appears certain to gain from the Aadhaar project is the global biometric industry. As Nandan Nilekani suggested in an interview, &ldquo;the Unique Identification Project is creating new opportunities for biometric technology&hellip;. Our success can, therefore, determine the course the industry will take, since these technologies will be tested in India on an unprecedented scale.&rdquo; On the other hand, the losses are likely to be felt mostly by the poor. It would be an irony that a project that is marketed in the name of &ldquo;including the poor&rdquo; would end up excluding them massively from whatever meagre provisions they obtain from the state today.</div><div style="text-align: justify"><br /></div><div style="text-align: justify"><em>R. Ramakumar is Associate Professor at the Tata Institute of Social Sciences, Mumbai.</em></div>', 'lang' => 'English', 'SITE_URL' => 'https://im4change.in/', 'site_title' => 'im4change', 'adminprix' => 'admin' ] $article_current = object(App\Model\Entity\Article) { 'id' => (int) 15902, 'title' => 'A tale of errors-R Ramakumar', 'subheading' => '', 'description' => '<div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> <em>Contrary to the claims of the UIDAI, fingerprints are a highly inappropriate tool to uniquely identify individuals.</em> </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Case 1: &ldquo;There are nine checks on visa nationals arriving into the U.K. [United Kingdom]. The fingerprint matching check is the most recent. It is the least reliable. It is the least effective in terms of delivering against our requirements&hellip;.&rdquo; </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> So stated Brodie Clark, the former head of the United Kingdom Border Force, to a stunned Home Affairs Committee on November 15, 2011. Clark was giving oral evidence to the committee on why he had authorised the suspension of fingerprint checks during busy hours at U.K. airports. Pressed further, Clark said, &ldquo;I knew of it, and I approved it because it was a very sensible thing.&rdquo; </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Case 2: &ldquo;The FBI [Federal Bureau of Investigation] apologises to Mr Mayfield and his family for the hardships that this matter has caused.&rdquo; </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The FBI&rsquo;s apology came in a public statement, dated May 24, 2004. Brandon Mayfield was an attorney in Oregon and a Muslim convert who was held as a material witness in the Madrid bombing of March 11, 2004. The Spanish police had located a latent fingerprint on a bag that contained explosives and sent it to the FBI. The FBI shortlisted potential matches from its fingerprint database. Two fingerprint experts, one internal and another external, concluded that the latent fingerprint belonged to Mayfield; one expert termed the match as &ldquo;100% identification&rdquo;. Mayfield was jailed on the basis of the fingerprint match. Two weeks later, the Spanish police informed the FBI that they had independently matched the latent print with Ouhnane Daoud, an Algerian national living in Spain. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The FBI&rsquo;s fingerprint gaffe on Mayfield was not the first in the U.S. A few years earlier, Stephen Cowans had to serve a jail sentence of more than six years in Boston on the basis of a false fingerprint match. He was exonerated on the basis of DNA evidence. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> For years, the infallibility of fingerprints as a mark of uniqueness has been some sort of a fairy tale. But with increasing cases of fingerprint mismatches leading to human rights violations like prison detentions, the confidence is waning. Indeed, it was such loss of confidence that contributed to the shelving of national identity projects in the U.K. and many other countries. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> If the confidence is waning globally, in India there appears to be a deeply intriguing faith in the use of fingerprints in establishing unique identity for a population of 120 crore. The Aadhaar project is a classic example. Biometrics &ndash; particularly fingerprints &ndash; is a central feature of the Aadhaar project. That a Parliamentary Standing Committee had torn apart the robustness of the fingerprint technology &ndash; calling it &ldquo;untested and unreliable&rdquo; &ndash; is dismissed by the government. While time will indeed prove this faith misplaced, some immediate respect for the sceptical voice appears to be long overdue. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The entry of biometrics into Aadhaar is characteristic of how governments evade laws and misrepresent expert opinion to insert untested ideas into policy. In 2009 itself, the Biometric Standards Committee (BSC) of the Unique Identification Authority of India (UIDAI) was circumspect about using fingerprints in Aadhaar. It had stated that &ldquo;retaining efficacy while scaling the database size&hellip; to a billion has not been adequately analysed&rdquo;. The BSC also stated that &ldquo;fingerprint quality, the most important variable for determining de-duplication accuracy, has not been studied in depth in the Indian context&rdquo;. The reason: a large share of the population is dependent on hard manual labour, leading to worn-out fingerprints. This was an early note of caution, which the UIDAI ignored. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Even the BSC had failed to list out the problems of fingerprints comprehensively. For instance, the BSC was silent on the issue of &ldquo;template ageing&rdquo;, that is, an increase in &ldquo;false rejection rates&rdquo; as people age and sensor characteristics of fingerprint devices change. According to Kevin Bowyer of the University of Notre Dame, physical ageing of fingers results in decreased suppleness of the skin, more wrinkles, lesser flexibility of joints, and accumulated cuts and scars, all of which change the fingerprint itself. This implies the need to re-enrol a large proportion of people almost annually, making the system vulnerable to fraud. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> There was another note of caution on fingerprints, which too was ignored. A report from 4G Identity Solutions, a supplier and consultant for the UIDAI, had mentioned in 2009 itself that about 15 per cent of the Indian population may fail to enrol because of unreadable fingerprints. It specifically noted that &ldquo;people above 60 years and young children below 12 years may have difficulty enrolling in a fingerprinting system&rdquo;. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> On iris scans, the BSC was even more circumspect. It did not even provide error estimates for iris scans owing to the &ldquo;absence of empirical Indian data&rdquo;. It suggested the use of iris scans only &ldquo;if they [UIDAI] feel it is required&rdquo;. This stance of the BSC did not dissuade the UIDAI from deciding to scan irises too at enrolment. In fact, in a clear case of fudge, UIDAI Chairman Nandan Nilekani stated in an interview to PlanetBiometrics (July 5, 2010) that the BSC had &ldquo; recommended the inclusion of iris to the biometric modalities&rdquo;. This was wrong; the BSC never made such a recommendation. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> It is becoming increasingly clear that the decision to include biometrics in Aadhaar had no scientific basis and flew in the face of available evidence (see &ldquo;How Reliable is UID?&rdquo;, Frontline, November 19, 2011). Recent evidence suggests that the chickens are indeed coming home to roost. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Biometrics appears at two stages in the Aadhaar project. The first stage is &ldquo;enrolment&rdquo;, where three sets of biometrics are collected from each resident: a photograph, fingerprints of all 10 fingers and iris scans of both eyes. The fingerprints and iris scans are used to uniquely identify (or &ldquo;de-duplicate&rdquo;) each resident and allot a unique Aadhaar number. The second stage is &ldquo;authentication&rdquo;; here, a service would be provided to residents only upon confirmation that his/her fingerprint &ldquo;matches&rdquo; the fingerprint stored against his/her name in the enrolment database. Iris scans are not used at the stage of authentication. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> I shall try to argue here that at both the stages &ndash; enrolment and authentication &ndash; the quantum of errors associated with biometrics is too large to be ignored. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> <em>Errors in enrolment</em> </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Let us first take enrolment. Facts emerging from the ground reveal that there have been widespread errors at this stage and that biometrics has been of little help. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> First, in Hyderabad, a data entry supervisor by the name of Mohammed Ali &ndash; a former employee of the Infrastructure Leasing and Financial Services Limited (IL&amp;FS) &ndash; was shown to have enrolled more than 30,000 residents in a short span of three months. According to reports, all the 30,000 applicants had been issued Aadhaar numbers. There were two interesting aspects with respect to biometrics in this scam. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> (a) Out of the 30,000 residents enrolled, about 870 people were enrolled as physically disabled (&ldquo;biometric exceptions&rdquo; in the UIDAI parlance). Their biometric information was not recorded. It is unclear as to how many of these 870 were actually disabled because most of their addresses were fake. It is also unclear as to how many thousands of such fake enrolments have already taken place across India. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> (b) A large proportion of the 30,000 residents enrolled were not enrolled by Ali (because Ali had left IL&amp;FS in between). Instead, these enrolments were done across 17 enrolment centres by other supervisors who used Ali&rsquo;s login and password. While logging into the system, along with the login and password, supervisors have to submit their fingerprints. Typically, if the supervisor&rsquo;s fingerprints were not matched as Ali&rsquo;s, the system should have rejected access. Yet, all the supervisors could gain access to the system using their fingerprints. Clearly, the system was not able to identify the supplied fingerprints as not Ali&rsquo;s. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Secondly, in what has been the most hilarious Aadhaar number provision to date, one Aadhaar number (4991-1866-5246) was issued in Anantapur district of Andhra Pradesh to a person named Mr Kothimeera (that is, coriander), with his father&rsquo;s name as Mr Palav (biryani) and address as Gongura Tota, Mamidikaya Vooru (Mango village), Jambuladinne, Anantapur, Andhra Pradesh - 515731. To top it, the date of birth of Mr Kothimeera was recorded as 1887, and the photograph on the card was that of a mobile phone. It is as yet unclear as to what biometric records were supplied with &ldquo;Mr Kothimeera&rsquo;s&rdquo; demographic details and how it passed the test of biometric de-duplication. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Thirdly, the Department of Posts is on record that across India, as on April 20, 6.46 lakh Aadhaar letters posted were returned because the addresses did not exist. In Andhra Pradesh itself, about 50,000 Aadhaar letters were lying undelivered because the addresses were fake. In Karwar, Ankola, Kumta, Honnavar and Bhatkal taluks of Karnataka, about 7,000 Aadhaar letters were lying undelivered because the addresses were fake. While fake addresses have nothing to do with biometrics per se, they provide corroborative evidence to the widespread fraud that takes place at enrolment. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> In sum, biometrics has not been able to prevent large-scale errors at the enrolment stage itself. Available evidence itself is persuasive, and it may be logically suspected that unreported errors are of a far larger magnitude. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> <em>Errors in authentication</em> </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Interestingly, while three sets of biometrics are collected at the time of enrolment, only one set &ndash; fingerprints &ndash; is used for authentication. As R.S. Sharma, the Mission Director of the UIDAI, confirmed in an interview to Frontline in 2011, &ldquo;fingerprint is the basic mode of authentication&rdquo;. According to Nandan Nilekani, iris scans are not used at authentication because &ldquo;it&rsquo;s not a mature technology&rdquo;. For the moment, we shall postpone asking the reasons for tweaking expert opinion and deciding to use an immature technology at the stage of enrolment. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> In his Frontline interview, Sharma admitted that the &ldquo;quality of fingerprints&hellip; poses a challenge for later authentication&rdquo;. He also stated that &ldquo;for manual labourers, this authentication will be difficult because only one or two of the 10 fingerprints may be good&rdquo;. It would appear that Sharma was foretelling what the UIDAI&rsquo;s Proof of Concept (PoC) studies published in 2012 were to reveal. The PoC studies reveal that fingerprint-based authentication of large populations is largely a non-starter, and point towards enormous risks of exclusion. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The PoC studies were internal studies on small populations conducted by the UIDAI to test the robustness of real-time, fingerprint-based authentication. There was no external review. In Phase 1, a small sample of 14,220 residents was studied in Tumkur district of Karnataka. In Phase 2, about 35,000 Aadhaar holders were covered across four States. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> First, the results confirm the fear that most people in rural areas have unreadable fingerprints. There was also significant variation of quality across the fingerprints of each individual. However, the UIDAI does not admit this in as many words. Instead, the PoC report says: &ldquo;Certain fingers were observed to provide better authentication accuracy due to good fingerprint ridges and hence better image quality.&rdquo; Further, it says that &ldquo;providing multiple attempts of the same finger was seen to improve resident&rsquo;s chances of successful authentication&rdquo;. Finally, &ldquo;senior residents (60+) had the highest rejection rates&rdquo;; age-wise rejection rates, however, are not provided. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Let us paraphrase the above three results: (a) only some fingers of residents showed best authentication accuracy; (b) even when fingerprint quality was good, authentication was not always successful at the first try; and (c) residents above the age of 60 years showed poor authentication accuracy. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Secondly, to bypass the pervasive problem of poor fingerprint quality, the PoC study defines a &ldquo;best finger&rdquo;. It is the finger that &ldquo;provides the highest chance of successful authentication&rdquo;. The idea of a &ldquo;best finger&rdquo; is a cop-out from the real problem of poor fingerprint quality. Only 93.6 per cent of the residents possessed at least one best finger. Thus, for 6.4 per cent of the residents authentication was not possible with a single finger. In absolute terms, when extrapolated to the population of 120 crore, a 6.4 per cent share translates to 7.2 crore persons. While the use of more than one finger improves authentication accuracy, the figure of 93.6 per cent provides an insight into the potential extent of exclusion due to fingerprint authentication. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Thirdly, authentication was possible only in the case of 93.5 per cent of residents with a single finger at the first attempt itself (see figure). In other words, in the case of about 6.5 per cent of residents (translating to 7.8 crore residents, when applied to 120 crore) authentication was not possible at the first attempt with a single finger. Even when three attempts were allowed, only 96.5 per cent of residents were able to be authenticated. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> In India, even a small share of exclusion from authentication can imply the actual exclusion of crores of individuals. Further, when applied to larger populations, the share of residents without one best finger is likely to rise sharply. At 120 crore people, it is impossible to forecast what this share would explode into. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Contrary to the claims of the UIDAI, fingerprints will be a highly inappropriate tool to uniquely identify individuals. Given multiple errors during enrolment and the potentially high error rates at authentication, the use of fingerprint authentication is likely to foster a regime of misidentification and exclusion. Worse still, exclusion will be most acute among poor manual labourers. The poor record of fingerprint readers in U.K. airports and frequent fingerprint mismatches in the U.S. were also a result of fallibilities in the fingerprint technology. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The elderly is another group that would be massively excluded. As the PoC reports admit, those above 60 years had the &ldquo;highest rejection rates&rdquo; at authentication. Yet, the Mid-Term Review of the Eleventh Plan by the Planning Commission has recommended the use of Aadhaar fingerprints to pay pension to the elderly through the National Social Assistance Programme (NSAP). The recommendation is to use &ldquo;banking correspondents&rdquo;, who would carry handheld fingerprint devices, to make &ldquo;payments at the doorstep&rdquo;. A sure recipe for exclusion, it would appear. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> In fact, the only group that appears certain to gain from the Aadhaar project is the global biometric industry. As Nandan Nilekani suggested in an interview, &ldquo;the Unique Identification Project is creating new opportunities for biometric technology&hellip;. Our success can, therefore, determine the course the industry will take, since these technologies will be tested in India on an unprecedented scale.&rdquo; On the other hand, the losses are likely to be felt mostly by the poor. It would be an irony that a project that is marketed in the name of &ldquo;including the poor&rdquo; would end up excluding them massively from whatever meagre provisions they obtain from the state today. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> <em>R. Ramakumar is Associate Professor at the Tata Institute of Social Sciences, Mumbai.</em> </div>', 'credit_writer' => 'Frontline, Volume 29, Issue 13, 30 June-13 July, 2012, http://www.frontline.in/stories/20120713291303400.htm', 'article_img' => '', 'article_img_thumb' => '', 'status' => (int) 1, 'show_on_home' => (int) 1, 'lang' => 'EN', 'category_id' => (int) 16, 'tag_keyword' => '', 'seo_url' => 'a-tale-of-errors-r-ramakumar-16029', 'meta_title' => null, 'meta_keywords' => null, 'meta_description' => null, 'noindex' => (int) 0, 'publish_date' => object(Cake\I18n\FrozenDate) {}, 'most_visit_section_id' => null, 'article_big_img' => null, 'liveid' => (int) 16029, 'created' => object(Cake\I18n\FrozenTime) {}, 'modified' => object(Cake\I18n\FrozenTime) {}, 'edate' => '', 'tags' => [ (int) 0 => object(Cake\ORM\Entity) {}, (int) 1 => object(Cake\ORM\Entity) {}, (int) 2 => object(Cake\ORM\Entity) {} ], 'category' => object(App\Model\Entity\Category) {}, '[new]' => false, '[accessible]' => [ '*' => true, 'id' => false ], '[dirty]' => [], '[original]' => [], '[virtual]' => [], '[hasErrors]' => false, '[errors]' => [], '[invalid]' => [], '[repository]' => 'Articles' } $articleid = (int) 15902 $metaTitle = 'LATEST NEWS UPDATES | A tale of errors-R Ramakumar' $metaKeywords = 'aadhaar,uid,ICTs' $metaDesc = ' Contrary to the claims of the UIDAI, fingerprints are a highly inappropriate tool to uniquely identify individuals. Case 1: &ldquo;There are nine checks on visa nationals arriving into the U.K. [United Kingdom]. The fingerprint matching check is the most recent. It...' $disp = '<div style="text-align: justify"><br /></div><div style="text-align: justify"><em>Contrary to the claims of the UIDAI, fingerprints are a highly inappropriate tool to uniquely identify individuals.</em></div><div style="text-align: justify"><br /></div><div style="text-align: justify">Case 1: &ldquo;There are nine checks on visa nationals arriving into the U.K. [United Kingdom]. The fingerprint matching check is the most recent. It is the least reliable. It is the least effective in terms of delivering against our requirements&hellip;.&rdquo;</div><div style="text-align: justify"><br /></div><div style="text-align: justify">So stated Brodie Clark, the former head of the United Kingdom Border Force, to a stunned Home Affairs Committee on November 15, 2011. Clark was giving oral evidence to the committee on why he had authorised the suspension of fingerprint checks during busy hours at U.K. airports. Pressed further, Clark said, &ldquo;I knew of it, and I approved it because it was a very sensible thing.&rdquo;</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Case 2: &ldquo;The FBI [Federal Bureau of Investigation] apologises to Mr Mayfield and his family for the hardships that this matter has caused.&rdquo;</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The FBI&rsquo;s apology came in a public statement, dated May 24, 2004. Brandon Mayfield was an attorney in Oregon and a Muslim convert who was held as a material witness in the Madrid bombing of March 11, 2004. The Spanish police had located a latent fingerprint on a bag that contained explosives and sent it to the FBI. The FBI shortlisted potential matches from its fingerprint database. Two fingerprint experts, one internal and another external, concluded that the latent fingerprint belonged to Mayfield; one expert termed the match as &ldquo;100% identification&rdquo;. Mayfield was jailed on the basis of the fingerprint match. Two weeks later, the Spanish police informed the FBI that they had independently matched the latent print with Ouhnane Daoud, an Algerian national living in Spain.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The FBI&rsquo;s fingerprint gaffe on Mayfield was not the first in the U.S. A few years earlier, Stephen Cowans had to serve a jail sentence of more than six years in Boston on the basis of a false fingerprint match. He was exonerated on the basis of DNA evidence.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">For years, the infallibility of fingerprints as a mark of uniqueness has been some sort of a fairy tale. But with increasing cases of fingerprint mismatches leading to human rights violations like prison detentions, the confidence is waning. Indeed, it was such loss of confidence that contributed to the shelving of national identity projects in the U.K. and many other countries.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">If the confidence is waning globally, in India there appears to be a deeply intriguing faith in the use of fingerprints in establishing unique identity for a population of 120 crore. The Aadhaar project is a classic example. Biometrics &ndash; particularly fingerprints &ndash; is a central feature of the Aadhaar project. That a Parliamentary Standing Committee had torn apart the robustness of the fingerprint technology &ndash; calling it &ldquo;untested and unreliable&rdquo; &ndash; is dismissed by the government. While time will indeed prove this faith misplaced, some immediate respect for the sceptical voice appears to be long overdue.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The entry of biometrics into Aadhaar is characteristic of how governments evade laws and misrepresent expert opinion to insert untested ideas into policy. In 2009 itself, the Biometric Standards Committee (BSC) of the Unique Identification Authority of India (UIDAI) was circumspect about using fingerprints in Aadhaar. It had stated that &ldquo;retaining efficacy while scaling the database size&hellip; to a billion has not been adequately analysed&rdquo;. The BSC also stated that &ldquo;fingerprint quality, the most important variable for determining de-duplication accuracy, has not been studied in depth in the Indian context&rdquo;. The reason: a large share of the population is dependent on hard manual labour, leading to worn-out fingerprints. This was an early note of caution, which the UIDAI ignored.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Even the BSC had failed to list out the problems of fingerprints comprehensively. For instance, the BSC was silent on the issue of &ldquo;template ageing&rdquo;, that is, an increase in &ldquo;false rejection rates&rdquo; as people age and sensor characteristics of fingerprint devices change. According to Kevin Bowyer of the University of Notre Dame, physical ageing of fingers results in decreased suppleness of the skin, more wrinkles, lesser flexibility of joints, and accumulated cuts and scars, all of which change the fingerprint itself. This implies the need to re-enrol a large proportion of people almost annually, making the system vulnerable to fraud.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">There was another note of caution on fingerprints, which too was ignored. A report from 4G Identity Solutions, a supplier and consultant for the UIDAI, had mentioned in 2009 itself that about 15 per cent of the Indian population may fail to enrol because of unreadable fingerprints. It specifically noted that &ldquo;people above 60 years and young children below 12 years may have difficulty enrolling in a fingerprinting system&rdquo;.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">On iris scans, the BSC was even more circumspect. It did not even provide error estimates for iris scans owing to the &ldquo;absence of empirical Indian data&rdquo;. It suggested the use of iris scans only &ldquo;if they [UIDAI] feel it is required&rdquo;. This stance of the BSC did not dissuade the UIDAI from deciding to scan irises too at enrolment. In fact, in a clear case of fudge, UIDAI Chairman Nandan Nilekani stated in an interview to PlanetBiometrics (July 5, 2010) that the BSC had &ldquo; recommended the inclusion of iris to the biometric modalities&rdquo;. This was wrong; the BSC never made such a recommendation.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">It is becoming increasingly clear that the decision to include biometrics in Aadhaar had no scientific basis and flew in the face of available evidence (see &ldquo;How Reliable is UID?&rdquo;, Frontline, November 19, 2011). Recent evidence suggests that the chickens are indeed coming home to roost.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Biometrics appears at two stages in the Aadhaar project. The first stage is &ldquo;enrolment&rdquo;, where three sets of biometrics are collected from each resident: a photograph, fingerprints of all 10 fingers and iris scans of both eyes. The fingerprints and iris scans are used to uniquely identify (or &ldquo;de-duplicate&rdquo;) each resident and allot a unique Aadhaar number. The second stage is &ldquo;authentication&rdquo;; here, a service would be provided to residents only upon confirmation that his/her fingerprint &ldquo;matches&rdquo; the fingerprint stored against his/her name in the enrolment database. Iris scans are not used at the stage of authentication.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">I shall try to argue here that at both the stages &ndash; enrolment and authentication &ndash; the quantum of errors associated with biometrics is too large to be ignored.</div><div style="text-align: justify"><br /></div><div style="text-align: justify"><em>Errors in enrolment</em></div><div style="text-align: justify"><br /></div><div style="text-align: justify">Let us first take enrolment. Facts emerging from the ground reveal that there have been widespread errors at this stage and that biometrics has been of little help.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">First, in Hyderabad, a data entry supervisor by the name of Mohammed Ali &ndash; a former employee of the Infrastructure Leasing and Financial Services Limited (IL&amp;FS) &ndash; was shown to have enrolled more than 30,000 residents in a short span of three months. According to reports, all the 30,000 applicants had been issued Aadhaar numbers. There were two interesting aspects with respect to biometrics in this scam.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">(a) Out of the 30,000 residents enrolled, about 870 people were enrolled as physically disabled (&ldquo;biometric exceptions&rdquo; in the UIDAI parlance). Their biometric information was not recorded. It is unclear as to how many of these 870 were actually disabled because most of their addresses were fake. It is also unclear as to how many thousands of such fake enrolments have already taken place across India.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">(b) A large proportion of the 30,000 residents enrolled were not enrolled by Ali (because Ali had left IL&amp;FS in between). Instead, these enrolments were done across 17 enrolment centres by other supervisors who used Ali&rsquo;s login and password. While logging into the system, along with the login and password, supervisors have to submit their fingerprints. Typically, if the supervisor&rsquo;s fingerprints were not matched as Ali&rsquo;s, the system should have rejected access. Yet, all the supervisors could gain access to the system using their fingerprints. Clearly, the system was not able to identify the supplied fingerprints as not Ali&rsquo;s.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Secondly, in what has been the most hilarious Aadhaar number provision to date, one Aadhaar number (4991-1866-5246) was issued in Anantapur district of Andhra Pradesh to a person named Mr Kothimeera (that is, coriander), with his father&rsquo;s name as Mr Palav (biryani) and address as Gongura Tota, Mamidikaya Vooru (Mango village), Jambuladinne, Anantapur, Andhra Pradesh - 515731. To top it, the date of birth of Mr Kothimeera was recorded as 1887, and the photograph on the card was that of a mobile phone. It is as yet unclear as to what biometric records were supplied with &ldquo;Mr Kothimeera&rsquo;s&rdquo; demographic details and how it passed the test of biometric de-duplication.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Thirdly, the Department of Posts is on record that across India, as on April 20, 6.46 lakh Aadhaar letters posted were returned because the addresses did not exist. In Andhra Pradesh itself, about 50,000 Aadhaar letters were lying undelivered because the addresses were fake. In Karwar, Ankola, Kumta, Honnavar and Bhatkal taluks of Karnataka, about 7,000 Aadhaar letters were lying undelivered because the addresses were fake. While fake addresses have nothing to do with biometrics per se, they provide corroborative evidence to the widespread fraud that takes place at enrolment.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In sum, biometrics has not been able to prevent large-scale errors at the enrolment stage itself. Available evidence itself is persuasive, and it may be logically suspected that unreported errors are of a far larger magnitude.</div><div style="text-align: justify"><br /></div><div style="text-align: justify"><em>Errors in authentication</em></div><div style="text-align: justify"><br /></div><div style="text-align: justify">Interestingly, while three sets of biometrics are collected at the time of enrolment, only one set &ndash; fingerprints &ndash; is used for authentication. As R.S. Sharma, the Mission Director of the UIDAI, confirmed in an interview to Frontline in 2011, &ldquo;fingerprint is the basic mode of authentication&rdquo;. According to Nandan Nilekani, iris scans are not used at authentication because &ldquo;it&rsquo;s not a mature technology&rdquo;. For the moment, we shall postpone asking the reasons for tweaking expert opinion and deciding to use an immature technology at the stage of enrolment.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In his Frontline interview, Sharma admitted that the &ldquo;quality of fingerprints&hellip; poses a challenge for later authentication&rdquo;. He also stated that &ldquo;for manual labourers, this authentication will be difficult because only one or two of the 10 fingerprints may be good&rdquo;. It would appear that Sharma was foretelling what the UIDAI&rsquo;s Proof of Concept (PoC) studies published in 2012 were to reveal. The PoC studies reveal that fingerprint-based authentication of large populations is largely a non-starter, and point towards enormous risks of exclusion.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The PoC studies were internal studies on small populations conducted by the UIDAI to test the robustness of real-time, fingerprint-based authentication. There was no external review. In Phase 1, a small sample of 14,220 residents was studied in Tumkur district of Karnataka. In Phase 2, about 35,000 Aadhaar holders were covered across four States.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">First, the results confirm the fear that most people in rural areas have unreadable fingerprints. There was also significant variation of quality across the fingerprints of each individual. However, the UIDAI does not admit this in as many words. Instead, the PoC report says: &ldquo;Certain fingers were observed to provide better authentication accuracy due to good fingerprint ridges and hence better image quality.&rdquo; Further, it says that &ldquo;providing multiple attempts of the same finger was seen to improve resident&rsquo;s chances of successful authentication&rdquo;. Finally, &ldquo;senior residents (60+) had the highest rejection rates&rdquo;; age-wise rejection rates, however, are not provided.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Let us paraphrase the above three results: (a) only some fingers of residents showed best authentication accuracy; (b) even when fingerprint quality was good, authentication was not always successful at the first try; and (c) residents above the age of 60 years showed poor authentication accuracy.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Secondly, to bypass the pervasive problem of poor fingerprint quality, the PoC study defines a &ldquo;best finger&rdquo;. It is the finger that &ldquo;provides the highest chance of successful authentication&rdquo;. The idea of a &ldquo;best finger&rdquo; is a cop-out from the real problem of poor fingerprint quality. Only 93.6 per cent of the residents possessed at least one best finger. Thus, for 6.4 per cent of the residents authentication was not possible with a single finger. In absolute terms, when extrapolated to the population of 120 crore, a 6.4 per cent share translates to 7.2 crore persons. While the use of more than one finger improves authentication accuracy, the figure of 93.6 per cent provides an insight into the potential extent of exclusion due to fingerprint authentication.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Thirdly, authentication was possible only in the case of 93.5 per cent of residents with a single finger at the first attempt itself (see figure). In other words, in the case of about 6.5 per cent of residents (translating to 7.8 crore residents, when applied to 120 crore) authentication was not possible at the first attempt with a single finger. Even when three attempts were allowed, only 96.5 per cent of residents were able to be authenticated.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In India, even a small share of exclusion from authentication can imply the actual exclusion of crores of individuals. Further, when applied to larger populations, the share of residents without one best finger is likely to rise sharply. At 120 crore people, it is impossible to forecast what this share would explode into.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Contrary to the claims of the UIDAI, fingerprints will be a highly inappropriate tool to uniquely identify individuals. Given multiple errors during enrolment and the potentially high error rates at authentication, the use of fingerprint authentication is likely to foster a regime of misidentification and exclusion. Worse still, exclusion will be most acute among poor manual labourers. The poor record of fingerprint readers in U.K. airports and frequent fingerprint mismatches in the U.S. were also a result of fallibilities in the fingerprint technology.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The elderly is another group that would be massively excluded. As the PoC reports admit, those above 60 years had the &ldquo;highest rejection rates&rdquo; at authentication. Yet, the Mid-Term Review of the Eleventh Plan by the Planning Commission has recommended the use of Aadhaar fingerprints to pay pension to the elderly through the National Social Assistance Programme (NSAP). The recommendation is to use &ldquo;banking correspondents&rdquo;, who would carry handheld fingerprint devices, to make &ldquo;payments at the doorstep&rdquo;. A sure recipe for exclusion, it would appear.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In fact, the only group that appears certain to gain from the Aadhaar project is the global biometric industry. As Nandan Nilekani suggested in an interview, &ldquo;the Unique Identification Project is creating new opportunities for biometric technology&hellip;. Our success can, therefore, determine the course the industry will take, since these technologies will be tested in India on an unprecedented scale.&rdquo; On the other hand, the losses are likely to be felt mostly by the poor. It would be an irony that a project that is marketed in the name of &ldquo;including the poor&rdquo; would end up excluding them massively from whatever meagre provisions they obtain from the state today.</div><div style="text-align: justify"><br /></div><div style="text-align: justify"><em>R. Ramakumar is Associate Professor at the Tata Institute of Social Sciences, Mumbai.</em></div>' $lang = 'English' $SITE_URL = 'https://im4change.in/' $site_title = 'im4change' $adminprix = 'admin'</pre><pre class="stack-trace">include - APP/Template/Layout/printlayout.ctp, line 8 Cake\View\View::_evaluate() - CORE/src/View/View.php, line 1413 Cake\View\View::_render() - CORE/src/View/View.php, line 1374 Cake\View\View::renderLayout() - CORE/src/View/View.php, line 927 Cake\View\View::render() - CORE/src/View/View.php, line 885 Cake\Controller\Controller::render() - CORE/src/Controller/Controller.php, line 791 Cake\Http\ActionDispatcher::_invoke() - CORE/src/Http/ActionDispatcher.php, line 126 Cake\Http\ActionDispatcher::dispatch() - CORE/src/Http/ActionDispatcher.php, line 94 Cake\Http\BaseApplication::__invoke() - CORE/src/Http/BaseApplication.php, line 235 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Routing\Middleware\RoutingMiddleware::__invoke() - CORE/src/Routing/Middleware/RoutingMiddleware.php, line 162 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Routing\Middleware\AssetMiddleware::__invoke() - CORE/src/Routing/Middleware/AssetMiddleware.php, line 88 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Error\Middleware\ErrorHandlerMiddleware::__invoke() - CORE/src/Error/Middleware/ErrorHandlerMiddleware.php, line 96 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Http\Runner::run() - CORE/src/Http/Runner.php, line 51</pre></div></pre>latest-news-updates/a-tale-of-errors-r-ramakumar-16029.html"/> <meta http-equiv="Content-Type" content="text/html; charset=utf-8"/> <link href="https://im4change.in/css/control.css" rel="stylesheet" type="text/css" media="all"/> <title>LATEST NEWS UPDATES | A tale of errors-R Ramakumar | Im4change.org</title> <meta name="description" content=" Contrary to the claims of the UIDAI, fingerprints are a highly inappropriate tool to uniquely identify individuals. Case 1: “There are nine checks on visa nationals arriving into the U.K. [United Kingdom]. The fingerprint matching check is the most recent. It..."/> <script src="https://im4change.in/js/jquery-1.10.2.js"></script> <script type="text/javascript" src="https://im4change.in/js/jquery-migrate.min.js"></script> <script language="javascript" type="text/javascript"> $(document).ready(function () { var img = $("img")[0]; // Get my img elem var pic_real_width, pic_real_height; $("<img/>") // Make in memory copy of image to avoid css issues .attr("src", $(img).attr("src")) .load(function () { pic_real_width = this.width; // Note: $(this).width() will not pic_real_height = this.height; // work for in memory images. }); }); </script> <style type="text/css"> @media screen { div.divFooter { display: block; } } @media print { .printbutton { display: none !important; } } </style> </head> <body> <table cellpadding="0" cellspacing="0" border="0" width="98%" align="center"> <tr> <td class="top_bg"> <div class="divFooter"> <img src="https://im4change.in/images/logo1.jpg" height="59" border="0" alt="Resource centre on India's rural distress" style="padding-top:14px;"/> </div> </td> </tr> <tr> <td id="topspace"> </td> </tr> <tr id="topspace"> <td> </td> </tr> <tr> <td height="50" style="border-bottom:1px solid #000; padding-top:10px;" class="printbutton"> <form><input type="button" value=" Print this page " onclick="window.print();return false;"/></form> </td> </tr> <tr> <td width="100%"> <h1 class="news_headlines" style="font-style:normal"> <strong>A tale of errors-R Ramakumar</strong></h1> </td> </tr> <tr> <td width="100%" style="font-family:Arial, 'Segoe Script', 'Segoe UI', sans-serif, serif"><font size="3"> <div style="text-align: justify"><br /></div><div style="text-align: justify"><em>Contrary to the claims of the UIDAI, fingerprints are a highly inappropriate tool to uniquely identify individuals.</em></div><div style="text-align: justify"><br /></div><div style="text-align: justify">Case 1: “There are nine checks on visa nationals arriving into the U.K. [United Kingdom]. The fingerprint matching check is the most recent. It is the least reliable. It is the least effective in terms of delivering against our requirements….”</div><div style="text-align: justify"><br /></div><div style="text-align: justify">So stated Brodie Clark, the former head of the United Kingdom Border Force, to a stunned Home Affairs Committee on November 15, 2011. Clark was giving oral evidence to the committee on why he had authorised the suspension of fingerprint checks during busy hours at U.K. airports. Pressed further, Clark said, “I knew of it, and I approved it because it was a very sensible thing.”</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Case 2: “The FBI [Federal Bureau of Investigation] apologises to Mr Mayfield and his family for the hardships that this matter has caused.”</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The FBI’s apology came in a public statement, dated May 24, 2004. Brandon Mayfield was an attorney in Oregon and a Muslim convert who was held as a material witness in the Madrid bombing of March 11, 2004. The Spanish police had located a latent fingerprint on a bag that contained explosives and sent it to the FBI. The FBI shortlisted potential matches from its fingerprint database. Two fingerprint experts, one internal and another external, concluded that the latent fingerprint belonged to Mayfield; one expert termed the match as “100% identification”. Mayfield was jailed on the basis of the fingerprint match. Two weeks later, the Spanish police informed the FBI that they had independently matched the latent print with Ouhnane Daoud, an Algerian national living in Spain.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The FBI’s fingerprint gaffe on Mayfield was not the first in the U.S. A few years earlier, Stephen Cowans had to serve a jail sentence of more than six years in Boston on the basis of a false fingerprint match. He was exonerated on the basis of DNA evidence.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">For years, the infallibility of fingerprints as a mark of uniqueness has been some sort of a fairy tale. But with increasing cases of fingerprint mismatches leading to human rights violations like prison detentions, the confidence is waning. Indeed, it was such loss of confidence that contributed to the shelving of national identity projects in the U.K. and many other countries.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">If the confidence is waning globally, in India there appears to be a deeply intriguing faith in the use of fingerprints in establishing unique identity for a population of 120 crore. The Aadhaar project is a classic example. Biometrics – particularly fingerprints – is a central feature of the Aadhaar project. That a Parliamentary Standing Committee had torn apart the robustness of the fingerprint technology – calling it “untested and unreliable” – is dismissed by the government. While time will indeed prove this faith misplaced, some immediate respect for the sceptical voice appears to be long overdue.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The entry of biometrics into Aadhaar is characteristic of how governments evade laws and misrepresent expert opinion to insert untested ideas into policy. In 2009 itself, the Biometric Standards Committee (BSC) of the Unique Identification Authority of India (UIDAI) was circumspect about using fingerprints in Aadhaar. It had stated that “retaining efficacy while scaling the database size… to a billion has not been adequately analysed”. The BSC also stated that “fingerprint quality, the most important variable for determining de-duplication accuracy, has not been studied in depth in the Indian context”. The reason: a large share of the population is dependent on hard manual labour, leading to worn-out fingerprints. This was an early note of caution, which the UIDAI ignored.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Even the BSC had failed to list out the problems of fingerprints comprehensively. For instance, the BSC was silent on the issue of “template ageing”, that is, an increase in “false rejection rates” as people age and sensor characteristics of fingerprint devices change. According to Kevin Bowyer of the University of Notre Dame, physical ageing of fingers results in decreased suppleness of the skin, more wrinkles, lesser flexibility of joints, and accumulated cuts and scars, all of which change the fingerprint itself. This implies the need to re-enrol a large proportion of people almost annually, making the system vulnerable to fraud.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">There was another note of caution on fingerprints, which too was ignored. A report from 4G Identity Solutions, a supplier and consultant for the UIDAI, had mentioned in 2009 itself that about 15 per cent of the Indian population may fail to enrol because of unreadable fingerprints. It specifically noted that “people above 60 years and young children below 12 years may have difficulty enrolling in a fingerprinting system”.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">On iris scans, the BSC was even more circumspect. It did not even provide error estimates for iris scans owing to the “absence of empirical Indian data”. It suggested the use of iris scans only “if they [UIDAI] feel it is required”. This stance of the BSC did not dissuade the UIDAI from deciding to scan irises too at enrolment. In fact, in a clear case of fudge, UIDAI Chairman Nandan Nilekani stated in an interview to PlanetBiometrics (July 5, 2010) that the BSC had “ recommended the inclusion of iris to the biometric modalities”. This was wrong; the BSC never made such a recommendation.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">It is becoming increasingly clear that the decision to include biometrics in Aadhaar had no scientific basis and flew in the face of available evidence (see “How Reliable is UID?”, Frontline, November 19, 2011). Recent evidence suggests that the chickens are indeed coming home to roost.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Biometrics appears at two stages in the Aadhaar project. The first stage is “enrolment”, where three sets of biometrics are collected from each resident: a photograph, fingerprints of all 10 fingers and iris scans of both eyes. The fingerprints and iris scans are used to uniquely identify (or “de-duplicate”) each resident and allot a unique Aadhaar number. The second stage is “authentication”; here, a service would be provided to residents only upon confirmation that his/her fingerprint “matches” the fingerprint stored against his/her name in the enrolment database. Iris scans are not used at the stage of authentication.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">I shall try to argue here that at both the stages – enrolment and authentication – the quantum of errors associated with biometrics is too large to be ignored.</div><div style="text-align: justify"><br /></div><div style="text-align: justify"><em>Errors in enrolment</em></div><div style="text-align: justify"><br /></div><div style="text-align: justify">Let us first take enrolment. Facts emerging from the ground reveal that there have been widespread errors at this stage and that biometrics has been of little help.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">First, in Hyderabad, a data entry supervisor by the name of Mohammed Ali – a former employee of the Infrastructure Leasing and Financial Services Limited (IL&FS) – was shown to have enrolled more than 30,000 residents in a short span of three months. According to reports, all the 30,000 applicants had been issued Aadhaar numbers. There were two interesting aspects with respect to biometrics in this scam.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">(a) Out of the 30,000 residents enrolled, about 870 people were enrolled as physically disabled (“biometric exceptions” in the UIDAI parlance). Their biometric information was not recorded. It is unclear as to how many of these 870 were actually disabled because most of their addresses were fake. It is also unclear as to how many thousands of such fake enrolments have already taken place across India.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">(b) A large proportion of the 30,000 residents enrolled were not enrolled by Ali (because Ali had left IL&FS in between). Instead, these enrolments were done across 17 enrolment centres by other supervisors who used Ali’s login and password. While logging into the system, along with the login and password, supervisors have to submit their fingerprints. Typically, if the supervisor’s fingerprints were not matched as Ali’s, the system should have rejected access. Yet, all the supervisors could gain access to the system using their fingerprints. Clearly, the system was not able to identify the supplied fingerprints as not Ali’s.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Secondly, in what has been the most hilarious Aadhaar number provision to date, one Aadhaar number (4991-1866-5246) was issued in Anantapur district of Andhra Pradesh to a person named Mr Kothimeera (that is, coriander), with his father’s name as Mr Palav (biryani) and address as Gongura Tota, Mamidikaya Vooru (Mango village), Jambuladinne, Anantapur, Andhra Pradesh - 515731. To top it, the date of birth of Mr Kothimeera was recorded as 1887, and the photograph on the card was that of a mobile phone. It is as yet unclear as to what biometric records were supplied with “Mr Kothimeera’s” demographic details and how it passed the test of biometric de-duplication.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Thirdly, the Department of Posts is on record that across India, as on April 20, 6.46 lakh Aadhaar letters posted were returned because the addresses did not exist. In Andhra Pradesh itself, about 50,000 Aadhaar letters were lying undelivered because the addresses were fake. In Karwar, Ankola, Kumta, Honnavar and Bhatkal taluks of Karnataka, about 7,000 Aadhaar letters were lying undelivered because the addresses were fake. While fake addresses have nothing to do with biometrics per se, they provide corroborative evidence to the widespread fraud that takes place at enrolment.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In sum, biometrics has not been able to prevent large-scale errors at the enrolment stage itself. Available evidence itself is persuasive, and it may be logically suspected that unreported errors are of a far larger magnitude.</div><div style="text-align: justify"><br /></div><div style="text-align: justify"><em>Errors in authentication</em></div><div style="text-align: justify"><br /></div><div style="text-align: justify">Interestingly, while three sets of biometrics are collected at the time of enrolment, only one set – fingerprints – is used for authentication. As R.S. Sharma, the Mission Director of the UIDAI, confirmed in an interview to Frontline in 2011, “fingerprint is the basic mode of authentication”. According to Nandan Nilekani, iris scans are not used at authentication because “it’s not a mature technology”. For the moment, we shall postpone asking the reasons for tweaking expert opinion and deciding to use an immature technology at the stage of enrolment.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In his Frontline interview, Sharma admitted that the “quality of fingerprints… poses a challenge for later authentication”. He also stated that “for manual labourers, this authentication will be difficult because only one or two of the 10 fingerprints may be good”. It would appear that Sharma was foretelling what the UIDAI’s Proof of Concept (PoC) studies published in 2012 were to reveal. The PoC studies reveal that fingerprint-based authentication of large populations is largely a non-starter, and point towards enormous risks of exclusion.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The PoC studies were internal studies on small populations conducted by the UIDAI to test the robustness of real-time, fingerprint-based authentication. There was no external review. In Phase 1, a small sample of 14,220 residents was studied in Tumkur district of Karnataka. In Phase 2, about 35,000 Aadhaar holders were covered across four States.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">First, the results confirm the fear that most people in rural areas have unreadable fingerprints. There was also significant variation of quality across the fingerprints of each individual. However, the UIDAI does not admit this in as many words. Instead, the PoC report says: “Certain fingers were observed to provide better authentication accuracy due to good fingerprint ridges and hence better image quality.” Further, it says that “providing multiple attempts of the same finger was seen to improve resident’s chances of successful authentication”. Finally, “senior residents (60+) had the highest rejection rates”; age-wise rejection rates, however, are not provided.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Let us paraphrase the above three results: (a) only some fingers of residents showed best authentication accuracy; (b) even when fingerprint quality was good, authentication was not always successful at the first try; and (c) residents above the age of 60 years showed poor authentication accuracy.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Secondly, to bypass the pervasive problem of poor fingerprint quality, the PoC study defines a “best finger”. It is the finger that “provides the highest chance of successful authentication”. The idea of a “best finger” is a cop-out from the real problem of poor fingerprint quality. Only 93.6 per cent of the residents possessed at least one best finger. Thus, for 6.4 per cent of the residents authentication was not possible with a single finger. In absolute terms, when extrapolated to the population of 120 crore, a 6.4 per cent share translates to 7.2 crore persons. While the use of more than one finger improves authentication accuracy, the figure of 93.6 per cent provides an insight into the potential extent of exclusion due to fingerprint authentication.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Thirdly, authentication was possible only in the case of 93.5 per cent of residents with a single finger at the first attempt itself (see figure). In other words, in the case of about 6.5 per cent of residents (translating to 7.8 crore residents, when applied to 120 crore) authentication was not possible at the first attempt with a single finger. Even when three attempts were allowed, only 96.5 per cent of residents were able to be authenticated.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In India, even a small share of exclusion from authentication can imply the actual exclusion of crores of individuals. Further, when applied to larger populations, the share of residents without one best finger is likely to rise sharply. At 120 crore people, it is impossible to forecast what this share would explode into.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Contrary to the claims of the UIDAI, fingerprints will be a highly inappropriate tool to uniquely identify individuals. Given multiple errors during enrolment and the potentially high error rates at authentication, the use of fingerprint authentication is likely to foster a regime of misidentification and exclusion. Worse still, exclusion will be most acute among poor manual labourers. The poor record of fingerprint readers in U.K. airports and frequent fingerprint mismatches in the U.S. were also a result of fallibilities in the fingerprint technology.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The elderly is another group that would be massively excluded. As the PoC reports admit, those above 60 years had the “highest rejection rates” at authentication. Yet, the Mid-Term Review of the Eleventh Plan by the Planning Commission has recommended the use of Aadhaar fingerprints to pay pension to the elderly through the National Social Assistance Programme (NSAP). The recommendation is to use “banking correspondents”, who would carry handheld fingerprint devices, to make “payments at the doorstep”. A sure recipe for exclusion, it would appear.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In fact, the only group that appears certain to gain from the Aadhaar project is the global biometric industry. As Nandan Nilekani suggested in an interview, “the Unique Identification Project is creating new opportunities for biometric technology…. Our success can, therefore, determine the course the industry will take, since these technologies will be tested in India on an unprecedented scale.” On the other hand, the losses are likely to be felt mostly by the poor. It would be an irony that a project that is marketed in the name of “including the poor” would end up excluding them massively from whatever meagre provisions they obtain from the state today.</div><div style="text-align: justify"><br /></div><div style="text-align: justify"><em>R. Ramakumar is Associate Professor at the Tata Institute of Social Sciences, Mumbai.</em></div> </font> </td> </tr> <tr> <td> </td> </tr> <tr> <td height="50" style="border-top:1px solid #000; border-bottom:1px solid #000;padding-top:10px;"> <form><input type="button" value=" Print this page " onclick="window.print();return false;"/></form> </td> </tr> </table></body> </html>' } $cookies = [] $values = [ (int) 0 => 'text/html; charset=UTF-8' ] $name = 'Content-Type' $first = true $value = 'text/html; charset=UTF-8'header - [internal], line ?? Cake\Http\ResponseEmitter::emitHeaders() - CORE/src/Http/ResponseEmitter.php, line 181 Cake\Http\ResponseEmitter::emit() - CORE/src/Http/ResponseEmitter.php, line 55 Cake\Http\Server::emit() - CORE/src/Http/Server.php, line 141 [main] - ROOT/webroot/index.php, line 39
<head>
<link rel="canonical" href="<?php echo Configure::read('SITE_URL'); ?><?php echo $urlPrefix;?><?php echo $article_current->category->slug; ?>/<?php echo $article_current->seo_url; ?>.html"/>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>
$viewFile = '/home/brlfuser/public_html/src/Template/Layout/printlayout.ctp' $dataForView = [ 'article_current' => object(App\Model\Entity\Article) { 'id' => (int) 15902, 'title' => 'A tale of errors-R Ramakumar', 'subheading' => '', 'description' => '<div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> <em>Contrary to the claims of the UIDAI, fingerprints are a highly inappropriate tool to uniquely identify individuals.</em> </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Case 1: “There are nine checks on visa nationals arriving into the U.K. [United Kingdom]. The fingerprint matching check is the most recent. It is the least reliable. It is the least effective in terms of delivering against our requirements….” </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> So stated Brodie Clark, the former head of the United Kingdom Border Force, to a stunned Home Affairs Committee on November 15, 2011. Clark was giving oral evidence to the committee on why he had authorised the suspension of fingerprint checks during busy hours at U.K. airports. Pressed further, Clark said, “I knew of it, and I approved it because it was a very sensible thing.” </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Case 2: “The FBI [Federal Bureau of Investigation] apologises to Mr Mayfield and his family for the hardships that this matter has caused.” </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The FBI’s apology came in a public statement, dated May 24, 2004. Brandon Mayfield was an attorney in Oregon and a Muslim convert who was held as a material witness in the Madrid bombing of March 11, 2004. The Spanish police had located a latent fingerprint on a bag that contained explosives and sent it to the FBI. The FBI shortlisted potential matches from its fingerprint database. Two fingerprint experts, one internal and another external, concluded that the latent fingerprint belonged to Mayfield; one expert termed the match as “100% identification”. Mayfield was jailed on the basis of the fingerprint match. Two weeks later, the Spanish police informed the FBI that they had independently matched the latent print with Ouhnane Daoud, an Algerian national living in Spain. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The FBI’s fingerprint gaffe on Mayfield was not the first in the U.S. A few years earlier, Stephen Cowans had to serve a jail sentence of more than six years in Boston on the basis of a false fingerprint match. He was exonerated on the basis of DNA evidence. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> For years, the infallibility of fingerprints as a mark of uniqueness has been some sort of a fairy tale. But with increasing cases of fingerprint mismatches leading to human rights violations like prison detentions, the confidence is waning. Indeed, it was such loss of confidence that contributed to the shelving of national identity projects in the U.K. and many other countries. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> If the confidence is waning globally, in India there appears to be a deeply intriguing faith in the use of fingerprints in establishing unique identity for a population of 120 crore. The Aadhaar project is a classic example. Biometrics – particularly fingerprints – is a central feature of the Aadhaar project. That a Parliamentary Standing Committee had torn apart the robustness of the fingerprint technology – calling it “untested and unreliable” – is dismissed by the government. While time will indeed prove this faith misplaced, some immediate respect for the sceptical voice appears to be long overdue. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The entry of biometrics into Aadhaar is characteristic of how governments evade laws and misrepresent expert opinion to insert untested ideas into policy. In 2009 itself, the Biometric Standards Committee (BSC) of the Unique Identification Authority of India (UIDAI) was circumspect about using fingerprints in Aadhaar. It had stated that “retaining efficacy while scaling the database size… to a billion has not been adequately analysed”. The BSC also stated that “fingerprint quality, the most important variable for determining de-duplication accuracy, has not been studied in depth in the Indian context”. The reason: a large share of the population is dependent on hard manual labour, leading to worn-out fingerprints. This was an early note of caution, which the UIDAI ignored. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Even the BSC had failed to list out the problems of fingerprints comprehensively. For instance, the BSC was silent on the issue of “template ageing”, that is, an increase in “false rejection rates” as people age and sensor characteristics of fingerprint devices change. According to Kevin Bowyer of the University of Notre Dame, physical ageing of fingers results in decreased suppleness of the skin, more wrinkles, lesser flexibility of joints, and accumulated cuts and scars, all of which change the fingerprint itself. This implies the need to re-enrol a large proportion of people almost annually, making the system vulnerable to fraud. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> There was another note of caution on fingerprints, which too was ignored. A report from 4G Identity Solutions, a supplier and consultant for the UIDAI, had mentioned in 2009 itself that about 15 per cent of the Indian population may fail to enrol because of unreadable fingerprints. It specifically noted that “people above 60 years and young children below 12 years may have difficulty enrolling in a fingerprinting system”. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> On iris scans, the BSC was even more circumspect. It did not even provide error estimates for iris scans owing to the “absence of empirical Indian data”. It suggested the use of iris scans only “if they [UIDAI] feel it is required”. This stance of the BSC did not dissuade the UIDAI from deciding to scan irises too at enrolment. In fact, in a clear case of fudge, UIDAI Chairman Nandan Nilekani stated in an interview to PlanetBiometrics (July 5, 2010) that the BSC had “ recommended the inclusion of iris to the biometric modalities”. This was wrong; the BSC never made such a recommendation. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> It is becoming increasingly clear that the decision to include biometrics in Aadhaar had no scientific basis and flew in the face of available evidence (see “How Reliable is UID?”, Frontline, November 19, 2011). Recent evidence suggests that the chickens are indeed coming home to roost. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Biometrics appears at two stages in the Aadhaar project. The first stage is “enrolment”, where three sets of biometrics are collected from each resident: a photograph, fingerprints of all 10 fingers and iris scans of both eyes. The fingerprints and iris scans are used to uniquely identify (or “de-duplicate”) each resident and allot a unique Aadhaar number. The second stage is “authentication”; here, a service would be provided to residents only upon confirmation that his/her fingerprint “matches” the fingerprint stored against his/her name in the enrolment database. Iris scans are not used at the stage of authentication. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> I shall try to argue here that at both the stages – enrolment and authentication – the quantum of errors associated with biometrics is too large to be ignored. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> <em>Errors in enrolment</em> </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Let us first take enrolment. Facts emerging from the ground reveal that there have been widespread errors at this stage and that biometrics has been of little help. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> First, in Hyderabad, a data entry supervisor by the name of Mohammed Ali – a former employee of the Infrastructure Leasing and Financial Services Limited (IL&FS) – was shown to have enrolled more than 30,000 residents in a short span of three months. According to reports, all the 30,000 applicants had been issued Aadhaar numbers. There were two interesting aspects with respect to biometrics in this scam. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> (a) Out of the 30,000 residents enrolled, about 870 people were enrolled as physically disabled (“biometric exceptions” in the UIDAI parlance). Their biometric information was not recorded. It is unclear as to how many of these 870 were actually disabled because most of their addresses were fake. It is also unclear as to how many thousands of such fake enrolments have already taken place across India. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> (b) A large proportion of the 30,000 residents enrolled were not enrolled by Ali (because Ali had left IL&FS in between). Instead, these enrolments were done across 17 enrolment centres by other supervisors who used Ali’s login and password. While logging into the system, along with the login and password, supervisors have to submit their fingerprints. Typically, if the supervisor’s fingerprints were not matched as Ali’s, the system should have rejected access. Yet, all the supervisors could gain access to the system using their fingerprints. Clearly, the system was not able to identify the supplied fingerprints as not Ali’s. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Secondly, in what has been the most hilarious Aadhaar number provision to date, one Aadhaar number (4991-1866-5246) was issued in Anantapur district of Andhra Pradesh to a person named Mr Kothimeera (that is, coriander), with his father’s name as Mr Palav (biryani) and address as Gongura Tota, Mamidikaya Vooru (Mango village), Jambuladinne, Anantapur, Andhra Pradesh - 515731. To top it, the date of birth of Mr Kothimeera was recorded as 1887, and the photograph on the card was that of a mobile phone. It is as yet unclear as to what biometric records were supplied with “Mr Kothimeera’s” demographic details and how it passed the test of biometric de-duplication. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Thirdly, the Department of Posts is on record that across India, as on April 20, 6.46 lakh Aadhaar letters posted were returned because the addresses did not exist. In Andhra Pradesh itself, about 50,000 Aadhaar letters were lying undelivered because the addresses were fake. In Karwar, Ankola, Kumta, Honnavar and Bhatkal taluks of Karnataka, about 7,000 Aadhaar letters were lying undelivered because the addresses were fake. While fake addresses have nothing to do with biometrics per se, they provide corroborative evidence to the widespread fraud that takes place at enrolment. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> In sum, biometrics has not been able to prevent large-scale errors at the enrolment stage itself. Available evidence itself is persuasive, and it may be logically suspected that unreported errors are of a far larger magnitude. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> <em>Errors in authentication</em> </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Interestingly, while three sets of biometrics are collected at the time of enrolment, only one set – fingerprints – is used for authentication. As R.S. Sharma, the Mission Director of the UIDAI, confirmed in an interview to Frontline in 2011, “fingerprint is the basic mode of authentication”. According to Nandan Nilekani, iris scans are not used at authentication because “it’s not a mature technology”. For the moment, we shall postpone asking the reasons for tweaking expert opinion and deciding to use an immature technology at the stage of enrolment. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> In his Frontline interview, Sharma admitted that the “quality of fingerprints… poses a challenge for later authentication”. He also stated that “for manual labourers, this authentication will be difficult because only one or two of the 10 fingerprints may be good”. It would appear that Sharma was foretelling what the UIDAI’s Proof of Concept (PoC) studies published in 2012 were to reveal. The PoC studies reveal that fingerprint-based authentication of large populations is largely a non-starter, and point towards enormous risks of exclusion. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The PoC studies were internal studies on small populations conducted by the UIDAI to test the robustness of real-time, fingerprint-based authentication. There was no external review. In Phase 1, a small sample of 14,220 residents was studied in Tumkur district of Karnataka. In Phase 2, about 35,000 Aadhaar holders were covered across four States. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> First, the results confirm the fear that most people in rural areas have unreadable fingerprints. There was also significant variation of quality across the fingerprints of each individual. However, the UIDAI does not admit this in as many words. Instead, the PoC report says: “Certain fingers were observed to provide better authentication accuracy due to good fingerprint ridges and hence better image quality.” Further, it says that “providing multiple attempts of the same finger was seen to improve resident’s chances of successful authentication”. Finally, “senior residents (60+) had the highest rejection rates”; age-wise rejection rates, however, are not provided. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Let us paraphrase the above three results: (a) only some fingers of residents showed best authentication accuracy; (b) even when fingerprint quality was good, authentication was not always successful at the first try; and (c) residents above the age of 60 years showed poor authentication accuracy. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Secondly, to bypass the pervasive problem of poor fingerprint quality, the PoC study defines a “best finger”. It is the finger that “provides the highest chance of successful authentication”. The idea of a “best finger” is a cop-out from the real problem of poor fingerprint quality. Only 93.6 per cent of the residents possessed at least one best finger. Thus, for 6.4 per cent of the residents authentication was not possible with a single finger. In absolute terms, when extrapolated to the population of 120 crore, a 6.4 per cent share translates to 7.2 crore persons. While the use of more than one finger improves authentication accuracy, the figure of 93.6 per cent provides an insight into the potential extent of exclusion due to fingerprint authentication. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Thirdly, authentication was possible only in the case of 93.5 per cent of residents with a single finger at the first attempt itself (see figure). In other words, in the case of about 6.5 per cent of residents (translating to 7.8 crore residents, when applied to 120 crore) authentication was not possible at the first attempt with a single finger. Even when three attempts were allowed, only 96.5 per cent of residents were able to be authenticated. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> In India, even a small share of exclusion from authentication can imply the actual exclusion of crores of individuals. Further, when applied to larger populations, the share of residents without one best finger is likely to rise sharply. At 120 crore people, it is impossible to forecast what this share would explode into. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Contrary to the claims of the UIDAI, fingerprints will be a highly inappropriate tool to uniquely identify individuals. Given multiple errors during enrolment and the potentially high error rates at authentication, the use of fingerprint authentication is likely to foster a regime of misidentification and exclusion. Worse still, exclusion will be most acute among poor manual labourers. The poor record of fingerprint readers in U.K. airports and frequent fingerprint mismatches in the U.S. were also a result of fallibilities in the fingerprint technology. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The elderly is another group that would be massively excluded. As the PoC reports admit, those above 60 years had the “highest rejection rates” at authentication. Yet, the Mid-Term Review of the Eleventh Plan by the Planning Commission has recommended the use of Aadhaar fingerprints to pay pension to the elderly through the National Social Assistance Programme (NSAP). The recommendation is to use “banking correspondents”, who would carry handheld fingerprint devices, to make “payments at the doorstep”. A sure recipe for exclusion, it would appear. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> In fact, the only group that appears certain to gain from the Aadhaar project is the global biometric industry. As Nandan Nilekani suggested in an interview, “the Unique Identification Project is creating new opportunities for biometric technology…. Our success can, therefore, determine the course the industry will take, since these technologies will be tested in India on an unprecedented scale.” On the other hand, the losses are likely to be felt mostly by the poor. It would be an irony that a project that is marketed in the name of “including the poor” would end up excluding them massively from whatever meagre provisions they obtain from the state today. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> <em>R. Ramakumar is Associate Professor at the Tata Institute of Social Sciences, Mumbai.</em> </div>', 'credit_writer' => 'Frontline, Volume 29, Issue 13, 30 June-13 July, 2012, http://www.frontline.in/stories/20120713291303400.htm', 'article_img' => '', 'article_img_thumb' => '', 'status' => (int) 1, 'show_on_home' => (int) 1, 'lang' => 'EN', 'category_id' => (int) 16, 'tag_keyword' => '', 'seo_url' => 'a-tale-of-errors-r-ramakumar-16029', 'meta_title' => null, 'meta_keywords' => null, 'meta_description' => null, 'noindex' => (int) 0, 'publish_date' => object(Cake\I18n\FrozenDate) {}, 'most_visit_section_id' => null, 'article_big_img' => null, 'liveid' => (int) 16029, 'created' => object(Cake\I18n\FrozenTime) {}, 'modified' => object(Cake\I18n\FrozenTime) {}, 'edate' => '', 'tags' => [ [maximum depth reached] ], 'category' => object(App\Model\Entity\Category) {}, '[new]' => false, '[accessible]' => [ [maximum depth reached] ], '[dirty]' => [[maximum depth reached]], '[original]' => [[maximum depth reached]], '[virtual]' => [[maximum depth reached]], '[hasErrors]' => false, '[errors]' => [[maximum depth reached]], '[invalid]' => [[maximum depth reached]], '[repository]' => 'Articles' }, 'articleid' => (int) 15902, 'metaTitle' => 'LATEST NEWS UPDATES | A tale of errors-R Ramakumar', 'metaKeywords' => 'aadhaar,uid,ICTs', 'metaDesc' => ' Contrary to the claims of the UIDAI, fingerprints are a highly inappropriate tool to uniquely identify individuals. Case 1: “There are nine checks on visa nationals arriving into the U.K. [United Kingdom]. The fingerprint matching check is the most recent. It...', 'disp' => '<div style="text-align: justify"><br /></div><div style="text-align: justify"><em>Contrary to the claims of the UIDAI, fingerprints are a highly inappropriate tool to uniquely identify individuals.</em></div><div style="text-align: justify"><br /></div><div style="text-align: justify">Case 1: “There are nine checks on visa nationals arriving into the U.K. [United Kingdom]. The fingerprint matching check is the most recent. It is the least reliable. It is the least effective in terms of delivering against our requirements….”</div><div style="text-align: justify"><br /></div><div style="text-align: justify">So stated Brodie Clark, the former head of the United Kingdom Border Force, to a stunned Home Affairs Committee on November 15, 2011. Clark was giving oral evidence to the committee on why he had authorised the suspension of fingerprint checks during busy hours at U.K. airports. Pressed further, Clark said, “I knew of it, and I approved it because it was a very sensible thing.”</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Case 2: “The FBI [Federal Bureau of Investigation] apologises to Mr Mayfield and his family for the hardships that this matter has caused.”</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The FBI’s apology came in a public statement, dated May 24, 2004. Brandon Mayfield was an attorney in Oregon and a Muslim convert who was held as a material witness in the Madrid bombing of March 11, 2004. The Spanish police had located a latent fingerprint on a bag that contained explosives and sent it to the FBI. The FBI shortlisted potential matches from its fingerprint database. Two fingerprint experts, one internal and another external, concluded that the latent fingerprint belonged to Mayfield; one expert termed the match as “100% identification”. Mayfield was jailed on the basis of the fingerprint match. Two weeks later, the Spanish police informed the FBI that they had independently matched the latent print with Ouhnane Daoud, an Algerian national living in Spain.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The FBI’s fingerprint gaffe on Mayfield was not the first in the U.S. A few years earlier, Stephen Cowans had to serve a jail sentence of more than six years in Boston on the basis of a false fingerprint match. He was exonerated on the basis of DNA evidence.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">For years, the infallibility of fingerprints as a mark of uniqueness has been some sort of a fairy tale. But with increasing cases of fingerprint mismatches leading to human rights violations like prison detentions, the confidence is waning. Indeed, it was such loss of confidence that contributed to the shelving of national identity projects in the U.K. and many other countries.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">If the confidence is waning globally, in India there appears to be a deeply intriguing faith in the use of fingerprints in establishing unique identity for a population of 120 crore. The Aadhaar project is a classic example. Biometrics – particularly fingerprints – is a central feature of the Aadhaar project. That a Parliamentary Standing Committee had torn apart the robustness of the fingerprint technology – calling it “untested and unreliable” – is dismissed by the government. While time will indeed prove this faith misplaced, some immediate respect for the sceptical voice appears to be long overdue.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The entry of biometrics into Aadhaar is characteristic of how governments evade laws and misrepresent expert opinion to insert untested ideas into policy. In 2009 itself, the Biometric Standards Committee (BSC) of the Unique Identification Authority of India (UIDAI) was circumspect about using fingerprints in Aadhaar. It had stated that “retaining efficacy while scaling the database size… to a billion has not been adequately analysed”. The BSC also stated that “fingerprint quality, the most important variable for determining de-duplication accuracy, has not been studied in depth in the Indian context”. The reason: a large share of the population is dependent on hard manual labour, leading to worn-out fingerprints. This was an early note of caution, which the UIDAI ignored.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Even the BSC had failed to list out the problems of fingerprints comprehensively. For instance, the BSC was silent on the issue of “template ageing”, that is, an increase in “false rejection rates” as people age and sensor characteristics of fingerprint devices change. According to Kevin Bowyer of the University of Notre Dame, physical ageing of fingers results in decreased suppleness of the skin, more wrinkles, lesser flexibility of joints, and accumulated cuts and scars, all of which change the fingerprint itself. This implies the need to re-enrol a large proportion of people almost annually, making the system vulnerable to fraud.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">There was another note of caution on fingerprints, which too was ignored. A report from 4G Identity Solutions, a supplier and consultant for the UIDAI, had mentioned in 2009 itself that about 15 per cent of the Indian population may fail to enrol because of unreadable fingerprints. It specifically noted that “people above 60 years and young children below 12 years may have difficulty enrolling in a fingerprinting system”.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">On iris scans, the BSC was even more circumspect. It did not even provide error estimates for iris scans owing to the “absence of empirical Indian data”. It suggested the use of iris scans only “if they [UIDAI] feel it is required”. This stance of the BSC did not dissuade the UIDAI from deciding to scan irises too at enrolment. In fact, in a clear case of fudge, UIDAI Chairman Nandan Nilekani stated in an interview to PlanetBiometrics (July 5, 2010) that the BSC had “ recommended the inclusion of iris to the biometric modalities”. This was wrong; the BSC never made such a recommendation.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">It is becoming increasingly clear that the decision to include biometrics in Aadhaar had no scientific basis and flew in the face of available evidence (see “How Reliable is UID?”, Frontline, November 19, 2011). Recent evidence suggests that the chickens are indeed coming home to roost.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Biometrics appears at two stages in the Aadhaar project. The first stage is “enrolment”, where three sets of biometrics are collected from each resident: a photograph, fingerprints of all 10 fingers and iris scans of both eyes. The fingerprints and iris scans are used to uniquely identify (or “de-duplicate”) each resident and allot a unique Aadhaar number. The second stage is “authentication”; here, a service would be provided to residents only upon confirmation that his/her fingerprint “matches” the fingerprint stored against his/her name in the enrolment database. Iris scans are not used at the stage of authentication.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">I shall try to argue here that at both the stages – enrolment and authentication – the quantum of errors associated with biometrics is too large to be ignored.</div><div style="text-align: justify"><br /></div><div style="text-align: justify"><em>Errors in enrolment</em></div><div style="text-align: justify"><br /></div><div style="text-align: justify">Let us first take enrolment. Facts emerging from the ground reveal that there have been widespread errors at this stage and that biometrics has been of little help.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">First, in Hyderabad, a data entry supervisor by the name of Mohammed Ali – a former employee of the Infrastructure Leasing and Financial Services Limited (IL&FS) – was shown to have enrolled more than 30,000 residents in a short span of three months. According to reports, all the 30,000 applicants had been issued Aadhaar numbers. There were two interesting aspects with respect to biometrics in this scam.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">(a) Out of the 30,000 residents enrolled, about 870 people were enrolled as physically disabled (“biometric exceptions” in the UIDAI parlance). Their biometric information was not recorded. It is unclear as to how many of these 870 were actually disabled because most of their addresses were fake. It is also unclear as to how many thousands of such fake enrolments have already taken place across India.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">(b) A large proportion of the 30,000 residents enrolled were not enrolled by Ali (because Ali had left IL&FS in between). Instead, these enrolments were done across 17 enrolment centres by other supervisors who used Ali’s login and password. While logging into the system, along with the login and password, supervisors have to submit their fingerprints. Typically, if the supervisor’s fingerprints were not matched as Ali’s, the system should have rejected access. Yet, all the supervisors could gain access to the system using their fingerprints. Clearly, the system was not able to identify the supplied fingerprints as not Ali’s.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Secondly, in what has been the most hilarious Aadhaar number provision to date, one Aadhaar number (4991-1866-5246) was issued in Anantapur district of Andhra Pradesh to a person named Mr Kothimeera (that is, coriander), with his father’s name as Mr Palav (biryani) and address as Gongura Tota, Mamidikaya Vooru (Mango village), Jambuladinne, Anantapur, Andhra Pradesh - 515731. To top it, the date of birth of Mr Kothimeera was recorded as 1887, and the photograph on the card was that of a mobile phone. It is as yet unclear as to what biometric records were supplied with “Mr Kothimeera’s” demographic details and how it passed the test of biometric de-duplication.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Thirdly, the Department of Posts is on record that across India, as on April 20, 6.46 lakh Aadhaar letters posted were returned because the addresses did not exist. In Andhra Pradesh itself, about 50,000 Aadhaar letters were lying undelivered because the addresses were fake. In Karwar, Ankola, Kumta, Honnavar and Bhatkal taluks of Karnataka, about 7,000 Aadhaar letters were lying undelivered because the addresses were fake. While fake addresses have nothing to do with biometrics per se, they provide corroborative evidence to the widespread fraud that takes place at enrolment.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In sum, biometrics has not been able to prevent large-scale errors at the enrolment stage itself. Available evidence itself is persuasive, and it may be logically suspected that unreported errors are of a far larger magnitude.</div><div style="text-align: justify"><br /></div><div style="text-align: justify"><em>Errors in authentication</em></div><div style="text-align: justify"><br /></div><div style="text-align: justify">Interestingly, while three sets of biometrics are collected at the time of enrolment, only one set – fingerprints – is used for authentication. As R.S. Sharma, the Mission Director of the UIDAI, confirmed in an interview to Frontline in 2011, “fingerprint is the basic mode of authentication”. According to Nandan Nilekani, iris scans are not used at authentication because “it’s not a mature technology”. For the moment, we shall postpone asking the reasons for tweaking expert opinion and deciding to use an immature technology at the stage of enrolment.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In his Frontline interview, Sharma admitted that the “quality of fingerprints… poses a challenge for later authentication”. He also stated that “for manual labourers, this authentication will be difficult because only one or two of the 10 fingerprints may be good”. It would appear that Sharma was foretelling what the UIDAI’s Proof of Concept (PoC) studies published in 2012 were to reveal. The PoC studies reveal that fingerprint-based authentication of large populations is largely a non-starter, and point towards enormous risks of exclusion.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The PoC studies were internal studies on small populations conducted by the UIDAI to test the robustness of real-time, fingerprint-based authentication. There was no external review. In Phase 1, a small sample of 14,220 residents was studied in Tumkur district of Karnataka. In Phase 2, about 35,000 Aadhaar holders were covered across four States.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">First, the results confirm the fear that most people in rural areas have unreadable fingerprints. There was also significant variation of quality across the fingerprints of each individual. However, the UIDAI does not admit this in as many words. Instead, the PoC report says: “Certain fingers were observed to provide better authentication accuracy due to good fingerprint ridges and hence better image quality.” Further, it says that “providing multiple attempts of the same finger was seen to improve resident’s chances of successful authentication”. Finally, “senior residents (60+) had the highest rejection rates”; age-wise rejection rates, however, are not provided.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Let us paraphrase the above three results: (a) only some fingers of residents showed best authentication accuracy; (b) even when fingerprint quality was good, authentication was not always successful at the first try; and (c) residents above the age of 60 years showed poor authentication accuracy.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Secondly, to bypass the pervasive problem of poor fingerprint quality, the PoC study defines a “best finger”. It is the finger that “provides the highest chance of successful authentication”. The idea of a “best finger” is a cop-out from the real problem of poor fingerprint quality. Only 93.6 per cent of the residents possessed at least one best finger. Thus, for 6.4 per cent of the residents authentication was not possible with a single finger. In absolute terms, when extrapolated to the population of 120 crore, a 6.4 per cent share translates to 7.2 crore persons. While the use of more than one finger improves authentication accuracy, the figure of 93.6 per cent provides an insight into the potential extent of exclusion due to fingerprint authentication.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Thirdly, authentication was possible only in the case of 93.5 per cent of residents with a single finger at the first attempt itself (see figure). In other words, in the case of about 6.5 per cent of residents (translating to 7.8 crore residents, when applied to 120 crore) authentication was not possible at the first attempt with a single finger. Even when three attempts were allowed, only 96.5 per cent of residents were able to be authenticated.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In India, even a small share of exclusion from authentication can imply the actual exclusion of crores of individuals. Further, when applied to larger populations, the share of residents without one best finger is likely to rise sharply. At 120 crore people, it is impossible to forecast what this share would explode into.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Contrary to the claims of the UIDAI, fingerprints will be a highly inappropriate tool to uniquely identify individuals. Given multiple errors during enrolment and the potentially high error rates at authentication, the use of fingerprint authentication is likely to foster a regime of misidentification and exclusion. Worse still, exclusion will be most acute among poor manual labourers. The poor record of fingerprint readers in U.K. airports and frequent fingerprint mismatches in the U.S. were also a result of fallibilities in the fingerprint technology.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The elderly is another group that would be massively excluded. As the PoC reports admit, those above 60 years had the “highest rejection rates” at authentication. Yet, the Mid-Term Review of the Eleventh Plan by the Planning Commission has recommended the use of Aadhaar fingerprints to pay pension to the elderly through the National Social Assistance Programme (NSAP). The recommendation is to use “banking correspondents”, who would carry handheld fingerprint devices, to make “payments at the doorstep”. A sure recipe for exclusion, it would appear.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In fact, the only group that appears certain to gain from the Aadhaar project is the global biometric industry. As Nandan Nilekani suggested in an interview, “the Unique Identification Project is creating new opportunities for biometric technology…. Our success can, therefore, determine the course the industry will take, since these technologies will be tested in India on an unprecedented scale.” On the other hand, the losses are likely to be felt mostly by the poor. It would be an irony that a project that is marketed in the name of “including the poor” would end up excluding them massively from whatever meagre provisions they obtain from the state today.</div><div style="text-align: justify"><br /></div><div style="text-align: justify"><em>R. Ramakumar is Associate Professor at the Tata Institute of Social Sciences, Mumbai.</em></div>', 'lang' => 'English', 'SITE_URL' => 'https://im4change.in/', 'site_title' => 'im4change', 'adminprix' => 'admin' ] $article_current = object(App\Model\Entity\Article) { 'id' => (int) 15902, 'title' => 'A tale of errors-R Ramakumar', 'subheading' => '', 'description' => '<div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> <em>Contrary to the claims of the UIDAI, fingerprints are a highly inappropriate tool to uniquely identify individuals.</em> </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Case 1: “There are nine checks on visa nationals arriving into the U.K. [United Kingdom]. The fingerprint matching check is the most recent. It is the least reliable. It is the least effective in terms of delivering against our requirements….” </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> So stated Brodie Clark, the former head of the United Kingdom Border Force, to a stunned Home Affairs Committee on November 15, 2011. Clark was giving oral evidence to the committee on why he had authorised the suspension of fingerprint checks during busy hours at U.K. airports. Pressed further, Clark said, “I knew of it, and I approved it because it was a very sensible thing.” </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Case 2: “The FBI [Federal Bureau of Investigation] apologises to Mr Mayfield and his family for the hardships that this matter has caused.” </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The FBI’s apology came in a public statement, dated May 24, 2004. Brandon Mayfield was an attorney in Oregon and a Muslim convert who was held as a material witness in the Madrid bombing of March 11, 2004. The Spanish police had located a latent fingerprint on a bag that contained explosives and sent it to the FBI. The FBI shortlisted potential matches from its fingerprint database. Two fingerprint experts, one internal and another external, concluded that the latent fingerprint belonged to Mayfield; one expert termed the match as “100% identification”. Mayfield was jailed on the basis of the fingerprint match. Two weeks later, the Spanish police informed the FBI that they had independently matched the latent print with Ouhnane Daoud, an Algerian national living in Spain. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The FBI’s fingerprint gaffe on Mayfield was not the first in the U.S. A few years earlier, Stephen Cowans had to serve a jail sentence of more than six years in Boston on the basis of a false fingerprint match. He was exonerated on the basis of DNA evidence. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> For years, the infallibility of fingerprints as a mark of uniqueness has been some sort of a fairy tale. But with increasing cases of fingerprint mismatches leading to human rights violations like prison detentions, the confidence is waning. Indeed, it was such loss of confidence that contributed to the shelving of national identity projects in the U.K. and many other countries. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> If the confidence is waning globally, in India there appears to be a deeply intriguing faith in the use of fingerprints in establishing unique identity for a population of 120 crore. The Aadhaar project is a classic example. Biometrics – particularly fingerprints – is a central feature of the Aadhaar project. That a Parliamentary Standing Committee had torn apart the robustness of the fingerprint technology – calling it “untested and unreliable” – is dismissed by the government. While time will indeed prove this faith misplaced, some immediate respect for the sceptical voice appears to be long overdue. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The entry of biometrics into Aadhaar is characteristic of how governments evade laws and misrepresent expert opinion to insert untested ideas into policy. In 2009 itself, the Biometric Standards Committee (BSC) of the Unique Identification Authority of India (UIDAI) was circumspect about using fingerprints in Aadhaar. It had stated that “retaining efficacy while scaling the database size… to a billion has not been adequately analysed”. The BSC also stated that “fingerprint quality, the most important variable for determining de-duplication accuracy, has not been studied in depth in the Indian context”. The reason: a large share of the population is dependent on hard manual labour, leading to worn-out fingerprints. This was an early note of caution, which the UIDAI ignored. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Even the BSC had failed to list out the problems of fingerprints comprehensively. For instance, the BSC was silent on the issue of “template ageing”, that is, an increase in “false rejection rates” as people age and sensor characteristics of fingerprint devices change. According to Kevin Bowyer of the University of Notre Dame, physical ageing of fingers results in decreased suppleness of the skin, more wrinkles, lesser flexibility of joints, and accumulated cuts and scars, all of which change the fingerprint itself. This implies the need to re-enrol a large proportion of people almost annually, making the system vulnerable to fraud. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> There was another note of caution on fingerprints, which too was ignored. A report from 4G Identity Solutions, a supplier and consultant for the UIDAI, had mentioned in 2009 itself that about 15 per cent of the Indian population may fail to enrol because of unreadable fingerprints. It specifically noted that “people above 60 years and young children below 12 years may have difficulty enrolling in a fingerprinting system”. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> On iris scans, the BSC was even more circumspect. It did not even provide error estimates for iris scans owing to the “absence of empirical Indian data”. It suggested the use of iris scans only “if they [UIDAI] feel it is required”. This stance of the BSC did not dissuade the UIDAI from deciding to scan irises too at enrolment. In fact, in a clear case of fudge, UIDAI Chairman Nandan Nilekani stated in an interview to PlanetBiometrics (July 5, 2010) that the BSC had “ recommended the inclusion of iris to the biometric modalities”. This was wrong; the BSC never made such a recommendation. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> It is becoming increasingly clear that the decision to include biometrics in Aadhaar had no scientific basis and flew in the face of available evidence (see “How Reliable is UID?”, Frontline, November 19, 2011). Recent evidence suggests that the chickens are indeed coming home to roost. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Biometrics appears at two stages in the Aadhaar project. The first stage is “enrolment”, where three sets of biometrics are collected from each resident: a photograph, fingerprints of all 10 fingers and iris scans of both eyes. The fingerprints and iris scans are used to uniquely identify (or “de-duplicate”) each resident and allot a unique Aadhaar number. The second stage is “authentication”; here, a service would be provided to residents only upon confirmation that his/her fingerprint “matches” the fingerprint stored against his/her name in the enrolment database. Iris scans are not used at the stage of authentication. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> I shall try to argue here that at both the stages – enrolment and authentication – the quantum of errors associated with biometrics is too large to be ignored. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> <em>Errors in enrolment</em> </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Let us first take enrolment. Facts emerging from the ground reveal that there have been widespread errors at this stage and that biometrics has been of little help. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> First, in Hyderabad, a data entry supervisor by the name of Mohammed Ali – a former employee of the Infrastructure Leasing and Financial Services Limited (IL&FS) – was shown to have enrolled more than 30,000 residents in a short span of three months. According to reports, all the 30,000 applicants had been issued Aadhaar numbers. There were two interesting aspects with respect to biometrics in this scam. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> (a) Out of the 30,000 residents enrolled, about 870 people were enrolled as physically disabled (“biometric exceptions” in the UIDAI parlance). Their biometric information was not recorded. It is unclear as to how many of these 870 were actually disabled because most of their addresses were fake. It is also unclear as to how many thousands of such fake enrolments have already taken place across India. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> (b) A large proportion of the 30,000 residents enrolled were not enrolled by Ali (because Ali had left IL&FS in between). Instead, these enrolments were done across 17 enrolment centres by other supervisors who used Ali’s login and password. While logging into the system, along with the login and password, supervisors have to submit their fingerprints. Typically, if the supervisor’s fingerprints were not matched as Ali’s, the system should have rejected access. Yet, all the supervisors could gain access to the system using their fingerprints. Clearly, the system was not able to identify the supplied fingerprints as not Ali’s. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Secondly, in what has been the most hilarious Aadhaar number provision to date, one Aadhaar number (4991-1866-5246) was issued in Anantapur district of Andhra Pradesh to a person named Mr Kothimeera (that is, coriander), with his father’s name as Mr Palav (biryani) and address as Gongura Tota, Mamidikaya Vooru (Mango village), Jambuladinne, Anantapur, Andhra Pradesh - 515731. To top it, the date of birth of Mr Kothimeera was recorded as 1887, and the photograph on the card was that of a mobile phone. It is as yet unclear as to what biometric records were supplied with “Mr Kothimeera’s” demographic details and how it passed the test of biometric de-duplication. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Thirdly, the Department of Posts is on record that across India, as on April 20, 6.46 lakh Aadhaar letters posted were returned because the addresses did not exist. In Andhra Pradesh itself, about 50,000 Aadhaar letters were lying undelivered because the addresses were fake. In Karwar, Ankola, Kumta, Honnavar and Bhatkal taluks of Karnataka, about 7,000 Aadhaar letters were lying undelivered because the addresses were fake. While fake addresses have nothing to do with biometrics per se, they provide corroborative evidence to the widespread fraud that takes place at enrolment. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> In sum, biometrics has not been able to prevent large-scale errors at the enrolment stage itself. Available evidence itself is persuasive, and it may be logically suspected that unreported errors are of a far larger magnitude. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> <em>Errors in authentication</em> </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Interestingly, while three sets of biometrics are collected at the time of enrolment, only one set – fingerprints – is used for authentication. As R.S. Sharma, the Mission Director of the UIDAI, confirmed in an interview to Frontline in 2011, “fingerprint is the basic mode of authentication”. According to Nandan Nilekani, iris scans are not used at authentication because “it’s not a mature technology”. For the moment, we shall postpone asking the reasons for tweaking expert opinion and deciding to use an immature technology at the stage of enrolment. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> In his Frontline interview, Sharma admitted that the “quality of fingerprints… poses a challenge for later authentication”. He also stated that “for manual labourers, this authentication will be difficult because only one or two of the 10 fingerprints may be good”. It would appear that Sharma was foretelling what the UIDAI’s Proof of Concept (PoC) studies published in 2012 were to reveal. The PoC studies reveal that fingerprint-based authentication of large populations is largely a non-starter, and point towards enormous risks of exclusion. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The PoC studies were internal studies on small populations conducted by the UIDAI to test the robustness of real-time, fingerprint-based authentication. There was no external review. In Phase 1, a small sample of 14,220 residents was studied in Tumkur district of Karnataka. In Phase 2, about 35,000 Aadhaar holders were covered across four States. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> First, the results confirm the fear that most people in rural areas have unreadable fingerprints. There was also significant variation of quality across the fingerprints of each individual. However, the UIDAI does not admit this in as many words. Instead, the PoC report says: “Certain fingers were observed to provide better authentication accuracy due to good fingerprint ridges and hence better image quality.” Further, it says that “providing multiple attempts of the same finger was seen to improve resident’s chances of successful authentication”. Finally, “senior residents (60+) had the highest rejection rates”; age-wise rejection rates, however, are not provided. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Let us paraphrase the above three results: (a) only some fingers of residents showed best authentication accuracy; (b) even when fingerprint quality was good, authentication was not always successful at the first try; and (c) residents above the age of 60 years showed poor authentication accuracy. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Secondly, to bypass the pervasive problem of poor fingerprint quality, the PoC study defines a “best finger”. It is the finger that “provides the highest chance of successful authentication”. The idea of a “best finger” is a cop-out from the real problem of poor fingerprint quality. Only 93.6 per cent of the residents possessed at least one best finger. Thus, for 6.4 per cent of the residents authentication was not possible with a single finger. In absolute terms, when extrapolated to the population of 120 crore, a 6.4 per cent share translates to 7.2 crore persons. While the use of more than one finger improves authentication accuracy, the figure of 93.6 per cent provides an insight into the potential extent of exclusion due to fingerprint authentication. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Thirdly, authentication was possible only in the case of 93.5 per cent of residents with a single finger at the first attempt itself (see figure). In other words, in the case of about 6.5 per cent of residents (translating to 7.8 crore residents, when applied to 120 crore) authentication was not possible at the first attempt with a single finger. Even when three attempts were allowed, only 96.5 per cent of residents were able to be authenticated. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> In India, even a small share of exclusion from authentication can imply the actual exclusion of crores of individuals. Further, when applied to larger populations, the share of residents without one best finger is likely to rise sharply. At 120 crore people, it is impossible to forecast what this share would explode into. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> Contrary to the claims of the UIDAI, fingerprints will be a highly inappropriate tool to uniquely identify individuals. Given multiple errors during enrolment and the potentially high error rates at authentication, the use of fingerprint authentication is likely to foster a regime of misidentification and exclusion. Worse still, exclusion will be most acute among poor manual labourers. The poor record of fingerprint readers in U.K. airports and frequent fingerprint mismatches in the U.S. were also a result of fallibilities in the fingerprint technology. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> The elderly is another group that would be massively excluded. As the PoC reports admit, those above 60 years had the “highest rejection rates” at authentication. Yet, the Mid-Term Review of the Eleventh Plan by the Planning Commission has recommended the use of Aadhaar fingerprints to pay pension to the elderly through the National Social Assistance Programme (NSAP). The recommendation is to use “banking correspondents”, who would carry handheld fingerprint devices, to make “payments at the doorstep”. A sure recipe for exclusion, it would appear. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> In fact, the only group that appears certain to gain from the Aadhaar project is the global biometric industry. As Nandan Nilekani suggested in an interview, “the Unique Identification Project is creating new opportunities for biometric technology…. Our success can, therefore, determine the course the industry will take, since these technologies will be tested in India on an unprecedented scale.” On the other hand, the losses are likely to be felt mostly by the poor. It would be an irony that a project that is marketed in the name of “including the poor” would end up excluding them massively from whatever meagre provisions they obtain from the state today. </div> <div style="text-align: justify"> <br /> </div> <div style="text-align: justify"> <em>R. Ramakumar is Associate Professor at the Tata Institute of Social Sciences, Mumbai.</em> </div>', 'credit_writer' => 'Frontline, Volume 29, Issue 13, 30 June-13 July, 2012, http://www.frontline.in/stories/20120713291303400.htm', 'article_img' => '', 'article_img_thumb' => '', 'status' => (int) 1, 'show_on_home' => (int) 1, 'lang' => 'EN', 'category_id' => (int) 16, 'tag_keyword' => '', 'seo_url' => 'a-tale-of-errors-r-ramakumar-16029', 'meta_title' => null, 'meta_keywords' => null, 'meta_description' => null, 'noindex' => (int) 0, 'publish_date' => object(Cake\I18n\FrozenDate) {}, 'most_visit_section_id' => null, 'article_big_img' => null, 'liveid' => (int) 16029, 'created' => object(Cake\I18n\FrozenTime) {}, 'modified' => object(Cake\I18n\FrozenTime) {}, 'edate' => '', 'tags' => [ (int) 0 => object(Cake\ORM\Entity) {}, (int) 1 => object(Cake\ORM\Entity) {}, (int) 2 => object(Cake\ORM\Entity) {} ], 'category' => object(App\Model\Entity\Category) {}, '[new]' => false, '[accessible]' => [ '*' => true, 'id' => false ], '[dirty]' => [], '[original]' => [], '[virtual]' => [], '[hasErrors]' => false, '[errors]' => [], '[invalid]' => [], '[repository]' => 'Articles' } $articleid = (int) 15902 $metaTitle = 'LATEST NEWS UPDATES | A tale of errors-R Ramakumar' $metaKeywords = 'aadhaar,uid,ICTs' $metaDesc = ' Contrary to the claims of the UIDAI, fingerprints are a highly inappropriate tool to uniquely identify individuals. Case 1: “There are nine checks on visa nationals arriving into the U.K. [United Kingdom]. The fingerprint matching check is the most recent. It...' $disp = '<div style="text-align: justify"><br /></div><div style="text-align: justify"><em>Contrary to the claims of the UIDAI, fingerprints are a highly inappropriate tool to uniquely identify individuals.</em></div><div style="text-align: justify"><br /></div><div style="text-align: justify">Case 1: “There are nine checks on visa nationals arriving into the U.K. [United Kingdom]. The fingerprint matching check is the most recent. It is the least reliable. It is the least effective in terms of delivering against our requirements….”</div><div style="text-align: justify"><br /></div><div style="text-align: justify">So stated Brodie Clark, the former head of the United Kingdom Border Force, to a stunned Home Affairs Committee on November 15, 2011. Clark was giving oral evidence to the committee on why he had authorised the suspension of fingerprint checks during busy hours at U.K. airports. Pressed further, Clark said, “I knew of it, and I approved it because it was a very sensible thing.”</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Case 2: “The FBI [Federal Bureau of Investigation] apologises to Mr Mayfield and his family for the hardships that this matter has caused.”</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The FBI’s apology came in a public statement, dated May 24, 2004. Brandon Mayfield was an attorney in Oregon and a Muslim convert who was held as a material witness in the Madrid bombing of March 11, 2004. The Spanish police had located a latent fingerprint on a bag that contained explosives and sent it to the FBI. The FBI shortlisted potential matches from its fingerprint database. Two fingerprint experts, one internal and another external, concluded that the latent fingerprint belonged to Mayfield; one expert termed the match as “100% identification”. Mayfield was jailed on the basis of the fingerprint match. Two weeks later, the Spanish police informed the FBI that they had independently matched the latent print with Ouhnane Daoud, an Algerian national living in Spain.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The FBI’s fingerprint gaffe on Mayfield was not the first in the U.S. A few years earlier, Stephen Cowans had to serve a jail sentence of more than six years in Boston on the basis of a false fingerprint match. He was exonerated on the basis of DNA evidence.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">For years, the infallibility of fingerprints as a mark of uniqueness has been some sort of a fairy tale. But with increasing cases of fingerprint mismatches leading to human rights violations like prison detentions, the confidence is waning. Indeed, it was such loss of confidence that contributed to the shelving of national identity projects in the U.K. and many other countries.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">If the confidence is waning globally, in India there appears to be a deeply intriguing faith in the use of fingerprints in establishing unique identity for a population of 120 crore. The Aadhaar project is a classic example. Biometrics – particularly fingerprints – is a central feature of the Aadhaar project. That a Parliamentary Standing Committee had torn apart the robustness of the fingerprint technology – calling it “untested and unreliable” – is dismissed by the government. While time will indeed prove this faith misplaced, some immediate respect for the sceptical voice appears to be long overdue.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The entry of biometrics into Aadhaar is characteristic of how governments evade laws and misrepresent expert opinion to insert untested ideas into policy. In 2009 itself, the Biometric Standards Committee (BSC) of the Unique Identification Authority of India (UIDAI) was circumspect about using fingerprints in Aadhaar. It had stated that “retaining efficacy while scaling the database size… to a billion has not been adequately analysed”. The BSC also stated that “fingerprint quality, the most important variable for determining de-duplication accuracy, has not been studied in depth in the Indian context”. The reason: a large share of the population is dependent on hard manual labour, leading to worn-out fingerprints. This was an early note of caution, which the UIDAI ignored.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Even the BSC had failed to list out the problems of fingerprints comprehensively. For instance, the BSC was silent on the issue of “template ageing”, that is, an increase in “false rejection rates” as people age and sensor characteristics of fingerprint devices change. According to Kevin Bowyer of the University of Notre Dame, physical ageing of fingers results in decreased suppleness of the skin, more wrinkles, lesser flexibility of joints, and accumulated cuts and scars, all of which change the fingerprint itself. This implies the need to re-enrol a large proportion of people almost annually, making the system vulnerable to fraud.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">There was another note of caution on fingerprints, which too was ignored. A report from 4G Identity Solutions, a supplier and consultant for the UIDAI, had mentioned in 2009 itself that about 15 per cent of the Indian population may fail to enrol because of unreadable fingerprints. It specifically noted that “people above 60 years and young children below 12 years may have difficulty enrolling in a fingerprinting system”.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">On iris scans, the BSC was even more circumspect. It did not even provide error estimates for iris scans owing to the “absence of empirical Indian data”. It suggested the use of iris scans only “if they [UIDAI] feel it is required”. This stance of the BSC did not dissuade the UIDAI from deciding to scan irises too at enrolment. In fact, in a clear case of fudge, UIDAI Chairman Nandan Nilekani stated in an interview to PlanetBiometrics (July 5, 2010) that the BSC had “ recommended the inclusion of iris to the biometric modalities”. This was wrong; the BSC never made such a recommendation.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">It is becoming increasingly clear that the decision to include biometrics in Aadhaar had no scientific basis and flew in the face of available evidence (see “How Reliable is UID?”, Frontline, November 19, 2011). Recent evidence suggests that the chickens are indeed coming home to roost.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Biometrics appears at two stages in the Aadhaar project. The first stage is “enrolment”, where three sets of biometrics are collected from each resident: a photograph, fingerprints of all 10 fingers and iris scans of both eyes. The fingerprints and iris scans are used to uniquely identify (or “de-duplicate”) each resident and allot a unique Aadhaar number. The second stage is “authentication”; here, a service would be provided to residents only upon confirmation that his/her fingerprint “matches” the fingerprint stored against his/her name in the enrolment database. Iris scans are not used at the stage of authentication.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">I shall try to argue here that at both the stages – enrolment and authentication – the quantum of errors associated with biometrics is too large to be ignored.</div><div style="text-align: justify"><br /></div><div style="text-align: justify"><em>Errors in enrolment</em></div><div style="text-align: justify"><br /></div><div style="text-align: justify">Let us first take enrolment. Facts emerging from the ground reveal that there have been widespread errors at this stage and that biometrics has been of little help.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">First, in Hyderabad, a data entry supervisor by the name of Mohammed Ali – a former employee of the Infrastructure Leasing and Financial Services Limited (IL&FS) – was shown to have enrolled more than 30,000 residents in a short span of three months. According to reports, all the 30,000 applicants had been issued Aadhaar numbers. There were two interesting aspects with respect to biometrics in this scam.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">(a) Out of the 30,000 residents enrolled, about 870 people were enrolled as physically disabled (“biometric exceptions” in the UIDAI parlance). Their biometric information was not recorded. It is unclear as to how many of these 870 were actually disabled because most of their addresses were fake. It is also unclear as to how many thousands of such fake enrolments have already taken place across India.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">(b) A large proportion of the 30,000 residents enrolled were not enrolled by Ali (because Ali had left IL&FS in between). Instead, these enrolments were done across 17 enrolment centres by other supervisors who used Ali’s login and password. While logging into the system, along with the login and password, supervisors have to submit their fingerprints. Typically, if the supervisor’s fingerprints were not matched as Ali’s, the system should have rejected access. Yet, all the supervisors could gain access to the system using their fingerprints. Clearly, the system was not able to identify the supplied fingerprints as not Ali’s.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Secondly, in what has been the most hilarious Aadhaar number provision to date, one Aadhaar number (4991-1866-5246) was issued in Anantapur district of Andhra Pradesh to a person named Mr Kothimeera (that is, coriander), with his father’s name as Mr Palav (biryani) and address as Gongura Tota, Mamidikaya Vooru (Mango village), Jambuladinne, Anantapur, Andhra Pradesh - 515731. To top it, the date of birth of Mr Kothimeera was recorded as 1887, and the photograph on the card was that of a mobile phone. It is as yet unclear as to what biometric records were supplied with “Mr Kothimeera’s” demographic details and how it passed the test of biometric de-duplication.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Thirdly, the Department of Posts is on record that across India, as on April 20, 6.46 lakh Aadhaar letters posted were returned because the addresses did not exist. In Andhra Pradesh itself, about 50,000 Aadhaar letters were lying undelivered because the addresses were fake. In Karwar, Ankola, Kumta, Honnavar and Bhatkal taluks of Karnataka, about 7,000 Aadhaar letters were lying undelivered because the addresses were fake. While fake addresses have nothing to do with biometrics per se, they provide corroborative evidence to the widespread fraud that takes place at enrolment.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In sum, biometrics has not been able to prevent large-scale errors at the enrolment stage itself. Available evidence itself is persuasive, and it may be logically suspected that unreported errors are of a far larger magnitude.</div><div style="text-align: justify"><br /></div><div style="text-align: justify"><em>Errors in authentication</em></div><div style="text-align: justify"><br /></div><div style="text-align: justify">Interestingly, while three sets of biometrics are collected at the time of enrolment, only one set – fingerprints – is used for authentication. As R.S. Sharma, the Mission Director of the UIDAI, confirmed in an interview to Frontline in 2011, “fingerprint is the basic mode of authentication”. According to Nandan Nilekani, iris scans are not used at authentication because “it’s not a mature technology”. For the moment, we shall postpone asking the reasons for tweaking expert opinion and deciding to use an immature technology at the stage of enrolment.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In his Frontline interview, Sharma admitted that the “quality of fingerprints… poses a challenge for later authentication”. He also stated that “for manual labourers, this authentication will be difficult because only one or two of the 10 fingerprints may be good”. It would appear that Sharma was foretelling what the UIDAI’s Proof of Concept (PoC) studies published in 2012 were to reveal. The PoC studies reveal that fingerprint-based authentication of large populations is largely a non-starter, and point towards enormous risks of exclusion.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The PoC studies were internal studies on small populations conducted by the UIDAI to test the robustness of real-time, fingerprint-based authentication. There was no external review. In Phase 1, a small sample of 14,220 residents was studied in Tumkur district of Karnataka. In Phase 2, about 35,000 Aadhaar holders were covered across four States.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">First, the results confirm the fear that most people in rural areas have unreadable fingerprints. There was also significant variation of quality across the fingerprints of each individual. However, the UIDAI does not admit this in as many words. Instead, the PoC report says: “Certain fingers were observed to provide better authentication accuracy due to good fingerprint ridges and hence better image quality.” Further, it says that “providing multiple attempts of the same finger was seen to improve resident’s chances of successful authentication”. Finally, “senior residents (60+) had the highest rejection rates”; age-wise rejection rates, however, are not provided.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Let us paraphrase the above three results: (a) only some fingers of residents showed best authentication accuracy; (b) even when fingerprint quality was good, authentication was not always successful at the first try; and (c) residents above the age of 60 years showed poor authentication accuracy.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Secondly, to bypass the pervasive problem of poor fingerprint quality, the PoC study defines a “best finger”. It is the finger that “provides the highest chance of successful authentication”. The idea of a “best finger” is a cop-out from the real problem of poor fingerprint quality. Only 93.6 per cent of the residents possessed at least one best finger. Thus, for 6.4 per cent of the residents authentication was not possible with a single finger. In absolute terms, when extrapolated to the population of 120 crore, a 6.4 per cent share translates to 7.2 crore persons. While the use of more than one finger improves authentication accuracy, the figure of 93.6 per cent provides an insight into the potential extent of exclusion due to fingerprint authentication.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Thirdly, authentication was possible only in the case of 93.5 per cent of residents with a single finger at the first attempt itself (see figure). In other words, in the case of about 6.5 per cent of residents (translating to 7.8 crore residents, when applied to 120 crore) authentication was not possible at the first attempt with a single finger. Even when three attempts were allowed, only 96.5 per cent of residents were able to be authenticated.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In India, even a small share of exclusion from authentication can imply the actual exclusion of crores of individuals. Further, when applied to larger populations, the share of residents without one best finger is likely to rise sharply. At 120 crore people, it is impossible to forecast what this share would explode into.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">Contrary to the claims of the UIDAI, fingerprints will be a highly inappropriate tool to uniquely identify individuals. Given multiple errors during enrolment and the potentially high error rates at authentication, the use of fingerprint authentication is likely to foster a regime of misidentification and exclusion. Worse still, exclusion will be most acute among poor manual labourers. The poor record of fingerprint readers in U.K. airports and frequent fingerprint mismatches in the U.S. were also a result of fallibilities in the fingerprint technology.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">The elderly is another group that would be massively excluded. As the PoC reports admit, those above 60 years had the “highest rejection rates” at authentication. Yet, the Mid-Term Review of the Eleventh Plan by the Planning Commission has recommended the use of Aadhaar fingerprints to pay pension to the elderly through the National Social Assistance Programme (NSAP). The recommendation is to use “banking correspondents”, who would carry handheld fingerprint devices, to make “payments at the doorstep”. A sure recipe for exclusion, it would appear.</div><div style="text-align: justify"><br /></div><div style="text-align: justify">In fact, the only group that appears certain to gain from the Aadhaar project is the global biometric industry. As Nandan Nilekani suggested in an interview, “the Unique Identification Project is creating new opportunities for biometric technology…. Our success can, therefore, determine the course the industry will take, since these technologies will be tested in India on an unprecedented scale.” On the other hand, the losses are likely to be felt mostly by the poor. It would be an irony that a project that is marketed in the name of “including the poor” would end up excluding them massively from whatever meagre provisions they obtain from the state today.</div><div style="text-align: justify"><br /></div><div style="text-align: justify"><em>R. Ramakumar is Associate Professor at the Tata Institute of Social Sciences, Mumbai.</em></div>' $lang = 'English' $SITE_URL = 'https://im4change.in/' $site_title = 'im4change' $adminprix = 'admin'
include - APP/Template/Layout/printlayout.ctp, line 8 Cake\View\View::_evaluate() - CORE/src/View/View.php, line 1413 Cake\View\View::_render() - CORE/src/View/View.php, line 1374 Cake\View\View::renderLayout() - CORE/src/View/View.php, line 927 Cake\View\View::render() - CORE/src/View/View.php, line 885 Cake\Controller\Controller::render() - CORE/src/Controller/Controller.php, line 791 Cake\Http\ActionDispatcher::_invoke() - CORE/src/Http/ActionDispatcher.php, line 126 Cake\Http\ActionDispatcher::dispatch() - CORE/src/Http/ActionDispatcher.php, line 94 Cake\Http\BaseApplication::__invoke() - CORE/src/Http/BaseApplication.php, line 235 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Routing\Middleware\RoutingMiddleware::__invoke() - CORE/src/Routing/Middleware/RoutingMiddleware.php, line 162 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Routing\Middleware\AssetMiddleware::__invoke() - CORE/src/Routing/Middleware/AssetMiddleware.php, line 88 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Error\Middleware\ErrorHandlerMiddleware::__invoke() - CORE/src/Error/Middleware/ErrorHandlerMiddleware.php, line 96 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Http\Runner::run() - CORE/src/Http/Runner.php, line 51
![]() |
A tale of errors-R Ramakumar |
Contrary to the claims of the UIDAI, fingerprints are a highly inappropriate tool to uniquely identify individuals. Case 1: “There are nine checks on visa nationals arriving into the U.K. [United Kingdom]. The fingerprint matching check is the most recent. It is the least reliable. It is the least effective in terms of delivering against our requirements….” So stated Brodie Clark, the former head of the United Kingdom Border Force, to a stunned Home Affairs Committee on November 15, 2011. Clark was giving oral evidence to the committee on why he had authorised the suspension of fingerprint checks during busy hours at U.K. airports. Pressed further, Clark said, “I knew of it, and I approved it because it was a very sensible thing.” Case 2: “The FBI [Federal Bureau of Investigation] apologises to Mr Mayfield and his family for the hardships that this matter has caused.” The FBI’s apology came in a public statement, dated May 24, 2004. Brandon Mayfield was an attorney in Oregon and a Muslim convert who was held as a material witness in the Madrid bombing of March 11, 2004. The Spanish police had located a latent fingerprint on a bag that contained explosives and sent it to the FBI. The FBI shortlisted potential matches from its fingerprint database. Two fingerprint experts, one internal and another external, concluded that the latent fingerprint belonged to Mayfield; one expert termed the match as “100% identification”. Mayfield was jailed on the basis of the fingerprint match. Two weeks later, the Spanish police informed the FBI that they had independently matched the latent print with Ouhnane Daoud, an Algerian national living in Spain. The FBI’s fingerprint gaffe on Mayfield was not the first in the U.S. A few years earlier, Stephen Cowans had to serve a jail sentence of more than six years in Boston on the basis of a false fingerprint match. He was exonerated on the basis of DNA evidence. For years, the infallibility of fingerprints as a mark of uniqueness has been some sort of a fairy tale. But with increasing cases of fingerprint mismatches leading to human rights violations like prison detentions, the confidence is waning. Indeed, it was such loss of confidence that contributed to the shelving of national identity projects in the U.K. and many other countries. If the confidence is waning globally, in India there appears to be a deeply intriguing faith in the use of fingerprints in establishing unique identity for a population of 120 crore. The Aadhaar project is a classic example. Biometrics – particularly fingerprints – is a central feature of the Aadhaar project. That a Parliamentary Standing Committee had torn apart the robustness of the fingerprint technology – calling it “untested and unreliable” – is dismissed by the government. While time will indeed prove this faith misplaced, some immediate respect for the sceptical voice appears to be long overdue. The entry of biometrics into Aadhaar is characteristic of how governments evade laws and misrepresent expert opinion to insert untested ideas into policy. In 2009 itself, the Biometric Standards Committee (BSC) of the Unique Identification Authority of India (UIDAI) was circumspect about using fingerprints in Aadhaar. It had stated that “retaining efficacy while scaling the database size… to a billion has not been adequately analysed”. The BSC also stated that “fingerprint quality, the most important variable for determining de-duplication accuracy, has not been studied in depth in the Indian context”. The reason: a large share of the population is dependent on hard manual labour, leading to worn-out fingerprints. This was an early note of caution, which the UIDAI ignored. Even the BSC had failed to list out the problems of fingerprints comprehensively. For instance, the BSC was silent on the issue of “template ageing”, that is, an increase in “false rejection rates” as people age and sensor characteristics of fingerprint devices change. According to Kevin Bowyer of the University of Notre Dame, physical ageing of fingers results in decreased suppleness of the skin, more wrinkles, lesser flexibility of joints, and accumulated cuts and scars, all of which change the fingerprint itself. This implies the need to re-enrol a large proportion of people almost annually, making the system vulnerable to fraud. There was another note of caution on fingerprints, which too was ignored. A report from 4G Identity Solutions, a supplier and consultant for the UIDAI, had mentioned in 2009 itself that about 15 per cent of the Indian population may fail to enrol because of unreadable fingerprints. It specifically noted that “people above 60 years and young children below 12 years may have difficulty enrolling in a fingerprinting system”. On iris scans, the BSC was even more circumspect. It did not even provide error estimates for iris scans owing to the “absence of empirical Indian data”. It suggested the use of iris scans only “if they [UIDAI] feel it is required”. This stance of the BSC did not dissuade the UIDAI from deciding to scan irises too at enrolment. In fact, in a clear case of fudge, UIDAI Chairman Nandan Nilekani stated in an interview to PlanetBiometrics (July 5, 2010) that the BSC had “ recommended the inclusion of iris to the biometric modalities”. This was wrong; the BSC never made such a recommendation. It is becoming increasingly clear that the decision to include biometrics in Aadhaar had no scientific basis and flew in the face of available evidence (see “How Reliable is UID?”, Frontline, November 19, 2011). Recent evidence suggests that the chickens are indeed coming home to roost. Biometrics appears at two stages in the Aadhaar project. The first stage is “enrolment”, where three sets of biometrics are collected from each resident: a photograph, fingerprints of all 10 fingers and iris scans of both eyes. The fingerprints and iris scans are used to uniquely identify (or “de-duplicate”) each resident and allot a unique Aadhaar number. The second stage is “authentication”; here, a service would be provided to residents only upon confirmation that his/her fingerprint “matches” the fingerprint stored against his/her name in the enrolment database. Iris scans are not used at the stage of authentication. I shall try to argue here that at both the stages – enrolment and authentication – the quantum of errors associated with biometrics is too large to be ignored. Errors in enrolment Let us first take enrolment. Facts emerging from the ground reveal that there have been widespread errors at this stage and that biometrics has been of little help. First, in Hyderabad, a data entry supervisor by the name of Mohammed Ali – a former employee of the Infrastructure Leasing and Financial Services Limited (IL&FS) – was shown to have enrolled more than 30,000 residents in a short span of three months. According to reports, all the 30,000 applicants had been issued Aadhaar numbers. There were two interesting aspects with respect to biometrics in this scam. (a) Out of the 30,000 residents enrolled, about 870 people were enrolled as physically disabled (“biometric exceptions” in the UIDAI parlance). Their biometric information was not recorded. It is unclear as to how many of these 870 were actually disabled because most of their addresses were fake. It is also unclear as to how many thousands of such fake enrolments have already taken place across India. (b) A large proportion of the 30,000 residents enrolled were not enrolled by Ali (because Ali had left IL&FS in between). Instead, these enrolments were done across 17 enrolment centres by other supervisors who used Ali’s login and password. While logging into the system, along with the login and password, supervisors have to submit their fingerprints. Typically, if the supervisor’s fingerprints were not matched as Ali’s, the system should have rejected access. Yet, all the supervisors could gain access to the system using their fingerprints. Clearly, the system was not able to identify the supplied fingerprints as not Ali’s. Secondly, in what has been the most hilarious Aadhaar number provision to date, one Aadhaar number (4991-1866-5246) was issued in Anantapur district of Andhra Pradesh to a person named Mr Kothimeera (that is, coriander), with his father’s name as Mr Palav (biryani) and address as Gongura Tota, Mamidikaya Vooru (Mango village), Jambuladinne, Anantapur, Andhra Pradesh - 515731. To top it, the date of birth of Mr Kothimeera was recorded as 1887, and the photograph on the card was that of a mobile phone. It is as yet unclear as to what biometric records were supplied with “Mr Kothimeera’s” demographic details and how it passed the test of biometric de-duplication. Thirdly, the Department of Posts is on record that across India, as on April 20, 6.46 lakh Aadhaar letters posted were returned because the addresses did not exist. In Andhra Pradesh itself, about 50,000 Aadhaar letters were lying undelivered because the addresses were fake. In Karwar, Ankola, Kumta, Honnavar and Bhatkal taluks of Karnataka, about 7,000 Aadhaar letters were lying undelivered because the addresses were fake. While fake addresses have nothing to do with biometrics per se, they provide corroborative evidence to the widespread fraud that takes place at enrolment. In sum, biometrics has not been able to prevent large-scale errors at the enrolment stage itself. Available evidence itself is persuasive, and it may be logically suspected that unreported errors are of a far larger magnitude. Errors in authentication Interestingly, while three sets of biometrics are collected at the time of enrolment, only one set – fingerprints – is used for authentication. As R.S. Sharma, the Mission Director of the UIDAI, confirmed in an interview to Frontline in 2011, “fingerprint is the basic mode of authentication”. According to Nandan Nilekani, iris scans are not used at authentication because “it’s not a mature technology”. For the moment, we shall postpone asking the reasons for tweaking expert opinion and deciding to use an immature technology at the stage of enrolment. In his Frontline interview, Sharma admitted that the “quality of fingerprints… poses a challenge for later authentication”. He also stated that “for manual labourers, this authentication will be difficult because only one or two of the 10 fingerprints may be good”. It would appear that Sharma was foretelling what the UIDAI’s Proof of Concept (PoC) studies published in 2012 were to reveal. The PoC studies reveal that fingerprint-based authentication of large populations is largely a non-starter, and point towards enormous risks of exclusion. The PoC studies were internal studies on small populations conducted by the UIDAI to test the robustness of real-time, fingerprint-based authentication. There was no external review. In Phase 1, a small sample of 14,220 residents was studied in Tumkur district of Karnataka. In Phase 2, about 35,000 Aadhaar holders were covered across four States. First, the results confirm the fear that most people in rural areas have unreadable fingerprints. There was also significant variation of quality across the fingerprints of each individual. However, the UIDAI does not admit this in as many words. Instead, the PoC report says: “Certain fingers were observed to provide better authentication accuracy due to good fingerprint ridges and hence better image quality.” Further, it says that “providing multiple attempts of the same finger was seen to improve resident’s chances of successful authentication”. Finally, “senior residents (60+) had the highest rejection rates”; age-wise rejection rates, however, are not provided. Let us paraphrase the above three results: (a) only some fingers of residents showed best authentication accuracy; (b) even when fingerprint quality was good, authentication was not always successful at the first try; and (c) residents above the age of 60 years showed poor authentication accuracy. Secondly, to bypass the pervasive problem of poor fingerprint quality, the PoC study defines a “best finger”. It is the finger that “provides the highest chance of successful authentication”. The idea of a “best finger” is a cop-out from the real problem of poor fingerprint quality. Only 93.6 per cent of the residents possessed at least one best finger. Thus, for 6.4 per cent of the residents authentication was not possible with a single finger. In absolute terms, when extrapolated to the population of 120 crore, a 6.4 per cent share translates to 7.2 crore persons. While the use of more than one finger improves authentication accuracy, the figure of 93.6 per cent provides an insight into the potential extent of exclusion due to fingerprint authentication. Thirdly, authentication was possible only in the case of 93.5 per cent of residents with a single finger at the first attempt itself (see figure). In other words, in the case of about 6.5 per cent of residents (translating to 7.8 crore residents, when applied to 120 crore) authentication was not possible at the first attempt with a single finger. Even when three attempts were allowed, only 96.5 per cent of residents were able to be authenticated. In India, even a small share of exclusion from authentication can imply the actual exclusion of crores of individuals. Further, when applied to larger populations, the share of residents without one best finger is likely to rise sharply. At 120 crore people, it is impossible to forecast what this share would explode into. Contrary to the claims of the UIDAI, fingerprints will be a highly inappropriate tool to uniquely identify individuals. Given multiple errors during enrolment and the potentially high error rates at authentication, the use of fingerprint authentication is likely to foster a regime of misidentification and exclusion. Worse still, exclusion will be most acute among poor manual labourers. The poor record of fingerprint readers in U.K. airports and frequent fingerprint mismatches in the U.S. were also a result of fallibilities in the fingerprint technology. The elderly is another group that would be massively excluded. As the PoC reports admit, those above 60 years had the “highest rejection rates” at authentication. Yet, the Mid-Term Review of the Eleventh Plan by the Planning Commission has recommended the use of Aadhaar fingerprints to pay pension to the elderly through the National Social Assistance Programme (NSAP). The recommendation is to use “banking correspondents”, who would carry handheld fingerprint devices, to make “payments at the doorstep”. A sure recipe for exclusion, it would appear. In fact, the only group that appears certain to gain from the Aadhaar project is the global biometric industry. As Nandan Nilekani suggested in an interview, “the Unique Identification Project is creating new opportunities for biometric technology…. Our success can, therefore, determine the course the industry will take, since these technologies will be tested in India on an unprecedented scale.” On the other hand, the losses are likely to be felt mostly by the poor. It would be an irony that a project that is marketed in the name of “including the poor” would end up excluding them massively from whatever meagre provisions they obtain from the state today. R. Ramakumar is Associate Professor at the Tata Institute of Social Sciences, Mumbai.
|