Deprecated (16384): The ArrayAccess methods will be removed in 4.0.0.Use getParam(), getData() and getQuery() instead. - /home/brlfuser/public_html/src/Controller/ArtileDetailController.php, line: 73 You can disable deprecation warnings by setting `Error.errorLevel` to `E_ALL & ~E_USER_DEPRECATED` in your config/app.php. [CORE/src/Core/functions.php, line 311]Code Context
trigger_error($message, E_USER_DEPRECATED);
}
$message = 'The ArrayAccess methods will be removed in 4.0.0.Use getParam(), getData() and getQuery() instead. - /home/brlfuser/public_html/src/Controller/ArtileDetailController.php, line: 73 You can disable deprecation warnings by setting `Error.errorLevel` to `E_ALL & ~E_USER_DEPRECATED` in your config/app.php.' $stackFrame = (int) 1 $trace = [ (int) 0 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/ServerRequest.php', 'line' => (int) 2421, 'function' => 'deprecationWarning', 'args' => [ (int) 0 => 'The ArrayAccess methods will be removed in 4.0.0.Use getParam(), getData() and getQuery() instead.' ] ], (int) 1 => [ 'file' => '/home/brlfuser/public_html/src/Controller/ArtileDetailController.php', 'line' => (int) 73, 'function' => 'offsetGet', 'class' => 'Cake\Http\ServerRequest', 'object' => object(Cake\Http\ServerRequest) {}, 'type' => '->', 'args' => [ (int) 0 => 'catslug' ] ], (int) 2 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Controller/Controller.php', 'line' => (int) 610, 'function' => 'printArticle', 'class' => 'App\Controller\ArtileDetailController', 'object' => object(App\Controller\ArtileDetailController) {}, 'type' => '->', 'args' => [] ], (int) 3 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/ActionDispatcher.php', 'line' => (int) 120, 'function' => 'invokeAction', 'class' => 'Cake\Controller\Controller', 'object' => object(App\Controller\ArtileDetailController) {}, 'type' => '->', 'args' => [] ], (int) 4 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/ActionDispatcher.php', 'line' => (int) 94, 'function' => '_invoke', 'class' => 'Cake\Http\ActionDispatcher', 'object' => object(Cake\Http\ActionDispatcher) {}, 'type' => '->', 'args' => [ (int) 0 => object(App\Controller\ArtileDetailController) {} ] ], (int) 5 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/BaseApplication.php', 'line' => (int) 235, 'function' => 'dispatch', 'class' => 'Cake\Http\ActionDispatcher', 'object' => object(Cake\Http\ActionDispatcher) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {} ] ], (int) 6 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/Runner.php', 'line' => (int) 65, 'function' => '__invoke', 'class' => 'Cake\Http\BaseApplication', 'object' => object(App\Application) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {}, (int) 2 => object(Cake\Http\Runner) {} ] ], (int) 7 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Routing/Middleware/RoutingMiddleware.php', 'line' => (int) 162, 'function' => '__invoke', 'class' => 'Cake\Http\Runner', 'object' => object(Cake\Http\Runner) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {} ] ], (int) 8 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/Runner.php', 'line' => (int) 65, 'function' => '__invoke', 'class' => 'Cake\Routing\Middleware\RoutingMiddleware', 'object' => object(Cake\Routing\Middleware\RoutingMiddleware) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {}, (int) 2 => object(Cake\Http\Runner) {} ] ], (int) 9 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Routing/Middleware/AssetMiddleware.php', 'line' => (int) 88, 'function' => '__invoke', 'class' => 'Cake\Http\Runner', 'object' => object(Cake\Http\Runner) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {} ] ], (int) 10 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/Runner.php', 'line' => (int) 65, 'function' => '__invoke', 'class' => 'Cake\Routing\Middleware\AssetMiddleware', 'object' => object(Cake\Routing\Middleware\AssetMiddleware) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {}, (int) 2 => object(Cake\Http\Runner) {} ] ], (int) 11 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Error/Middleware/ErrorHandlerMiddleware.php', 'line' => (int) 96, 'function' => '__invoke', 'class' => 'Cake\Http\Runner', 'object' => object(Cake\Http\Runner) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {} ] ], (int) 12 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/Runner.php', 'line' => (int) 65, 'function' => '__invoke', 'class' => 'Cake\Error\Middleware\ErrorHandlerMiddleware', 'object' => object(Cake\Error\Middleware\ErrorHandlerMiddleware) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {}, (int) 2 => object(Cake\Http\Runner) {} ] ], (int) 13 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/Runner.php', 'line' => (int) 51, 'function' => '__invoke', 'class' => 'Cake\Http\Runner', 'object' => object(Cake\Http\Runner) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {} ] ], (int) 14 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/Server.php', 'line' => (int) 98, 'function' => 'run', 'class' => 'Cake\Http\Runner', 'object' => object(Cake\Http\Runner) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\MiddlewareQueue) {}, (int) 1 => object(Cake\Http\ServerRequest) {}, (int) 2 => object(Cake\Http\Response) {} ] ], (int) 15 => [ 'file' => '/home/brlfuser/public_html/webroot/index.php', 'line' => (int) 39, 'function' => 'run', 'class' => 'Cake\Http\Server', 'object' => object(Cake\Http\Server) {}, 'type' => '->', 'args' => [] ] ] $frame = [ 'file' => '/home/brlfuser/public_html/src/Controller/ArtileDetailController.php', 'line' => (int) 73, 'function' => 'offsetGet', 'class' => 'Cake\Http\ServerRequest', 'object' => object(Cake\Http\ServerRequest) { trustProxy => false [protected] params => [ [maximum depth reached] ] [protected] data => [[maximum depth reached]] [protected] query => [[maximum depth reached]] [protected] cookies => [ [maximum depth reached] ] [protected] _environment => [ [maximum depth reached] ] [protected] url => 'latest-news-updates/updating-aadhaar-for-better-privacy-rahul-tongia-4678955/print' [protected] base => '' [protected] webroot => '/' [protected] here => '/latest-news-updates/updating-aadhaar-for-better-privacy-rahul-tongia-4678955/print' [protected] trustedProxies => [[maximum depth reached]] [protected] _input => null [protected] _detectors => [ [maximum depth reached] ] [protected] _detectorCache => [ [maximum depth reached] ] [protected] stream => object(Zend\Diactoros\PhpInputStream) {} [protected] uri => object(Zend\Diactoros\Uri) {} [protected] session => object(Cake\Http\Session) {} [protected] attributes => [[maximum depth reached]] [protected] emulatedAttributes => [ [maximum depth reached] ] [protected] uploadedFiles => [[maximum depth reached]] [protected] protocol => null [protected] requestTarget => null [private] deprecatedProperties => [ [maximum depth reached] ] }, 'type' => '->', 'args' => [ (int) 0 => 'catslug' ] ]deprecationWarning - CORE/src/Core/functions.php, line 311 Cake\Http\ServerRequest::offsetGet() - CORE/src/Http/ServerRequest.php, line 2421 App\Controller\ArtileDetailController::printArticle() - APP/Controller/ArtileDetailController.php, line 73 Cake\Controller\Controller::invokeAction() - CORE/src/Controller/Controller.php, line 610 Cake\Http\ActionDispatcher::_invoke() - CORE/src/Http/ActionDispatcher.php, line 120 Cake\Http\ActionDispatcher::dispatch() - CORE/src/Http/ActionDispatcher.php, line 94 Cake\Http\BaseApplication::__invoke() - CORE/src/Http/BaseApplication.php, line 235 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Routing\Middleware\RoutingMiddleware::__invoke() - CORE/src/Routing/Middleware/RoutingMiddleware.php, line 162 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Routing\Middleware\AssetMiddleware::__invoke() - CORE/src/Routing/Middleware/AssetMiddleware.php, line 88 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Error\Middleware\ErrorHandlerMiddleware::__invoke() - CORE/src/Error/Middleware/ErrorHandlerMiddleware.php, line 96 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Http\Runner::run() - CORE/src/Http/Runner.php, line 51 Cake\Http\Server::run() - CORE/src/Http/Server.php, line 98
Deprecated (16384): The ArrayAccess methods will be removed in 4.0.0.Use getParam(), getData() and getQuery() instead. - /home/brlfuser/public_html/src/Controller/ArtileDetailController.php, line: 74 You can disable deprecation warnings by setting `Error.errorLevel` to `E_ALL & ~E_USER_DEPRECATED` in your config/app.php. [CORE/src/Core/functions.php, line 311]Code Context
trigger_error($message, E_USER_DEPRECATED);
}
$message = 'The ArrayAccess methods will be removed in 4.0.0.Use getParam(), getData() and getQuery() instead. - /home/brlfuser/public_html/src/Controller/ArtileDetailController.php, line: 74 You can disable deprecation warnings by setting `Error.errorLevel` to `E_ALL & ~E_USER_DEPRECATED` in your config/app.php.' $stackFrame = (int) 1 $trace = [ (int) 0 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/ServerRequest.php', 'line' => (int) 2421, 'function' => 'deprecationWarning', 'args' => [ (int) 0 => 'The ArrayAccess methods will be removed in 4.0.0.Use getParam(), getData() and getQuery() instead.' ] ], (int) 1 => [ 'file' => '/home/brlfuser/public_html/src/Controller/ArtileDetailController.php', 'line' => (int) 74, 'function' => 'offsetGet', 'class' => 'Cake\Http\ServerRequest', 'object' => object(Cake\Http\ServerRequest) {}, 'type' => '->', 'args' => [ (int) 0 => 'artileslug' ] ], (int) 2 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Controller/Controller.php', 'line' => (int) 610, 'function' => 'printArticle', 'class' => 'App\Controller\ArtileDetailController', 'object' => object(App\Controller\ArtileDetailController) {}, 'type' => '->', 'args' => [] ], (int) 3 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/ActionDispatcher.php', 'line' => (int) 120, 'function' => 'invokeAction', 'class' => 'Cake\Controller\Controller', 'object' => object(App\Controller\ArtileDetailController) {}, 'type' => '->', 'args' => [] ], (int) 4 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/ActionDispatcher.php', 'line' => (int) 94, 'function' => '_invoke', 'class' => 'Cake\Http\ActionDispatcher', 'object' => object(Cake\Http\ActionDispatcher) {}, 'type' => '->', 'args' => [ (int) 0 => object(App\Controller\ArtileDetailController) {} ] ], (int) 5 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/BaseApplication.php', 'line' => (int) 235, 'function' => 'dispatch', 'class' => 'Cake\Http\ActionDispatcher', 'object' => object(Cake\Http\ActionDispatcher) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {} ] ], (int) 6 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/Runner.php', 'line' => (int) 65, 'function' => '__invoke', 'class' => 'Cake\Http\BaseApplication', 'object' => object(App\Application) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {}, (int) 2 => object(Cake\Http\Runner) {} ] ], (int) 7 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Routing/Middleware/RoutingMiddleware.php', 'line' => (int) 162, 'function' => '__invoke', 'class' => 'Cake\Http\Runner', 'object' => object(Cake\Http\Runner) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {} ] ], (int) 8 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/Runner.php', 'line' => (int) 65, 'function' => '__invoke', 'class' => 'Cake\Routing\Middleware\RoutingMiddleware', 'object' => object(Cake\Routing\Middleware\RoutingMiddleware) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {}, (int) 2 => object(Cake\Http\Runner) {} ] ], (int) 9 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Routing/Middleware/AssetMiddleware.php', 'line' => (int) 88, 'function' => '__invoke', 'class' => 'Cake\Http\Runner', 'object' => object(Cake\Http\Runner) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {} ] ], (int) 10 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/Runner.php', 'line' => (int) 65, 'function' => '__invoke', 'class' => 'Cake\Routing\Middleware\AssetMiddleware', 'object' => object(Cake\Routing\Middleware\AssetMiddleware) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {}, (int) 2 => object(Cake\Http\Runner) {} ] ], (int) 11 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Error/Middleware/ErrorHandlerMiddleware.php', 'line' => (int) 96, 'function' => '__invoke', 'class' => 'Cake\Http\Runner', 'object' => object(Cake\Http\Runner) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {} ] ], (int) 12 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/Runner.php', 'line' => (int) 65, 'function' => '__invoke', 'class' => 'Cake\Error\Middleware\ErrorHandlerMiddleware', 'object' => object(Cake\Error\Middleware\ErrorHandlerMiddleware) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {}, (int) 2 => object(Cake\Http\Runner) {} ] ], (int) 13 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/Runner.php', 'line' => (int) 51, 'function' => '__invoke', 'class' => 'Cake\Http\Runner', 'object' => object(Cake\Http\Runner) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\ServerRequest) {}, (int) 1 => object(Cake\Http\Response) {} ] ], (int) 14 => [ 'file' => '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Http/Server.php', 'line' => (int) 98, 'function' => 'run', 'class' => 'Cake\Http\Runner', 'object' => object(Cake\Http\Runner) {}, 'type' => '->', 'args' => [ (int) 0 => object(Cake\Http\MiddlewareQueue) {}, (int) 1 => object(Cake\Http\ServerRequest) {}, (int) 2 => object(Cake\Http\Response) {} ] ], (int) 15 => [ 'file' => '/home/brlfuser/public_html/webroot/index.php', 'line' => (int) 39, 'function' => 'run', 'class' => 'Cake\Http\Server', 'object' => object(Cake\Http\Server) {}, 'type' => '->', 'args' => [] ] ] $frame = [ 'file' => '/home/brlfuser/public_html/src/Controller/ArtileDetailController.php', 'line' => (int) 74, 'function' => 'offsetGet', 'class' => 'Cake\Http\ServerRequest', 'object' => object(Cake\Http\ServerRequest) { trustProxy => false [protected] params => [ [maximum depth reached] ] [protected] data => [[maximum depth reached]] [protected] query => [[maximum depth reached]] [protected] cookies => [ [maximum depth reached] ] [protected] _environment => [ [maximum depth reached] ] [protected] url => 'latest-news-updates/updating-aadhaar-for-better-privacy-rahul-tongia-4678955/print' [protected] base => '' [protected] webroot => '/' [protected] here => '/latest-news-updates/updating-aadhaar-for-better-privacy-rahul-tongia-4678955/print' [protected] trustedProxies => [[maximum depth reached]] [protected] _input => null [protected] _detectors => [ [maximum depth reached] ] [protected] _detectorCache => [ [maximum depth reached] ] [protected] stream => object(Zend\Diactoros\PhpInputStream) {} [protected] uri => object(Zend\Diactoros\Uri) {} [protected] session => object(Cake\Http\Session) {} [protected] attributes => [[maximum depth reached]] [protected] emulatedAttributes => [ [maximum depth reached] ] [protected] uploadedFiles => [[maximum depth reached]] [protected] protocol => null [protected] requestTarget => null [private] deprecatedProperties => [ [maximum depth reached] ] }, 'type' => '->', 'args' => [ (int) 0 => 'artileslug' ] ]deprecationWarning - CORE/src/Core/functions.php, line 311 Cake\Http\ServerRequest::offsetGet() - CORE/src/Http/ServerRequest.php, line 2421 App\Controller\ArtileDetailController::printArticle() - APP/Controller/ArtileDetailController.php, line 74 Cake\Controller\Controller::invokeAction() - CORE/src/Controller/Controller.php, line 610 Cake\Http\ActionDispatcher::_invoke() - CORE/src/Http/ActionDispatcher.php, line 120 Cake\Http\ActionDispatcher::dispatch() - CORE/src/Http/ActionDispatcher.php, line 94 Cake\Http\BaseApplication::__invoke() - CORE/src/Http/BaseApplication.php, line 235 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Routing\Middleware\RoutingMiddleware::__invoke() - CORE/src/Routing/Middleware/RoutingMiddleware.php, line 162 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Routing\Middleware\AssetMiddleware::__invoke() - CORE/src/Routing/Middleware/AssetMiddleware.php, line 88 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Error\Middleware\ErrorHandlerMiddleware::__invoke() - CORE/src/Error/Middleware/ErrorHandlerMiddleware.php, line 96 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Http\Runner::run() - CORE/src/Http/Runner.php, line 51 Cake\Http\Server::run() - CORE/src/Http/Server.php, line 98
Warning (512): Unable to emit headers. Headers sent in file=/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Error/Debugger.php line=853 [CORE/src/Http/ResponseEmitter.php, line 48]Code Contextif (Configure::read('debug')) {
trigger_error($message, E_USER_WARNING);
} else {
$response = object(Cake\Http\Response) { 'status' => (int) 200, 'contentType' => 'text/html', 'headers' => [ 'Content-Type' => [ [maximum depth reached] ] ], 'file' => null, 'fileRange' => [], 'cookies' => object(Cake\Http\Cookie\CookieCollection) {}, 'cacheDirectives' => [], 'body' => '<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <link rel="canonical" href="https://im4change.in/<pre class="cake-error"><a href="javascript:void(0);" onclick="document.getElementById('cakeErr67ef453bce406-trace').style.display = (document.getElementById('cakeErr67ef453bce406-trace').style.display == 'none' ? '' : 'none');"><b>Notice</b> (8)</a>: Undefined variable: urlPrefix [<b>APP/Template/Layout/printlayout.ctp</b>, line <b>8</b>]<div id="cakeErr67ef453bce406-trace" class="cake-stack-trace" style="display: none;"><a href="javascript:void(0);" onclick="document.getElementById('cakeErr67ef453bce406-code').style.display = (document.getElementById('cakeErr67ef453bce406-code').style.display == 'none' ? '' : 'none')">Code</a> <a href="javascript:void(0);" onclick="document.getElementById('cakeErr67ef453bce406-context').style.display = (document.getElementById('cakeErr67ef453bce406-context').style.display == 'none' ? '' : 'none')">Context</a><pre id="cakeErr67ef453bce406-code" class="cake-code-dump" style="display: none;"><code><span style="color: #000000"><span style="color: #0000BB"></span><span style="color: #007700"><</span><span style="color: #0000BB">head</span><span style="color: #007700">> </span></span></code> <span class="code-highlight"><code><span style="color: #000000"> <link rel="canonical" href="<span style="color: #0000BB"><?php </span><span style="color: #007700">echo </span><span style="color: #0000BB">Configure</span><span style="color: #007700">::</span><span style="color: #0000BB">read</span><span style="color: #007700">(</span><span style="color: #DD0000">'SITE_URL'</span><span style="color: #007700">); </span><span style="color: #0000BB">?><?php </span><span style="color: #007700">echo </span><span style="color: #0000BB">$urlPrefix</span><span style="color: #007700">;</span><span style="color: #0000BB">?><?php </span><span style="color: #007700">echo </span><span style="color: #0000BB">$article_current</span><span style="color: #007700">-></span><span style="color: #0000BB">category</span><span style="color: #007700">-></span><span style="color: #0000BB">slug</span><span style="color: #007700">; </span><span style="color: #0000BB">?></span>/<span style="color: #0000BB"><?php </span><span style="color: #007700">echo </span><span style="color: #0000BB">$article_current</span><span style="color: #007700">-></span><span style="color: #0000BB">seo_url</span><span style="color: #007700">; </span><span style="color: #0000BB">?></span>.html"/> </span></code></span> <code><span style="color: #000000"><span style="color: #0000BB"> </span><span style="color: #007700"><</span><span style="color: #0000BB">meta http</span><span style="color: #007700">-</span><span style="color: #0000BB">equiv</span><span style="color: #007700">=</span><span style="color: #DD0000">"Content-Type" </span><span style="color: #0000BB">content</span><span style="color: #007700">=</span><span style="color: #DD0000">"text/html; charset=utf-8"</span><span style="color: #007700">/> </span></span></code></pre><pre id="cakeErr67ef453bce406-context" class="cake-context" style="display: none;">$viewFile = '/home/brlfuser/public_html/src/Template/Layout/printlayout.ctp' $dataForView = [ 'article_current' => object(App\Model\Entity\Article) { 'id' => (int) 30888, 'title' => 'Updating Aadhaar for better privacy -Rahul Tongia', 'subheading' => '', 'description' => '<div align="justify"> -The Hindu<br /> <br /> <em>Each authorised user of the system would get a longer number that is generated to be unique, but based on the base UID number.<br /> </em><br /> To its proponents, Unique Identification (UID, branded Aadhaar) is the solution to citizen empowerment. To its opponents, UID is a violation of not only citizen privacy but even citizen rights. In reality, like any programme or project, it can be anything we design it to be. It is only through purposeful design that we can ensure that risks and unintended consequences are kept under control. The government passed the Aadhaar Bill giving statutory rights for the programme, but this still leaves privacy as a specific challenge. However, this can be addressed.<br /> <br /> <em>Stated goal of UID<br /> </em><br /> Privacy with Aadhaar isn&rsquo;t just an abstract issue, but related to the fundamental view of how data are to be accessed and used. Leaders of the UID project stated in past discussions that privacy was not only paramount, but easily handled because the UID system would only be a yes or no identification system (relying, of course, on the accuracy of underlying registration). The system can be queried to verify if a person is who she claims to be based on the registration. Per design, the UID system would not know or care whether the person was Above Poverty Line or Below Poverty Line &mdash; such things would be the prerogative of the users of the system such as banks, service providers, or development schemes (here, users are not the citizens but system users like listed).<br /> <br /> At one level, this sounds appealing. But the problem is precisely the use of UID beyond the intended and appealing aspects, by its partners and systems providers. As Henry Wadsworth Longfellow wrote poetically if not prophetically, &ldquo;I shot an arrow into the air, It fell to earth I know not where.&rdquo; Instead of UID being agnostic to how the system gets used by others, UID&rsquo;s design should assume the worst, and try to prevent linking of databases by third parties, or unintended usage. Otherwise, these could lead to not only an abstract violation of privacy but also very specific and troubling asymmetries in commercial transactions and citizen empowerment/rights, including through profiling. We have already seen advertisements of private entities offering to use the Aadhaar database for commercial/private uses.<br /> <br /> Who has rights to the data? This needs clarity. The problem with rights to access is the possibility of unintended access. One thing we can learn from other large IT systems is that the boundary matters &mdash; just worrying about outsider hackers is wrong for IT systems since most IT security breaches involve an insider (and also mistakes). Similarly, UID&rsquo;s privacy cannot be viewed simply from an internal database and its security perspective but rather the ecosystem of users of UID. UID is only as secure as its weakest link. This is where segregation of data can help.<br /> <br /> We must ensure that the UID database is not used in a manner that can hurt the citizens either accidentally or through mission creep with unintended consequences. It&rsquo;s worth thinking about what could go wrong.<br /> <br /> <em>The solution <br /> </em><br /> What if we could have a UID that was never inter-linkable across users, but yet at the same time uniquely linked to the person through biometrics? The answer is we can, through the use of not a single UID, but a base UID (like we have today) plus modifications per user (if not per use). Instead of, say, MNREGA using the 12-digit number like today, each authorised user of the system (such as MNREGA, a bank, and so on) would get a modified (longer) number that is cryptographically generated to be unique but based on the base UID number in such a way that it could be proven to be functionally the same. Technologically, this would use a one-way hash that would be irreversible so that the longer number or code couldn&rsquo;t reveal the base UID number.<br /> <br /> The benefits of this would be twofold. First, a corporation or other user could not create a linked database for profiling &mdash; they would all have different UID+ numbers. Second, to even get the UID+, the cryptographic process could be restricted to authorised users. This way, we could prevent the UID becoming a casual identifier. For instance, in the U.S., the social security number morphs into something required by the cable TV operator when you raise a service complaint! Of course, in India we risk a similar link/identifier &mdash; our mobile number.<br /> <br /> This same concept of separation applies to security from an Indian government-citizen perspective. Given that Indian and global private technology companies are inevitably involved, breaking up the data (analogous to the UID versus UID+), where it&rsquo;s stored, broken up, and so on can improve security.<br /> <br /> <em>From UID to UID+<br /> </em><br /> One has to get the technology right for any programme, but its long-term success depends on people wanting it. Even if due to misinformation, perceptions matter. Recall how the U.S. nuclear power industry was effectively stalled even before the Three Mile Island accident due to a combination of secrecy, arrogance, and &ldquo;trust us&rdquo; instead of engagement and communication.<br /> <br /> The proposed update of UID to a UID+ system can address many of the concerns, and its roll-out need not be viewed as a failure of the original system but simply an update. The next step should be an analysis of how it can be done without disrupting the existing UID database(s).<br /> <br /> The good news is almost anything is feasible, computationally. We simply need to update our mindset of a Unique ID &mdash; there can be many such unique numbers, just like many people now have multiple and even disposable email addresses. There will be a small overhead for such designs, including one-time update costs for those who are already using the current UID number, but this is a worthwhile investment for something meant to last more than a citizen&rsquo;s lifetime.<br /> <em><br /> (Rahul Tongia is a Fellow at Brookings India, and Adjunct Professor at Carnegie Mellon University. All views are personal.)</em> </div>', 'credit_writer' => 'The Hindu, 28 March, 2016, http://www.thehindu.com/opinion/op-ed/updating-aadhaar-for-better-privacy/article8402375.ece?homepage=true', 'article_img' => '', 'article_img_thumb' => '', 'status' => (int) 1, 'show_on_home' => (int) 1, 'lang' => 'EN', 'category_id' => (int) 16, 'tag_keyword' => '', 'seo_url' => 'updating-aadhaar-for-better-privacy-rahul-tongia-4678955', 'meta_title' => null, 'meta_keywords' => null, 'meta_description' => null, 'noindex' => (int) 0, 'publish_date' => object(Cake\I18n\FrozenDate) {}, 'most_visit_section_id' => null, 'article_big_img' => null, 'liveid' => (int) 4678955, 'created' => object(Cake\I18n\FrozenTime) {}, 'modified' => object(Cake\I18n\FrozenTime) {}, 'edate' => '', 'tags' => [ [maximum depth reached] ], 'category' => object(App\Model\Entity\Category) {}, '[new]' => false, '[accessible]' => [ [maximum depth reached] ], '[dirty]' => [[maximum depth reached]], '[original]' => [[maximum depth reached]], '[virtual]' => [[maximum depth reached]], '[hasErrors]' => false, '[errors]' => [[maximum depth reached]], '[invalid]' => [[maximum depth reached]], '[repository]' => 'Articles' }, 'articleid' => (int) 30888, 'metaTitle' => 'LATEST NEWS UPDATES | Updating Aadhaar for better privacy -Rahul Tongia', 'metaKeywords' => 'Privacy,Privacy Rights,biometric identification system,Biometric information,UIDAI,uid,aadhaar,Aadhaar (Targeted Delivery of Financial and Other Subsidies Benefits and Services) Bill (2016),Aadhaar Bill', 'metaDesc' => ' -The Hindu Each authorised user of the system would get a longer number that is generated to be unique, but based on the base UID number. To its proponents, Unique Identification (UID, branded Aadhaar) is the solution to citizen empowerment. To its...', 'disp' => '<div align="justify">-The Hindu<br /><br /><em>Each authorised user of the system would get a longer number that is generated to be unique, but based on the base UID number.<br /></em><br />To its proponents, Unique Identification (UID, branded Aadhaar) is the solution to citizen empowerment. To its opponents, UID is a violation of not only citizen privacy but even citizen rights. In reality, like any programme or project, it can be anything we design it to be. It is only through purposeful design that we can ensure that risks and unintended consequences are kept under control. The government passed the Aadhaar Bill giving statutory rights for the programme, but this still leaves privacy as a specific challenge. However, this can be addressed.<br /><br /><em>Stated goal of UID<br /></em><br />Privacy with Aadhaar isn&rsquo;t just an abstract issue, but related to the fundamental view of how data are to be accessed and used. Leaders of the UID project stated in past discussions that privacy was not only paramount, but easily handled because the UID system would only be a yes or no identification system (relying, of course, on the accuracy of underlying registration). The system can be queried to verify if a person is who she claims to be based on the registration. Per design, the UID system would not know or care whether the person was Above Poverty Line or Below Poverty Line &mdash; such things would be the prerogative of the users of the system such as banks, service providers, or development schemes (here, users are not the citizens but system users like listed).<br /><br />At one level, this sounds appealing. But the problem is precisely the use of UID beyond the intended and appealing aspects, by its partners and systems providers. As Henry Wadsworth Longfellow wrote poetically if not prophetically, &ldquo;I shot an arrow into the air, It fell to earth I know not where.&rdquo; Instead of UID being agnostic to how the system gets used by others, UID&rsquo;s design should assume the worst, and try to prevent linking of databases by third parties, or unintended usage. Otherwise, these could lead to not only an abstract violation of privacy but also very specific and troubling asymmetries in commercial transactions and citizen empowerment/rights, including through profiling. We have already seen advertisements of private entities offering to use the Aadhaar database for commercial/private uses.<br /><br />Who has rights to the data? This needs clarity. The problem with rights to access is the possibility of unintended access. One thing we can learn from other large IT systems is that the boundary matters &mdash; just worrying about outsider hackers is wrong for IT systems since most IT security breaches involve an insider (and also mistakes). Similarly, UID&rsquo;s privacy cannot be viewed simply from an internal database and its security perspective but rather the ecosystem of users of UID. UID is only as secure as its weakest link. This is where segregation of data can help.<br /><br />We must ensure that the UID database is not used in a manner that can hurt the citizens either accidentally or through mission creep with unintended consequences. It&rsquo;s worth thinking about what could go wrong.<br /><br /><em>The solution <br /></em><br />What if we could have a UID that was never inter-linkable across users, but yet at the same time uniquely linked to the person through biometrics? The answer is we can, through the use of not a single UID, but a base UID (like we have today) plus modifications per user (if not per use). Instead of, say, MNREGA using the 12-digit number like today, each authorised user of the system (such as MNREGA, a bank, and so on) would get a modified (longer) number that is cryptographically generated to be unique but based on the base UID number in such a way that it could be proven to be functionally the same. Technologically, this would use a one-way hash that would be irreversible so that the longer number or code couldn&rsquo;t reveal the base UID number.<br /><br />The benefits of this would be twofold. First, a corporation or other user could not create a linked database for profiling &mdash; they would all have different UID+ numbers. Second, to even get the UID+, the cryptographic process could be restricted to authorised users. This way, we could prevent the UID becoming a casual identifier. For instance, in the U.S., the social security number morphs into something required by the cable TV operator when you raise a service complaint! Of course, in India we risk a similar link/identifier &mdash; our mobile number.<br /><br />This same concept of separation applies to security from an Indian government-citizen perspective. Given that Indian and global private technology companies are inevitably involved, breaking up the data (analogous to the UID versus UID+), where it&rsquo;s stored, broken up, and so on can improve security.<br /><br /><em>From UID to UID+<br /></em><br />One has to get the technology right for any programme, but its long-term success depends on people wanting it. Even if due to misinformation, perceptions matter. Recall how the U.S. nuclear power industry was effectively stalled even before the Three Mile Island accident due to a combination of secrecy, arrogance, and &ldquo;trust us&rdquo; instead of engagement and communication.<br /><br />The proposed update of UID to a UID+ system can address many of the concerns, and its roll-out need not be viewed as a failure of the original system but simply an update. The next step should be an analysis of how it can be done without disrupting the existing UID database(s).<br /><br />The good news is almost anything is feasible, computationally. We simply need to update our mindset of a Unique ID &mdash; there can be many such unique numbers, just like many people now have multiple and even disposable email addresses. There will be a small overhead for such designs, including one-time update costs for those who are already using the current UID number, but this is a worthwhile investment for something meant to last more than a citizen&rsquo;s lifetime.<br /><em><br />(Rahul Tongia is a Fellow at Brookings India, and Adjunct Professor at Carnegie Mellon University. All views are personal.)</em></div>', 'lang' => 'English', 'SITE_URL' => 'https://im4change.in/', 'site_title' => 'im4change', 'adminprix' => 'admin' ] $article_current = object(App\Model\Entity\Article) { 'id' => (int) 30888, 'title' => 'Updating Aadhaar for better privacy -Rahul Tongia', 'subheading' => '', 'description' => '<div align="justify"> -The Hindu<br /> <br /> <em>Each authorised user of the system would get a longer number that is generated to be unique, but based on the base UID number.<br /> </em><br /> To its proponents, Unique Identification (UID, branded Aadhaar) is the solution to citizen empowerment. To its opponents, UID is a violation of not only citizen privacy but even citizen rights. In reality, like any programme or project, it can be anything we design it to be. It is only through purposeful design that we can ensure that risks and unintended consequences are kept under control. The government passed the Aadhaar Bill giving statutory rights for the programme, but this still leaves privacy as a specific challenge. However, this can be addressed.<br /> <br /> <em>Stated goal of UID<br /> </em><br /> Privacy with Aadhaar isn&rsquo;t just an abstract issue, but related to the fundamental view of how data are to be accessed and used. Leaders of the UID project stated in past discussions that privacy was not only paramount, but easily handled because the UID system would only be a yes or no identification system (relying, of course, on the accuracy of underlying registration). The system can be queried to verify if a person is who she claims to be based on the registration. Per design, the UID system would not know or care whether the person was Above Poverty Line or Below Poverty Line &mdash; such things would be the prerogative of the users of the system such as banks, service providers, or development schemes (here, users are not the citizens but system users like listed).<br /> <br /> At one level, this sounds appealing. But the problem is precisely the use of UID beyond the intended and appealing aspects, by its partners and systems providers. As Henry Wadsworth Longfellow wrote poetically if not prophetically, &ldquo;I shot an arrow into the air, It fell to earth I know not where.&rdquo; Instead of UID being agnostic to how the system gets used by others, UID&rsquo;s design should assume the worst, and try to prevent linking of databases by third parties, or unintended usage. Otherwise, these could lead to not only an abstract violation of privacy but also very specific and troubling asymmetries in commercial transactions and citizen empowerment/rights, including through profiling. We have already seen advertisements of private entities offering to use the Aadhaar database for commercial/private uses.<br /> <br /> Who has rights to the data? This needs clarity. The problem with rights to access is the possibility of unintended access. One thing we can learn from other large IT systems is that the boundary matters &mdash; just worrying about outsider hackers is wrong for IT systems since most IT security breaches involve an insider (and also mistakes). Similarly, UID&rsquo;s privacy cannot be viewed simply from an internal database and its security perspective but rather the ecosystem of users of UID. UID is only as secure as its weakest link. This is where segregation of data can help.<br /> <br /> We must ensure that the UID database is not used in a manner that can hurt the citizens either accidentally or through mission creep with unintended consequences. It&rsquo;s worth thinking about what could go wrong.<br /> <br /> <em>The solution <br /> </em><br /> What if we could have a UID that was never inter-linkable across users, but yet at the same time uniquely linked to the person through biometrics? The answer is we can, through the use of not a single UID, but a base UID (like we have today) plus modifications per user (if not per use). Instead of, say, MNREGA using the 12-digit number like today, each authorised user of the system (such as MNREGA, a bank, and so on) would get a modified (longer) number that is cryptographically generated to be unique but based on the base UID number in such a way that it could be proven to be functionally the same. Technologically, this would use a one-way hash that would be irreversible so that the longer number or code couldn&rsquo;t reveal the base UID number.<br /> <br /> The benefits of this would be twofold. First, a corporation or other user could not create a linked database for profiling &mdash; they would all have different UID+ numbers. Second, to even get the UID+, the cryptographic process could be restricted to authorised users. This way, we could prevent the UID becoming a casual identifier. For instance, in the U.S., the social security number morphs into something required by the cable TV operator when you raise a service complaint! Of course, in India we risk a similar link/identifier &mdash; our mobile number.<br /> <br /> This same concept of separation applies to security from an Indian government-citizen perspective. Given that Indian and global private technology companies are inevitably involved, breaking up the data (analogous to the UID versus UID+), where it&rsquo;s stored, broken up, and so on can improve security.<br /> <br /> <em>From UID to UID+<br /> </em><br /> One has to get the technology right for any programme, but its long-term success depends on people wanting it. Even if due to misinformation, perceptions matter. Recall how the U.S. nuclear power industry was effectively stalled even before the Three Mile Island accident due to a combination of secrecy, arrogance, and &ldquo;trust us&rdquo; instead of engagement and communication.<br /> <br /> The proposed update of UID to a UID+ system can address many of the concerns, and its roll-out need not be viewed as a failure of the original system but simply an update. The next step should be an analysis of how it can be done without disrupting the existing UID database(s).<br /> <br /> The good news is almost anything is feasible, computationally. We simply need to update our mindset of a Unique ID &mdash; there can be many such unique numbers, just like many people now have multiple and even disposable email addresses. There will be a small overhead for such designs, including one-time update costs for those who are already using the current UID number, but this is a worthwhile investment for something meant to last more than a citizen&rsquo;s lifetime.<br /> <em><br /> (Rahul Tongia is a Fellow at Brookings India, and Adjunct Professor at Carnegie Mellon University. All views are personal.)</em> </div>', 'credit_writer' => 'The Hindu, 28 March, 2016, http://www.thehindu.com/opinion/op-ed/updating-aadhaar-for-better-privacy/article8402375.ece?homepage=true', 'article_img' => '', 'article_img_thumb' => '', 'status' => (int) 1, 'show_on_home' => (int) 1, 'lang' => 'EN', 'category_id' => (int) 16, 'tag_keyword' => '', 'seo_url' => 'updating-aadhaar-for-better-privacy-rahul-tongia-4678955', 'meta_title' => null, 'meta_keywords' => null, 'meta_description' => null, 'noindex' => (int) 0, 'publish_date' => object(Cake\I18n\FrozenDate) {}, 'most_visit_section_id' => null, 'article_big_img' => null, 'liveid' => (int) 4678955, 'created' => object(Cake\I18n\FrozenTime) {}, 'modified' => object(Cake\I18n\FrozenTime) {}, 'edate' => '', 'tags' => [ (int) 0 => object(Cake\ORM\Entity) {}, (int) 1 => object(Cake\ORM\Entity) {}, (int) 2 => object(Cake\ORM\Entity) {}, (int) 3 => object(Cake\ORM\Entity) {}, (int) 4 => object(Cake\ORM\Entity) {}, (int) 5 => object(Cake\ORM\Entity) {}, (int) 6 => object(Cake\ORM\Entity) {}, (int) 7 => object(Cake\ORM\Entity) {}, (int) 8 => object(Cake\ORM\Entity) {} ], 'category' => object(App\Model\Entity\Category) {}, '[new]' => false, '[accessible]' => [ '*' => true, 'id' => false ], '[dirty]' => [], '[original]' => [], '[virtual]' => [], '[hasErrors]' => false, '[errors]' => [], '[invalid]' => [], '[repository]' => 'Articles' } $articleid = (int) 30888 $metaTitle = 'LATEST NEWS UPDATES | Updating Aadhaar for better privacy -Rahul Tongia' $metaKeywords = 'Privacy,Privacy Rights,biometric identification system,Biometric information,UIDAI,uid,aadhaar,Aadhaar (Targeted Delivery of Financial and Other Subsidies Benefits and Services) Bill (2016),Aadhaar Bill' $metaDesc = ' -The Hindu Each authorised user of the system would get a longer number that is generated to be unique, but based on the base UID number. To its proponents, Unique Identification (UID, branded Aadhaar) is the solution to citizen empowerment. To its...' $disp = '<div align="justify">-The Hindu<br /><br /><em>Each authorised user of the system would get a longer number that is generated to be unique, but based on the base UID number.<br /></em><br />To its proponents, Unique Identification (UID, branded Aadhaar) is the solution to citizen empowerment. To its opponents, UID is a violation of not only citizen privacy but even citizen rights. In reality, like any programme or project, it can be anything we design it to be. It is only through purposeful design that we can ensure that risks and unintended consequences are kept under control. The government passed the Aadhaar Bill giving statutory rights for the programme, but this still leaves privacy as a specific challenge. However, this can be addressed.<br /><br /><em>Stated goal of UID<br /></em><br />Privacy with Aadhaar isn&rsquo;t just an abstract issue, but related to the fundamental view of how data are to be accessed and used. Leaders of the UID project stated in past discussions that privacy was not only paramount, but easily handled because the UID system would only be a yes or no identification system (relying, of course, on the accuracy of underlying registration). The system can be queried to verify if a person is who she claims to be based on the registration. Per design, the UID system would not know or care whether the person was Above Poverty Line or Below Poverty Line &mdash; such things would be the prerogative of the users of the system such as banks, service providers, or development schemes (here, users are not the citizens but system users like listed).<br /><br />At one level, this sounds appealing. But the problem is precisely the use of UID beyond the intended and appealing aspects, by its partners and systems providers. As Henry Wadsworth Longfellow wrote poetically if not prophetically, &ldquo;I shot an arrow into the air, It fell to earth I know not where.&rdquo; Instead of UID being agnostic to how the system gets used by others, UID&rsquo;s design should assume the worst, and try to prevent linking of databases by third parties, or unintended usage. Otherwise, these could lead to not only an abstract violation of privacy but also very specific and troubling asymmetries in commercial transactions and citizen empowerment/rights, including through profiling. We have already seen advertisements of private entities offering to use the Aadhaar database for commercial/private uses.<br /><br />Who has rights to the data? This needs clarity. The problem with rights to access is the possibility of unintended access. One thing we can learn from other large IT systems is that the boundary matters &mdash; just worrying about outsider hackers is wrong for IT systems since most IT security breaches involve an insider (and also mistakes). Similarly, UID&rsquo;s privacy cannot be viewed simply from an internal database and its security perspective but rather the ecosystem of users of UID. UID is only as secure as its weakest link. This is where segregation of data can help.<br /><br />We must ensure that the UID database is not used in a manner that can hurt the citizens either accidentally or through mission creep with unintended consequences. It&rsquo;s worth thinking about what could go wrong.<br /><br /><em>The solution <br /></em><br />What if we could have a UID that was never inter-linkable across users, but yet at the same time uniquely linked to the person through biometrics? The answer is we can, through the use of not a single UID, but a base UID (like we have today) plus modifications per user (if not per use). Instead of, say, MNREGA using the 12-digit number like today, each authorised user of the system (such as MNREGA, a bank, and so on) would get a modified (longer) number that is cryptographically generated to be unique but based on the base UID number in such a way that it could be proven to be functionally the same. Technologically, this would use a one-way hash that would be irreversible so that the longer number or code couldn&rsquo;t reveal the base UID number.<br /><br />The benefits of this would be twofold. First, a corporation or other user could not create a linked database for profiling &mdash; they would all have different UID+ numbers. Second, to even get the UID+, the cryptographic process could be restricted to authorised users. This way, we could prevent the UID becoming a casual identifier. For instance, in the U.S., the social security number morphs into something required by the cable TV operator when you raise a service complaint! Of course, in India we risk a similar link/identifier &mdash; our mobile number.<br /><br />This same concept of separation applies to security from an Indian government-citizen perspective. Given that Indian and global private technology companies are inevitably involved, breaking up the data (analogous to the UID versus UID+), where it&rsquo;s stored, broken up, and so on can improve security.<br /><br /><em>From UID to UID+<br /></em><br />One has to get the technology right for any programme, but its long-term success depends on people wanting it. Even if due to misinformation, perceptions matter. Recall how the U.S. nuclear power industry was effectively stalled even before the Three Mile Island accident due to a combination of secrecy, arrogance, and &ldquo;trust us&rdquo; instead of engagement and communication.<br /><br />The proposed update of UID to a UID+ system can address many of the concerns, and its roll-out need not be viewed as a failure of the original system but simply an update. The next step should be an analysis of how it can be done without disrupting the existing UID database(s).<br /><br />The good news is almost anything is feasible, computationally. We simply need to update our mindset of a Unique ID &mdash; there can be many such unique numbers, just like many people now have multiple and even disposable email addresses. There will be a small overhead for such designs, including one-time update costs for those who are already using the current UID number, but this is a worthwhile investment for something meant to last more than a citizen&rsquo;s lifetime.<br /><em><br />(Rahul Tongia is a Fellow at Brookings India, and Adjunct Professor at Carnegie Mellon University. All views are personal.)</em></div>' $lang = 'English' $SITE_URL = 'https://im4change.in/' $site_title = 'im4change' $adminprix = 'admin'</pre><pre class="stack-trace">include - APP/Template/Layout/printlayout.ctp, line 8 Cake\View\View::_evaluate() - CORE/src/View/View.php, line 1413 Cake\View\View::_render() - CORE/src/View/View.php, line 1374 Cake\View\View::renderLayout() - CORE/src/View/View.php, line 927 Cake\View\View::render() - CORE/src/View/View.php, line 885 Cake\Controller\Controller::render() - CORE/src/Controller/Controller.php, line 791 Cake\Http\ActionDispatcher::_invoke() - CORE/src/Http/ActionDispatcher.php, line 126 Cake\Http\ActionDispatcher::dispatch() - CORE/src/Http/ActionDispatcher.php, line 94 Cake\Http\BaseApplication::__invoke() - CORE/src/Http/BaseApplication.php, line 235 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Routing\Middleware\RoutingMiddleware::__invoke() - CORE/src/Routing/Middleware/RoutingMiddleware.php, line 162 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Routing\Middleware\AssetMiddleware::__invoke() - CORE/src/Routing/Middleware/AssetMiddleware.php, line 88 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Error\Middleware\ErrorHandlerMiddleware::__invoke() - CORE/src/Error/Middleware/ErrorHandlerMiddleware.php, line 96 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Http\Runner::run() - CORE/src/Http/Runner.php, line 51</pre></div></pre>latest-news-updates/updating-aadhaar-for-better-privacy-rahul-tongia-4678955.html"/> <meta http-equiv="Content-Type" content="text/html; charset=utf-8"/> <link href="https://im4change.in/css/control.css" rel="stylesheet" type="text/css" media="all"/> <title>LATEST NEWS UPDATES | Updating Aadhaar for better privacy -Rahul Tongia | Im4change.org</title> <meta name="description" content=" -The Hindu Each authorised user of the system would get a longer number that is generated to be unique, but based on the base UID number. To its proponents, Unique Identification (UID, branded Aadhaar) is the solution to citizen empowerment. To its..."/> <script src="https://im4change.in/js/jquery-1.10.2.js"></script> <script type="text/javascript" src="https://im4change.in/js/jquery-migrate.min.js"></script> <script language="javascript" type="text/javascript"> $(document).ready(function () { var img = $("img")[0]; // Get my img elem var pic_real_width, pic_real_height; $("<img/>") // Make in memory copy of image to avoid css issues .attr("src", $(img).attr("src")) .load(function () { pic_real_width = this.width; // Note: $(this).width() will not pic_real_height = this.height; // work for in memory images. }); }); </script> <style type="text/css"> @media screen { div.divFooter { display: block; } } @media print { .printbutton { display: none !important; } } </style> </head> <body> <table cellpadding="0" cellspacing="0" border="0" width="98%" align="center"> <tr> <td class="top_bg"> <div class="divFooter"> <img src="https://im4change.in/images/logo1.jpg" height="59" border="0" alt="Resource centre on India's rural distress" style="padding-top:14px;"/> </div> </td> </tr> <tr> <td id="topspace"> </td> </tr> <tr id="topspace"> <td> </td> </tr> <tr> <td height="50" style="border-bottom:1px solid #000; padding-top:10px;" class="printbutton"> <form><input type="button" value=" Print this page " onclick="window.print();return false;"/></form> </td> </tr> <tr> <td width="100%"> <h1 class="news_headlines" style="font-style:normal"> <strong>Updating Aadhaar for better privacy -Rahul Tongia</strong></h1> </td> </tr> <tr> <td width="100%" style="font-family:Arial, 'Segoe Script', 'Segoe UI', sans-serif, serif"><font size="3"> <div align="justify">-The Hindu<br /><br /><em>Each authorised user of the system would get a longer number that is generated to be unique, but based on the base UID number.<br /></em><br />To its proponents, Unique Identification (UID, branded Aadhaar) is the solution to citizen empowerment. To its opponents, UID is a violation of not only citizen privacy but even citizen rights. In reality, like any programme or project, it can be anything we design it to be. It is only through purposeful design that we can ensure that risks and unintended consequences are kept under control. The government passed the Aadhaar Bill giving statutory rights for the programme, but this still leaves privacy as a specific challenge. However, this can be addressed.<br /><br /><em>Stated goal of UID<br /></em><br />Privacy with Aadhaar isn’t just an abstract issue, but related to the fundamental view of how data are to be accessed and used. Leaders of the UID project stated in past discussions that privacy was not only paramount, but easily handled because the UID system would only be a yes or no identification system (relying, of course, on the accuracy of underlying registration). The system can be queried to verify if a person is who she claims to be based on the registration. Per design, the UID system would not know or care whether the person was Above Poverty Line or Below Poverty Line — such things would be the prerogative of the users of the system such as banks, service providers, or development schemes (here, users are not the citizens but system users like listed).<br /><br />At one level, this sounds appealing. But the problem is precisely the use of UID beyond the intended and appealing aspects, by its partners and systems providers. As Henry Wadsworth Longfellow wrote poetically if not prophetically, “I shot an arrow into the air, It fell to earth I know not where.” Instead of UID being agnostic to how the system gets used by others, UID’s design should assume the worst, and try to prevent linking of databases by third parties, or unintended usage. Otherwise, these could lead to not only an abstract violation of privacy but also very specific and troubling asymmetries in commercial transactions and citizen empowerment/rights, including through profiling. We have already seen advertisements of private entities offering to use the Aadhaar database for commercial/private uses.<br /><br />Who has rights to the data? This needs clarity. The problem with rights to access is the possibility of unintended access. One thing we can learn from other large IT systems is that the boundary matters — just worrying about outsider hackers is wrong for IT systems since most IT security breaches involve an insider (and also mistakes). Similarly, UID’s privacy cannot be viewed simply from an internal database and its security perspective but rather the ecosystem of users of UID. UID is only as secure as its weakest link. This is where segregation of data can help.<br /><br />We must ensure that the UID database is not used in a manner that can hurt the citizens either accidentally or through mission creep with unintended consequences. It’s worth thinking about what could go wrong.<br /><br /><em>The solution <br /></em><br />What if we could have a UID that was never inter-linkable across users, but yet at the same time uniquely linked to the person through biometrics? The answer is we can, through the use of not a single UID, but a base UID (like we have today) plus modifications per user (if not per use). Instead of, say, MNREGA using the 12-digit number like today, each authorised user of the system (such as MNREGA, a bank, and so on) would get a modified (longer) number that is cryptographically generated to be unique but based on the base UID number in such a way that it could be proven to be functionally the same. Technologically, this would use a one-way hash that would be irreversible so that the longer number or code couldn’t reveal the base UID number.<br /><br />The benefits of this would be twofold. First, a corporation or other user could not create a linked database for profiling — they would all have different UID+ numbers. Second, to even get the UID+, the cryptographic process could be restricted to authorised users. This way, we could prevent the UID becoming a casual identifier. For instance, in the U.S., the social security number morphs into something required by the cable TV operator when you raise a service complaint! Of course, in India we risk a similar link/identifier — our mobile number.<br /><br />This same concept of separation applies to security from an Indian government-citizen perspective. Given that Indian and global private technology companies are inevitably involved, breaking up the data (analogous to the UID versus UID+), where it’s stored, broken up, and so on can improve security.<br /><br /><em>From UID to UID+<br /></em><br />One has to get the technology right for any programme, but its long-term success depends on people wanting it. Even if due to misinformation, perceptions matter. Recall how the U.S. nuclear power industry was effectively stalled even before the Three Mile Island accident due to a combination of secrecy, arrogance, and “trust us” instead of engagement and communication.<br /><br />The proposed update of UID to a UID+ system can address many of the concerns, and its roll-out need not be viewed as a failure of the original system but simply an update. The next step should be an analysis of how it can be done without disrupting the existing UID database(s).<br /><br />The good news is almost anything is feasible, computationally. We simply need to update our mindset of a Unique ID — there can be many such unique numbers, just like many people now have multiple and even disposable email addresses. There will be a small overhead for such designs, including one-time update costs for those who are already using the current UID number, but this is a worthwhile investment for something meant to last more than a citizen’s lifetime.<br /><em><br />(Rahul Tongia is a Fellow at Brookings India, and Adjunct Professor at Carnegie Mellon University. All views are personal.)</em></div> </font> </td> </tr> <tr> <td> </td> </tr> <tr> <td height="50" style="border-top:1px solid #000; border-bottom:1px solid #000;padding-top:10px;"> <form><input type="button" value=" Print this page " onclick="window.print();return false;"/></form> </td> </tr> </table></body> </html>' } $maxBufferLength = (int) 8192 $file = '/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Error/Debugger.php' $line = (int) 853 $message = 'Unable to emit headers. Headers sent in file=/home/brlfuser/public_html/vendor/cakephp/cakephp/src/Error/Debugger.php line=853'Cake\Http\ResponseEmitter::emit() - CORE/src/Http/ResponseEmitter.php, line 48 Cake\Http\Server::emit() - CORE/src/Http/Server.php, line 141 [main] - ROOT/webroot/index.php, line 39
Warning (2): Cannot modify header information - headers already sent by (output started at /home/brlfuser/public_html/vendor/cakephp/cakephp/src/Error/Debugger.php:853) [CORE/src/Http/ResponseEmitter.php, line 148]Code Context$response->getStatusCode(),
($reasonPhrase ? ' ' . $reasonPhrase : '')
));
$response = object(Cake\Http\Response) { 'status' => (int) 200, 'contentType' => 'text/html', 'headers' => [ 'Content-Type' => [ [maximum depth reached] ] ], 'file' => null, 'fileRange' => [], 'cookies' => object(Cake\Http\Cookie\CookieCollection) {}, 'cacheDirectives' => [], 'body' => '<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <link rel="canonical" href="https://im4change.in/<pre class="cake-error"><a href="javascript:void(0);" onclick="document.getElementById('cakeErr67ef453bce406-trace').style.display = (document.getElementById('cakeErr67ef453bce406-trace').style.display == 'none' ? '' : 'none');"><b>Notice</b> (8)</a>: Undefined variable: urlPrefix [<b>APP/Template/Layout/printlayout.ctp</b>, line <b>8</b>]<div id="cakeErr67ef453bce406-trace" class="cake-stack-trace" style="display: none;"><a href="javascript:void(0);" onclick="document.getElementById('cakeErr67ef453bce406-code').style.display = (document.getElementById('cakeErr67ef453bce406-code').style.display == 'none' ? '' : 'none')">Code</a> <a href="javascript:void(0);" onclick="document.getElementById('cakeErr67ef453bce406-context').style.display = (document.getElementById('cakeErr67ef453bce406-context').style.display == 'none' ? '' : 'none')">Context</a><pre id="cakeErr67ef453bce406-code" class="cake-code-dump" style="display: none;"><code><span style="color: #000000"><span style="color: #0000BB"></span><span style="color: #007700"><</span><span style="color: #0000BB">head</span><span style="color: #007700">> </span></span></code> <span class="code-highlight"><code><span style="color: #000000"> <link rel="canonical" href="<span style="color: #0000BB"><?php </span><span style="color: #007700">echo </span><span style="color: #0000BB">Configure</span><span style="color: #007700">::</span><span style="color: #0000BB">read</span><span style="color: #007700">(</span><span style="color: #DD0000">'SITE_URL'</span><span style="color: #007700">); </span><span style="color: #0000BB">?><?php </span><span style="color: #007700">echo </span><span style="color: #0000BB">$urlPrefix</span><span style="color: #007700">;</span><span style="color: #0000BB">?><?php </span><span style="color: #007700">echo </span><span style="color: #0000BB">$article_current</span><span style="color: #007700">-></span><span style="color: #0000BB">category</span><span style="color: #007700">-></span><span style="color: #0000BB">slug</span><span style="color: #007700">; </span><span style="color: #0000BB">?></span>/<span style="color: #0000BB"><?php </span><span style="color: #007700">echo </span><span style="color: #0000BB">$article_current</span><span style="color: #007700">-></span><span style="color: #0000BB">seo_url</span><span style="color: #007700">; </span><span style="color: #0000BB">?></span>.html"/> </span></code></span> <code><span style="color: #000000"><span style="color: #0000BB"> </span><span style="color: #007700"><</span><span style="color: #0000BB">meta http</span><span style="color: #007700">-</span><span style="color: #0000BB">equiv</span><span style="color: #007700">=</span><span style="color: #DD0000">"Content-Type" </span><span style="color: #0000BB">content</span><span style="color: #007700">=</span><span style="color: #DD0000">"text/html; charset=utf-8"</span><span style="color: #007700">/> </span></span></code></pre><pre id="cakeErr67ef453bce406-context" class="cake-context" style="display: none;">$viewFile = '/home/brlfuser/public_html/src/Template/Layout/printlayout.ctp' $dataForView = [ 'article_current' => object(App\Model\Entity\Article) { 'id' => (int) 30888, 'title' => 'Updating Aadhaar for better privacy -Rahul Tongia', 'subheading' => '', 'description' => '<div align="justify"> -The Hindu<br /> <br /> <em>Each authorised user of the system would get a longer number that is generated to be unique, but based on the base UID number.<br /> </em><br /> To its proponents, Unique Identification (UID, branded Aadhaar) is the solution to citizen empowerment. To its opponents, UID is a violation of not only citizen privacy but even citizen rights. In reality, like any programme or project, it can be anything we design it to be. It is only through purposeful design that we can ensure that risks and unintended consequences are kept under control. The government passed the Aadhaar Bill giving statutory rights for the programme, but this still leaves privacy as a specific challenge. However, this can be addressed.<br /> <br /> <em>Stated goal of UID<br /> </em><br /> Privacy with Aadhaar isn&rsquo;t just an abstract issue, but related to the fundamental view of how data are to be accessed and used. Leaders of the UID project stated in past discussions that privacy was not only paramount, but easily handled because the UID system would only be a yes or no identification system (relying, of course, on the accuracy of underlying registration). The system can be queried to verify if a person is who she claims to be based on the registration. Per design, the UID system would not know or care whether the person was Above Poverty Line or Below Poverty Line &mdash; such things would be the prerogative of the users of the system such as banks, service providers, or development schemes (here, users are not the citizens but system users like listed).<br /> <br /> At one level, this sounds appealing. But the problem is precisely the use of UID beyond the intended and appealing aspects, by its partners and systems providers. As Henry Wadsworth Longfellow wrote poetically if not prophetically, &ldquo;I shot an arrow into the air, It fell to earth I know not where.&rdquo; Instead of UID being agnostic to how the system gets used by others, UID&rsquo;s design should assume the worst, and try to prevent linking of databases by third parties, or unintended usage. Otherwise, these could lead to not only an abstract violation of privacy but also very specific and troubling asymmetries in commercial transactions and citizen empowerment/rights, including through profiling. We have already seen advertisements of private entities offering to use the Aadhaar database for commercial/private uses.<br /> <br /> Who has rights to the data? This needs clarity. The problem with rights to access is the possibility of unintended access. One thing we can learn from other large IT systems is that the boundary matters &mdash; just worrying about outsider hackers is wrong for IT systems since most IT security breaches involve an insider (and also mistakes). Similarly, UID&rsquo;s privacy cannot be viewed simply from an internal database and its security perspective but rather the ecosystem of users of UID. UID is only as secure as its weakest link. This is where segregation of data can help.<br /> <br /> We must ensure that the UID database is not used in a manner that can hurt the citizens either accidentally or through mission creep with unintended consequences. It&rsquo;s worth thinking about what could go wrong.<br /> <br /> <em>The solution <br /> </em><br /> What if we could have a UID that was never inter-linkable across users, but yet at the same time uniquely linked to the person through biometrics? The answer is we can, through the use of not a single UID, but a base UID (like we have today) plus modifications per user (if not per use). Instead of, say, MNREGA using the 12-digit number like today, each authorised user of the system (such as MNREGA, a bank, and so on) would get a modified (longer) number that is cryptographically generated to be unique but based on the base UID number in such a way that it could be proven to be functionally the same. Technologically, this would use a one-way hash that would be irreversible so that the longer number or code couldn&rsquo;t reveal the base UID number.<br /> <br /> The benefits of this would be twofold. First, a corporation or other user could not create a linked database for profiling &mdash; they would all have different UID+ numbers. Second, to even get the UID+, the cryptographic process could be restricted to authorised users. This way, we could prevent the UID becoming a casual identifier. For instance, in the U.S., the social security number morphs into something required by the cable TV operator when you raise a service complaint! Of course, in India we risk a similar link/identifier &mdash; our mobile number.<br /> <br /> This same concept of separation applies to security from an Indian government-citizen perspective. Given that Indian and global private technology companies are inevitably involved, breaking up the data (analogous to the UID versus UID+), where it&rsquo;s stored, broken up, and so on can improve security.<br /> <br /> <em>From UID to UID+<br /> </em><br /> One has to get the technology right for any programme, but its long-term success depends on people wanting it. Even if due to misinformation, perceptions matter. Recall how the U.S. nuclear power industry was effectively stalled even before the Three Mile Island accident due to a combination of secrecy, arrogance, and &ldquo;trust us&rdquo; instead of engagement and communication.<br /> <br /> The proposed update of UID to a UID+ system can address many of the concerns, and its roll-out need not be viewed as a failure of the original system but simply an update. The next step should be an analysis of how it can be done without disrupting the existing UID database(s).<br /> <br /> The good news is almost anything is feasible, computationally. We simply need to update our mindset of a Unique ID &mdash; there can be many such unique numbers, just like many people now have multiple and even disposable email addresses. There will be a small overhead for such designs, including one-time update costs for those who are already using the current UID number, but this is a worthwhile investment for something meant to last more than a citizen&rsquo;s lifetime.<br /> <em><br /> (Rahul Tongia is a Fellow at Brookings India, and Adjunct Professor at Carnegie Mellon University. All views are personal.)</em> </div>', 'credit_writer' => 'The Hindu, 28 March, 2016, http://www.thehindu.com/opinion/op-ed/updating-aadhaar-for-better-privacy/article8402375.ece?homepage=true', 'article_img' => '', 'article_img_thumb' => '', 'status' => (int) 1, 'show_on_home' => (int) 1, 'lang' => 'EN', 'category_id' => (int) 16, 'tag_keyword' => '', 'seo_url' => 'updating-aadhaar-for-better-privacy-rahul-tongia-4678955', 'meta_title' => null, 'meta_keywords' => null, 'meta_description' => null, 'noindex' => (int) 0, 'publish_date' => object(Cake\I18n\FrozenDate) {}, 'most_visit_section_id' => null, 'article_big_img' => null, 'liveid' => (int) 4678955, 'created' => object(Cake\I18n\FrozenTime) {}, 'modified' => object(Cake\I18n\FrozenTime) {}, 'edate' => '', 'tags' => [ [maximum depth reached] ], 'category' => object(App\Model\Entity\Category) {}, '[new]' => false, '[accessible]' => [ [maximum depth reached] ], '[dirty]' => [[maximum depth reached]], '[original]' => [[maximum depth reached]], '[virtual]' => [[maximum depth reached]], '[hasErrors]' => false, '[errors]' => [[maximum depth reached]], '[invalid]' => [[maximum depth reached]], '[repository]' => 'Articles' }, 'articleid' => (int) 30888, 'metaTitle' => 'LATEST NEWS UPDATES | Updating Aadhaar for better privacy -Rahul Tongia', 'metaKeywords' => 'Privacy,Privacy Rights,biometric identification system,Biometric information,UIDAI,uid,aadhaar,Aadhaar (Targeted Delivery of Financial and Other Subsidies Benefits and Services) Bill (2016),Aadhaar Bill', 'metaDesc' => ' -The Hindu Each authorised user of the system would get a longer number that is generated to be unique, but based on the base UID number. To its proponents, Unique Identification (UID, branded Aadhaar) is the solution to citizen empowerment. To its...', 'disp' => '<div align="justify">-The Hindu<br /><br /><em>Each authorised user of the system would get a longer number that is generated to be unique, but based on the base UID number.<br /></em><br />To its proponents, Unique Identification (UID, branded Aadhaar) is the solution to citizen empowerment. To its opponents, UID is a violation of not only citizen privacy but even citizen rights. In reality, like any programme or project, it can be anything we design it to be. It is only through purposeful design that we can ensure that risks and unintended consequences are kept under control. The government passed the Aadhaar Bill giving statutory rights for the programme, but this still leaves privacy as a specific challenge. However, this can be addressed.<br /><br /><em>Stated goal of UID<br /></em><br />Privacy with Aadhaar isn&rsquo;t just an abstract issue, but related to the fundamental view of how data are to be accessed and used. Leaders of the UID project stated in past discussions that privacy was not only paramount, but easily handled because the UID system would only be a yes or no identification system (relying, of course, on the accuracy of underlying registration). The system can be queried to verify if a person is who she claims to be based on the registration. Per design, the UID system would not know or care whether the person was Above Poverty Line or Below Poverty Line &mdash; such things would be the prerogative of the users of the system such as banks, service providers, or development schemes (here, users are not the citizens but system users like listed).<br /><br />At one level, this sounds appealing. But the problem is precisely the use of UID beyond the intended and appealing aspects, by its partners and systems providers. As Henry Wadsworth Longfellow wrote poetically if not prophetically, &ldquo;I shot an arrow into the air, It fell to earth I know not where.&rdquo; Instead of UID being agnostic to how the system gets used by others, UID&rsquo;s design should assume the worst, and try to prevent linking of databases by third parties, or unintended usage. Otherwise, these could lead to not only an abstract violation of privacy but also very specific and troubling asymmetries in commercial transactions and citizen empowerment/rights, including through profiling. We have already seen advertisements of private entities offering to use the Aadhaar database for commercial/private uses.<br /><br />Who has rights to the data? This needs clarity. The problem with rights to access is the possibility of unintended access. One thing we can learn from other large IT systems is that the boundary matters &mdash; just worrying about outsider hackers is wrong for IT systems since most IT security breaches involve an insider (and also mistakes). Similarly, UID&rsquo;s privacy cannot be viewed simply from an internal database and its security perspective but rather the ecosystem of users of UID. UID is only as secure as its weakest link. This is where segregation of data can help.<br /><br />We must ensure that the UID database is not used in a manner that can hurt the citizens either accidentally or through mission creep with unintended consequences. It&rsquo;s worth thinking about what could go wrong.<br /><br /><em>The solution <br /></em><br />What if we could have a UID that was never inter-linkable across users, but yet at the same time uniquely linked to the person through biometrics? The answer is we can, through the use of not a single UID, but a base UID (like we have today) plus modifications per user (if not per use). Instead of, say, MNREGA using the 12-digit number like today, each authorised user of the system (such as MNREGA, a bank, and so on) would get a modified (longer) number that is cryptographically generated to be unique but based on the base UID number in such a way that it could be proven to be functionally the same. Technologically, this would use a one-way hash that would be irreversible so that the longer number or code couldn&rsquo;t reveal the base UID number.<br /><br />The benefits of this would be twofold. First, a corporation or other user could not create a linked database for profiling &mdash; they would all have different UID+ numbers. Second, to even get the UID+, the cryptographic process could be restricted to authorised users. This way, we could prevent the UID becoming a casual identifier. For instance, in the U.S., the social security number morphs into something required by the cable TV operator when you raise a service complaint! Of course, in India we risk a similar link/identifier &mdash; our mobile number.<br /><br />This same concept of separation applies to security from an Indian government-citizen perspective. Given that Indian and global private technology companies are inevitably involved, breaking up the data (analogous to the UID versus UID+), where it&rsquo;s stored, broken up, and so on can improve security.<br /><br /><em>From UID to UID+<br /></em><br />One has to get the technology right for any programme, but its long-term success depends on people wanting it. Even if due to misinformation, perceptions matter. Recall how the U.S. nuclear power industry was effectively stalled even before the Three Mile Island accident due to a combination of secrecy, arrogance, and &ldquo;trust us&rdquo; instead of engagement and communication.<br /><br />The proposed update of UID to a UID+ system can address many of the concerns, and its roll-out need not be viewed as a failure of the original system but simply an update. The next step should be an analysis of how it can be done without disrupting the existing UID database(s).<br /><br />The good news is almost anything is feasible, computationally. We simply need to update our mindset of a Unique ID &mdash; there can be many such unique numbers, just like many people now have multiple and even disposable email addresses. There will be a small overhead for such designs, including one-time update costs for those who are already using the current UID number, but this is a worthwhile investment for something meant to last more than a citizen&rsquo;s lifetime.<br /><em><br />(Rahul Tongia is a Fellow at Brookings India, and Adjunct Professor at Carnegie Mellon University. All views are personal.)</em></div>', 'lang' => 'English', 'SITE_URL' => 'https://im4change.in/', 'site_title' => 'im4change', 'adminprix' => 'admin' ] $article_current = object(App\Model\Entity\Article) { 'id' => (int) 30888, 'title' => 'Updating Aadhaar for better privacy -Rahul Tongia', 'subheading' => '', 'description' => '<div align="justify"> -The Hindu<br /> <br /> <em>Each authorised user of the system would get a longer number that is generated to be unique, but based on the base UID number.<br /> </em><br /> To its proponents, Unique Identification (UID, branded Aadhaar) is the solution to citizen empowerment. To its opponents, UID is a violation of not only citizen privacy but even citizen rights. In reality, like any programme or project, it can be anything we design it to be. It is only through purposeful design that we can ensure that risks and unintended consequences are kept under control. The government passed the Aadhaar Bill giving statutory rights for the programme, but this still leaves privacy as a specific challenge. However, this can be addressed.<br /> <br /> <em>Stated goal of UID<br /> </em><br /> Privacy with Aadhaar isn&rsquo;t just an abstract issue, but related to the fundamental view of how data are to be accessed and used. Leaders of the UID project stated in past discussions that privacy was not only paramount, but easily handled because the UID system would only be a yes or no identification system (relying, of course, on the accuracy of underlying registration). The system can be queried to verify if a person is who she claims to be based on the registration. Per design, the UID system would not know or care whether the person was Above Poverty Line or Below Poverty Line &mdash; such things would be the prerogative of the users of the system such as banks, service providers, or development schemes (here, users are not the citizens but system users like listed).<br /> <br /> At one level, this sounds appealing. But the problem is precisely the use of UID beyond the intended and appealing aspects, by its partners and systems providers. As Henry Wadsworth Longfellow wrote poetically if not prophetically, &ldquo;I shot an arrow into the air, It fell to earth I know not where.&rdquo; Instead of UID being agnostic to how the system gets used by others, UID&rsquo;s design should assume the worst, and try to prevent linking of databases by third parties, or unintended usage. Otherwise, these could lead to not only an abstract violation of privacy but also very specific and troubling asymmetries in commercial transactions and citizen empowerment/rights, including through profiling. We have already seen advertisements of private entities offering to use the Aadhaar database for commercial/private uses.<br /> <br /> Who has rights to the data? This needs clarity. The problem with rights to access is the possibility of unintended access. One thing we can learn from other large IT systems is that the boundary matters &mdash; just worrying about outsider hackers is wrong for IT systems since most IT security breaches involve an insider (and also mistakes). Similarly, UID&rsquo;s privacy cannot be viewed simply from an internal database and its security perspective but rather the ecosystem of users of UID. UID is only as secure as its weakest link. This is where segregation of data can help.<br /> <br /> We must ensure that the UID database is not used in a manner that can hurt the citizens either accidentally or through mission creep with unintended consequences. It&rsquo;s worth thinking about what could go wrong.<br /> <br /> <em>The solution <br /> </em><br /> What if we could have a UID that was never inter-linkable across users, but yet at the same time uniquely linked to the person through biometrics? The answer is we can, through the use of not a single UID, but a base UID (like we have today) plus modifications per user (if not per use). Instead of, say, MNREGA using the 12-digit number like today, each authorised user of the system (such as MNREGA, a bank, and so on) would get a modified (longer) number that is cryptographically generated to be unique but based on the base UID number in such a way that it could be proven to be functionally the same. Technologically, this would use a one-way hash that would be irreversible so that the longer number or code couldn&rsquo;t reveal the base UID number.<br /> <br /> The benefits of this would be twofold. First, a corporation or other user could not create a linked database for profiling &mdash; they would all have different UID+ numbers. Second, to even get the UID+, the cryptographic process could be restricted to authorised users. This way, we could prevent the UID becoming a casual identifier. For instance, in the U.S., the social security number morphs into something required by the cable TV operator when you raise a service complaint! Of course, in India we risk a similar link/identifier &mdash; our mobile number.<br /> <br /> This same concept of separation applies to security from an Indian government-citizen perspective. Given that Indian and global private technology companies are inevitably involved, breaking up the data (analogous to the UID versus UID+), where it&rsquo;s stored, broken up, and so on can improve security.<br /> <br /> <em>From UID to UID+<br /> </em><br /> One has to get the technology right for any programme, but its long-term success depends on people wanting it. Even if due to misinformation, perceptions matter. Recall how the U.S. nuclear power industry was effectively stalled even before the Three Mile Island accident due to a combination of secrecy, arrogance, and &ldquo;trust us&rdquo; instead of engagement and communication.<br /> <br /> The proposed update of UID to a UID+ system can address many of the concerns, and its roll-out need not be viewed as a failure of the original system but simply an update. The next step should be an analysis of how it can be done without disrupting the existing UID database(s).<br /> <br /> The good news is almost anything is feasible, computationally. We simply need to update our mindset of a Unique ID &mdash; there can be many such unique numbers, just like many people now have multiple and even disposable email addresses. There will be a small overhead for such designs, including one-time update costs for those who are already using the current UID number, but this is a worthwhile investment for something meant to last more than a citizen&rsquo;s lifetime.<br /> <em><br /> (Rahul Tongia is a Fellow at Brookings India, and Adjunct Professor at Carnegie Mellon University. All views are personal.)</em> </div>', 'credit_writer' => 'The Hindu, 28 March, 2016, http://www.thehindu.com/opinion/op-ed/updating-aadhaar-for-better-privacy/article8402375.ece?homepage=true', 'article_img' => '', 'article_img_thumb' => '', 'status' => (int) 1, 'show_on_home' => (int) 1, 'lang' => 'EN', 'category_id' => (int) 16, 'tag_keyword' => '', 'seo_url' => 'updating-aadhaar-for-better-privacy-rahul-tongia-4678955', 'meta_title' => null, 'meta_keywords' => null, 'meta_description' => null, 'noindex' => (int) 0, 'publish_date' => object(Cake\I18n\FrozenDate) {}, 'most_visit_section_id' => null, 'article_big_img' => null, 'liveid' => (int) 4678955, 'created' => object(Cake\I18n\FrozenTime) {}, 'modified' => object(Cake\I18n\FrozenTime) {}, 'edate' => '', 'tags' => [ (int) 0 => object(Cake\ORM\Entity) {}, (int) 1 => object(Cake\ORM\Entity) {}, (int) 2 => object(Cake\ORM\Entity) {}, (int) 3 => object(Cake\ORM\Entity) {}, (int) 4 => object(Cake\ORM\Entity) {}, (int) 5 => object(Cake\ORM\Entity) {}, (int) 6 => object(Cake\ORM\Entity) {}, (int) 7 => object(Cake\ORM\Entity) {}, (int) 8 => object(Cake\ORM\Entity) {} ], 'category' => object(App\Model\Entity\Category) {}, '[new]' => false, '[accessible]' => [ '*' => true, 'id' => false ], '[dirty]' => [], '[original]' => [], '[virtual]' => [], '[hasErrors]' => false, '[errors]' => [], '[invalid]' => [], '[repository]' => 'Articles' } $articleid = (int) 30888 $metaTitle = 'LATEST NEWS UPDATES | Updating Aadhaar for better privacy -Rahul Tongia' $metaKeywords = 'Privacy,Privacy Rights,biometric identification system,Biometric information,UIDAI,uid,aadhaar,Aadhaar (Targeted Delivery of Financial and Other Subsidies Benefits and Services) Bill (2016),Aadhaar Bill' $metaDesc = ' -The Hindu Each authorised user of the system would get a longer number that is generated to be unique, but based on the base UID number. To its proponents, Unique Identification (UID, branded Aadhaar) is the solution to citizen empowerment. To its...' $disp = '<div align="justify">-The Hindu<br /><br /><em>Each authorised user of the system would get a longer number that is generated to be unique, but based on the base UID number.<br /></em><br />To its proponents, Unique Identification (UID, branded Aadhaar) is the solution to citizen empowerment. To its opponents, UID is a violation of not only citizen privacy but even citizen rights. In reality, like any programme or project, it can be anything we design it to be. It is only through purposeful design that we can ensure that risks and unintended consequences are kept under control. The government passed the Aadhaar Bill giving statutory rights for the programme, but this still leaves privacy as a specific challenge. However, this can be addressed.<br /><br /><em>Stated goal of UID<br /></em><br />Privacy with Aadhaar isn&rsquo;t just an abstract issue, but related to the fundamental view of how data are to be accessed and used. Leaders of the UID project stated in past discussions that privacy was not only paramount, but easily handled because the UID system would only be a yes or no identification system (relying, of course, on the accuracy of underlying registration). The system can be queried to verify if a person is who she claims to be based on the registration. Per design, the UID system would not know or care whether the person was Above Poverty Line or Below Poverty Line &mdash; such things would be the prerogative of the users of the system such as banks, service providers, or development schemes (here, users are not the citizens but system users like listed).<br /><br />At one level, this sounds appealing. But the problem is precisely the use of UID beyond the intended and appealing aspects, by its partners and systems providers. As Henry Wadsworth Longfellow wrote poetically if not prophetically, &ldquo;I shot an arrow into the air, It fell to earth I know not where.&rdquo; Instead of UID being agnostic to how the system gets used by others, UID&rsquo;s design should assume the worst, and try to prevent linking of databases by third parties, or unintended usage. Otherwise, these could lead to not only an abstract violation of privacy but also very specific and troubling asymmetries in commercial transactions and citizen empowerment/rights, including through profiling. We have already seen advertisements of private entities offering to use the Aadhaar database for commercial/private uses.<br /><br />Who has rights to the data? This needs clarity. The problem with rights to access is the possibility of unintended access. One thing we can learn from other large IT systems is that the boundary matters &mdash; just worrying about outsider hackers is wrong for IT systems since most IT security breaches involve an insider (and also mistakes). Similarly, UID&rsquo;s privacy cannot be viewed simply from an internal database and its security perspective but rather the ecosystem of users of UID. UID is only as secure as its weakest link. This is where segregation of data can help.<br /><br />We must ensure that the UID database is not used in a manner that can hurt the citizens either accidentally or through mission creep with unintended consequences. It&rsquo;s worth thinking about what could go wrong.<br /><br /><em>The solution <br /></em><br />What if we could have a UID that was never inter-linkable across users, but yet at the same time uniquely linked to the person through biometrics? The answer is we can, through the use of not a single UID, but a base UID (like we have today) plus modifications per user (if not per use). Instead of, say, MNREGA using the 12-digit number like today, each authorised user of the system (such as MNREGA, a bank, and so on) would get a modified (longer) number that is cryptographically generated to be unique but based on the base UID number in such a way that it could be proven to be functionally the same. Technologically, this would use a one-way hash that would be irreversible so that the longer number or code couldn&rsquo;t reveal the base UID number.<br /><br />The benefits of this would be twofold. First, a corporation or other user could not create a linked database for profiling &mdash; they would all have different UID+ numbers. Second, to even get the UID+, the cryptographic process could be restricted to authorised users. This way, we could prevent the UID becoming a casual identifier. For instance, in the U.S., the social security number morphs into something required by the cable TV operator when you raise a service complaint! Of course, in India we risk a similar link/identifier &mdash; our mobile number.<br /><br />This same concept of separation applies to security from an Indian government-citizen perspective. Given that Indian and global private technology companies are inevitably involved, breaking up the data (analogous to the UID versus UID+), where it&rsquo;s stored, broken up, and so on can improve security.<br /><br /><em>From UID to UID+<br /></em><br />One has to get the technology right for any programme, but its long-term success depends on people wanting it. Even if due to misinformation, perceptions matter. Recall how the U.S. nuclear power industry was effectively stalled even before the Three Mile Island accident due to a combination of secrecy, arrogance, and &ldquo;trust us&rdquo; instead of engagement and communication.<br /><br />The proposed update of UID to a UID+ system can address many of the concerns, and its roll-out need not be viewed as a failure of the original system but simply an update. The next step should be an analysis of how it can be done without disrupting the existing UID database(s).<br /><br />The good news is almost anything is feasible, computationally. We simply need to update our mindset of a Unique ID &mdash; there can be many such unique numbers, just like many people now have multiple and even disposable email addresses. There will be a small overhead for such designs, including one-time update costs for those who are already using the current UID number, but this is a worthwhile investment for something meant to last more than a citizen&rsquo;s lifetime.<br /><em><br />(Rahul Tongia is a Fellow at Brookings India, and Adjunct Professor at Carnegie Mellon University. All views are personal.)</em></div>' $lang = 'English' $SITE_URL = 'https://im4change.in/' $site_title = 'im4change' $adminprix = 'admin'</pre><pre class="stack-trace">include - APP/Template/Layout/printlayout.ctp, line 8 Cake\View\View::_evaluate() - CORE/src/View/View.php, line 1413 Cake\View\View::_render() - CORE/src/View/View.php, line 1374 Cake\View\View::renderLayout() - CORE/src/View/View.php, line 927 Cake\View\View::render() - CORE/src/View/View.php, line 885 Cake\Controller\Controller::render() - CORE/src/Controller/Controller.php, line 791 Cake\Http\ActionDispatcher::_invoke() - CORE/src/Http/ActionDispatcher.php, line 126 Cake\Http\ActionDispatcher::dispatch() - CORE/src/Http/ActionDispatcher.php, line 94 Cake\Http\BaseApplication::__invoke() - CORE/src/Http/BaseApplication.php, line 235 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Routing\Middleware\RoutingMiddleware::__invoke() - CORE/src/Routing/Middleware/RoutingMiddleware.php, line 162 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Routing\Middleware\AssetMiddleware::__invoke() - CORE/src/Routing/Middleware/AssetMiddleware.php, line 88 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Error\Middleware\ErrorHandlerMiddleware::__invoke() - CORE/src/Error/Middleware/ErrorHandlerMiddleware.php, line 96 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Http\Runner::run() - CORE/src/Http/Runner.php, line 51</pre></div></pre>latest-news-updates/updating-aadhaar-for-better-privacy-rahul-tongia-4678955.html"/> <meta http-equiv="Content-Type" content="text/html; charset=utf-8"/> <link href="https://im4change.in/css/control.css" rel="stylesheet" type="text/css" media="all"/> <title>LATEST NEWS UPDATES | Updating Aadhaar for better privacy -Rahul Tongia | Im4change.org</title> <meta name="description" content=" -The Hindu Each authorised user of the system would get a longer number that is generated to be unique, but based on the base UID number. To its proponents, Unique Identification (UID, branded Aadhaar) is the solution to citizen empowerment. To its..."/> <script src="https://im4change.in/js/jquery-1.10.2.js"></script> <script type="text/javascript" src="https://im4change.in/js/jquery-migrate.min.js"></script> <script language="javascript" type="text/javascript"> $(document).ready(function () { var img = $("img")[0]; // Get my img elem var pic_real_width, pic_real_height; $("<img/>") // Make in memory copy of image to avoid css issues .attr("src", $(img).attr("src")) .load(function () { pic_real_width = this.width; // Note: $(this).width() will not pic_real_height = this.height; // work for in memory images. }); }); </script> <style type="text/css"> @media screen { div.divFooter { display: block; } } @media print { .printbutton { display: none !important; } } </style> </head> <body> <table cellpadding="0" cellspacing="0" border="0" width="98%" align="center"> <tr> <td class="top_bg"> <div class="divFooter"> <img src="https://im4change.in/images/logo1.jpg" height="59" border="0" alt="Resource centre on India's rural distress" style="padding-top:14px;"/> </div> </td> </tr> <tr> <td id="topspace"> </td> </tr> <tr id="topspace"> <td> </td> </tr> <tr> <td height="50" style="border-bottom:1px solid #000; padding-top:10px;" class="printbutton"> <form><input type="button" value=" Print this page " onclick="window.print();return false;"/></form> </td> </tr> <tr> <td width="100%"> <h1 class="news_headlines" style="font-style:normal"> <strong>Updating Aadhaar for better privacy -Rahul Tongia</strong></h1> </td> </tr> <tr> <td width="100%" style="font-family:Arial, 'Segoe Script', 'Segoe UI', sans-serif, serif"><font size="3"> <div align="justify">-The Hindu<br /><br /><em>Each authorised user of the system would get a longer number that is generated to be unique, but based on the base UID number.<br /></em><br />To its proponents, Unique Identification (UID, branded Aadhaar) is the solution to citizen empowerment. To its opponents, UID is a violation of not only citizen privacy but even citizen rights. In reality, like any programme or project, it can be anything we design it to be. It is only through purposeful design that we can ensure that risks and unintended consequences are kept under control. The government passed the Aadhaar Bill giving statutory rights for the programme, but this still leaves privacy as a specific challenge. However, this can be addressed.<br /><br /><em>Stated goal of UID<br /></em><br />Privacy with Aadhaar isn’t just an abstract issue, but related to the fundamental view of how data are to be accessed and used. Leaders of the UID project stated in past discussions that privacy was not only paramount, but easily handled because the UID system would only be a yes or no identification system (relying, of course, on the accuracy of underlying registration). The system can be queried to verify if a person is who she claims to be based on the registration. Per design, the UID system would not know or care whether the person was Above Poverty Line or Below Poverty Line — such things would be the prerogative of the users of the system such as banks, service providers, or development schemes (here, users are not the citizens but system users like listed).<br /><br />At one level, this sounds appealing. But the problem is precisely the use of UID beyond the intended and appealing aspects, by its partners and systems providers. As Henry Wadsworth Longfellow wrote poetically if not prophetically, “I shot an arrow into the air, It fell to earth I know not where.” Instead of UID being agnostic to how the system gets used by others, UID’s design should assume the worst, and try to prevent linking of databases by third parties, or unintended usage. Otherwise, these could lead to not only an abstract violation of privacy but also very specific and troubling asymmetries in commercial transactions and citizen empowerment/rights, including through profiling. We have already seen advertisements of private entities offering to use the Aadhaar database for commercial/private uses.<br /><br />Who has rights to the data? This needs clarity. The problem with rights to access is the possibility of unintended access. One thing we can learn from other large IT systems is that the boundary matters — just worrying about outsider hackers is wrong for IT systems since most IT security breaches involve an insider (and also mistakes). Similarly, UID’s privacy cannot be viewed simply from an internal database and its security perspective but rather the ecosystem of users of UID. UID is only as secure as its weakest link. This is where segregation of data can help.<br /><br />We must ensure that the UID database is not used in a manner that can hurt the citizens either accidentally or through mission creep with unintended consequences. It’s worth thinking about what could go wrong.<br /><br /><em>The solution <br /></em><br />What if we could have a UID that was never inter-linkable across users, but yet at the same time uniquely linked to the person through biometrics? The answer is we can, through the use of not a single UID, but a base UID (like we have today) plus modifications per user (if not per use). Instead of, say, MNREGA using the 12-digit number like today, each authorised user of the system (such as MNREGA, a bank, and so on) would get a modified (longer) number that is cryptographically generated to be unique but based on the base UID number in such a way that it could be proven to be functionally the same. Technologically, this would use a one-way hash that would be irreversible so that the longer number or code couldn’t reveal the base UID number.<br /><br />The benefits of this would be twofold. First, a corporation or other user could not create a linked database for profiling — they would all have different UID+ numbers. Second, to even get the UID+, the cryptographic process could be restricted to authorised users. This way, we could prevent the UID becoming a casual identifier. For instance, in the U.S., the social security number morphs into something required by the cable TV operator when you raise a service complaint! Of course, in India we risk a similar link/identifier — our mobile number.<br /><br />This same concept of separation applies to security from an Indian government-citizen perspective. Given that Indian and global private technology companies are inevitably involved, breaking up the data (analogous to the UID versus UID+), where it’s stored, broken up, and so on can improve security.<br /><br /><em>From UID to UID+<br /></em><br />One has to get the technology right for any programme, but its long-term success depends on people wanting it. Even if due to misinformation, perceptions matter. Recall how the U.S. nuclear power industry was effectively stalled even before the Three Mile Island accident due to a combination of secrecy, arrogance, and “trust us” instead of engagement and communication.<br /><br />The proposed update of UID to a UID+ system can address many of the concerns, and its roll-out need not be viewed as a failure of the original system but simply an update. The next step should be an analysis of how it can be done without disrupting the existing UID database(s).<br /><br />The good news is almost anything is feasible, computationally. We simply need to update our mindset of a Unique ID — there can be many such unique numbers, just like many people now have multiple and even disposable email addresses. There will be a small overhead for such designs, including one-time update costs for those who are already using the current UID number, but this is a worthwhile investment for something meant to last more than a citizen’s lifetime.<br /><em><br />(Rahul Tongia is a Fellow at Brookings India, and Adjunct Professor at Carnegie Mellon University. All views are personal.)</em></div> </font> </td> </tr> <tr> <td> </td> </tr> <tr> <td height="50" style="border-top:1px solid #000; border-bottom:1px solid #000;padding-top:10px;"> <form><input type="button" value=" Print this page " onclick="window.print();return false;"/></form> </td> </tr> </table></body> </html>' } $reasonPhrase = 'OK'header - [internal], line ?? Cake\Http\ResponseEmitter::emitStatusLine() - CORE/src/Http/ResponseEmitter.php, line 148 Cake\Http\ResponseEmitter::emit() - CORE/src/Http/ResponseEmitter.php, line 54 Cake\Http\Server::emit() - CORE/src/Http/Server.php, line 141 [main] - ROOT/webroot/index.php, line 39
Warning (2): Cannot modify header information - headers already sent by (output started at /home/brlfuser/public_html/vendor/cakephp/cakephp/src/Error/Debugger.php:853) [CORE/src/Http/ResponseEmitter.php, line 181]Notice (8): Undefined variable: urlPrefix [APP/Template/Layout/printlayout.ctp, line 8]Code Context$value
), $first);
$first = false;
$response = object(Cake\Http\Response) { 'status' => (int) 200, 'contentType' => 'text/html', 'headers' => [ 'Content-Type' => [ [maximum depth reached] ] ], 'file' => null, 'fileRange' => [], 'cookies' => object(Cake\Http\Cookie\CookieCollection) {}, 'cacheDirectives' => [], 'body' => '<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <link rel="canonical" href="https://im4change.in/<pre class="cake-error"><a href="javascript:void(0);" onclick="document.getElementById('cakeErr67ef453bce406-trace').style.display = (document.getElementById('cakeErr67ef453bce406-trace').style.display == 'none' ? '' : 'none');"><b>Notice</b> (8)</a>: Undefined variable: urlPrefix [<b>APP/Template/Layout/printlayout.ctp</b>, line <b>8</b>]<div id="cakeErr67ef453bce406-trace" class="cake-stack-trace" style="display: none;"><a href="javascript:void(0);" onclick="document.getElementById('cakeErr67ef453bce406-code').style.display = (document.getElementById('cakeErr67ef453bce406-code').style.display == 'none' ? '' : 'none')">Code</a> <a href="javascript:void(0);" onclick="document.getElementById('cakeErr67ef453bce406-context').style.display = (document.getElementById('cakeErr67ef453bce406-context').style.display == 'none' ? '' : 'none')">Context</a><pre id="cakeErr67ef453bce406-code" class="cake-code-dump" style="display: none;"><code><span style="color: #000000"><span style="color: #0000BB"></span><span style="color: #007700"><</span><span style="color: #0000BB">head</span><span style="color: #007700">> </span></span></code> <span class="code-highlight"><code><span style="color: #000000"> <link rel="canonical" href="<span style="color: #0000BB"><?php </span><span style="color: #007700">echo </span><span style="color: #0000BB">Configure</span><span style="color: #007700">::</span><span style="color: #0000BB">read</span><span style="color: #007700">(</span><span style="color: #DD0000">'SITE_URL'</span><span style="color: #007700">); </span><span style="color: #0000BB">?><?php </span><span style="color: #007700">echo </span><span style="color: #0000BB">$urlPrefix</span><span style="color: #007700">;</span><span style="color: #0000BB">?><?php </span><span style="color: #007700">echo </span><span style="color: #0000BB">$article_current</span><span style="color: #007700">-></span><span style="color: #0000BB">category</span><span style="color: #007700">-></span><span style="color: #0000BB">slug</span><span style="color: #007700">; </span><span style="color: #0000BB">?></span>/<span style="color: #0000BB"><?php </span><span style="color: #007700">echo </span><span style="color: #0000BB">$article_current</span><span style="color: #007700">-></span><span style="color: #0000BB">seo_url</span><span style="color: #007700">; </span><span style="color: #0000BB">?></span>.html"/> </span></code></span> <code><span style="color: #000000"><span style="color: #0000BB"> </span><span style="color: #007700"><</span><span style="color: #0000BB">meta http</span><span style="color: #007700">-</span><span style="color: #0000BB">equiv</span><span style="color: #007700">=</span><span style="color: #DD0000">"Content-Type" </span><span style="color: #0000BB">content</span><span style="color: #007700">=</span><span style="color: #DD0000">"text/html; charset=utf-8"</span><span style="color: #007700">/> </span></span></code></pre><pre id="cakeErr67ef453bce406-context" class="cake-context" style="display: none;">$viewFile = '/home/brlfuser/public_html/src/Template/Layout/printlayout.ctp' $dataForView = [ 'article_current' => object(App\Model\Entity\Article) { 'id' => (int) 30888, 'title' => 'Updating Aadhaar for better privacy -Rahul Tongia', 'subheading' => '', 'description' => '<div align="justify"> -The Hindu<br /> <br /> <em>Each authorised user of the system would get a longer number that is generated to be unique, but based on the base UID number.<br /> </em><br /> To its proponents, Unique Identification (UID, branded Aadhaar) is the solution to citizen empowerment. To its opponents, UID is a violation of not only citizen privacy but even citizen rights. In reality, like any programme or project, it can be anything we design it to be. It is only through purposeful design that we can ensure that risks and unintended consequences are kept under control. The government passed the Aadhaar Bill giving statutory rights for the programme, but this still leaves privacy as a specific challenge. However, this can be addressed.<br /> <br /> <em>Stated goal of UID<br /> </em><br /> Privacy with Aadhaar isn&rsquo;t just an abstract issue, but related to the fundamental view of how data are to be accessed and used. Leaders of the UID project stated in past discussions that privacy was not only paramount, but easily handled because the UID system would only be a yes or no identification system (relying, of course, on the accuracy of underlying registration). The system can be queried to verify if a person is who she claims to be based on the registration. Per design, the UID system would not know or care whether the person was Above Poverty Line or Below Poverty Line &mdash; such things would be the prerogative of the users of the system such as banks, service providers, or development schemes (here, users are not the citizens but system users like listed).<br /> <br /> At one level, this sounds appealing. But the problem is precisely the use of UID beyond the intended and appealing aspects, by its partners and systems providers. As Henry Wadsworth Longfellow wrote poetically if not prophetically, &ldquo;I shot an arrow into the air, It fell to earth I know not where.&rdquo; Instead of UID being agnostic to how the system gets used by others, UID&rsquo;s design should assume the worst, and try to prevent linking of databases by third parties, or unintended usage. Otherwise, these could lead to not only an abstract violation of privacy but also very specific and troubling asymmetries in commercial transactions and citizen empowerment/rights, including through profiling. We have already seen advertisements of private entities offering to use the Aadhaar database for commercial/private uses.<br /> <br /> Who has rights to the data? This needs clarity. The problem with rights to access is the possibility of unintended access. One thing we can learn from other large IT systems is that the boundary matters &mdash; just worrying about outsider hackers is wrong for IT systems since most IT security breaches involve an insider (and also mistakes). Similarly, UID&rsquo;s privacy cannot be viewed simply from an internal database and its security perspective but rather the ecosystem of users of UID. UID is only as secure as its weakest link. This is where segregation of data can help.<br /> <br /> We must ensure that the UID database is not used in a manner that can hurt the citizens either accidentally or through mission creep with unintended consequences. It&rsquo;s worth thinking about what could go wrong.<br /> <br /> <em>The solution <br /> </em><br /> What if we could have a UID that was never inter-linkable across users, but yet at the same time uniquely linked to the person through biometrics? The answer is we can, through the use of not a single UID, but a base UID (like we have today) plus modifications per user (if not per use). Instead of, say, MNREGA using the 12-digit number like today, each authorised user of the system (such as MNREGA, a bank, and so on) would get a modified (longer) number that is cryptographically generated to be unique but based on the base UID number in such a way that it could be proven to be functionally the same. Technologically, this would use a one-way hash that would be irreversible so that the longer number or code couldn&rsquo;t reveal the base UID number.<br /> <br /> The benefits of this would be twofold. First, a corporation or other user could not create a linked database for profiling &mdash; they would all have different UID+ numbers. Second, to even get the UID+, the cryptographic process could be restricted to authorised users. This way, we could prevent the UID becoming a casual identifier. For instance, in the U.S., the social security number morphs into something required by the cable TV operator when you raise a service complaint! Of course, in India we risk a similar link/identifier &mdash; our mobile number.<br /> <br /> This same concept of separation applies to security from an Indian government-citizen perspective. Given that Indian and global private technology companies are inevitably involved, breaking up the data (analogous to the UID versus UID+), where it&rsquo;s stored, broken up, and so on can improve security.<br /> <br /> <em>From UID to UID+<br /> </em><br /> One has to get the technology right for any programme, but its long-term success depends on people wanting it. Even if due to misinformation, perceptions matter. Recall how the U.S. nuclear power industry was effectively stalled even before the Three Mile Island accident due to a combination of secrecy, arrogance, and &ldquo;trust us&rdquo; instead of engagement and communication.<br /> <br /> The proposed update of UID to a UID+ system can address many of the concerns, and its roll-out need not be viewed as a failure of the original system but simply an update. The next step should be an analysis of how it can be done without disrupting the existing UID database(s).<br /> <br /> The good news is almost anything is feasible, computationally. We simply need to update our mindset of a Unique ID &mdash; there can be many such unique numbers, just like many people now have multiple and even disposable email addresses. There will be a small overhead for such designs, including one-time update costs for those who are already using the current UID number, but this is a worthwhile investment for something meant to last more than a citizen&rsquo;s lifetime.<br /> <em><br /> (Rahul Tongia is a Fellow at Brookings India, and Adjunct Professor at Carnegie Mellon University. All views are personal.)</em> </div>', 'credit_writer' => 'The Hindu, 28 March, 2016, http://www.thehindu.com/opinion/op-ed/updating-aadhaar-for-better-privacy/article8402375.ece?homepage=true', 'article_img' => '', 'article_img_thumb' => '', 'status' => (int) 1, 'show_on_home' => (int) 1, 'lang' => 'EN', 'category_id' => (int) 16, 'tag_keyword' => '', 'seo_url' => 'updating-aadhaar-for-better-privacy-rahul-tongia-4678955', 'meta_title' => null, 'meta_keywords' => null, 'meta_description' => null, 'noindex' => (int) 0, 'publish_date' => object(Cake\I18n\FrozenDate) {}, 'most_visit_section_id' => null, 'article_big_img' => null, 'liveid' => (int) 4678955, 'created' => object(Cake\I18n\FrozenTime) {}, 'modified' => object(Cake\I18n\FrozenTime) {}, 'edate' => '', 'tags' => [ [maximum depth reached] ], 'category' => object(App\Model\Entity\Category) {}, '[new]' => false, '[accessible]' => [ [maximum depth reached] ], '[dirty]' => [[maximum depth reached]], '[original]' => [[maximum depth reached]], '[virtual]' => [[maximum depth reached]], '[hasErrors]' => false, '[errors]' => [[maximum depth reached]], '[invalid]' => [[maximum depth reached]], '[repository]' => 'Articles' }, 'articleid' => (int) 30888, 'metaTitle' => 'LATEST NEWS UPDATES | Updating Aadhaar for better privacy -Rahul Tongia', 'metaKeywords' => 'Privacy,Privacy Rights,biometric identification system,Biometric information,UIDAI,uid,aadhaar,Aadhaar (Targeted Delivery of Financial and Other Subsidies Benefits and Services) Bill (2016),Aadhaar Bill', 'metaDesc' => ' -The Hindu Each authorised user of the system would get a longer number that is generated to be unique, but based on the base UID number. To its proponents, Unique Identification (UID, branded Aadhaar) is the solution to citizen empowerment. To its...', 'disp' => '<div align="justify">-The Hindu<br /><br /><em>Each authorised user of the system would get a longer number that is generated to be unique, but based on the base UID number.<br /></em><br />To its proponents, Unique Identification (UID, branded Aadhaar) is the solution to citizen empowerment. To its opponents, UID is a violation of not only citizen privacy but even citizen rights. In reality, like any programme or project, it can be anything we design it to be. It is only through purposeful design that we can ensure that risks and unintended consequences are kept under control. The government passed the Aadhaar Bill giving statutory rights for the programme, but this still leaves privacy as a specific challenge. However, this can be addressed.<br /><br /><em>Stated goal of UID<br /></em><br />Privacy with Aadhaar isn&rsquo;t just an abstract issue, but related to the fundamental view of how data are to be accessed and used. Leaders of the UID project stated in past discussions that privacy was not only paramount, but easily handled because the UID system would only be a yes or no identification system (relying, of course, on the accuracy of underlying registration). The system can be queried to verify if a person is who she claims to be based on the registration. Per design, the UID system would not know or care whether the person was Above Poverty Line or Below Poverty Line &mdash; such things would be the prerogative of the users of the system such as banks, service providers, or development schemes (here, users are not the citizens but system users like listed).<br /><br />At one level, this sounds appealing. But the problem is precisely the use of UID beyond the intended and appealing aspects, by its partners and systems providers. As Henry Wadsworth Longfellow wrote poetically if not prophetically, &ldquo;I shot an arrow into the air, It fell to earth I know not where.&rdquo; Instead of UID being agnostic to how the system gets used by others, UID&rsquo;s design should assume the worst, and try to prevent linking of databases by third parties, or unintended usage. Otherwise, these could lead to not only an abstract violation of privacy but also very specific and troubling asymmetries in commercial transactions and citizen empowerment/rights, including through profiling. We have already seen advertisements of private entities offering to use the Aadhaar database for commercial/private uses.<br /><br />Who has rights to the data? This needs clarity. The problem with rights to access is the possibility of unintended access. One thing we can learn from other large IT systems is that the boundary matters &mdash; just worrying about outsider hackers is wrong for IT systems since most IT security breaches involve an insider (and also mistakes). Similarly, UID&rsquo;s privacy cannot be viewed simply from an internal database and its security perspective but rather the ecosystem of users of UID. UID is only as secure as its weakest link. This is where segregation of data can help.<br /><br />We must ensure that the UID database is not used in a manner that can hurt the citizens either accidentally or through mission creep with unintended consequences. It&rsquo;s worth thinking about what could go wrong.<br /><br /><em>The solution <br /></em><br />What if we could have a UID that was never inter-linkable across users, but yet at the same time uniquely linked to the person through biometrics? The answer is we can, through the use of not a single UID, but a base UID (like we have today) plus modifications per user (if not per use). Instead of, say, MNREGA using the 12-digit number like today, each authorised user of the system (such as MNREGA, a bank, and so on) would get a modified (longer) number that is cryptographically generated to be unique but based on the base UID number in such a way that it could be proven to be functionally the same. Technologically, this would use a one-way hash that would be irreversible so that the longer number or code couldn&rsquo;t reveal the base UID number.<br /><br />The benefits of this would be twofold. First, a corporation or other user could not create a linked database for profiling &mdash; they would all have different UID+ numbers. Second, to even get the UID+, the cryptographic process could be restricted to authorised users. This way, we could prevent the UID becoming a casual identifier. For instance, in the U.S., the social security number morphs into something required by the cable TV operator when you raise a service complaint! Of course, in India we risk a similar link/identifier &mdash; our mobile number.<br /><br />This same concept of separation applies to security from an Indian government-citizen perspective. Given that Indian and global private technology companies are inevitably involved, breaking up the data (analogous to the UID versus UID+), where it&rsquo;s stored, broken up, and so on can improve security.<br /><br /><em>From UID to UID+<br /></em><br />One has to get the technology right for any programme, but its long-term success depends on people wanting it. Even if due to misinformation, perceptions matter. Recall how the U.S. nuclear power industry was effectively stalled even before the Three Mile Island accident due to a combination of secrecy, arrogance, and &ldquo;trust us&rdquo; instead of engagement and communication.<br /><br />The proposed update of UID to a UID+ system can address many of the concerns, and its roll-out need not be viewed as a failure of the original system but simply an update. The next step should be an analysis of how it can be done without disrupting the existing UID database(s).<br /><br />The good news is almost anything is feasible, computationally. We simply need to update our mindset of a Unique ID &mdash; there can be many such unique numbers, just like many people now have multiple and even disposable email addresses. There will be a small overhead for such designs, including one-time update costs for those who are already using the current UID number, but this is a worthwhile investment for something meant to last more than a citizen&rsquo;s lifetime.<br /><em><br />(Rahul Tongia is a Fellow at Brookings India, and Adjunct Professor at Carnegie Mellon University. All views are personal.)</em></div>', 'lang' => 'English', 'SITE_URL' => 'https://im4change.in/', 'site_title' => 'im4change', 'adminprix' => 'admin' ] $article_current = object(App\Model\Entity\Article) { 'id' => (int) 30888, 'title' => 'Updating Aadhaar for better privacy -Rahul Tongia', 'subheading' => '', 'description' => '<div align="justify"> -The Hindu<br /> <br /> <em>Each authorised user of the system would get a longer number that is generated to be unique, but based on the base UID number.<br /> </em><br /> To its proponents, Unique Identification (UID, branded Aadhaar) is the solution to citizen empowerment. To its opponents, UID is a violation of not only citizen privacy but even citizen rights. In reality, like any programme or project, it can be anything we design it to be. It is only through purposeful design that we can ensure that risks and unintended consequences are kept under control. The government passed the Aadhaar Bill giving statutory rights for the programme, but this still leaves privacy as a specific challenge. However, this can be addressed.<br /> <br /> <em>Stated goal of UID<br /> </em><br /> Privacy with Aadhaar isn&rsquo;t just an abstract issue, but related to the fundamental view of how data are to be accessed and used. Leaders of the UID project stated in past discussions that privacy was not only paramount, but easily handled because the UID system would only be a yes or no identification system (relying, of course, on the accuracy of underlying registration). The system can be queried to verify if a person is who she claims to be based on the registration. Per design, the UID system would not know or care whether the person was Above Poverty Line or Below Poverty Line &mdash; such things would be the prerogative of the users of the system such as banks, service providers, or development schemes (here, users are not the citizens but system users like listed).<br /> <br /> At one level, this sounds appealing. But the problem is precisely the use of UID beyond the intended and appealing aspects, by its partners and systems providers. As Henry Wadsworth Longfellow wrote poetically if not prophetically, &ldquo;I shot an arrow into the air, It fell to earth I know not where.&rdquo; Instead of UID being agnostic to how the system gets used by others, UID&rsquo;s design should assume the worst, and try to prevent linking of databases by third parties, or unintended usage. Otherwise, these could lead to not only an abstract violation of privacy but also very specific and troubling asymmetries in commercial transactions and citizen empowerment/rights, including through profiling. We have already seen advertisements of private entities offering to use the Aadhaar database for commercial/private uses.<br /> <br /> Who has rights to the data? This needs clarity. The problem with rights to access is the possibility of unintended access. One thing we can learn from other large IT systems is that the boundary matters &mdash; just worrying about outsider hackers is wrong for IT systems since most IT security breaches involve an insider (and also mistakes). Similarly, UID&rsquo;s privacy cannot be viewed simply from an internal database and its security perspective but rather the ecosystem of users of UID. UID is only as secure as its weakest link. This is where segregation of data can help.<br /> <br /> We must ensure that the UID database is not used in a manner that can hurt the citizens either accidentally or through mission creep with unintended consequences. It&rsquo;s worth thinking about what could go wrong.<br /> <br /> <em>The solution <br /> </em><br /> What if we could have a UID that was never inter-linkable across users, but yet at the same time uniquely linked to the person through biometrics? The answer is we can, through the use of not a single UID, but a base UID (like we have today) plus modifications per user (if not per use). Instead of, say, MNREGA using the 12-digit number like today, each authorised user of the system (such as MNREGA, a bank, and so on) would get a modified (longer) number that is cryptographically generated to be unique but based on the base UID number in such a way that it could be proven to be functionally the same. Technologically, this would use a one-way hash that would be irreversible so that the longer number or code couldn&rsquo;t reveal the base UID number.<br /> <br /> The benefits of this would be twofold. First, a corporation or other user could not create a linked database for profiling &mdash; they would all have different UID+ numbers. Second, to even get the UID+, the cryptographic process could be restricted to authorised users. This way, we could prevent the UID becoming a casual identifier. For instance, in the U.S., the social security number morphs into something required by the cable TV operator when you raise a service complaint! Of course, in India we risk a similar link/identifier &mdash; our mobile number.<br /> <br /> This same concept of separation applies to security from an Indian government-citizen perspective. Given that Indian and global private technology companies are inevitably involved, breaking up the data (analogous to the UID versus UID+), where it&rsquo;s stored, broken up, and so on can improve security.<br /> <br /> <em>From UID to UID+<br /> </em><br /> One has to get the technology right for any programme, but its long-term success depends on people wanting it. Even if due to misinformation, perceptions matter. Recall how the U.S. nuclear power industry was effectively stalled even before the Three Mile Island accident due to a combination of secrecy, arrogance, and &ldquo;trust us&rdquo; instead of engagement and communication.<br /> <br /> The proposed update of UID to a UID+ system can address many of the concerns, and its roll-out need not be viewed as a failure of the original system but simply an update. The next step should be an analysis of how it can be done without disrupting the existing UID database(s).<br /> <br /> The good news is almost anything is feasible, computationally. We simply need to update our mindset of a Unique ID &mdash; there can be many such unique numbers, just like many people now have multiple and even disposable email addresses. There will be a small overhead for such designs, including one-time update costs for those who are already using the current UID number, but this is a worthwhile investment for something meant to last more than a citizen&rsquo;s lifetime.<br /> <em><br /> (Rahul Tongia is a Fellow at Brookings India, and Adjunct Professor at Carnegie Mellon University. All views are personal.)</em> </div>', 'credit_writer' => 'The Hindu, 28 March, 2016, http://www.thehindu.com/opinion/op-ed/updating-aadhaar-for-better-privacy/article8402375.ece?homepage=true', 'article_img' => '', 'article_img_thumb' => '', 'status' => (int) 1, 'show_on_home' => (int) 1, 'lang' => 'EN', 'category_id' => (int) 16, 'tag_keyword' => '', 'seo_url' => 'updating-aadhaar-for-better-privacy-rahul-tongia-4678955', 'meta_title' => null, 'meta_keywords' => null, 'meta_description' => null, 'noindex' => (int) 0, 'publish_date' => object(Cake\I18n\FrozenDate) {}, 'most_visit_section_id' => null, 'article_big_img' => null, 'liveid' => (int) 4678955, 'created' => object(Cake\I18n\FrozenTime) {}, 'modified' => object(Cake\I18n\FrozenTime) {}, 'edate' => '', 'tags' => [ (int) 0 => object(Cake\ORM\Entity) {}, (int) 1 => object(Cake\ORM\Entity) {}, (int) 2 => object(Cake\ORM\Entity) {}, (int) 3 => object(Cake\ORM\Entity) {}, (int) 4 => object(Cake\ORM\Entity) {}, (int) 5 => object(Cake\ORM\Entity) {}, (int) 6 => object(Cake\ORM\Entity) {}, (int) 7 => object(Cake\ORM\Entity) {}, (int) 8 => object(Cake\ORM\Entity) {} ], 'category' => object(App\Model\Entity\Category) {}, '[new]' => false, '[accessible]' => [ '*' => true, 'id' => false ], '[dirty]' => [], '[original]' => [], '[virtual]' => [], '[hasErrors]' => false, '[errors]' => [], '[invalid]' => [], '[repository]' => 'Articles' } $articleid = (int) 30888 $metaTitle = 'LATEST NEWS UPDATES | Updating Aadhaar for better privacy -Rahul Tongia' $metaKeywords = 'Privacy,Privacy Rights,biometric identification system,Biometric information,UIDAI,uid,aadhaar,Aadhaar (Targeted Delivery of Financial and Other Subsidies Benefits and Services) Bill (2016),Aadhaar Bill' $metaDesc = ' -The Hindu Each authorised user of the system would get a longer number that is generated to be unique, but based on the base UID number. To its proponents, Unique Identification (UID, branded Aadhaar) is the solution to citizen empowerment. To its...' $disp = '<div align="justify">-The Hindu<br /><br /><em>Each authorised user of the system would get a longer number that is generated to be unique, but based on the base UID number.<br /></em><br />To its proponents, Unique Identification (UID, branded Aadhaar) is the solution to citizen empowerment. To its opponents, UID is a violation of not only citizen privacy but even citizen rights. In reality, like any programme or project, it can be anything we design it to be. It is only through purposeful design that we can ensure that risks and unintended consequences are kept under control. The government passed the Aadhaar Bill giving statutory rights for the programme, but this still leaves privacy as a specific challenge. However, this can be addressed.<br /><br /><em>Stated goal of UID<br /></em><br />Privacy with Aadhaar isn&rsquo;t just an abstract issue, but related to the fundamental view of how data are to be accessed and used. Leaders of the UID project stated in past discussions that privacy was not only paramount, but easily handled because the UID system would only be a yes or no identification system (relying, of course, on the accuracy of underlying registration). The system can be queried to verify if a person is who she claims to be based on the registration. Per design, the UID system would not know or care whether the person was Above Poverty Line or Below Poverty Line &mdash; such things would be the prerogative of the users of the system such as banks, service providers, or development schemes (here, users are not the citizens but system users like listed).<br /><br />At one level, this sounds appealing. But the problem is precisely the use of UID beyond the intended and appealing aspects, by its partners and systems providers. As Henry Wadsworth Longfellow wrote poetically if not prophetically, &ldquo;I shot an arrow into the air, It fell to earth I know not where.&rdquo; Instead of UID being agnostic to how the system gets used by others, UID&rsquo;s design should assume the worst, and try to prevent linking of databases by third parties, or unintended usage. Otherwise, these could lead to not only an abstract violation of privacy but also very specific and troubling asymmetries in commercial transactions and citizen empowerment/rights, including through profiling. We have already seen advertisements of private entities offering to use the Aadhaar database for commercial/private uses.<br /><br />Who has rights to the data? This needs clarity. The problem with rights to access is the possibility of unintended access. One thing we can learn from other large IT systems is that the boundary matters &mdash; just worrying about outsider hackers is wrong for IT systems since most IT security breaches involve an insider (and also mistakes). Similarly, UID&rsquo;s privacy cannot be viewed simply from an internal database and its security perspective but rather the ecosystem of users of UID. UID is only as secure as its weakest link. This is where segregation of data can help.<br /><br />We must ensure that the UID database is not used in a manner that can hurt the citizens either accidentally or through mission creep with unintended consequences. It&rsquo;s worth thinking about what could go wrong.<br /><br /><em>The solution <br /></em><br />What if we could have a UID that was never inter-linkable across users, but yet at the same time uniquely linked to the person through biometrics? The answer is we can, through the use of not a single UID, but a base UID (like we have today) plus modifications per user (if not per use). Instead of, say, MNREGA using the 12-digit number like today, each authorised user of the system (such as MNREGA, a bank, and so on) would get a modified (longer) number that is cryptographically generated to be unique but based on the base UID number in such a way that it could be proven to be functionally the same. Technologically, this would use a one-way hash that would be irreversible so that the longer number or code couldn&rsquo;t reveal the base UID number.<br /><br />The benefits of this would be twofold. First, a corporation or other user could not create a linked database for profiling &mdash; they would all have different UID+ numbers. Second, to even get the UID+, the cryptographic process could be restricted to authorised users. This way, we could prevent the UID becoming a casual identifier. For instance, in the U.S., the social security number morphs into something required by the cable TV operator when you raise a service complaint! Of course, in India we risk a similar link/identifier &mdash; our mobile number.<br /><br />This same concept of separation applies to security from an Indian government-citizen perspective. Given that Indian and global private technology companies are inevitably involved, breaking up the data (analogous to the UID versus UID+), where it&rsquo;s stored, broken up, and so on can improve security.<br /><br /><em>From UID to UID+<br /></em><br />One has to get the technology right for any programme, but its long-term success depends on people wanting it. Even if due to misinformation, perceptions matter. Recall how the U.S. nuclear power industry was effectively stalled even before the Three Mile Island accident due to a combination of secrecy, arrogance, and &ldquo;trust us&rdquo; instead of engagement and communication.<br /><br />The proposed update of UID to a UID+ system can address many of the concerns, and its roll-out need not be viewed as a failure of the original system but simply an update. The next step should be an analysis of how it can be done without disrupting the existing UID database(s).<br /><br />The good news is almost anything is feasible, computationally. We simply need to update our mindset of a Unique ID &mdash; there can be many such unique numbers, just like many people now have multiple and even disposable email addresses. There will be a small overhead for such designs, including one-time update costs for those who are already using the current UID number, but this is a worthwhile investment for something meant to last more than a citizen&rsquo;s lifetime.<br /><em><br />(Rahul Tongia is a Fellow at Brookings India, and Adjunct Professor at Carnegie Mellon University. All views are personal.)</em></div>' $lang = 'English' $SITE_URL = 'https://im4change.in/' $site_title = 'im4change' $adminprix = 'admin'</pre><pre class="stack-trace">include - APP/Template/Layout/printlayout.ctp, line 8 Cake\View\View::_evaluate() - CORE/src/View/View.php, line 1413 Cake\View\View::_render() - CORE/src/View/View.php, line 1374 Cake\View\View::renderLayout() - CORE/src/View/View.php, line 927 Cake\View\View::render() - CORE/src/View/View.php, line 885 Cake\Controller\Controller::render() - CORE/src/Controller/Controller.php, line 791 Cake\Http\ActionDispatcher::_invoke() - CORE/src/Http/ActionDispatcher.php, line 126 Cake\Http\ActionDispatcher::dispatch() - CORE/src/Http/ActionDispatcher.php, line 94 Cake\Http\BaseApplication::__invoke() - CORE/src/Http/BaseApplication.php, line 235 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Routing\Middleware\RoutingMiddleware::__invoke() - CORE/src/Routing/Middleware/RoutingMiddleware.php, line 162 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Routing\Middleware\AssetMiddleware::__invoke() - CORE/src/Routing/Middleware/AssetMiddleware.php, line 88 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Error\Middleware\ErrorHandlerMiddleware::__invoke() - CORE/src/Error/Middleware/ErrorHandlerMiddleware.php, line 96 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Http\Runner::run() - CORE/src/Http/Runner.php, line 51</pre></div></pre>latest-news-updates/updating-aadhaar-for-better-privacy-rahul-tongia-4678955.html"/> <meta http-equiv="Content-Type" content="text/html; charset=utf-8"/> <link href="https://im4change.in/css/control.css" rel="stylesheet" type="text/css" media="all"/> <title>LATEST NEWS UPDATES | Updating Aadhaar for better privacy -Rahul Tongia | Im4change.org</title> <meta name="description" content=" -The Hindu Each authorised user of the system would get a longer number that is generated to be unique, but based on the base UID number. To its proponents, Unique Identification (UID, branded Aadhaar) is the solution to citizen empowerment. To its..."/> <script src="https://im4change.in/js/jquery-1.10.2.js"></script> <script type="text/javascript" src="https://im4change.in/js/jquery-migrate.min.js"></script> <script language="javascript" type="text/javascript"> $(document).ready(function () { var img = $("img")[0]; // Get my img elem var pic_real_width, pic_real_height; $("<img/>") // Make in memory copy of image to avoid css issues .attr("src", $(img).attr("src")) .load(function () { pic_real_width = this.width; // Note: $(this).width() will not pic_real_height = this.height; // work for in memory images. }); }); </script> <style type="text/css"> @media screen { div.divFooter { display: block; } } @media print { .printbutton { display: none !important; } } </style> </head> <body> <table cellpadding="0" cellspacing="0" border="0" width="98%" align="center"> <tr> <td class="top_bg"> <div class="divFooter"> <img src="https://im4change.in/images/logo1.jpg" height="59" border="0" alt="Resource centre on India's rural distress" style="padding-top:14px;"/> </div> </td> </tr> <tr> <td id="topspace"> </td> </tr> <tr id="topspace"> <td> </td> </tr> <tr> <td height="50" style="border-bottom:1px solid #000; padding-top:10px;" class="printbutton"> <form><input type="button" value=" Print this page " onclick="window.print();return false;"/></form> </td> </tr> <tr> <td width="100%"> <h1 class="news_headlines" style="font-style:normal"> <strong>Updating Aadhaar for better privacy -Rahul Tongia</strong></h1> </td> </tr> <tr> <td width="100%" style="font-family:Arial, 'Segoe Script', 'Segoe UI', sans-serif, serif"><font size="3"> <div align="justify">-The Hindu<br /><br /><em>Each authorised user of the system would get a longer number that is generated to be unique, but based on the base UID number.<br /></em><br />To its proponents, Unique Identification (UID, branded Aadhaar) is the solution to citizen empowerment. To its opponents, UID is a violation of not only citizen privacy but even citizen rights. In reality, like any programme or project, it can be anything we design it to be. It is only through purposeful design that we can ensure that risks and unintended consequences are kept under control. The government passed the Aadhaar Bill giving statutory rights for the programme, but this still leaves privacy as a specific challenge. However, this can be addressed.<br /><br /><em>Stated goal of UID<br /></em><br />Privacy with Aadhaar isn’t just an abstract issue, but related to the fundamental view of how data are to be accessed and used. Leaders of the UID project stated in past discussions that privacy was not only paramount, but easily handled because the UID system would only be a yes or no identification system (relying, of course, on the accuracy of underlying registration). The system can be queried to verify if a person is who she claims to be based on the registration. Per design, the UID system would not know or care whether the person was Above Poverty Line or Below Poverty Line — such things would be the prerogative of the users of the system such as banks, service providers, or development schemes (here, users are not the citizens but system users like listed).<br /><br />At one level, this sounds appealing. But the problem is precisely the use of UID beyond the intended and appealing aspects, by its partners and systems providers. As Henry Wadsworth Longfellow wrote poetically if not prophetically, “I shot an arrow into the air, It fell to earth I know not where.” Instead of UID being agnostic to how the system gets used by others, UID’s design should assume the worst, and try to prevent linking of databases by third parties, or unintended usage. Otherwise, these could lead to not only an abstract violation of privacy but also very specific and troubling asymmetries in commercial transactions and citizen empowerment/rights, including through profiling. We have already seen advertisements of private entities offering to use the Aadhaar database for commercial/private uses.<br /><br />Who has rights to the data? This needs clarity. The problem with rights to access is the possibility of unintended access. One thing we can learn from other large IT systems is that the boundary matters — just worrying about outsider hackers is wrong for IT systems since most IT security breaches involve an insider (and also mistakes). Similarly, UID’s privacy cannot be viewed simply from an internal database and its security perspective but rather the ecosystem of users of UID. UID is only as secure as its weakest link. This is where segregation of data can help.<br /><br />We must ensure that the UID database is not used in a manner that can hurt the citizens either accidentally or through mission creep with unintended consequences. It’s worth thinking about what could go wrong.<br /><br /><em>The solution <br /></em><br />What if we could have a UID that was never inter-linkable across users, but yet at the same time uniquely linked to the person through biometrics? The answer is we can, through the use of not a single UID, but a base UID (like we have today) plus modifications per user (if not per use). Instead of, say, MNREGA using the 12-digit number like today, each authorised user of the system (such as MNREGA, a bank, and so on) would get a modified (longer) number that is cryptographically generated to be unique but based on the base UID number in such a way that it could be proven to be functionally the same. Technologically, this would use a one-way hash that would be irreversible so that the longer number or code couldn’t reveal the base UID number.<br /><br />The benefits of this would be twofold. First, a corporation or other user could not create a linked database for profiling — they would all have different UID+ numbers. Second, to even get the UID+, the cryptographic process could be restricted to authorised users. This way, we could prevent the UID becoming a casual identifier. For instance, in the U.S., the social security number morphs into something required by the cable TV operator when you raise a service complaint! Of course, in India we risk a similar link/identifier — our mobile number.<br /><br />This same concept of separation applies to security from an Indian government-citizen perspective. Given that Indian and global private technology companies are inevitably involved, breaking up the data (analogous to the UID versus UID+), where it’s stored, broken up, and so on can improve security.<br /><br /><em>From UID to UID+<br /></em><br />One has to get the technology right for any programme, but its long-term success depends on people wanting it. Even if due to misinformation, perceptions matter. Recall how the U.S. nuclear power industry was effectively stalled even before the Three Mile Island accident due to a combination of secrecy, arrogance, and “trust us” instead of engagement and communication.<br /><br />The proposed update of UID to a UID+ system can address many of the concerns, and its roll-out need not be viewed as a failure of the original system but simply an update. The next step should be an analysis of how it can be done without disrupting the existing UID database(s).<br /><br />The good news is almost anything is feasible, computationally. We simply need to update our mindset of a Unique ID — there can be many such unique numbers, just like many people now have multiple and even disposable email addresses. There will be a small overhead for such designs, including one-time update costs for those who are already using the current UID number, but this is a worthwhile investment for something meant to last more than a citizen’s lifetime.<br /><em><br />(Rahul Tongia is a Fellow at Brookings India, and Adjunct Professor at Carnegie Mellon University. All views are personal.)</em></div> </font> </td> </tr> <tr> <td> </td> </tr> <tr> <td height="50" style="border-top:1px solid #000; border-bottom:1px solid #000;padding-top:10px;"> <form><input type="button" value=" Print this page " onclick="window.print();return false;"/></form> </td> </tr> </table></body> </html>' } $cookies = [] $values = [ (int) 0 => 'text/html; charset=UTF-8' ] $name = 'Content-Type' $first = true $value = 'text/html; charset=UTF-8'header - [internal], line ?? Cake\Http\ResponseEmitter::emitHeaders() - CORE/src/Http/ResponseEmitter.php, line 181 Cake\Http\ResponseEmitter::emit() - CORE/src/Http/ResponseEmitter.php, line 55 Cake\Http\Server::emit() - CORE/src/Http/Server.php, line 141 [main] - ROOT/webroot/index.php, line 39
<head>
<link rel="canonical" href="<?php echo Configure::read('SITE_URL'); ?><?php echo $urlPrefix;?><?php echo $article_current->category->slug; ?>/<?php echo $article_current->seo_url; ?>.html"/>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>
$viewFile = '/home/brlfuser/public_html/src/Template/Layout/printlayout.ctp' $dataForView = [ 'article_current' => object(App\Model\Entity\Article) { 'id' => (int) 30888, 'title' => 'Updating Aadhaar for better privacy -Rahul Tongia', 'subheading' => '', 'description' => '<div align="justify"> -The Hindu<br /> <br /> <em>Each authorised user of the system would get a longer number that is generated to be unique, but based on the base UID number.<br /> </em><br /> To its proponents, Unique Identification (UID, branded Aadhaar) is the solution to citizen empowerment. To its opponents, UID is a violation of not only citizen privacy but even citizen rights. In reality, like any programme or project, it can be anything we design it to be. It is only through purposeful design that we can ensure that risks and unintended consequences are kept under control. The government passed the Aadhaar Bill giving statutory rights for the programme, but this still leaves privacy as a specific challenge. However, this can be addressed.<br /> <br /> <em>Stated goal of UID<br /> </em><br /> Privacy with Aadhaar isn’t just an abstract issue, but related to the fundamental view of how data are to be accessed and used. Leaders of the UID project stated in past discussions that privacy was not only paramount, but easily handled because the UID system would only be a yes or no identification system (relying, of course, on the accuracy of underlying registration). The system can be queried to verify if a person is who she claims to be based on the registration. Per design, the UID system would not know or care whether the person was Above Poverty Line or Below Poverty Line — such things would be the prerogative of the users of the system such as banks, service providers, or development schemes (here, users are not the citizens but system users like listed).<br /> <br /> At one level, this sounds appealing. But the problem is precisely the use of UID beyond the intended and appealing aspects, by its partners and systems providers. As Henry Wadsworth Longfellow wrote poetically if not prophetically, “I shot an arrow into the air, It fell to earth I know not where.” Instead of UID being agnostic to how the system gets used by others, UID’s design should assume the worst, and try to prevent linking of databases by third parties, or unintended usage. Otherwise, these could lead to not only an abstract violation of privacy but also very specific and troubling asymmetries in commercial transactions and citizen empowerment/rights, including through profiling. We have already seen advertisements of private entities offering to use the Aadhaar database for commercial/private uses.<br /> <br /> Who has rights to the data? This needs clarity. The problem with rights to access is the possibility of unintended access. One thing we can learn from other large IT systems is that the boundary matters — just worrying about outsider hackers is wrong for IT systems since most IT security breaches involve an insider (and also mistakes). Similarly, UID’s privacy cannot be viewed simply from an internal database and its security perspective but rather the ecosystem of users of UID. UID is only as secure as its weakest link. This is where segregation of data can help.<br /> <br /> We must ensure that the UID database is not used in a manner that can hurt the citizens either accidentally or through mission creep with unintended consequences. It’s worth thinking about what could go wrong.<br /> <br /> <em>The solution <br /> </em><br /> What if we could have a UID that was never inter-linkable across users, but yet at the same time uniquely linked to the person through biometrics? The answer is we can, through the use of not a single UID, but a base UID (like we have today) plus modifications per user (if not per use). Instead of, say, MNREGA using the 12-digit number like today, each authorised user of the system (such as MNREGA, a bank, and so on) would get a modified (longer) number that is cryptographically generated to be unique but based on the base UID number in such a way that it could be proven to be functionally the same. Technologically, this would use a one-way hash that would be irreversible so that the longer number or code couldn’t reveal the base UID number.<br /> <br /> The benefits of this would be twofold. First, a corporation or other user could not create a linked database for profiling — they would all have different UID+ numbers. Second, to even get the UID+, the cryptographic process could be restricted to authorised users. This way, we could prevent the UID becoming a casual identifier. For instance, in the U.S., the social security number morphs into something required by the cable TV operator when you raise a service complaint! Of course, in India we risk a similar link/identifier — our mobile number.<br /> <br /> This same concept of separation applies to security from an Indian government-citizen perspective. Given that Indian and global private technology companies are inevitably involved, breaking up the data (analogous to the UID versus UID+), where it’s stored, broken up, and so on can improve security.<br /> <br /> <em>From UID to UID+<br /> </em><br /> One has to get the technology right for any programme, but its long-term success depends on people wanting it. Even if due to misinformation, perceptions matter. Recall how the U.S. nuclear power industry was effectively stalled even before the Three Mile Island accident due to a combination of secrecy, arrogance, and “trust us” instead of engagement and communication.<br /> <br /> The proposed update of UID to a UID+ system can address many of the concerns, and its roll-out need not be viewed as a failure of the original system but simply an update. The next step should be an analysis of how it can be done without disrupting the existing UID database(s).<br /> <br /> The good news is almost anything is feasible, computationally. We simply need to update our mindset of a Unique ID — there can be many such unique numbers, just like many people now have multiple and even disposable email addresses. There will be a small overhead for such designs, including one-time update costs for those who are already using the current UID number, but this is a worthwhile investment for something meant to last more than a citizen’s lifetime.<br /> <em><br /> (Rahul Tongia is a Fellow at Brookings India, and Adjunct Professor at Carnegie Mellon University. All views are personal.)</em> </div>', 'credit_writer' => 'The Hindu, 28 March, 2016, http://www.thehindu.com/opinion/op-ed/updating-aadhaar-for-better-privacy/article8402375.ece?homepage=true', 'article_img' => '', 'article_img_thumb' => '', 'status' => (int) 1, 'show_on_home' => (int) 1, 'lang' => 'EN', 'category_id' => (int) 16, 'tag_keyword' => '', 'seo_url' => 'updating-aadhaar-for-better-privacy-rahul-tongia-4678955', 'meta_title' => null, 'meta_keywords' => null, 'meta_description' => null, 'noindex' => (int) 0, 'publish_date' => object(Cake\I18n\FrozenDate) {}, 'most_visit_section_id' => null, 'article_big_img' => null, 'liveid' => (int) 4678955, 'created' => object(Cake\I18n\FrozenTime) {}, 'modified' => object(Cake\I18n\FrozenTime) {}, 'edate' => '', 'tags' => [ [maximum depth reached] ], 'category' => object(App\Model\Entity\Category) {}, '[new]' => false, '[accessible]' => [ [maximum depth reached] ], '[dirty]' => [[maximum depth reached]], '[original]' => [[maximum depth reached]], '[virtual]' => [[maximum depth reached]], '[hasErrors]' => false, '[errors]' => [[maximum depth reached]], '[invalid]' => [[maximum depth reached]], '[repository]' => 'Articles' }, 'articleid' => (int) 30888, 'metaTitle' => 'LATEST NEWS UPDATES | Updating Aadhaar for better privacy -Rahul Tongia', 'metaKeywords' => 'Privacy,Privacy Rights,biometric identification system,Biometric information,UIDAI,uid,aadhaar,Aadhaar (Targeted Delivery of Financial and Other Subsidies Benefits and Services) Bill (2016),Aadhaar Bill', 'metaDesc' => ' -The Hindu Each authorised user of the system would get a longer number that is generated to be unique, but based on the base UID number. To its proponents, Unique Identification (UID, branded Aadhaar) is the solution to citizen empowerment. To its...', 'disp' => '<div align="justify">-The Hindu<br /><br /><em>Each authorised user of the system would get a longer number that is generated to be unique, but based on the base UID number.<br /></em><br />To its proponents, Unique Identification (UID, branded Aadhaar) is the solution to citizen empowerment. To its opponents, UID is a violation of not only citizen privacy but even citizen rights. In reality, like any programme or project, it can be anything we design it to be. It is only through purposeful design that we can ensure that risks and unintended consequences are kept under control. The government passed the Aadhaar Bill giving statutory rights for the programme, but this still leaves privacy as a specific challenge. However, this can be addressed.<br /><br /><em>Stated goal of UID<br /></em><br />Privacy with Aadhaar isn’t just an abstract issue, but related to the fundamental view of how data are to be accessed and used. Leaders of the UID project stated in past discussions that privacy was not only paramount, but easily handled because the UID system would only be a yes or no identification system (relying, of course, on the accuracy of underlying registration). The system can be queried to verify if a person is who she claims to be based on the registration. Per design, the UID system would not know or care whether the person was Above Poverty Line or Below Poverty Line — such things would be the prerogative of the users of the system such as banks, service providers, or development schemes (here, users are not the citizens but system users like listed).<br /><br />At one level, this sounds appealing. But the problem is precisely the use of UID beyond the intended and appealing aspects, by its partners and systems providers. As Henry Wadsworth Longfellow wrote poetically if not prophetically, “I shot an arrow into the air, It fell to earth I know not where.” Instead of UID being agnostic to how the system gets used by others, UID’s design should assume the worst, and try to prevent linking of databases by third parties, or unintended usage. Otherwise, these could lead to not only an abstract violation of privacy but also very specific and troubling asymmetries in commercial transactions and citizen empowerment/rights, including through profiling. We have already seen advertisements of private entities offering to use the Aadhaar database for commercial/private uses.<br /><br />Who has rights to the data? This needs clarity. The problem with rights to access is the possibility of unintended access. One thing we can learn from other large IT systems is that the boundary matters — just worrying about outsider hackers is wrong for IT systems since most IT security breaches involve an insider (and also mistakes). Similarly, UID’s privacy cannot be viewed simply from an internal database and its security perspective but rather the ecosystem of users of UID. UID is only as secure as its weakest link. This is where segregation of data can help.<br /><br />We must ensure that the UID database is not used in a manner that can hurt the citizens either accidentally or through mission creep with unintended consequences. It’s worth thinking about what could go wrong.<br /><br /><em>The solution <br /></em><br />What if we could have a UID that was never inter-linkable across users, but yet at the same time uniquely linked to the person through biometrics? The answer is we can, through the use of not a single UID, but a base UID (like we have today) plus modifications per user (if not per use). Instead of, say, MNREGA using the 12-digit number like today, each authorised user of the system (such as MNREGA, a bank, and so on) would get a modified (longer) number that is cryptographically generated to be unique but based on the base UID number in such a way that it could be proven to be functionally the same. Technologically, this would use a one-way hash that would be irreversible so that the longer number or code couldn’t reveal the base UID number.<br /><br />The benefits of this would be twofold. First, a corporation or other user could not create a linked database for profiling — they would all have different UID+ numbers. Second, to even get the UID+, the cryptographic process could be restricted to authorised users. This way, we could prevent the UID becoming a casual identifier. For instance, in the U.S., the social security number morphs into something required by the cable TV operator when you raise a service complaint! Of course, in India we risk a similar link/identifier — our mobile number.<br /><br />This same concept of separation applies to security from an Indian government-citizen perspective. Given that Indian and global private technology companies are inevitably involved, breaking up the data (analogous to the UID versus UID+), where it’s stored, broken up, and so on can improve security.<br /><br /><em>From UID to UID+<br /></em><br />One has to get the technology right for any programme, but its long-term success depends on people wanting it. Even if due to misinformation, perceptions matter. Recall how the U.S. nuclear power industry was effectively stalled even before the Three Mile Island accident due to a combination of secrecy, arrogance, and “trust us” instead of engagement and communication.<br /><br />The proposed update of UID to a UID+ system can address many of the concerns, and its roll-out need not be viewed as a failure of the original system but simply an update. The next step should be an analysis of how it can be done without disrupting the existing UID database(s).<br /><br />The good news is almost anything is feasible, computationally. We simply need to update our mindset of a Unique ID — there can be many such unique numbers, just like many people now have multiple and even disposable email addresses. There will be a small overhead for such designs, including one-time update costs for those who are already using the current UID number, but this is a worthwhile investment for something meant to last more than a citizen’s lifetime.<br /><em><br />(Rahul Tongia is a Fellow at Brookings India, and Adjunct Professor at Carnegie Mellon University. All views are personal.)</em></div>', 'lang' => 'English', 'SITE_URL' => 'https://im4change.in/', 'site_title' => 'im4change', 'adminprix' => 'admin' ] $article_current = object(App\Model\Entity\Article) { 'id' => (int) 30888, 'title' => 'Updating Aadhaar for better privacy -Rahul Tongia', 'subheading' => '', 'description' => '<div align="justify"> -The Hindu<br /> <br /> <em>Each authorised user of the system would get a longer number that is generated to be unique, but based on the base UID number.<br /> </em><br /> To its proponents, Unique Identification (UID, branded Aadhaar) is the solution to citizen empowerment. To its opponents, UID is a violation of not only citizen privacy but even citizen rights. In reality, like any programme or project, it can be anything we design it to be. It is only through purposeful design that we can ensure that risks and unintended consequences are kept under control. The government passed the Aadhaar Bill giving statutory rights for the programme, but this still leaves privacy as a specific challenge. However, this can be addressed.<br /> <br /> <em>Stated goal of UID<br /> </em><br /> Privacy with Aadhaar isn’t just an abstract issue, but related to the fundamental view of how data are to be accessed and used. Leaders of the UID project stated in past discussions that privacy was not only paramount, but easily handled because the UID system would only be a yes or no identification system (relying, of course, on the accuracy of underlying registration). The system can be queried to verify if a person is who she claims to be based on the registration. Per design, the UID system would not know or care whether the person was Above Poverty Line or Below Poverty Line — such things would be the prerogative of the users of the system such as banks, service providers, or development schemes (here, users are not the citizens but system users like listed).<br /> <br /> At one level, this sounds appealing. But the problem is precisely the use of UID beyond the intended and appealing aspects, by its partners and systems providers. As Henry Wadsworth Longfellow wrote poetically if not prophetically, “I shot an arrow into the air, It fell to earth I know not where.” Instead of UID being agnostic to how the system gets used by others, UID’s design should assume the worst, and try to prevent linking of databases by third parties, or unintended usage. Otherwise, these could lead to not only an abstract violation of privacy but also very specific and troubling asymmetries in commercial transactions and citizen empowerment/rights, including through profiling. We have already seen advertisements of private entities offering to use the Aadhaar database for commercial/private uses.<br /> <br /> Who has rights to the data? This needs clarity. The problem with rights to access is the possibility of unintended access. One thing we can learn from other large IT systems is that the boundary matters — just worrying about outsider hackers is wrong for IT systems since most IT security breaches involve an insider (and also mistakes). Similarly, UID’s privacy cannot be viewed simply from an internal database and its security perspective but rather the ecosystem of users of UID. UID is only as secure as its weakest link. This is where segregation of data can help.<br /> <br /> We must ensure that the UID database is not used in a manner that can hurt the citizens either accidentally or through mission creep with unintended consequences. It’s worth thinking about what could go wrong.<br /> <br /> <em>The solution <br /> </em><br /> What if we could have a UID that was never inter-linkable across users, but yet at the same time uniquely linked to the person through biometrics? The answer is we can, through the use of not a single UID, but a base UID (like we have today) plus modifications per user (if not per use). Instead of, say, MNREGA using the 12-digit number like today, each authorised user of the system (such as MNREGA, a bank, and so on) would get a modified (longer) number that is cryptographically generated to be unique but based on the base UID number in such a way that it could be proven to be functionally the same. Technologically, this would use a one-way hash that would be irreversible so that the longer number or code couldn’t reveal the base UID number.<br /> <br /> The benefits of this would be twofold. First, a corporation or other user could not create a linked database for profiling — they would all have different UID+ numbers. Second, to even get the UID+, the cryptographic process could be restricted to authorised users. This way, we could prevent the UID becoming a casual identifier. For instance, in the U.S., the social security number morphs into something required by the cable TV operator when you raise a service complaint! Of course, in India we risk a similar link/identifier — our mobile number.<br /> <br /> This same concept of separation applies to security from an Indian government-citizen perspective. Given that Indian and global private technology companies are inevitably involved, breaking up the data (analogous to the UID versus UID+), where it’s stored, broken up, and so on can improve security.<br /> <br /> <em>From UID to UID+<br /> </em><br /> One has to get the technology right for any programme, but its long-term success depends on people wanting it. Even if due to misinformation, perceptions matter. Recall how the U.S. nuclear power industry was effectively stalled even before the Three Mile Island accident due to a combination of secrecy, arrogance, and “trust us” instead of engagement and communication.<br /> <br /> The proposed update of UID to a UID+ system can address many of the concerns, and its roll-out need not be viewed as a failure of the original system but simply an update. The next step should be an analysis of how it can be done without disrupting the existing UID database(s).<br /> <br /> The good news is almost anything is feasible, computationally. We simply need to update our mindset of a Unique ID — there can be many such unique numbers, just like many people now have multiple and even disposable email addresses. There will be a small overhead for such designs, including one-time update costs for those who are already using the current UID number, but this is a worthwhile investment for something meant to last more than a citizen’s lifetime.<br /> <em><br /> (Rahul Tongia is a Fellow at Brookings India, and Adjunct Professor at Carnegie Mellon University. All views are personal.)</em> </div>', 'credit_writer' => 'The Hindu, 28 March, 2016, http://www.thehindu.com/opinion/op-ed/updating-aadhaar-for-better-privacy/article8402375.ece?homepage=true', 'article_img' => '', 'article_img_thumb' => '', 'status' => (int) 1, 'show_on_home' => (int) 1, 'lang' => 'EN', 'category_id' => (int) 16, 'tag_keyword' => '', 'seo_url' => 'updating-aadhaar-for-better-privacy-rahul-tongia-4678955', 'meta_title' => null, 'meta_keywords' => null, 'meta_description' => null, 'noindex' => (int) 0, 'publish_date' => object(Cake\I18n\FrozenDate) {}, 'most_visit_section_id' => null, 'article_big_img' => null, 'liveid' => (int) 4678955, 'created' => object(Cake\I18n\FrozenTime) {}, 'modified' => object(Cake\I18n\FrozenTime) {}, 'edate' => '', 'tags' => [ (int) 0 => object(Cake\ORM\Entity) {}, (int) 1 => object(Cake\ORM\Entity) {}, (int) 2 => object(Cake\ORM\Entity) {}, (int) 3 => object(Cake\ORM\Entity) {}, (int) 4 => object(Cake\ORM\Entity) {}, (int) 5 => object(Cake\ORM\Entity) {}, (int) 6 => object(Cake\ORM\Entity) {}, (int) 7 => object(Cake\ORM\Entity) {}, (int) 8 => object(Cake\ORM\Entity) {} ], 'category' => object(App\Model\Entity\Category) {}, '[new]' => false, '[accessible]' => [ '*' => true, 'id' => false ], '[dirty]' => [], '[original]' => [], '[virtual]' => [], '[hasErrors]' => false, '[errors]' => [], '[invalid]' => [], '[repository]' => 'Articles' } $articleid = (int) 30888 $metaTitle = 'LATEST NEWS UPDATES | Updating Aadhaar for better privacy -Rahul Tongia' $metaKeywords = 'Privacy,Privacy Rights,biometric identification system,Biometric information,UIDAI,uid,aadhaar,Aadhaar (Targeted Delivery of Financial and Other Subsidies Benefits and Services) Bill (2016),Aadhaar Bill' $metaDesc = ' -The Hindu Each authorised user of the system would get a longer number that is generated to be unique, but based on the base UID number. To its proponents, Unique Identification (UID, branded Aadhaar) is the solution to citizen empowerment. To its...' $disp = '<div align="justify">-The Hindu<br /><br /><em>Each authorised user of the system would get a longer number that is generated to be unique, but based on the base UID number.<br /></em><br />To its proponents, Unique Identification (UID, branded Aadhaar) is the solution to citizen empowerment. To its opponents, UID is a violation of not only citizen privacy but even citizen rights. In reality, like any programme or project, it can be anything we design it to be. It is only through purposeful design that we can ensure that risks and unintended consequences are kept under control. The government passed the Aadhaar Bill giving statutory rights for the programme, but this still leaves privacy as a specific challenge. However, this can be addressed.<br /><br /><em>Stated goal of UID<br /></em><br />Privacy with Aadhaar isn’t just an abstract issue, but related to the fundamental view of how data are to be accessed and used. Leaders of the UID project stated in past discussions that privacy was not only paramount, but easily handled because the UID system would only be a yes or no identification system (relying, of course, on the accuracy of underlying registration). The system can be queried to verify if a person is who she claims to be based on the registration. Per design, the UID system would not know or care whether the person was Above Poverty Line or Below Poverty Line — such things would be the prerogative of the users of the system such as banks, service providers, or development schemes (here, users are not the citizens but system users like listed).<br /><br />At one level, this sounds appealing. But the problem is precisely the use of UID beyond the intended and appealing aspects, by its partners and systems providers. As Henry Wadsworth Longfellow wrote poetically if not prophetically, “I shot an arrow into the air, It fell to earth I know not where.” Instead of UID being agnostic to how the system gets used by others, UID’s design should assume the worst, and try to prevent linking of databases by third parties, or unintended usage. Otherwise, these could lead to not only an abstract violation of privacy but also very specific and troubling asymmetries in commercial transactions and citizen empowerment/rights, including through profiling. We have already seen advertisements of private entities offering to use the Aadhaar database for commercial/private uses.<br /><br />Who has rights to the data? This needs clarity. The problem with rights to access is the possibility of unintended access. One thing we can learn from other large IT systems is that the boundary matters — just worrying about outsider hackers is wrong for IT systems since most IT security breaches involve an insider (and also mistakes). Similarly, UID’s privacy cannot be viewed simply from an internal database and its security perspective but rather the ecosystem of users of UID. UID is only as secure as its weakest link. This is where segregation of data can help.<br /><br />We must ensure that the UID database is not used in a manner that can hurt the citizens either accidentally or through mission creep with unintended consequences. It’s worth thinking about what could go wrong.<br /><br /><em>The solution <br /></em><br />What if we could have a UID that was never inter-linkable across users, but yet at the same time uniquely linked to the person through biometrics? The answer is we can, through the use of not a single UID, but a base UID (like we have today) plus modifications per user (if not per use). Instead of, say, MNREGA using the 12-digit number like today, each authorised user of the system (such as MNREGA, a bank, and so on) would get a modified (longer) number that is cryptographically generated to be unique but based on the base UID number in such a way that it could be proven to be functionally the same. Technologically, this would use a one-way hash that would be irreversible so that the longer number or code couldn’t reveal the base UID number.<br /><br />The benefits of this would be twofold. First, a corporation or other user could not create a linked database for profiling — they would all have different UID+ numbers. Second, to even get the UID+, the cryptographic process could be restricted to authorised users. This way, we could prevent the UID becoming a casual identifier. For instance, in the U.S., the social security number morphs into something required by the cable TV operator when you raise a service complaint! Of course, in India we risk a similar link/identifier — our mobile number.<br /><br />This same concept of separation applies to security from an Indian government-citizen perspective. Given that Indian and global private technology companies are inevitably involved, breaking up the data (analogous to the UID versus UID+), where it’s stored, broken up, and so on can improve security.<br /><br /><em>From UID to UID+<br /></em><br />One has to get the technology right for any programme, but its long-term success depends on people wanting it. Even if due to misinformation, perceptions matter. Recall how the U.S. nuclear power industry was effectively stalled even before the Three Mile Island accident due to a combination of secrecy, arrogance, and “trust us” instead of engagement and communication.<br /><br />The proposed update of UID to a UID+ system can address many of the concerns, and its roll-out need not be viewed as a failure of the original system but simply an update. The next step should be an analysis of how it can be done without disrupting the existing UID database(s).<br /><br />The good news is almost anything is feasible, computationally. We simply need to update our mindset of a Unique ID — there can be many such unique numbers, just like many people now have multiple and even disposable email addresses. There will be a small overhead for such designs, including one-time update costs for those who are already using the current UID number, but this is a worthwhile investment for something meant to last more than a citizen’s lifetime.<br /><em><br />(Rahul Tongia is a Fellow at Brookings India, and Adjunct Professor at Carnegie Mellon University. All views are personal.)</em></div>' $lang = 'English' $SITE_URL = 'https://im4change.in/' $site_title = 'im4change' $adminprix = 'admin'
include - APP/Template/Layout/printlayout.ctp, line 8 Cake\View\View::_evaluate() - CORE/src/View/View.php, line 1413 Cake\View\View::_render() - CORE/src/View/View.php, line 1374 Cake\View\View::renderLayout() - CORE/src/View/View.php, line 927 Cake\View\View::render() - CORE/src/View/View.php, line 885 Cake\Controller\Controller::render() - CORE/src/Controller/Controller.php, line 791 Cake\Http\ActionDispatcher::_invoke() - CORE/src/Http/ActionDispatcher.php, line 126 Cake\Http\ActionDispatcher::dispatch() - CORE/src/Http/ActionDispatcher.php, line 94 Cake\Http\BaseApplication::__invoke() - CORE/src/Http/BaseApplication.php, line 235 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Routing\Middleware\RoutingMiddleware::__invoke() - CORE/src/Routing/Middleware/RoutingMiddleware.php, line 162 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Routing\Middleware\AssetMiddleware::__invoke() - CORE/src/Routing/Middleware/AssetMiddleware.php, line 88 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Error\Middleware\ErrorHandlerMiddleware::__invoke() - CORE/src/Error/Middleware/ErrorHandlerMiddleware.php, line 96 Cake\Http\Runner::__invoke() - CORE/src/Http/Runner.php, line 65 Cake\Http\Runner::run() - CORE/src/Http/Runner.php, line 51
![]() |
Updating Aadhaar for better privacy -Rahul Tongia |
-The Hindu
Each authorised user of the system would get a longer number that is generated to be unique, but based on the base UID number. To its proponents, Unique Identification (UID, branded Aadhaar) is the solution to citizen empowerment. To its opponents, UID is a violation of not only citizen privacy but even citizen rights. In reality, like any programme or project, it can be anything we design it to be. It is only through purposeful design that we can ensure that risks and unintended consequences are kept under control. The government passed the Aadhaar Bill giving statutory rights for the programme, but this still leaves privacy as a specific challenge. However, this can be addressed. Stated goal of UID Privacy with Aadhaar isn’t just an abstract issue, but related to the fundamental view of how data are to be accessed and used. Leaders of the UID project stated in past discussions that privacy was not only paramount, but easily handled because the UID system would only be a yes or no identification system (relying, of course, on the accuracy of underlying registration). The system can be queried to verify if a person is who she claims to be based on the registration. Per design, the UID system would not know or care whether the person was Above Poverty Line or Below Poverty Line — such things would be the prerogative of the users of the system such as banks, service providers, or development schemes (here, users are not the citizens but system users like listed). At one level, this sounds appealing. But the problem is precisely the use of UID beyond the intended and appealing aspects, by its partners and systems providers. As Henry Wadsworth Longfellow wrote poetically if not prophetically, “I shot an arrow into the air, It fell to earth I know not where.” Instead of UID being agnostic to how the system gets used by others, UID’s design should assume the worst, and try to prevent linking of databases by third parties, or unintended usage. Otherwise, these could lead to not only an abstract violation of privacy but also very specific and troubling asymmetries in commercial transactions and citizen empowerment/rights, including through profiling. We have already seen advertisements of private entities offering to use the Aadhaar database for commercial/private uses. Who has rights to the data? This needs clarity. The problem with rights to access is the possibility of unintended access. One thing we can learn from other large IT systems is that the boundary matters — just worrying about outsider hackers is wrong for IT systems since most IT security breaches involve an insider (and also mistakes). Similarly, UID’s privacy cannot be viewed simply from an internal database and its security perspective but rather the ecosystem of users of UID. UID is only as secure as its weakest link. This is where segregation of data can help. We must ensure that the UID database is not used in a manner that can hurt the citizens either accidentally or through mission creep with unintended consequences. It’s worth thinking about what could go wrong. The solution What if we could have a UID that was never inter-linkable across users, but yet at the same time uniquely linked to the person through biometrics? The answer is we can, through the use of not a single UID, but a base UID (like we have today) plus modifications per user (if not per use). Instead of, say, MNREGA using the 12-digit number like today, each authorised user of the system (such as MNREGA, a bank, and so on) would get a modified (longer) number that is cryptographically generated to be unique but based on the base UID number in such a way that it could be proven to be functionally the same. Technologically, this would use a one-way hash that would be irreversible so that the longer number or code couldn’t reveal the base UID number. The benefits of this would be twofold. First, a corporation or other user could not create a linked database for profiling — they would all have different UID+ numbers. Second, to even get the UID+, the cryptographic process could be restricted to authorised users. This way, we could prevent the UID becoming a casual identifier. For instance, in the U.S., the social security number morphs into something required by the cable TV operator when you raise a service complaint! Of course, in India we risk a similar link/identifier — our mobile number. This same concept of separation applies to security from an Indian government-citizen perspective. Given that Indian and global private technology companies are inevitably involved, breaking up the data (analogous to the UID versus UID+), where it’s stored, broken up, and so on can improve security. From UID to UID+ One has to get the technology right for any programme, but its long-term success depends on people wanting it. Even if due to misinformation, perceptions matter. Recall how the U.S. nuclear power industry was effectively stalled even before the Three Mile Island accident due to a combination of secrecy, arrogance, and “trust us” instead of engagement and communication. The proposed update of UID to a UID+ system can address many of the concerns, and its roll-out need not be viewed as a failure of the original system but simply an update. The next step should be an analysis of how it can be done without disrupting the existing UID database(s). The good news is almost anything is feasible, computationally. We simply need to update our mindset of a Unique ID — there can be many such unique numbers, just like many people now have multiple and even disposable email addresses. There will be a small overhead for such designs, including one-time update costs for those who are already using the current UID number, but this is a worthwhile investment for something meant to last more than a citizen’s lifetime. (Rahul Tongia is a Fellow at Brookings India, and Adjunct Professor at Carnegie Mellon University. All views are personal.) |