News Security

Rajasthan Government Fixes Security Flaws In Jan Aadhaar Portal

Rajasthan Government Fixes Security Flaws In Jan Aadhaar Portal
The Jan Aadhaar initiative, launched in 2019, aimed to provide a single identifier to individuals and families in Rajasthan, facilitating their access to various welfare schemes offered by the state government

Rajasthan state government has successfully addressed security concerns that were posing a risk to the personal data of millions of residents. The vulnerabilities, discovered in the state’s Jan Aadhaar website, exposed sensitive documents and personal information belonging to registrants of the program.

The Jan Aadhaar initiative, launched in 2019, aimed to provide a single identifier to individuals and families in Rajasthan, facilitating their access to various welfare schemes offered by the state government. However, the presence of bugs on the website compromised the security of this sensitive information.

Security researcher Viktor Markopoulos, affiliated with cybersecurity firm CloudDefense.ai, uncovered these vulnerabilities and sought assistance from TechCrunch to address the issue with the authorities. Markopoulos identified two main bugs in the Jan Aadhaar portal. One flaw allowed unauthorised access to personal documents and information by using a registrant’s phone number, while the other bug enabled the retrieval of sensitive data due to inadequate validation of one-time passwords.

Rajasthan government’s Jan Aadhaar Authority’s subsequent engagement with the Indian Computer Emergency Response Team (CERT-In), the vulnerabilities were promptly rectified. CERT-In confirmed that the bugs had been fixed, ensuring the protection of users’ data on the platform.

“This is to inform you that we have received a response from the concerned authority that the reported vulnerability has been fixed,” the agency said. The researcher also confirmed the fix.

The successful resolution of these security concerns is a crucial step in safeguarding the privacy and personal information of the over 78 million individual registrants and 20 million families enrolled in the Jan Aadhaar program. By addressing these vulnerabilities, the state government has demonstrated its commitment to ensuring the security and integrity of its welfare schemes, providing reassurance to residents across Rajasthan.

This incident highlights the importance of proactive cybersecurity measures in safeguarding sensitive data, particularly in government-run programs aimed at serving the public. It underscores the need for continuous monitoring and timely action to address vulnerabilities and protect user information from potential breaches.

Leave a Reply

Your email address will not be published. Required fields are marked *