Discussion on Aadhaar Based Bank Frauds!

TEUser2K1

Skilled
Jul 16, 2007
1,124
820
202
Mumbai
@iosoft If SIM card PIN is on SIM packing, most people may not have it.
As mentioned by Airtel guide, if someone types wrong PIN multiple times phone may get locked.
Probably what happened to @Arjun
 

iosoft

PC enthusiast since MS DOS 5
Skilled
Dec 30, 2005
1,411
151
153
Kolkata, India
www.gigahertz.net.in
I dont know, i will go to the airtel store and get it checked.
sorry to hear that. hope it gets fixed soon.
@iosoft If SIM card PIN is on SIM packing, most people may not have it.
As mentioned by Airtel guide, if someone types wrong PIN multiple times phone may get locked.
Probably what happened to @Arjun
Honestly, I didn't know that.
I locked mine, my wife, my mother, my sister, my brother-in-law without any issue. (Artel, Jio, Vi, BSNL)
 
  • Like
Reactions: TEUser2K1

calvin1719

Mostly harmless.
Adept
Jun 21, 2020
875
1,021
208
Has the Aadhar website been having issues for other people? Been trying to lock biometrics for a few days now, it just keeps saying couldn't connect to the backend.
Did it via the app finally, and even that took 2-3 tries.
 
  • Like
Reactions: krisappu

TEUser2K1

Skilled
Jul 16, 2007
1,124
820
202
Mumbai
Biometric locking and unlocking have always been an issue from the beginning of time from when that feature that introduced.
So, nobody is alone, take your own due diligence. Because if you suddenly need it and if the app and web crap it out, you will be in difficult situation.
 

LinkdJay

Recruit
Aug 28, 2023
21
16
6
Has the Aadhar website been having issues for other people? Been trying to lock biometrics for a few days now, it just keeps saying couldn't connect to the backend.
Did it via the app finally, and even that took 2-3 tries.
Both the website and the app have been crapping out for the past 4 days as far as I am concerned. The website keeps giving out the cannot connect to backend error. As for the app every time I try to lock my biometric and input the OTP I get a pop-up notification that says my biometric has been locked, but when I check again in the 'My Aadhaar' tab my biometric is clearly not locked.
 
  • Like
Reactions: krisappu

calvin1719

Mostly harmless.
Adept
Jun 21, 2020
875
1,021
208
but when I check again in the 'My Aadhaar' tab my biometric is clearly not locked.
Happens for me as well, but if you click biometric lock it shows the status as locked. On the my aadhar screen it initially shows the lock icon for biometric as open, but that seems to be incorrect as it shows the correct status on clicking into it.
 

tearphones

Disciple
May 6, 2023
77
113
48
Did any of the news article actually address the details of the attack?
  1. How can just the image of a fingerprint be used for aadhaar authentication without some serious silicone 3D printing or something like that?
  2. Which merchant processed the AEPS? Why have those merchants not been penalized?
  3. How did the crooks obtain the images of the fingerprint in the first place?
 
  • Like
Reactions: krisappu and iosoft

LinkdJay

Recruit
Aug 28, 2023
21
16
6
Happens for me as well, but if you click biometric lock it shows the status as locked. On the my aadhar screen it initially shows the lock icon for biometric as open, but that seems to be incorrect as it shows the correct status on clicking into it.
Oh no. In my case my biometric is still unlocked, but the app keeps giving out false notifications.

Step1 I go to My Aadhaar tab of app> Step2 Tap on biometric lock option> Syep3 enter the captcha> Step4 wait for otp> Step5 Enter the otp> Step6 Get fake notification from app that my biometric has been locked> Step7 Completely close the app> Step8 Open the app and go to myadhaar and see that biometric is unlocked > Repeat step2 to Step8
I have done this at least 18 times now ( counting all the Aadhaar OTP emails from last 3 days).

Strangely enough, I was able to lock my dad's biometric after only 6 attempts on his phone. The first 5 attempts I got the same fake success notification. I know that his biometrics have been properly locked because now if I tap on biometric lock/unlock (the lock icon is red and locked) then the next page I get clearly mentions that "your biometric is locked" along with the options to unlock, and disable.
 

LinkdJay

Recruit
Aug 28, 2023
21
16
6
  1. How did the crooks obtain the images of the fingerprint in the first place?
Apparently from state govt websites and land registries. Recently read some news articles:
https://indianexpress.com/article/c...umb-prints-from-land-registries-7914530/lite/

https://www.thehindu.com/sci-tech/t...eps-abused-cybercriminals/article66842275.ece

https://www.boomlive.in/amp/decode/...hands-of-scammers-pulling-off-aeps-scam-23120

I firmly believe that govt. officials are completely in cahoots with the criminals to pull off this kind of fraudulent activity.
 

TEUser2K1

Skilled
Jul 16, 2007
1,124
820
202
Mumbai
@LinkdJay They should hide fingerprint, signature, pictures, document id /numbers of people when exposing legal documents public.
Now that scammers started exploiting this, they should at least start protecting citizen's privacy and safety.
 

tearphones

Disciple
May 6, 2023
77
113
48
Completely agree with @iosoft, @TEUser2K1 and @LinkdJay: govt. should be more responsible with data. But it is also important not to stop at the first problem we notice and ignore the remaining problems. I am still wondering about the remaining parts of the puzzle: how did they convince the aadhaar system that this stolen picture was a live fingerprint: did they mod some hardware, or did they use silicone transfers? Who was the recipient of the money? Why can't they just trace it simply by going to the point of sale?
 
  • Like
Reactions: iosoft

LinkdJay

Recruit
Aug 28, 2023
21
16
6
Completely agree with @iosoft, @TEUser2K1 and @LinkdJay: govt. should be more responsible with data. But it is also important not to stop at the first problem we notice and ignore the remaining problems. I am still wondering about the remaining parts of the puzzle: how did they convince the aadhaar system that this stolen picture was a live fingerprint: did they mod some hardware, or did they use silicone transfers? Who was the recipient of the money? Why can't they just trace it simply by going to the point of sale?
Furthermore, at least to my knowledge, no govt body, RBI or UIDAI have even acknowledged this blatantly obvious flaw in the system (please correct me if I am wrong about this).
If I was a bigger sceptic then I would say that our govt knowingly kept these flaws & loopholes and are themselves responsible for doing these scams or at the very least the higher ups are quite closely associated with the scammers.
 
  • Like
Reactions: TEUser2K1

TEUser2K1

Skilled
Jul 16, 2007
1,124
820
202
Mumbai
"...It seems anyone can learn how to clone a fingerprint with epoxy putty on YouTube; and anyone can buy an identification card online. Fingerprints can be lifted from digitized property sale deeds. Or, to steal money from bank accounts, one could hack into a mobile app used by small village shops that double up as micro-ATMs for Aadhaar-holders...."





edit: Unfortunate reality is that fraudsters will get control of technology, they are more capable and wiling in taking risks where common man cannot even get legal things legitimately; it's systemic collateral damage in poor country like ours. How to strictly control the same is what need to be checked. People insisting aadhar card details even for silliest of work to get done need to be strictly controlled, for eg., courier companies irks me the most - this must've been made punishable offense, not just illegal.
 
Last edited:

tearphones

Disciple
May 6, 2023
77
113
48
Thanks for the links.

Reading between the lines of the reporting so far, there is still the language like "criminals have been known to use silicone" for fingerprint cloning, but I guess no one will actually know what happened in this particular case until the criminals are caught. What is sad is that we still don't really know the details of how this particular instance of the crime is being conducted.
 
  • Like
Reactions: iosoft

TEUser2K1

Skilled
Jul 16, 2007
1,124
820
202
Mumbai
Moody's questions Aadhaar's reliability; govt rebuffs

 
  • Like
Reactions: tearphones

iosoft

PC enthusiast since MS DOS 5
Skilled
Dec 30, 2005
1,411
151
153
Kolkata, India
www.gigahertz.net.in
9bffd847-38f8-4f12-9b46-44f16821b606b.jpg
 
  • Like
Reactions: tearphones

tearphones

Disciple
May 6, 2023
77
113
48
[picture]
Thank you so much for the article, there're so many interesting things in it:
  • They've arrested the people based on the Customer Service Point machine, which I thought was an obvious way to track people down. Good.
  • They claim that they converted photos of fingerprints into a near-perfect silicone fingerprint with a success rate of 6 - 12%
  • To make this, they used a hard dice and silicone solution. I don't know if this is a mistranslation or a transcription error, but I really don't understand it.
 

iosoft

PC enthusiast since MS DOS 5
Skilled
Dec 30, 2005
1,411
151
153
Kolkata, India
www.gigahertz.net.in
Thank you so much for the article, there're so many interesting things in it:
  • They've arrested the people based on the Customer Service Point machine, which I thought was an obvious way to track people down. Good.
  • They claim that they converted photos of fingerprints into a near-perfect silicone fingerprint with a success rate of 6 - 12%
  • To make this, they used a hard dice and silicone solution. I don't know if this is a mistranslation or a transcription error, but I really don't understand it.
Actually, they (Police) will never revel the actual process for obvious reason :sunglasses: