advertisement
Millions of Indians woke up on Saturday, 27 October, to a lengthy apology published in national newspapers and issued to “the People of India” by Gemalto, a global digital security agency.
In an unprecedented move, Gemalto CEO, Phillip Valle, tendered an unqualified apology on Saturday, for publishing a global Breach Level Index report on 15 October that had claimed 1.2 billion Aadhaar records were compromised in a breach in the first half of 2018.
However, in retracting its report hastily and offering a profuse apology, Gemalto appears to have withheld one key fact – UIDAI, the Aadhaar issuing body, is a client of Gemalto.
In the interest of full disclosure, many have pointed out, that this omission is conspicuous by its absence.
This is the same question Gemalto asks rhetorically on its official website. In a post, last updated on 1 July, 2018, a sub-header asks ‘So where does Gemalto fit into this story?’
It proceeds to answer this questions stating that “in the search for biometric solutions capable of capturing fingerprints and iris scans from over billion people, the Indian authorities turned in particular to 3M Cogent – now a Gemalto Company”.
Later, when we authenticated ourselves using our fingerprints to get a SIM card, we did so using a Gemalto machine.
The global Breach Level Index report originally published on 15 October and the one re-published on 23 October have a number of crucial differences, on account of the removal of 1.2 billion Aadhaar data breach. The statistics pertain to the first half of 2018.
In its report Gemalto had attributed its numbers to a report by The Tribune in January 2018, which had exposed an anonymous service that allowed anyone with Rs 500 to access all 1.2 billion Indian citizens’ personal information.
Anyone who read the apology on Saturday would have been struck by the profuseness of its language. Phillip Vallee, Gemalto CEO, addressed his apology, not to the Government of India or to the UIDAI, but to “the people of India”.
He opens his apology by terming the BLI report as “inaccurate” and the news article about the Aadhaar data breach as “unverified”. It goes on to state the company is ‘deeply regretful’ and that by publishing its report “Gemalto has caused prejudices in the minds of the general public at large against Aadhaar which we deeply regret.”
The report further states that the Dutch company is launching an internal investigation and that they have found no evidence of any Aadhaar data being breached.
“Hiding the UIDAI Gemalto relationship while issuing the apology clearly shows Gemalto was under pressure to do this,” said Srinivas Kodali, an independent security researcher. Anivar Aravind, a security researcher, added that “there is nothing to apologize if they are doing their research properly. The apology is to save their business.”
A quick glance at how Gemalto’s website describes Aadhaar provides a glimpse into a client-customer relationship.
A post titled Aadhaar Project in India: 2018 facts and trends uses hyperbole to describe the project. The post is replete with phrases such as ‘Aadhaar – the word on everyone’s lips in India’ and describes ‘Aadhaar’ as ‘word of the year’. It also goes on to explain why ‘Aadhaar has no parallel’.
The same post also specifies the equipment it sells to UIDAI.
Twitter users also pointed towards the fact that Gemalto is in the process of a merger with Thales, a French aerospace and defence technology company, within the first quarter of 2019.
Why is this relevant?
Because Rafale fighter jets’ “on-board electronics systems, equipment and sensors are supplied by Thales and account for about 25 per cent of the plane’s value,” says Thales’ official website.
The Quint has reached out to Gemalto and UIDAI for comments and will be updated with their responses when/if they arrive.
(At The Quint, we question everything. Play an active role in shaping our journalism by becoming a member today.)