Mainstream, VOL XLIX, No 41, October 1, 2011

Letter to Nandan Nilekani

Wednesday 5 October 2011, by S G Vombatkere

I have sent you (by e-mail to nandan.nilekani an article on the system considerations and security risks of the UID Aadhaar project, requesting your comments, but have not been fortunate enough to receive a response so far. I will keep hoping that you will do me the courtesy of at least an acknowledgement, if not a response. I am attaching the article again for your convenience.

Further to my earlier communication, I note with alarm that Google has admitted to handing over user data stored in its European data banks to the USA’s intelligence agencies, since it is a company registered in the USA and is obliged to do so according to the US Patriot Act. You would also be aware that Gordon Frazer, Microsoft UK’s Managing Director, made news headlines recently when he admitted that Microsoft can be compelled to share data with the US Government regardless of where it is hosted in the world. Further, the firms can be forced to keep quiet about it in order to avoid exposing active investigations that may alert those targeted by the probes.

As shown in the UIDAI website, contracts for collaboration have been awarded by UIDAI to various firms, and some of them are foreign firms. I write with particular reference to M/s Ernst and Young which has been awarded the contract for setting up the Central ID Data Repository (CIDR) and selection of Managed Service Provider (MSP). Also, M/s L-1 Identity Solutions and M/s Accenture Services have been awarded contracts when both these firms are connected with the intelligence services in the USA. It is my fear that intelligence-trained indivi-duals in these firms will gain access to information in the CIDR or the route to access that information. This will facilitate a cyber strike by an unfriendly nation or even a terrorist organisation. There is little use arguing that we will have the tightest possible security, because our security is rather poor, considering that the PMO’s system has been hacked (possibly by the Chinese) and recently Union Finance Minister Pranab Mukherjee’s office was bugged.

Creating an all-eggs-in-one-basket CIDR there-fore appears risky in a lax security atmosphere. It is puzzling how such security risks have not been taken into account. Some members of the Parliamentary Standing Committee on Finance are only questioning the huge expenditures on the UID project. The security issues can only be addressed in the national interest by a national body that has experience in the cyber security field.

You would be aware of the matter of the Indian Institute of Science (IISc), Bangalore, signing an agreement to set up a telecom laboratory with Huawei Technologies which has links with the Chinese Government and PLA. As reported in the media, this was objected by the Indian intelligence community, which had expressed prior disapproval. That the same Indian intelli-gence agencies are silent on awarding contracts to US firms that have close links with the USA’s intelligence agencies for directly handling high security systems of the UIDAI is puzzling for any thinking Indian. It would be well to repeat that any or all information that these firms obtain legally or illegally would be available to the USA’s intelligence agencies by the authority of the Patriot Act, and what is more, the firm can be forced by the same law to remain silent on whether or what information has been passed on.

I earnestly request you to immediately respond to these genuine concerns regarding national security and safety.

Yours sincerely,

Sudhir Vombatkere (Retired Major General)

475, 7th Main Road, Vijayanagar 1st Stage, Mysore-570017

Tel: 0821-2515187 / E-mail:

S.G.Vombatkere retired as a Major General after 35 years in the Indian military. He is engaged in voluntary social work, and is member of the National Alliance of People’s Movements (NAPM) and People’s Union for Civil Liberties (PUCL). As Adjunct Associate Professor of the University of Iowa, USA, he coordinates and lectures a course on Science, Technology and Sustainable Development for under-graduate students from the USA and Canada. He holds a Master of Engineering degree in Structural Engineering from the University of Poona and a Ph.D in civil Structural Dynamics from the IIT, Madras.

