2. In the #Aadhaar #Android app they defined a flag called isLogger which is set to false by defaultpic.twitter.com/PPo16zVLEI
You can add location information to your Tweets, such as your city or precise location, from the web and via third-party applications. You always have the option to delete your Tweet location history. Learn more
2. In the #Aadhaar #Android app they defined a flag called isLogger which is set to false by defaultpic.twitter.com/PPo16zVLEI
3. If the flag isLogger is equal to true, every time the writeLog method is called a log file is created in /sdcard/mAadhaar/pic.twitter.com/CP18EYdDsE
4. The writeLog method is called a lot in the code. They log: - request url, method, body - decoded response - setting data - profile data - ...pic.twitter.com/d99OWcQ665
5. To enable the logging you just have to:
- unpack the #Aadhaar #Android app with #apktool
- change v1 to v0 in one line
- repack the app with apktool
- resign the apppic.twitter.com/wV5mcgHF6w
6. Install the app, login and voila! You can find the log file in /sdcard/mAadhaar/pic.twitter.com/J20Q7yd7Gv
7. If an attacker repack the app with the logging activated and distribute it, all your #Aadhaar data will be available on the sdcard in clear. After that, it super easy for the attacker to upload this log file to his server.
8. So @UIDAI and @KhoslaLabs, can you ask to your interns...sorry I meant: can you ask to your developers to remove this "debug feature" of the APK?
Hey.. are you real Elliot of Mr. Robot .?
Looks like YOU'RE 
Why is the #SupremeCourt unable to stop #Aadhar from becoming one of the greatest disasters India is ever going to witness?
Haven't you seen the new. I guess the Aadhaar case is already rigged against us. 4 Senior Judges of SC saying that allocation of important cases by CJI is highly suspicious indicates that the Aadhaar case is decided long back.....
God mode ,Elliot! So there is a major flaw with mAadhar and these folks are planning of Virtual IDS on top of it, by using mAadhar as one of the tools.
@fs0c131y Any thoughts about this if this will work...?
Skeptical bro. Urban areas might have an ease but it'd be a hurdle for ppl in rural areas & remote places to obtain it as and when required as they have to commute to nrst Aadhar centre.
After all the retweets I have done to your tweets, I might end up with a FIR against me!

You must probably do the coding for @UIDAI .. 
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.