Elliot Alderson: The ethical hacker who exposed Aadhaar's security flaws

A few weeks ago, French security researcher Baptiste Robert, who is better known by his Twitter username Elliot Alderson, hacked into the Aadhaar app within a minute and reportedly gained access to 22,000 Aadhaar card details. This was not the first government platform he broke into. Who is Alderson and why has he been tearing apart Indian web portals?
Alderson is a French security expert who is a network and telecommunications engineer by profession. He claims to have no ulterior motive behind his revelations other than highlighting serious security vulnerabilities so that they can be patched at the earliest. To be transparent about the whole process, Alderson openly communicates with the concerned organizations on Twitter, and often publicly posts DM conversations with them.
The French developer draws inspiration from renowned whistleblower Edward Snowden. "By nature, I'm curious and I like to understand how things are working which often leads by finding security flaws," he said. The 28-year-old cybersecurity expert does not have any sort of team behind him and follows a "standard process" to find security flaws.
Initially, Alderson had found a loophole in the Aadhaar's Android application which revealed that users' biometric data was being saved in a local database by app developers whose password wasn't too difficult to obtain. "These cards can be found on the internet. They are not on the UIDAI server. Everything is public, no hack is required," he said.
How to bypass the password protection of the official #Aadhaar #android #app in 1 minute.
— Elliot Alderson (@fs0c131y) March 13, 2018
For this attack, the attacker need a physical access to the phone, rooted phone is not needed and yes this is the latest version of the app.
cc @uidai @ceo_uidai pic.twitter.com/7aZ0fvr0Wv
On February 25, Alderson accessed the database of the Telangana government's benefit disbursement portal TSPost. This contained personal information of 56 lakh beneficiaries of the National Rural Employment Guarantee scheme and 40 lakh beneficiaries of social security pensions. He had also earlier highlighted that Paytm was seeking root access to users' devices, after which the mobile payments company removed the root request.
Previously, Alderson has discovered vulnerabilities in the online portals of Punjab Police, Indian Postal Service, Apollo Hospitals, and BSNL. He says that even though it is "complicated," it is not entirely impossible to achieve almost 100% privacy online. Interestingly, his username has been inspired by a character by the same name from the television series Mr Robot, who is also a vigilante hacker.
When you create a profile in the official @narendramodi #Android app, all your device info (OS, network type, Carrier …) and personal data (email, photo, gender, name, …) are send without your consent to a third-party domain called https://t.co/N3zA3QeNZO. pic.twitter.com/Vey3OP6hcf
— Elliot Alderson (@fs0c131y) March 23, 2018