UMANG
Portal
Prelims:
Science & Technology, Governance
Mains:
GS Paper II-Governance, GS Paper III-Science
& Technology, Internal Security
Current
relevance:
Security researchers
reported multiple vulnerabilities in the UMANG (Unified Mobile
Application for New-age Governance) portal, exposing sensitive user
information such as EPFO UANs, LPG booking details, and Aadhaar numbers.
At a glance:
Security Flaws:
1. Researchers
identified multiple security flaws in the UMANG portal,
potentially exposing the personal data of millions of users.
2. The
reported vulnerabilities exposed information such as: EPFO Universal Account
Numbers (UANs), LPG cylinder booking details, Aadhaar numbers stored across
several services.
3. Government
Response:
MeitY acknowledged the security vulnerabilities and
stated that corrective and preventive measures, including the encryption
of sensitive information in the affected APIs, are being implemented.
4. Role of
CERT-In:
The vulnerabilities were reported to the Indian Computer Emergency
Response Team (CERT-In), the national nodal agency that assists
organisations in identifying and mitigating cybersecurity threats.
About UMANG Portal:
1. Unified
Mobile Application for New-age Governance (UMANG), developed by the
Ministry of Electronics and Information Technology (MeitY) and the
National e-Governance Division (NeGD).
2. It provides
a single platform to access Central, State, and local government
services through a mobile application and web portal.
3. The
platform offers services such as EPFO, PAN, Aadhaar-linked services,
DigiLocker, Passport, gas booking, utility bill payments, healthcare,
education, and taxation.
4. It is
available in multiple Indian languages, making government services more
accessible.
5. Supports
the vision of Digital India by promoting paperless, faceless, and
cashless governance.
6. It enables single
sign-on (SSO), allowing users to access multiple government services with
one login.
7. The platform is accessible through Android, iOS, KaiOS, and the UMANG web portal.
Source:
THE HINDU - https://www.thehindu.com/sci-tech/technology/umang-portal-flaws-exposed-user-data-across-hundreds-of-services-researchers-find/article71217208.ece