UIDAI Launches Bug Bounty Programme to Further Strengthen Aadhaar Security

1. At a Glance

2. Why in the News

3. Background & Evolution

4. Core Static Facts

5. Multi-Dimensional Analysis

Scientific / Technological - Crowdsources offensive security testing — uncovers flaws in-house audits and CERT-In empanelled auditors may miss [S1][S6]. - Targets web, mobile and crypto-attestation (Secure QR Code) layers — covers full stack of resident-facing Aadhaar services [S1].

Legal / Constitutional - Operates within the Aadhaar Act 2016 (Section 28 — security & confidentiality of identity information) and Digital Personal Data Protection (DPDP) Act 2023 duties on data fiduciaries. - Reinforces compliance with Puttaswamy (2017) privacy judgment by hardening technical safeguards demanded as "reasonable security".

Governance / Ethical - Closed-panel model balances transparency vs. risk — limits exposure of critical national infrastructure while still tapping external expertise [S1]. - Aligns with CERT-In's Cyber Crisis Management Plan and the National Cyber Security Policy 2013 ecosystem [S6].

Administrative - Builds an institutional pipeline of vetted researchers UIDAI can re-engage; reduces reliance solely on empanelled auditors. - Tiered reward structure incentivises focus on high-impact bugs (auth bypass, data exposure) over cosmetic issues [S2].

6. Recent Developments (last 12-18 months)

7. Prelims Hooks

8. Mains Relevance

9. Related Topics to Study Next

10. Common Errors / Trap Areas

11. Sources