So #COVID19Vaccination has its own app - tech infra management - #CoWIN. #Thread to keep a watch on this. It is *as* important or even more important than @SetuAarogya app Page 45 of https://web.archive.org/web/20210109215951/https://www.mohfw.gov.in/pdf/COVID19VaccineOG111Chapter16.pdf CoVID-19 Vaccine Intelligence Network (Co-WIN): The Digital Platform
High level overview of CoWIN- VIN operations.
https://www.cowin.gov.in/home  - is the website and https://app.cowin.gov.in/home  is the app backend for CoWIN beneficiary registration and AEFI management https://twitter.com/logic/status/1350694241886879744
https://web.archive.org/web/20210117080551/https://pib.gov.in/PressReleasePage.aspx?PRID=1686350 - Note the word - permission / not consent. Lets get back to this in a bit
Back to the app - The #PrivacyPolicy of the #CowinApp is https://ndhm.gov.in/health_management_policy - Why is Privacy policy of Vaccination app linked to national digital health missions' health data management policy ?
The said policy mentions "Voluntary" use of Aadhaar for creation of Health ID. Assuming this is the privacy policy of the app and going by various other communication from @MoHFW_INDIA - Aadhaar is one of the ID and not the only ID for vaccination.
But what happens you are one of those students under the age of 18 or those poor folks in rural India who have #Aadhaar as only ID Proof ?

The individual should still be provided option to create the health ID / not right ? That's what the policy above said no ?
The app description says - #Aadhaar Authentication is to ensure de-duplication.

If you have forgot Aadhaar lingo -
Authentication - gives only Yes / No response based on biometric / OTP / demographic input.
#eKYC - A copy of your personal data in #Aadhaar is shared to app
When you share #Aadhaar as a proof - the app (available with vaccine administrators) - will perform #Aadhaar biometric authentication (Also most of the said section of population might not have mobile phones as well) ... But is it doing biometric authentication (Yes/No) OR eKYC?
How do we know if any #Aadhaar biometric authentication call is #Auth / #eKYC ? From UIDAI's API documentation - 'wadh' parameter in PID block(where fingerprint is held) is the parameter that differentiates.

WADH should be empty for auth, filled for eKYC
https://uidai.gov.in/images/resource/aadhaar_ekyc_api_2_5.pdf
When you reverse the #CowinApp you will see wadh parameter is 'hardcoded'.So @MoHFW_INDIA is doing #eKYC instead of plain authentication.This also is a mass bulk subsidy to @UIDAI which gets tax free money for each eKYC. MoHFW now has your data in #Aadhaar & can create #HealthID
Why does @MoHFW_INDIA not give option to people not to create #HealthID and 'hardcodes' wadh to make every authentication #eKYC ?

Because someone has taught them the way to 'hardcoding' fascism in code is far tougher to untangle than specifying in files https://twitter.com/logic/status/1221717072939376640
This is not to say - don't get vaccinated. By all means do - but care about the your and others' personal health data now longitudinally collected WITHOUT your consent to create the #healthid by #CowinApp when there is no #DataProtectionLaw. Let that sink in. #
We will track the damn app - Thread https://twitter.com/logic/status/1350804961433513992
Who is behind #CowinApp - @UNDP_India
You can follow @logic.
Tip: mention @twtextapp on a Twitter thread with the keyword “unroll” to get a link to it.

Latest Threads Unrolled:

By continuing to use the site, you are consenting to the use of cookies as explained in our Cookie Policy to improve your experience.