Topic 15 of 21
GS Paper 3 Digital Governance & Cybersecurity Digital Governance & Cybersecurity

What happens when a "fix" makes a vulnerability harder to see, not gone?

Summary

Independent security researchers found architectural flaws in UMANG, the government's 2,400-service portal, exposing EPFO account numbers, LPG booking data and Aadhaar numbers, some stored in plain text despite the Aadhaar Act's ban on this.

The IT Ministry's initial fix left the flaws active and researchers say it made the problem harder to detect rather than closing it, raising sharper questions about how India secures centralised citizen-data platforms. Reconsidered approach and abandoned unnecessary tool usage Reconsidered approach and abandoned unnecessary tool usage

WHY IN NEWS FOR UPSC & STATE PCS

Security researchers Akshay C.S. and Viral Vaghela disclosed that UMANG's architecture exposes EPFO UANs, LPG booking details and Aadhaar numbers, some in plain text despite this being barred by the Aadhaar Act, 2016. The IT Ministry's initial response, according to a third independent reviewer, did not close the flaw but made it harder to detect, while the EPFO portal itself was pulled down for "migration" soon after disclosure.

Standard News

A Fix That Hides a Flaw Isn't a Fix Here's what's actually happening: when the government's response to a security disclosure is examined, the real story isn't that UMANG had vulnerabilities - most large digital systems eventually do.

The real story is what "fixing" it actually meant and what that reveals about how a system built for convenience handles risk. The Mechanism That Actually Broke UMANG works as an aggregator - a single portal that talks to hundreds of separate government databases (EPFO, LPG providers, Aadhaar-linked services) on a citizen's behalf, through APIs, which are essentially the messaging channels software systems use to request and hand over data.

The researchers found the problem wasn't in one weak API - it was structural. As one researcher put it, "almost everything is broken by design." That distinction matters: a single broken door can be locked. An architecture where the doors were never built to be secure has to be rebuilt, not patched.

When the IT Ministry responded, it encrypted APIs that had been sending data in plain text. That sounds like a fix. But according to the independent reviewer who examined it afterward, the encryption used was weak enough to be cracked with a simple workaround - meaning the flaw wasn't closed, it was made less visible.

That's the difference between security and obscurity: one makes the door harder to open, the other just paints it so you can't see the hinges. Why Centralisation Raises the Stakes The EPFO module alone recorded over 40 crore transactions in three months.

When a single portal aggregates that much traffic across thousands of services, a flaw in the shared architecture doesn't expose one database - it potentially exposes all of them at once. That's the trade-off centralised e-governance always makes: enormous convenience, concentrated in a single point of failure.

UMANG didn't create this trade-off; it's inherent to any "one app for everything" model. But this disclosure shows what happens when the underlying plumbing isn't held to the same rigour as the interface built on top of it.

Where India Actually Stands India has built one of the world's largest digital governance stacks and UMANG is central to it. That scale is real and internationally notable. What this episode reveals is a gap between deploying digital infrastructure fast and securing it with matching seriousness - a gap that shows up specifically at the moment a flaw is disclosed and the fix has to actually close it, not just quiet it.

For the exam, the sharper insight isn't "government portal had a bug." It's that centralisation multiplies the consequence of any single architectural weakness and a response that merely obscures a flaw rather than eliminating it leaves the actual risk untouched - just less visible to the next researcher who goes looking.

Quick Facts

  • UMANG hosts over 2,400 Union and State government services. EPFO module used over 40 crore times in the past three months. Data exposed: EPFO UANs, LPG booking details, Aadhaar numbers. Flaws reported to MeitY and CERT-In. Aadhaar Act, 2016 bars plain-text storage of Aadhaar numbers.

Beyond The Headlines
GS Paper 3 Digital Governance & Cybersecurity

Connect the dots for your UPSC preparation.

Standard news covers the event. Log in to read our comprehensive analysis and uncover the hidden constitutional, structural, and ethical dimensions of this topic:

1

The website answer explains why encrypting an API isn't the same as securing it - Deep Analysis goes further into what "security by obscurity" actually means as a systemic governance failure and what a genuine fix would require across UMANG's 2,400 dependent services. Premium also carries the full Case Study on centralised e-governance as a single point of failure, a ready Mains PYQ framework built directly around India's 2018 data-security question and a Directive Word breakdown for structuring a strengths-and-weaknesses answer on data protection.

Included in this analysis

Deep Analysis Sharpens your Mains-level understanding.
8 Languages Read the news comfortably in your language.
PYQ Connection Direct connection with previous year Mains questions.
Expected Questions Possible upcoming questions for Prelims & Mains.
Daily Evaluation Daily Prelims test, plus category-wise Mains evaluation.
Mentor Observation Daily, topic-wise expert feedback on your tests.
Value Additions Important Case Studies and daily Vocab Word.

Join thousands of aspirants analyzing the news deeply.

Log In to Read Full Article

More from 14 Jul 2026

Short titles by category — open any story to read it fully.