New Delhi, May 6: The government on Wednesday said no data or security breach has been identified in Aarogya Setu after an ethical hacker raised concerns about a potential security issue in the app.
The app is the government's mobile application for contact tracing and disseminating medical advisories to users in order to contain the spread of coronavirus.
On Tuesday, a French hacker and cyber security expert Elliot Alderson had claimed that "a security issue has been found" in the app and that "privacy of 90 million Indians is at stake".
Dismissing the claims, the government said "no personal information of any user has been proven to be at risk by this ethical hacker".
"We are continuously testing and upgrading our systems. Team Aarogya Setu assures everyone that no data or security breach has been identified," the government said through the app’s Twitter handle.
The tweet gave point-by-point clarification on the red flags raised by the hacker.
"We discussed with the hacker and were made aware of the following... the app fetches user location on a few occasions," it said, but added that this was by design and is clearly detailed in the privacy policy.
The app fetches users’ location and stores on the server in a secure, encrypted, anonymised manner - at the time of registration, at the time of self assessment, when users submit their contact tracing data voluntary through the app or when it fetches the contact tracing data of users after they have turned COVID-19 positive, it said.
On another issue that users can get COVID-19 stats displayed on the home screen by changing the radius and latitude-longitude using a script, Aarogya Setu said that all this information is already public for all locations and hence does not compromise on any personal or sensitive data.
"We thank the ethical hacker on engaging with us. We encourage any users who identify a vulnerability to inform us immediately...," it said.
Responding to Aarogya Setu's clarification, Alderson tweeted, "I will come back to you tomorrow".
Comments
The day is not too long to fight for Muslim Freedom/Indipendent - India will FIRE....
That means bakht indian are easily fooled by their cheddi leaders from knowing the TRUTH of WORSHIPING ONE GOD... (NA TASYA PRATIMA ASTI) and these cheddis very easily CONTROL these IGNOrANTS of their GOD given LIFE and BLIND them from understanding their own religion .... Swami AGNIVESH is telling the TRUTH but cheddis blinded the Bhakts so shakuningly that they ignored truth and and stand with the cheddis cos of their religious IGNORANT... Learn from AGNIWESH, cow is not your mother or God its an ANIMAL created by ONE MERCIFUL GOD for human sustenance thru milk or meat... Human beings are an intelligent creation of GOD, if they dont try to know this ONE GOD who created all that exists, then they are really easily FOOLED by the evils of the Society. Wake up guys dont be FOOLS of our time
Yea there is no wonder if one day may afgan talaban enters india to sacrifice their life to protect muslims from crime of saffron talaban killings of innocent muslims.
Well said Mr. Taroor. You are totally right. Even its dung has value also.
Safer to be 'a ugly than a wife of Shashi Tharoor: Sunanda Pushkar
Add new comment