These are the privacy issues in Aarogya Setu, India's Covid-19 tracker app, alleged by French hacker Elliot Alderson
Rounak Jain/Business Insider India
Elliot Aldersonhas claimed that the Aarogya Setuapp allows users to find out who is sick in a particular area.
- He has also contradicted the Aarogya Setu team’s claim that bulk calls to the API are not possible.
After this, Alderson has come up with a post highlighting the issues found by him in the Aarogya Setu app.
App allows users to access internal files
In April, Alderson found that the WebViewActivity allowed users to access internal files of the app by using commands as there was no host validation. However, the issue has now been fixed.
Aarogya Setu allows you to find out who is sick
The next issue found by Alderson is that it is possible to modify the user’s location to find out who is sick in a particular area. While the app allows users to change the radius of the area between 500m, 1km, 2km, 5km or 10km, Alderson was able to change it to 100km.
He added that this flaw could allow anyone to find out who is sick in a particular area.
“Thanks to this endpoint an attacker can know who is infected anywhere in India, in the area of his choice. I can know if my neighbour is sick for example. Sounds like a privacy issue for me…” said Alderson.
However, local governments have been publishing information about Covid-19 patients to alert the people who may have come in contact with them, so this may not be a very big issue.
Alderson claims bulk calls to the API are possible
The Aarogya Setu team in its earlier response to Alderson’s claims had said that bulk calls to the API are not possible as it is behind a Web Application firewall. However, Alderson has now claimed that bulk calls are possible, and he spent an entire day sending bulk calls.
Aarogya Setu denies privacy breach, contradicts ethical hacker’s claims
Stranded Indians landing in country will have to register for COVID-19 'Aarogya Setu' app: MHA
COVID-19: Smartphone without 'Aarogya Setu' app will draw punishment for user in Gautam Buddh Nagar
Popular on BI
- Paras Defence and Space Technologies IPO: Here’s how to check allotment status
- Google’s birthday: Here's a look at the significant milestones in Google's 23-year history
- Dolce & Gabbana want to make Elon Musk the ‘King of Crypto’ — but only if he can shell out more than ₹3.8 crore for the ‘Doge Crown’
- Buy biodegradable sanitary pads for women in India
- Best baby booster seat in India
- Amazon-backed Capital Float plans to go big in the buy now, pay later segment; raises $50 million
- Where Indians work — seven charts that show you the employment map of the world’s sixth largest economy
- Alibaba, Binance, Sparkpool and other companies are scrambling to avoid any heat from China over crypto concerns