These are the privacy issues in Aarogya Setu, India's Covid-19 tracker app, alleged by French hacker Elliot Alderson

Advertisement
These are the privacy issues in Aarogya Setu, India's Covid-19 tracker app, alleged by French hacker Elliot Alderson
The Aarogya Setu app.Rounak Jain/Business Insider India
  • Elliot Alderson has claimed that the Aarogya Setu app allows users to find out who is sick in a particular area.
  • He has also contradicted the Aarogya Setu team’s claim that bulk calls to the API are not possible.
A French ethical hacker who goes with the alias "Elliot Alderson" earlier claimed that he found security and privacy issues in India’s Covid-19 tracker app Arogya Setu. This was denied by the Aarogya Setu team and they said that the app is secure.

After this, Alderson has come up with a post highlighting the issues found by him in the Aarogya Setu app.

App allows users to access internal files

In April, Alderson found that the WebViewActivity allowed users to access internal files of the app by using commands as there was no host validation. However, the issue has now been fixed.
Advertisement

Aarogya Setu allows you to find out who is sick

The next issue found by Alderson is that it is possible to modify the user’s location to find out who is sick in a particular area. While the app allows users to change the radius of the area between 500m, 1km, 2km, 5km or 10km, Alderson was able to change it to 100km.

He added that this flaw could allow anyone to find out who is sick in a particular area.

Advertisement

“Thanks to this endpoint an attacker can know who is infected anywhere in India, in the area of his choice. I can know if my neighbour is sick for example. Sounds like a privacy issue for me…” said Alderson.

However, local governments have been publishing information about Covid-19 patients to alert the people who may have come in contact with them, so this may not be a very big issue.

Alderson claims bulk calls to the API are possible

The Aarogya Setu team in its earlier response to Alderson’s claims had said that bulk calls to the API are not possible as it is behind a Web Application firewall. However, Alderson has now claimed that bulk calls are possible, and he spent an entire day sending bulk calls.
Advertisement

See also:

Aarogya Setu denies privacy breach, contradicts ethical hacker’s claims

Stranded Indians landing in country will have to register for COVID-19 'Aarogya Setu' app: MHA

COVID-19: Smartphone without 'Aarogya Setu' app will draw punishment for user in Gautam Buddh Nagar
{{}}