These are the privacy issues in Aarogya Setu, India's Covid-19 tracker app, alleged by French hacker Elliot Alderson
Rounak Jain/Business Insider India
Elliot Aldersonhas claimed that the Aarogya Setuapp allows users to find out who is sick in a particular area.
- He has also contradicted the Aarogya Setu team’s claim that bulk calls to the API are not possible.
AdvertisementA French ethical hacker who goes with the alias "Elliot Alderson" earlier claimed that he found security and privacy issues in India’s Covid-19 tracker app Arogya Setu. This was denied by the Aarogya Setu team and they said that the app is secure.
After this, Alderson has come up with a post highlighting the issues found by him in the Aarogya Setu app.
App allows users to access internal files
In April, Alderson found that the WebViewActivity allowed users to access internal files of the app by using commands as there was no host validation. However, the issue has now been fixed.
Aarogya Setu allows you to find out who is sick
The next issue found by Alderson is that it is possible to modify the user’s location to find out who is sick in a particular area. While the app allows users to change the radius of the area between 500m, 1km, 2km, 5km or 10km, Alderson was able to change it to 100km.
He added that this flaw could allow anyone to find out who is sick in a particular area.
“Thanks to this endpoint an attacker can know who is infected anywhere in India, in the area of his choice. I can know if my neighbour is sick for example. Sounds like a privacy issue for me…” said Alderson.
However, local governments have been publishing information about Covid-19 patients to alert the people who may have come in contact with them, so this may not be a very big issue.
Alderson claims bulk calls to the API are possible
The Aarogya Setu team in its earlier response to Alderson’s claims had said that bulk calls to the API are not possible as it is behind a Web Application firewall. However, Alderson has now claimed that bulk calls are possible, and he spent an entire day sending bulk calls.
Aarogya Setu denies privacy breach, contradicts ethical hacker’s claims
Stranded Indians landing in country will have to register for COVID-19 'Aarogya Setu' app: MHA
COVID-19: Smartphone without 'Aarogya Setu' app will draw punishment for user in Gautam Buddh Nagar
Popular on BI
- I'm a 56-year-old IT worker who got laid off last year and have been unemployed ever since. I have a hunch I'm not finding work due to ageism. How do I prove it?
- WhatsApp introduces the “Message Yourself” feature, working on voice status updates and more
- DeSantis says Congress should act if Apple follows through on Elon Musk claims and bans Twitter from App Store
- Best refrigerator under ₹15000
- Asus ROG Phone 6 review: A bit more than just gaming
- Fintech unicorn CRED to acquire SaaS startup CreditVidya
- Jio Haptik and CASHe partner to deliver instant credit lines on Whatsapp
- Dharmaj Crop Guard IPO subscribed 5.97 times on day 2