Ethical hacker claims data breach via Aarogya Setu app

(Image credit: Future)

Updated with the latest comments from French security researcher Elliot Anderson

In these times of lockdown and uncertainty all around us, we now have to worry about our personal data being up for grabs or misused by an alleged breach in the Indian government’s contact tracing Aarogya Setu app. 

Elliot Anderson, a French security researcher and ethical hacker, on Tuesday (May 6), threw the gauntlet at the Indian government and claimed that the Aarogya Setu is flawed and data of 90 million Indians could be vulnerable.

As per the ethical hacker, the two major issues that require a fix include the fact that ‘the app fetches user location on a few occasions”, and a ‘user can get the Covid-19 stats displayed on home screen by changing the radius and latitude-longitude using a script’.

“Hi @SetuAarogya, A security issue has been found in your app. The privacy of 90 million Indians is at stake. Can you contact me in private? Regards. PS: Rahul Gandhi was right,” he said.

While very confident about his claims of data breach, Anderson has not been forthcoming with any technical details of the same and said that he is awaiting the Indian government's response in fixing the issue.

The National Informatics Centre (NIC) under the Ministry of Electronics and Information Technology, which developed the app, has denied these claims and issued the following reply via their Twitter handle:

The Aarogya Setu team clarified that the fetching of a user’s location is ‘by design’ and it is ‘stored on the server in a secure, encrypted and anonymised manner’.

Regarding the second issue, the team said the radius parameters on the app  ‘are fixed and can only take one of the five values: 500m, 1km, 2km, 5 km, and 10 km’. It added that the information does not ‘compromise on any personal or sensitive data’. 

Anderson responded with a nonchalant tweet, saying: “Basically, you said “nothing to see here” We will see. I will come back to you tomorrow.”  

However, he did come back to report that when he had first analysed the Aarogya Setu app, he was able to open any internal file with a single command line, something that cannot be done with the latest version. In other words, he is now claiming that the issue has been fixed.

Interestingly, this statement from the app team comes close on the heels of Congress leader Rahul Gandhi’s recent remark that the contact tracing app is a ‘sophisticated surveillance system outsourced to a private operator’.

Recently there was also an uproar about the Centre deploying wearable trackers and Arogya Setu to monitor Covid-19 patients. 

Nitesh Kumar

Nitesh is a writer at Techradar india. He has spent 12 Years as Journalist, Content Writer, Editor with Newspapers and Magazine, English language, Email. Nitesh went to Nagpur University.

Latest in Cyber Crime
A person scanning a QR code on a smartphone
Quishing is the new QR code scam you need to watch out for – here's how to stay safe
Ransomware on the rise: how small and medium-sized businesses can achieve cyber resilience during turbulent times
Ransomware on the rise: how small and medium-sized businesses can achieve cyber resilience during turbulent times
Text Phishing Scams
Do not fall for this dangerous Amazon shopping scam
Cyber-security
Safeguarding against next-gen cyber risks
The North Face jacket
Thousands of North Face customers accounts hacked, personal data stolen
Smartphone hacked with data flow in the background
9 signs your phone has been hacked
Latest in News
Millwall FC The Den
The UK's first football club mobile network is here - but you probably won't guess which team has launched it
The Witcher 4
You're probably not playing The Witcher 4 until 2027 at the earliest, per CD Projekt's latest financial update
Apple iPhone 16 Pro REVIEW
The iPhone 17 Air looks impressively slim in this new comparison image, but that just makes me more worried about the specs
Matt Murdock smiling in Daredevil: Born Again episode 5 and Kamala Khan looking stunned in The Marvels
Daredevil: Born Again episode 5 just revealed what Kamala Khan has been up to since The Marvels, and now I'm more excited for the next superhero team to appear in the MCU
Google Pixel Watch 3, 41mm and 45mm
Google says it will fix broken Wear OS 5.1 update, but why does this keep happening?
DeepSeek
DeepSeek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models