Firstpost
  • Home
  • Video Shows
    Vantage Firstpost America Firstpost Africa First Sports
  • World
    US News
  • Explainers
  • News
    India Opinion Cricket Tech Entertainment Sports Health Photostories
  • Asia Cup 2025
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
Trending:
  • Charlie Kirk shot dead
  • Nepal protests
  • Russia-Poland tension
  • Israeli strikes in Qatar
  • Larry Ellison
  • Apple event
  • Sunjay Kapur inheritance row
fp-logo
'Indian govt should convince public on Aarogya Setu's efficacy rather than forcing it on them': Cybersecurity expert Elliot Alderson tells Firstpost
Whatsapp Facebook Twitter
Whatsapp Facebook Twitter
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
  • Home
  • India
  • 'Indian govt should convince public on Aarogya Setu's efficacy rather than forcing it on them': Cybersecurity expert Elliot Alderson tells Firstpost

'Indian govt should convince public on Aarogya Setu's efficacy rather than forcing it on them': Cybersecurity expert Elliot Alderson tells Firstpost

Neerad Pandharipande • May 23, 2020, 15:33:23 IST
Whatsapp Facebook Twitter

In an interview with Firstpost, Elliot Alderson replied to several assertions made by the Union government about Aarogya Setu, which is being widely being promoted as a contact-tracing app that help to combat COVID-19.

Advertisement
Subscribe Join Us
Add as a preferred source on Google
Prefer
Firstpost
On
Google
'Indian govt should convince public on Aarogya Setu's efficacy rather than forcing it on them': Cybersecurity expert Elliot Alderson tells Firstpost

French ethical hacker Elliot Alderson, who sparked off a fierce debate on security issues related to Aarogya Setu earlier this month, said that the Indian government must convince people of the app’s efficacy rather than force them to use it. In an interview with Firstpost, Alderson, a cybersecurity expert, replied to several assertions made by the Union government about Aarogya Setu, which is being widely being promoted as a contact-tracing app that help to combat COVID-19. [caption id=“attachment_8400501” align=“alignleft” width=“380”] ![Aarogya Setu app on iOS](https://images.firstpost.com/wp-content/uploads/2020/05/380-this.jpg) Aarogya Setu app on iOS[/caption] The Press Information Bureau has said that the app was developed as a ‘public-private partnership’ and as per media reports, several individual volunteers have worked on it, including former Google India executive Lalitesh Katragadda and MakeMyTrip founder Deep Kalra. ‘Publishing source code important to gain trust’ Alderson said the Union government should follow the example of several other countries and make the app open source, which would enable it to be scrutinised for security flaws by independent coders and researchers. He said, “To potentially be useful, a contact-tracing app needs to be downloaded and used by a lot of people. To ensure adoption of the app on a large scale among the population, you need to gain their trust. Publishing the source code is one way to get this trust.” In an interview to Hindustan Times, MyGov’s CEO Abhishek Singh said the app was not made open source because there were changes being made to its code as the developers would get new insights. Singh said that unless the app is stable, releasing its source code may not help as there would always be someone raising false alarms. However, several countries have developed similar apps to facilitate easier contact tracing and made the apps open source: Israel, Singapore and the United Kingdom being prominent examples.

Alderson noted these examples in a tweet and urged Indian government to do the same.

Another concern raised by Singh was that making the app open source may lead to its misuse by non-State actors. Responding to this concern, Alderson told Firstpost, “This fear is totally illegitimate. A lot of countries made their apps open source and nothing bad happened. Making the source code of an app public is something that has been done for years and is quite a standard practice.” Another point of contention between the government and privacy activists is whether the app ensures anonymity. The Economic Times quoted a senior government official as saying that all data is anonymised, and after an anonymous device ID is created “all future interactions” happen with the anonymised device ID. Alderson doesn’t agree. He said, “Once you are declared infected with COVID-19, your GPS data of the past few weeks is sent to the Indian government. This system is absolutely not anonymous. So, this app is a surveillance system to track people infected with COVID-19.” In a blog post on Medium on 6 May, Alderson showed it possible to modify the location of the app, which can enable one to identify how many people are unwell or infected even without being physically present in their vicinity. On the basis of the data obtained, he was able to show that five people felt unwell at the Prime Minister’s Office (PMO), two people felt unwell at the army headquarters and one person was infected at the Parliament. In the blog post entitled “Aarogya Setu: The story of a failure” Alderson also showed that it was possible to modify the radius of the app to a figure that is not available normally to users, although the government denied the claim. Alderson also said that in an earlier version of the app, it was possible for an attacker to open any internal file, including the local database of an area. However, he said that in the subsequent version, this issue was ‘fixed silently’ by the developers. Commenting on this, Alderson said, “I sent them my report and they fixed the issues I flagged. That is the most important thing.” ‘Forcing people to install app not good’ The Union home ministry, in its latest guidelines on the coronavirus lockdown, no longer makes it mandatory for office-goers to install the Aarogya Setu app. The new guidelines dated 17 May state that employers should ensure that the app is downloaded by all employees having compatible mobile phones “on best effort basis.” The earlier guidelines, dated 1 May, stated, “Use of Aarogya Setu shall be mandatory for all employees, private and public. It shall be the responsibility of the head of the respectively organisations to ensure 100 percent coverage of this app among the employees.” Commenting on this, Alderson said, “This is a step in the right direction. Forcing people to install an app is never a good thing. You can legally force them to install an app but you cannot force them to use it. Instead of forcing people, the Indian government should spend its energy on convincing people that this app is really useful (if this is what it believes).” However, after air and rail travel has been partially restored, it has been made mandatory for people planning to travel by flights and rail to install the Aarogya Setu app. Also, some private companies such as Zomato and Xiaomi have made it mandatory for employees to download the app. In Gautam Budh Nagar district, which includes Noida, Greater Noida and Dadri, local authorities made it mandatory for people to install the app in a 3 May order. However, the order was reversed on 20 May after some residents submitted a representation to the Additional Deputy Commissioner (Law and order) challenging the directive’s legal basis.

Tags
Congress NewsTracker ConnectTheDots Surveillance privacy data privacy lockdown Data Security Personal Privacy Elliot Alderson Coronavirus outbreak Coronavirus Pandemic COVID 19 COVID 19 outbreak COVID 19 pandemic Coronavirus lockdown Aarogya Setu
End of Article
Latest News
Find us on YouTube
Subscribe
End of Article

Impact Shorts

News18 SheShakti 2025: Voices of cinema, sport and music redefine nation-building

News18 SheShakti 2025: Voices of cinema, sport and music redefine nation-building

At News18 SheShakti 2025 Delhi, women from sports, cinema, and music discussed breaking barriers. Kriti Sanon and Sanya Malhotra focused on equity in cinema, Mira Erda and Ashalata Devi on sports challenges, and Kavita Krishnamurti stressed humility and perseverance for lasting success.

More Impact Shorts

Top Stories

Charlie Kirk, shot dead in Utah, once said gun deaths are 'worth it' to save Second Amendment

Charlie Kirk, shot dead in Utah, once said gun deaths are 'worth it' to save Second Amendment

From governance to tourism, how Gen-Z protests have damaged Nepal

From governance to tourism, how Gen-Z protests have damaged Nepal

Did Russia deliberately send drones into Poland’s airspace?

Did Russia deliberately send drones into Poland’s airspace?

Netanyahu ‘killed any hope’ for Israeli hostages: Qatar PM after Doha strike

Netanyahu ‘killed any hope’ for Israeli hostages: Qatar PM after Doha strike

Charlie Kirk, shot dead in Utah, once said gun deaths are 'worth it' to save Second Amendment

Charlie Kirk, shot dead in Utah, once said gun deaths are 'worth it' to save Second Amendment

From governance to tourism, how Gen-Z protests have damaged Nepal

From governance to tourism, how Gen-Z protests have damaged Nepal

Did Russia deliberately send drones into Poland’s airspace?

Did Russia deliberately send drones into Poland’s airspace?

Netanyahu ‘killed any hope’ for Israeli hostages: Qatar PM after Doha strike

Netanyahu ‘killed any hope’ for Israeli hostages: Qatar PM after Doha strike

Top Shows

Vantage Firstpost America Firstpost Africa First Sports

QUICK LINKS

  • Mumbai Rains
Latest News About Firstpost
Most Searched Categories
  • Web Stories
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Tech/Auto
  • Entertainment
  • IPL 2025
NETWORK18 SITES
  • News18
  • Money Control
  • CNBC TV18
  • Forbes India
  • Advertise with us
  • Sitemap
Firstpost Logo

is on YouTube

Subscribe Now

Copyright @ 2024. Firstpost - All Rights Reserved

About Us Contact Us Privacy Policy Cookie Policy Terms Of Use
Home Video Shorts Live TV