Aarogya Setu developers say no data, security breach has been identified
Rahul Gandhi had alleged Aarogya Setu was a sophisticated surveillance system
Rahul Gandhi had alleged Aarogya Setu was a sophisticated surveillance system
Rahul Gandhi had alleged Aarogya Setu was a sophisticated surveillance system
Rahul Gandhi had alleged Aarogya Setu was a sophisticated surveillance system
The developers of the Aarogya Setu app have declared the app is not collecting personal information. The Aarogya Setu app has been promoted by the government as a means to help users identify whether they are at risk of the COVID-19 infection and provides people with important information, including ways to avoid coronavirus and its symptoms. However, it has been criticised as having inadequate measures to ensure security of private data.
Congress leader Rahul Gandhi had alleged Aarogya Setu was a "sophisticated surveillance system".
The developers of Aarogya Setu issued a statement on the app's Twitter handle early on Thursday, claiming they were alerted by an ‘ethical hacker’ about a potential security issue. Interestingly, the statement followed a claim by a French cybersecurity expert, who goes by the name Elliot Alderson, that the Aarogya Setu app had a security issue.
In the statement, the developers of Aarogya Setu highlighted concerns raised by the 'ethical hacker' and their responses. In the first concern, about the Aarogya Setu app fetching user location, the developers noted this was done "by design" and was detailed in the app's privacy policy. The app developers said the user's location data is stored on the server in a "secure, anonymised manner".
Referring to a concern that users can get COVID-19 statistics by changing radius and latitude/longitude by running a script, Aarogya Setu developers said the radius parameters were fixed and can only take five values: 500m, 1km, 2km, 5km and 10km. Noting these were "standard parameters", the Aarogya Setu developers said giving any other value would lead to the radius being set to a default value of 1km. The developers acknowledged users could change latitude/longitude, but said this information was already public and did not "compromise any personal or sensitive data".
The Aarogya Setu developers said, "no personal information of any user has been proven to be at risk" by the ethical hacker and that they were continuously testing and upgrading systems. "Team Aarogya Setu assures everyone that no data or security breach has been identified," the developers said.
In the most recent update to the lockdown guidelines, the Centre had said installation of the Aarogya Setu app was mandatory for employees of both public and private sectors.