After epidemic of Covid-19 various countries have launched contact tracing apps that may alert to the users when the another user is affected with virus nearby.
India also launched the same behaviour app named Arogya Setu. This app is released on 01 April 2020 and within the months it installed by more than 50 million users on Google Play Store. After the trend of Installation and launched this app, various personals questioning about the security and privacy policy of this app.
Last week Indian Government made compulsory installation of this app by every user in India. The mandatory term stunned to people’s. Opposition party also questioned about the same. That why the app is being made mandatory? Some leader of opposition parties said that this app is being made for surveillance of common people and divert the choice of their ability.
After these trends French Security Researcher Baptiste Robert aka Elliott Alderson check the app’s security and claimed various Vulnerabilities in the app. Report of vulnerability has been triagged by Arogya Setu official latest tweet and the same has been fixed now.
The hacker claims that he got the access in data of infected people in PMO office, Army HQ, etc.
As per his blog:- PMO office: {“infected”:0,”unwell”:5,”bluetoothPositive”:4,”success”:true,”selfAsses”:215,”usersNearBy”:1936}
– Ministry of Defense: {“infected”:0,”unwell”:5,”bluetoothPositive”:11,”success”:true,”selfAsses”:123,”usersNearBy”:1375}
– Indian Parliament: {“infected”:1,”unwell”:2,”bluetoothPositive”:17,”success”:true,”selfAsses”:225,”usersNearBy”:2338}
– Indian Army Headquarters: {“infected”:0,”unwell”:2,”bluetoothPositive”:4,”success”:true,”selfAsses”:91,”usersNearBy”:1302}
If you see the data given by the hacker is serious because it gives the details of sensitive area, in which normal peoples are not supposed to get the access. Like Army HQ and PMO office.
However, the vulnerability has been fixed by Arogya Setu Officials but is it good to being mandatory for every user of India is still a good question?