French Hacker Says Aarogya Setu App Has ‘Security Issue’; Developers Refutes the Claim

“The privacy of 90 million Indians is at stake,” the security researcher who goes by pseudonym Elliot Alderson on Twitter said while revealing the flaw in the Aarogya Setu app.

Advertisement
By Jagmeet Singh | Updated: 6 May 2020 11:04 IST
Highlights
  • Aarogya Setu app has been downloaded by over nine crore users
  • Researcher claimed he was contacted by CERT-In and NIC teams
  • Aarogya Setu team posted a note denying the alleged security issue

The team behind the Aarogya Setu app has so far denied to acknowledge any security issues

French security researcher Robert Baptiste, who goes by pseudonym Elliot Alderson on Twitter, said the Aarogya Setu app has a “security issue” that has put the privacy of crores of Indians at stake. The researcher tweeted on Tuesday to notify the government and his over 1.67 lakh followers about the alleged security issue in the government's contact tracing app. The Indian Computer Emergency Response Team (CERT-In) and National Informatics Centre (NIC) quickly reached out to him to understand the problem. However, the team behind the Aarogya Setu app refuted the claim made by the researcher.

Without specifying the loophole, the researcher tweeted on Tuesday to highlight the concerns with the Aarogya Setu app. “The privacy of 90 million Indians is at stake. Can you contact me in private?” he wrote on Twitter, alongside tagging the official account of the contact tracing app.

The researcher also included a postscript in his tweet that said Congress MP Rahul Gandhi was right. Gandhi has last week claimed that the Aarogya Setu app is a “sophisticated surveillance system” that raises “serious data security and privacy concerns.” He also said that the app is outsourced to a private operator, with no institutional oversight.

Advertisement

Within 49 minutes after his initial tweet, the researcher said that he was contacted by the CERT-In and NIC teams. “[The] issue has been disclosed to them,” he said.

Advertisement

The app is the most downloaded in India, having broken records in how quickly its download numbers have gone up. But it has drawn a lot of criticism from groups like the Software Freedom Law Center, India (SFLC.in) and the Internet Freedom Foundation (IFF), and while the app was voluntary to use to begin with, this has quickly been changing. It is required in many offices, for workers in the gig economy, and also in government offices. Most recently, the police in Noida have been enforcing the use of the app as well.

‘No risk has been proven'
The team behind the Aarogya Setu app acknowledged the communication with the researcher through a note tweeted on early Wednesday. However, it didn't provide any details about the alleged security issue and even refuted the alleged security issue.

Advertisement

“No personal information of any user has been proven to be at risk by this ethical hacker. We are continuously testing and upgrading our systems. Team Aarogya Setu assures everyone that no data or security breach has been identified,” the team wrote in the note.

Baptiste responded to the letter posted by the Aarogya Setu team saying, “I will come back to you tomorrow.” He also asked the team about triangulation — suggesting a flaw within the system that collects user data through the app.

Advertisement

 

Good record of exposing loopholes
Although there isn't any evidence supporting what the researcher has said on Twitter, other experts have raised security concerns in the Aarogya Setu app as well. The researcher also has a good record of finding serious security loopholes. He gained popularity in India by revealing security issues in the Aadhaar system in the past. Last year, the researcher also claimed that a security lapse exposed millions of Aadhaar numbers of dealers and distributors associated with LPG brand Indane. His claim was, however, denied by the brand.

In January 2018, the researcher also discovered a flaw in OnePlus' OxygenOS clipboard that was allegedly allowing data transmission to China. The smartphone brand, however, refuted the claims made by the researcher.


In 2020, will WhatsApp get the killer feature that every Indian is waiting for? Samsung Galaxy S20 in India? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts or RSS, download the episode, or just hit the play button below.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus Ace 6T With Massive 8,300mAh Battery Launched at This Price
  2. Realme P4x 5G Launch Today: Know Price in India, Specs and More
  3. Here's How Much the Samsung Galaxy Z TriFold May Cost in India
  4. Motorola Edge 70 India Launch Date Leaked; Might Arrive With Bigger Battery
  5. Redmi 15C 5G Launched in India With These Specifications
  6. Redmi Note 15 5G Series Price, Specifications Tipped
  7. A Nearby Lost Planet May Have Created the Moon, Study Suggests
  8. Sanchar Saathi App Pre-Installation is Not Mandatory, Government Says
  9. The Abandons Arrives December 4 on Netflix: All You Need to Know
  1. Realme P4x 5G Launching Today: Know Price in India, Features, Specifications and More
  2. Pariah OTT Release: Vikram Chatterjee’s Heart-Wrenching Stray Dog Thriller Set for OTT Debut
  3. Dies Irae OTT Release: When, Where to Watch Pranav Mohanlal's Malayalam Horror Thriller Online
  4. A Nearby Planet May Have Formed the Moon Following a Collision With Early Earth: Study
  5. Netflix’s Gritty Frontier Drama The Abandons to Begin Streaming Soon: All You Need to Know
  6. Superman OTT Release Date Announced: Everything You Need to Know About Clark Kent's Latest Adventure
  7. International Space Station Makes History As Eight Visiting Spacecraft Simultaneously Dock
  8. Dulquer Salmaan’s Kaantha Set for OTT Debut: When and Where to Watch 1950's Period Drama Online?
  9. Motorola Edge 70 India Launch Date Leaked; Indian Variant Said to Feature Bigger Battery, Slim Design
  10. SpaceX Adds 29 New Starlink Satellites in Successful Falcon 9 Launch
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.