Developers Can Now Help Find Flaws In The Aarogya Setu App And Get Rewarded

Dhir Acharya - May 27, 2020


Developers Can Now Help Find Flaws In The Aarogya Setu App And Get Rewarded

Finally, the government has made the Aarogya Setu app an open source for developers in attempts to get rid of surveillance and privacy concerns.

Finally, the government has made the Aarogya Setu app an open source for developers in attempts to get rid of surveillance and privacy concerns. On Monday, the Ministry of Electronics and Information Technology issued a notice, saying that the code for the app’s Android version is now available on GitHub, and developers can access it. Meanwhile, the code for the iOS version of the app will be available in two weeks.

Besides, the National Informatics Centre has announced a bug bounty program for developers that can find vulnerabilities in Aarogya Setu.

The Aarogya Setu app
The Aarogya Setu app's code is now open-sourced

The government made the app’s code open-source about two months after launching it. As of now, the COVID-19 contact-tracking app has got more than 114 million users. While the app serves as a useful source of coronavirus-related information for Indians, it has also been criticized for lack of transparency in its code, especially after a French hacker found multiple security loopholes. The Indian government responded to the hacker but people grew bigger and bigger fear of using the app, so the government had to make the code open-sourced.

About this move, the French hacker posted on Twitter:

“This is a very positive news and I'm very happy that the Indian government took this direction. Now, we would like to see what is happening on the server side.”

The Aarogya Setu
Developers can access the code and find vulnerabilities

According to the Ministry, 98% of users of the Aarogya Setu app are on Android, so the code for the Android version has been made available before that of the KaiOS and iOS versions. The Ministry of Electronics and Information Technology said:

“Releasing the source code of a rapidly evolving product that is being regularly used by more than 114 million users, is challenging. Developing and maintaining the source code is a huge responsibility, both for Team Aarogya Setu and the developer community. The repository now being shared is the actual production environment. All subsequent product updates will also be made available through this repository.”

>>> Bangalore-Based Engineer Hacked Aarogya Setu App To Appear Safe At All Times

Tags

Comments

Sort by Newest | Popular

Next Story