Elliot Alderson has claimed that theAarogya Setu app allows users to find out who is sick in a particular area.- He has also contradicted the Aarogya Setu team’s claim that bulk calls to the API are not possible.
After this, Alderson has come up with a post highlighting the issues found by him in the Aarogya Setu app.
App allows users to access internal files
In April, Alderson found that the WebViewActivity allowed users to access internal files of the app by using commands as there was no host validation. However, the issue has now been fixed.
Aarogya Setu allows you to find out who is sick
The next issue found by Alderson is that it is possible to modify the user’s location to find out who is sick in a particular area. While the app allows users to change the radius of the area between 500m, 1km, 2km, 5km or 10km, Alderson was able to change it to 100km.
He added that this flaw could allow anyone to find out who is sick in a particular area.
“Thanks to this endpoint an attacker can know who is infected anywhere in India, in the area of his choice. I can know if my neighbour is sick for example. Sounds like a privacy issue for me…” said Alderson.
However, local governments have been publishing information about Covid-19 patients to alert the people who may have come in contact with them, so this may not be a very big issue.
Alderson claims bulk calls to the API are possible
The Aarogya Setu team in its earlier response to Alderson’s claims had said that bulk calls to the API are not possible as it is behind a Web Application firewall. However, Alderson has now claimed that bulk calls are possible, and he spent an entire day sending bulk calls.
See also:
Aarogya Setu denies privacy breach, contradicts ethical hacker’s claims
Stranded Indians landing in country will have to register for COVID-19 'Aarogya Setu' app: MHA
COVID-19: Smartphone without 'Aarogya Setu' app will draw punishment for user in Gautam Buddh Nagar