Quick Contact

Talk to our team

Social

fb-footer
instagram-footer
Twiiter
youtube-footer
linkedin-footer
Blog --------

The Aarogya Setu Dilemma

Share
AAROGYA SETU DILEMMA Cybersecurity wattlecorp

The Indian Government has developed an app to provide efficient COVID-19 contact tracing – Aarogya Setu. The government has made it mandatory as a way to stay safe, but is the app a technological wonder to lower the number of cases or a privacy nightmare lurking in the shadows?

Before we answer the question, we will need to answer a few questions and understand the technology used by the app, the privacy concerns raised, and much more.

Aarogya Setu – The App

aarogya-setu-dilemma

Developed under the guidance of Indiaโ€™s National Informatics Center, Aarogya Setu is an app available on both iOS and Android. It was popularised through advertisements on television channels and newspapers. Instructions were given to have it pre-installed on new phones and banks and telecom companies were instructed to broadcast information about the app to all customers via telephone calls, emails, and text messages. The Prime Minister has also taken to Twitter among other platforms to encourage downloads of the app.ย 

Moving away from the marketing of the app, the app was released to trace the origin of people who are diagnosed as contact cases.

Read More About Cybercrime in the time of Pandemic

The Technology

aarogyasetu-app-wattlecorp-cybersecurity

The app uses Bluetooth and GPS to find out a userโ€™s location. The functioning of the application relies on all citizens of India to update their health status when they test positive for the case. Based on the location of people who tested positive, the app notifies users if there are users in a 500 m, 1 m, or 5m range.

Apart from the notifications about cases in the vicinity, Aarogya Setu also acts as a route map to allow the originโ€™s detection when it comes to contact cases. A three-way handshake is done using Bluetooth when 2 or more people coincide in a particular place.ย 

If someone using the application tested COVID-19 positive, all their contacts who met them would be contacted by the government using the details on their Aadhar card and mobile number used during registration.

While the technology behind the app seems to be good, let us now understand the security provided by the app.

Read More About Is Whatsapp Spying you?

Arogya Setuโ€™s Security

tracing India Wattlecorp

The security of Arogya Setu has been put into question since the initial launch. Aarogya Setuโ€™s privacy policy claims that โ€œuser information will be used only by the government in anonymized aggregated data setsโ€, implying that all data collected by the app will be used only by the government and this data will be sent only after making the users anonymous.

If you have a closer nation, you can find that there is no committee overlooking the data handed over to the government. This proves to be a big breach of privacy that is concerning for Aarogya Setu users. The app asks for almost all permissions from the device and it works only when all of them are granted. In the midst of a pandemic that is strife with political tension, this seems like theyโ€™re not concerned with the privacy of their users.

Apart from the handover of data, there are other vulnerabilities related to data being stored, it can also cause concerns raising questions about the usage of the app when there are multiple security concerns. The app claims that all data stored in the app is encrypted, but since Aarogya Setu was never released as an open-source code, it is not possible for ethical hackers to check for vulnerabilities and the validity of these claims.

The worst blow for Aarogya Setuโ€™s already downhill battle against the rising privacy concerns was setback even further by the presence of an ethical hacker who goes by the name Elliot Anderson who is known for previously finding a vulnerability within the Aadhar system. Elliot tweeted that there was a serious security vulnerability present in Aarogya Setu. With his previous issue findings, the makers of the app claim to have had discussions with the ethical hacker, but none of it is made public.

The Verdict

aarogya-setu-app

While Aarogya Setu has made quite a few advancements in biotechnology, the biggest concern still remains the same –ย  is it an unavoidable privacy nightmare or worth taking risks for?

Aarogya Setu appears to be a good application if you ignore the security concerns. But in a time where security is an essential tool it is better to bid farewell to App which is not going to be there on the app stores anymore.

Join 15,000+ Cybersecurity Innovators

Protect. Comply. Lead.

Secure your stack, stay compliant, and outpace threats with concise, fieldโ€‘tested guidance on VAPT, cloud security, and regional privacy laws delivered by Wattlecorpโ€™s
trusted advisors across the globe.

Leave a Comment

Your email address will not be published. Required fields are marked *

Saudi data protection law Data Privacy Consulting for Saudi Enterprises: How to Operationalize PDPL Data Subject Rights in 2026

Key Takeaways: The Saudi data protection law may apply to organizations outside the Kingdom when they process personal data related to individuals in Saudi Arabia, meaning geographic location alone does not automatically exclude an organization from PDPL obligations. PDPL data subject rights span access, correction, deletion, and consent withdrawal, and enterprises are on the hook […]

Read more >>
third-party vendor risk assessment DPDP Third-Party Vendor Security Risk Assessment Under DPDP: A Guide for Indian Enterprises

Key Takeaways: Third-party vendor risk assessment with DPDP practices helps Indian enterprises to verify that external partners handle personal data with adequate safeguards. The Digital Personal Data Protection Act holds data fiduciaries accountable for vendor conduct, which makes due diligence a legal and operational necessity. A structured vendor security questionnaire, covering encryption, access control, and […]

Read more >>
virtual CISO UAE Virtual CISO Services for UAE Free Zone Startups: Affordable Security Leadership for Growing Companies

Key Takeaways: Most startups already hold sensitive data such as customer info, source code, financials, long before they feel big enough to take security seriously, and that’s exactly when the risk starts. A virtual CISO gets you someone who’s done this before, setting up strategy and guiding compliance, without the cost of putting a full-time […]

Read more >>
SOC as a service for BFSI and FinTech India SOC as a Service for Indian BFSI and FinTech Companies: 24/7 Monitoring for CERT-In Readiness

Key Takeaways: SOC as a Service for BFSI and FinTech India gives banks, NBFCs, insurers and digital lenders continuous security visibility without the cost and hiring effort of building an in-house operations centre. CERT-In directions require regulated entities to report qualifying cyber incidents within six hours of detection, and implementing SOC for BFSI and FinTech […]

Read more >>
SOC as a service SOC as a Service in India: How It Works, Pricing, and Why Businesses Need Itย 

Key Takeaways: SOC as a Service helps Indian businesses to get 24×7 security monitoring without huge cost and complexity of building a full in-house security operations center. A managed SOC check and analyse beyond basic log monitoring, which combining SIEM, threat intelligence, analyst-led alert triage, incident escalation, reporting, and security response support. SOC as a […]

Read more >>
mobile app security testing Mobile App Security Testing for Indian Digital Lending Apps RBI, DPDP and API Risk Checklist

Key Takeaways: Mobile app security testing forms an important part of meeting RBI cybersecurity expectations, secure application development practices, and periodic security assessment requirements for digital lending platforms. APIs in lending apps are constantly under attack. Broken object-level authorization, data leaking where it shouldn’t, weak token validation, and missing rate limiting, these aren’t edge cases, […]

Read more >>