3 ms·
No, what would have put all the legitimate concerns to rest would have been: a) transparency into who the developers are, and what the terms of engagement are
by moh_maya 6y ago
No, what would have put all the legitimate concerns to rest would have been:
a) transparency into who the developers are, and what the terms of engagement are
b) even if they didn't / couldn't open source the code from the get go, a clear date and target of when they would do so
c) even before the app was launched, a single one page document of the architecture, the regulations governing data retention, etc (all were released post facto, after the "fake news" and "privacy noise").
Concerns about the govt collecting massive, potentially identifiable data on an individual level for an application that they originally mandated everyone had to use to travel, is not "fake news". Perhaps one may feel such concern was unwarranted (and I disagree there), but how is that "fake news"?
We may have differences of opinion on the level of trust one can have on govts, but I'm sure we can agree that transparency and visibility into such critical decisions is reasonable to demand and expect.
- kosmischemusik 6y agoYou're spot on. I've seen a lot of folks talk about how the government rushed into putting out the app without having an open consultation with technologists. Rather, a closed-door discussion with a vague set of "industry players". Nonetheless, this is the first step the government has taken. Let's hope continued pressure will result in audits and better protocols in the future.
- pm90 6y ago> Concerns about the govt collecting massive, potentially identifiable data on an individual level for an application that they originally mandated everyone had to use to travel, is not "fake news". Perhaps one may feel such concern was unwarranted (and I disagree there), but how is that "fake news"? I'm not the OP but from what I've heard there's a mix of genuine concerns and conspiracy theories about this (as often happens), and its quite hard for a layperson to understand what to believe. I read the OP as saying "finally, we get to see what's really happening and can thus determine if the concerns for data privacy are legitimate and put the conspiracy theories to rest"
- sbmthakur 6y agoLike every other thing, even this was politicized in India. There are people terming the app as a "surveillance app" without a proper technical analysis[0]. 0. https://www.nationalheraldindia.com/india/aarogya-setu-is-a-surveillance-app-will-not-help-those-who-are-most-vulnerable-to-covid-19 https://www.nationalheraldindia.com/india/aarogya-setu-is-a-...
- moh_maya 6y agoHow does one do proper "technical analysis" without access to the code, or knowing the architecture? None of those were available when the app was released. Was the shrill noise over the top? IMO, perhaps; but that does not detract from the fact that the application was just announced, with mandatory use if you had to travel (now diluted to encouraged), without any transparency.. National herald is not an unbiased source; it's clearly anti-current incumbent govt, but the argument that people were criticizing without "technical analysis" when no data was provided nor were they (initially) open to even sharing the code for scrutiny, makes me wonder how one could have assumed the app did what it said on the tin, except by blindly trusting the govt. Which, personally, I'm not a fan of. There is a reason the US federal govt is constrained by the 1st amendment, and not private corps. Govts are unique entities in our societies, with a monopoly on multiple forms of power, and their oversight should be held to a higher standard (again, IMO)
- sbmthakur 6y agoWell, people have decompiled the Android app. I believe if someone wants to term the app as a complete sham then they should at least do that. Note that I am not against criticism of the app. Privacy concerns are full valid and I also want the app to be open sourced in its entirety.
- moh_maya 6y agoFair point; I think we both probably agree that there was a lot of needless hysteria. However, the ability to decompile / reverse engineer the app itself was explicitly disallowed in the app ToS [1]: “...You agree that you will not tamper with, reverse-engineer or otherwise use the App for any purpose for which it was not intended including, but not limited to, accessing information about registered users stored in the App, identifying or attempting to identify other registered users or gaining or attempting to gain access to the cloud database of the Service.” exposing the software engineer / group that did it & published the analysis to significant harassment & risk. One could argue that this was for data protection, but it reeks of security through obscurity, especially the way the clause is worded (including but not restricted to). Whatever the intentions, the initial roll-out was a disaster from the transparency / info-sec PoV IMO. [1] https://sflc.in/our-concerns-aarogya-setu-app https://sflc.in/our-concerns-aarogya-setu-app edit: added link to the Software Freedom Law Center India site with details on the clause prohibiting reverse engineering