9 ms·
How does one do proper "technical analysis" without access to the code, or knowing the architecture? None of those were available when the app was released. Wa
by moh_maya 6y ago
How does one do proper "technical analysis" without access to the code, or knowing the architecture? None of those were available when the app was released. Was the shrill noise over the top? IMO, perhaps; but that does not detract from the fact that the application was just announced, with mandatory use if you had to travel (now diluted to encouraged), without any transparency..
National herald is not an unbiased source; it's clearly anti-current incumbent govt, but the argument that people were criticizing without "technical analysis" when no data was provided nor were they (initially) open to even sharing the code for scrutiny, makes me wonder how one could have assumed the app did what it said on the tin, except by blindly trusting the govt.
Which, personally, I'm not a fan of. There is a reason the US federal govt is constrained by the 1st amendment, and not private corps. Govts are unique entities in our societies, with a monopoly on multiple forms of power, and their oversight should be held to a higher standard (again, IMO)
- sbmthakur 6y agoWell, people have decompiled the Android app. I believe if someone wants to term the app as a complete sham then they should at least do that. Note that I am not against criticism of the app. Privacy concerns are full valid and I also want the app to be open sourced in its entirety.
- moh_maya 6y agoFair point; I think we both probably agree that there was a lot of needless hysteria. However, the ability to decompile / reverse engineer the app itself was explicitly disallowed in the app ToS [1]: “...You agree that you will not tamper with, reverse-engineer or otherwise use the App for any purpose for which it was not intended including, but not limited to, accessing information about registered users stored in the App, identifying or attempting to identify other registered users or gaining or attempting to gain access to the cloud database of the Service.” exposing the software engineer / group that did it & published the analysis to significant harassment & risk. One could argue that this was for data protection, but it reeks of security through obscurity, especially the way the clause is worded (including but not restricted to). Whatever the intentions, the initial roll-out was a disaster from the transparency / info-sec PoV IMO. [1] https://sflc.in/our-concerns-aarogya-setu-app https://sflc.in/our-concerns-aarogya-setu-app edit: added link to the Software Freedom Law Center India site with details on the clause prohibiting reverse engineering