2 ms·
Fair point; I think we both probably agree that there was a lot of needless hysteria. However, the ability to decompile / reverse engineer the app itself was ex
by moh_maya 6y ago
Fair point; I think we both probably agree that there was a lot of needless hysteria. However, the ability to decompile / reverse engineer the app itself was explicitly disallowed in the app ToS [1]:
“...You agree that you will not tamper with, reverse-engineer or otherwise use the App for any purpose for which it was not intended including, but not limited to, accessing information about registered users stored in the App, identifying or attempting to identify other registered users or gaining or attempting to gain access to the cloud database of the Service.”
exposing the software engineer / group that did it & published the analysis to significant harassment & risk.
One could argue that this was for data protection, but it reeks of security through obscurity, especially the way the clause is worded (including but not restricted to). Whatever the intentions, the initial roll-out was a disaster from the transparency / info-sec PoV IMO.
[1] https://sflc.in/our-concerns-aarogya-setu-app https://sflc.in/our-concerns-aarogya-setu-app
edit: added link to the Software Freedom Law Center India site with details on the clause prohibiting reverse engineering