30 ms·
India orders smartphone makers to preload state-owned cyber safety app
- elia_is_me 10mo agoi thought 'india' here indicate china before i clicked in.
- qwerty59 10mo agoVery concerning. I will be suprised if companies like apple comply though.
- goku12 10mo agoAs concerning as it is, this is just another addition to the pile of malware that a modern smartphone is. Everyone including SoC manufacturer, RF baseband manufacturer, OEM, OS developer, browser developer and app developers add their own opaque blobs, hidden executable rings, lockdown measures, attestation layers, telemetry, trojan apps, hidden permissions and more. We lost the game when we allowed these players to impose limits on us in the way we can use the device that we bought with our hard earned money. Even modifying the root image of these OSes is treated like some sort of criminal activity. And there are enough people around ready to gaslight us with the stories about grandma's security, RF regulations, etc. Yet, its the extensive custom mods like Lineage OS that offer any form of security. Their extensive lockdown only leads to higher usage costs and a mountain of malware. We really need to demand control over our own devices. We should fight to outlaw any restrictions on the ways we can use our own devices. We should strongly condemn and shame the people who try to gaslight us for their greed and duplicity.
- nunobrito 10mo agoGood to see someone well-informed. There is a lot being on that topic, you are not alone.
- goku12 10mo agoThank you for your kind words and solidarity! Those who understand this should definitely take a public stance, because we're far too apathetic towards such exploitation. It's even more disturbing to see some people supporting measures like these!
- deleted 10mo ago[deleted]
- charlie-83 10mo agoI completely agree with you but I'm not sure I can really think of a solution for the RF baseband problem. I really don't want to live in a world where everyone's wifi signal is terrible because lots of stupid software devs decided to boost the RF power for their product to make it work better.
- goku12 10mo agoYes. That thought did cross my mind. However, the RF baseband is an independent opaque blackbox already. As far as I know, it even includes an entire hidden operating system. But opening up the rest of the system, leaving the BB as it is, will go a long way to an open user-controlled system. We could adopt that as a stop gap measure until a longer term solution is found. In the longer term however, we will need such a restriction on RF BB lifted too. Openness isn't just about modifiability. It's essential for security too. I'm someone who believes that security and granular restrictions can be implemented without being hostile towards users. This is why I don't buy Apple's argument that hardware lockdown measures like soldering on batteries, permanently gluing up ICs, etc are essential for miniaturization and security. One solution for the problem you mentioned (devs over-boosting the RF output) is to have a one-time programmable power limiter after one of the final fixed-gain RF power amplifiers. (An example of a one-time programmable device is an anti-fuse FPGA). Such a baseband can be programmed to conform to the market country's regulations (or something even stricter) before assembly. This way, the developer can boost the signal as much as they want, but the device simply won't respond beyond the permissible limit. Of course, all these are daydreams, because it has to be implemented by the baseband manufacturer. Unfortunately, their incentives don't align with our interests.
- hurutparittya 10mo agoIs there any person or organization out there doing significant work against remote attestation being a thing? I'd love to support them.
- alephnerd 10mo ago> I will be suprised if companies like apple comply though They will. All tech companies already comply with India's IT Act. And India now manufactures 44% of all iPhones sold in the US [0] while dangling the stick of a $38B anti-trust fine [6] but also the carrot of implementing China-style labor laws [10] that Apple lobbied for [11], so Apple doesn't have much of a choice because both China and Vietnam (the primary competitors for this segment of manufacturing) have similar regulations while not shielding them from Chinese competitors. Samsung is in the same boat at 25% of their manufacturing globally being done in India in CY24 [1] while is also trying to further entrench itself [2][8][9] due to existential competition from Chinese vendors [3][7]. Heck, Apple complied with similar regulations in Russia [7] before the Ukraine War despite being a smaller market than India with no Apple manufacturing, engineering, or capex presence. All large companies who face existential threats from Chinese competitors have no choice but to entrench in India as it's the only large market with barriers against direct Chinese competition - ASEAN has an expansive FTA with China which has lead both South Korea, Japan, and Taiwan to lose their staying power in countries like Vietnam, Indonesia, and Thailand where Chinese competitors are being given the red carpet, and Brazil is in the process of one as well. And the Indian government is taking full advantage of this to get large companies to bend to Indian laws, as can be seen with the damocles sword of tax enforcement on Volkswagen [4] while negotiating an FTA with the EU and a potential $38B anti-trust fine against Apple [5] while negotiating a BTA with the US. It's the same playbook China used when it was in India's current position in the late 2000s and early 2010s. Finally, India was in a de facto war earlier this year against Pakistan (Chinese manufactured missiles landed near my ancestral home along with plenty of Turkish and Chinese drones) along with a suicide bombing in India's Tiannamen Square (the Red Fort) a couple weeks ago [12], so anything national security has a bit more credence and leeway. [0] - https://scw-mag.com/news/apples-supply-shift-to-india-speeds-up-to-44-surpassing-china-for-the-first-time/ https://scw-mag.com/news/apples-supply-shift-to-india-speeds... [1] - https://www.techinasia.com/news/samsung-to-broaden-manufacturing-portfolio-in-india-minister https://www.techinasia.com/news/samsung-to-broaden-manufactu... [2] - https://www.chosun.com/english/industry-en/2025/11/25/SLEYWTPTVRHBPPYPCNNEAP6CDQ/ https://www.chosun.com/english/industry-en/2025/11/25/SLEYWT... [3] - https://www.digitimes.com/news/a20251118VL205/2030-samsung-sk-hynix-dram-ymtc.html https://www.digitimes.com/news/a20251118VL205/2030-samsung-s... [4] - https://www.ft.com/content/6ec91d4a-2f37-4a01-9132-6c7ae5b06d5d https://www.ft.com/content/6ec91d4a-2f37-4a01-9132-6c7ae5b06... [5] - https://www.reuters.com/sustainability/boards-policy-regulation/apple-contests-indias-antitrust-penalty-law-with-risk-38-billion-fine-filing-2025-11-26/ https://www.reuters.com/sustainability/boards-policy-regulat... [6] - https://www.macrumors.com/2021/03/16/apple-to-offer-government-approved-apps-russia/ https://www.macrumors.com/2021/03/16/apple-to-offer-governme... [7] - https://www.businesskorea.co.kr/news/articleView.html?idxno=235998 https://www.businesskorea.co.kr/news/articleView.html?idxno=... [8] - https://www.digitimes.com/news/a20250903PD208/samsung-india-investment.html https://www.digitimes.com/news/a20250903PD208/samsung-india-... [9] - https://www.digitimes.com/news/a20241212PR200/samsung-india-education-semiconductors-design.html https://www.digitimes.com/news/a20241212PR200/samsung-india-... [10] - https://www.bloomberg.com/news/articles/2025-11-21/india-implements-overhauled-labor-laws-to-attract-more-investors https://www.bloomberg.com/news/articles/2025-11-21/india-imp... [11] - https://www.bloomberg.com/news/articles/2023-03-21/apple-seeks-india-labor-reform-in-push-to-diversify-beyond-china https://www.bloomberg.com/news/articles/2023-03-21/apple-see... [12] - https://abcnews.go.com/International/wireStory/india-intensifies-crackdown-disputed-kashmir-after-new-delhi-127883576 https://abcnews.go.com/International/wireStory/india-intensi...
- embedding-shape 10mo agoDo they actually have a choice? Usually with laws and orders from the government, you can't do much than either go with the flow, try to lobby against it afterwards, or straight up refuse and leave the market. Considering Apple's ties to India, I feel like Apple is unlikely to leave, so that really only leaves Apple with the first; comply and complain.
- JumpCrisscross 10mo ago> Do they actually have a choice? Yes. Apple's revenues are half as much as the government of India's [1][2]. That's a resource advantage that gives Cupertino real leverage against New Delhi. [1] https://www.apple.com/newsroom/2025/10/apple-reports-fourth-quarter-results/ https://www.apple.com/newsroom/2025/10/apple-reports-fourth-... $102.5bn / quarter [2] https://en.wikipedia.org/wiki/List_of_countries_by_government_budget https://en.wikipedia.org/wiki/List_of_countries_by_governmen... $827bn / year
- jonplackett 10mo agoApple need India though. They’re moving a lot of their manufacturing there to derisk from a China. Also, they gave in to the CCP and always say ‘we obey the laws of the countries in which we operate’. Apple is, at the end of the day, just a business.
- JumpCrisscross 10mo ago> Apple need India though. They’re moving a lot of their manufacturing there to derisk from a China That creates obligations both ways. Put another way, Apple is an increasingly-major employer in India. The real carrot New Delhi has is its growing middle class. The real carrot Apple has is its aspirational branding. > they gave in to the CCP and always say ‘we obey the laws of the countries in which we operate' Apple regularly negotiates and occasionally openly fights laws its disagrees with. This would be no different. Cupertino is anything but lazy and nihilistic. Mandated installation opens a door they've fought hard to keep shut because it carries global precedent.
- brendoelfrendo 10mo agoWhy wouldn't they? If Apple doesn't comply, the Indian government could force them to withdraw from the market or otherwise make their lives difficult. I can't see Apple or their shareholders caring about privacy enough to abandon such a large market.
- fsflover 10mo agoYou shouldn't be: https://news.ycombinator.com/item?id=26644216 https://news.ycombinator.com/item?id=26644216
- GuinansEyebrows 10mo agohave you seen what Tim Apple has been up to lately with his own government?
- hsuduebc2 10mo agoThey are doing this for US from the beginning so it is only matter of time or carefully applied pressure. This is only a PR.
- oldjim798 10mo agoHonestly shocked it took this long for governments to start doing this; it seemed inevitable that governments would want all the data private entities have been enjoying. More and more it seems like the benefits of being connected are not worth the cost of being so visible to so many hostile (state and non-state) actors
- okokwhatever 10mo agoYeah, internet is a dead star in so many ways this days. Repetitive, addictive and a private data sucker. I'm already starting to buy programming books and offline content preparing for a radical semi-disconnection.
- stickfigure 10mo agoWhat stops someone from loading GrapheneOS on their (Indian) Android phone?
- notRobot 10mo agoCustom ROMs fail device integrity, which means you cannot use banking, financial, government, payments and telcom apps, not to mention all the games that refuse to work.
- alephnerd 10mo agoIt will be used as evidence that the person who has GrapheneOS on their phone is attempting to break the law. Telegram and Signal chats are often used as circumstantial evidence of malfeasance in Indian national security cases, so the jump to using GrapheneOS as evidence of malfesance is tiny.
- OutOfHere 10mo agoFUD
- nosianu 10mo ago"Cops in this country think everyone using a Google Pixel must be a drug dealer" (because of GrapheneOS) https://news.ycombinator.com/item?id=44473694 https://news.ycombinator.com/item?id=44473694 https://grapheneos.social/@GrapheneOS/114784469162979608 https://grapheneos.social/@GrapheneOS/114784469162979608 > European authoritarians and their enablers in the media are misrepresenting GrapheneOS and even Pixel phones as if they're something for criminals. GrapheneOS is opposed to the mass surveillance police state these people want to impose on everyone.
- Aachen 10mo agoI see it more as an extra reason to use it: - If only criminals want privacy, privacy becomes suspicious - If more people use an open OS, it's more profitable for commercial entities to not put in extra effort to block these devices due to the FUD going around about them being insecure So if someone suggests that using open source software is increasingly being seen as suspicious, the #1 thing to do is start using it
- catlikesshrimp 10mo agoGoogle, the phone manufacturer and now the state running bloatware on my phone. I will have three dialers, calendars, etc. All of them uninstallable
- poly2it 10mo agoGet GrapheneOS. The installation is painless and the OS surperior. No mainstream phone OS is viable in the privacy and security nightmare of today. https://grapheneos.org/ https://grapheneos.org/
- __rito__ 10mo agoI wouldn’t venture in the direction that many here will take. I will point out that India have the highest number of victims of cyber-fraud. I personally know many people who have lost significant sums through social engineering attacks. The money is transferred to multiple mule accounts and physical cash is siphoned off to the fraudsters by the owners of those account. They choose helpless, illiterate, village dwelling account holders for this. Another huge issue is unregulated loan apps. There are horror stories of people installing apps in order to take high-interest loans and then those apps stealing their private photos and contacts or accessing camera to take photos in private moments, and then sending those photos to contacts via WhatsApp when interest payment is overdue. Then there are obvious security issues with terrorism and organized crime. The government wants data. It's clear why. There is huge potential for misuse.
- JumpCrisscross 10mo ago> I will point out that India have the highest number of victims of cyber-fraud Based on what? > Another huge issue is unregulated loan apps You don't need to root everyone's phones to regulate financial crime. > Then there are obvious security issues with terrorism and organized crime India is building a centralised backdoor into every phone in the country. That's a massive national security risk.
- lallysingh 10mo agoThe way for the community to fight this is to keep finding holes in the app until they stop trying to put one on.
- JumpCrisscross 10mo ago> way for the community to fight this is to keep finding holes in the app until they stop trying to put one on I'm not familiar with Indian activist tradition. But if we look at other countries where this happened, the technical attacks didn't work. It had to be done through policy, instead.
- __rito__ 10mo ago
- profsummergig 10mo agoref: "the new tobacco" this last year i'm seeing very concerning behavior in students in the 14-20 range. complete addiction to their phones. very deep interests in things i was completely unaware that they existed. similar to how when i started noticing anime girlfriends/waifus in 2016. about 40% are deep in discord communities where i literally cannot figure out a single sentence of what they're talking about. if society doesn't do something, and soon, say goodbye to the cognitive ability of a large chunk of future generations.
- deleted 10mo ago[deleted]
- ikmckenz 10mo ago> very deep interests in things i was completely unaware that they existed ... say goodbye to the cognitive ability of a large chunk of future generations I would think very deep interests in niche or obscure topics is correlated with increased cognitive ability, not a decrease.
- profsummergig 10mo agoanime waifus?
- AlexandrB 10mo ago> very deep interests in things i was completely unaware that they existed That's just a symptom of getting old. Young people always find stuff that baffles adults. When I was a teenager, Anime itself was like this - just being "into" anime was considered some kind of bizarre, obscure affectation by adults. I think smartphones present real challenges (and I don't get how/why they're allowed in schools), but a lot of what you're describing is normal.
- krelas 10mo ago> about 40% are deep in discord communities where i literally cannot figure out a single sentence of what they're talking about. I feel like the same could be said of an at the time adult looking at my IRC or MSN Messenger logs from when I was a teen.
- marginalx 10mo ago"With 5 million total downloads - the app has saved 3.7 million lost phones", this somehow doesn't add up for me, as this implies more than 74% of phones are stolen? Or this this govt lying to pad the numbers to make the app look like a sheep in wolves clothing.
- perryizgr8 10mo agoPeople download it only when their phone is stolen.
- officerk 10mo agoThey download it where? On a spare phone? How does that work?
- rishabhaiover 10mo agoI'm shocked by people and state using the crutch of cyber crime or scams to push a totalitarian solution to a problem that is better solved by improved education and targeted campaigns against common security pitfalls. I abhor any decision that robs even a grain of my individual freedom.
- djohnston 10mo agoI share your abhorrence but are you really shocked? "Think of the children", "Stop the terrorists," these have been the foundations for the erosion of personal liberty for the past thirty years.
- politelemon 10mo agoAnd long before that too, it's just taken different soundbites that play on people's fears at the time.
- nephihaha 10mo agoIn the UK, they've used variously terrorism, illegal migration and pornography to push this.
- hsuduebc2 10mo agoIt's actually much more older argument. Hurr durr muh children is so common in history yet so effective that this is beyond absurd.
- energy123 10mo agoI am unconvinced from a practical standpoint that this vision of the world that you wish to live in is even possible today due to the increase in sectarian communal tensions, dense cities, widely available cars/guns/etc and stresses from cost of living and income inequality, as well as the spread of ideas that mass casualty attacks might be a thing to do (the US did not have school attacks until it became an unfortunate "thing" in the culture that sick people glommed onto). An absence of surveillance causes increased frequency of terrorist attacks which causes people to demand solutions (necessarily involving surveillance and other authoritarian measures) which leads to increased surveillance. It's an unfortunate negative feedback loop. If you lack solutions for too long, the negative feedback loop becomes severe and instead of just surveillance within a liberal democratic context, you get public safety authoritarians like Bukele or Duterte. "Surveillance doesn't materially reduce terrorist attacks" - I am not sure about that based on the number of arrests of plotters and the lack of visibility I have into the tools and methods they used to find those plotters. "Terrorist attacks still happen even with surveillance" - Yes, but if they happen less frequently, this reduces the demand from the public to ratchet up authoritarianism. See the problem? "Terrorist attacks are a price worth paying for our freedom." - I mostly agree, but feeling like this doesn't make any difference to the negative feedback loop, does it? Regular people want public safety from physical danger almost as much as food and water.
- JumpCrisscross 10mo agoDo we have a breakdown of what this app actually does?
- alephnerd 10mo agohttps://sancharsaathi.gov.in/ https://sancharsaathi.gov.in/ Basically IMEI stamping because sim card purchase with ID has come to be viewed as flawed/compromised by NatSec types in India. Here's some additional context from a previous thread on HN [0] [0] - https://news.ycombinator.com/item?id=40476498 https://news.ycombinator.com/item?id=40476498 ------ Edit: Can't reply Lots of old phones still exist, so a virtual/eSIM does nothing to give visibility into those devices. Also, India wants to own the complete end-to-end supply chain for electronics like what China did in the early 2010s, so India has been subsidizing legacy, highly commodified electronic component manufacturing [0] - of which physical SIMs are a major component because they both help subsidize semiconductor packaging as well as IoT/Smart Card manufacturing. A mix of international [1][2] and domestic players [3] have been leveraging physical SIM manufacturing in India as a way to climb up the value chain. On a separate note, this is why I keep harping about India constantly - I'm starting to see the same trends and strategies arising in Delhi like those we'd see the PRC use in the late 2000s and early 2010s, but no one listened to me about China back then because they all had their priors set to the 1990s. No one took the PRC seriously until it was too late, and a similar thing could arise with India - we as the US cannot win in a world where 3 continental countries (Russia, China, India) are ambivalent to antagonistic against us. Even Indian policy papers and makers increasingly reference and even copying the Chinese model when thinking about policy or industrial development, and I've started seeing Indian LEO types starting to operate abroad in major ASEAN and African countries helping their vendors build NatSec capacity (cough cough Proforce - not the American one - and their Offensive Sec teams). Ironically, I've found Chinese analysts to be much more realistic about India's capacity [4][5] unlike Western commentators - and China has taken action as a result [6][7][8] [0] - https://ecms.meity.gov.in/ https://ecms.meity.gov.in/ [1] - https://www.idemia.com/press-release/idemias-production-facility-first-india-be-awarded-gsma-afnor-security-accreditation-euicc-sim-personalization-and-production-management-services-2021-06-30 https://www.idemia.com/press-release/idemias-production-faci... [2] - https://www.trasna.io/blog/trasna-eyes-asian-iot-growth-as-it-expands-into-india https://www.trasna.io/blog/trasna-eyes-asian-iot-growth-as-i... [3] - https://seshaasai.com/products/esim-and-sim https://seshaasai.com/products/esim-and-sim [4] - https://finance.sina.cn/china/gjcj/2022-06-08/detail-imizmscu5759549.d.html https://finance.sina.cn/china/gjcj/2022-06-08/detail-imizmsc... [5] - https://www.gingerriver.com/p/vietnam-or-india-which-one-will-be https://www.gingerriver.com/p/vietnam-or-india-which-one-wil... [6] - https://www.bloomberg.com/news/articles/2025-07-02/foxconn-pulls-chinese-staff-from-india-in-hurdle-for-apple-aapl https://www.bloomberg.com/news/articles/2025-07-02/foxconn-p... [7] - https://www.reuters.com/world/china/india-taking-steps-mitigate-disruptions-due-chinas-rare-earth-curbs-2025-06-27/ https://www.reuters.com/world/china/india-taking-steps-mitig... [8] - https://www.reuters.com/world/china/china-files-wto-complaint-over-india-ev-battery-subsidies-2025-10-15/ https://www.reuters.com/world/china/china-files-wto-complain...
- pdyc 10mo agoWhat should have happened is that they should have forced mobile vendors to allow users to uninstall all apps. What actually happened is that they are asking for their app to be installed as well, sigh.
- SilverElfin 10mo agoI assume that in the US, the major manufacturers of phones and their operating systems already have backdoors for national security reasons. I think back to the past leaks from Snowden regarding the PRISM program. That program specifically included Google and Apple cooperating with the government under the FISA Amendments Act of 2008. So while this state-owned cyber safety app is authoritarian, I wonder if it reflects just the most practical way India’s government can achieve the same things that the US has.
- greycol 10mo agoI am not defending it's use but a secret program is a targeted program, you can't use it in sweeping arrests without parallel construction. Whereas with an openly existing program you can point out that someone has been talking to their friend about how to get abortion medication and arrest them. The real issue with 100% enforcement of law is it requires a society with differing values to not just agree on which laws exist but what just punishment is. Without leeway for differing social judgement or bifurcation.
- radicaldreamer 10mo agoParallel construction is incredibly easy though with confidential informants and honeytraps/entrapment (for another crime, for example).
- mlmonkey 10mo agoThese are just excuses to convince yourself that what the US is doing is "not bad" but what India is doing is "terrible". Both are doing similar things. You have no idea what the US is doing; I have some inkling, and it is terrible. At least India is publicly disclosing what this app does, and that the phone has this app. Do you have any idea what the US does? Hint: that big data center in Utah, what is it for? Another hint: the US has given many billions of dollars to US telecom companies under the guise of "rural broadband" and "rural cell service". Has the state of rural service really changed much in the last 30 years?? Why has all that money been given, then?
- mcny 10mo agoI don't get it. Don't many if not most of these scams originate from India? Wouldn't it be better to stop the scammers directly?
- awestroke 10mo agoIf their goal was to increase the security for their citizens, you would have a point
- orochimaaru 10mo agoActually it’s Cambodia now.
- marginalx 10mo agoNothing in this app stops scammers, scammers use land lines/voip to make calls.
- ConanRus 10mo ago[dead]
- lez 10mo agoIt is happening, in spite many won't really deeply believe. Every day 33 brits are arrested for what they say online. It's happening, and it's time we say no. It's uncomfortable, but we need to do it en masse, right now. Do not buy backdoored hardware, help others get rid of the backdoors, use anonymous technology to organize protests. There has to be a line.
- logram-llc 10mo agoDo you have a source for the Brits being arrested?
- calvinmorrison 10mo agoA Liberty GB spokesman said: "Mr Weston was standing on the steps of Winchester Guildhall, addressing the passers-by in the street with a megaphone. "He quoted an excerpt about Islam from the book The River War by Winston Churchill. "Reportedly, a woman came out of the Guildhall and asked Mr Weston if he had the authorisation to make this speech. "When he answered that he didn't, she told him: 'It's disgusting', and then called the police. "Six or seven officers arrived. They talked with the people standing nearby, asking questions about what had happened. "The police had a long discussion with Mr Weston, lasting about 40 minutes. "At about 3pm he was arrested. They searched him, put him in a police van and took him away."
- rpcope1 10mo agoYou got a loiscence for that speech? If even half of that is true, I can't fathom why someone would willingly live in that total shithole of a country.
- calvinmorrison 10mo agowillingly live in their homeland? yeah i don't know either bro
- guywithahat 10mo ago
- kwar13 10mo agoI have to say I'm really surprised that I didn't find "fighting CP & terrorism" as the main push for this.
- quantum_state 10mo agoHorrible for a so-called democratic country …
- deleted 10mo ago[deleted]
- jeroenhd 10mo agoThe clipper chip was brought to us by the country that proclaims to spread democracy across the world. Democracies can be authoritarian if you scare the public enough.
- nxm 10mo agoDemocrats in the US touting „combating hate speech” would love to do the same here
- spaceman_2020 10mo agothe good news is that I'm personally on my last few years online. I don't think there's anything really worthwhile in this space to do as a contributor or even as a consumer
- bobse 10mo ago[dead]
- Animats 10mo agoWhat does this app actually do, in detail? Anyone know?
- more_corn 10mo agoIt doesn’t matter what the app does today it can be made to do anything they want after the fact. Monitor speech, location, contacts, content, preserve evidence for prosecution, inspection your dinner choices or your sexual habits. This is on the far end of the spectrum of bad.
- MonkeyClub 10mo ago> It doesn’t matter what the app does today it can be made to do anything they want after the fact. This is an extremely important point of universal application that can't be emphasized too much. Even if one agrees with a current politician's position, once the precedent is set, there's nothing stopping an administration down the line extending the reach of an already installed and by then socially accepted mechanism. Someone called this the "totalitarian tip toe"; that guy (who shall rename unnamed) was "a bit weird", but his concept stands anyway imo.
- nrhrjrjrjtntbt 10mo agoWhen the app is mandated installed then user permissions are also moot. It will have full access an app can have.
- adrr 10mo agoWouldn't that require Apple to sign the app with their own key to get low level API access? Has apple ever done that with anyone?
- ssivark 10mo agoThis seems to be the app: https://www.sancharsaathi.gov.in/ https://www.sancharsaathi.gov.in/ Looks like it's quire popular/established already, with over 10 million downloads. Basically a "portal" for basic digital safety/hygiene related services. Quoting Perplexity regarding what facilities the app offers: 1. Chakshu: Report suspicious calls, SMS, or WhatsApp for scams like impersonation, fake investments, or KYC frauds. 2. Block Lost/Stolen Phones: Trace and block devices across all telecom networks using IMEI; track if reactivated. 3. Check Connections in Your Name: View and disconnect unauthorized numbers linked to your ID. 4. Verify Device Genuineness: Confirm if a phone (new or used) is authentic before purchase.
- WhereIsTheTruth 10mo agoSovereign tech stacks matter Without domestic silicon or OS, you're forced to mandate bloatware that users can see Real power operates at the silicon/firmware level, invisible, unremovable, and uncompromisable This is a cringe move from India https://www.centerforcybersecuritypolicy.org/insights-and-research/congress-proposed-chip-security-act-threatens-to-create-new-cyber-vulnerabilities-in-u-s-semiconductors https://www.centerforcybersecuritypolicy.org/insights-and-re...
- mk89 10mo agoWhen the hell do we start to build these products here again like it was just 20 years ago? And let's stop with "it's too expensive here...". For God's sake, these are products we use every minute of our lives. Enough is enough...
- banjwoorri 10mo ago[dead]
- sharadov 10mo agoIndian government is big on pronouncements. It will be a garbage app that most likely will not work, considering the historical incompetence of the Indian government's expertise in all things tech. I am pretty certain Apple and Samsung will pay off someone in the government.
- lacy_tinpot 10mo agoIsn't one of the largest payment processors in the world made by the Indian Government? Personally I wouldn't risk my personal digital privacy on the incompetence of the government. I'd assume the opposite.
- aeyes 10mo agoNot really, UPI is developed and operated by several large banks. Maybe you were thinking about PIX in Brazil which is developed and operated by their central bank.
- chupchap 10mo agoI thought it was made by NPCI, which is owned by RBI, AND the IBA. It is ultimately a government organisation.
- captn3m0 10mo agoNPCI ownership is not with RBI and IBA. RBI does not have any NPCI shares.
- lacy_tinpot 10mo agoNo. UPI. It's an initiative by the Indian government. It's controlled by the RBI, just through a complex public-private corporate structure through NPCI. UPI is much larger and more international than PIX. It's currently processing iirc something like 200 billion transactions. UPI is also used in several countries, France being among the most recent examples. As such UPI has a broader scope than PIX and requires a public-private corporate structure with stakeholders from both sides. But this is off topic. The competence of the Indian government to at the very minimum partner with Industry shows that such software preloaded on phones is a threat to the civil liberties of people that the State shouldn't encroach on. This is a violation of individual privacy.
- m3kw9 10mo agoIf the app requires an on device backdoor, Apple won’t likely cave to it. If it’s sandboxed, the amount of things it can do is limited to tracking user location, given Apple also disabled turning off location sharing
- SamuelAdams 10mo agoI wonder if this will cause a reduction in remote jobs for citizens. Compliance with US laws like HIPAA and FERPA have strict requirements regarding access. Many employees use 2FA on their personal devices, which if passed this law would interfere with.
- tzs 10mo agoHow would this interfere with 2FA?
- j16sdiz 10mo agoDepends on what permission this app have. - Is this a (voice) call blocker? - Can it intercept SMS? - Can it enumerate installed app and read data from other apps?
- MangoToupe 10mo agoOr, maybe it'll finally convince people that SMS is the worst of all worlds when it comes to security (and phone numbers for identity). Doubt it tho
- earlyreturns 10mo ago[flagged]
- nephihaha 10mo agoThis is going to tie in with digital ID. Obviously the Indian government has never been corrupt or abusive.
- renewiltord 10mo agoThese things are more a factor of aggregate risk handling. As an example, if you have tuberculosis it is possible even in the US for the country to mandate that a doctor watch you take the treatment. Totalitarian? Authoritarian? A tool that could be used to force someone to have to show up to where a state-controlled authority could confirm that they are? Yes, all of these things could be words you could assign to that. But societal combined risk is commonly handled in this way. In the US, if you employ someone you have to report that you paid them to a central federal government. Way to track someone? Surveillance state? All words you could use. And the government previously restricted gambling and so on. The question isn't "why would a bad government do these things?". The question is "would a benevolent government do these things?" and "if so, why?". And the answer is quite straightforward, I think: Someone in the government has observed that there is a great deal of cyber crime in India. A fairly uneducated population, with very high smart-phone penetration (85%+ apparently), and a large number of fraudulent actors that their federal government is unable to enforce against. So they're attempting to attack the problem where they can. This is ultimately India. They don't need insidious "app on your phone" / stingray / any other sophisticated solution. The local politicians can manipulate local authorities to get your cell tower association data and SMS. And if they want your comms devices they will rubber-hose the secrets out of you. Someone I know worked at a big FAANG. He's Indian so went back to Bangalore to see his ailing mother. One day he took an auto-rickshaw while wearing his FAANG sweatshirt. The driver took him to a makeshift jail where he, police officers, and a magistrate conspired to threaten the guy with prison unless he paid $10k. $10k is nothing to a FAANG engineer, so he paid up, was brought in front of court on some lesser charges and then had to pay a small fine (much less than $10k). And then he flew back to the West Coast and never returned to India. Trying to reason about this kind of place using the perspective of the West is meaningless. I think it unlikely they're trying to use this as cyber-surveillance. India simply does not have the infrastructure necessary to do that at scale. And they have the infrastructure for the rubber-hose, and Indians wear their identification on their sleeve, so to speak. Names point to ethnic groups and castes. Primarily endogamous marriage means if you want to perform violence against groups you can simply spread out from one member of the family unit being visibly of that group. Using an app to get access to someone's data there is sort of like using Heartbleed to get root on a machine on which you are in /etc/sudoers with NOPASSWD.
- spoaceman7777 10mo agoSo, basically, this is just SIM card functionality for the age of eSIMs? A lot of people in this thread seem unaware of what SIM cards actually are and do.
- wosined 10mo agoSounds so authoritarian. Luckily, in the UK you only have to scan your face and ID to access cat photos.
- ibejoeb 10mo agoIt's all happening really quickly, so I haven't been able to keep up. I know Starmer said that digital ID will be mandatory to work in the UK. Did he mention how that would be implemented? Is the UK going to issue and official device to everyone in country, or are the people supposed to pay for it? What about homeless, poor, and the provisional residents?
- zarzavat 10mo agoI assume that almost everyone in the UK who is able to work has a smartphone already. If they were to require digital ID for pensions or disability benefits there would be more problems.
- ibejoeb 10mo agoEven if that were the case, by what mechanism are they commandeering it? That's essentially what I was thinking about in this India case. Undoubtedly most people will comply, but there will be a few who don't, so I'm curious what the plan is to bring them in line.
- zarzavat 10mo agoUK isn't commandeering anything. The UK government hasn't decided yet how digital ID will work, currently it's just a talking point. Probably it will be an app that you install, like the NHS app. Nobody is proposing that it be installed by default. Apple separately announced that a Digital ID feature will be built into iOS[0] which the UK may use or not use. > few who don't, so I'm curious what the plan is to bring them in line They will be told by their employer to get it otherwise they will lose their job. Just the same as now, only at the moment you need a paper passport rather than a smartphone. [0] https://www.apple.com/newsroom/2025/11/apple-introduces-digital-id-a-new-way-to-create-and-present-an-id-in-apple-wallet/ https://www.apple.com/newsroom/2025/11/apple-introduces-digi...
- tintor 10mo agoDoes it apply to iPhones manufactured to India, which are meant for export to other countries?
- nbsande 10mo ago> With more than 5 million downloads since its launch, the app has helped block more than 3.7 million stolen or lost mobile phones, while more than 30 million fraudulent connections have also been terminated. I might be reading this wrong but these numbers seem very weird. Did more than half the people who downloaded the app block a stolen phone? And did each person who downloaded the app terminate 6 fraudulent connections?
- SSLy 10mo ago> And did each person who downloaded the app terminate 6 fraudulent connections? That much is believable, if not on the low side. Spam there is intense.
- chloeburbank 10mo agoIt's not rare to have multiple phone numbers registered to a person's name fraudulently in India. Therefore, in this aspect the app will list out all the connections under the user's Aadhar (Indian Digital ID).
- blackoil 10mo agoIt's easy just use made up definitions for "helped", "fraudulent" and "terminated".
- semiquaver 10mo agoAnd also use made up numbers, just to be safe.
- HackerThemAll 10mo agoSoon in U.S. For the safety and security of children, of course.
- rationalfaith 10mo ago[dead]
- zkmon 10mo agoDoes this mean visitors to India would also get this app installed on their phone as soon as they land in India?
- kylehotchkiss 10mo agoApple's geotargetting was at least in the past tied to where device was sold. Example is FaceTime in UAE: phones sold there will never have working FaceTime anywhere but if you bring your American phone in, it seems to work. But easy enough to tie it to iCloud region - you have to set your device and iCloud to Indian region to be able to use many of their region specific payment methods (ie UPI)
- akg_67 10mo agoI am visiting India. The app wasn’t installed automatically. I received the SMS telling me to install the app but I am using an Indian sim borrowed from a friend. So I figured I got the SMS because of Indian sim. My wife didn’t receive sms as she is using Airalo esim data service. I didn’t know the SMS was legit or not and I just marked it as spam. The challenge I have found with mobile in India is the excess of sms spam. Also the sender is always some cryptic alphanumeric characters so authenticity is difficult to judge.
- alwinaugustin 10mo agoWant to check number of SIMs in your name? Download Sanchar Saathi to check:Links to Play store and App Store. Department of Telecom I was getting these messages for sometime and installed it finally. It is the same app that is mentioned in the article. My phone is already in the system then.
- bossyTeacher 10mo agoAnd this is why we need unlockable bootloaders and stuff like Graphene and LineageOs. Having only two mobile Os is very convenient until stuff like this happens.
- yahoozoo2 10mo ago[dead]
- gnarlouse 10mo agoTotalitarianism is a form of class warfare. Make class warfare M.A.D.
- rglover 10mo agoThe more I see stuff like this, the more I think "you know, I don't think the world is collapsing, I think the old world is collapsing." Governments in their current form are increasingly becoming irrelevant (h/t to "The Fourth Turning") and actions like this prove it.
- fn-mote 10mo agoHow is this demonstrating governments are irrelevant? It seems like it is demonstrating their continued power. Steelmanning the argument, perhaps you see this as a demonstration that corporate power has gotten so large the government is being forced to react. I might believe that, but I can’t get from there to irrelevance.
- user3939382 10mo agoI can actually not have a phone like I don’t need one that bad if they want to make it a nightmare. I can go back to a dial tone.
- chloeburbank 10mo ago"cyber safety"
- 0ckpuppet 10mo agoIf it can be abused, it will be abused. Corruption exists anywhere humans exist. Convenience and security are the bait. Why do people want to be caged?
- reactivematter 10mo agoHow is it different from preloading apps like Netflix, GMail and other shady apps for profits that collects a lot of data. Considering India's low literacy, having a state owned cyber safety app shouldn't be much of an issue. It's not like a backdoor, but safety of citizens, which is the prime mandate of a sovereign state.
- cheema33 10mo ago> It's not like a backdoor, but safety of citizens, which is the prime mandate of a sovereign state. This sounds great in theory. But in practice this sort of thing is rife for abuse. Say, I have complete control over what this app installed on your phone does in the background. And you were my political opponent. Would you trust me to not use this backdoor into your phone to my advantage? Apps like Netflix, GMail are not forced on users by a govt. It is an open marketplace. Users have options. They are free to buy phones that do not have those apps pre-installed.
- alabhyajindal 10mo agoThe difference is restricting removal of the app. It takes away the user's choice. As far as I know all preloaded apps, at least on Android, can be disabled if not uninstalled. > The November 28 order, seen by Reuters, gives major smartphone companies 90 days to ensure that the government's Sanchar Saathi app is pre-installed on new mobile phones, with a provision that users cannot disable it.
- sanjayjc 10mo agoI found a directive[1]: > Pre-installed App must be Visible, Functional, and Enabled for users at first setup. Manufacturers must ensure the App is easily accessible during device setup, with no disabling or restriction of its features While I can get behind the stated goals, the lack of any technical details is frustrating. The spartan privacy policy page[2] lists the following required permissions: > For Android: Following permission are taken in android device along with purpose: > - Make & Manage phone calls: To detect mobile numbers in your phone. > - Send SMS: To complete registration by sending the SMS to DoT on 14422. > - Call/SMS Logs: To report any Call/SMS in facilities offered by Sanchar Saathi App. > - Photos & files: To upload the image of Call/SMS while reporting Call/SMS or report lost/stolen mobile handset. > - Camera: While scanning the barcode of IMEI to check its genuineness. Only the last two are mentioned as required on iOS. From a newspaper article on the topic[3]: > Apple, for instance, resisted TRAI’s draft regulations to install a spam-reporting app, after the firm balked at the TRAI app’s permissions requirements, which included access to SMS messages and call logs. Thinking aloud, might cryptographic schemes exist (zero knowledge proofs) which allow the OS to securely reveal limited and circumscribed attributes to the Govt without the "all or nothing", blanket permissions? To detect that an incoming call is likely from a spam number, a variant of HIBP's k-Anonymity[4] should seemingly suffice. I'm not a cryptographer but hope algorithms exist, or could be created, to cover other legitimate fraud prevent use cases. It is a common refrain, and a concern I share, that any centralized store of PII data is inherently an attractive target; innumerable breaches should've taught everyone that. After said data loss, (a) there's no cryptographically guaranteed way for victims to know it happened, to avoid taking on the risk of searching through the dark web; (b) they can't know whether some AI has been trained to impersonate them that much better; (c) there's no way to know which database was culpable; and (d) for this reason, there's no practical recourse. I recently explained my qualms with face id databases[5], for which similar arguments apply. [1] https://www.pib.gov.in/PressReleasePage.aspx?PRID=2197140®=3&lang=2 https://www.pib.gov.in/PressReleasePage.aspx?PRID=2197140&re... [2] https://sancharsaathi.gov.in/Home/app-privacy-policy.jsp https://sancharsaathi.gov.in/Home/app-privacy-policy.jsp [3] https://www.thehindu.com/sci-tech/technology/pre-install-sanchar-saathi-app-on-new-phones-by-march-2026-dot-tells-phone-makers/article70345721.ece https://www.thehindu.com/sci-tech/technology/pre-install-san... [4] https://www.troyhunt.com/understanding-have-i-been-pwneds-use-of-sha-1-and-k-anonymity/ https://www.troyhunt.com/understanding-have-i-been-pwneds-us... [5] https://news.ycombinator.com/item?id=46054724 https://news.ycombinator.com/item?id=46054724
- gsky 10mo ago[flagged]
- mindaslab 10mo agoThe government is afraid of its people.
- seatac76 10mo agoSuch a stupid move, I’d bet that it’ll be withdrawn quietly.
- melvinodsa 10mo agoIn wrong hands, this is a very dangerous tool.
- deleted 10mo ago[deleted]
- figmert 10mo agoMeanwhile the US has more than 4 different state owned cyber crime apps named after random things such as Google, Apple, Microsoft and Facebook, and many more. The kicker is they run all over the world. Anyway, that doesn't in any way negate that this is shit for the people of India.
- shevy-java 10mo agoIt's always the same - governments suddenly wanting to spy on people. We need a world where this can be guaranteed to not happen. We need 3D printing everywhere, without restrictions or payload attached.
- Kanishk_Kumar 10mo agoWhen Deep State is doing this through Google and Apple's backdoor, its okay. But when a democratically elected entity does this in its own region, they start getting lectures on freedom.
- rcMgD2BwE72F 10mo agoFind one HN thread where consensus/majority is that Apple/Google backdoors are okay
- jamesnorden 10mo agoLiterally nobody thinks that's ok besides the people doing it.
- petterroea 10mo agoI wish the article talked more about this app India wanted to pre-install. Forcing the pre-install of apps is worrisome in general, but there's some nuance that is missed by not explaining what is being forced on the citizens. "Cybersecurity app" can mean a lot. From the looks it's a government-sponsored "brick my phone"-kind of app for disabling stolen phones?
- deleted 10mo ago[deleted]
- batrat 10mo agoIt's a dangerous trend that is happening. From EU chat control to this, is like everybody is so interested to know what the hell I'm doing with my life. The problem is with my kids, they likely will not enjoy freedom as we did it.
- radium3d 10mo agoIs this going to be a requirement for BRICS member countries?
- gblargg 10mo agoDO NOT PRELOAD! DO NOT PRELOAD!!!
- covabty 10mo ago[dead]
- Lapsa 10mo agoreminder - there's tech out there that enables reading your mind
- choeger 10mo agoJust another round in the decades-long battle of who owns your device: Industry or state. It's never you, mind you, who owns your device. The perversion is that you are legally responsible for what happens with your device, but you are unable to prevent others from using it as they wish. An app like this is automation for putting people into jail. Just upload some illegal content and then "detect it". There's literally nothing you can do to defend against this attack, and it will work until it's overused.
- mananonhn 10mo ago[dead]
- SuperSandro2000 10mo agoWhen do we find the first Critical CVE in it?
- john61 10mo agoThe year of the Linux phone in India is coming.
- pete1302 10mo agoOK: added to debloat list.
- bitlad 10mo agoToo bad, 90% traffic they will monitor would be porn.
- risfriend 10mo agoThis is just bad PR from Indian government. Communication minister clarifies the app is optional https://timesofindia.indiatimes.com/technology/tech-news/telecom-minister-jyotiraditya-scindia-makes-a-big-clarification-on-sanchar-saathi-app-says-it-is-optional-and-not-mandatory/articleshow/125712669.cms https://timesofindia.indiatimes.com/technology/tech-news/tel... Reuters/BBC have been famous to pounce and sensationalizing.
- piyushpr134 10mo agonot really. you may read the official notification here https://www.pib.gov.in/PressReleasePage.aspx?PRID=2197140®=3&lang=2 https://www.pib.gov.in/PressReleasePage.aspx?PRID=2197140&re... "Manufacturers must ensure the App is easily accessible during device setup, with no disabling or restriction of its features"
- master-lincoln 10mo agoSounds like both articles are right: There was a private government order to preload that app to smartphone makers. And it is not mandatory for citizens to use the app. No sensationalizing apart from you it seems
- hereme888 10mo agoAs "totalitarian" as it sounds, it actually makes sense that India's govt had to take such drastic steps. Telecom providers and smartphone manufacturers have criminally refused for decades to protect end-users, because it makes them money. Govt can't have their population at large being scammed by criminals and do relatively nothing about it. It's a huge economic and productivity drain people seem to have "accepted as normal". So how do you not shut down and arrest these greedy international corporations, which would disrupt a country's infrastructure, despite ongoing warnings? Force them. To me it's akin to the US govt mandating software that allows users to report any and all spam, fully traceable to criminals and providers, whom the govt could prosecute/heavily fine 100% of the time. Dangerous 2-edged sword, but if takes down that despicable scam industry, later it can transition to a law mandating the same protection but in a privacy a preserving manner.
- tedggh 10mo ago“greedy international corporations”. I see where you coming from.
- tedggh 10mo ago“The welfare of the people has always been the alibi of tyrants.”
- bilekas 10mo ago>With more than 5 million downloads since its launch, the app has helped block more than 3.7 million stolen or lost mobile phones Ah yes, so because someone has stolen MY phone, I should give up all my right to privacy and allow the government to have their claws in my phone. Logic. What a silly point to make when 'findmyphone' services, which are OPT-IN litterally do the same thing.
- deleted 10mo ago[deleted]
- HardwareLust 10mo agoApple said this morning they will not comply.
- LightBug1 10mo agoThe only correct response.
- thisislife2 10mo agoA government minister has clarified that the app is not mandatory but "optional" and can be deleted by the user is they don't want to use it - Sanchar Saathi app optional, can be deleted, says Telecom Minister Scindia - https://www.thehindu.com/sci-tech/technology/sanchar-saathi-app-jyotiraditya-scindia-parliament/article70348490.ece https://www.thehindu.com/sci-tech/technology/sanchar-saathi-... .
- arunabha 10mo ago> A government minister has clarified that the app is not mandatory but "optional" and can be deleted by the user In India it doesn't really mean anything. As an example the biometric based id 'Aadhaar' is 'voluntary' on paper, The Modi govt had to concede this after a Supreme court judgement that made it clear that Aadhaar cannot be made mandatory. However in practice it's anything but. Govt officials will openly refuse to consider other forms of id. They have been informally told by the highest rungs of govt that they will be protected against any complaints and that they need to insist on Aadhaar. The whole point is to make daily life practically impossible without Aadhaar so that the citizens give in and 'voluntarily' give their biometrics.
- captn3m0 10mo agoThe order states: > Ensure that the pre-installed Sanchar Saathi application is readily visible and accessible to the end users at the time of first use or device setup and that its functionalities are not disabled or restricted. https://www.pib.gov.in/PressReleasePage.aspx?PRID=2197140®=3&lang=2 https://www.pib.gov.in/PressReleasePage.aspx?PRID=2197140&re... (Press Release) https://x.com/arvindgunasekar/status/1995540552205697079 https://x.com/arvindgunasekar/status/1995540552205697079 (Leaked Order) Does not sound optional. (I do not have an Aadhaar and have to fight across regulated domains - finance, insurance, banking, investments, even renting).
- deleted 10mo ago[deleted]
- nout 10mo agoWhy would you give the government such power? Don't think about the current government that you may be happy about - think about the next one.
- albert_e 10mo agoThe developers of this app have a @ gmail.com mailbox listed as the support contact. And they claim to protect people from fraud / phishing / scams. > https://x.com/shantanugoel/status/1995874411543671208 https://x.com/shantanugoel/status/1995874411543671208 >> sanchaarsaathi.dot AT gmail dot com >> broadbandmission AT gmail dot com
- whizzter 10mo agoThe article mentions blocking phones with stolen IMEI's, but iirc that's mostly up to telecom network providers to block rather than some "app". Also doesn't Apple have their own locking technology? In short, the arguments for this seems to stink?
- deleted 10mo ago[deleted]
- jmonty900 10mo ago> Apple's iOS powered an estimated 4.5% of 735 million smartphones in India by mid-2025, with the rest using Android, Counterpoint Research says. Sounds like Google should be the one leading the charge against this. Will be interesting to see what they do. > The app is mainly designed to help users block and track lost or stolen smartphones across all telecom networks, using a central registry. It's an app. That's all it does now (presumably). Once installed, it can be changed in the future to do all kinds of terrible things. This is big brother.
- pedromoss 10mo agoGovernment of India issued a follow up gazette notification withdrawing mandatory pre-installation of Sanchar Saathi app on smartphones: https://news.ycombinator.com/item?id=46132822 https://news.ycombinator.com/item?id=46132822