9 ms·
India scraps order to pre-install state-run cyber safety app on smartphones
- nephihaha 10mo agoIf this means what I think it does, it's good news... But unfortunately, I've a nasty feeling that this will be attempted again and again until it sticks. We shouldn't call it "cyber safety" as that is a loaded phrase here. Obviously other considerations were part of it.
- subscribed 10mo agoThey'll wait for UK/AU/EU to enforce one first. Like with the chat control in the EU now, the foot is already blocking the door
- MonkeyClub 10mo agoYeah, I'm with sateesh in a sibling comment in that this is a win for the digital citizenry's awareness, but I also agree with you that when the EU caves in everyone else will follow. And I'm sure in the end it will cave in. The "they" have a clear plan supported by infinitely more patience and resources than the "us" can muster, and the von der Leyen presidency has shown clear signs of direction towards more control, less privacy (by weakening the GDPR), and less of the good kind of regulation in industry. As an EU citizen, I'm very unhappy with the Union's recent direction. But, at least for now, hooray for the temporary victory on the Indian front!
- Arnt 10mo agoThe app itself seems to be a reinvention of https://www.gsma.com/solutions-and-impact/connectivity-for-good/public-policy/mobile-policy-handbook/consumer-protection/mobile-device-theft/ https://www.gsma.com/solutions-and-impact/connectivity-for-g... which is good I suppose, but why not use the original registry?
- kylehotchkiss 10mo agoAppetite for `Make in India` and favor for homegrown solutions. Indian gov/companies is more capable of delivering a solution better suited for the many local languages. Instead of mandating, they should just try to put some more minds together and make a general purpose India super app to help citizens access gov services that isn't PayTM.
- Arnt 10mo agoI don't see why the languages matter. AFAICT, the major factor here is making a stolen phone useless on as many networks as possible. The point of the GSMA registry is that one shouldn't be able to ship a stolen phone across the border (to Pakistan/Bangladesh/China) and sell it.
- kamaal 10mo agoLooks like the complaining and protesting on Twitter helped, even if was serious, and some just memes. Somethings to note- 1. Most Indian bureaucracy is clueless about tech things, and just goes by whatever somebody who sounds like techy enough is selling them. Which in this case I'm guessing is a data mining company/lobby. 2. The information derived can be used for various purposes. Plotting election trends, economics, spotting general trends pro/against politics and other nefarious causes. etc. 3. Spying. 4. Using information to go after political opponents. 5. Demographic targeting, which in Indian context almost always means a pogrom against groups, which other groups don't like. 6. Selling data to commercial entities for better targeting, or even social engineering buying choices etc. There could be many others. But its kind of nice that it was taken back. Having said this, it will be pushed again at some point when people are busy with a crisis and this will be sold as a fix.
- Tade0 10mo agoI believe Apple's resistance to this notion played a role.
- gamesbrainiac 10mo agoThis was never going anywhere and if the Indian government thought it could get away with effectively installing spyware, then they were just self indulgent.
- ignoramous 10mo agoBugging communication devices has long been a government / law enforcement tactic, mostly enabled by telcos via ITU, which since its inception has been a willing collaborator. Ex A: Ind x ITU, https://cis-india.org/internet-governance/blog/india-itu-resolution-busan-2014-revised https://cis-india.org/internet-governance/blog/india-itu-res... Ex B: China x ITU, https://datatracker.ietf.org/liaison/1677/ https://datatracker.ietf.org/liaison/1677/
- gamesbrainiac 10mo agoIt has been, but getting Apple to do it was dumb. They could've just used a government app that everyone has to use, and put the bugging in there.
- kylehotchkiss 10mo agothis glosses over the point that they could have just accomplished that with already effectively required UPI apps
- stonecharioteer 10mo agohttps://www.pib.gov.in/PressReleasePage.aspx?PRID=2198110®=3&lang=1 https://www.pib.gov.in/PressReleasePage.aspx?PRID=2198110&re... Read between the lines? > Given Sanchar Saathi’s increasing acceptance, Government has decided not to make the pre- installation mandatory for mobile manufacturers.
- clot27 10mo agooutrage works
- unmole 10mo agoOutrage works when the party in government doesn't have an outright majority in parliament.
- sateesh 10mo agoThe only upshot of this whole saga seems to be an increased awareness (though a small bit) in general public about importance of privacy in the digital world. Most of the media outlets (both English and regional language newspapers) provided a prominent coverage of this news.
- alephnerd 10mo agoIt was Apple's pushback that lead to the DoT backing down [0], but they will most likely either try to push this again if they are able to assuage Apple (eg. drop the $38B anti-trust bill [1]), or will potentially adopt China- and Vietnam-style data sovereignty regulations. English speaking urban Indians are loud on English media but ultimately don't matter for political decisions because they can't actually flip an LA or LS election. You need to either be a significant voting bloc or a major economic bloc to become a veto player in any country. [0] - https://www.reuters.com/sustainability/boards-policy-regulation/apple-resist-india-order-preload-state-run-app-political-outcry-builds-2025-12-02/ https://www.reuters.com/sustainability/boards-policy-regulat... [1] - https://www.reuters.com/sustainability/boards-policy-regulation/apple-contests-indias-antitrust-penalty-law-with-risk-38-billion-fine-filing-2025-11-26/ https://www.reuters.com/sustainability/boards-policy-regulat...
- akudha 10mo agoWill the increased awareness change anything though? After Snowden, nothing seemed to have changed, it just seems to be getting worse. Most likely, Indian government will try again
- lern_too_spel 10mo agoAfter Snowden, the single illegal U.S. surveillance program he leaked was shut down, the browser vendors essentially forced https everywhere, companies encrypted their WANs, and E2EE became popular in consumer applications. That's just off the top of my head.
- vpShane 10mo agotell that to salt typhoon who collected copious amounts of data on all of us. https still uses unencrypted client hello's (ECH) across the vast majority of the internet, showing which domain the client is visiting in plaintext for multi-site servers to do SNI. DNS is still plaintext on most consumer routers/models provided by ISPs, stingray technology exists in the wild and is widely used to mimic cell towers. E2EE is not popular in consumer applications, even Telegram isn't E2EE and the main ones that claim they are like X's new Chat they have the keys on; Matrix having E2EE still shows meta data in plain text, room names in plain text. While iMessages, RCS, Signal are mostly mainstream, most people are unaware of the need for E2EE. RCS is its own set of issues. Pegasus, Cellbright, I can go on and on with the spyware companies that can just send a text message and infect devices with 0click exploits. We can have E2EE but if they can just see the screen or hook in to the messaging app's memory doesn't mean much. Pick up your cell phone, is it connected to Wifi? Can it see other Wifis? Apps track those nearby SSIDs and report to major databases to have accurate geo-location data down to the spot we stand. Don't get me started on Ad-Tech. The EU wants to install backdoors on everybody's devices and get rid of encryption entirely. Zero Trust Technologies are a fun thing to read in to, especially the need for them.
- spprashant 10mo agoThey ll make it mandatory to access critical services at a later point. Tax payments, utility enrollments stuff like that. That is how they ramped up enrollment in Aadhaar UID.
- jeswin 10mo agoIn a country with dozens government supplied IDs, Aadhaar has been a godsend for the common man. It's one card to open a bank account, buy a SIM card, apply for a loan, enter an airport, or whatever. I held out for many years due to privacy reasons. In the end, I changed my mind - its just immensely useful to the general public.
- mandeepj 10mo agoCongratulations! Your data is already sold out for Rs. 40 in black market! Also, why do you need aadhar to enter airport? Now, the morons in charge are making it mandatory to book a gas cylinder as well. It’s like once a blind suddenly starts seeing, he wants to capture everything.
- never_inline 10mo agoYour data will be sold regardless of whether you have Aadhar or not. You just may not know it.
- aiauthoritydev 10mo agoThere is no concept of privacy in India. Your health and banking data is available to literally anyone interested. aadhar is not relevant to that.
- arunabha 10mo agoYou just demonstrated first hand the point made by GP. When the supreme court ordered the Govt to cease making Aadhaar mandatory, they just responded by adding so much friction to daily life without Aadhaar that most people, including privacy conscious folks like you just gave in.
- tensegrist 10mo agopreviously: https://news.ycombinator.com/item?id=46104193 https://news.ycombinator.com/item?id=46104193
- ChrisArchitect 10mo agoGov release: https://www.pib.gov.in/PressReleasePage.aspx?PRID=2198110®=3&lang=2 https://www.pib.gov.in/PressReleasePage.aspx?PRID=2198110&re... (https://news.ycombinator.com/item?id=46132822 https://news.ycombinator.com/item?id=46132822)
- silisili 10mo agoI've not been following this closely, but reading the headlines each day....is the timeline roughly - India: Every phone must install a cyber safety app Apple: No India: OK, nevermind ?
- alephnerd 10mo agoPretty much. Apple has been a massive driver for India's electronics manufacturing boom, because it's Apple that has been strongarming it's suppliers like Foxconn and Envision to start manufacturing (not just assembling) in India - just like how Apple helped turbocharge China's electronics upskilling in the late 2000s and early 2010s which helped Apple vendors like BYD and BOE become global competitors in the 2020s. Tata Group has also become an Apple vendor now as well for both assembly as well as chip packaging, so they probably helped arbitrate. Apple and India are also negotiating over a potential $38B anti-trust bill [0] which is a significantly higher priority for both parties. [0] - https://www.reuters.com/sustainability/boards-policy-regulation/apple-contests-indias-antitrust-penalty-law-with-risk-38-billion-fine-filing-2025-11-26/ https://www.reuters.com/sustainability/boards-policy-regulat...
- notepad0x90 10mo agoDo people have rights around the world, to not use a smartphone or the internet to access critical services/commerce? Shouldn't that be a thing if not?
- stackedinserter 10mo agoCanadian government must provide services for blind and deaf people via Teletype or something, so at least state services are covered. The question is what makes service critical. Is Expedia or Uber critical?
- notepad0x90 10mo agoTravel counts, sure. Food, travel, accommodations/rent/housing. Freedom to eat, to have shelter, to move about, start a business or trade with other people. New technology should not result in a reduction of freedoms, or even privileges.
- stackedinserter 10mo agoSo when I'm banned on Uber Eats, it counts as infringement of rights? Is it what you're saying?
- notepad0x90 10mo agoA ban, no, but if ubereats is required to purchase foods for example, that is an infringement. You don't have to use ubereats to buy food. Let me spin it a bit, if a new tech comes along and that results in not being able to use delivery apps like ubereats to get food, that new tech should be considered an infringement of rights. "New means by which individuals purchase food may not inhibit or otherwise reduce their ability existing means of purchasing food" that's how I'd word it. An uber eats ban is not a new mean of buying food but uber eats itself is. If doordash collaborates with payment card processors for an exclusive payment processing for delivery apps, that would be an infringement for example, because that's new tech/means reducing existing means.
- boltzmann64 10mo agoThis is the standard playbook. And the gov just pulled a switcheroo: Policy that is hard to pass: SIM binding for all messenger apps and automatic log out every 6 hours for desktop apps. Even more egregious policy: Pre-install spyware that cannot be disabled. Withdraw the egregious policy on outrage, and people think they have won the battle.
- sidcool 10mo agoBBC news about India has been so negative in the past few years, I have stopped trusting them. Of course there are other news about them spoofing videos.