Renowned Ethical Hacker Baptiste Robert aka Elliot Alderson (twitter.com/fs0c131y) has found a security issue in the Aarogya Setu COVID-19 contact tracing app developed by the Government of India that privacy issue of the sensitive data of 90 million users registered on the app.
In a series of tweets, he informed Aarogya Setu’s official twitter handle that the app has a security issue and he has the power to access the data of 90 million Indians.
49 minutes after this tweet, @IndianCERT and @NICMeity contacted me. Issue has been disclosed to them.
— Baptiste Robert (@fs0c131y) May 5, 2020
He also mentioned Rahul Gandhi, INC MP from Wayanad district of Kerala who raised issue the the app has security issue and it can be used as a surveillance system.
The Hacker did not disclosed the issue yet as the CERT-IN and NIC contacted him within 49 minutes of the tweet.
He was preparing for the hack from a short time and hacked it within five hours with the use of a valid Indian mobile number that is not registered on the app.
I need to do one final test. If you have a valid Indian phone number and never created an account on Aarogya Setu, can you send me a DM now? https://t.co/j8eFAFTm6X
— Baptiste Robert (@fs0c131y) May 5, 2020
Response from Aarogya Setu:
After contacted with the hacker, in some hours Aarogya Setu teams posted a message on social media about the data security of the app.
Statement from Team #AarogyaSetu on data security of the App. pic.twitter.com/JS9ow82Hom
— Aarogya Setu (@SetuAarogya) May 5, 2020
The app developers said that its contact-tracing app Aarogya Setu “by design” collects the location data of its 90 million users and allows them to view the concentration of people who have tested positive for the COVID-19 in their vicinity.
In reply to which the hacker said you said “nothing to see here”
We will see. I will come back to you tomorrow.
And later posted a tweet
Do you know what triangulation is @SetuAarogya?
— Baptiste Robert (@fs0c131y) May 5, 2020
We expect more details will be revealed soon.
Findings revealed by the Security Researcher:
And yes, yesterday:
— Baptiste Robert (@fs0c131y) May 6, 2020
– 5 people felt unwell at the PMO office
– 2 unwell at the Indian Army Headquarters
– 1 infected people at the Indian parliament
– 3 infected at the Home Office
Should I continue?
His full findings can be read on this article published on Medium.
This is not the first time the twitter handle has informed about security issues in public databases in India, he has also informed about security issues in the UIDAI (Adhaar Card) which led to massive outrage.