• FluTrackers.com Inc. does not provide medical advice. Information on this web site is collected from various internet resources, and the FluTrackers board of directors makes no warranty to the safety, efficacy, correctness or completeness of the information posted on this site by any author or poster. The information collated here is for instructional and/or discussion purposes only and is NOT intended to diagnose or treat any disease, illness, or other medical condition. Every individual reader or poster should seek advice from their personal physician/healthcare practitioner before considering or using any interventions that are discussed on this website. By continuing to access this website you agree to consult your personal physican before using any interventions posted on this website, and you agree to hold harmless FluTrackers.com Inc., the board of directors, the members, and all authors and posters for any effects from use of any medication, supplement, vitamin or other substance, device, intervention, etc. mentioned in posts on this website, or other internet venues referenced in posts on this website.
  • We are not asking for any donations. Do not donate to any entity who says they are raising funds for us.

India said its coronavirus contact-tracing app is perfect... adds bug bounty and open-sources it anyway

Gert van der Hoek

In Memoriam - Editor, Senior Moderator
WED 27 MAY 2020

India has open-sourced its Aarogya Setu contact-tracing app and announced a bug bounty programme to detect any security issues.

Aarogya Setu – which translates to English as "path to health" – has now been downloaded over 110 million times. Unlike many comparable apps around the world, Aarogya Setu tracks users' locations and its source code – for both apps and back-end – remained secret. However, that stance could not prevent partial decompilation of the Android APK, which led to some reports of vulnerabilities.

India has previously brushed off such concerns with the app's developers

Yet the nation has now decided to open the app and run a bug bounty programme.

It's not clear what sparked the change, but India's Ministry of Electronics & Information Technology admitted: "Despite the best measures taken, the presence of vulnerabilities may exist. When such vulnerabilities are found, Government would like to learn of them as soon as possible." The ministry also said the nation wishes only to share its code with the world for the common good.
 
Back
Top