Live data from Hacker News

India orders smartphone makers to preload state-owned cyber safety app

reuters.com

371–380 of 783 posts

Re: India orders smartphone makers to preload state-owned cyber safety app

#371
I wish the article talked more about this app India wanted to pre-install. Forcing the pre-install of apps is worrisome in general, but there's some nuance that is missed by not explaining what is being forced on the citizens. "Cybersecurity app" can mean a lot. From the looks it's a government-sponsored "brick my phone"-kind of app for disabling stolen phones?

Re: India orders smartphone makers to preload state-owned cyber safety app

#373
post #334

Earlier quoted context omitted.

It doesn't. But judicial scrutiny under a government clearly opposed to him does clear the mislabelling. And how does it even help the discussion here?

[flagged]

Impartiality factors less when the entire Federal government apparatus is used to investigate some one for more than a decade. Also, by that reasoning should we start believing in the principle "guilty before proven otherwise"?

> It does help the discussion here, the comment correctly points out how this literal 1984-esque action plays into the current regime's totalitarian tendencies which go way before the 2002 pogrom and of course their parent org, RSS which is a whole other can of worms.

Who decided that those riots were a progrom? That term itself is misleading.

I am not fan of this step but the problems it's designed to tackle are huge in India and it's very much an option unless there are solid alternatives.

Re: India orders smartphone makers to preload state-owned cyber safety app

#374

Earlier quoted context omitted.

This allegation was dismissed by the Supreme Court completely after years of investigation.

Is the Supreme Court completely impartial in India? Is so, then this is credible. At least in the US, the Supreme Court is anything but impartial. Judges typically vote along party lines.

Probably not. Though, for a decade after that the Federal government was controlled by a key opposition party. Essentially they(people who accused him) had all the time to investigate him.

Re: India orders smartphone makers to preload state-owned cyber safety app

#375

I'm shocked by people and state using the crutch of cyber crime or scams to push a totalitarian solution to a problem that is better solved by improved education and targeted campaigns against common security pitfalls. I abhor any decision that robs even a grain of my individual freedom.

> improved education and targeted campaigns against common security pitfalls Good one. Do you see how dumb the average consumer is? They don't know or care even if you try to educate them.

It's articles like these that make me comfortable saying you are part of the problem. Your materialist fear of losing a wholly replaceable phone is manufacturing consent for disaster.

Re: India orders smartphone makers to preload state-owned cyber safety app

#376
post #264

Earlier quoted context omitted.

You shouldn't, I agree with you, but what's the solution that works for everyone, not just the tech literate?

There doesn't need to be a solution that works for everyone. It doesn't matter how many barriers you put in place, people will always get scammed - so don't punish the other capable 85%.

You do in fact need a system that works for the vast majority. If your system flat out doesnt work for 15% of the population, you'd have mass riots and unrest.

Re: India orders smartphone makers to preload state-owned cyber safety app

#377

How is it different from preloading apps like Netflix, GMail and other shady apps for profits that collects a lot of data. Considering India's low literacy, having a state owned cyber safety app shouldn't be much of an issue. It's not like a backdoor, but safety of citizens, which is the prime mandate of a sovereign state.

I found a directive[1]:

> Pre-installed App must be Visible, Functional, and Enabled for users at first setup. Manufacturers must ensure the App is easily accessible during device setup, with no disabling or restriction of its features

While I can get behind the stated goals, the lack of any technical details is frustrating. The spartan privacy policy page[2] lists the following required permissions:

> For Android: Following permission are taken in android device along with purpose:

> - Make & Manage phone calls: To detect mobile numbers in your phone.

> - Send SMS: To complete registration by sending the SMS to DoT on 14422.

> - Call/SMS Logs: To report any Call/SMS in facilities offered by Sanchar Saathi App.

> - Photos & files: To upload the image of Call/SMS while reporting Call/SMS or report lost/stolen mobile handset.

> - Camera: While scanning the barcode of IMEI to check its genuineness.

Only the last two are mentioned as required on iOS. From a newspaper article on the topic[3]:

> Apple, for instance, resisted TRAI’s draft regulations to install a spam-reporting app, after the firm balked at the TRAI app’s permissions requirements, which included access to SMS messages and call logs.

Thinking aloud, might cryptographic schemes exist (zero knowledge proofs) which allow the OS to securely reveal limited and circumscribed attributes to the Govt without the "all or nothing", blanket permissions? To detect that an incoming call is likely from a spam number, a variant of HIBP's k-Anonymity[4] should seemingly suffice. I'm not a cryptographer but hope algorithms exist, or could be created, to cover other legitimate fraud prevent use cases.

It is a common refrain, and a concern I share, that any centralized store of PII data is inherently an attractive target; innumerable breaches should've taught everyone that. After said data loss, (a) there's no cryptographically guaranteed way for victims to know it happened, to avoid taking on the risk of searching through the dark web; (b) they can't know whether some AI has been trained to impersonate them that much better; (c) there's no way to know which database was culpable; and (d) for this reason, there's no practical recourse.

I recently explained my qualms with face id databases[5], for which similar arguments apply.

[1] https://www.pib.gov.in/PressReleasePage.aspx?PRID=2197140&re...

[2] https://sancharsaathi.gov.in/Home/app-privacy-policy.jsp

[3] https://www.thehindu.com/sci-tech/technology/pre-install-san...

[4] https://www.troyhunt.com/understanding-have-i-been-pwneds-us...

[5] https://news.ycombinator.com/item?id=46054724

Re: India orders smartphone makers to preload state-owned cyber safety app

#378

Earlier quoted context omitted.

Mate, this isn't even remotely "nationalist". This stuff is being pushed across the world. Digital ID? The only people really desperate for it are our rulers.

How so? In Sweden we have digital ID and it's great! Super practical and I struggle to think of how it would be used to spy on citizens, given that it has the same legal protections as banks have regarding your account transactions etc. Like sure you could in theory see every document I've ever signed if you have a warrant for BankID servers, but you could probably glean most of that if you had a warrant for the bank…

"Legal" protections can disappear in one evening, and then you are left with a centralized system, very practical for population control.

Re: India orders smartphone makers to preload state-owned cyber safety app

#379

Earlier quoted context omitted.

I think a lot of people in the US are clinging to the hope that this type of friction, along with judicial decisions, will cause the process of removing our legal protections to stall out. I'm not optimistic that this is the case, because the party currently driving the federal incursion on private and state-held data is the one that until recently was opposed to things like national ID. Anything can be done in the n…

I don’t really get why people seem convinced that the government is removing protections for all citizens under a smokescreen of illegal immigration handling, as opposed to taking limited and temporary measures to deal with an unusual situation. My current interpretation is that they are fear mongering about violence because they are actually way more racist than they admit publicly, and might want to remove more peo…

> I don’t really get why people seem convinced that the government is removing protections for all citizens under a smokescreen of illegal immigration handling, as opposed to taking limited and temporary measures to deal with an unusual situation.

Probably because the actions being taken are against people of every category; illegal immigrants, legal immigrants, and naturally born citizens.

As has been noted, _anyone_ not being entitled due process means _nobody_ is entitled to due process. Because then can kidnap you, claim you're "of a group not entitled to due process", and do whatever they want to you. And you can't push back because you're not in that group... because you need due process to do that.

> But why do we think that they are using this as a ruse to like become despotically authoritarian in general?

At some point, you have to call a duck a duck. They're doing things that despotically authoritarian would do, over and over. They may or may not _think_ that's what their goal is, but it clearly is.

Re: India orders smartphone makers to preload state-owned cyber safety app

#380

Earlier quoted context omitted.

> I'm shocked India is currently run by a nationalist regime headed by the so called "butcher of Gujarat"[1], there isn't much that would shock me wrt to that lot's totalitarian tendencies. [1] https://en.wikipedia.org/wiki/Public_image_of_Narendra_Modi

Mate, this isn't even remotely "nationalist". This stuff is being pushed across the world. Digital ID? The only people really desperate for it are our rulers.

> Mate, this isn't even remotely "nationalist".

India's government is not termed 'nationalist' because of this one policy.

Post reply on HN