Live data from Hacker News

India orders smartphone makers to preload state-owned cyber safety app

reuters.com

431–440 of 783 posts

Re: India orders smartphone makers to preload state-owned cyber safety app

#431

Earlier quoted context omitted.

> I'm shocked India is currently run by a nationalist regime headed by the so called "butcher of Gujarat"[1], there isn't much that would shock me wrt to that lot's totalitarian tendencies. [1] https://en.wikipedia.org/wiki/Public_image_of_Narendra_Modi

[flagged]

A state intervention in the form of mandatory app installation that no user can deny is a danger, especially given that the current government has allegedly used cyber surveillance to plant "evidence" in the computers of dissidents like Stan Swamy who subsequently died in custody.

Re: India orders smartphone makers to preload state-owned cyber safety app

#432
post #392

Earlier quoted context omitted.

> I have this app installed on my phone, and it helped eliminate "digital arrest" scam calls from 5-6 calls per day to maybe one in 2 months. Yeah, no. Correlation is not causation. Having the app installed doesn't eliminate calls. The app doesn't have the ability to block calls. Operators like Airtel stepped up and started flagging spam/scam and now warn their users when they recieve a call from flagged numbers.

How do you think operators built a database of spammers? I've been reporting spammers since 2005, since DND rules came into place. Only in the last year have I seen the spam slow down. Earlier operators would dismiss the complaint saying to it was a "transactional communication," now it's logged with TRAI and the operator and they have less room to manipulate the complaint.

Reports submitted through the new TRAI DND app and Sanchar Sathi are handled identically.

Simply installing Sanchar Sathi won’t eliminate spam calls, which was my point.

Re: India orders smartphone makers to preload state-owned cyber safety app

#433

Earlier quoted context omitted.

It's like people want to hand over scans of their passport and/or driving license to random businesses again and again, every time the need to prove who they are; and have their ID documents littered in Outlook mailboxes or company file shares with zero permissions. Or be forced to install yet another ID app from a private service that requires you have an iPhone or "compatible" Android. The debate about this in the…

> What really is the Government going to do with a digital ID service that they can't do already? In 20 years, the UK suffers a terrorist attack just before an election, and then elects a ultra right wing government on a platform of "remigrating foreigners." You're a British born citizen but your mom fled from Iran in the 80s and immigrated to the UK. If you don't have digital ID, and the government decides to "remig…

> However if there's a digital ID system that lets the government instantly know everything about a person, you lose the protection of friction.

"Digital ID" doesn't necessitate that all data is collected into one gigantic store with centralised access. Just that you can use the same attestation of identity to access the various systems. And you can also grant others access to a limited subset of the data.

If the government wanted to they could already have set up some direct access from (say) the passport office to HMRC. It's all digital anyway, backwards as the UK government can be, they're not sending people to pore over paper ledgers in person like in The Jackal.

Some of the system already works like this anyway with the share codes for permission to work for foreigners and proving your driving licence.

Theoretically you would also be able to have an audit log of who asked for attestation for access to which system using that ID. Which you currently don't have when everyone is doing it by passport scans, NI numbers given over the phone and so on.

What it does allow is a creeping over-attestation especially of non-government services where you need to use the ID to do things that were previously anonymous or at least potentially anonymous. But since you currently need to use a driving license or selfie to look at boobies, that's already a thing.

It also, depending on cryptographic implementation, can leak information about attestations directly to the government. For example if I certify my identity at BumTickling.com, the website might only find out that I'm over 18, but the government may then know that BT.com's operator requested attestation of my ID's age field. Whereas currently, BT.com's (probably) shady identity service partner may have my selfie and know I tried to look at BT.com, but the government (probably, maybe they forward these things secretly) doesn't know about it unless they audit that partner.

It also has the possibility to gate access to government services behind app installations which, when done lazily, means not only smartphones are required which is bad enough, but specifically Google and Apple devices.

Re: India orders smartphone makers to preload state-owned cyber safety app

#434

Earlier quoted context omitted.

[flagged]

[flagged]

> that is because the RSS was formed to counter attacks on Hindus by Muslims in the 1920s.

> Founded on 27 September 1925,[18] the initial impetus of the organisation was to provide character training and instil "Hindu discipline" in order to unite the Hindu community and establish a Hindu Rashtra (Hindu nation).

> ....After reading Vinayak Damodar Savarkar's ideological pamphlet, Essentials of Hindutva, published in Nagpur in 1923, and meeting Savarkar in the Ratnagiri prison in 1925, Hedgewar was extremely influenced by him, and he founded the RSS with the objective of "strengthening" Hindu society.

https://en.wikipedia.org/wiki/Rashtriya_Swayamsevak_Sangh

Please stop spreading baseless opinions as fact when you yourself know no better. And for matters involving communal issues, I would much rather trust a crowd-sourced knowledge base rather than the opinions of a half-assed biography.

Re: India orders smartphone makers to preload state-owned cyber safety app

#435

Earlier quoted context omitted.

How so? In Sweden we have digital ID and it's great! Super practical and I struggle to think of how it would be used to spy on citizens, given that it has the same legal protections as banks have regarding your account transactions etc. Like sure you could in theory see every document I've ever signed if you have a warrant for BankID servers, but you could probably glean most of that if you had a warrant for the bank…

The best implementation I know of digital ID is the one in Estonia. It comes with a data tracker, such that each citizen can see who exactly has been looking at their data [1]. [1]: https://e-estonia.com/digital-id-protecting-against-surveill...

Done more or less like that in Belgium too. Basically, if any civil servant look at your data, this is recorded in the "Banque Carrefour de la Sécurité Sociale". Your eid is used to authentify/authorize you on various state web site (which is OK)

Re: India orders smartphone makers to preload state-owned cyber safety app

#436
post #228

Earlier quoted context omitted.

Definitely, requiring the entire smartphone to be "trusted" is way too much. Small external signers with a display and confirmation button are a nice compromise (and also largely solve MITM!), since I don't mind an external device being under somebody else's administrative control as long as I can run what I want on my smartphone or computer. But people don't want to carry two things... Hopefully we can at least have…

>But people don't want to carry two things... It can be moved into a security processor within the smartphone's SOC.

True, but that's already a much less clean separation between the credential issuer's and my domain on many dimensions other than security.

As an example, this was the security model for mobile contactless payments for the longest time, and arguably as a result these never really took off until Google came up with a software-only alternative for Android. The potential for rent seeking of the hardware vendor is often too great, and even absent that, it requires close cooperation of too many distinct entities (hardware vendor, OS developer, bank, maybe a payment scheme etc).

(Apple had no issues, because their ecosystem is already a fully walled garden, and they can usually get away with charging access fees even for non-security-relevant hardware interfaces.)

With a contactless smartcard, I might have to carry one more plastic card than strictly necessary, but the technology for that is pretty mature (wallets), and I can migrate to a new phone without any hassle or use my credential on somebody else's device in a pinch.

Re: India orders smartphone makers to preload state-owned cyber safety app

#437
post #430

Earlier quoted context omitted.

[flagged]

"And the Islamic countries are more than happy to bend the knee to a superior white globalist monolith that doesn't like diversity of ideas." Have you ever spoken to people from islamic countries and about their views towards the west?

I was talking about the power structure rather than normal people

Re: India orders smartphone makers to preload state-owned cyber safety app

#438
post #65

Earlier quoted context omitted.

> Do they actually have a choice? Yes. Apple's revenues are half as much as the government of India's [1][2]. That's a resource advantage that gives Cupertino real leverage against New Delhi. [1] https://www.apple.com/newsroom/2025/10/apple-reports-fourth-... $102.5bn / quarter [2] https://en.wikipedia.org/wiki/List_of_countries_by_governmen... $827bn / year

Like any business Apple needs growth to satisfy the shareholders. New growth would come from India and China. Apple didn't leave China and neither it will leave India. India can and will survive without Apple. Though having it in the country would be good for optics. The moment mobile companies locked down sideloading, ability to uninstall bundled software, etc., they made it impossible to argue techincally against b…

You say "Like any business Apple needs growth to satisfy the shareholders." like it is acceptable.

Re: India orders smartphone makers to preload state-owned cyber safety app

#439

Earlier quoted context omitted.

Can anyone explain the history of "self ID" rules and laws in the UK? It seems like you do not have to prove your ID to the police. It is the reverse. As an outsider, I don't understand it.

The fundamental proposition on which all of English culture flows from is that of innocence . For example, in court, you do not have to prove your innocence because you are presumed innocent. In the case of ID cards and the like, the state does not rule over the populace, it rules on behalf of the populace. I am innocent and they work for me . Hence, I do not have to prove to some random government agent who I am unl…

This theory mixes up the distinct concepts of the government, as a trusted entity (where applicable), issuing identity document for the use of its citizens (including in person-to-person or person-to-private-company scenarios), and that of the government requiring its citizens to identify themselves to it on demand.

Sure, its slightly harder to have a government issue credentials to everybody and not have them abuse the possibilities that come with it, but if a society can pull it of, there are vast benefits in many areas of life.

On top of that, the flip side of people regularly not carrying any identification documents seems to be a police force much more eager to arrest people on the spot to figure out their identity. (Presented as an observation without value judgement: This way of doing things does lower the likelihood of the police arresting somebody because of not carrying identification.)

Re: India orders smartphone makers to preload state-owned cyber safety app

#440

I'm shocked by people and state using the crutch of cyber crime or scams to push a totalitarian solution to a problem that is better solved by improved education and targeted campaigns against common security pitfalls. I abhor any decision that robs even a grain of my individual freedom.

> I'm shocked India is currently run by a nationalist regime headed by the so called "butcher of Gujarat"[1], there isn't much that would shock me wrt to that lot's totalitarian tendencies. [1] https://en.wikipedia.org/wiki/Public_image_of_Narendra_Modi

The EU is not run by butchers of anything, but they push Chat Control nonetheless.

Politicians crave power and control, it is that simple, and the current tech can give it to them quite easily. Not even Stalin could put a secret cop into every living room, but secret coppery can now be efficiently automated.

Post reply on HN