MEITY, NIC & NeGD, in response to @OfficialSauravD RTI say they have no info on who created Aarogya Setu.
In this thread, I'll connect some dots:
1.Much of this info is in public domain. Then why no official documents? To protect those who built it? Or
(1/n)
to protect bureaucrats who authorised the building of this app by third party volunteers, possibly, without requisite paperwork? List of Aarogya Setu volunteers had been published on Github btw medianama.com/2020/05/223-aa…
(2/n)
2. Volunteers in govt tech: in Aadhaar, some of Nandan Nilekani's team were "volunteers", but via an official process. So much of tech+policy development done by (Nandan linked) iSpirt "volunteers" is officially (govt) undocumented or invisible. 3. Volunteers have a unique+
(3/n)
position of responsibility+dependency, no accountability. Does the govt they have documentation on process of involvement of who all worked on Aarogya Setu? Where they vetted for such a role? 4. I'm not saying that volunteers
(4/n)
behind Aarogya Setu had bad intentions. I'm saying they had no official accountability. PPP should have contracts.
He even said there was competition for building Aarogya Setu, and they won. AND, they took it to 130M downloads and handed it to the government. medianama.com/2020/10/223-de…
He said it on MMT's June earnings call too. medianama.com/2020/06/223-ma…
(6/n)
In fact, MakeMyTrip had denied any official involvement in April. Why? What was there to hide then? medianama.com/2020/04/223-aa…
MMT execs had claimed that they were volunteering in their personal capacity, later in April. medianama.com/2020/04/223-aa…
(7/n)
6. 1mg is another company whose involvement was highlighted by Deep Kalra. When Aarogya Setu was launched, Tanmay Saksena, COO of 1mg had confirmed the involvement of the co to @medianama, only for founder Prashant Tandon to retract.
(8/n) medianama.com/2020/04/223-aa…
7. Lalitesh Katragadda is credited as Principal Architect of Aarogya Setu. See this quote. Ajay Sawhney, Secretary MEITY says they called him in, and they already had a team in place for Aarogya Setu. What team? How does MEITY not know when he did?
(9/n) business-standard.com/article/techno…
8. Arnab Kumar, Program Director of Frontier Technologies at NITI Aayog, spoke to @medianama about the importance of Aarogya Setu for the rollout of the National Health Stack/India Health Stack. Who is rolling out the health stack? Read on.
(10/n) medianama.com/2020/04/223-aa…
9. Health Stack is being rolled out by (Nilekani linked) iSpirt. Lalitesh Katragadda = iSpirt fellow. May 23rd: On a health stack webinar, iSpirt's Sharma called him a "core volunteer" & said that Aarogya Setu is part of Health Stack".
(11/n) medianama.com/2020/06/223-is…
10. Remember Aarogya Setu Mitr, the private services launched on Aarogya Setu? That was by Swasth Alliance. Two reads: 1. medianama.com/2020/05/223-aa… 2. indianexpress.com/article/techno…
Who was on Swasth Alliance?Co's whose employees worked on Aarogya Setu.And Prashant Tandon & iSpirt.
(12/n)
11. Swasth Alliance's advisory council had "Amitabh Kant (CEO, NITI Aayog), Indu Bhushan (CEO, Ayushman Bharat and National Health Authority), & Nandan Nilekani. Among partners: Bill & Melinda Gates Foundation. Bill Gates praised Aarogya Setu.
(13/n) tech.hindustantimes.com/tech/news/bill…
14. So what's the point? Zooming out: Private co execs volunteer for unproven govt app which collects sensitive health data. Govt pushes+gets 130+ Mn downloads. Some volunteers are from Nilekani-linked think tank that is privately building health data infra.
(16/n)
Govt execs say app will link to health infra.Some volunteers become part of a private alliance to build private services on the app, which has govt exec on advisory board, & Nilekani-linked think tank as partner.
(17/n)
Govt likely to adopt health infra created by Nilekani linked think tank & says will work with Alliance in PPP model. Remember there is a health ID being pushed by the PM too.
Maybe it's all opportunism. Maybe by design.
QUESTION: Where's the paperwork?
(18/n)
All this info is in the public domain. Great, dogged and persistent work on Aarogya Setu by @Aditi_muses . Detailed reporting on Health Stack by @trishajalan
19/19
15. Update: Only two redeeming aspects of Aarogya Setup were: a good privacy policy & a half-decent data sharing protocol.
16. As per the RTI response:
a. Govt hasn't documented which entities data has been shared with
b. No security practices have been enforced for those who have received the data.
c. No anonymisation protocol has been developed
d. There is no audit or review mechanism for
(21/n)
17. Based on these revelations, it is very clear that we cannot trust the government of India to follow its own data sharing protocols.
I strongly that everyone who has downloaded it should UNINSTALL AAROGYA SETU.
You need to treat it like a surveillance application.
18. Note that @SFLCin and @anivar have filed an important case against Aarogya Setu in challenging its mandatory usage. The Karnataka HC has said that without law, govt cannot deny services for not installing Aarogya Setu.
19. Aarogya Setu has been brought in & forced upon citizens without a law - even a temporary law like Singapore has - which seems to be in violation of the Right to Privacy judgment. I would urge @SFLCin and also @internetfreedom to challenge Aarogya Setu on these grounds.
Whataboutery. My response: 1. Govts have more accountability to citizens than social networks. 2. Am here by choice. Govt forced Aarogya Setu on ppl. 3. It's not either-or. Both need accountability. I have also raised Q's about social networks.Look it up.
1. Govt is positioning this as a benefit. That's incorrect. FDI has been reduced from 100% to 26%. How do we know it was 100%? NewsCorp had bought VCCircle in 2015: medianama.com/2015/03/223-ne… They've now sold it at a loss to Mint, after the FDI policy was announced.
(2/n)
2. This move strengthens the traditional media lobby against digital companies. Traditional media co's had formed a digital lobby group in 2018. This is probably their doing: medianama.com/2018/10/223-on… (3/n)
The removal of Paytm and Paytm First Games from the Google Play Store covers two interesting #techpolicy issues:
1. Platform Power: Google and Apple have an operating system duopoly. Remember that you can't upload an app store app on the Google Play Store. Thus
(1/n)
They have the power of the default. It's also an app store duopoly. They leverage this duopoly to control entire ecosystems, and effectively control the app economy of a country. The TRAI Chairman @rssharma has spoken about "platform neutrality". Can they ban apps from
(2/n)
their platform, without repercussions? Of course they can, as a pvt platform. They don't want to enable realmoney gaming & gambling? That's their prerogative. But there's a challenge when apps don't have any other significant options.
Q's you have to ask about the IE story on Zenhua and Chinese profiling of significant Indian folks is: 1. is profiling illegal?
It isn't. Not even as per the personal data protection bill. Twitter does it. Facebook does it. LinkedIn does it. Political parties do it.
1/n
2. Is collecting public data off social media illegal?
It isn't. Much of ad industry is exactly that. Collect data, classify people, target them. But it is surveillance. SC said about Indian govts social media tender: blanket montioring of social media is mass surveillance.
2/n
3. Is identifying/documenting relationships between people using publicly available data illegal?
It isn't. Journalists do this for stories. LinkedIn does it, quite publicly. Social media = behavioral and relational info
3/n
Dunzo, one of India's most popular hyper-local delivery apps (funded by Google) said its user phone numbers and email addresses were breached in a #cybersecurity incident.
Here's what we know 👇
1. Attackers compromised servers of a third party that Dunzo works with, and accessed the Dunzo database through them.
2. Payment info (credit cards etc) was not compromised
3. Passwords were not compromised because Dunzo uses OTPs
What we don't know 👇
1. We don't know if email addresses of all users have been compromised, or only some.
2. Who the vendor is. Dunzo hasn't disclosed the name.
There remains a risk (if the vendor wasn't working exclusively with Dunzo) that other databases could have been compromised.
India has banned 59 Chinese apps. The list is below.
Thread with my comments on this follows 👇 (1/6)
1. This is the very first time, to my knowledge, that the Indian govt has actually ANNOUNCED a ban on apps under Section 69 of the IT Act. You know what's surprising? They don't NEED to announce it. Section 69 allows for secret govt blocking. (2/6)
Thus, this is a POLITICAL decision. It has been announced to send China a message. It should not be seen as anything but a political decision. No change in way these apps function over the past 3 months. If this is the right decision, why wasn't it taken a year ago? (3/6)
Thread: I attended an Zoom call (also live-streamed on FB) on Sunday, on invitation from BJP's Vinit Goenka, who has filed a case in the SC against Twitter.
Mr. Goenka called for Twitter to be declared a terrorist org. My story on this call: medianama.com/2020/06/223-vi… (1/n)
Not only did Mr. Goenka call for twitter to be declared a terrorist organisation, but also for charges of sedition to be filed against the company’s public policy officials, and cases and complaints to be filed against them across the country medianama.com/2020/06/223-vi… (2/n)
On the call were various other complainants. One has filed complaints with commissioners of Police in Mumbai and Pune, as well as the NIA. Others in their local police stations. One said he is in the process of filing a case in Gujarat HC medianama.com/2020/06/223-vi… (3/n)