BENGALURU: Concerns Rise Over India’s New Smartphone Security Proposals
The Indian government’s recent proposal that would require smartphone manufacturers to share their source code has sparked backlash from privacy advocates and tech experts. They worry that these measures could lead to increased government surveillance.
Major companies like Apple and Samsung are said to have expressed their concerns privately about this new set of security rules. One key part of the proposal includes a requirement for phone users to keep logs of their devices for a whole year, according to a recent report.
This initiative is part of Prime Minister Narendra Modi’s efforts to safeguard user data as cases of online fraud and data breaches rise in India, which has nearly 750 million smartphone users.
The Ministry of Information Technology has stated that they are open to discussing any legitimate concerns raised by the industry. They also clarified that they are not actively seeking to obtain source code, though they didn’t comment on the documents referenced in the report.
One organization, the Internet Freedom Foundation, voiced strong opposition to the proposal, emphasizing that it could give the government undue access to sensitive source code and impose strict controls on devices used daily by millions of people in India. They argued that the proposals could negatively impact how users interact with their own devices.
Interestingly, a planned meeting on Tuesday between the ministry and tech companies to discuss these concerns has been called off, raising questions about transparency.
Experts argue that seeking access to source code undermines trust and contradicts India’s ambition to improve the business environment. Last month, India reversed a decision that would have required a state-run cybersecurity app on smartphones due to backlash from political parties and privacy advocates.
Under the latest proposal, tech companies would need to notify government officials before rolling out any security updates, which raises potential conflicts of interest. Critics believe this could allow the state to monitor vulnerabilities for its own surveillance purposes.
