Showing posts with label Aarogya Setu app. Show all posts
Showing posts with label Aarogya Setu app. Show all posts

Monday, May 18, 2020

Phishing attacks in name of Aarogya Setu app increasing: Cyber agency

Phishing attacks in name of Aarogya Setu app increasing: Cyber agency


New Delhi: Phishing attacks in the name of Aarogya Setu mobile application are witnessing a “high rise” as online scamsters are taking advantage of the increased inquisitiveness of internet users during the COVID-19 pandemic, India’s cyber security agency said on Saturday.
It said attackers are also impersonating tools linked to the World Health Organisation and popular video-conferencing platforms like Zoom to steal sensitive data.
“Aarogya Setu app-focused phishing have seen high rise. Scammers impersonate as HR department, CEO, or any other known person and target users by spreading messages like ‘your neighbour is affected’, ‘see who all are affected’, ‘someone who came in contact with you tested positive’, ‘recommendations to self-isolate’, ‘guidelines to use Aarogya Setu’ among others,” the CERT-In said in a latest advisory accessed by PTI.
The Aarogya Setu application uses bluetooth and GPS to alert users who may have encountered people who later tested positive for the coronavirus.
Phishing denotes to the cyber term of luring and cheating an internet user through a fake SMS or email and thereby breaching their privacy to steal sensitive information.
“In recent trends, threat actors are taking advantage of pandemic situation to trick the users to give up their sensitive information by taking advantage of the interest associated with recent novel coronavirus activities, news, and information,” the advisory said.
The Computer Emergency Response Team of India (CERT-In) is the national technology arm to combat cyber attacks and guarding of the Indian cyber space.
It said cyber attackers (threat actors) impersonate popular video platforms like Zoom, Google Meet, Microsoft Teams, Aarogya Setu app and WHO to send phishing messages through SMS (smishing), WhatsApp (whishing) or phishing emails to steal identities and engage in other nefarious activities during the COVID-19 pandemic.
The cyber attackers, it said, are using fake domains to impersonate popular apps to first lure the victims and then send them links such as “relief package”, “safety tips during corona”, “corona testing kit”, “corona vaccine”, “payment and donation during corona”.
It said the name of the WHO was also being impersonated.
“Cyber criminals are sending phishing emails impersonating WHO and e-mails appear to be originating from the domain of WHO. Such e-mails may contain malicious file and URLs (universal resource locators),” it said.
The cyber agency suggested come counter-measures to check this online menace:
Beware about the domain, spelling errors in emails, websites and un-familiar email senders; check the integrity of URLs before providing login credentials or clicking a link and do not submit personal information to unknown and unfamiliar websites.
It said users should exercise caution and avoid clicking dubious URLs providing special offers like winning prize, rewards, cashback offers and they practice safe browsing tools, filtering tools their anti-virus and use a proper firewall.

Tuesday, May 12, 2020

Govt likely to make Aarogya Setu app mandatory for flyers post lockdown

Govt likely to make Aarogya Setu app mandatory for flyers post lockdown


New Delhi: The Centre is likely to make it mandatory for people to have Aarogya Setu mobile application installed in their phones while taking a flight post-lockdown, officials said on Monday.
“Preliminary discussions regarding making this app mandatory for air passengers have been done with the airlines,” the government officials noted, adding that the Civil Aviation Ministry is yet to take a decision in this regard.
The mobile application helps users identify whether they are at risk of COVID-19. It also provides people with important information, including ways to avoid coronavirus and its symptoms.
The app gives color coded-designation to users as per their health status and travel history. It helps the user know if he or she is near anyone who has tested positive for the virus.
“If the proposal is approved in the Aviation ministry, passengers who do not have the app on their phone would not be allowed to board their flight,” the officials noted.
The third phase of coronavirus-triggered lockdown will end on May 17. The government is yet to take a decision regarding the resumption of commercial passenger flight services.
India has been under lockdown since March 25 to curb the spread of the novel coronavirus, which has infected more than 67,100 people and killed over 2,200 till now in the country.
All commercial passenger flight operations have been suspended for the lockdown period. However, cargo flights, medical evacuation flights, and special flights approved by the aviation regulator DGCA have been allowed to operate.

Wednesday, May 6, 2020

No security breach in Aarogya Setu app: Govt assures after ethical hacker raises privacy concerns

No security breach in Aarogya Setu app: Govt assures after ethical hacker raises privacy concerns


New Delhi: The government on Wednesday, May 6 said no data or security breach has been identified in Aarogya Setu app after an ethical hacker raised concerns about a potential security issue in the app.
The app is the government’s mobile application for contact tracing and disseminating medical advisories to users in order to contain the spread of COVID-19.
On Tuesday, a French hacker and cybersecurity expert Elliot Alderson had claimed that “a security issue has been found” in the app and that “privacy of 90 million Indians is at stake”.
Dismissing the claims, the government said “no personal information of any user has been proven to be at risk by this ethical hacker”.
“We are continuously testing and upgrading our systems. Team Aarogya Setu app assures everyone that no data or security breach has been identified,” the government said through the app’s Twitter handle.
The tweet gave point-by-point clarification on the red flags raised by the hacker.
“We discussed with the hacker and were made aware of the following. the app fetches user location on a few occasions,” it said but added that this was by design and is clearly detailed in the privacy policy.
“The app fetches users’ location and stores on the server in a secure, encrypted, anonymized manner – at the time of registration, at the time of self-assessment, when users submit their contact tracing data voluntary through the app or when it fetches the contact tracing data of users after they have turned COVID-19 positive,” it said.
On another issue that users can get COVID-19 stats displayed on the home screen by changing the radius and latitude-longitude using a script, Aarogya Setu app said that all this information is already public for all locations and hence does not compromise on any personal or sensitive data.
“We thank the ethical hacker on engaging with us. We encourage any users who identify any vulnerability to inform us immediately…,” it said.
Responding to Aarogya Setu’s clarification, Alderson tweeted, “I will come back to you tomorrow”.