Published On : Sat, Dec 3rd, 2016

22-year-old hacks Modi app and accesses private data of 7 million people

Advertisement

extra-large_120216094030Long since Narendra Modi became Prime Minister of the nation, he has talked about Digital India. Presently, in India, internet penetration is a mere seven per cent, while those actually who own a smartphone make up roughly 41 per cent of the population.

Narendra Modi has his own app which is separate from the official app which can be downloaded for iPhones, Android devices and Windows phones.

After addressing the nation on November 8, laying temporary but new banking rules till December 31 under his demonetisation drive, the nation has both suffered and rejoiced.

A couple of weeks ago, Narendra Modi wanted the nation to use his app which offered a survey containing 10 questions. The review was to determine if the citizens of India were likely to support demonetisation, or not.

Amidst the hustle-bustle of the payday, on December 1, a 22-year-old hacker cracked the Narendra Modi app.

According to a YourStory report, hacker Javed Khatri claimed that he was able to hack the app.

In an email which he sent to YourStory, he wrote:
“I am able to access private data of any user on the app. The data includes phone number, email, name, location, interests, last seen etc. I successfully managed to extract the personal phone numbers and email ids of ministers like Smriti Irani.

Not only that, I can make any user on the platform follow any other user on the platform. This is just the summary of this huge security loophole which I want to report. The privacy of more than seven million users is at stake if this gets ignored.”Javed told YourStory that he did not want to cause any harm but wanted to demonstrate how poor the security of the app is. He even mentioned it was easy for him to hack the app.

Javed shared a couple of screenshots in which he gives proof of the hack being legitimate. The grabs have personal data of Dr Jitendra Singh who is the Minister of State for the Ministry of Development of North Eastern Region, which he accessed via the Narendra Modi app.

WHAT WENT WRONG?
According to Javed, skilled app developers test the security of their apps through various penetration tests (a method to check how hack-proof the app is). Clearly, in this case, the app developer of the Narendra Modi app did not authenticate the mechanism rigorously.

The loopholes in the app can be exploited through various methods. This makes the security of the app susceptible to hacks.

A few hours after YourStory put up the story, it was taken down since the online portal had just one side of the story.