Tuesday, May 12, 2026

Security Vulnerabilities of the NaMo App

Date:

The NaMo app, used by Prime Minister Narendra Modi, has been found to have significant security vulnerabilities, raising concerns about user data privacy. In 2016, a 22-year-old hacker, Javed Khatri, claimed to have successfully accessed private data of over 7 million users of the app. This data included phone numbers, email addresses, names, locations, and interests, and even the ability to make a user follow any other user on the platform. The hacker demonstrated the ease with which the app could be compromised, highlighting the poor security measures in place.

https://www.indiatoday.in/fyi/story/security-22-year-old-hacks-modi-app-private-data-7-million-355398-2016-12-02

The core of the problem lay in how the app communicated with its API (Application Programming Interface) at narendramodi.in. One major issue was the lack of proper authentication for API endpoints, allowing unauthorized access to user data. For example, it was possible to extract email addresses by simply iterating through user IDs. The API was also served over HTTP instead of HTTPS, meaning data was transmitted as plain text, making it vulnerable to interception.

The security flaws in the NaMo app had several potential consequences:

The NaMo App, the official app of Prime Minister Narendra Modi, collects various types of user data. The app requests access to numerous personal features on users’ devices, including location, photographs, contacts, microphone, and camera. The app’s description states that “no permission is compulsory” and users can disable access in settings, but many permissions are granted by default upon download. The app also collects information such as user photos, gender, name, email ID, location details, profession, interests, IP address, phone number, device information, and uses unique application numbers and cookies.

Allegations

The NaMo App shares user data with third-party services for analytics and to provide a better user experience. This includes offering contextual content, showing content in the user’s language, and providing a personalized experience based on interests. The app’s privacy policy was updated to reflect this data sharing, stating that information like name, email, mobile phone number, device information, location, and network carrier may be shared.

Government and BJP Response

Controversy arose when a French security researcher alleged that the NaMo App was sharing user data with a third-party US company, CleverTap, without consent. The BJP (Bharatiya Janata Party) responded to these allegations by stating that most of the data shared on the app was already in the public domain and that user information was stored in an encrypted mode. The researcher claimed that the app was sending user data to a third-party domain. The Congress party also criticized the app, accusing Prime Minister Modi of spying on Indians and building a personal database.

Data Storage Location

CleverTap, the US-based analytics company, stated that it does not sell, share, rent, or re-market user data. The company clarified that it works with first-party data provided by the app publisher, and the data collected is governed by the publisher’s privacy policy. CleverTap also mentioned that it offers various hosting locations globally, including Indian data centers.

Privacy Policy Changes

The government has stated that the data from the NaMo App is saved in Indian servers and is safe.  CleverTap also offers Indian data centers for businesses that require them.

About CleverTap

Founded in May 2013 by three Indians, Anand Jain, Sunil Thomas, and Suresh Kondamudi, CleverTap is a mobile marketing firm that provides real-time insights to marketers. Among other services, the company offers behavioral targeting. This means that it studies what users do with an app and this, in turn, helps the app creators tailor user experiences accordingly.

Before launching CleverTap, the three co-founders had worked at media conglomerate Network 18. Jain had earlier co-founded restaurant recommendation engine Burrp, while Thomas spent nine years at Seattle-based internet search firm Infospace (now called Blucora). Kondamudi is an IIT-Madras alumnus with a background in mobile marketing.

So far, CleverTap has raised $9.6 million from marquee investors like Sequoia Capital and Accel Partners, among others.

The Narendra Modi app had come under scrutiny after a Twitter trend called DeleteNamoApp alleged that it shares user data with CleverTap, a third-party data analytics company. This trend gained momentum as users disputed the app’s practices and claimed it was tied to Cambridge Analytica, although evidence to support this was weak. The BJP’s IT Cell reacted to the allegations by promoting the hashtag DeleteCongFakeNews, suggesting this was part of a political rivalry.

Security researcher Elliot Alderson pointed out concerns regarding the Narendra Modi app, particularly its collection of personal and device information sent to third-party domains. CleverTap is known as a popular SDK used by app developers for user engagement and marketing. The data collected includes sensitive information like the device model, carrier, app settings, and other personal details, all sent to a domain associated with CleverTap.

That ominous tweet was followed up by a series of tweets about the Narendra Modi App sending user’s personal and device data to third-party domains.

CleverTap for those unaware is a marketing SDK incorporated by app makers to deliver retention, usage, and retargeting campaigns for their users. It provides tools and insights into users and allows developers to send tailored push notifications or email-based campaigns to promote the app’s usage.

Of course the question is why does the Namo App need to send data to third-party servers at all? As for what data is being sent, the tweeted pictures clearly show the extent of the collection. Besides the make and model of your phone, everything from your carrier, app settings and all the information you have submitted are being sent to wzrkt.com.

The website clearly belongs to CleverTap, which used to be called Wizrocket when it started out. CleverTap has offices in the Los Angeles, San Francisco, New York, as well as in Bangalore, Mumbai and New Delhi, but the Indian connection is hard to miss with CEO and Co-founder Sunil Thomas, Anand Jain who is Co-founder and Suresh Kondamudi, CTO and Co-founder. All three were previously with Network18, the media company owned by Mukesh Ambani’s Reliance Industries. The name was changed from Wizrocket around the middle of 2015. The company has received nearly $10 million in funding according to Crunchbase.

Beebom team has reached out to Clevertap through the email contacts on their website for an explanation on the data being collected and the extent of its use and whether it is stored outside India as well. They will update the story right after they hear back from Clevertap.

Ref: https://beebom.com/narendra-modi-app-data-clevertap/

Questions arise regarding the need for the Narendra Modi app to send this data to external servers. The presence of CleverTap, which has significant ties to the Indian tech landscape, raises further concerns about how this data may be utilized. Attempts to reach CleverTap for clarification on their data collection practices are ongoing.

The privacy policy for the Narendra Modi app has also been criticized for being poorly designed and lacking clear information on its use of the CleverTap SDK. It fails to inform users that their setup profiles are sent to third-party servers for data mining.

Moreover, there are reports of government bodies encouraging the use of the Narendra Modi app for direct communication, which includes collecting personal information from over 15 lakh students in the National Cadets Corps. The Prime Minister’s office indicates that this app is intended to facilitate interaction with cadets.

While the Congress party and Alderson claim that the BJP has been unlawfully sharing its data with CleverTap, cybersecurity experts told Quartz that the company is just one of many such service providers. It’s common for companies to use such third-party data analytics to improve user profiling, said Altaf Halde, global business head at cybersecurity services firm Network Intelligence.

Comparison with Other Apps

Following the allegations, the privacy policy of the NaMo App was updated. The updated policy acknowledges that certain information may be shared with third-party services to improve user experience.

India currently lacks a dedicated legal framework to govern mobile applications, which has been highlighted as a concern in the context of these data privacy issues.

The NaMo App collects user data and shares it with third-party services for analytics and to enhance user experience. While the government and the BJP maintain that the data is stored securely in Indian servers and is not misused, the controversy has raised concerns about data privacy and the need for a stronger legal framework in India.

Danger Ahead: ‘Photo Booth’ on the ‘NaMo App’ showcases the use of AI

‘Photo Booth’ on the ‘NaMo App’ showcases the remarkable use of AI

During a conversation with Bill Gates, PM Modi mentioned that the ‘Photo Booth’ feature on the ‘NaMo App’ highlights how AI is being used.

PM Modi: It’s very helpful for me across the entire country. This is my photo booth—now you can take a selfie here. Just take a selfie on this. Not only that, but in the last 20 years, every photo you and I have taken will be stored here. For example, if at some public event, your part is visible, even if I’m in the photo and you’re not, the system can still match and retrieve it.

This shows how technology can be utilized, and I believe that such applications add real value. Earlier, if I wanted a photo, I had to ask someone to take it. Now, I just say, “Go to AI, go to my Namo A photo booth, take a selfie yourself.” You’ll get all the photos with me, even from the corners where you’re standing. So, we should use technology to help people in their daily lives. My effort is to first make people comfortable, so they feel, “Yes, this is useful for me.” Once it’s helpful, innovation and new features naturally follow.

Remediation and Updates

  • Data Exposure: The primary concern was the exposure of personal data, including email addresses, phone numbers, and potentially other sensitive information.
  • Unauthorized Access: The vulnerabilities allowed unauthorized access to user accounts, enabling actions like posting comments as other users.
  • Privacy Concerns: The app’s data-sharing practices, including sending user data to third-party domains without consent, raised serious privacy concerns.
  • Political Ramifications: The security breaches became a political issue, with opposition parties criticizing the BJP for its handling of user data and the app’s security.

Comparison with Congress App

The developers of the NaMo app addressed some of the vulnerabilities. They fixed the unauthorized access to personal information, implemented authentication checks for API endpoints, and blocked HTTP, ensuring all responses were served over HTTPS. However, the initial fixes were criticized as being insufficient, with the underlying design flaws of the API remaining unaddressed.

The Congress party’s official Android app also faced scrutiny regarding its security practices. It was alleged that the app used HTTP instead of HTTPS for data transmission, potentially exposing user data to interception. The Congress party later removed its app from app stores after these allegations.

CleverTap’s Response

The government and the BJP responded to the allegations by stating that the data is used for analytics, similar to Google Analytics, and is not stored or used by the third-party services. They emphasized that the data exposed by the French Twitter user was data entered by the user on their own device and that there was no security breach. The BJP also stated that the permissions required are contextual and cause-specific. The PMO issued a statement defending the app, highlighting its features and engagement with users.

Ref:

  1. Security flaw: 22-year-old hacks Modi app and accesses private data of 7 million people. [ https://www.indiatoday.in/fyi/story/security-22-year-old-hacks-modi-app-private-data-7-million-355398-2016-12-02 ]
  2. Major Security Flaw in NaMo App. [ https://cis-india.org/internet-governance/blog/major-security-flaw-namo-app]
  3. India privacy scandal brews over claim PM Narendra Modi’s app ships personal data abroad. [ https://www.scmp.com/news/asia/south-asia/article/2139063/india-privacy-scandal-brews-over-claim-pm-narendra-modis-app]
  4. Data of NaMo app users safe, saved in Indian servers: Govt sources. [https://m.economictimes.com/news/politics-and-nation/data-of-namo-app-users-safe-saved-in-indian-servers-govt-sources/articleshow/63456217.cms]
  5. NaMo App asks for sweeping access: Camera, audio among 22 inputs; Facebook data leak. [ https://indianexpress.com/article/india/namo-app-asks-for-sweeping-access-camera-audio-among-22-inputs-facebook-data-leak-5111353/]
  6. ‘NaMo app doesn’t store data to be used by 3rd parties’. [ https://timesofindia.indiatimes.com/india/namo-app-doesnt-store-data-to-be-used-by-3rd-parties/articleshow/63457913.cms]
  7. Rahul Gandhi attacks PM Modi again for sharing NaMo app data. [ https://www.hindustantimes.com/india-news/rahul-gandhi-attacks-pm-modi-again-for-sharing-namo-app-data/story-LcbcniFSn5Bvoep7GMHDHJ.html]
  8. NaMo app data is shared with third party companies to improve user experience, says BJP. [ https://scroll.in/latest/873309/namo-app-data-is-shared-with-third-party-companies-to-improve-user-experience-says-bjp]
  9. Full text: PMO’s response to charges around NaMo app forwarding people’s data to a third party app. [ https://www.indiatoday.in/india/story/full-text-pmo-response-to-charges-around-namo-app-forwarding-people-s-data-to-a-third-party-app-1197478-2018-03-25]
  10. NaMo App Data Breach: US-based analytics firm says it doesn’t sell, rent data. [ https://www.outlookindia.com/national/namo-app-data-breach-us-based-analytics-firm-says-it-doesnt-sell-rent-data-news-310067]
  11. Privacy Policy. [ https://www.narendramodi.in/en/mobile/privacy-policy]
  12. BJP changes privacy setting on NAMO App. [ https://www.nationalheraldindia.com/news/bjp-changes-privacy-setting-on-namo-app]
  13. Data leak war: Day after BJP tweaks policy, Congress junks app. [ https://timesofindia.indiatimes.com/india/data-leak-war-day-after-bjp-tweaks-policy-congress-junks-app/articleshow/63472986.cms]
  14. Youtube-Image

Also Read:

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Related articles

The hard work of 2.2 million students has gone to waste, with the NEET UG exam cancelled.

Amidst the alleged paper leak of the NEET UG exam, the NTA has decided to cancel the exam...

US should review Pakistan’s role in Iran war: Trump’s close leader demands, Shahbaz-Munir tensions rise

Washington: Republican Senator Lindsey Graham, considered close to US President Donald Trump, has strongly criticized Pakistan. He demanded...

Is your charging cable repeatedly breaking? Before buying a new one, learn these home remedies; it’ll fix it in minutes.

These days, smartphones have become an integral part of our lives, and with them, charging cables have also...

Troubled by fungal infections in the summer? Stop making these mistakes today.

With the arrival of summer, not only does the temperature rise, but skin-related problems also increase rapidly. Intense...
news-1701

sabung ayam online

yakinjp

yakinjp

rtp yakinjp

slot thailand

yakinjp

yakinjp

yakin jp

yakinjp id

maujp

maujp

maujp

maujp

sabung ayam online

sabung ayam online

judi bola online

sabung ayam online

judi bola online

slot mahjong ways

slot mahjong

sabung ayam online

judi bola

live casino

sabung ayam online

judi bola

live casino

SGP Pools

slot mahjong

sabung ayam online

slot mahjong

SLOT THAILAND

berita 128000726

berita 128000727

berita 128000728

berita 128000729

berita 128000730

berita 128000731

berita 128000732

berita 128000733

berita 128000734

berita 128000735

berita 128000736

berita 128000737

berita 128000738

berita 128000739

berita 128000740

berita 128000741

berita 128000742

berita 128000743

berita 128000744

berita 128000745

berita 128000746

berita 128000747

berita 128000748

berita 128000749

berita 128000750

berita 128000751

berita 128000752

berita 128000753

berita 128000754

berita 128000755

artikel 128000821

artikel 128000822

artikel 128000823

artikel 128000824

artikel 128000825

artikel 128000826

artikel 128000827

artikel 128000828

artikel 128000829

artikel 128000830

artikel 128000831

artikel 128000832

artikel 128000833

artikel 128000834

artikel 128000835

artikel 128000836

artikel 128000837

artikel 128000838

artikel 128000839

artikel 128000840

artikel 128000841

artikel 128000842

artikel 128000843

artikel 128000844

artikel 128000845

artikel 128000846

artikel 128000847

artikel 128000848

artikel 128000849

artikel 128000850

article 138000756

article 138000757

article 138000758

article 138000759

article 138000760

article 138000761

article 138000762

article 138000763

article 138000764

article 138000765

article 138000766

article 138000767

article 138000768

article 138000769

article 138000770

article 138000771

article 138000772

article 138000773

article 138000774

article 138000775

article 138000776

article 138000777

article 138000778

article 138000779

article 138000780

article 138000781

article 138000782

article 138000783

article 138000784

article 138000785

article 138000816

article 138000817

article 138000818

article 138000819

article 138000820

article 138000821

article 138000822

article 138000823

article 138000824

article 138000825

article 138000826

article 138000827

article 138000828

article 138000829

article 138000830

article 138000831

article 138000832

article 138000833

article 138000834

article 138000835

article 138000836

article 138000837

article 138000838

article 138000839

article 138000840

article 138000841

article 138000842

article 138000843

article 138000844

article 138000845

article 138000786

article 138000787

article 138000788

article 138000789

article 138000790

article 138000791

article 138000792

article 138000793

article 138000794

article 138000795

article 138000796

article 138000797

article 138000798

article 138000799

article 138000800

article 138000801

article 138000802

article 138000803

article 138000804

article 138000805

article 138000806

article 138000807

article 138000808

article 138000809

article 138000810

article 138000811

article 138000812

article 138000813

article 138000814

article 138000815

story 138000816

story 138000817

story 138000818

story 138000819

story 138000820

story 138000821

story 138000822

story 138000823

story 138000824

story 138000825

story 138000826

story 138000827

story 138000828

story 138000829

story 138000830

story 138000831

story 138000832

story 138000833

story 138000834

story 138000835

story 138000836

story 138000837

story 138000838

story 138000839

story 138000840

story 138000841

story 138000842

story 138000843

story 138000844

story 138000845

article 138000726

article 138000727

article 138000728

article 138000729

article 138000730

article 138000731

article 138000732

article 138000733

article 138000734

article 138000735

article 138000736

article 138000737

article 138000738

article 138000739

article 138000740

article 138000741

article 138000742

article 138000743

article 138000744

article 138000745

article 208000456

article 208000457

article 208000458

article 208000459

article 208000460

article 208000461

article 208000462

article 208000463

article 208000464

article 208000465

article 208000466

article 208000467

article 208000468

article 208000469

article 208000470

journal-228000376

journal-228000377

journal-228000378

journal-228000379

journal-228000380

journal-228000381

journal-228000382

journal-228000383

journal-228000384

journal-228000385

journal-228000386

journal-228000387

journal-228000388

journal-228000389

journal-228000390

journal-228000391

journal-228000392

journal-228000393

journal-228000394

journal-228000395

journal-228000396

journal-228000397

journal-228000398

journal-228000399

journal-228000400

journal-228000401

journal-228000402

journal-228000403

journal-228000404

journal-228000405

article 228000376

article 228000377

article 228000378

article 228000379

article 228000380

article 228000381

article 228000382

article 228000383

article 228000384

article 228000385

article 228000386

article 228000387

article 228000388

article 228000389

article 228000390

article 228000391

article 228000392

article 228000393

article 228000394

article 228000395

article 228000396

article 228000397

article 228000398

article 228000399

article 228000400

article 228000401

article 228000402

article 228000403

article 228000404

article 228000405

article 228000406

article 228000407

article 228000408

article 228000409

article 228000410

article 228000411

article 228000412

article 228000413

article 228000414

article 228000415

article 228000416

article 228000417

article 228000418

article 228000419

article 228000420

article 228000421

article 228000422

article 228000423

article 228000424

article 228000425

article 228000426

article 228000427

article 228000428

article 228000429

article 228000430

article 228000431

article 228000432

article 228000433

article 228000434

article 228000435

article 238000461

article 238000462

article 238000463

article 238000464

article 238000465

article 238000466

article 238000467

article 238000468

article 238000469

article 238000470

article 238000471

article 238000472

article 238000473

article 238000474

article 238000475

article 238000476

article 238000477

article 238000478

article 238000479

article 238000480

article 238000481

article 238000482

article 238000483

article 238000484

article 238000485

article 238000486

article 238000487

article 238000488

article 238000489

article 238000490

article 238000491

article 238000492

article 238000493

article 238000494

article 238000495

article 238000496

article 238000497

article 238000498

article 238000499

article 238000500

article 238000501

article 238000502

article 238000503

article 238000504

article 238000505

article 238000506

article 238000507

article 238000508

article 238000509

article 238000510

article 238000511

article 238000512

article 238000513

article 238000514

article 238000515

article 238000516

article 238000517

article 238000518

article 238000519

article 238000520

update 238000492

update 238000493

update 238000494

update 238000495

update 238000496

update 238000497

update 238000498

update 238000499

update 238000500

update 238000501

update 238000502

update 238000503

update 238000504

update 238000505

update 238000506

update 238000507

update 238000508

update 238000509

update 238000510

update 238000511

update 238000512

update 238000513

update 238000514

update 238000515

update 238000516

update 238000517

update 238000518

update 238000519

update 238000520

update 238000521

sumbar-238000396

sumbar-238000397

sumbar-238000398

sumbar-238000399

sumbar-238000400

sumbar-238000401

sumbar-238000402

sumbar-238000403

sumbar-238000404

sumbar-238000405

sumbar-238000406

sumbar-238000407

sumbar-238000408

sumbar-238000409

sumbar-238000410

news-1701