A French security researcher, who has kept UIDAI on their toes by exposing various security holes in the Aadhaar infrastructure, has claimed in a series of tweets that Prime Minister Narendra Modi’s application is sending personal information of its users to a third party website called in.wzrkt.com and it is doing so without the user’s consent.

Pushing personal information such as email, photo, name, gender etc to a third party website without a user’s consent is a serious privacy breach. To ascertain whether this privacy breach occurred or not, Alt News decided to take a deep dive into this issue and investigated PM Modi’s Android App.

Sniffing data transmitted by your phone

To ascertain whether your phone is transacting with a certain website or not, the data between the phone and the outside world needs to be intercepted. There are several software applications which allows one to do so. We used a popular software called Charles. As described on the Charles website, it enables one to view all the HTTP and SSL/HTTPS traffic between a machine and the Internet. The trial version of Charles works for 30 days after installation and runs only 30 minutes at a time. Details of how to configure Charles and your phone to intercept data is provided at the bottom of the article in the section “Technical Details”.

Intercepting data

To verify the claim of the researcher, we installed the Narendra Modi Android app on our phone, tapped on the “Sign Up” button at the bottom and created a profile.

During the process of creation of the profile leading upto a successful registration, the APP was transacting data over the Internet which we captured using the Charles software mentioned above. What we saw was that personal information such as name, email id, gender, telecom operator type and more was indeed being shared with the website in.wzrkt.com. In the screenshot below, it can be seen that the email-id pratik@xyzabc.com that we entered during registration has been sent to in.wzrkt.com.

The video below will show a live demonstration of this fact-check and will show how personal information that you’re sharing with the Prime Minister’s app is indeed being sent to a third party website without your consent.

NOTE: Kindly watch the video in Full HD/1080p for better viewing.

NOTE: Those not interested in the technical details of how to setup your phone and computer for intercepting data can skip the next section.

Technical details

Once Charles is installed on your PC/laptop, your phone’s proxy server needs to be configured to point to the machine which has Charles running so that it can intercept all the traffic emanating from your phone. This is done by inputting the IP Address of your PC/laptop and the proxy server port (Default: 8888) that Charles is listening on in the proxy server section of the Wi-Fi Settings on your phone.

Additionally, since the data that is being transacted between the Narendra Modi app and outside world is over HTTPS and is encrypted, one needs to install the Charles Root Certificate on your phone by pointing your Mobile browser to chls.pro/ssl and following the prompts.

Lastly, add in.wzrkt.com in the list at “SSL Proxy Settings” which in turn can be found in the “Proxy” main menu.

Once the above settings are configured, Charles running on your machine is ready to intercept the data from the Narendra Modi app on your phone.

Donate to Alt News!
Independent journalism that speaks truth to power and is free of corporate and political control is possible only when people start contributing towards the same. Please consider donating towards this endeavour to fight fake news and misinformation.

To make an instant donation, click on the "Donate Now" button above. For information regarding donation via Bank Transfer/Cheque/DD, click here.
You could follow Alt News posts either via our Facebook page or by following us on Twitter or by subscribing to our E-mail updates.


11
Leave a Reply

avatar
5 Comment threads
6 Thread replies
2 Followers
 
Most reacted comment
Hottest comment thread
9 Comment authors
Tanushree GangopadhyaySharmajikabetaAndyanna sannaNeil S Recent comment authors
  Subscribe  
newest oldest most voted
Notify of
Awanish Sharma
Guest
Awanish Sharma

One thing is sure this idiot don’t have any technical know how, he is just blabbering to defame Modi

Kajol
Guest
Kajol

Abe chu*** video dekha na….pura process dekhya ha fer bhi nhi man raha ha…..is lia to tuj jiase ch**** ko bhakt bolte ha.

Rakesh Agrawal
Guest
Rakesh Agrawal

Yes, this robot is a blind bhakt & intellectually & morally challenged!

Rehan
Guest
Rehan

Y do u have to b uncivilized to address bhakts..Don’t stoop to their levels..That’s Wat they want…They are paid to do it…Chill..

Rakesh Agrawal
Guest
Rakesh Agrawal

So, Mr. Robot, you understood the process as you are a tech wizard! Pl expose Alt News now!

anna sanna
Guest
anna sanna

bhosadike tu modi and yogi ka gobar khate rah jao, aapki utni hi aukat hai

Sharmajikabeta
Guest
Sharmajikabeta

ooh Genius then explain on what points his wrong.

Typical bhakths response…

Rakesh Agrawal
Guest
Rakesh Agrawal

That’s why this lousy govt is insisting to make aadhaar compulsory even to breadth and save a few persons like me, almost everyone has to get it, so that this party can monitor behavior of the voters and influence them, save bhakts who are robots like the one who supported this moron!

Neil S
Guest
Neil S

The App allows one to ‘Continue as Guest’. In which case one is not entering any info on oneself. Can the author confirm whether in the guest mode any data is being passed on? And if so, what is the data being passed on, since the user has not furnished any. Also, upon launch, there is a popup asking for permission to access photos, media, and files on my device. I clicked on deny. Upon second launch, it asked the permission again, and now there was a choice to deny and a box to ‘Don’t ask again’ which also I… Read more »

Andy
Guest
Andy

Why do we worry? it is obvious who have that app. Chalo bhakto k information is for sale and lets rejoice their stupidity.

Tanushree Gangopadhyay
Guest
Tanushree Gangopadhyay

Pratik your effort at Modi’s App is really super. Its shocking that your information is sent to a third party who you are not aware of. It is criminal. He should be penalised.