India Proposes Mandatory Source Code for Smartphone Security | Quick Digest

India Proposes Mandatory Source Code for Smartphone Security | Quick Digest
India's government has proposed mandatory source code disclosure and other stringent security measures for smartphone makers. This move aims to bolster user data security but faces strong opposition from major tech companies like Apple and Samsung, citing corporate secrecy and global privacy concerns.

India mandates smartphone makers to disclose proprietary source code for security reviews.

New rules include restrictions on app permissions and one-year log retention.

Apple, Samsung, Google, and Xiaomi oppose the proposals citing global precedents and secrecy.

Government aims to enhance user data security amidst rising online fraud in India.

Industry argues proposals lack global precedent and risk revealing proprietary details.

Consultations are ongoing, with the IT Secretary promising an open mind to industry concerns.

The Indian government has put forward a comprehensive set of new security regulations for smartphone manufacturers, which notably includes a proposal for mandatory disclosure of proprietary source code. This significant move is part of Prime Minister Narendra Modi's broader efforts to enhance user data security and combat the growing incidence of online fraud and data breaches in India, the world's second-largest smartphone market with approximately 750 million users. Beyond source code access, the proposed 83 security standards also entail several other stringent requirements. These include restrictions on apps accessing cameras, microphones, or location services in the background, periodic alerts for users to review app permissions, and the mandatory retention of security audit logs for a full 12 months on devices. However, these proposals have met with significant resistance from major global tech companies such as Apple, Samsung, Google, and Xiaomi. Represented by the Manufacturers' Association for Information Technology (MAIT), the industry has voiced strong opposition, arguing that such measures lack any global precedent and pose a substantial risk of revealing sensitive proprietary details and violating corporate secrecy. They also contend that requirements like continuous malware scanning could drain battery life and that seeking government approval for software updates before release is impractical, potentially leaving users vulnerable to exploits. Despite the pushback, India's IT Secretary, S. Krishnan, has indicated that the government is open to addressing any legitimate industry concerns, signifying that consultations on these proposals are still ongoing. The government had previously revoked an order mandating a state-run cybersecurity app, suggesting a willingness to consider industry feedback.
Read the full story on Quick Digest