Jio’s Coronavirus Testing Tool Exposed Data of Millions: Report

The affected database by Jio for its COVID-19 tracking tool included the data of individuals, such as their user agent and symptoms on the basis of the questions asked by the tool.

Share on Facebook Tweet Snapchat Share Reddit Comment
Jio’s Coronavirus Testing Tool Exposed Data of Millions: Report

Jio launched its COVID-19 tool in late March

Highlights
  • Jio didn’t use a password for the affected database
  • It pulled the database offline shortly after getting notified
  • Jio’s tool was used not just in India but also in some other markets

Jio's tool to check COVID-19 symptoms was found to have a major security lapse that exposed one of its core databases containing the records of millions of users who logged in to perform a self-test, according to a report. The affected database, which was pulled offline after Jio was notified about the flaw, included logs and records starting April 17. It reportedly contained a running log of website errors and other system messages to a large extent — alongside including the data of users self-tested on the platform.

The affected database by Jio for its COVID-19 tracking tool included the data of individuals, such as their user agent that helps identify the browser version and operating system of participants, profile records, symptoms on the basis of the questions asked by the tool, reported TechCrunch. It also reportedly included the precise location of users, if they had enabled it.

Security researcher Anurag Sen on May 1 discovered that the database in question was exposed to the Internet without a password. Jio reportedly made it offline soon after it was notified about the flaw. However, it is unclear whether the data stored in the database was accessed by a third-party — apart from the security researcher revealing its exposure.

“We have taken immediate action,” said Jio spokesperson Tushar Pania, as quoted by TechCrunch. “The logging server was for monitoring performance of our website, intended for the limited purpose of people doing a self-check to see if they have any COVID-19 symptoms.”

Jio launched the COVID-19 self-testing tool in late March — sometime alongside the release of a similar checker by Bharti Airtel. It was designed to help people understand whether they're safe or at coronavirus risk. Users need to provide their gender and have the ability to even test the symptoms of their family members. The tool also asks the user's age, if the user came in contact with someone who has been tested positive for COVID-19. Furthermore, it is said to be used by even people outside India, including some from North America and the UK.


In 2020, will WhatsApp get the killer feature that every Indian is waiting for? Samsung Galaxy S20 in India? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts or RSS, download the episode, or just hit the play button below.

Comments

For the latest tech news and reviews, follow Gadgets 360 on Twitter, Facebook, and subscribe to our YouTube channel.

Jagmeet Singh Jagmeet Singh writes about consumer technology for Gadgets 360, out of New Delhi. Jagmeet is a senior reporter for Gadgets 360, and has frequently written about apps, computer security, Internet services, and telecom developments. Jagmeet is available on Twitter at @JagmeetS13 or Email at jagmeets@ndtv.com. Please send in your leads and tips. More
Realme Phones, Other Products Now on Sale via Realme Website, Amazon, and Flipkart in Green, Orange Zones

Related Stories

© Copyright Red Pixels Ventures Limited 2020. All rights reserved.
Listen to the latest songs, only on JioSaavn.com