Among the most sensitive requirements in the new Indian Telecom Security Assurance Requirements is access to source code — the underlying programming instructionsAmong the most sensitive requirements in the new Indian Telecom Security Assurance Requirements is access to source code — the underlying programming instructions

India proposes forcing smartphone makers to give source code in security overhaul

2026/01/12 14:29

NEW DELHI, India – India proposes requiring smartphone makers to share source code with the government and make several software changes as part of a raft of security measures, prompting behind-the-scenes opposition from giants like Apple and Samsung.

The tech companies have countered that the package of 83 security standards, which would also include a requirement to alert the government to major software updates, lacks any global precedent and risks revealing proprietary details, according to four people familiar with the discussions and a Reuters review of confidential government and industry documents.

The plan is part of Prime Minister Narendra Modi’s efforts to boost security of user data as online fraud and data breaches increase in the world’s second-largest smartphone market, with nearly 750 million phones.

IT Secretary S. Krishnan told Reuters on Saturday, January 10, “any legitimate concerns of the industry will be addressed with an open mind”, adding it was “premature to read more into it”.

A ministry spokesperson said in an emailed statement on Saturday it could not comment further due to ongoing consultation with tech companies on the proposals.

After the story was published, an IT ministry statement said late on Sunday that the consultations are aimed at developing “an appropriate and robust regulatory framework for mobile security”, and it “routinely” engaged with the industry “to better understand technical and compliance burden.”

The IT ministry added it “refutes the statement” that it is considering seeking source code from smartphone makers, without elaborating or commenting on the government or industry documents cited by Reuters.

Ongoing tug of war over government requirements

Apple, South Korea’s Samsung, Google, China’s Xiaomi, and MAIT, the Indian industry group that represents the firms, did not respond to requests for comment.

Indian government requirements have irked technology firms before. Last month it revoked an order mandating a state-run cyber safety app on phones amid concerns over surveillance. But the government brushed aside lobbying last year and required rigorous testing for security cameras over fears of Chinese spying.

Xiaomi and Samsung — whose phones use Google’s Android operating system — hold 19% and 15%, respectively, of India’s market share and Apple 5%, Counterpoint Research estimates.

Among the most sensitive requirements in the new Indian Telecom Security Assurance Requirements is access to source code — the underlying programming instructions that make phones work. This would be analyzed and possibly tested at designated Indian labs, the documents show.

The Indian proposals also require companies to make software changes to allow pre-installed apps to be uninstalled and to block apps from using cameras and microphones in the background to “avoid malicious usage.”

“Industry raised concerns that globally security requirement have not been mandated by any country,” said a December IT ministry document detailing meetings that officials held with Apple, Samsung, Google and Xiaomi.

The security standards, drafted in 2023, are in the spotlight now as the government is considering imposing them legally. IT ministry and tech executives are due to meet on Tuesday for more discussions, sources said.

Companies say source code review, analysis, ‘not possible’

Smartphone makers closely guard their source code. Apple declined China’s request for source code between 2014 and 2016, and US law enforcement has also tried and failed to get it.

India’s proposals for “vulnerability analysis” and “source code review” would require smartphone makers to perform a “complete security assessment,” after which test labs in India could check their claims through source code review and analysis.

“This is not possible… due to secrecy and privacy,” MAIT said in a confidential document drafted in response to the government proposal, and seen by Reuters. “Major countries in the EU, North America, Australia, and Africa do not mandate these requirements.”

MAIT asked the ministry last week to drop the proposal, a source with direct knowledge said.

The Indian proposals would mandate automatic and periodic malware scanning on phones. Device makers would also have to inform the National Centre for Communication Security about major software updates and security patches before releasing them to users, and the centre would have the right to test them.

MAIT’s document says regular malware scanning significantly drains a phone’s battery and seeking government approval for software updates is “impractical” as they need to be issued promptly.

India also wants the phone’s logs – digital records of its system activity – to be stored for at least 12 months on the device.

“There is not enough room on device to store 1-year log events,” MAIT said in the document. –Rappler.com

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

The Channel Factories We’ve Been Waiting For

The Channel Factories We’ve Been Waiting For

The post The Channel Factories We’ve Been Waiting For appeared on BitcoinEthereumNews.com. Visions of future technology are often prescient about the broad strokes while flubbing the details. The tablets in “2001: A Space Odyssey” do indeed look like iPads, but you never see the astronauts paying for subscriptions or wasting hours on Candy Crush.  Channel factories are one vision that arose early in the history of the Lightning Network to address some challenges that Lightning has faced from the beginning. Despite having grown to become Bitcoin’s most successful layer-2 scaling solution, with instant and low-fee payments, Lightning’s scale is limited by its reliance on payment channels. Although Lightning shifts most transactions off-chain, each payment channel still requires an on-chain transaction to open and (usually) another to close. As adoption grows, pressure on the blockchain grows with it. The need for a more scalable approach to managing channels is clear. Channel factories were supposed to meet this need, but where are they? In 2025, subnetworks are emerging that revive the impetus of channel factories with some new details that vastly increase their potential. They are natively interoperable with Lightning and achieve greater scale by allowing a group of participants to open a shared multisig UTXO and create multiple bilateral channels, which reduces the number of on-chain transactions and improves capital efficiency. Achieving greater scale by reducing complexity, Ark and Spark perform the same function as traditional channel factories with new designs and additional capabilities based on shared UTXOs.  Channel Factories 101 Channel factories have been around since the inception of Lightning. A factory is a multiparty contract where multiple users (not just two, as in a Dryja-Poon channel) cooperatively lock funds in a single multisig UTXO. They can open, close and update channels off-chain without updating the blockchain for each operation. Only when participants leave or the factory dissolves is an on-chain transaction…
Share
BitcoinEthereumNews2025/09/18 00:09
SUI Price Eyes Breakout, Targets $11 Says Analyst

SUI Price Eyes Breakout, Targets $11 Says Analyst

The post SUI Price Eyes Breakout, Targets $11 Says Analyst appeared on BitcoinEthereumNews.com. SUI price shows a technical setup for a macro breakout with analyst Dan Gambardello targeting $10-$11 levels. Recent partnership with Google’s Agentic Payments Protocol adds fundamental support to the technical analysis as SUI moves closer to potential breakout levels. SUI Price Analysis Points to $10-$11 Breakout Target Dan Gambardello has identified a clear ascending triangle formation on SUI price daily chart with upside targets around $10.79. The analyst simplified this target range to $10-$11 for practical trading purposes. The pattern shows sustained higher lows meeting resistance at current levels before a potential breakout. VanEck maintains more aggressive SUI crypto targets ranging from $13-$25 according to Gambardello’s research. SUI Price Analysis | Source: Dan Gambardello, X The $10 level is a more conservative higher high area for the current cycle. Midterm targets point to $7.50 in the 1.618 Fibonacci extension zone before longer-term objectives. The monthly RSI shows extreme compression that Gambardello describes as “screaming for a macro breakout to the upside.” This momentum oscillator behavior typically precedes major price movements in the crypto market. SUI crypto risk model currently sits at 51 and matches pre-bull market levels seen in coins like Ethereum. Gambardello compared this to Ethereum’s December 2020 reading of 51 before its major breakout. The March 2017 Ethereum reading of 53 preceded that cycle’s parabolic move. The analyst also noted that SUI price trades near the same levels from almost a year ago in November 2024. Bollinger Bands Signal Historic Compression CryptoBullet has identified the tightest Bollinger Bands in SUI’s entire trading history on the weekly chart. The BBW indicator compression reached levels that were historically followed by major price movements. This setup mirrors conditions before SUI’s previous major rallies. Historical data shows SUI price delivered +253% gains between December 2023 and March 2024 following similar compression. SUI…
Share
BitcoinEthereumNews2025/09/18 11:32
How Zero Knowledge Proof Is Changing Blockchain Performance Forever

How Zero Knowledge Proof Is Changing Blockchain Performance Forever

The post How Zero Knowledge Proof Is Changing Blockchain Performance Forever appeared on BitcoinEthereumNews.com. Crypto Projects Learn how Zero Knowledge Proof
Share
BitcoinEthereumNews2026/01/13 04:11