India Targets Decentralized App Code
A government demand to remove open-source repositories from GitHub challenges the legal limits of controlling offline messaging.
An official mandate from the Indian government to force the removal of GitHub repositories associated with the decentralized messaging application Bitchat has ignited a debate over the scope of state authority. By targeting the underlying code rather than specific content, authorities are navigating uncharted legal territory regarding how software architecture itself can be deemed a tool for circumvention.
Targeting Decentralized Architecture
The controversy emerged following a notice publicized by Jack Dorsey, which reportedly originated from India’s Ministry of Home Affairs. The document, dated July 23, specifically ordered the restriction of three repositories linked to the Bluetooth-powered app. Officials argued that because the software operates without central servers and functions during internet shutdowns, it hinders their capacity for lawful interception and traceability.
This initiative coincides with ongoing student-led protests in New Delhi, often described as the “cockroach” movement. As authorities move to tighten internet restrictions to manage these demonstrations, the reliance on offline communication tools like Bitchat has grown, leading to a surge in domestic adoption.
Disputing Legal Precedent
Legal experts observe that the notice marks a departure from traditional enforcement methods. Previously, government removals typically relied on Section 69A of the IT Act, which requires identifying specific illegal material. Critics argue the current approach lacks a clear statutory basis for banning an entire software project simply because of its functional capabilities.
They’re [the Indian government] not just targeting the designated service provider, but they’re trying to say that open source development of this type of product … should not occur.
— Raman Chima, global programme director at the Association for Progressive Communications
Usage Statistics and Impact
- India accounted for approximately 85% of the application's global downloads between July 17 and July 23.
- The app saw more than 91,000 downloads in India within a five-day period.
- Daily active users in India reached a peak of over 330,000 on Thursday.
- Downloads for the software increased 32-fold on July 19 compared to the prior day.
Consequences for Open Source
For the broader technology sector, the attempt to suppress Jack Dorsey’s offline Bluetooth-powered messaging app Bitchat suggests that infrastructure-level code may become a new focal point for regulatory intervention. If such orders succeed, developers could face significant liability simply for building tools that provide private, resilient communication channels. As organizations like the Internet Freedom Foundation note, removing repositories prevents scrutiny of the code itself, yet does nothing to stop the software from functioning on devices where it is already installed.
Sources
- TechCrunch Original source
- Jack Dorsey’s offline Bluetooth-powered messaging app Bitchat Also reporting
- tighten internet restrictions Also reporting
Continue Reading
Critical Path Injection Found in Microsoft Kiota
Microsoft has patched a critical path traversal vulnerability in Kiota that allows malicious OpenAPI descriptions to inject unauthorized file references.
Critical RCE Flaw Patched in Prompty Core
A server-side template injection vulnerability in the @prompty/core Nunjucks renderer allows attackers to execute arbitrary code on the host system.
Critical Auth Bypass Found in kin-openapi
A failure in the kin-openapi ValidationHandler allows unauthenticated attackers to bypass security requirements, earning a critical 9.1 CVSS score.