Saturday, August 1, 2026
Qui Pus Info

India Wants 83 Security Rules Baked Into Your Next Phone

Your phone finished installing a security patch last night while you slept. Under a draft rule India is still arguing over, that patch would have stopped at a government body for review before it ever reached you, and the code behind it would sit in a testing lab somewhere in India. Same phone, same update, one extra reader.

India Wants 83 Security Rules Baked Into Your Next Phone
TL;DR: India's draft ITSAR package bundles 83 security standards into one rulebook for every handset sold here. Source-code review, pre-release patch vetting, and a year of system logs stored on your device. Nothing is notified yet, and the real fight is over who gets to look.

Why It Matters

Start with what already happened, because it sets the pattern. India's Ministry of Communications gave handset makers 90 days to preinstall its Sanchar Saathi app in a December 2025 order, told them to make sure users could not disable it, and withdrew the whole thing two days later after the backlash. The app survived. The mandate did not. That sequence, order first and consultation afterwards, is the thing worth watching, not any single rule inside it.

The ITSAR package is a bigger version of the same instinct. Reuters reported in January 2026 that the draft would require device makers to open source code for review at designated labs in India, submit updates and security patches to a government body before public release, run periodic on-device malware scans, and keep system logs on the handset. India's IT ministry publicly refuted the source-code characterisation the next day. Both things are on the record, and neither has been resolved since.

And here is where I part company with most of the coverage. The patch-vetting clause worries me more than the source-code clause does. Source code review is a one-time exposure that vendors can negotiate, sandbox, and lawyer around. A standing approval queue between a security fix and your handset is different: it inserts a delay into the exact process that exists to remove delay. Every hour a patch waits in a review inbox is an hour the bug it fixes is still live on 750 million devices. That is not a privacy argument. It is an arithmetic one. The same tension showed up when credit lines quietly attached themselves to ordinary UPI payments, and again when EV charging fragmented into a hundred incompatible apps: the rulebook arrives after the behaviour, and consumers absorb the gap.

Draft Standards

83

Rules in one package

Log Retention

12 months

Kept on your handset

Average Phone Price

$282

Record India price, 2025

Yearly Price Rise

8%

Counterpoint's 2025 increase

Those price figures come from Counterpoint Research's 2025 India numbers, and they belong in this conversation for a plain reason. Compliance is never free. Testing, lab submissions, and a separate India build all land somewhere in the bill of materials, and in a market where the average handset already costs more than it did a year ago, the cheapest phones are where that cost shows up first. The people most likely to buy a device with a locked-down India-specific security build are also the people least able to pay another few hundred rupees for it.

"

A year of system logs sitting on your handset is not a security feature. It is an evidence locker, and you are holding the key on someone else's behalf.

What The Draft Actually Contains

Strip away the legal briefings and the exam-prep summaries, and the package resolves into a handful of concrete changes to the device in your pocket. Some of them are things privacy advocates have wanted for a decade. Others are the opposite.

Category Detail Why It Matters
Framework ITSAR, drafted in 2023, now weighed as binding Old text, brand new legal force
Source Code Reviewed and tested at designated Indian labs Vendors call it precedent-free globally
Update Path Patches submitted for review before public release A queue sits between fix and phone
Bloatware Every pre-installed app becomes removable The one clean consumer win here
Permissions Limits on what apps may run in background Fewer apps listening while idle
Scanning Periodic malware scans running on the handset Battery and performance cost falls on you
Status Consultations open, no rules notified so far Still a draft, not yet law

Read down that table and the split is obvious. Two rows help you. Four rows help someone else and bill you for the privilege. The removable-bloatware clause alone would do more for the average budget handset in India than anything a manufacturer has shipped voluntarily in five years, which is exactly why it should not be traded away as a sweetener for the rest.

1 Dec 2025 · 3 Dec 2025 · 11 Jan 2026 · Aug 2026 Preinstall order · Order withdrawn · ITSAR draft reported · Still unnotified

The timeline above tracks four moves in eight months: a preinstall order on 1 December 2025, its withdrawal on 3 December 2025, the ITSAR draft surfacing on 11 January 2026, and no notified rule as of August 2026.

The Friction Points Nobody Has Solved

Nobody has answered the question that actually matters: who audits the auditor. A state that can read source code and clear patches before release gains real defensive capability and real surveillance capability from the identical access, and the draft says nothing about which one it is buying. That is not a conspiracy claim. It is a design gap, and it is the kind of gap that gets filled quietly by whoever holds the keys, in whichever direction is convenient at the time. My position is that access this broad needs an independent oversight body named in the rule itself, before the rule exists, not bolted on after the first misuse.

There is a fair counter-argument and it deserves stating properly. India absorbs enormous volumes of device-level fraud, and regulators have limited leverage over handset makers headquartered elsewhere. Sitting on your hands is also a choice with a body count. The complaint here is not that India is regulating phones. It is that the sequencing keeps running backwards, the same way telecom oversight arrived years after market concentration had already set.

  • Patch latency compounds: a review queue that adds even days to an emergency fix hands attackers a window that scales with every device in the country.
  • Storage and battery are finite: continuous scanning plus a year of retained logs consumes exactly the resources that budget handsets have least of.
  • Log access is undefined: the draft says logs must exist, not who may request them, under what process, or how long a request stays secret.
  • Fragmentation risk: an India-specific build that diverges from the global one tends to receive updates last, which is the reverse of the stated goal.
  • Enforcement is untested: the same withdrawal that killed the preinstall order shows how fast a mandate can move, in both directions, without warning.

Key Takeaways

India shipped 152 million smartphones in 2025 on IDC's count, roughly flat year on year, so any device rule here lands on a market that is large but no longer growing.

Nothing in the package is enforceable today. Consultations are open and no standard has been notified, which means public comment still counts for something.

The removable pre-installed apps clause is worth defending on its own merits, separately from the surveillance-adjacent clauses it currently travels with.

Read the consultation notices when they appear and say something specific about the clause you object to, because a draft with no notified rule is the only stage at which any of this is still negotiable. Once 83 standards ship as one package, nobody gets to keep the two good ones and drop the rest.

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.