BREAKING
Revolutionary climate technology breakthrough announced • Championship finals draw record 150M+ viewers • Global markets surge following policy changes • New discovery in quantum computing promises faster processors
Technology

India vs smartphone giants: Why the fight over source code is really about control, not data

What happened: The Indian government and global smartphone makers are locked in a standoff over proposed mobile security standards, including device log storage, software update...

Jan 24
5 min read
India vs smartphone giants: Why the fight over source code is really about control, not data
  • What happened: The Indian government and global smartphone makers are locked in a standoff over proposed mobile security standards, including device log storage, software update oversight, and possible source code access.

  • Why it matters now: With over 750 million smartphones in use, the dispute could redefine how security, privacy, and state power interact in India’s digital ecosystem.

  • What changes for people: Phone updates, device security, user autonomy, and even free expression could be affected depending on how rules are framed.

  • Who is affected: Smartphone users, global tech companies, cybersecurity firms, regulators, and India’s digital economy.

The Indian government says it does not want your personal data. What it wants, critics argue, is far more consequential: a window into how your phone is built and how it behaves.

At the centre of a growing confrontation between New Delhi and global smartphone manufacturers is a deceptively technical phrase: source code access. Officials describe the issue as a routine security discussion. Industry experts and digital rights advocates say that description hides a far deeper philosophical conflict.


What “source code” really means

Source code is not your messages, photos, or contacts.

It is the instruction layer that tells a smartphone:

  • How it processes information

  • How security protections work

  • How and when updates are deployed

Underline: Access to source code is access to a device’s internal logic.

According to documents reviewed by Reuters, proposed standards could require manufacturers to:

  • Store device logs for up to one year

  • Notify authorities before major software updates

  • Submit updates for testing or approval

  • Potentially share elements of source code

While the government says consultations are ongoing and denies seeking code access, the gap between official statements and documented proposals has fuelled concern.


Why the government is pushing this

From first principles, the state’s anxiety is understandable.

India has nearly 750 million smartphones, now used as:

  • Wallets

  • Identity tools

  • Work terminals

  • Political megaphones

Cyber fraud is rising. Security vulnerabilities are real. A government that ignored these risks would face accusations of negligence.

Underline: The concern is legitimate. The method is the controversy.


The speed problem in digital security

Modern cybersecurity depends on speed.

Vulnerabilities emerge constantly. Fixes work only if they reach users immediately. Any system that slows updates, even in the name of safety, increases exposure.

Security experts warn that:

  • Pre-approval of updates can delay critical patches

  • Advance notice requirements widen attack windows

  • Even hours or days of delay can be exploited during active cyber threats

This risk is not theoretical. It is how real-world breaches spread.


Questions of trust and intent

Sujit Janardanan, CMO of Neysa Networks, argues the issue begins even earlier.

India, he points out, still struggles with:

  • Internet affordability

  • Access gaps

  • Weak last-mile digital ecosystems

Technologies like 5G were pitched as transformational for education and agriculture, but outcomes have fallen short.

Against this backdrop, Janardanan questions security initiatives that:

  • Do not clearly define what risk they solve

  • Lack global precedents

  • Rely on broad claims of “user protection” without specifics

Underline: Trust erodes when objectives are vague and tools are expansive.


From targeted surveillance to built-in oversight

Apar Gupta, founder-director of the Internet Freedom Foundation (IFF), says the real issue is not one proposal in isolation, but the system forming around it.

Combining:

  • Source code access

  • Mandatory device logging

  • Pre-clearance of OS updates

  • Restrictions on modification or rollback

changes the nature of state power.

Underline: Surveillance shifts from targeted action to built-in capability.

Scale, not necessity, becomes the defining feature.


The constitutional challenge

India’s Supreme Court has repeatedly ruled that privacy intrusions must meet tests of:

  • Legality

  • Necessity

  • Proportionality

Embedding monitoring capabilities across every handset, with unclear statutory backing and limited independent oversight, raises serious constitutional questions.

Once such systems exist, experts warn, limits become difficult to enforce in practice.


How other democracies handle phone security

Globally, handset security is usually strengthened through:

  • Independent audits

  • Security standards

  • Responsible vulnerability disclosure

  • Rapid patch deployment

Not by:

  • Slowing updates

  • Mandating behavioural logging

  • Giving governments architectural influence over device design

India’s proposed approach would place it outside mainstream democratic practice.


The hidden risks users may feel later

Critics warn of predictable second-order effects:

  • Long-term device logs encourage self-censorship

  • Update delays weaken cybersecurity

  • Anti-modification rules reduce user choice and control

  • Vendor and state-approved software ecosystems become harder to escape

India’s past experience with spyware allegations and zero-click attacks has already shown how dangerous powerful vulnerabilities can be when misused.


The choice India now faces

The debate is not about whether India should secure smartphones.

It must.

The real question is how.

Underline: Will security be built on speed, resilience, and accountability—or on control, pre-clearance, and architectural oversight?

That decision will not remain confined to phones. It will shape:

  • How software is written

  • How trust is maintained

  • How power is exercised in India’s digital economy

And once a device is designed for control, it does not easily relearn freedom.