Home

Donate
Analysis

BitChat-Github Takedown Shows India Redrawing Its Perimeter of Online Control

Amber Sinha / Aug 12, 2026

Amber Sinha is a contributing editor at Tech Policy Press.

A protestor carries a poster with a message in Hindi which translates as 'Save Our Constitution' as he participates in a protest movement led by Cockroach Janta Party, in New Delhi, India, Wednesday, July 22, 2026. (AP Photo/Vipin)

Republish

The Indian government’s takedown notice to GitHub regarding the BitChat application is a new use of the state’s machinery for online control. The directive, issued by the Indian Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs, demanded the removal of three open-source repositories hosting the BitChat application within a rigid three-hour window. While it is tempting to view this incident as a structural shift in how the state regulates technology, a closer examination of India’s administrative history would suggest that it represents a natural, pragmatic progression of the state's systematic use of coercive power online. As communication technologies evolve to circumvent traditional chokepoints, the Indian state is adjusting its regulatory perimeter, applying long-standing administrative strategies to new technological architectures.

To understand the implications of this order, let us look at the technology and the administrative context in which the state operates.

The tool and the protest context

BitChat is a decentralized, open-source messaging application that utilizes Bluetooth mesh networking. It allows users to communicate off-grid, relaying encrypted messages from device to device without relying on cellular infrastructure, Wi-Fi, or centralized servers. Because it bypasses traditional network layers, it requires no user registration or phone number verification.

The application recently gained significant traction among demonstrators in New Delhi. When local law enforcement authorities deployed a familiar tactic—imposing localized mobile internet blackouts under the Temporary Suspension of Telecom Services Rules—protesters adapted by utilizing BitChat to maintain coordination and communication. During the recent protests led by the Cockroach Janta Party (CJP) at Jantar Mantar in New Delhi, demonstrators turned to BitChat to maintain local coordination and real-time communication. Operating on a decentralized, peer-to-peer Bluetooth Low Energy (BLE) mesh network, BitChat allowed nearby smartphones to automatically relay encrypted messages directly from device to device without relying on cellular towers, central routing servers, SIM cards, or internet access. By removing the need for phone numbers or registered accounts, the app enabled protesters to organize logistics on the ground and bypass traditional network shutdowns and state surveillance chokepoints.

In its takedown notice, the I4C explicitly cited BitChat's decentralized architecture as the primary justification for the order. The agency argued that the app’s design “significantly impedes lawful interception, attribution, and investigation by law enforcement agencies.” Because there are no centralized servers to subpoena and no subscriber logs to request, the state found its traditional surveillance and interception mechanisms neutralized.

A natural progression of coercive power

The Indian state’s foundational objective during periods of civil unrest has always been to maintain a monopoly on information flow and communication. For some years, the most efficient mechanism to achieve this was the suspension of mobile internet. By coercing telecom service providers the government could effectively render a geographic zone offline. But as peer-to-peer applications like BitChat abstract communication away from cellular towers and into localized, device-to-device meshes, the telecom operator ceases to be a comprehensive chokepoint.

Faced with a decentralized protocol, the state moved one step up the technology stack to identify a new intermediary vulnerable to executive control, in this instance, GitHub. By targeting the platform that hosts the source code and installation binaries, the state’s attempt is to restrict the distribution of the tool at its source.

Statutory bypasses and intermediary liability

The legal mechanism employed by the I4C provides the most instructive insight into the state's operational pragmatism. As analysis by civil society groups like the Internet Freedom Foundation (IFF) have highlighted, the government did not rely on the standard statutory framework for website blocking.

Under normal circumstances, content blocking is governed by Section 69A of the Information Technology (IT) Act, 2000, read alongside the 2009 Blocking Rules. Section 69A contains procedural safeguards explicitly upheld by the Supreme Court in Shreya Singhal v. Union of India (2015). These safeguards include a designated review committee, an opportunity for a hearing for the content creator, and the requirement of a written, reasoned order.

Instead, the I4C utilized Section 79(3)(b) of the IT Act. Section 79 is primarily designed as a safe harbor provision, granting intermediaries immunity from liability for third-party content. However, sub-clause (3)(b) revokes this immunity if an intermediary fails to expeditiously remove or disable access to unlawful material upon receiving “actual knowledge” via a government or court order. By weaponizing an intermediary liability exemption to effectuate a content takedown, the government circumvented the procedural friction of Section 69A. Section 79(3)(b) does not mandate hearings for developers, nor does it require detailed proportionality assessments by a review committee. It operates on the threat of secondary liability: comply within three hours, or risk losing safe harbor protections in India.

The Indian state frequently seeks the path of least administrative resistance, utilizing broad statutory interpretations to compel platform compliance without inviting judicial scrutiny or procedural delays. As MediaNama reports, the true danger of this order lies in its potential for replication. The logic used against BitChat applies equally to any permission-less protocol, such as decentralized social networks. If the government can routinely use intermediary liability threats to remove communication tools simply because their architecture limits surveillance, a troubling precedent is set for all decentralized technologies. Addressing these systemic loopholes remains essential to securing any privacy-preserving, decentralized software.

Support Tech Policy Press
If you've found our work helpful, consider supporting us.

Authors

Amber Sinha
Amber Sinha is a Contributing Editor at Tech Policy Press. He is the Executive Director of European Digital Rights (EDRi). He works at the intersection of law, technology, and society and studies the impact of digital technologies on socio-political processes and structures. Until 2022, Amber was th...

Topics

Related

Perspective
India's Telegram Ban Risks Normalizing Platform-Wide BlockingJune 22, 2026
Analysis
India’s Decentralized System of Internet CensorshipApril 8, 2026