BitChat: when the government bans the app, but not the network

5 min read Original article ↗

It wasn’t simply a matter of security. It was a direct and coordinated political order. According to a report by CyberInsider, on July 16, 2026, India’s Ministry of Electronics and Information Technology (MeitY) did more than just request the removal of BitChat from app stores. It issued a direct order to GitHub to delete the app’s source code repository. The official reason? Violation of local cybersecurity regulations and a threat to public order.

The result was a three-pronged attack:

  1. Removal from App Stores: The app has been removed from the Google Play Store and the Apple App Store in India. New users cannot download it.

  2. Deletion of source code: GitHub has removed the public repository. The code is no longer visible or easily clonable from that specific link.

  3. Domain blocking: Indian internet service providers have been ordered to block access to the official website and associated domains.

For millions of users, the connection was severed in an instant. But the crucial question is:

What really happens to those who had already installed the app?

The paradox: technical resilience vs. social fragility

Here, the uncomfortable truth that no one wants to admit comes to light. If BitChat were a centralized app (like WhatsApp), the servers would have been shut down and the app would have become a digital “brick.” Since it’s built on P2P (Peer-to-Peer) architecture and E2EE (End-to-End Encryption), the app technically continues to work for those who already have it installed, as long as they can connect to other nodes on the network.

But the government’s attack has struck at the “lifelines”:

  • No updates: Since users can’t download new versions from app stores, the app becomes vulnerable to future bugs.

  • Progressive isolation: The blocking of bootstrap domains prevents the discovery of new peers. Existing users risk becoming isolated in a shrinking network.

  • The barrier for the average user: Even if the code exists (saved by developers on alternative mirrors), the average user doesn’t know how to find it, how to verify the digital signature, or how to manually reinstall the APK.

Is open source resilient?

Yes. The code cannot be destroyed because it has been copied thousands of times. But technical resilience does not automatically translate to social survival. If 95% of users don’t know how to bypass the block, the app is dead to them. Censorship doesn’t have to kill the code; it just has to make using it so inconvenient that it pushes people back to the controlled apps. And in India, this plan is working.

For years, we’ve been sold on the idea that open source is a panacea:

If the code is open, no one can censor it.

That’s only half true. Open source builds trust in the app (anyone can read the source code), but it doesn’t protect access (who decides whether you can download the app or update it). BitChat has shown that even the most secure apps are vulnerable to the infrastructure they rely on: official app stores, DNS, and centralized repositories. When a government orders Google, Apple, and GitHub to comply, no amount of code can protect you.

True data sovereignty isn’t just about having verifiable code. It’s about having an ecosystem that survives political attacks:

  • Alternative distribution channels (mesh networks, Telegram, IPFS).

  • A community ready to keep mirrors alive.

  • Users educated not to blindly trust the convenience of app stores.

The BitChat situation isn’t a failure of privacy. It’s a stress test for our mental model.

Being in control doesn’t mean having an app that magically works forever. It means:

  • Accepting fragility: Knowing that the app store can remove the app and that the domain can be blocked.

  • Having a Plan B: Knowing where to find the alternative source code and how to verify its integrity.

  • Stop being passive: Security isn’t a product you buy and forget about. It’s an ongoing process that requires attention.

If an app disappears, it’s not the end. It’s the beginning of an active search. And this search is an act of resistance.

BitChat was attacked. It was wounded. But it isn’t dead. The Indian government has bought time, not victory. The information has leaked out. Anyone looking for BitChat today will find it, but they’ll have to go the extra mile. That extra effort is the price of freedom.

For those of us who build tools like Meishi, the challenge is clear: it’s not enough to create secure apps. We must create apps that are resilient to takedowns – apps that work even without app stores, official domains, or centralized updates.

And for you, the users: don’t wait for censorship to wake you up. If your favorite app were removed tomorrow, would you know what to do? If the answer is no, then you aren’t free yet. You’re just waiting.

Data sovereignty isn’t a gift. It’s a hard-won victory. And the battle for BitChat is just the beginning.

Don’t trust. Verify. Be prepared.

And we’ll be by your side in this battle.

The concept of Data Sovereignty in the Meishi Manifesto is missing here. If access to our data is restricted for commercial, regulatory, power, or security reasons, are we owners or just renters of our own lives? Data Sovereignty isn’t a gift – it’s a right we build ourselves. While you wait for the next post, I ask you:

Who do you want to control your data?

  1. 5–7 Big Tech companies

  2. 200+ governments

  3. You

Choose wisely!

✊❤️🔒
Own Your Data
Marco Parisi

Discussion about this post

Ready for more?