In a recent LinkedIn post, Nithin Kamath discusses his reservations about the mandatory permissions requested by many net banking applications on mobile devices. Kamath, the founder of Zerodha, a prominent financial services company, articulated his stance on cybersecurity and user privacy, drawing a clear line between genuine security measures and invasive data access.
Kamath opened by stating his personal practice of avoiding net banking apps on his phone due to the extensive permissions they require. He questioned the rationale behind these demands, particularly when they involve access to sensitive data like SMS, phone calls, and contacts.
“Why does a banking app need access to my SMS, phone, contacts, etc., in the name of security, when not seeking invasive device permissions is, in fact, the global benchmark for cybersecurity.”
The Principle of Least Privilege in Practice
Central to Nithin Kamath’s argument is the Principle of Least Privilege (PoLP), a fundamental cybersecurity concept. According to Kamath, PoLP dictates that any user, program, or process should have only the bare minimum privileges necessary to perform its intended function. He contrasts this with the invasive permissions often sought by banking apps, suggesting that such requests run counter to established cybersecurity best practices.
Kamath emphasized that this principle is deeply ingrained in Zerodha’s operational philosophy. He stated:
“‘Don’t do unto others what you don’t want done unto you’ has been at the heart of the Zerodha philosophy.”
This ethical framework, Kamath suggests, directly influences how Zerodha designs its products and handles user data. He pointed out that their trading platform, Kite, exemplifies this approach.
Zerodha’s Approach to Permissions and Trust
Highlighting Zerodha’s commitment to user privacy, Nithin Kamath noted that their mobile trading application, Kite, requests no permissions from users’ devices. This minimalist approach to permissions is presented as a key factor in building trust with their extensive user base.
“Kite asks for ZERO permissions on mobile, for instance, and this is one of the big reasons why millions of people trust us.”
Kamath further elaborated that the trust users place in Zerodha is bolstered by regulatory frameworks. He credited SEBI’s mandatory strong two-factor authentication framework for striking an effective balance between robust security and essential user privacy. This combination, in his view, allows for a secure yet non-intrusive user experience.
Broader Implications for the Fintech Industry
Nithin Kamath’s insights raise important questions for the broader fintech industry. As digital banking becomes increasingly prevalent, the balance between security and user privacy remains a critical challenge. Kamath’s advocacy for the Principle of Least Privilege serves as a reminder that robust cybersecurity does not necessitate intrusive data collection.
He argues that financial institutions should prioritize user trust by adopting privacy-conscious design principles. By minimizing data access and adhering to PoLP, companies can not only enhance their security posture but also strengthen their relationship with customers.
The discussion initiated by Nithin Kamath on LinkedIn underscores the ongoing need for transparency and ethical data handling within the financial technology sector. His perspective suggests that prioritizing user privacy through thoughtful permission management can be a significant differentiator and a cornerstone of long-term business success.
📝 About This Content
This article is based on insights shared by Nithin Kamath on LinkedIn.
📅 Originally posted on March 17, 2026 | View original post on LinkedIn →