6 ms·
I don't quite understand why Apple and Google are releasing an API instead of a single system application. This is going to create a gigantic mess as governmen
by devit 6y ago
I don't quite understand why Apple and Google are releasing an API instead of a single system application.
This is going to create a gigantic mess as governments with limited software development competence slowly release incompatible and partially broken applications, while Apple and Google could just deploy a single solution via a system update.
Also, it's much easier to make it mandatory if it's a system app (and obviously it needs to be mandatory to be useful).
- jedieaston 6y agoThe governments each want their own app so data isn't shared with other governments, so either Apple sends out 100+ versions of an iOS update, or, they expose an API and let the governments ingest it into an app that they control, which adds privacy for the user by making it opt-in.
- devit 6y agoBut no data is shared with the government, so there isn't any data that gets shared with "other governments". All that is shared is a randomly generated key that can only be used by other smartphones to determine if any of the ids that they have collected come from the key.
- bjtitus 6y ago> But no data is shared with the government > All that is shared is a randomly generated key thinking face I agree, though, it seems dumb to have governments anywhere near this.
- pmiller2 6y agoThat sounds like a massive privacy violation to me.
- yegle 6y agoThe only time your keys are uploaded, is when you are infected. The assumption is that if you are infectious certain privacy needs to forgo to protect others. In fact this is over simplification. The only key that will be uploaded is partial of the daily tracing key (called Diagnosis Key in the specification). Most importantly, there's no location or timestamp involved or needed. Once this Diagnosis Key is uploaded, every client (anyone who wants to know if they are potentially infected) will periodically download the batch and see if your phone has seen any of the Rolling Proximity Identifiers, and when.
- pmiller2 6y agoRight, and there’s no possible abuses this could be used for, of course — no way this data can ever be deanonymized, right? What I object to is putting this all into an automated system for everyone, infected or not. If there’s a way to generate a diagnosis key, there’s a way to spoof it, and that can be used to infer contacts for the non infected. You may have a point when it comes to the infected, but even then, giving Apple or Google this type of information is putting far too much trust and power into too few hands.
- yegle 6y agoWait what part of the data do you want to deanonymize? It's computational impossible to reverse from Rolling Proximity Key to Daily Tracing Key to Tracing Key.
- pmiller2 6y agoThat literally cannot be true if there’s a way to generate this “diagnosis key” and notify everyone I’ve been in contact with.
- 0xBeefFed 6y agoYour use of the word partial could lead to confusion. The Diagnosis Keys are a subset of the Daily Tracing Keys for the days youre contagious. You then upload these Daily Tracing Keys and associated day numbers. Also you are incorrect about the involvement of a timestamp. The protocol uses DayNumbers to track the specific day a Daily Tracing Number was used. In terms of privacy, small-scale adversaries can deanonymize infected users that have uploaded their [keys by keeping logs] of and limiting who they have come in close contact with. On a large-scale, adversaries in control of large Bluetooth receiver networks (such as cities performing traffic analysis) can now track the movements of individual infected users over the course of a day. One could argue that this is already being done to track anyone with bluetooth enabled. In addition, the process of uploading to the backend server could alert adversaries monitoring your network that you (the device using your IP address, uploading to the server IP address) have tested positive for the virus. I recommend that you look at other contact tracing protocols that circumvent some of these issues by decrease or eliminating the linkability of identifiers, allowing users to censor records uploaded, and encourge the use of network-anonymization. *Edit Spelling - Source: https://covid19-static.cdn-apple.com/applications/covid19/current/static/contact-tracing/pdf/ContactTracing-CryptographySpecification.pdf https://covid19-static.cdn-apple.com/applications/covid19/cu...
- floatingatoll 6y agoWhat you describe is how iOS was first released. Anyone who wanted to build an app would use progressive web apps. Every native app was controlled by Apple only. This was loathed by developers and corrected in a later release. Given the steady recurring posts here on HN and elsewhere about hoping that Apple will open up to third-party app selections for email/browser/etc. someday, suggesting that Apple control the only Covid app on their platform is contradictory to that goal.
- yegle 6y agoThe system is intended to be annonymous and can't have any user registration or authentication. How can you validate when someone report they are infectious, the Diagnostic Key is indeed from a legit iOS device? If you can't validate it, this can be easily abused (attacker generate a huge list of Diagnosis Keys and upload, claiming to be infected, and causing a wave of public panic) My understanding is that there must be some internal/proprietary API from Apple that they are using to validate this, and there's no other vendor except Apple to develop such an API to mitigate the abuse risk.
- Reelin 6y agoThis is misguided. As you note, the system is anonymous and can't have any registration or authentication. Moreover, an Apple or Google specific API for validation would prevent interoperability of other (future) implementations including any free and open source (ie actually verifiable) ones. Therefore, all authentication must be done on the receiving end by deciding which data sources to trust. This should be fairly straightforward because when a healthcare provider performs testing they are in a position to collect any keys from you at the same time. They are then the ones trusted to accurately report keys, which should be fine since we already trust them both to accurately report test results and to safeguard patient privacy. Importantly, such a decentralized design allows for cooperative framework implementations, competing app implementations, and multiple data sources. Google or Apple could run a data server, your local government could run a data server, etc. Even more interestingly, such a framework could be repurposed for other less critical uses later as a form of privacy-preserving mutually opt-in contact discovery. Non-essential use of the framework might even ensure that people keep it running all the time, so that the data is ready and waiting the next time a novel pathogen appears.
- yegle 6y agoWhat you describe is not in conflict with the Apple/Google proposed solutions. Or rather, it (the part of reporting and aggregating on the server side) is not part of the proposed solution. When tested positive, to which server the diagnosis keys are reported to can vary depending on the platform and app. It could be reported via a goverment approved app, or reported to Google/Apple provided server. As long as Google/Apple aggregate the diagnosis keys across multiple servers (or even multiple servers across multiple countries), we still take the full advantage of this contact tracing framework.
- sneak 6y ago> and obviously it needs to be mandatory to be useful That's not only not-obvious, I don't even believe it's true. Contact tracing is useful even if only 50% of the population uses such a system. (Remember, not everyone even has a smartphone.) It would be business suicide to force such a choice on users. I'd throw my iPhone into the nearest river if a system update forced it upon me, even if I trust the system and would have opted in.
- atleta 6y agoIt doesn't have to be governments. 3rd parties can build these systems either by themselves or paid for by governments and several governments can use/buy the same system. Also, these (some of these) can hopefully be open source apps, too. Pretty important as there will be privacy concerns (rightfully) which can hurt in two ways. First: the concerns could be real and the data collection could be problematic. Second: whether or not the first is the case, this may prevent a lot of people installing it. If it's a mandatory update that sidesteps the second issue, but then it could hurt Google's and Apple's image. Also, could cause serious problems with the EU (think GDPR). Even if they really can't get any meaningful and sensitive data out of it, they would be running the risk of an investigation.
- jtl999 6y agoI was thinking the same thing, are we going to have a mess of contact tracing apps and services with the similar analogy of the incompatibility with differing messaging protocols? > Also, it's much easier to make it mandatory if it's a system app (and obviously it needs to be mandatory to be useful). That might work in the case of Apple, Google Pixel and (some) Android One devices where the firmware is (often) manufacturer controlled. Outside of the Google Play Services approach good luck trying to deploy a new Android feature to all the devices out there.
- natch 6y agoI don't understand it either but that doesn't lead me to leap to a conclusion that Apple's and Google's expert cryptographers and system architects don't know what they are doing. I instead blame my own current ignorance, and look forward to gaining more understanding. But yes as a user, personally I'd prefer to use and trust an app supplied by my OS provider, mandatory or not, built in to the OS or not (and plenty of Apple apps are optional after-the-fact downloads, so it need not be a forced download unless there are reasons for that that overcome all the negatives).