3 ms·
But no data is shared with the government, so there isn't any data that gets shared with "other governments". All that is shared is a randomly generated key th
by devit 6y ago
But no data is shared with the government, so there isn't any data that gets shared with "other governments".
All that is shared is a randomly generated key that can only be used by other smartphones to determine if any of the ids that they have collected come from the key.
- bjtitus 6y ago> But no data is shared with the government > All that is shared is a randomly generated key thinking face I agree, though, it seems dumb to have governments anywhere near this.
- pmiller2 6y agoThat sounds like a massive privacy violation to me.
- yegle 6y agoThe only time your keys are uploaded, is when you are infected. The assumption is that if you are infectious certain privacy needs to forgo to protect others. In fact this is over simplification. The only key that will be uploaded is partial of the daily tracing key (called Diagnosis Key in the specification). Most importantly, there's no location or timestamp involved or needed. Once this Diagnosis Key is uploaded, every client (anyone who wants to know if they are potentially infected) will periodically download the batch and see if your phone has seen any of the Rolling Proximity Identifiers, and when.
- pmiller2 6y agoRight, and there’s no possible abuses this could be used for, of course — no way this data can ever be deanonymized, right? What I object to is putting this all into an automated system for everyone, infected or not. If there’s a way to generate a diagnosis key, there’s a way to spoof it, and that can be used to infer contacts for the non infected. You may have a point when it comes to the infected, but even then, giving Apple or Google this type of information is putting far too much trust and power into too few hands.
- yegle 6y agoWait what part of the data do you want to deanonymize? It's computational impossible to reverse from Rolling Proximity Key to Daily Tracing Key to Tracing Key.
- pmiller2 6y agoThat literally cannot be true if there’s a way to generate this “diagnosis key” and notify everyone I’ve been in contact with.
- 0xBeefFed 6y agoYour use of the word partial could lead to confusion. The Diagnosis Keys are a subset of the Daily Tracing Keys for the days youre contagious. You then upload these Daily Tracing Keys and associated day numbers. Also you are incorrect about the involvement of a timestamp. The protocol uses DayNumbers to track the specific day a Daily Tracing Number was used. In terms of privacy, small-scale adversaries can deanonymize infected users that have uploaded their [keys by keeping logs] of and limiting who they have come in close contact with. On a large-scale, adversaries in control of large Bluetooth receiver networks (such as cities performing traffic analysis) can now track the movements of individual infected users over the course of a day. One could argue that this is already being done to track anyone with bluetooth enabled. In addition, the process of uploading to the backend server could alert adversaries monitoring your network that you (the device using your IP address, uploading to the server IP address) have tested positive for the virus. I recommend that you look at other contact tracing protocols that circumvent some of these issues by decrease or eliminating the linkability of identifiers, allowing users to censor records uploaded, and encourge the use of network-anonymization. *Edit Spelling - Source: https://covid19-static.cdn-apple.com/applications/covid19/current/static/contact-tracing/pdf/ContactTracing-CryptographySpecification.pdf https://covid19-static.cdn-apple.com/applications/covid19/cu...