4 ms·
They should only accept infection reports that are signed with a trust chain terminating with an Apple/Google internal CA, and sign keys provided by governments
by devit 6y ago
They should only accept infection reports that are signed with a trust chain terminating with an Apple/Google internal CA, and sign keys provided by governments with their root CA.
Alternatively, the system could be configured to connect to the "infected keys server" run by the local government(s), as determined by the countries of the cell network the user connected to in the last 30 days.
- 0xBeefFed 6y agoOther protocols have suggested that uploads be governed by authorization codes provided by health-care providers. Another suggests having providers digitially sign records uploaded to the server too.