4 ms·
I think that we won't go back to normal (like pre-COVID normal) for a long time. Unfortunately there is no silver bullet yet, and we should prepare to live with
by tigroferoce 6y ago
I think that we won't go back to normal (like pre-COVID normal) for a long time. Unfortunately there is no silver bullet yet, and we should prepare to live without one for a while; in the meanwhile we will adopt a number of means to keep the virus diffusion low, and the lockdown away.
A contact tracing app (like a mask or washing hands) is among those things. If it is not privacy intrusive and it has some effectiveness, it's OK for me. I'm happy to reduce the infection rate, even if it's just a few decimal points.
I really don't understand all these discussions about something that might save lives. IMO the real discussion should be whether these app are privacy preserving enough. Are there (realistic) attacks on these apps? How can we mitigate them?
- jgraham 6y ago> I really don't understand all these discussions about something that might save lives. IMO the real discussion should be whether these app are privacy preserving enough. Are there (realistic) attacks on these apps? How can we mitigate them? The problem is there's likely a pretty direct tradeoff between preserving privacy and efficacy. So I think people whose main concern is privacy are taking the position that the apps can't work, without being clear about the fact that it really depends on what assumptions you make around enforcement. Clear disclaimer: I'm not anything like an expert here. Much of what I've written below is likely wrong or misleading and I'd welcome corrections. A simple, bad, toy model is that the fraction of infection chains you prevent is (fraction of people using the app)^2 x (fraction of transmissions detected) x (fraction of people who comply). So if your model is "app usage must be opt-in" and "it must be impossible to tell who is complying with the app's recommendations" you do indeed find that the app only detects a small fraction of transmission chains (e.g. assuming 50% of the population opts in, 80% of transmission events are detected, and there's 50% compliance rate, you only stop 10% of infection chains). But if it's mandatory to use the app, and there's a mechanism to ensure enforcement you can do much better e.g. with 80% of people using it and 95% compliance you're closer to stopping 50% of transmission chains. Of course that model is far too simple to be correct. But https://045.medsci.ox.ac.uk/files/files/report-effective-app-configurations.pdf https://045.medsci.ox.ac.uk/files/files/report-effective-app... models this in more detail. Their simulation finds that you can suppress the overall transmission in the UK with 80% of smartphone users using the app (56% of population, comparable to the most popular apps), 80% detection of transmission, and 2% dropout rate per day on a quarantine period for all individuals flagged as contacts, which lasts up to 2 weeks. I don't know what they used to come up with that number for dropout rate, but it seems highly optimistic if the information about who has registered as a contact is kept private. They also find that up to half the population might be in quarantine at any one time, which I suspect is higher than most people are anticipating for a post-lockdown period. To combat this, they propose various going through a process of optimising the algorithm based on feedback, but again, if the most-privacy-preserving approach is taken for the data collection, performing such optimisations may become difficult or even impossible, since you won't be able to followup on individuals. So, my — non-expert — conclusion at this point is that privacy-preserving digital contact tracing probably isn't going to be that useful because people either won't use it or won't follow the advice when doing so is inconvenient (e.g. because it puts their employment at risk). But digital contact tracing in general seems like it can help, if you can drive both usage and compliance high enough. So there may be a pretty direct tradeoff here between our ability to trust the health services with personal data and our ability to prevent further rounds of unchecked exponential growth of this virus. And that is worrying, because — as a British person — I'm very unexcited about giving a government that has a history of using targeted data from social media to achieve policy ends even more data to work with. But I don't know that I can construct a satisfactory argument that it's OK for people to die, or even for those that don't to suffer an additional year of economic disruption, in order to avoid the privacy implications of a system of contact-tracing-with-enforcement. And I also worry that those who would be happy to collect this data will use the launch of an initial ineffective app, and a corresponding second wave of infections, as a way to make this kind of data privacy socially unacceptable. Maybe there's an argument that by focusing on legal limits to the use of the data rather than to technical controls on its availability, we will end up in a better position in five years time, not just on the pandemic, but also on privacy.
- spuz 6y ago> 2% dropout rate per day on a quarantine period for all individuals flagged as contacts, which lasts up to 2 weeks. I don't know what they used to come up with that number for dropout rate, but it seems highly optimistic if the information about who has registered as a contact is kept private Sorry but I don't understand how keeping contact information private or public has any effect on the compliance of people to stay in quarantine? > So, my — non-expert — conclusion at this point is that privacy-preserving digital contact tracing probably isn't going to be that useful because people either won't use it or won't follow the advice when doing so is inconvenient (e.g. because it puts their employment at risk). But digital contact tracing in general seems like it can help, if you can drive both usage and compliance high enough. I don't understand why you think an app that can promise to keep people's personal data private would gain lower adoption than one that was explicitly collecting such data. Maybe I've misunderstood what you're trying to say here but it would make more sense to me that an app that can preserve privacy would have higher adoption, higher trust and therefore higher compliance levels.
- jgraham 6y ago> Sorry but I don't understand how keeping contact information private or public has any effect on the compliance of people to stay in quarantine? Because if you know who's supposed to be in quarantine you can take steps to verify that they actually are. And also because people are simply less likely to comply with rules when they know no one can tell if they're following them. > I don't understand why you think an app that can promise to keep people's personal data private would gain lower adoption than one that was explicitly collecting such data. Maybe I've misunderstood what you're trying to say here but it would make more sense to me that an app that can preserve privacy would have higher adoption, higher trust and therefore higher compliance levels. Again, because you're comparing "opt-in and private" with "opt-in and non-private". I'm comparing "opt-in and private" with "mandatory and shares user data with the health authorities" (which is different from "[opt-in|mandatory] and public" in that in the latter case any member of the public can get information about infections; I think South Korea are/were running a system with that level of sharing).