3 ms·
As an Australian who has privacy concerns their government's COVIDSafe app (see https://github.com/vteague/contactTracing https://github.com/vteague/contactTrac
by bjz_ 6y ago
As an Australian who has privacy concerns their government's COVIDSafe app (see https://github.com/vteague/contactTracing https://github.com/vteague/contactTracing), and hence not installing it, I'm really thankful that Apple and Google are pushing this model of contact tracing. We still don't know if digital contact tracing is effective in practice, but it's still important to try, but we can do this in a way that avoids giving governments with worrying authoritarian tendencies another tool.
- valtism 6y agoCOVIDSafe will be using these new APIs.
- afro88 6y agoHave you got a link / source for this? Genuinely interested, not being a dick.
- sk0g 6y agoFrom what I heard it works fine on Android, but on iOS it works ok... as long as you have the app running in the foreground, and your phone unlocked, while out and about. The only way to fix that would be to use this new API on iOS.
- sk0g 6y agoSince people seem to be downvoting without commenting: https://www.gizmodo.com.au/2020/05/covidsafe-issues-ios-iphone-explained/ https://www.gizmodo.com.au/2020/05/covidsafe-issues-ios-ipho...
- Springtime 6y agoI wasn't one who downvoted but parent post was asking for source on whether this app is going to utilize the new APIs, specifically. According to your subsequent link, near the bottom, currently it's unclear: "The Government will work with Google and Apple to investigate whether the new functionality announced by Google and Apple partnership is beneficial for the app performance"
- Juno321 6y agoThe COVID Safe app was already released (although not fully functional on the server side yet) but the Google and Apple APIs are not available yet, so doesn't that mean that it isn't using the Google and Apple APIs? At least currently, any way. According to the Australian COVIDSafe app's privacy policy, when you register for the app, after you successfully enter a PIN sent by SMS, it transmits the following info to the Australian authorities: your mobile phone number, the name you enter, the age range you enter, the postcode you enter. The reasons for each are explained in the policy. This data is stored in the cloud. I don't see why the registration info (I'm just talking about the registration info, not the Blutooth-related data) can't simply be entered later, or stored locally on the device and not uploaded until, when and if, the user volunteers to share their registration info with health authorities, e.g. as a result of being notified that someone that was near them has tested positive for COVID-19. If this info wasn't transmitted as part of setting up the app, I expect the uptake of the Australian COVIDSafe app would be significantly higher. I am also still waiting for Australia to publish the source code for their COVIDSafe app...
- crushthecurve 6y agoAnother consideration that seems to have been obscured by the debate on privacy and the narrow focus on the particular client implementation of the app is the significant problem of false positives and negatives. A lot of voices have spoken out about this issue overseas (particularly in the US) while many local tech voices have skipped considering this at all. See: * Previous FTC CTO / Obama Whitehouse senior adviser: https://twitter.com/ashk4n/status/1248659875669798912 https://twitter.com/ashk4n/status/1248659875669798912 * Brookings Institute article: https://www.brookings.edu/techstream/inaccurate-and-insecure-why-contact-tracing-apps-could-be-a-disaster/ https://www.brookings.edu/techstream/inaccurate-and-insecure... * Margolis Center for Health Policy at Duke University (pdf report): https://healthpolicy.duke.edu/sites/default/files/atoms/files/covid-19_surveillance_roadmap_final.pdf https://healthpolicy.duke.edu/sites/default/files/atoms/file... * Bruce Schneier: https://www.schneier.com/blog/archives/2020/05/me_on_covad-19_.html https://www.schneier.com/blog/archives/2020/05/me_on_covad-1...
- orasis 6y agoWe need to be driving test numbers up until only 3-5% are showing positive in order to be confident about low prevalence in an area. I don't see a problem with false positives encouraging asymptomatic people to get tested - it's as good of a sub-population as any.
- crushthecurve 6y agoThe project lead of Singapore's TraceTogether initiative goes into detail about the problems with an automated system, and why a human-in-the-loop is ideally required to evaluate the type of contact and make a determination. A determination around being a close contact results in 14-day isolation regardless of symptoms, presumably because you may initially test negative before moving into an infectious and asymptomatic or symptomatic phase. https://blog.gds-gov.tech/automated-contact-tracing-is-not-a-coronavirus-panacea-57fb3ce61d98 https://blog.gds-gov.tech/automated-contact-tracing-is-not-a...
- crushthecurve 6y ago
- coliveira 6y agoHaving Google/Apple develop a tracking technology is the same as the US government having it. If you don't believe, read again what Snowden revealed several years ago.
- uluyol 6y agoWhat? I don't think this is accurate. From what I recall, the US was/is spying on the major tech companies and would regularly demand data and place gag orders on those companies. Neither actions are willful forms of data transfer. The first is actually an eternal game of cat and mouse. NSA finds a leak for some data, Google fixes it, new leak, etc. The second is targeted handover of data, and only affects a few individuals. Equating these with the US government having full access to everyone's data is misleading. If you think otherwise, please provide more detail.
- TheSpiceIsLife 6y ago> is spying on the major tech companies and would regularly demand data and place gag orders on those companies. So you agree. > Neither actions are willful forms of data transfer. What’s that got to do with it? > Equating these with the US government having full access to everyone's data is misleading. If the data exists, the only prudent approach is to assume state-level actors, at least, can get access to it.
- tastroder 6y agoThe discussion is beyond "if the data exists", it will be gathered and some people seem to prefer yelling at clouds instead of looking at the technical implementation. Even nation state actors will have a harder time gathering data that only exists locally on a bunch of smartphones, separate from geolocation as proposed here, versus a centralised database lacking comprehensive oversight. The rest is pretty irrelevant, we're talking about data collection using phones that already have an OS from both of these vendors. "But Snowden" is really no argument anybody in these discussions will listen to (and I'm not convinced they should if it's used in a way to imply that you shouldn't use the internet for anything). If you have a problem with data collection for contact tracing please be specific why and optimally provide what you feel would be a better alternative.
- rstuart4133 6y agoThere are two sides to trusting the covid-19 app. One is the technical side those people are commenting on. Technical deficiencies can be fixed, and more to the point will be fixed if you just keep shining some light on them as they are doing. The other side is trusting the government to keep it's promises. During this covid-19 crisis I do trust them, but in the longer term their record of keeping promises has been less than stellar. Frankly, keeping this app or any app of theirs installed over a few years on the basis them promising not to missuse the data is downright foolish given their past history. Such promises tend to become null and void at the next election. But right now we have no choice - it's either take them at their word, or don't install the app. Yes, we can do what the gang of four above have done and de-compile it, but that takes a huge amount of effort that has to be repeated every new release. That effort isn't going to continue. If it doesn't continue the light doesn't continue to shine on it's technical deficiencies, and so they won't be fixed. But - that can change with a few simple and cheap changes to the way the government does things. All they have to do is release the source to a public repository before they release the binary and have a reproducible build. Do that lots of things become much easier. Checking what the commented source does as opposed decompiled output is much easier, checking just the differences in source between one version and the next is much, much easier than checking the entire thing, using reproducible build to allow you to check the source rather than decompiled output is very much easier. Do that, and the light on the technical deficiencies will stay on forever. Implementing those inexpensive and straightforward things has anther wonderful emergent properties aside from the technical deficiencies being fixed: you suddenly don't have to trust the government, you can trust the code instead. But no one seems to focus on changes to the overall process. Instead it's essentially nit picking on how the app does things today. It's an unfortunate focus.