3 ms·
There is a separate Hacker News thread on an "article" that points to this PDF -- https://news.ycombinator.com/item?id=23074447 https://news.ycombinator.com/ite
by szc 6y ago
There is a separate Hacker News thread on an "article" that points to this PDF -- https://news.ycombinator.com/item?id=23074447 https://news.ycombinator.com/item?id=23074447
The summary, from my perspective is that this approach is terrible.
It builds a social graph. If you get sick, and a LOT of people are going to get Covid-19, then you reveal your social graph.
There are "technical" parts of the description that do not make sense -- why is your "phone model number" important, Covid-19 doesn't care. Why is that data being collected?
If you read closely, an "installation ID" is created and ends up being recorded. This is a unique tracking identifier. When you get sick, you reveal this ID and put a name to it -- along with a "fuzzy" geographic location.
Now that I've looked at the PDF, some of the crypto includes the "Country Code". Which is "recoverable" on the server side. The trite explanation for that is "and the country code allows for multiple countries to interact".
Why is "Country Code" in the crypto and not in the questions you ask the patient?
[edit: to remove bad linking]
I do not believe this is a good design.
Caveat, it is far, far easier to criticize than it is to create a good design.
- Silhouette 6y agoWhere in the technical document does it say anything about a "phone model number"? It explicitly describes what data is to be sent at the different stages, and I see no mention of anything like that. Where does it say anything about associating a name with the installation ID? The risk of potentially commingling the graph built from notifications with other data sets is explicitly acknowledged and discussed, and is obviously the big drawback of a centralised notification system like this. Precautions to be taken to prevent abuse are also discussed. It seems to me that most of your objections here, and in your comment on the other thread, are attacking straw men and ignoring the technical details and logical arguments presented in the document.
- Robin_Message 6y agohttps://www.ncsc.gov.uk/blog-post/security-behind-nhs-contact-tracing-app#section_4 https://www.ncsc.gov.uk/blog-post/security-behind-nhs-contac... is the closest link I can provide. In the section subtitled Here comes the crypto, second paragraph, it says "it records the model of your phone (for example ‘Apple iPhone 10,2’)." So, you're wrong about these arguments being straw men. However, the reason for doing this is reasonable enough: you need to model what the bluetooth signal strength measured by each phone actually means in terms of physical distance; and that means knowing the phone model. The real argument is not technical; it is that the UK government has proven itself repeatedly incapable of avoiding mission creep in these kind of laws and systems. My go to example "Half of councils use anti-terror laws to spy on 'bin crimes'" – https://www.telegraph.co.uk/news/uknews/3333366/Half-of-councils-use-anti-terror-laws-to-spy-on-bin-crimes.html https://www.telegraph.co.uk/news/uknews/3333366/Half-of-coun...
- Silhouette 6y agoI stand corrected. In fact, the report we were actually discussing does mention collection of the device model during initial registration, in one brief reference at the bottom of page 9. That feels deceptive, not least because it directly contradicts an earlier statement in the section about the app's operation on page 4, which states explicitly that the extra data collected is currently limited to the first part of a postcode and some clinical questions about symptoms. To be fair, that brief reference on page 9 does also answer szc's question about why that data is collected, though: as suggested, it's used to normalise the RSSI values to determine realistic distances. I still haven't seen anything in that document about trying to associate a name with the tracking ID or otherwise commingling data sets, so those still look like straw men as far as that document is concerned. Of course with other information that's been coming out over the past few days, that app is looking worse and worse all the time. For me personally, any reduction in scepticism about the app when the technical details were published has now passed and my usual caution about anything that might represent a threat to privacy is now back in full effect.
- djaychela 6y ago>There are "technical" parts of the description that do not make sense -- why is your "phone model number" important, Covid-19 doesn't care. Why is that data being collected? Off the cuff, I would think it would be useful to give some idea of the Bluetooth range of the device being used? There may be performance changes or mitigations needed for whatever it is they're planning to allow this to work?