4 ms·
I used the Australian COVIDSafe ios app today which uses herald. The only way it can keep the app receiving Bluetooth while in the background is to request loca
by hiharryhere 6y ago
I used the Australian COVIDSafe ios app today which uses herald. The only way it can keep the app receiving Bluetooth while in the background is to request location permissions and show the blue ios bar at the top that says “COVIDSafe is using your location”.
It’s a hack. Nobody seems to spell that out in the media coverage about it. Yes it works some of the time, but only under very specific circumstances.
Someone needs to tell it straight. It doesn’t work, we should just use the platform provided apis and be done with it.
Edit: this is an excellent summary of what’s wrong with the Australian app:
https://github.com/AU-COVIDSafe/mobile-android/issues/30 https://github.com/AU-COVIDSafe/mobile-android/issues/30
- amanzi 6y agoI was so pleased to see the NZ govt integrate the native ENF from iOS and Android into our Covid app. It took longer than I would have liked, and there were some misguided investigations into alternatives (like the Bluetooth "covid card" that would dangle around people's necks on lanyards) but it's a great result for us.
- justsee 6y agoI'm in awe of the effort Jim Mussared (https://twitter.com/jim_mussared https://twitter.com/jim_mussared), Vanessa Teague (https://twitter.com/VTeagueAus https://twitter.com/VTeagueAus) and a few others have put into identifying serious issues with the COVIDSafe app (and making sensible, well-informed recommendations). That ticket is incredibly damning of the Australian Government. Highly-skilled technologists and cryptographers volunteer significant amounts of time in the hope critical digital infrastructure can be improved and everything is basically dismissed.
- merlinscholz 6y agoSadly it's the exact same situation as with the German covid app. The limitations of what can be done without the iOS/Android APIs are too high to make the app useful, as can be seen in the official documentation: https://github.com/corona-warn-app/cwa-documentation/blob/master/solution_architecture.md#limitations https://github.com/corona-warn-app/cwa-documentation/blob/ma...
- arrrg 6y agoIt’s not the exact same situation. It’s a completely different situation. These apps need to use the OS APIs, otherwise there is no hope for them. The German app uses those APIs, the Australian one does not. While there are obviously trade-offs involved with the OS APIs, it's not hopeless like this clusterfuck.
- arendtio 6y agoWhy not use the OS APIs when available and provide a hack/fallback for old Phones which don't have those APIs?
- arrrg 6y agoWhy would that be worth the effort? Support is pretty far-reaching and picking up marginal old phones isn’t that important.
- arendtio 6y agoI have no statistics at hand but the Android ecosystem is known for having a lot of old phones. Since the corona apps are not about reaching the wealthiest, but about reaching as many people as possible it might be worth the effort.
- arendtio 6y agoIn this article you can find statistics about the amount of old Android versions still in use: https://arstechnica.com/gadgets/2020/12/lets-encrypt-comes-up-with-workaround-for-abandonware-android-devices/ https://arstechnica.com/gadgets/2020/12/lets-encrypt-comes-u...
- vlowrian 6y agoThe interesting thing about the German covid app is that it is actually pretty good considering the solution space available to its creators. It features a decentralized "privacy first" architecture and utilizes the platform APIs which _should_ be the best implementation for handling the actual contact tracing. Since it is open source and uses a very common tech stack, it is easy to check and understand for as many people as possible that it is well-crafted and does not contain any obvious security vulnerabilities or backdoors. This makes it very trustworthy from an IT-persons point of view, and should in minimize the number of unsettled people who don't install the application on their handsets since they mistrust the government. Well-known public instances like the CCC (German IT-Security NGO) did a review on the app and gave it a good testimonial - even on mass media like public television. The government and the involved third-parties like Deutsche Telekom and SAP did a lot to emphasize that there is no harm to be expected from the app and the worst thing that could happen is that it doesn't work - which would be the exact same outcome as if you just didn't use it. Still, Germans' are hard to convince, once they made up their mind about something. The public image of the government, as well as Deutsche Telekom and SAP is often disconnected from their actual performance. The same people often disregard these instances' and companies' ideas, products and services with the same persistence they welcome or defend equaly debatable innovations and decisions from actors they look favorably upon, like Apple. It's sad to see that the good work of many smart people is so easily disregarded. The government and the involved companies actually listened to privacy and security experts and made a lot of right choices. That's something I'd like to see more of in the future. A little bit of appreciation could go a long way for shaping such decisions for the years to come.
- deleted 6y ago[deleted]
- polishdude20 6y agoDoes IOS normally not need location permissions to enable Bluetooth Low Energy? Because android does.