22 ms·
Massachusetts health notifications app installed without users’ knowledge
- sohei 5y agoSomeone should archive a copy for reversing. One comment says it has "permission to utilize all device functions".
- deleted 5y ago[deleted]
- murderfs 5y agoOne comment also says that it's a Communist conspiracy. Over in reality, though, the only permissions it has are to use the internet and bluetooth: https://hastebin.com/yexoyuluzu.xml https://hastebin.com/yexoyuluzu.xml
- m463 5y agoI would imagine you can get location by getting in range of those edison beacons google is pushing.
- ganzuul 5y agoThey bundled bluetooth and location permissions not long ago. Claimed their users were too ill-informed to know the difference.
- delusional 5y agoAre you sure about that? Previously they required the location permission to scan for nearby bluetooth devices (because of the obvious implications). Recenly they've split that into it's own separate permission. It that what you're thinking of?
- ganzuul 5y agoYes, that is it. I did notice it's not the case anymore, but do you know if they admitted error with the change, or gave any kind of motivation? I think that in this context, this previous issue is relevant.
- corin_ 5y agoWere you just guessing their motivation before, when you wrote "Claimed their users were too ill-informed to know the difference."?
- ganzuul 5y agoNot guessing no, but I distilled what they said unfavorably. My understanding was that they thought they could not communicate to their customers the complexity of how bluetooth can be used to infer information about location. But somehow this communications barrier meant that they thought it was better to expose GPS data too? - Hence why I feel justified treating them unfavorably in this case. It was just an absurd way to reason that they presented. It should have been obvious that it's better to protect as much data as possible when the user often has no choice but to enable bluetooth.
- delusional 5y agoIf it works like all the other covid tracking apps it just records randomized bluetooth beacons emitted by all the phones near you. You can get location in a ton of ways, but I doubt the OS will let you without the proper permission.
- kuschku 5y agoIt doesn’t. All it can do is request Google Play Services to enable distributed covid exposure notifications, which in turn means the app itself doesn’t even get bluetooth beacon data. Your calculator app has more tracking than this.
- marderfarker2 5y agoYou sure about that? You can easily see the permissions granted on the app page. This app has access to: Other view network connections pair with Bluetooth devices full network access run at startup prevent device from sleeping
- gostsamo 5y agoHere is an official page for the same app. Interesting what is the whole story. https://www.mass.gov/info-details/enable-massnotify-on-your-smartphone https://www.mass.gov/info-details/enable-massnotify-on-your-...
- Animats 5y agoWhy do this at this late date? A year ago it would have been useful. Now, 59% of Massachusetts's population has been fully vaccinated. About 70% have at least one shot. A bit more pushing and they'll hit 80%, which seems to be about where the epidemic dies out for lack of new carriers.
- cromka 5y agoOut of fear for a new, dangerous strain, perhaps?
- gostsamo 5y agoNo idea, I'm not from there. Some interesting facts: 1. this is not active unless activated. 2. Apple too. 3. Not communicated to the users, especially, that a os level update is served as an app install.
- csomar 5y agoBecause that’s when the developers finally shipped?
- sbassi 5y agofunny thing is that California also had something like this but was disabled during this week.
- ehsankia 5y agoIsn't contact tracing actually more useful when the number of cases are reasonably low?
- Animats 5y ago
- skunkworker 5y agoIt would be one thing to get a push notification asking if you wanted to install the app. But pushing this out silently is going to far. It’s the scarier version of the free U2 album.
- bjornlouser 5y ago“… and I still haven’t found what I’m looking for on your phone …”
- kuschku 5y agoThe app is just a fork of the German Corona-Warn-App [1][2]. From what I can tell only the UI was modified, the codebase seems to be still the same. Honestly, pushing the app to users isn’t anything to worry about – and in fact something I’d have loved to see other countries do as well. ________ [1] https://www.coronawarn.app/en/ https://www.coronawarn.app/en/ [2] https://github.com/corona-warn-app https://github.com/corona-warn-app
- boredpudding 5y agoThe worrying part is that it was installed without consent.
- kuschku 5y agoThere’s nothing worrying about that. You get tons of apps installed without consent (including whatever spam your network provider pushes on you). This app can actually save lives without sacrificing any privacy, pushing it to users is something that has no drawbacks. The largest trouble for the German version of the app was that not enough people installed it. Choosing to install it automatically isn’t something nefarious under these circumstances.
- sildur 5y ago> There’s nothing worrying about that. You get tons of apps installed without consent (including whatever spam your network provider pushes on you). That is different. They are pre-installed and I can list them and disable them. They do not install suddenly by themselves months after buying the device. If they did so, there would be an outrage. > This app can actually save lives without sacrificing any privacy, pushing it to users is something that has no drawbacks. Yeah, "for our own good". Next time it would be an app that sends an alarm when an excon is near you. And next time it would be an app that sends an alarm when someone who shows dangerous opinions (ie. against government) is near you. No thanks, please unsubscribe me of this Chinese dystopia.
- 5y ago
- Animats 5y ago"...gives itself full permission to utilize all device functions" Is that right?
- studentrob 5y agoWhere does it say that?
- wartijn_ 5y agoIn one of the reviews[0] The permission modal says this though: - view network connections - pair with Bluetooth devices - full network access - run at startup - prevent device from sleeping [0]https://play.google.com/store/apps/details?id=gov.ma.covid19.exposurenotifications.v3&reviewId=gp%3AAOqpTOFDkXDUvl6sov4J_8VKhzNq_nWcyHBntwX49-x2M6FqxSjgGkUC8Sw9Pn_jgC3S1QnVoclGa4or-9moaQ https://play.google.com/store/apps/details?id=gov.ma.covid19...
- sildur 5y agoIt has 167 reviews, but they seem to be hidden.
- 0xy 5y agoGovernments around the world have already started to pilfer data collected from these apps, as was predictable. [1] [1] https://www.9news.com.au/national/wa-police-stand-by-decision-to-use-safewa-contact-tracing-app-in-nick-martin-murder-investigation/9250eb64-b523-46ea-810d-bf09521f1e1f https://www.9news.com.au/national/wa-police-stand-by-decisio...
- cromulent 5y agoThat's a totally different category of app though right - the ones using the Apple-Google framework don't share any PII.
- thu2111 5y agoThat's not a distinction most will recognize, partly because believing this is true requires you to trust Google wouldn't share sensitive data with the authorities. They just proved they will happily push code to your device without notifying you at all, if they think it's for the greater good.
- deleted 5y ago[deleted]
- rvdmei 5y agoJust the thought of Google being able to do something like this scares the $&@*#% out of me. How on earth can you trust a company that does something like this?
- malka 5y ago... you trust Google ?
- ahofmann 5y agoEveryone running android play services on their phone has to trust Google, right?
- mrweasel 5y agoMany might not have a choice. If you need a SmartPhone and can’t afford an iPhone, you’re out of options. Most of the apps people actually need has to be installed via the Play Store. You basically get a (more) privacy focus OS from a luxury brand or you get your OS from an advertising company.
- marosgrego 5y agoThey can run an ungoogled ROM, like LineageOS.
- malka 5y agoFor one, I don't. But since having a smartphone is mandatory, I have one.
- perryizgr8 5y agoI don't, but I have no other alternative that feels better to me. 1. Buy a standard android but spend ages trying to de-google it. 2. Buy an iphone, but then I just have to trust another trillion $ company, and pay much more too. 3. Live my life without a phone. I choose 1 because that seems the least worse option right now.
- 5y ago
- simpss 5y agoI think the real question is what mechanism allows them to push a random app to some phones? google play services is actively listening for remote installation requests? that's essentially a remote-code-execution backdoor to all android phones?
- ahofmann 5y agoYou can install apps from your browser on the PC since years. I think this also works on apple?
- contriban 5y agoNot exactly. On the Android store you can choose exactly which device to install an application on. For Apple as far as I know the most you can do is buy the app on desktop and, if the device is configured that way, it will receive the new app. This means it’s limited to new purchases and by the device’s settings.
- ahofmann 5y agoOk, but my point was that on Android and iOS it is possible to install apps without touching your phone. This qualifies as remote code execution. You need your credentials for doing this, but google and Apple apparently don't need them.
- villgax 5y agoSimilar to UIDAI contact being added in India with consent
- he0001 5y agoHow is this different from any update program, like windows update or Ubuntu update, installing software/upgrades whenever you get updates?
- ohazi 5y ago"Automatically update the programs I currently have installed when new versions are available, with a flag to disable this behavior" vs. "Arbitrarily install new programs from scratch via a separate mechanism that doesn't respect the 'disable automatic updates' flag"
- MiddleEndian 5y agoWindows Update pushes all sorts of junk. At some point, Nadella must have realized, "Shit, Windows users put up with years of adware on their computers in the 90s and 00s. We're leaving money on the table by not taking advantage of this!" Ex: In 2019, Microsoft added a shortcut Win+Ctrl+Alt+Shift that when pressed, brings up an advertisement to buy MS Office, which I have no use for, and you need to edit the registry to disable the shortcut. I already gave MS thousands of dollars for the laptop, you'd think they could leave me alone if they want me to buy another one. Although at least with Windows, you can remove most of the damage yourself, which is more than can be said for Android. Quite honestly why does the Computer Fraud and Abuse Act exist if manufacturers remain free to abuse your machines at will?
- arpstick 5y agothe difference is that there is a fundamentally different power dynamic, you can just not do business with microsoft, you can't do that with the government.
- ElViajero 5y agoIt is obvious that we need better legislation to deal with all the new possibilities that technologies have opened. The installation of this app, even done with good intent, open a lot of questions on what should be possible or not to be done by government and corporations. When you get a device with pre-installed, uninstallable, or auto-installed apps. What are the rules? > "By enabling this service, you can be quickly notified if you’ve likely been exposed to the virus by another MassNotify user, allowing you to reduce risk to your loved ones, seek medical attention, and slow the spread in your community." In this case it seems that the same goal could have been better achieved by SMS that do not depend on the brand of your phone. The dependency on proprietary app stores and OSs seems a risk for the continuation of a free and reliable communications. The only thing that is impossible to achieve without an app is to allow the user to select contacts to whom send a notification. Corporations like Google, and Apple know the list of all your contacts. So, it seems that the intention of the app is to reduce friction and send notifications as easy and effortlessly as possible to avoid that procrastination causes people to delay the warning. But, instead of the silent install the government could have spend money in advertisement campaigns to assure a correct amount of installations. It costs money, but, people pay taxes so the government can engage on this type of initiative at a scale. This could have been a very good alternative, even if it means increasing the budged. Medical emergencies are worth the investing.
- dagi3d 5y ago> In this case it seems that the same goal could have been better achieved by SMS that do not depend on the brand of your phone. The dependency on proprietary app stores and OSs seems a risk for the continuation of a free and reliable communications. While installing an app without users consent can be as questionable as you want, the point about these apps are not the notifications itself but about the contact tracing which is achieved through the bluetooth functionality. also, sending sms messages has other privacy concerns that the tracing apps have tried to avoid from the very beginning. having a person phone number can lead to eventually identify that person while that internal trace id it might use, won't.
- esyir 5y ago
- cblconfederate 5y agoGoogle and apple install tons of software basically without consent (os updates) , so an app being pushed like that is not surprising. It is worrying however that tech people dont seem to realize how great their tools are for totalitarian states , which push apps and spying much worse than this to their subjects. We really need to talk about users owning their devices and their software rather than leasing them. There is no device that allows users to control what it does , that's scary
- viktorcode 5y agoYou are explicitly allowing to install updates in phone's settings. It is made painfully clear. The question here is about what mechanism Google used to install an app, can it be disabled, and what other kind of apps Google is capable of installing silently on the devices?
- cblconfederate 5y agoThe mechanism is google's so that point is moot. There should be a physical switch for updates just like some cameras have physical covers
- beprogrammed 5y agoThis is just software updating software, so a switch would just be a token gesture, unless it wasn't, in which case you need to have the software be loaded from some ROM and the ROM only writable when the switch was activated, in which case that would be a fantastic device.
- cblconfederate 5y agoall diskettes used to have read-only locks
- beprogrammed 5y agoThat's a good point. But it also brings up the false sense of security, a floppy drive could just choose to ignore the switch and write anyways, just as the phone could secretly write the firmware.
- rasengan0 5y agoInnovative, contact tracing? Just google it. My guess is all the user reviews with 'real names' are from Massachusetts? ¯\_(ツ)_/¯
- bitcoinGod88 5y agoWho cares... Google could just as easily slide spyware into your phone. This is an openly visible app. What's so egregious about this
- deleted 5y ago[deleted]
- riekus 5y agoApparently it is not so open and visible, that is the problem.
- remuskaos 5y agoI wonder if this is the same functionality some carriers use to install their management app on your phone. For example, I've recently bought a second hand Samsung tablet. I've reset it to factory settings and put in a Vodafone SIM. The next time I looked though the installed apps I saw some Vodafone Services app that I didn't install. It couldn't be removed either. So clearly, either Google with play services or the carrier over the baseband modem can install apps without user consent. Is there any way this can be avoided? Do open ROMs like carbonROM or LineageOS protect against this?
- pineapple128 5y agoLineageOS without Google Play services (and if you want with microG) would not install anything from Google automaticly. Other comments mention embedded Java in SIM cards, that's possible, but I'm not sure.
- kalleboo 5y ago> The next time I looked though the installed apps I saw some Vodafone Services app that I didn't install. It couldn't be removed either Are you sure that's an actual Android App and not just the SIM Application Toolkit[0]? On iOS these show up under the Carrier menu in Settings but on Android it shows them as if they were an app, even though it's something running on your SIM card (they are backwards compatible and show up way back on old feature phones). https://en.wikipedia.org/wiki/SIM_Application_Toolkit https://en.wikipedia.org/wiki/SIM_Application_Toolkit
- remuskaos 5y agoThat's a very good point! I removed the SIM and the app was gone again. So I guess you're right, it may be installed on the SIM and not actually the device.
- 0x0nyandesu 5y agoWell well well. Looks like all my fears have been fully realized. Please tell me more about how unrootable devices are for my own good.
- fragileone 5y agoBootloader unlockable is sufficient to replace the OS. Rooting is likely to die in the near future now that Google hired the Magisk dev.
- 0x0nyandesu 5y agoIt's an open source project. Someone else will pick up the baton.
- midrus 5y agoGoogle is fucking evil nowadays. The "Don't be evil" days are far gone. https://en.wikipedia.org/wiki/Don%27t_be_evil https://en.wikipedia.org/wiki/Don%27t_be_evil
- ehsankia 5y agoCalling installing a contact tracing app (which really is just a small wrapper over the existing Exposure Notification API) as "fucking evil" seems like bit over the top...
- digitalsin 5y agoCan you point me to the github repo so I can review the wrapper code? 'cuz I trust the government since they are so sane these days.
- machinerychorus 5y agoHere is the platform that the app is built from: https://github.com/google/exposure-notifications-android https://github.com/google/exposure-notifications-android And here is the code for the two services it talks to: https://github.com/google/exposure-notifications-verification-server https://github.com/google/exposure-notifications-verificatio... https://github.com/google/exposure-notifications-server https://github.com/google/exposure-notifications-server
- riekus 5y agoI disagree, you paid money for you device, you own it. Whatever they want pushed should come with a notification.
- triska 5y agoThis is very inconsiderate. For example, depending on your cell phone plan, data transfer may incur high costs, especially when roaming etc. Therefore, owners of cell phones may be interested in limiting it to the absolute minimum. As I see it, this consideration by itself already should have prevented this automatic installation.
- kuschku 5y agoAutomatic app installation and updates will only trigger when charging, not in active use for >90 minutes, and on a wifi network that's not set as metered
- deleted 5y ago[deleted]
- machinerychorus 5y agothe app doesn't use any data, just a bluetooth connection for exchanging keys with nearby devices, and wifi for downloading the keys published by people who tested positive
- baybal2 5y agoFYI: Google can remotely install/delete/alter any app on your phone without your notice if you have GAPPS installed, and they removed the option to disable it back in 2.* days. This is very rampant in India. Operators keep pushing crapware like Linkedin app, clash of kings, etc for money from app vendors.
- MiddleEndian 5y agoIt honestly baffles me that there are Android enthusiasts. My phone runs Android but it's not a good operating system.
- NeoVeles 5y agoI think it baffles me that there is enthusiasts that will defend either side as an absolute. I mean I get it, people tend to fall into tribal thinking. But sometime you have to take a step back and remember that these are just gadgets. Personally, I run Android. It is an OS. It is ok. Not great not bad. I don't really care what other people run, I just hope it doesn't treat them to poorly.
- MiddleEndian 5y agoI certainly don't defend iOS and am unlikely to ever buy an iPhone. Overall I like my phone better than my previous phones, but Android is certainly designed so that manufacturers and providers can irritate their users on a whim leaving them with little recourse.
- meibo 5y agoDon't buy a shitty phone and expect to get a good experience. Avoiding big brands like Samsung usually helps.
- MiddleEndian 5y agoI like my phone, the Palm Phone, overall. Definitely the least annoying phone I've ever had, even less bothersome than my Windows Phones or flip phones of the past. I just find Android to have somewhat of a user-hostile design.
- arpstick 5y agoa government installing a software without notice or consent onto their population's devices is not something a healthy functioning democracy does, it's what a psychotic paranoid despot does. if the Mass Gov truly wants to minimize harm this is the opposite of what needs to be done. all this will do is drive conspiracy theories and deepen a very legitimate mistrust in the institutions that plague the USA (which helped give rise to people like donald trump)
- Barrin92 5y ago>"if the Mass Gov truly wants to minimize harm this is the opposite of what needs to be done." where is the actual evidence for this? Both Taiwan and South Korea deployed massive, digital tracking efforts to respond to covid often at the cell-provider/ infrastructure level so the entire population was covered whether they wanted to or not. Nothing about this was despotic or paranoid, it was simply the correct, swift, and strong response to the situation at hand. Until half of Americans have voluntarily installed a tracing app on their phone, if they even know how to do it, we're five years into the pandemic. Defaults matter. There's a nice example from organ donations in a study conducted by Johnson & Goldstein[1]. When you ask people to opt-in, even if you send everyone a letter personally, only 30% do. When you switch to opt-out, 90% stay in without any resources expended. I would like to think the first obligation of a healthy democracy is to the health of her people. What gives rise to despots is governments failing exactly at that, providng essential functions, being harmstrung by excessive checks and mistrust. [1]http://www.dangoldstein.com/papers/DefaultsScience.pdf http://www.dangoldstein.com/papers/DefaultsScience.pdf
- thu2111 5y agoYou are merely arguing that it was worth it because you agree with the goal, not that it wasn't despotic or paranoid.
- Barrin92 5y agoit was neither desponic nor paranoid. Paranoia is an irrational or delusional bout of fear. Thinking the cleaning crew in front of your house is secret agents trying to kidnap you is paranoia, taking measures against a pandemic is not, because the pandemic is real and deadly. In the same vein, despotism is the tyrannical and arbitrary exercise of power, not merely the exercise of power towards legitimate ends. In fact if anyone is paranoid then it is the public every time the issue of governance and technology converge, because in particular in the US there exists a phobia both to technology as well as government.
- pharrington 5y agoFrom what I've read (I don't live in Massachusetts), the app is installed via the auto update channel, but it explicitly asks permission to activate. If you think this is bad, the commercial apps that have been auto-installing for years, without notifying the user, should have you throwing a conniption.
- arpstick 5y agoI live in MA, i had no prompt asking me to activate this at all. it was silently installed without any notice. this isn't an auto update, this was an unsolicited app install.
- dsr_ 5y agoSame here.
- tyingq 5y agoI also see lots of comments that it doesn't create a visible icon, that you have to go to the applications list to see it. That seems shady.
- pharrington 5y agomea culpa, https://news.ycombinator.com/item?id=27560468 https://news.ycombinator.com/item?id=27560468
- dalbasal 5y agoI think some of he "consent" norms we are building up are a double edged sword. Ooh, its good to reinforce the idea that users need freedom. OTOH, "consent" isn't really an informed consent. It's pages of TCs, UI antipatterns and take-it-or-leave-it choices. In practice, I don't think consent is genuinely increasing user sovereignty. It's more about disclosure than consent, currently. Human centIpad stuff.
- foxrider 5y agoThis is exactly why I hate all the "app stores". The idea that anyone can just decide to install an app on my phone prevents me from using anything touched by google.
- TomOwens 5y agoMost of the comments on that app as well as here are probably wrong. I'd suspect that everyone who had the app "installed without their permission" opted into the Android COVID-19 Exposure Notification program. This was deployed by Google as part of an update to Google Play Services. When you go to your phone's settings with this update, there's an option to enable COVID-19 Exposure Notifications. When you turn it on, it prompts you for your location and will download your region's app that uses your phone's new capabilities to connect to the appropriate health authorities. Massachusetts just opted into this program in the last couple of weeks. I'm honestly not sure why they did it so late - this would have been helpful earlier. Apple iPhones also have this capability, including interoperability with Android phones, and iPhone users in Massachusetts are also able to turn on this setting. Now, if someone can actually prove that they didn't opt into the COVID-19 Exposure Notifications, then I'd be concerned. But my guess is they opted in when it came out, but there was no app for their region, so nothing was downloaded and the feature did nothing. Then, Massachusetts rolled out the app now and lots of people who configured their phones earlier in the pandemic got a new app. They granted permission for it, perhaps months ago.
- studentrob 5y agoWhen you opt-in, does it notify you of all the permissions the app will require? - view network connections - pair with Bluetooth devices - full network access - run at startup - prevent device from sleeping
- dstaley 5y agoVirtually every non-trivial Android application has these permissions, none of which are even important enough for the system to prompt you for permission. The only interesting one is "pair with Bluetooth devices" which is how the Exposure Notifications system works.
- studentrob 5y agoUsers expect to see the requested permissions.
- dstaley 5y agoI think it's far more interesting to think about what went wrong so that the MassNotify app actually displays as installed on these devices. All of the Android COVID exposure apps for US states are simply the Google Play Services COVID Exposure Notifications code with an icon, splash screen, and possibly some text. The idea is that you enable the setting by installing the app, but in this case it seems that rolling out the setting itself has caused the app to appear as installed. I wonder if there was a misconfiguration on the part of the MassNotify developer, which caused this. The push to devices enabling the setting is likely automatic on Google's end, so I doubt a human did a check to ensure the MassNotify app behaved as expected. At the end of the day, there likely wasn't actually anything more than a package ID installed on user devices. It didn't opt anyone into exposure notifications, and it most likely didn't include any executable code.
- optymizer 5y agoThis is not true. An app _was_ actually installed on my device. The device isn't rooted, but I have Developer Options enabled and I can see that the folder /data/data/gov.ma.covid19.exposurenotifications.v3 exists. Logcat also shows that this isn't a Google Play misconfiguration where it would show details about an application as if it were installed. Executable code was installed and run on my phone. 06-19 10:55:21.977 1192 1609 I ActivityManager: Start proc 10474:gov.ma.covid19.exposurenotifications.v3/u0a418 for service {gov.ma.covid19.exposurenotifications.v3/androidx.work.impl.background.systemjob.SystemJobService} 06-19 10:55:22.032 10474 10474 D LoadedApk: LoadedApk::makeApplication() appContext=android.app.ContextImpl@bfaf057 appContext.mOpPackageName=gov.ma.covid19.exposurenotifications.v3 appContext.mBasePackageName=gov.ma.covid19.exposurenotifications.v3 appContext.mPackageInfo=android.app.LoadedApk@1f755d6
- deleted 5y ago[deleted]
- Black101 5y agoIs it possible to remove Google's remote administrator access on Android devices?
- intellirogue 5y agoIt's part of the Play Store. You'd need to install a non-Google build of Android (e.g. LineageOS) which doesn't include Play Store/Services, which also means you can't download apps etc from there.
- marosgrego 5y agoYou can use a 3rd party client like Aurora store to download apps from Google Play. However, it's better to get the from an alternative source like F-Droid if possible.
- NiceWayToDoIT 5y agoHow about just wearing a mask ?!
- gorgoiler 5y agoPeople are scared of the privacy implications of tracking. They should be, but they don’t have to be. If I had any ability to execute ideas I would have made the app using raffle / cloakroom tickets as the metaphor. Every time your phone sees another phone, they get one of your tickets and you get one of theirs. Then whenever someone gets symptoms, if their ticket book was pink then the government announces “anyone with a pink ticket, stay inside for a week”. (With real ticket books, there aren’t enough unique colours for everyone but the tickets do have unique serial numbers.) https://www.feteandpartygameshire.co.uk/wp-content/uploads/2017/08/Raffle-Ticket-Book.jpg https://www.feteandpartygameshire.co.uk/wp-content/uploads/2...
- danuker 5y ago> Every time your phone sees another phone, they get one of your tickets and you get one of theirs. This is exactly how the German app works. It broadcasts anonymous Bluetooth beacons, and logs whatever beacons it saw. If you are infected, your app sends to the server "I saw these beacons then found out I'm infected", and the server updates its live infection list. The one in Play Store uses Google Exposure Notification Framework of course, but a de-Googled version is on F-Droid: https://f-droid.org/packages/de.corona.tracing/ https://f-droid.org/packages/de.corona.tracing/
- known 5y ago“The government solution to a problem is usually as bad as the problem” --Milton Friedman (b. 1912)
- sokoloff 5y agoMass Notify info: https://www.mass.gov/info-details/enable-massnotify-on-your-smartphone https://www.mass.gov/info-details/enable-massnotify-on-your-... Posting the link for its relevancy only.
- streamofdigits 5y agoThere should be a theorem that says a society will either drift into trustless oppressive state that imposes a functioning order by force or evolves a dense graph of trust relations where changes improving collective welfare propagate without friction.
- Metacelsus 5y agoI'm an Android user in MA and I don't seem to have this app installed.
- combolo 5y agoYou need to go the Google Play store page for the app to see if it's installed: https://play.google.com/store/apps/details?id=gov.ma.covid19.exposurenotifications.v3&showAllReviews=true https://play.google.com/store/apps/details?id=gov.ma.covid19... The app will NOT show up on your App drawer.
- piggy79 5y agoIt is done silently using "INSTALL_ASSET" and "REMOVE_ASSET" directives. Both are implemented in Google Play Services. No user interaction ever needed.
- stevewodil 5y agoInteresting. I started getting the COVID exposure opt-in message a few days ago. I've declined both times it's popped up (it's already too late to be contact tracing, no need). This app is already installed on my phone apparently despite declining to opt-in.
- maxerickson 5y agoI don't think it will happen or that we particularly need to do it, but at this point, contact tracing (I'm talking about in the US) would be cheap and effective. Especially if it traced back to likely exposure events.
- stevewodil 5y agoI'm already vaccinated and so is everyone I'm around. It's something I would have enabled maybe 10 months ago but not even worth it at this point
- maxerickson 5y agoYeah, vaccinated people wouldn't benefit much. Other people would though.
- oftenwrong 5y agoThis app is silently installed even for users enrolled in Google's Advanced Protection Program. https://landing.google.com/advancedprotection/ https://landing.google.com/advancedprotection/
- deleted 5y ago[deleted]
- diveanon 5y agoThis should be mentioned to the owner of these phones. Google.
- xlaacid 5y agoThe problem is that you dont opt in to COVID-19 exposure notifications. It was enable by default. I disabled it as soon as I found it.I just checked for the app and its not installed on my phone.
- xlaacid 5y agoupdate: just checked my wife's phone and there was a notification asking if you want to be part of the exposure notification. Clicked NO and checked the apps- the app was already installed even though I said no. Epic fail for MA gov.
- combolo 5y agoSame here. The app was silently installed on my phone even with the Google Settings for COVID notification still showing it as being turned off.
- digitalsin 5y agoAnd to think I was upset that I couldn't uninstall Facebook from my Galaxy S10 (only 'disable it', for whatever that's worth) and got rid of that phone yesterday. I mean, I paid $700 or so for an unlocked phone and I can't uninstall the biggest piece of spyware in modern history. This kind of stuff is out of control and consumers need to seriously stand up to this in court.
- dozog 5y agoI'm an MA resident and feel a bit deceived that I agreed to the exposure notification feature last night. It was late when I received the push notification, and I agreed to enable the feature not fully realizing a new app would install (which was me not thinking clearly, but I was literally lying in bed trying to sleep). Now I don't know how to uninstall the app... I can disable exposure notifications, but it appears to be a built-in app I can only see in settings, not on the home screen. Am I missing something? The language is confusing too: "Your iPhone is not collecting or sharing exposure notification data with anyone." It is not collecting data with anyone? Or it's not collecting data at all? Either way you parse that sentence makes no sense to me. This app is also not listed under the Location Services app list, which seems strange... How else would this app work other than by tracking your location? Anybody know how to uninstall this easily?
- NoImmatureAdHom 5y agoFellow humans, there are alternatives! Your neck need not be under FAANG's boot! You don't even need to give up any functionality: CalyxOS: https://calyxos.org/ https://calyxos.org/ Privacy-respecting Android distribution that replaces Google spyware with MicroG, so you can have your cake and eat it too. Most everything will work as you're used to, but it does still talk to Google to make that happen. GrapheneOS: https://grapheneos.org/ https://grapheneos.org/ Very much like Calyx, but extra-hardened and with no MicroG. No involvement with Google at all. LineageOS: https://lineageos.org/ https://lineageos.org/ The successor to CyanogenMod, will work with many different phones. More privacy and control than stock Android. There are also many others: Sailfish, Replicant, e Hardware-wise: CalyxOS and GrapheneOS run best on Pixel 3, 3a, 3XL, 4, 4a, 4XL, 5. The path of least resistance is to get one of these phones and run CalyxOS (if there is an app you need to use that needs Google services like Firebase Cloud Messaging...note that many that can use FCM will run fine without), otherwise run GrapheneOS. You can also buy a Librem 5 https://puri.sm/products/librem-5/ https://puri.sm/products/librem-5/ If privacy and security and hacking are really important to you. Or a pinephone: https://www.pine64.org/pinephone/ https://www.pine64.org/pinephone/
- FearlessNebula 5y agoEven with Graphene OS you’re still using a phone that has a proprietary modem which has its own hidden CPU that acts like a black box. Who knows what it does or if it can read main memory.
- ellenhp 5y agoI'm not smart enough to know what some of these words mean or if this guy is being truthful, but I found this comforting to read as a GrapheneOS user: https://grapheneos.org/faq#baseband-isolation https://grapheneos.org/faq#baseband-isolation
- clarkmoody 5y agoDon't let perfect be the enemy of good and always evaluate solutions against your threat model.
- 5y ago
- madars 5y agoI was reading about this yesterday and confirmed that I did not have gov.ma.covid19.exposurenotifications.v3 nor gov.ma.covid19.exposurenotifications installed. I turned off auto-updates in the Play store (Settings -> Network preferences -> Auto update apps -> Don't auto update apps) and went to sleep. This morning I woke up with a cheerful notification that Google can help with COVID notifications and gov.ma.covid19.exposurenotifications.v3 installed -- the app was pushed overnight over explicit instructions NOT to update (sure, one can say auto-install != auto-update, but it is worrying that forced pushes can happen even with every single relevant UI switch turned off). adb logcat seems to have the following relevant lines: 06-19 09:27:54.481 1689 1990 I PackageManager: Integrity check passed for file:///data/app/vmdl1074248108.tmp [..] 06-19 09:27:55.580 1689 5456 D PackageInstallerSession: Ignoring abandon after commit relinquished control [..] 06-19 09:27:55.649 1689 2530 W BroadcastQueue: Background execution not allowed: receiving Intent { act=android.intent.action.PACKAGE_ADDED dat=package:gov.ma.covid19.exposurenotifications.v3 flg=0x4000010 (has extras) } to com.google.android.packageinstaller/com.android.packageinstaller.PackageInstalledReceiver (+ lots of other similar intents) After that the package immediately becomes active: 06-19 09:27:56.539 1689 13571 D ConnectivityService: requestNetwork for uid/pid:10450/30673 NetworkRequest [ TRACK_DEFAULT id=1249, [ Capabilities: INTERNET&NOT_RESTRICTED&TRUSTED Uid: 10450 AdministratorUids: [] RequestorUid: 10450 RequestorPackageName: gov.ma.covid19.exposurenotifications.v3] ] 06-19 09:27:56.540 1689 3625 D ConnectivityService: NetReassign [1249 : null → 102] [..] 06-19 09:27:56.833 1689 3750 E JobScheduler.Background: App gov.ma.covid19.exposurenotifications.v3 became active but still in NEVER bucket So no, it is not just "oh those people opted in and just forgot".
- notwhereyouare 5y agoDid you check your covid19 exposure opt-in settings? Of everything you mentioned you checked, I didn’t see you say you checked that setting. That setting could be what caused the install
- madars 5y agoYes, I confirmed last night that Settings -> Google -> COVID-19 Exposure Notifications was off. (Aside, I read somewhere but have not confirmed this myself that manually enabling that setting leads to a flow for installing the gov.ma.covid19.exposurenotifications app, whereas the forced update is gov.ma.covid19.exposurenotifications.v3 -- note the extra v3). By the way, MassNotify app is not visible from Play Store search (both on mobile and on desktop -- https://play.google.com/store/search?q=MassNotify https://play.google.com/store/search?q=MassNotify) and does not create an icon -- you can only find it in Play Store via its internal name (e.g. a link like https://play.google.com/store/apps/details?id=gov.ma.covid19.exposurenotifications.v3 https://play.google.com/store/apps/details?id=gov.ma.covid19...), and would have to specifically look in system dialog for all apps to see if it is installed.
- swiley 5y agoEventually there will be laws preventing the horrible things smartphone OS vendors (or alternatively, a practical end to democracy) but in the mean time you should avoid smartphones.
- aww_dang 5y agoRemember when this was being actively debunked as a nutty conspiracy theory?
- ReptileMan 5y agoWe were held indefinitely inside, denied freedom of association and travel, the social media companies went berserk censoring anything that didn't fit the narrative. The restrictions were sometimes contradictory or made no sense or worked and nobody cared to check which were which. And somehow installing app without asking is surprising and a problem. You have been already trough far worse in the last year.
- fitzie 5y agoof course anyone following the details of covid understands that contact tracing is useless with high cycle PCR testing, asymptomatic spread, and widespread infection rates. contact tracing has been shown to be ineffective and a waste of resources since it was tried in the very beginning. but govt continues to dump money and create regulations into this folly.
- ENOTTY 5y agoApple got rid of the need for a separate app in iOS 13.7 https://developer.apple.com/documentation/exposurenotification/supporting_exposure_notifications_express https://developer.apple.com/documentation/exposurenotificati...
- sslalready 5y agoI too found this after reading about it here. I contacted them and received the following reply. > Exposure notifications cannot be enabled without user consent, so if you have not turned MassNotify on, then it is not active on your phone. However, a recent Google update, which makes MassNotify available as an option in your phone's settings, is causing some users to see MassNotify in their app list. Apologies if this caused any confusion. > > The appearance of MassNotify in the app list does not mean that MassNotify is enabled on your phone. The presence of the app merely means that MassNotify has been made available as an option in your phone's settings if you wish to enable it. For more information about this, please see this help center article from Google: https://support.google.com/android/answer/10775533 https://support.google.com/android/answer/10775533 > > You can see whether MassNotify is active by going to Settings -> Google -> COVID-19 Exposure Notifications. The “Use Exposure Notifications” toggle at the top of the page will show you whether MassNotify is active or not. From this screen, you can also enable or disable MassNotify at any time.
- enumBoss 5y agoYeah I noticed this on my phone yesterday. And I only noticed it because I have auto updates disabled for the Play Store and it was asking for an update. When I searched my installed apps list (both in the phone settings and in the Play Store), it did not show up. So not only was this silently installed on my phone without permission, it was hidden from me even seeing it was installed. Some have speculated that this may only be happening to people who mistakenly (or purposefully) turned on the COVID-19 Exposure Notifications in the Google Settings. But I confirmed that that setting is turned off on my phone and the app still installed silently on my device anyway.
- 015UUZn8aEvW 5y agoI emailed massnotifyhelp@mass.gov to ask why the app was on my phone, and I got the following response: Hi [my name], In order for MassNotify to be available to users in their phone’s settings, an update was made by Google that resulted in some users seeing MassNotify appear in their app list in the Google Play Store. Apologies if this caused any confusion. The appearance of MassNotify in the app list does not mean that MassNotify is enabled on your phone. The presence of the app merely means that MassNotify has been made available as an option in your phone's settings if you wish to enable it. For more information about this, please see this help center article from Google: https://support.google.com/android/answer/10775533 https://support.google.com/android/answer/10775533 You can see whether MassNotify is active by going to Settings -> Google -> COVID-19 Exposure Notifications. The “Use Exposure Notifications” toggle at the top of the page will show you whether MassNotify is active or not. From this screen, you can also enable or disable MassNotify at any time. If you have any further questions about this, or anything else related to MassNotify, please don’t hesitate to reach out and we’ll be happy to help. Regards, [name] MassNotify Help Desk Team www.mass.gov/massnotify For information about MA COVID-19 resources visit www.mass.gov/isolate
- dTal 5y agoThis raises an interesting point. Android subdivides much of its core functionality into various hidden "apps". Everyone's all up in arms about this, but I don't remember a similar outcry when the Covid-19 exposure API was "forcibly" added to the Google Services Framework. This isn't really any different from that, or any other OS update. I naturally agree that Google's remote-root is creepy and weird, but why is this the thing that's put a bee in everyone's bonnet? Is it just that an app in the app list is more visible? Won't this outcry merely encourage them to do things the less-visible way?
- oehpr 5y agoLikely because it's being perceived as a third party app that was just arbitrarily installed. At least it can be presented that way, which is enough to get the story to spread. It's honestly not that far off from the truth. Just because google uses your phone as a personal playground all the time doesn't make this instance any more or less outrageous. If this is what it takes for it to be perceived as outrageous as it is, then fine.
- neycoda 5y agoI suppose Google didn't consider that this would further fuel anti-mask/vax conspiracy theories and further harm efforts to eradicate pandemics and viruses.
- neycoda 5y agoI tapped on the developer link on the app's main page in the mobile Play store on my phone, and it said no results found. How can that app be in the store of a publisher that doesn't exist? pub:MA Department of Public Health No results found.
- aramh 5y agoJust to be clear, if you do nothing, then some code gets installed but no bluetooth messages are sent or received right? And by default covid exposure notifications are off?
- eed72 5y agoHad it on both my phones. Would not have known except kept getting alerts and someone told me to check my app list in Settings. Outrageous violation. Like being in communist China.