5 ms·
> In this case it seems that the same goal could have been better achieved by SMS that do not depend on the brand of your phone. The dependency on proprietary a
by dagi3d 5y ago
> In this case it seems that the same goal could have been better achieved by SMS that do not depend on the brand of your phone. The dependency on proprietary app stores and OSs seems a risk for the continuation of a free and reliable communications.
While installing an app without users consent can be as questionable as you want, the point about these apps are not the notifications itself but about the contact tracing which is achieved through the bluetooth functionality.
also, sending sms messages has other privacy concerns that the tracing apps have tried to avoid from the very beginning. having a person phone number can lead to eventually identify that person while that internal trace id it might use, won't.
- esyir 5y agoThis sounds worse to me? Rather than violation of a relatively small privacy (phone number), you instead get timestamp social graph interactions in the physical world. This seems like fat more extreme an invasion than the former.
- marcan_42 5y agoRead up on how the contact tracing apps work. They do not upload your data to the cloud. Phones broadcast a rolling random identifier, other phones collect received identifiers, and only on confirmed infection does the person's phone upload its last two weeks of broadcast IDs to the cloud, where other phones can grab them and cross-check. Having someone's phone number allows you (via the phone company) to trace their location at any time, forever. That is much worse.
- thinkingemote 5y agoI think the low adoption is because it's hard to explain. No one on my street, none of the most vulnerable people would understand your paragraph. No wonder it's not being adopted by those who should be adopting it, but just being used by vigilant young tech savvy and already covid safe people. So not only are only a small number of people using it, these people are least likely to make a difference using it.
- marcan_42 5y agoEdit: Surely we can come up with a more approachable explanation for less technical folks, though? Here's an attempt: "Contact tracing respects your privacy and does not send your location to the cloud. Instead, your phone makes up a new random name every 15 minutes and broadcasts it to nearby phones. It remembers the last two weeks of names it used, as well as the last two weeks of names it heard from other phones. When someone catches COVID-19, they register it in the app. Their phone then uploads the last two weeks' worth of names it used to the cloud, where other phones can download the data. The names aren't connected to their identity, all they represent is someone who caught COVID-19. If your phone finds a match between a name it has recently heard and the online database, it sends you a notification. After 2 weeks the data is erased, so you are only notified if you were near an infected person in the past 2 weeks. Since the random names change every 15 minutes, nobody can track you or know that you are the same person as last time they saw your phone. The data is only stored locally, so after it is deleted two weeks later, there is no way to go back and recover it." How's that? (Edited because without the intro sentence it sounded like I was trying to imply the parent didn't get it; that wasn't my intent.
- thinkingemote 5y agoAhh apologies. It's not the wording of your paragraph, I understood both very well, they are well written. It's a more fundamental understanding of stuff that's hard by those who are most at risk. The old, the vulnerable etc. It's the old digital divide idea. My neighbor doesn't have any internet connected devices, for example. But she would benefit much more from the app than 40 of her mask wearing, young, self isolating, working from home fellow city inhabitants.
- marcan_42 5y agoI didn't want to imply you didn't understand it; I was trying to come up with a more accessible explanation that might help others do so and help drive adoption. You're right that it's not easy to explain, but surely we can come up with something that gets the idea across? :)
- 5y ago
- watwut 5y agoJust because protocol is theoretically safe does not imply it is safe in actual practice or that it is not possible to exploit it.
- bonoboTP 5y agoRight. They can change things with the next silent update anyway. In Germany they also started requiring turning on the GPS while using it. Initially it wasn't necessary and only Bluetooth was needed. Who knows what they modify all the time. I have no spare capacity to follow these developments and when they decide to stop caring about privacy and go rogue in the name of harm prevention.
- Quanttek 5y agoThe apps used around Europe, including Germany's Corona-Warn-App, do NOT use GPS. It only asks for location permissions since it utilizes the exposure notification API that indirectly tracks your "location" relative to other users (i.e. the ID exchange)
- trulyme 5y agoI fail to see the difference. You say it doesn't use GPS, but then continue to say that it uses location data (and thus, I assume, GPS). So which is it? Or are you saying that the app doesn't receive the user location data, only Google does?
- Quanttek 5y agoNeither the App nor Google use location data. However, Google still prompts your for these permissions because, in their mind, the swapping of rotating IDs presents an indirect way of tracking somebody's location (although that data is solely stays on the device and is never transferred, unless a positive person decides to upload the list of IDs there were in contact with)
- 5y ago
- sokoloff 5y ago> only on confirmed infection does the person's phone upload its last two weeks of broadcast IDs to the cloud Alternatively phrased: “only upon government request does the person’s phone upload…” with the implied promise that such request will only come as a result of a CV-19+ test result.
- kn1ght 5y agoThe whole protocol was designed very cleverly from the start to avoid all the privacy blocks that might inhibit people from using it [1], because the main drawback in this is that it's completely useless unless you have a critical mass of users that actually use it. It is very difficult to explain to people that are not curious about the technology and all they hear is 'tracing = tracking = no privacy'. I imagine this is why this app has been silently pushed, but in my mind just having it available and active on phones does not help you that much if the same users are also not aware and actively reporting their infections. So you will have a very small group that consciously install it and when they get infected they report; a lot larger group will get a notification that they have been close to an infected individual. I suppose they hope that by showing those notifications then people that subsequently get tested positive will be curious enough to find out how they should report in, etc. It's risky especially seeing this backlash about silent installations... [1] https://covid19-static.cdn-apple.com/applications/covid19/current/static/contact-tracing/pdf/ContactTracing-BluetoothSpecification.pdf https://covid19-static.cdn-apple.com/applications/covid19/cu...
- Aerroon 5y ago>It is very difficult to explain to people that are not curious about the technology and all they hear is 'tracing = tracking = no privacy'. But this is literally true. This is an app pushed to people remotely without their consent or even knowledge. People cannot trust the claim that there is no privacy gotcha involved in this, especially when previous attempts seem to have opened the log of this information to all installed apps: https://themarkup.org/privacy/2021/04/27/google-promised-its-contact-tracing-app-was-completely-private-but-it-wasnt https://themarkup.org/privacy/2021/04/27/google-promised-its... You cannot trust them when they say that the app respects your privacy.
- dTal 5y agoIs there something special about it being an app? Because the contact tracing framework that the app uses was already pushed to people remotely without their consent or knowledge - as well as the contents of every update ever to Google Services Framework. And in the big scheme of shady shit that Android does without the user's consent or knowledge, that's a pretty benign, privacy-respecting one.
- deleted 5y ago[deleted]
- thepete2 5y agoWould it not be possible to send everyone currently in the state an SMS? I personally would be okay with the government having access to this type of PSA.
- dagi3d 5y agoI'm not sure I get your point. The notifications are sent when system detects you were in contact with a person that tested positive, so mass messages don't make that much sense. Unless you are referring to using the sms as a marketing way to encourage people to install the application...
- thepete2 5y agoThe latter is what I mean. Not really marketing, more like an official announcement.
- theteapot 5y ago> having a person phone number can lead to eventually identify that person while that internal trace id it might use, won't. What? Many many bad people seem to somehow have my number. Practically daily I get an SMSs saying "I've been transferred $5000 to the please login to confirm your transaction .." or some such. I block but they keep on coming. Now, I think I'd rather the person who was responsible for these SMSs to have my phone number than a freaking app running on my phone, especially an app that was basically snuck on without consent.