Pan-European Privacy-Preserving Proximity Tracing
pepp-pt.org
pepp-pt.org
The app basically uses Bluetooth Low Energy for the proximity measurements: The app generates temporary IDs, so if two smartphones with the app come close, they exchange their IDs and save the IDs of their respective partner locally and encrypted. If a person is tested positivive for the novel coronavirus, the doctor can ask the person to upload their list of contacts to the Pepp-PT server. The app can then compare its list with the list on the server and notify the user if they had contact with person who has COVID-19.
Source for the summary (before I found the site at the top): https://www.spiegel.de/netzwelt/apps/corona-warn-app-fuer-eu...
If the comparison takes place on the server, it will save a lot of bandwidth. But then there will need to be a Tor like network to hide the IPs of the phones doing the requests.
This way the phone would need to download just the lists for those regions and periods of the places it has been through.
Instead, the system should rather tell Alice she may have been exposed to the virus and should get tested. Bloom filters can provide that uncertainty.
I don't know why Singapore GovTech hasn't yet released the source even after they said they intend to do so...
These folks also seem pretty open https://start.ito-app.org/ and cooperate / plan to cooperate with other initiatives.
There's a significant portion of any of these technical rundowns I don't get though. All of them seem to treat BTLE beacons, sprinkled with a bunch of hashing schemes, as some form of magic bullet for privacy. If your crypto was this great you might as well use my GPS with far better location accuracy, does anybody know the reasoning behind this (apart from the obvious "the public wouldn't want that")?
https://www.livingmap.com/technology/location-matters-geospa...
> And can that be opensource as well. What's your point?
Probably because military software likely contains military secrets that would be useful to an adversary.
A lot of espionage is focused on getting seemingly boring information like the performance characteristics of a radar system. If the radar system is run by software, and the software is made publicly available to anyone, an adversary country could learn what they want from the software (and do other things, like improve their jammers).
The government should definitely get the rights to the source code (and other IP) for military projects they fund, but I think it should still be kept secret (so not "open sourced" under a typical understanding of the term).
> As the formal organization is not yet established, we cannot yet provide links for making a donation or for downloading the guidelines for a donation. Please sign up below if you would like to be informed when you can support us.
a. They aren't even incorporated. b. Donations aren't public grants for which one has to apply.
The members listed on the page do include public entities such as universities and publicly funded research groups. However, membership to a non-profit organization doesn't necessarily imply that the non-profit needs to comply to policy rules that govern the funding of individual members.
Of course, if the majority of those members are public entities, adhering to open policies would enhance the credibility of such organizations. Even so, open source and open access are easier said then done. For starters, a significant portion of research ends up behind the paywalls of incumbent academic publishers.
Furthermore, you have to ask yourself why such an initiative suddenly springs to life exactly at this time. It's not the first infectious disease that causes a pandemic. The main reason is that it created public awareness in the Western World overnight. No more, no less. And so, there's suddenly an opportunity to rally funding, justify ethical shortcuts and do large scale social and technological experiments that are usually left to the realm of "what if".
The fact that this thing exists now shakes a shiver down my spine, regardless of any well meant intentions.
> Furthermore, you have to ask yourself why such an initiative suddenly springs to life exactly at this time.
I don’t get this paragraph at all. It’s no mystery why this is happening now and didn’t happen last year: there’s a pandemic on.
I realize you say as much. But somehow, with the “no more, no less” and “technological experiments” you make it sound sinister. Like C-SPAN, but with an iMovie horror sound & lighting preset.
So are wars and terrorism. Fundamental human rights are pressured as soon as they are threatened.
I'll leave this here:
https://www.hrw.org/news/2020/04/02/joint-civil-society-stat...
> it’s specifically set up to protect privacy.
It can't protect privacy. A non-profit isn't a public authority. This initiative is meant to (a) create technology that adheres to existing legislation and (b) lobby - read argue or ask - with politics to use this technology.
The harsh reality is that authorities can happily ignore or cherry pick from such efforts, and that they are free to change or deprecate legal frameworks is such is deemed necessary "in the public interest".
This initiative sounds nice, but I don't read anywhere how they tie into the longstanding efforts of human rights organizations such as Human Rights Watch.
That's why I feel this is a technological experiment. It simply doesn't even consider the social impacts: there's no mention whatsoever of social research or leveraging existing social research.
The page lists 130 members although it is unclear if that is the same as a partner.
Partial quote from halfway down the page:
"As a partner, you will:
… have access to our services and mechanisms.
… have access to our documentation and the source code of a reference implementation."
is not the same as "the implementation"
ie the binary will be built from other sources and those will not be made available to other parties, partner or not?
Having an app to help tracking infections, is something I would install. But what my government seem to be going for, no way. Way to intrusive and all encompassing.
I haven't found Simula, which is building the Norwegian app, on the list of partner of PEP-PT. So this is probably a saner initiative.
Why not follow their lead?
1) Transmission via surfaces is thought to be important (afaik). You don't have to be in the same place at the same time to transmit.
2) My bluetooth seems pretty slow and unreliable when connecting to my headphones. Is it reliable for logging ~50 proximities during my trip to the supermarket?
According to Hendrik Streeck, a leading researcher in Germany, this may not be the case: https://youtu.be/VP7La2bkOMo?t=231
They are working on a more formal study of this but indications are that the viruses that other teams have found on surfaces may be "dead" (in the sense that they cannot actually replicate anymore and therefore are not bioactive relatively soon after leaving host organisms).
Video only in German, sorry, sure this will get publicized internationally if the study confirms the indications.
and they only measured the quantity, not whether the viruses they found after x hours could actually still replicate.
[1] https://www.nejm.org/doi/10.1056/NEJMc2004973 [2] https://www.eurosurveillance.org/content/10.2807/1560-7917.E...
Then see what the false negative rate is - unless the average number of "others seen" is close to 100, this isn't going to work.
2) Scanning is mostly just listening and waiting for other devices to send beacons. With one discoverable device nearby, it might take a moment to hear anything. With 50 devices nearby, you scan should be spammed with results.
You might have missed a few devices if you were unlucky and moved out of range before they got a successful beacon through. However, in that case you could use second-hand proximity to find the "lost" contact through some of the successful ones.
Furthermore any kind of app will only reach a subset of the population. (Senior citizens are unlikely to install this app.)
Yes, bluetooth drivers are a horrible hellscape of cyberspace, but it's probably because connecting to a sink/source (speaker/mic/camera/whatever) sets up the corresponding audio/media/etc channels too, and the interaction of the relevant components (pairing, PIN, kernel modules, gstreamer or who knows what) is what requires a very fragile dance. I have no idea how broken the BLE part is.
Firechat doesn't seem that bad and it uses Bluetooth too.
Claiming to respect privacy without being open source is useless.
Google, Facebook, etc. also "claim" to respect you, they are also "compliant with European norms"
I never said the app is useless, I said that "claiming to respect privacy" on a website is not useful if you don't prove it with open code.
Huh, that sounds ridiculous/impossible... who will be putting these qr codes all over the Netherlands??
Also note that this air is often piped somewhere else, hence you would need an airflow analysis.
But please see the problems with it!
They didn't lock down the cities. They did it and continue to do it without locking down.
They are staying flat now because they continue to do that.
This is a tool to help that second part of contact tracing. No one is saying it's a replacement for social distancing, but it enables us to relax it if there's a way to stop detected infections spreading.
It's viewed as part of the recipe that countries with SARS and/or MERS exposure learned that helped them to handle this situation better than others.
A relevant datapoint here is the case of Webasto in Germany. The woman who infected employees of Webasto and thereby unwittingly created one of the first clusters in Germany was traveling, ate in restaurants etc. Yet the only known infections happened with her colleagues at Webasto, ie those with whom she sat in proximity close and over an extended period.
That indicates that infection „requires“ (or is favored) by extended proximity. It may also indicate that infection by aerosols is more „difficult“ and droplets may be more relevant —> masks!
I am writing this not to say all-safe but to caution against overexcitement/-anxiety/panic. Caution is good but it seems infection is not as easy or fast as mainstream media are touting atm.
Works on Android, maybe useful for someone else, since they are not open-sourcing the app.
Another reason: "lets meet at a corona party, no cell phones permitted".
Basically, we have to stop 2/3 of infections to get an R<1. If 2/3 of the population use the app honestly and we keep up some other measures (no indoor events where people are in close contact, wearing masks while shopping, no visitors in nursing homes and hospitals, etc.) then this might be enough to contain the virus until we have a vaccine.
Totally non-commercial; we're relying on the generosity of cloud providers @neo4j and @digitialocean.
I reached out pepp-pt (catchy name) to see if they wanted to contribute. Come put time and energy into our hack.
If any JS devs wanna help out please, please say hi: https://github.com/contactTracing-app
That's why BLE works, it's because it's a very low distance technology only phones actually within a distance that are relevant are going to show up.