How Apple And Google Are Going To Enable Contact Tracing
joekent.nyc
joekent.nyc
US deaths just passed 22k, over seven times 9/11 and over four times the total Iraq war death toll. It is likely we will see five to ten times that total number before the pandemic is ended.
People have been happily arguing to let the old die as a means to end the lockdown. How about cellphone tracking instead?
(And remember that every cellphone knows your approximate location by necessity of which cell you're connected to.)
There are easier and less blatantly intrusive ways of achieving 80% or 90% of the mitigation, like for example a combination of nonstop education of the public and issuing tickets for breaking social distancing rules as is being done in some places.
After the 9/11 attacks, Americans passively accepted huge intrusions on privacy that have still not been rolled back, 19 years later.
We should be very careful what we wish for. This tracking thing is a very slippery slope.
I knew crap like this was going to happen. Hello Big Brother.
Nothing. Except a slightly elevated chance of getting infected.
Remember: The goal is not to (make your Grandmother) die for your cause, but to make the virus die for their ill-calibrated conspiracy theory.
It also doesn’t require anyone to install an app...
You can have a national app that is under the control of the health department and doctors ,t hat only does things like "send a notification to all users that were in contact with person with this ID to come to hospital and get a test".
I understand that this could be potentially abused for evil or that evil people already do this using WiFi or cell towers, I am thinking that we should also think at the good that could come of this.
If my purpose-built wirst watch shows me veering dozens of meters of course even if I explicitly tell it to precisely track my location then that’s not fit for purpose.
BLE only has a range of 20 meters or so indoors.
Anyone else see this as a MASSIVE slippery slope with too much potential for exploitation?
That's the same idea here; sure, maybe the CIA and NSA already have the capability. But what's the harm in having it twice? There's actually benefits from the aspect of checking one against the other, not to mention one may reveal something the other doesn't.
I'm not saying this is what will happen. I'm simply saying that power seeks more power.
https://amp.reddit.com/r/AskReddit/comments/fhkcw8/what_are_...
If you are going to attack it, you need to actually address what it does and explain why you don't think that is sufficient.
If this system goes to some lengths to preserve privacy, slippery slope argument doesn't really apply.
There is not NEED to use this scheme in such a convoluted way. There are far better ways to spy, and the way to protect against it is through politics and laws.
A tech-savvy person could drive by your house and find out your IDs for that day. If you reveal them later on (as you would if infected), that person would know you're infected. In small towns a single person could in practice publish a database of all infected households.
A government can install Bluetooth receivers throughout a city and find out where an infected user passed by.
Or if you don't want to, a tl;dr is:
1. Your phone broadcasts a message via BLE every X milliseconds with a "random" ID. The ID is only predictable with a secret key which never leaves user device before "voluntarily revealing" (I agree this can be shaddy). The "random" ID is rotated every Y minutes.
2. The secret key will be rotated daily. The user device only reveals last 14 keys if user voluntarily do so.
3. Note that every BLE advertisement already contains a hardware address and your phone does this regularly. Guess how they mitigate this privacy issue? Rotating the hardware address every Y minutes. So no additional entropy being leaked here, unless you have the user's secret key.
A government can do much more with less effort using other means. And it's hard to see the value of making that kind of attack as an individual.
You really think that won't be the predicate for abandoning security and anonymity?
edit: and no, the observable "ID" is not fixed, so you can't link two unknown IDs.
This program goes out of its way to achieve provable anonymity. That is, in fact, the only reason Google and Apple are needs to implement this. Google Maps has actual location data, with similar precision at least in cities. That data has been there for sliding/skating governments to grab for years now. It's on servers, where it's easier to get to than data on your phone, legally. And location data is far more valuable than "X and Y came within 5 minutes at least once in the three days beginning April 15th".
If all that doesn't convince, rest assured it will convince the public. As would anything, really, because they already see this pretty clearly. With that in mind, consider that going to the barricades for privacy now means certain failure on this issue, and possibly lasting repetitional damage for the cause.
[0]: One wishes...
Also: that central server has got to be pretty powerful.
More information gives me more tools to protect myself and those I love.
Might be possible with iOS devices as it's pretty easy to test each of them. Harder to do with the 1000s of Android devices that exist.
The tl;dr is that at least in the context of a pandemic like this one, lack of access to a smartphone and lack of willingness to enable tracking puts a person in the new second-class-citizen category. It's not the stick that government would use to restrict freedom; it's the carrot of granting more freedom to those who are more trusting of authority.
Not only do I personally not see much of a way around that scenario, the Vox article notes it's entirely possible that Americans' general mistrust of authority means the country may recover more slowly and painfully than nations that are willing to let the government data-tag and monitor everyone.
At what point does the value of participating in society and the economy outweigh the value of one's privacy? It seems this question is going to rapidly become even more non-academic than it already is.
https://news.ycombinator.com/item?id=22834959 (805 points, 459 comments)
Random identifiers not linked to you or your device, identifiers change every 10 minutes so third parties can't track you over time, processing locally on the device instead of by Apple or Google or the government, etc.
It cant, and any claims it can is sheer arrogance on the part of the developers.
you can not simultaneously assign an identifier to everyone, and maintain privacy, they are mutually exclusive. If you can ID someone, and trace that ID back then it is not private
The idea that can not be used for something other than COVID is moronic, this type of system has been done in Marketing for a long time, Google knows this very well.
This is not a new or novel idea, nor it is private
you can not have an anonymous system that also provides aways to trace back to individuals you came in contact with
it is impossible
and their complex Hash of hashes is just a way to make it seems private for people that do not understand what is really going on, it sounds good on the surface, but that is all it is surface level
that is with out getting into the ways to compromise the device to get the original Tracking key that all of the other tracking keys are generated from
You can afford to give up a few days of your privacy for that. Really, you can.
If that is all the justification you have, you have already lost the debate. That kind of justification can be used for all manner of dystopian programs. Authoritarians have been limiting privacy and freedom for centuries on the basis of safety.
Right now in congress the EARNIT act is attempting to use that very argument for the "safety of children" we all need to give up E2E encryption
No I completely reject your premise that because of safety I need to give up my privacy
it is not sociopathic to put an extremely high value on privacy and liberty
For example should I have my every moment monitored because I might hurt someone? Should everyone have to have a BAC monitor on their cars so save people from drunk driving?
Just trying to see if there is any limits in your Authoritarian world