NHS rejects Apple-Google coronavirus app plan
bbc.co.uk
bbc.co.uk
Edit: Google and Apple need to get their act together though, and just provide a contact tracing framework as part of the OS that is compatible, and can have data housed in each country where they see fit. It should be optional for people, but it should be part of the OS, and it should just be presented to the countries as ready to go with just a little bit of integration. That way we can force everyone to respect user privacy and not do sketchy contact tracing apps.
They need to get their act together, and ignore folks trying to backdoor their systems.
As you'll have to provide information about your recent contacts to the authorities performing the contact tracing. At least that's how I understand our local law (Germany).
So I don't think its necessarily worse doing it with an App than doing it the old fashioned way. Sure digital traces are always easier to abuse, but then on the other hand, because things get automated, actually less people might get access to your data. Which would be a privacy win.
I believe what's even more important than how we design the app, is how we design the legal framework around it. We do need rock solid laws, having enforceable data retention periods, and that limit access to the pare minimum needed.
Unfortunately, our track record for the design of such laws has not been too good over the last years.
I would like to note that a v1.1 has recently been released, my information is about v1.0.
The ENSelfExposureInfoRequest class can be used by an app to obtain diagnosis keys for the previous 14 days. What an app does with those keys is up to whoever implements it.
https://covid19-static.cdn-apple.com/applications/covid19/cu...
This is an example off the top of my head, as other comments in this thread have explained, violence against people who have the virus is happening around the world and is something that must be accounted for in these protocols.
Edit: a link to a story from another comment (https://www.washingtonpost.com/world/the_americas/coronaviru...). I hope you can see that this technology can worsen this.
This is true, but I think a DP-3T like protocol (ex the Apple-Google spec) doesn't actually pose much risk here. The hypothetical drug dealer or other illicit contact can receive a notification that they were potentially exposed to someone that was infected, but in general no one else (a police officer, a spouse, etc) will be able to determine who was in contact with who.
In order to link someone to a particular location, you would need to observe their broadcast identifier while they were there and also link their diagnosis key back to them (this is likely to be quite difficult for most actors to accomplish).
In order to reveal a contact between two people, you would either need to do the above for both of them or to observe at least one of them at that location and time in some other manner.
Personally, I will not opt-in to this technology, and if forced to use it, I will leave my phone at home. It’s a small act of civil disobedience but it’s a necessary one IMO.
It’s alarming to me how so many in tech seem welcoming of, even excited for, this technology. I say this as someone who wrote my senior thesis on a subject related to privacy enhancing technology, so I’m familiar with the ideas.
It gets contact tracing right by accomplishing the goal while yielding almost no ground on privacy and remaining almost entirely offline. In an ideal world, all new technologies would be implemented in such a focused manner without regard for turning a profit.
I'm puzzled by your concern about normalization of self-surveillance; everyone I know has already voluntarily made drastic alterations to their behaviors due to current circumstances. I really don't see what introduction of this technology changes.
> who’s to say an emphasis will remain on privacy in future iterations of the technology?
If people don't object to widespread state surveillance later, would they have objected now? I don't see why a decentralized technology specifically built to prevent surveillance should lead to an increase in acceptance of it.
And even is someone goes to that extent to track your identity down, I am not sure that local de-anonymisation is a problem. This is not something like HIV. I don't think there is any social stigma to catching the coronavirus. If you catch it you should self-isolate, and it will be obvious to the people around you that you got it. And if you don't want to self-isolate and want to hide it, what is the point to self declare that you got contaminated on the app in the first place?
"In Mexico, Colombia, India, the Philippines, Australia and other countries, people terrified by the highly infectious virus are lashing out at medical professionals — kicking them off buses, evicting them from apartments, even dousing them with water mixed with chlorine."
https://www.washingtonpost.com/world/the_americas/coronaviru...
...and these are cases where the victims don't even have the virus.
Disease has always carried stigma. We tend to lash out at things we don't understand. History has seen everything from leper colonies to menstruating women herded into tents.
You or I may be able to rationalize it and say "well, shit, the test was positive-- time to self-isolate" but plenty of plebes will use it as cause to incite a witch hunt, especially if a loved one dies from it and transmission is attributable to you.
Not quite. It takes a wiz to collect and correlate the data, yes. What happens to that data after that? For it to be useful, it's going to get stored somewhere. All it takes is an uneducated clerk or bored intern with access to go snooping around the de-anonymized data to compromise anybody implicated.
And this does happen routinely.
* Facebook, Uber and Google have all had problems with plebes (and tech wizzes!) with god-tier access doing inappropriate things with sensitive data.
* Bored data entry clerks with access to the credit reporting database routinely snoop on neighbors', exes' and celebrities' credit reports in spite of federal law.
* Revenge porn is such a thing that rule 34(a) ought to be that if you produce nudes, your confidant or Geek Squad/iRepair technician will post them on the internet.
* Look at how often people get doxxed by employees leaking customer PII onto reddit and 4chan, then look at how fast the mob descends on people innocent of any actual wrongdoing.
* We've seen a secretary get her hands on the Pepsi formula and try to sell it to Coca-Cola.
* The people living in the geographic center of America continue to receive death threats and harassment because of a flaw in outdated MaxMind databases that attributes ungeolocatable IPs to their location.
* There are people who refuse to participate in the census because of what certain cults of personality have done with such data.
Any chain of confidentiality is only as strong as its weakest link. You presume far too much intelligence and rationality on the part of humanity. Never forget that half of Americans wanted a belligerent narcissist to be "leader of the free world," and he still has supporters despite publicly recommending anti-parasitics and Lysol douches as solutions for a global viral pandemic.
Sensitive data is not created and left to decay in an underground bunker in Yuma. Despite its practical uses, at some level it will be exposed to individuals who lack discretion and will be exploited to malevolent ends.
Not once in human history has it worked out any other way!
Actually that's not true for the situation I described.
The bad actor would be able to connect any of your broadcast identifiers they observed back to each other via the diagnosis key that you published. Assuming they have a number of nodes monitoring Bluetooth traffic over a broad area that you passed through, they will be able to reconstruct the path you traveled over time.
For a naive implementation, the resolution of this reconstruction would depend on the spacing of the nodes. For a more advanced implementation, other data could be integrated to drastically improve it. Remember, your Bluetooth device is a broadcasting radio at the end of the day.
As to the likelihood of such things becoming commonplace worldwide, do bear in mind that many devices now periodically randomize their Bluetooth MAC addresses due to real world examples of tracking. Thankfully in this case it would only be possible to compromise the privacy of those who tested positive, and only within a singe 24 hour period (ie the daily tracing key rotation time frame) at that.
I'm much more concerned about reducing COVID-19 to save millions of lives.
If you enable the framework but never test positive (and thus never publish any of your keys), it's no different than if you had just kept Bluetooth on all the time.
If you enable the framework, later test positive, and choose to publish your diagnosis keys, each key can be used to link all your rolling identifiers together for the corresponding time period (nominally 24 hours). Contrast this with a randomizing Bluetooth implementation, which never intentionally reveals anything that would allow the different MAC addresses to be linked.
Of course, Bluetooth MAC address randomization itself is trivial to defeat for a reasonably capable and motivated adversary. If they can plant a bunch of radios for the purpose of tracking you, why can't they also use cameras?
This technology is currently being used to track people today. The use of Bluetooth address randomization does not do a sufficient job to prevent this, the only option is to not use Bluetooth.
It is important that people are aware of these risks. I am fortunate to live in a place where I can live my life without scrutiny from the government, but not all are afforded such a luxury.
But I just can't think of a system that achieves contact tracing while no one having any idea of the whereabouts of a person who self declares as contaminated. At one point the person who self declares has to volunteer to disclose some information.
And it is a bit theoretical, as the authorities who have the capability to track your blutooth across the city have many other ways to track you (starting by calling your phone service).
What I object here with the NHS is the creation of one more tracking database with the explicit intention to let some researcher roam through it to find something interesting.
I guess my original comment is a bit vague. When I look at these protocols I am interested in how large scale adversaries (Nation State) would use this technology, but also small scale adversaries (day-to-day person you are not friendly with). I think its also important to note as others have, that being outed as having the virus does put people at risk of violence in some places.
Every person is a danger to society until this is over. Release is out of the question. The choices here are continued incarceration, or parole.
I can sort of imagine a libertarian solution here, with truth in labeling: as long as I can tell before I get within six feet of you whether you share a connected component with any conscientious objectors, then I can make my own decision about risk. But I cannot imagine that many public places would permit entry to such people.
Sadly, this is not true in India. Infected people have been threatened by their neighbors and friends with death. Infected people have also been harmed. Doctors, nurses and healthcare workers who have been caring for COVID-19 patients have been evicted from their houses or physically harmed (the latter forced the government to bring an emergency law providing for stringent punishment for those who attack healthcare workers).
I’m guessing that there will be a social stigma depending on the culture as well as other factors like the mortality rate (if your area has a higher mortality rate, then you’d likely hate infected people and take matters into your own hands).
Humans can very quickly develop irrational fears and react on that.
So there is a huge need to preserve the privacy of those infected.
Maybe not. But there is definitely a social stigma about certain activities, like meeting your drug dealer or cheating on your spouse, which would be revealed through automated contact tracing.
Except they refuse to be limited by cryptographic means to that.
Why? Because they demand the ability to change their promise in the future ... exact details to be specified. Perhaps “solving drugs” with contact tracing. At which point they have your data, you have zero control, and “your honour we can prove he lied: he was close to that drug dealer 5 times. Further details (such as that this happened in the train station and 5000 other people were also close) cannot be confirmed because that would violate privacy”.
This is the government that got caught letting police officers stalk their ex for 2+ years and then initially arrested the victim for more than 2 weeks when caught. Let’s not pretend they’re above doing this, especially since it’s become increasingly clear this contact tracing is the police’s wet dream.
But yeah there has been lots of stories about medical personnel who where thrown out of their rented places because of the fear of the virus.
So, this has a tradeoff. Personally I don‘t think that linking multiple IDs in a day is a big intrusion of your privacy (and remember, it‘s only disclosed to anyone for the timeframe that is epidemologically relevant) - full de-anonymization still requires some second channel, such as cameras or the like - which can be linked together without those Broadcast IDs anyways.
It never provides a false negative so all positives can download their set-up filters until they're satisfied.
The filter that DP3T are describing isn't that much bigger than the DTK set anyway.
I think that's a terrible idea. Think about how somebody can mark themselves as being infected. Normally you'd want this to be authorized by a doctor or similar, or maybe just by reporting symptoms if the situation is dire.
Google and Apple rightfully did not want to be involved with these decisions, they just want to provide a way to detect contacts via bluetooth while still mandating preservation of their users privacy.
That's exactly what they're doing.
https://9to5mac.com/2020/04/23/apple-contact-tracing-april-2...
Explain how having every person you're in contact with being tracked by governments and corporations can be done in a 'privacy preserving way'. The very concept of contact tracing is probably the greatest violation of privacy I've seen proposed yet.
The central authority just has a list of tokens from infected people. A corrupt central authority could also massively deploy token recorders across an area and then see when and where the infected people were seen, but governments already have that capability just from the cellular systems.
---
[1] https://github.com/RaphaelJ/covid-tracer/blob/master/README....
A simple method is to have phones directly exchange random numbers over bluetooth. If and only if someone tests positive, they publish their phone's recent random number transmissions. All phones download all published random numbers (just random numbers, no personal info) and see whether they've received any of them via bluetooth.
This way the phone knows whether it's been in contact with someone who tested positive, but nobody else knows. Since the user has a strong incentive to get a covid test at that point, that's fine.
The effectiveness of a contact tracing app scales with adoption. A sketchy, battery-draining implementation with questionable privacy may not see widespread adoption.
A battery draining implementation may be the best they can do by themselves, and, from past form, the lack of privacy is a feature and not a bug.
They’ve really gone out of their way to adopt a centralized solution, when a decentralized solution would be better in almost every way.
The point is to get a list of close contacts, if needed (someone has tested positive), for a limited period of time (until the epidemic has ended).
The privacy issue is minimal, certainly compared to the situation we are in.
Do you really think that the government will go over these data to find out that you tend to have close contacts with your neighbour's wife very often? Let's keep a sense of proportion and let's calm down. This is getting very irrational.
Anyway, since they do not seem to be willing to make contact tracing mandatory, these apps will remain a curiosity until this is over. Then historians will be able to debate whether this was all a distraction or a costly lack of political courage.
No. They already have their act together by providing only an API that cannot be abused by authoritarian regimes to do whatever, and keep stupid/badly advised politicians such as my own German government at bay. I hope they keep that line.
The reason Germany switched the approach finally was the public pressure by a) having Google/Apple stay course and b) the German public - learning from journalists and other experts - that there in fact was a less privacy-invasive approach that according to many if not most epidemiologists wasn't any worse either for tracking the pandemic.
Hadn't thought of this until you mentioned it, but having it only work within a country could significantly hinder the ability to trace imported cases (ie, cases from travelers).
If the data is housed in country-of-citizenship, then travelers would not notify people they contact while abroad.
If the data is housed in country-of-current-location, then people who test positive while abroad might not notify people in their home country whom they contacted before leaving. There might also be failures cases when they return home, but those could probably be solved with careful implementation.
Regardless, this seems like a case where a single international, globally-accessible registry is useful. And therefore privacy becomes a very important concern.
Even traveling between Munich and Nuremberg, a one hour trip, I might be on a train near an Austrian who saw no reason to leave Munich during all this heading up to Berlin to finish a consulting contract, but a week ago had been in a meeting with a German who turned up positive. Our Austrian consultant would have been allowed to stay this past "shelter-in-place" month if she had a lease on an apartment and had registered it as her primary residence - no residence permit required, as she's an EU citizen. Again, it would be in everyone's interest for the three of us (and everyone we had much time around) to know about when the exposure took place and that we might need to self-quarantine/be tested.
I think DP-3T is the better choice, and Germany has clearly come to that decision as well (helped, no doubt, by the fact that this is the protocol that will receive API support) but I think it is reasonable to come to the conclusion that PEPP-PT is better.
Big warning here, i know they tried persuade multiple countries, but I'm so glad to be living in Europe. ( They do have some business here though)
https://www.bloomberg.com/news/articles/2020-04-01/palantir-...
At least Germany is using the best possible solution.
I'm pretty sure a fair amount of bribe/lobby money is involved in the US.
Can't find much sources about them in Europe currently :
https://ec.europa.eu/transparencyregister/public/consultatio...
Absolutely not. That has way too much temptation for any government to utterly abuse. Simply creating it is opening a pandora's box and should not be done.
What's the benefit if they can gather better stats with a central approach if it doesn't work because a lot of people aren't installing the app?
You immediately answered your own question.
This topic seems to be a rorschach test.
60% is the minimum number the experts are saying must use the app before it's effective.
With covid-19, if the R0 is 3, then being able to track 2/3rds of infections should _hopefully_ bring the R0 below 1.
At least that's how I've been reasoning it out.
But the current R value in the UK under the lockdown is estimated to be somewhere between 0.5 and 1. A contact-tracing app doesn't need to be perfect; any reduction in R would allow for either a swifter reduction in cases or a liberalisation of lockdown measures.
The virus is extremely infectious. Random sampling in NYC was hinting there were 1-2 millions of people infected and that's not the only city like that.
The virus still spreads as long as R is over 0; you still get new infections if there's any spread. However, an R of 1 is the boundary for exponential spread. If infections are not spreading exponentially it has to be below 1 by definition (as I understand it).
In the UK death rates and hospital admissions have been falling for some time, indicating R is currently well below 1. Neil Ferguson, one of the UK's top infectious disease modellers estimated the current R value at between 0.6 and 0.7 a couple of days ago: https://unherd.com/thepost/imperials-prof-neil-ferguson-resp... .
50% compliance? We already lost, too many people will ignore the app and we can't get to 2/3 even if 100% of the population installs.
compliance rate | necessary install rate
<67% failure (R_t stays >1)
67% 100%
80% 83%
90% 74%
95% 70%
100% 67%
If as another person replied the R0 is around 6, then: compliance rate | necessary install rate
67% failure (R_t > 1)
80% failure (R_t > 1)
90% 93%
95% 88%
100% 83%
These are... not great numbers for trying to deviate from what Apple and Google will push as a built-in app. Even assuming >= 90% of the country has a smartphone, you need a huge fraction of the population to participate.And even if we "only" drive R_t to almost 1 we can at least buy a lot of time for our healthcare workers, which is valuable.
Either way, I didn't mean to be that pessimistic. I think an ensemble approach is necessary. For now, general (easy to follow) shelter in place rules, followed by test and trace using these apps, and then targeted relaxation of the rules as we discover what we can reopen without causing a spike in R_t.
Thus, it's like for a lockdown, it cannot be opt-in to be effective unless they bet on the vast majority of the population to weigh the pros and cons.
Is the existence of a log that you came close to someone you probably don't know to be potentially used for a critical public health purpose, for a limited time, any issue?
If feels like refusing to tell your blood type when you're having a massive hemorrhage in order to "protect your privacy"...
This shows the limit of individualism, the belief that I am all (this is what the privacy issue is about). An epidemic is when the group must prevail over the individual and cultures that are more group-orientated react much more effectively (China/Taiwan, Korea).
You don't fail to see how it would keep researchers busy for years, but why would only researchers be interested?
Collective benefit over individual rights is not a novel discussion. I see people trying to make a case for individual rights be construed as anti-collective benefit. These people however are also just people, trying to speak for what they think is right, but often times get criticized for it. A lot of times people consider starkly different cost-balance calculations and arrive at different conclusions but this is rarely made explicit. What if you set the time scale a little differently? Corona might be ravaging the world today, but how about in 50 years? 15? Laws to combat terrorism passed during times of crisis that were supposed to be temporary are still here (not a US resident, I might be misinformed, but I hope my point is evident).
Given the ubiquity of (and willingness to leverage) the UK's camera and social-media surveillance across across all level of law enforcement in the country, I've come under the impression that they've collectively decided that they'll tolerate just about anything in exchange for an orderly and secure society.
Mandatory app installation really doesn't seem out of the question.
We have a strangely inconsistent pattern on this issue. Up to a point, people here seem willing to trust the government and the police and security services, and therefore to tolerate more intrusion than in many places. On the other hand, if you go too far, you get a situation like No2ID, and any hope the government has of introducing anything even vaguely resembling a sufficiently controversial measure dies for a generation (or probably more, since our younger generations are, as in most places, much more tech savvy and aware of these issues).
Given that people here are already somewhat sceptical of the government's handling of the coronavirus situation in general and of the lockdown measures specifically, but for now people are mostly following the guidance anyway, rocking that boat is probably not a wise move politically.
FWIW, I wouldn't install such an app if I didn't consider it to have sufficient safeguards, but then I'm a strong advocate of privacy and civil liberties who is also willing to give up various other "normal" parts of life to avoid compromising those principles in ways that make me uncomfortable. What should concern the powers that be in this case isn't me, but rather the number of my friends and family who typically do tolerate more intrusion into their privacy (for example, being willing to share a lot of personal information on major social networks) but have expressed concern about this app.
Which is so weird because despite all this rugged "fight for your rights", Americans have some of the weakest labour and health rights. But I guess you do have the right to say you have very weak rights!
I believe that the American conception of rights is quite distinct from the European one. In the US, the rights outlined in the constitution are independent of the state, which was engineered as their guarantor. These rights restrain the state, and ought ostensibly to be universally applied, but offer no guarantee of service beyond the securement of those rights, and provision for the common defense.
Conversely, European rights seem to be hard-earned privileges or guarantees on quality of life that have been extended to the people by the state. These rights can directly impose duties on either the state, or certain members of the population (I.e. employers).
Functionally, they're pretty similar day to day, but European-style rights benefit from flexibility, but are also much more likely to be subject to provisions or restrictions such as laws around speech, in part because they're closer to a negotiable agreement between the people and their government, as opposed to some inviolate universal law which requires extreme measures to actually amend.
Europeans generally seem to have a higher quality of life, and are afforded better care and services by more broadly competent governments.
They have superior labor protections. I wish we had some of them. I'm not convinced they have more rights, as I would define them.
So you get obnoxious Home-Owner Association rules when you buy a house, you get unions (your right to freely associate and organise with others) curtailed and destroyed, you get no meaningful privacy protection against scummy companies vacuuming up data (e.g. Equifax)
Yes, Europeans do have a higher quality of life, I agree.
What they don't have is an army of low paid people, who have no choice but to deliver services cheaply to those who can afford it. I suspect many in America like this part of "capitalism".
-----
reply to effie below as I've talked about something that the HN police don't like and have the fake "you're submitting too fast".
-----
It's a reasonable point, but as you say they have some protections, and this enables them to refuse low pay and bad working conditions, up to a point.
Also although all human life has great value, we are comparing immigrants (and agreeing they have better protection) to citizens in the USA, who have weaker protection.
Really quite incredible.
The real difference is how the citizens are protected. In Europe, citizen is treated as human regardless of how much money they have. In U.S. this doesn't seem to be so. The money is more important.
American companies are more free to not pay a worker who is delivering no work on sick or parental leave, and to end employment of a worker they no longer want to employ. American health providers have more right to gain profits from their services. American companies are generally less burdened by things like VAT tracking and customs enforcement and silly cookie disclosures.
There's a reason that the FAANG industry dominators all came from American origins, as well as those of yesteryear like IBM and Intel, or in other industries like Ford or Disney or Visa.
I know you are kind of agreeing, but from a diff perspective.
What the USA has going for it is that it was very far away from its enemies during WW2, and so while European countries had to rebuild everything, the US economy went into overdrive. Plus it's the 3rd most populous country in the world and that has advantages.
It's certainly nothing to do with simplicity of doing business.
Then the cost (a few less people who would have got the decentralised Apple/Google app, but not a government-made one) might be smaller than the benefit (richer data).
UKGov has fairly well demonstrated their ambivalence to the well being of the UK population over the past few years. I imagine they're hoping to sneak in new surveillance apparatus with the power of societal pressure - after all, if you don't install the app, You're Riding With Corona. If not enough people install it to make it effective, eh, they'll try a different tack later.
Because they could require people to use it, the may have to anyhow. Also - most people are not at all concerned that the NHS can track them during a pandemic after all Google and FB track them all day.
If it's opt-in, masses of people will be too lazy, won't care, will forget, will have 'good intentions' but won't use it, will let their battery die, forget their phone.
At least with a 'face mask' policy, it becomes apparently clear that someone is 'not wearing a mask if they are supposed to'.
With contact tracing ... there's no way to flag people.
Without extended contact tracing and 'almost everyone on board' it's simply too dangerous for people to be out and about.
People are going to have to use it to go outside, it's as simple as that.
They may be right. But this piece of dirt won't be on my phone.
It doesn't sound like it would collect anywhere near as much personal data as Google, or the government, already does.
For the sake of protecting lives and getting out of lockdown quicker to rebuild the economy I'm prepared to sacrifice a little privacy.
Edit: I don't particularly care, but there seems to be a systematic approach from some users to voting down posts for expressing honestly held beliefs that a balanced approach can be taken with respect to privacy.
We can speculate as to reasons why: one could be that the authors feel that the decentralised approach is lacking some important feature that could save lives, such as insufficient feedback about how it is being used.
Another could be that they feel that they can implement a solution faster than waiting for Google/Apple to finish their platform and then building something on top of it. This leaves open the possibility of changing tack if the new API is superior.
Or maybe they're just hedging their bets in case the Google/Apple approach doesn't work or gets pulled.
(I'm assuming none of this is a nefarious plot by the government to add to their general surveillance powers. I personally don't think they'd care given the considerable abilities they already reputedly have to track mobiles).
Developing a reasonably anonymous contact-tracing app is not that complex at all. I wrote a very simple (but working) app that also implements contact-tracing in a way similar to D3P-T or Apple/Google, and it only took me a few days: https://github.com/RaphaelJ/covid-tracer/blob/master/README....
Users will also never opt-in for such apps if they don't at least try to slightly protect privacy.
Also not a good look (edit: for the uk) on the day Germany swapped from using this style app to a Google-Apple backed system.
If the true reason for the centralised matching is that they want to have a better oversight of the spread could they not do that with the Google-Apple system by having it (optionally) phone home to a server when there is a match?
>The tech giants believe their effort provides more privacy, as it limits the ability of either the authorities or a hacker to use the computer server logs to track specific individuals and identify their social interactions.
>But NHSX believes a centralised system will give it more insight into Covid-19's spread, and therefore how to evolve the app accordingly.
I hope we follow Germany and reverse this decision!
It sounds to me like NHS wants location data logs of everyone in the country. You can measure contacts and spread that way but it's a privacy disaster. The decentralized approach tells authorities and users if they've been near someone who later on marked themselves as infected. The data is much more limited but still accomplishes the main purpose.
[1] https://covid19-static.cdn-apple.com/applications/covid19/cu...
This whole system works on advertising packets. Beacons are non-connectable, aptly named.
Your phone can be connected n number of BLE devices and also appear to be n number of peripherals itself. No hard limit that I can think of, usually just depends on the stack.
But this isn’t that. This is your phone pumping out <CONTACT: I am 7733> and listening for other people’s phones to say <CONTACT: I am xxxx>.
I can think of no stack that has a connection limit and after that stops allowing for reception of advertising packets.
Advertising is different, and not limited, but it is not classified as a 'connection'. My understanding is that advertisements are simply broadcast, so there is no bidirectional communication.
Yes. That’s what I said, beacons are advertising packeting with the connectable flag cleared.
You misunderstood, there is no bidirectional in my post. Just two transmitters and two receivers.
How are they going to get that with either model being discussed? There is no location data being transmitted. In fact there is no data at all leaving the phone until you get ill. And if they could deduce it from some sophisticated analysis of codes sent and matched, it would be far, far easier from the geolocation data users happily donate to Google/Apple free-of-charge 24/7.
> In fact there is no data at all leaving the phone until you get ill.
Source? Everything I found that could be interpreted as a statement in that direction sounded like it was part of a description of the Apple-Google approach.
In particular, I wonder if the APIs exposed to non-system apps let them rotate the Bluetooth identifiers, of if this will cause the phones to beacon their non-randomized Bluetooth equivalent of a MAC address nonstop. (The Apple-Google proposal covered this by randomizing that address too.)
It's easy to do on Android (though somewhat unreliable because the Android Bluetooth stack is utter shite).
On iOS it is more tricky, but as I recall it is possible if your app has a widget on the home screen. This is what Chrome has to do for the physical web:
> Germany had been in line with NHSX, but its government announced on Sunday it had switched tack to a "strongly decentralised approach".
Today's Stratechery (https://stratechery.com/2020/more-on-apple-and-google-german...):
> What is worth noting is why Germany changed their approach:
> > Germany as recently as Friday backed a centralized standard called Pan-European Privacy-Preserving Proximity Tracing (PEPP-PT), which would have needed Apple in particular to change the settings on its iPhones. When Apple refused to budge there was no alternative but to change course, said a senior government source.
> This is exactly what I was driving at in Coronavirus Clarity: tech companies are the ones setting the rules, not governments.
Is there more context that might imply that Google wasn't playing ball?
Many of us probably think ridiculous the people who are jumping to reopen businesses (and states) in the interest of economic activity, at the cost of putting people's lives at risk.
Why, on the other hand, is privacy so important versus saving lives if a more effective (but slightly less private) information gathering mechanism could be implemented?
How do we judge one not worth the risk, while the other is?
In this case however it's a reasonably safe and effective system vs an pretty unsafe but slightly more efficient system. To my mind there's a clear winner there.
Individually: you can sell your privacy for some temporary security. But you can't sell mine.
Governements will abuse anything, and will never let a good crisis go to waste. It's not a question of if, but when. We still have the "temporary" Patriot Act in the US, while countries like France still live in a "temporary" permanent state of emergency years after it was "temporarily" instaured.
I do not trust google - but I trust government even less, because when caught with their hand in the cookie jars, at least companies have to clean their act, or face loss of customers.
Governments, not so - due to the rigidities preventing immigration.
They have far fewer tools to make a contact tracing app happen, when that app needs to be voluntarily installed by everyone. So doing things like turning it into a surveillance system (even if it's just because they want better Covid data) when other countries aren't, is just increasing the risk that the public turn it down and the whole thing fails.
And "this app is bad and you shouldn't install it" can spread really, really fast. A few weeks ago my extended family wanted to do a video call and someone suggested everyone install House Party. The day we were going to do our first call some weird tweets went viral saying that app was hacking people's banking apps and other accounts. I'm not sure what came of that, the accusation makes no sense, but our use of House Party was cancelled because there was something on Facebook saying don't download it and how are non-technical people meant to distinguish it really when basically everything you can click through to on Facebook is a scam?
If something like that happens then you really need credible people to be able to push the messaging that this app is vetted, people can trust it, it's safe. If all the background noise is about privacy and similar concerns, then negative messaging can get a lot of cut through with nothing pushing back. I'm pretty certain nobody in that family chat who saw those Facebook posts will ever install House Party, and I'm pretty sure a few well placed Facebook posts going viral with no credible voice telling them otherwise could stop them installing any contact tracing app as well.
They can get businesses to enforce the requirement for them. Want to enter the grocery store? Be prepared to show a QR code from the tracking app, or you can’t go inside.
The most effective time to try to create a pervasive surveillance system is when people are afraid.
Also, there's no evidence that a more invasive system is "more effective". If a privacy-preserving system is equally effective, there's no valid argument. And in any case, if a privacy-preserving system is effective enough to get community transmission under control (bringing R below 1), that may suffice.
People worry about their own privacy, but they should worry about the protection of people engaged in politics - not (only) political activists but (also) "professional" politicians.
These data is an absolutely fabulous weapon to ruin the public credibility of, say, a competitor for the next poll. Or you can use them for blackmail. If you can't blackmail your opponent directly you can always look at what their family members are doing.
The possibilities are so numerous that it's hilarious. The irony is that the MPs who vote those laws seem not to be aware they are shooting themselves in the foot.
Privacy is a human right. Before given up on it, you have to make sure that a) it is temporary and b) the benefits are real (is it an effective way of preventing something bad etc.)
Iron-clad proof a minister violated some lockdown restrictions.
The location of someone hiding from an abusive partner.
The new name of someone in a witness protection programme.
The identity of a defendant in an important but secret trial.
If you want real privacy, it has to come from getting the right privacy aware, privacy understanding, people in power. Anything short of that wont make a whit of difference.
So, given the existence of a privacy-preserving option, it is extremely dubious to be pushing a privacy-destroying option for the sake of a small amount of extra data and flexibility.
Given the past record of our beloved governments, I'm certain that, as War on Terror, this will persist forever, to also protect children, you know.
It just amazes me how short sighted people are, more so because, I assume, it's mostly people from USA...
The best of all worlds is where the government says, "look, our responsibility is to look out for your health AND your other fundamental rights, and so we need this, but we want it to respect your privacy too". Which is what governments who choose DP-3T are saying.
Consider every Middle Eastern country; China (Xinjiang, Tibet etc); India (Kashmir etc); Latin American countries that have cozy relationships with gangs and cartels; Russia; even the USA with ICE and other agencies.
Do you really think Apple and Google should be giving information on their users to those governments? They can't possibly say "stronger contact tracing for Canadians, but not for Mexicans" - it has to be one global standard.
Why not? Apple and Google could just as easily say, "Only countries that meet the standards we set get access to more data."
On one hand, it seems like the HN community seems okay with giving Apple and Google the power to set norms on technology policy that apply worldwide (e.g., what level of potential privacy loss is acceptable to combat a pandemic), but on the the other hand we don't trust Apple and Google to know how to distinguish a totalitarian regime from a government that respects its citizens' rights?
Unlike other countries, the UK has the opportunity to frame this as an NHS-created app, rather than a state-created app. If they're able to do that, then it wouldn't surprise me that the UK's population takes up the app.
Additionally, few people consider data privacy concerns at the best of times. Given the circumstances, I think more people are willing to prioritise public health over privacy concerns.[1] So, they seem to have judged that the richer data trumps the slight reduction in usage.
The combination of these factors could be the rationale behind this judgment call.
[1] https://www.ft.com/content/1752affb-24dc-4ad9-8503-78f9ce1ad... (there's a paywall, so the link below shows a similar poll)
[2] Ipsos MORI poll https://www.ipsos.com/sites/default/files/2020-04/coronaviru...
This looks very orwellian. Does it come from a grass root initiative, or was it started by the government?
https://www.swlondoner.co.uk/i-feel-like-a-proper-londoner-n...
Plus it won't be practical at all to use a centralized solution on iPhone and it may be less practical to use it on Android, so this won't be just a slight reduction in usage, this risk to be a major one.
As long as new cases are very low, manual tracing by trained personell is superior (because of all the edge cases) and sustainable. If you have too many cases (>100s per million) you re better off shutting down anyway.
What are all these apps other than a new kind of surveillance toys, which we know will be force-installed in many countries and will most likely be abused? Maybe it's solutionism that appeals to world leaders for safety theater.
https://www.brookings.edu/techstream/inaccurate-and-insecure...
First, it is important to understand that there are two protocols, both of them based on the work done by the Oxford epi group and others over the years on minimally disclosive electronic contact tracing.
Both of these are a massive privacy improvement on the pervasive surveillance used in South Korea and China. I don't know enough about the Singapore app to comment on that but I would guess this is also an improvement on what they have.
These protocols are DP-3T, on which Google/Apple have based their API and PEPP-PT which many countries including the UK have been building their solution. Until very recently, Germany was also using PEPP-PT but they have switched to DP-3T.
Both protocols make trade-offs between the amount of information which leaks and the usefulness of the tool. That's important. Installing an app based on either will strictly reduce your current privacy.
It is also important, in understanding the privacy trade-off made, to understand the degree of new privacy loss from either framework. We are already pervasively geolocated based on our phone position, this just adds a possible layer of precision to that data. If GCHQ wants to track your movements, they do have tools which can do that relatively effectively already.
Both frameworks use pseudo-random rotating keys which are exchanged over Bluetooth.
In PEPP-PT a central server manages a rotating private key which is used to generate a set of time-gated ephemeral IDs for each device. Devices exchange and log these IDs.
When a health authority determines that someone is infected, they issue them a key which allows them to upload all their logged IDs to the central server. The server is able to determine who the infected person's phone has logged a contact with and notify those people. A random sample of additional people also receive notification messages which their phones are able to discard as invalid decoy messages.
In DP-3T, the keys are generated on the devices and IDs are stored only on the devices. If a central server authorises you to do so (based on a confirmed diagnosed infection), you broadcast the IDs of all the devices you have been in proximity to. All devices regularly download a list of IDs and check the list for one of their own rotating ID numbers. If they match, the user is notified and is able to pre-emptively isolate.
The second approach reduces the consequences of a nefarious central operator but at the cost of sharing more information with more people (since everyone sees the list of possibly-infected IDs). In other words, even in privacy terms, this is not a perfect approach either. That information can be used to carry out re-identification attacks and reveal infected users if certain conditions are met.
From a privacy point of view, I think many people would prefer the latter (possibly allow malicious attacker, if they are able to do certain not-so-easy things to determine that they were infected) since most people in the UK will not consider that deeply private and secret information about themselves. Many of my friends who got it have posted about it on FB, twitter, etc. The former, which gives a state actor more information seems like a greater breach of privacy.
However, it is worth considering why the NHSX team has made this decision, there are epidemiological reasons to significantly prefer PEPP-PT.
First, it allows tweaking of the notification algorithm over time. DP-3T only allows notification of everyone in the contact with no risk indication, it's binary.
Second, the greater information on the infection graph available to the central authority allows for better aggregate contact measuring which may shape increasing or decreasing distancing measures much more quickly than is currently possible since we currently have to use measures that lag considerably.
DP-3T requires more data exchange and on-phone calculation but I'm not convinced that is a convincing argument against it.
I tend towards selecting the solution with greater protection against state data collection and the fact that it will have API support and will therefore likely be able to run with a lower power requirement means that I would select DP-3T over PEPP-PT but I'm not the one who has to make that decision and I would love to see the internal decision making document. I do not think it is so obvious as many people are making it out to be.
Seems like false connections could be spread more easily than the actual virus, no? I would hope this has been addressed somehow but if not, have you ever met people? People* will always figure out a way to break stuff given the opportunity.
*Valid for some subset of "people".
"8. Who will create the apps and where do I find them? Public health authorities will update or create apps which users may install if they choose to participate. Google and Apple will make available, as normal, the public health authority apps for each region in the Play Store and App Store."
[1] https://covid19-static.cdn-apple.com/applications/covid19/cu...
The app take up will be poor and they'll start using the goog/appl data 'alongside' the centralised app, eventually sidelining the centralised app altogether.
But the contractors will have been paid and will continue to be paid.
Seems Like Carole Cadwalladr has already joined the dots...
@carolecadwalla Let’s add another data point. Faculty won this contract back in August, we now know. That’s when NHSX new £250m lab announced. Yet Faculty decided to divulge this news on March 13. Day after SAGE meeting Cummings attended with Ben Warner - brother of Faculty founder, Marc
https://twitter.com/carolecadwalla/status/125488742826086809...
Is the NHSX planning to try and force Google / Apple to change their plan and build the app the way that they want or are they proposing that they will develop a different app?
The only difference between a centralised and decentralised solution so far as I can tell is whether or not we end up with massive centralised databases of every social contact between people who are not infected. Collecting that data seems completely unjustifiable to me, given that it is by definition unnecessary.
That's a really interesting statement. Could you elaborate on your thinking? Under what form of government do you live? Why do you feel Apple or Google is more trustworthy than your government?
* tracking app
* social distancing
* self quarantine
* lockdown
Life is not a video game. There are no game designers able to decide that tracking apps somehow work, for instance. Can you please not downvote my post?
People here who make proverbial hammers are liable to want to hit nails, without considering if it is necessary. Especially considering the lockdown and that you can't get tested.
Trouble is, as soon as the data leaves these shores, it falls under the usual Five Eyes spying loopholes.
I had one of those Youtube surveys 'Do you trust Apple, Google etc with your health data' - Not very much thankyou!
So the thing you are fearful of is actually happening because the NHS plan is the route they are choosing.
In that way it's similar like e.g. location APIs work - the device handles the resolution and data processing for you, but there still needs to be an app to retrieve it and do something with it.
Hence your original question isn't applicable in context of APIs they've designed.