UK’s NHS Covid-19 App
github.com
github.com
My understanding is that in reporting our unique identifiers (and location data?) to the govt servers, this data could be de-anonymised and misused. But what data is actually being reported and how could it be misused?
The bigger issue is potential leaks or poor access controls resulting in a malicious third party gaining access. With the decentralised approach where Apple/Google control access to their APIs, the threat surface is significantly reduced (e.g. contact tracing apps cannot also use geolocation)
Disclosure: Also a Google employee.
>But what data is actually being reported and how could it be misused?
All advertisers already know who I live with, and if I'm obeying social distancing I will only be coming into contact with strangers. Is this data really more sensitive than the stuff we firehouse out every day?
With the de-centralised model, your device tracks who you've seen recently and when. The government would announce the IDs of devices owned by people that had tested positive and your device would tell you if you had encountered any of the positive devices.
The centralised approach makes it much easier for the government to track compliance (e.g. we know 500 people should have come forward for testing, but only 200 did) - but again, complete privacy disaster.
<TinFoilHat>This is being run in 'partnership' with a relative non-entity, who in turn have links to a private American medical company.
Not sure I'm happy with private NHS medical records being slurped up in this way - unless consent is expressly given - which, based on their website that 'anonymizes' uploaded imagery, I guess we'll never know for sure.</TinFoilHat>
Good to see the code for both the iOS and Android clients being posted, as this should prove if these clients can ultimately be trusted.
This is not a stab against the people who developed it, in fact I know some of the people involved in the development of the application and they have the highest ethical standards.
The problem is that in the post-Snowden era, no matter the good intentions behind such projects it is naive to not ask for as many safeguards as we possibly can.
https://github.com/nhsx/COVID-19-app-Android-BETA/blob/43a16...
"In order to use Bluetooth features in your application, you must declare the Bluetooth permission BLUETOOTH. You need this permission to perform any Bluetooth communication, such as requesting a connection, accepting a connection, and transferring data.
You must also declare the ACCESS_FINE_LOCATION permission, given that LE beacons are often associated with location. Without this permission, scans won't return any results."
My understanding is those are still in development and haven't yet been pushed to the world.
https://blog.google/documents/55/Android_Contact_Tracing_API...
(Though that analytics platform itself does do device fingerprinting, inasmuch as detecting phone model, OS version etc -- I assume no individually identifying stuff like IMEIs, but who knows what a bad actor can do with sufficient entropy?)
[1] https://github.com/nhsx/COVID-19-app-Android-BETA/search?p=1...
I assume crashlytics is for crash dumps only, could firebase-messaging pull in firebase-analytics?