(I'm British in case you wondered... sigh...)
(I'm British in case you wondered... sigh...)
Because of protests and massive intervention of experts and digital citizens rights group like the CCC.
Luckily, the government listened in this case. I am somewhat amazed how well different sectors of society can suddenly work together when the situation is serious.
I am not sure why everything has to be compared in terms of all or nothing.
In this case specifically, they knew that they're playing a loosing game since Apple and Google are ultimately the gatekeepers of the gadgets doing the actual tracing.
Thinking that somehow the UK has the individual power to go ahead and reasonably do it's own thing is nothing but arrogant.
ETA: sources in grandchild comment.
I am trusting Kenny Paterson at ETH Zurich on the cost of the Swiss app, since he was involved in developing it: https://twitter.com/kennyog/status/1273612397861842950?s=20
ETA: NYT article also mentions a "secretive procurement process" for the UK app, which sounds a bit worrying.
Sadly this is unsurprising and par for the course for the UK government these days.
Not particularly secretive, just a bit bureaucratic.
Does the G-Cloud procurement website have any details on where the 108M was spent?
[1] Random website I found when googling, grain of salt etc: https://bylinetimes.com/2020/05/08/nhsx-contract-tracing-app...
It's the same strategy non-democratic regimes use ( Trump, China, Russia)
Some of the feedback seems to be frustrating (for those building a system like this) in that it came down to more human factors like people not wanting to receive this kind of news via a message on their phone, and it scaring them.
I think the constant delaying to the app is a real problem, but it does appear to have become a target of pot-shots from all sides of the political spectrum. Despite this, some of the innovation that went into the app seemed to be quite impressive, and I think it's a shame we won't get to see the outcomes of a "well-thought-out" centralised app compared to the decentralised ones. My concern with the decentralised apps is that they are reliant on testing, testing means latency, and given the incubation period of covid, it seems people will be at their most infectious, spreading it to the next generation of recipients, at the time they are notified they may have been exposed.
At least in my view, getting notifications out ASAP is most important given the pre-symptomatic spreading, and the centralised approach seems to both aid that, and help get people able to stop isolating if it turns out they weren't exposed to Covid (i.e. they and others exposed to same person don't have symptoms in 5 days, thus suggesting a false alarm). There was more to the centralised app than purely "centralised vs decentralised", but there's clearly other issues in the approach to handling covid.
Also, only speaking for myself here: The morning the German App was released, I installed it without hesitation or any trace of doubt. It's now running on my [only] phone, which I have 24/7 with me. So within its limits, the App is rather effective. If it was centralized,... I probably would have hesitated a lot, maybe even skipped it or installed it on my old phone (with the GPS disabled via root), and only turn on that phone on demand. What I want to say: Acceptance/wide-spread use is rather important. Of course the gov can [try to] mandate the app to be used (does the UK do that? idk), but then they're opening another can of worms because they're discriminating against poorer people/demographics who might have older phones with poor battery, limited memory/RAM/CPU, or no smartphones at all (e.g. cheap dumbphones).
Full disclosure: I'm sometimes checking with BeaconScope if the people around me are generally using the app. It's not as many as one would like, but it's slowly ramping up.
The UK has no plan to make the app "mandatory", and they are well aware of the demographic issues that would cause, especially with large areas of elderly populations. That's why there's such a focus on the traditional approach to contact tracing.
RE decentralised vs centralised, the trade-off isn't so simple though in my view - the decentralised app requires the creation of a list of the "infected", which is synced to everyone. That means those who get infected suffer a fairly large "loss" of privacy compared to those not infected. The centralised approach "averages" the two by not broadcasting an infected list. It isn't hugely difficult to use time-based correlation with a calendar or diary to work out if a given person was infected etc, if you have access to the list and database (which we should assume in a threat model people have). The question is if this is a design goal or not.
In addition to the app is traditional "public health authority" contact tracing. That in itself is very privacy-invasive though, and I think people are ignoring it in favour of talking about the app - collecting names and contact info of everyone someone was in contact with, storing this into an IT system, then contacting them etc. Data retention concerns etc and privacy risks here seem significant, yet there has been more focus on the apps than on this traditional approach.
I don't think it works that way.
Here the requirements on privacy which became the accepted base for the German app:
https://www.ccc.de/en/updates/2020/contact-tracing-requireme...
Looking at the Apple + Google spec though, this is happening - see https://covid19-static.cdn-apple.com/applications/covid19/cu...
I can't really see a way to avoid creating an "infected tokens" list, if you want a decentralised approach where the uninfected are not interacting with the protocol on an ongoing basis as well.
The UK approach (centralised) was different though, as it was based on the infected person telling the server "who" (based on the tokens) it saw, and they take the steps to notify those users by decrypting the tokens etc, and working out who needs notified.
In the decentralised apps, your phone squawks a changing "identifier", everyone stores the squawks they hear, and periodically checks their list of squawks heard to see if any are flagged on the infected list.
So it's not the case that privacy was never considered by NHSX, just that they wanted to do things that you cannot do without some degree of centralisation. Most importantly they warn you when a contact develops symptoms and then warn you again if they test positive. That would help get at least some people reducing their contacts earlier.
Apparently despite some very clever design on their Bluetooth system they never got it to work well enough.
Have you seen the news about the government terminating student nurse paid contracts early? Right when we need them the most and when public support for health workers is at an all time the high, our government decide to screw them over. I just don’t get the sanity of such a move.
https://www.personneltoday.com/hr/student-nurses-see-paid-pl...
Contact tracing scales extremely poorly. Contact tracing a single case involves a long interview and to the tune of a hundred people to be found and tested; for a disease like COVID you need to catch 60–80% of all infected contacts. Rinse repeat for each newly discovered case. It just wasn't possible in the UK for more than a few hundred cases and in the absence of R-reducing measures, so it was abandoned. And before you make comparisons with other countries, just having a centralised database of addresses makes contact tracing much easier, but it's not a thing in the UK because privacy.
Mass testing requires mass testing capacity, which just wasn't there. And it's not clear how mass testing would make anything better anyway, the policy was to self quarantine on any symptoms regardless of covid status.
The way people behaving already makes clear that the pandemic is over in everyone's heads. You might think that especially then an app would be helpful, but we might be talking about 10% of the population actively using it. They probably didn't get the memo the app is completed. Still, I think this sets an important example of how to develop an app as a public service.
If the German government would have developed such an app without loud input from critics, it would probably look exactly like the one the British tried to create. But having a loud voice around issues of data protection doesn't seem to be bad for software at all.
edit: btw: quite some problems wouldn't have been this large if OS for mobile devices would actually be good. And I don't mean extending Apple/Google "features" for protected memory.