Analysis of SwissCovid app
lasec.epfl.ch
lasec.epfl.ch
By the same logic, this would seem to require all of iOS and Android to be open source. Where does the "App" end and the underlying OS and libraries begin in this requirement?
(This just my understanding from the web page and wikipedia, I'm not familiar with all of this :) )
To justify such exclusion, SwissCovid promoters argue that GAEN is part of the operating system of the phone, or sometimes part of the Bluetooth communication interface of the phone, and that it is not common to require to disclose the source code of such parts. We deny that GAEN is any such part of the phone, at least on Android phones. GAEN is part of the Google Play Services which are independent of the operating system and of the communication interfaces. We could actually run a pre-standard version of SwissCovid on an Android phone which had no Google Play Services. However, this phone had the Android operating system and could use Bluetooth. Furthermore, most of the former DP3T protocol which was implemented in this pre-standard version disappeared in the current version of the app since an equivalent protocol is now in GAEN. We conclude that there is no founded technical justification for excluding GAEN from the components of the system.
"One difficulty of using Bluetooth in phones is that the operating system does not allow apps running in the background to use the Bluetooth advertising system. Hence, to do so,either the app must stay in the foreground, which drains the battery a lot, or the operating system must be changed. Apple and Google allied to provide a standard Bluetooth API which would not drain the battery. Hence, automated contact tracing apps must either be complian twith this API or make the user upset about heavy battery usage."
Singapore's TraceTogether app doesn't use GAEN api and does have this issue [2].
France's StopCovid app uses a different protocol called ROBERT[3], and they asked Apple to allow their app to run in the background[4]. So they also have battery issues.
[1]: https://lasec.epfl.ch/people/vaudenay/swisscovid-ana.pdf
[2]: https://en.wikipedia.org/wiki/TraceTogether#Description
[3]: https://github.com/ROBERT-proximity-tracing/documents
[4]: https://en.wikipedia.org/wiki/Exposure_Notification#Non-adop...
This has epidemiological consequences, as acknowledged by one of the leaders of the DP-3T team to the BBC: https://www.bbc.com/news/technology-52995881
Apple (and Google?) retain higher quality signals than what they make available to the apps.
It introduces new security issues, because Apple and Google have had to make choices that degrade the qualities of the protocol. See Sections 3.5 and 3.6 in the report. The Swiss Cyber Security Centre expressed negative sentiments towards the fact that Apple and Google didn't implement some of the recommended protocol improvements: https://www.melani.admin.ch/dam/melani/de/dokumente/2020/Rep...
Finally, this Bluetooth layer becomes a covert channel for transmitting information between phones. There is a lot that we can't tell from this outside.
See the yellow "important" box on https://developer.apple.com/documentation/exposurenotificati... for some more info. Not sure how this works on Android but I assume there is a similar permissions gate to prevent other apps accessing this feature.
I'm speculating but I suspect the agreement they're referring to is the agreement for Google's proprietary Play Services API. I believe it's possible to compile Android itself and regular non-Google-Play Android apps without agreeing to anything but the terms of the open-source licenses.
Change the system... honor open source principles.
If ivory tower thinking means, improved state of affairs, then.. ok... ? Call it whatever you want haha.
Some consequential parts of the protocol are implemented as a black box.
> A big part of the contact tracing protocol (which was originally the DP3T protocol) is implemented by Apple-Google in a part of the system called GAEN. This part has no available source code although the law requires disclosure of the source code of all components of the system.
Since the first point is separate from that, it must be referring to something else?!
How does that work? Do they mean the Bluetooth MAC or can the users also be traced/identified by third parties through the Apple/Google API?
> NCSC states that "Users can always turn off tracing if they are in what they consider to be a sensitive environment".
Data (location and/or contacts) is either sensitive data or is it not (according to local Laws), the concept of "less sensitive data that I can risk being not protected" as opposed to "more sensitive data that - to be safe - I must exclude from collection by turning off the app" is "crazy".
Example:
1) going to work and back: app on
2) at work: app on
3) at home: app on
4) going out to - say - procure something illegal or meet lover (cheating on wife), sensitive environment: app off
In this case absence of data may be data as well.
FUD - This report is all about Fear, Uncertainty and Doubt and is every bit as dangerous as lying.
I find it difficult to believe that, even among the HackerNews crowd, this point registers near as important as having an easy to use, efficient way to do contact tracing for Covid-19.
Why does every attempt to make the world a better place have to be ripped apart and thrown in the dumpster fire?
A security analysis needs to be more than just an uncharitable read of an architecture that shows it has exposure to scandal or discredit. These apps are going to have issues around data access, custody and control and a lot of others, but the analysis of them needs to be stronger.
That can unfortunately be said of quite a few apps, but it's good that they pointed it out here. In any case, if you're running a phone with Google Apps installed, privacy can only be an illusion.
The content is not that great and the plain text does nothing to make it feel technical coherent or valuable.