How I helped fix Canadaʼs Covid Alert app
seancoates.com
seancoates.com
I'm one of the team that did the initial implementation of the server and iOS app before handing it off to the CDS for the latter part of implementation, and I've been really, really impressed with the CDS. They're a great model for what tech in government should look like.
On a somewhat-related note: you wouldn't happen to be / know who is responsible for the BC CDC Covid results service, would you?
I was disappointed to see this page, which asks for personal information including your PHN, served over HTTP.
Not only that but there is actually a disclaimer saying it's fine to ignore the big red padlock because the iframe uses HTTPS (which is also technically not true as far as I can tell - the iframe _redirects_ to HTTPS though).
Canada is kind of... weird, in this regard. I knew about the CDS, and was on their mailing list (they talk about pretty neat stuff and it sounds like a neat place to work), so this didn't surprise me, but...
So a while ago, we (the company I worked for at the time) had some servers hosted at a hosting company based here in Vancouver, though the servers were in Seattle.
Well, we got an e-mail from our host, forwarding some automated e-mails that they had received from the Canadian government (possibly the CDS, but I don't think so) notifying us that we had open memcached ports (11211) on some of our servers.
I went and checked the configuration, and sure enough we'd had a configuration error, where memcached would only accept one IP address to bind to, but our script had provided two (because the servers had an internal and external), creating an invalid config which was never deployed, so memcached was just listening on [::]:11211, and since it wasn't supposed to be open we didn't have any ACLs on the access routers. We fixed the configuration issue and switched to a default-deny policy and all was fixed, but it was surreal that an e-mail from the government was what tipped us off.
We use bugsnag on many of our client web apps to catch javascript runtime errors and with one of our apps we frequently come across problems that reference javascript functions and variables that aren't ours.
Sometimes it turns out to be a benign plugin, but in many of these cases it is a known virus or dangerous browser plugin that is trying to log keystrokes, mine crypto, extract banking info, etc.
We have gotten to the point where we can often tell them which virus they have, how we know, and include removal instructions. Our app is very expensive so most customers are people who need our tools and use the app everyday, which means we can often tell them when they got the virus too. It's way out of scope for our role in their life, so it's a little bizarre for everyone involved, but the customers seem to appreciate it at least.
I worked on a project with them about 4 years ago, and it was a less than ideal experience. CDS was not entirely at fault, as there were other departments involved, but they were willing to bend on specific details that we (as an outside service provider) specifically recommended against.
It put us at odds contractually in terms of project timelines, but we were pushed between delivering securely or timely, and the stress from all sides for the latter caused a number of people to not only leave our company, but also take leaves of absense on the government side.
I strongly support them as a Canadian citizen, and sincerly hope that they've reached the zenith in that their stated position holds, because the alternative was a downright awful experience.
can you introduce me to someone? i'm working on this currently: https://www.youtube.com/watch?v=t9xFQFkvoLg&
I'm glad to hear that his interactions with them were relatively without friction. A big part of what they're trying to do is lead by example for how modern software development can take place somewhere like the government (Taking a lot of cues from GDS and 18F).
it's funny how small the world is
I don’t see why both the iOS and the Android versions can’t be fully native, besides a desire to have a single codebase. The apps aren’t doing anything fancy, UI-wise. They are basically just integrating with the native contract tracing system framework on each platform.
Dragging in React Native and its giant web of dependencies makes the codebase harder to audit and manage from a security perspective. It’s also a product of Facebook, which is greatly concerning from a privacy point of view.
I still have this app installed on my iPhone and I keep it up to date, but I really wish it was built differently.
Considering how this issue was from a package that isn't included with React Native, this seems like a bit of a stretch.
So while this isn't really the specific fault of react native, it does seem to me to be the fault of a non-native framework that encourages developers to use higher level abstractions rather than system frameworks.
> A remote host is considered reachable when a data packet, sent by an application into the network stack, can leave the local device. Reachability does not guarantee that the data packet will actually be received by the host.
https://developer.apple.com/documentation/systemconfiguratio...
More details in this issue: https://github.com/react-native-community/react-native-netin...
* Reduces development cost
* Provides more consistency for users (simpler to document and explain)
The workflow in our UI is larger than most and we support more languages (including right-to-left language). It's just not complex so - IMHO - it's a no-brainer to build the two out in parallel.
We're also building it in the open and in English - come take a look here: https://github.com/minvws
Disclaimer: I'm working on the server.
Once we're past this it will make a very nice point for study.
Next up, can you please help fix the broken "Alert Ready" Emergency Alert System!!
This is cute, given that Apple "may collect a variety of information, including your name, mailing address, phone number, email address, contact preferences, device identifiers, IP address, location information, credit card information" [0] any time you "download a software update" or "connect to our services".
Where is my fix to opt out of this garbage? When they say "connect to our services", do they mean automatic checks for os updates that all their products do without an option to opt out?
This concern over privacy on the level of individuals 'fixing' things is utter lunacy. You've fixed one of a thousand cuts your privacy is killed with, congratulations :)
https://github.com/cds-snc/covid-alert-server/pull/241
(I don't know Go (-: )
I assume React Native doesn't require CORS, like the web version does?