Contact-tracing data harvested from pubs and restaurants being sold
thetimes.co.uk
thetimes.co.uk
I don't share my number, it was quite private, I never got these calls, maybe I had 5 calls in 5 YEARS, now I get more than that in one day. Why is this, I think? A lot of restaurants use lists and then just pass them to guests at the tables or make them visible for everyone writing on them. Recently there are places that offer QR codes and individual forms, and it gets better, but having these lists visible, anyone that is at the restaurant can just take a picture of the whole list.
I could say that I entered a different name some time ago and I got a spam call asking "Is this different name?", but that would be illegal and I would get a fine. :)
When one has to become an OPSEC professional just to get a goddamn burger without getting haunted afterwards, something is deeply wrong.
My only regret is that I do still get the spam texts and calls. I am thinking that I should somehow make my current number a google voice number or something so that there can be just an automated system that asks them to press any number to connect. Something that simple would stop 100% of my spam calls because they are all robocall recordings.
I think that, as long as you're okay with paying for a service, it can be fairly easy. It's when you want to do it all yourself that you have to be an OPSEC professional. There is plenty of middle ground of paying someone who knows what they're doing to provide the ability to better mask who you are and make it expensive for someone to spam you. Make them waste their time talking to your automated answering service for a change.
But yeah, it's frustratingly complicated. Some of this stuff just seems like it should be a built-in feature of modern telecommunications. My cell provider should give me the ability to present an automated message for free, and at least block numbers... mine doesn't even let me block numbers, I have to do it at the phone level so I still get voicemail messages. That kind of stuff seems like it should be considered basic service.
Right now, due to COVID-19, sometimes we are sacrificing some of our privacy. But we still have choices, too.
You don't have to go to a restaurant to buy a burger. You can buy a burger at a butcher or grocery store. Or not buy one.
Maybe one of you all that is good at phone apps could make one to fill out the forum automatically. I'm not sure why this already isn't a feature in Google considering they screen calls.
> Just a decade ago, SMS messages in the US cost 10 to 25 cents per SMS. You also got charged for spam SMS. Prices were completely disjointed from the reality of underlying costs (zero for the telcos).
> In the following ten years, the tech giants sweeped in, competed, provided a better service, with better cross-platform support, for zero dollar immediate cost to the end customer -- gained a massive following (think whatsapp), and are now vilified for their "monopoly" and the "harm" it has caused.)
The only thing holding back a messaging-style disruption of voice services is the universal inter-operability of phone numbers. Various apps can be used for voice calls within the apps themselves but they're not compatible with a phone call from a landline for restaurant booking confirmations and such.
Google Voice achieves this and Twilio got a mention in the other thread, but I'm not sure what else is out there (I'm not in the US so it's not a problem I need to solve for myself). Seems that US telco's are still asleep at the wheel in regards to their consumer-level services and will devolve into providing purely network connectivity and losing entirely any of the services that sit atop the network.
What's ridiculous is that such things have become necessary. That there's no (enforced) legislation to prevent selling any and all contact information that passes a receptionists desk.
Even then, SAP is the one that developed it for 15 million. The important bits were already completely by the universities. SAP just made a UI for it - for 15 million euros. That's an insane, absurd price to pay.
Without privacy guarantees people don't use it. If people don't use it the whole system fails.
None of these other grey market data collection firms have to do any of that. One thing I noticed is these guys are collecting data that would fall under HIPPA.
Go ahead do some searches for Hepatitis C and then look at your ads on Facebook.
The vast vast majority of people don't know anything about privacy guarantees and this does not factor into their decisions in any way.
https://www.instituteforgovernment.org.uk/sites/default/file...
So no, you're extremely wrong.
What do people really care about and will actually action? Very different to what you think.
Turns out 99% will use Google and Facebook and crack on despite the tracking and not really care about it.
I mean, yes, I get the strong impression you don't care.
I really struggle to believe that 20% of people have heard of Snowden in any meaningful way to form an opinion.
I'm picturing 20% of the people who live on my street. When I talk to them I don't get the impression most of them follow the news in that much depth. Many have been retired and zoned out from any kind of public life for many years. (Not a criticism - maybe they have other interests than me. Maybe they're happier than me for that?)
> I get the strong impression you don't care.
No, sorry you've imagine that out of nowhere. It isn't implied by anything I've said - I haven't talked about my personal beliefs at all.
I'm just a realist about what the people around me outside the tech and media bubble are reading and thinking.
Do you live on a street in the Valley with 100 Google engineers? Most people don't.
72% in the UK.
>Do you live on a street in the Valley
You don't... really believe in polling do you?
People say all kinds of things in response to polling. That's why polling gets it wrong again and again. For example... the 2016 election.
Guess what: phone my 90 year old neighbours with a question about Edward Snowden... they aren't going to even pick up the phone!
Look at what people PRACTICALLY do rather than what they poll to do. You'll find it doesn't match.
That's correct. The US is currently conducting a poll to decide most of the composition of its government (including some local and many national political positions) and as you claim, the voters will say "all kinds of things".
But the answers stick anyway. Even though they say "all kinds of things" you live in a democracy and those "all kinds of things" decides the rules. Now, given that I'd be trying to maybe get them to say smarter things, but if you prefer to just smirk about it I cannot stop you.
I don't understand where this snark is coming from?
Am I saying something that you don't wish was true?
The reality is... most people out there don't care about privacy nor Snowden. The reality is most of them are trying to make enough to feed their families this week plus pay their bills and don't have the energy to think about anything else. I'm not smirking about it. I didn't express any opinion about it. I'm telling you the facts!
Are you assuming I think this is good? Where did you read that? You've imagined it!
You're confusing a reality check with an opinion on how I think things should be!
This is a bizarre question. They predicted Clinton would win. She didn’t.
People stopped using it because it stopped being a good way to keep in touch with friends and instead became a Bazaare containing every single person you've ever met for a millisecond. People no longer felt connected, and gravitated to more curated communication channels where they could choose who they talk to.
I'm sure people say it's important in the abstract, but not in practice, and not right now.
Covid risks are _way_ lower here than risks of random creeps misusing names/numbers of women...
I'm less affected by those particular risks, but I still use a burner Twilio SMS number and a burner gmail address that doesn't get used for anything else, with plus addressing to help try identify where a leak happened. If that account starts getting spam to nomdeplume+somesmallbar@gmail.com or nomdeplume+someQRcodesigninservice@gmail.com, I might get a smoking gun about who leaked it.
If the spammers are cleaning their lists of that well-enough-known email tracking trick and sending enough smtp to make the address a problem to use, I can just walk away from that gmail account and set up a new one.
I'm contemplating building an automated system of "rolling 4 week validity email addresses" that I can easily enough work out on-the-spot, perhaps month/week-of-month encoding so I'd use nomdeplume-102+randombar@example.org this week (102 being october 2nd week) and only have the addresses live long enough for contact tracing purposes. Perhaps using something t5hat works the same as gmail's "plus addressing" but different enough that spammers list cleaning tools won't know about it. That'd involve running my own mail server though, and the risks here right now are so low (in the single digit cases per day in a city of 5million people) that I'm more motivated to just lie on the contact forms instead...
From the linked web page: "sample size 1006 respondents". Given the UK population of around 68 million that seems a small sample.
"Privacy" is not an abstract generic concept. It is context and consequence dependent.
When "contact data" has the monetary and social value associated with a mandatory 14-day quarantine, people accurately consider restrictions on future movement, not privacy. Those who don't, quickly learn the hard way or from a friend. They don't need the word "privacy", only "don't do that again".
Where I live people put their full names, email addresses and phone numbers happily down on on a piece of paper for everyone to see!
> "Privacy" is not an abstract generic concept.
It is to these people!
I don't get why you're being so snarky - it's actually against the rules here.
People are sharing names, email addresses and phone numbers based on assumptions and models of reality developed over many years, e.g. they have experienced zero observable consequences from all previous sharing of this information. Based on their historical observations, it's not illogical to continue sharing.
But policy has changed in 2020. Now the data goes into databases with a physical consequence: temporary blacklisting from work, play, school, travel, even non-essential medical treatment.
This is why people who have already been contact traced (they are already experiencing and learning the consequences) have been reluctant to give the names of their close contacts, because they know personally the consequences that will be imposed on their contacts, facilitated by their disclosure of contact names.
Until people have this first-hand learning experience, it's difficult to put the data in context. Most importantly, being contact traced does not mean they are sick or will get sick from the (possibly symptom-free and false-positive PCR test) contact being traced, yet they and their contacts would be asked to pay an expensive price.
It's really unfortunate that much of the spreading of Covid-19 may be people with no symptoms, who believe incorrectly that because they have no symptoms, they don't have it, can't have it, present no risk to anyone and certainly aren't spreading the virus.
A friend tells me they have a friend who insists on hanging out because "I can't have it, I don't have any symptoms".
Did they? Ask your woman friends. I'll bet a _lot_ of them are using fake details. They have genuine threat models that the sort of people who decide "lets just have a piece of paper with everybody's name and phone number at the front door" never have to think about.
That being said, I haven't installed the app. I know I "should", but I just do not trust it. I've completely and utterly lost all faith in the government, and although I have the .apk executable sitting in my downloads folder just waiting for me to disassemble it and read through it myself, I haven't yet.
It's almost as if decades of sophisticated spying and "dark practices" have conditioned the entirety of the UK to not trust their government, or something. I use a VPN (or three) at home, tor where appropriate, and root my phone and cut out the Google dial-home. It's a very big ask to get me to install a government-developed application. I just have a deep, probably irrational, fear of it watching everything I do.
(This is for England only, I have no idea what the rest of the UK is up to)
The algorithm the app uses is pretty simple and in your case would be going off like a siren nearly daily. It announces itself in the vicinity via bluetooth and listens for similar announcements. Each device has a random, self generated ID and this is changed regularly. If someone gets a positive test and reports via the app then their ID at the time is sent out. Apps will compare their list of known IDs and times they were seen with the positive list. Basically if your app decides that it saw a "positive" ID for something like 15 minutes or more then it will flag it to you. Then it is up to you whether to isolate, get tested etc. It is not an offence to ignore the app but it is if you ignore an official Check and Trace operative.
This is why you are told not to use it at work. The algorithm is designed to work for people going about "normal" life and your life in the NHS is not normal. It can't possibly work for you or my cousin working as a matron in a hospital. The algorithm basically measures exposure and the current thinking is that 15 mins is long enough to flag a warning. So don't stop and chat for ages in the supermarket/park/pub or whatever to your mates - say hi and use a phone later. If you do go to a pub or restaurant then you have to accept that there is a risk.
If you are worried about the sign in QR code thing not having a sign out until midnight, you can create your own home "sign in" to do the same job. See https://www.gov.uk/create-coronavirus-qr-poster .
There is no need for conspiracy theories! The source code is on Github so no need to mess with the apk. You may want to check that the source generates the .apk though. I'm not a fan of some things that have been done here but the new app is the right way to do it in my opinion. It's very, very simple and has no personally identifiable data involved. It's basically one simple rule of thumb that is good enough to semi-automate part of the C&T function. It is not good enough for your trade though and you should not use it at work.
Stay safe.
Not surprised but still disappointed to learn that they're done by opportunist cowboys. Most things like this in Britain are.
Also, due to the incredible damage such cases cause (people will provide fake data), there need to be severe penalty for such abuses - not just financial, serious jail time.
Edit to add: Art. 6 GDPR is pretty clear -processing data is legal only to the extent that one of the subclauses applies. a) Something hidden in T&C isn't valid consent, b) selling the data is not necessary to fulfill the contract (serving food), c) collecting the data is but selling the data isn't necessary for compliance with the contact tracing obligation, d) selling the data isn't necessary to protect the interests of the customer, e) there is no public interest in selling the data (quite the opposite!), leaving only f) legitimate interest. Anyone claiming that will likely learn that others disagree with this being a _legitimate_ interest that is not overridden by the data subject's right to privacy.
punishment for who? those making the poorly thought out policy or the restaurant / pub owners who suddenly see themselves as the nominated enforcers of these data collection activities? rule #1 should be not to collect data you don't have a safe way to process. GDPR or not this shouldn't even be collected.
My understanding was that the law, at least in England, required for this data to be collected and retained.
I don't like the idea that my OS/browser history basically knows everything about me, but I don't really see how visiting a menu is a serious problem, given that the same systems also generally have my location data too... Is the concern that people who visit restaurants are much more likely to be spreaders of COVID? Could just looking at a menu (implying visiting the restaurant) be enough to implicate me of something?
I'm just left wondering in all this mess. Who watches the watchmen?
See also: https://picturesofpeoplescanningqrcodes.tumblr.com/
There is no problem with making a QR code that links to a menu in PDF format and that would be private & secure. The problem is that the majority of those QR codes would link to a page on the restaurant's website where various trackers are embedded and Zuckerberg is not far away, and most people browse without private mode nor ad-blockers so their browser is known by those trackers.
Scanning a code and putting in your name & address is mandatory at all eat-in places in the UK (or writing it down on a list).
To build on that - It is also true that up to 2 weeks ago, the QR scan 'without giving your name and address' option was not an option and all solutions required giving your name & address.
Specially elderly people with their feature phones, or plain classic ones
But also there's no contact tracing done that way.
On the other hand, I received tons of spam email on my single generic email address (sometimes I'm "weak" because I don't want to login into my email admin GUI etc.. and I just use that generic/main address).
I therefore guess that whoever sells addresses and/or whoever generates spam does care about the email not being traceable to a single source? (they therefore do filter the lists that they have/get?)
It's would be ideal for privacy as well, as phone numbers are frequently used to combine datasets across companies.
Unbelievably, we went to a restaurant last weekend where there was absolutely no service so we had to use their WiFi to even see the drinks menu. Once connected, we had to go through a convoluted process to order and before even being able to place an order, I had to sign up for an account with the online service. This was before we could even order tap water. Food orders were done the regular way, with regular people, in person. They refused to take drink orders (including for water) any other way than online.
Last night my wife and I went out to dinner and neither of us brought our phones (for the first time in forever). It was great. They had to give us regular menus, like the good old days.
I’m going to file this story:
third-party/corporate contract tracing apps sitting on mountains of valuable contact information ask themselves, what should we do with all this free milk?
...together with common _business_ practice from some US companies such as Walgreens and Target who require you to show ID for any purchase of alcohol or tobacco products no matter how old you are (prev age was less than 35). Of course they want to scan your ID for this, which gives them all this State processed and verified PII with extra data not related to age verification—-for free.
Recall in 2013 Target had a data breach of 40m user cc and debit card info.
There is some responsibility for protecting payment data (quick search says it cost Target $300m).
Data on your DL, AFAIK, is unregulated, so what is the consequences of mishandling your contact info?
Unless you're arguing we are innately incapable of doing that? That feels like defeatism.
The problem is the government incompetence and/or malfeasance, not contract tracing itself.
Not so.
https://www.scss.tcd.ie/Doug.Leith/pubs/contact_tracing_app_...
Contract tracing seems to have worked out great in many countries. And you’re entirely discounting the possibility of a vaccine here. Given that a lot of people will have to die in order to achieve herd immunity (and the science isn’t even clear on exactly how many yet, nor on the long term implications for those that survive a COVID infection) I’m not sure blanket assertions are the wisest choice right now.
You can do that if you wish. Nobody is really stopping you in most countries.
I’m not joining you though. And I would bet that I am joined by enough people that normal cannot be achieved.
Also correct and much more important: this virus can have incredibly deleterious effects on otherwise healthy people beyond killing them.
Just because it probably won't kill you doesn't mean it can't fuck you up. In fact I think I'd rather the virus kill me than leave me with permanent damage that destroys any quality of life.
i understand we're anxious and angry to return to a sense of normalcy, but make no mistake, it has nothing to do with sheer will. business cannot survive on the select few "choosing" to be reckless.
it will return when we get it under control and people's perceive risk (whether valid) goes down.
Not true. If they were allowed to fill their theaters up, they'd probably have reopened already. The business decision to not reopen is because they can't be profitable with the vastly reduced capacity that the government is currently mandating.
you might survive for a few months, but if the science is correct, you will just shut down again or people will be afraid to go. broadway can't afford to gamble like that.
It's time to give choice back to the people.
I'm not anti-anything. I'm pro-choice. I'm with you.
[1] - Monday Oct 05 the WHO announced there were 750 million cases of Covid worldwide (see tons of news sources). According to the official WHO tracker there have been 1 million deaths. 1 million divided by 750 million is 0.00133333 or 0.13% IFR.
The solution, and the inevitable return to normalcy will come when people feel protected. That can come with herd immunity, which is nearly impossible (NYC had excess deaths in the same range as the Spanish flu and only has 20% immunity in the population to show for it) or it can come with advanced treatment, therapeutics and at some point a vaccine.
This is a multi year process but the result will be a return to normalcy, as happened with the Spanish flu.