About the worst that could come of this is an accidental capture in a crash report.
About the worst that could come of this is an accidental capture in a crash report.
I'm not saying this isn't a problem, I'm in the same boat here, just that the contact tracing app doesn't really add to it.
How is that not the story here?
So.. this data is exposed and available even though they said would/could never leak. Seems pretty cut and dry to me. It is a black and white issue. Accidental disclosure is still a disclosure.
So it's real unlikely that MotoCare is intentionally trying to de-anonymize someone's COVID-19 data by code injection or continuous GPS logging. It is extremely likely and expected that the app is periodically grabbing the syslog as a crash report, and that means Google's claim of keeping your data private now has to implicitly assume that MotoCare, without doing anything special other than its regular behavior, is also keeping your data private. That's not a claim Google should be implicitly making on behalf of MotoCare (let alone on behalf of every app that could hypothetically be installed on your system and is understood to be well-behaved in the sense that it just reads the syslog).
It's really incumbent on a privacy-protecting application to not put private data in the syslog. If it's in the syslog, it's not private (even though it's more private than, say, a notification on the homescreen).