Massachusetts health notifications app installed without users’ knowledge
play.google.com
play.google.com
gov.ma.covid19.exposurenotifications.v3 nor gov.ma.covid19.exposurenotifications installed. I turned off auto-updates in the Play store (Settings -> Network preferences -> Auto update apps -> Don't auto update apps) and went to sleep. This morning I woke up with a cheerful notification that Google can help with COVID notifications and gov.ma.covid19.exposurenotifications.v3 installed -- the app was pushed overnight over explicit instructions NOT to update (sure, one can say auto-install != auto-update, but it is worrying that forced pushes can happen even with every single relevant UI switch turned off).
adb logcat seems to have the following relevant lines:
06-19 09:27:54.481 1689 1990 I PackageManager: Integrity check passed for file:///data/app/vmdl1074248108.tmp
[..]
06-19 09:27:55.580 1689 5456 D PackageInstallerSession: Ignoring abandon after commit relinquished control
[..]
06-19 09:27:55.649 1689 2530 W BroadcastQueue: Background execution not allowed: receiving Intent { act=android.intent.action.PACKAGE_ADDED dat=package:gov.ma.covid19.exposurenotifications.v3 flg=0x4000010 (has extras) } to com.google.android.packageinstaller/com.android.packageinstaller.PackageInstalledReceiver
(+ lots of other similar intents)
After that the package immediately becomes active: 06-19 09:27:56.539 1689 13571 D ConnectivityService: requestNetwork for uid/pid:10450/30673 NetworkRequest [ TRACK_DEFAULT id=1249, [ Capabilities: INTERNET&NOT_RESTRICTED&TRUSTED Uid: 10450 AdministratorUids: [] RequestorUid: 10450 RequestorPackageName: gov.ma.covid19.exposurenotifications.v3] ]
06-19 09:27:56.540 1689 3625 D ConnectivityService: NetReassign [1249 : null → 102]
[..]
06-19 09:27:56.833 1689 3750 E JobScheduler.Background: App gov.ma.covid19.exposurenotifications.v3 became active but still in NEVER bucket
So no, it is not just "oh those people opted in and just forgot".That setting could be what caused the install
How could the publisher MA Department of Public Health do this themselves, or why would Google allow this?
If Google is pushing it themselves, why the Massachusetts one?!
They never learn from Solar Winds, do they ?
I have used Glasswire and am pretty happy with it (no affiliation) because it allows me to block individual apps from having internet connectivity, and can configure it to notify me the first time an app tries to connect.
Of course, the problem is that it's a hassle to have to check and block new stuff, or unblock when I need to use something (e.g. Uber).
You can understand it with an OS update. It's the new shiny thing that comes with bunch of stuff and this new one has this new app.
However, getting it without action on our own part feels very wrong. Even with games, you would receive a pack or something that you can take action to activate. When it's happening without our action, it messes up with our sense of control and continuity.
If was very creepy to have an album injected in my library. A socially inept blunder that I bet Steve Jobs would have never done.
By the way, I can't believe he has died 10 years ago. It feels so recent.
If they had simply made it free to download for 24 hours, or pay-what-you-want donated to charity, few would have complained, and it would probably have generated a lot of positive rather than negative publicity.
The installation of this app, even done with good intent, open a lot of questions on what should be possible or not to be done by government and corporations.
When you get a device with pre-installed, uninstallable, or auto-installed apps. What are the rules?
> "By enabling this service, you can be quickly notified if you’ve likely been exposed to the virus by another MassNotify user, allowing you to reduce risk to your loved ones, seek medical attention, and slow the spread in your community."
In this case it seems that the same goal could have been better achieved by SMS that do not depend on the brand of your phone. The dependency on proprietary app stores and OSs seems a risk for the continuation of a free and reliable communications.
The only thing that is impossible to achieve without an app is to allow the user to select contacts to whom send a notification. Corporations like Google, and Apple know the list of all your contacts. So, it seems that the intention of the app is to reduce friction and send notifications as easy and effortlessly as possible to avoid that procrastination causes people to delay the warning.
But, instead of the silent install the government could have spend money in advertisement campaigns to assure a correct amount of installations. It costs money, but, people pay taxes so the government can engage on this type of initiative at a scale. This could have been a very good alternative, even if it means increasing the budged. Medical emergencies are worth the investing.
While installing an app without users consent can be as questionable as you want, the point about these apps are not the notifications itself but about the contact tracing which is achieved through the bluetooth functionality. also, sending sms messages has other privacy concerns that the tracing apps have tried to avoid from the very beginning. having a person phone number can lead to eventually identify that person while that internal trace id it might use, won't.
Having someone's phone number allows you (via the phone company) to trace their location at any time, forever. That is much worse.
No wonder it's not being adopted by those who should be adopting it, but just being used by vigilant young tech savvy and already covid safe people.
So not only are only a small number of people using it, these people are least likely to make a difference using it.
"Contact tracing respects your privacy and does not send your location to the cloud.
Instead, your phone makes up a new random name every 15 minutes and broadcasts it to nearby phones. It remembers the last two weeks of names it used, as well as the last two weeks of names it heard from other phones.
When someone catches COVID-19, they register it in the app. Their phone then uploads the last two weeks' worth of names it used to the cloud, where other phones can download the data. The names aren't connected to their identity, all they represent is someone who caught COVID-19.
If your phone finds a match between a name it has recently heard and the online database, it sends you a notification. After 2 weeks the data is erased, so you are only notified if you were near an infected person in the past 2 weeks.
Since the random names change every 15 minutes, nobody can track you or know that you are the same person as last time they saw your phone. The data is only stored locally, so after it is deleted two weeks later, there is no way to go back and recover it."
How's that?
(Edited because without the intro sentence it sounded like I was trying to imply the parent didn't get it; that wasn't my intent.
It's a more fundamental understanding of stuff that's hard by those who are most at risk. The old, the vulnerable etc.
It's the old digital divide idea. My neighbor doesn't have any internet connected devices, for example. But she would benefit much more from the app than 40 of her mask wearing, young, self isolating, working from home fellow city inhabitants.
You're right that it's not easy to explain, but surely we can come up with something that gets the idea across? :)
Very non-technical people are not familiar with the basic concepts involved.
"Makes up a new random name and broadcasts it to nearby phones" is something they'd struggle with if they never heard or thought about random number generators, don't understand Bluetooth etc.
Also don't underestimate learned helplessness. Many will stop reading if it looks technical because they "can't understand that sort of thing. " Many such people never ever read such lengthy step by step technical documentation. It seems to them as a quantum physics experimental setup description sounds to the average programmer.
Learned helplessness is so real. My partner works at a help desk, and I constantly hear stories of older folks just mentally shutting down as soon as she has them open the start menu or a settings menu.
I even see it in myself, a super curious neophile software/hardware hacker. Sometimes I'll come across some particularly arcane API docs and it's like my brain just goes "tl;dr" to the whole thing and tries to immediately find a way to avoid interfacing with it.
That mental switch of "ah this is overwhelming, eyes glaze over" is all too easy to trip, even if you push through it and it really is not that bad after the fact.
It's easier for them to just refuse to participate and dismiss the topic as irrelevant, than to take up the game and then perhaps be seen as "dumb".
And this state of affairs is actually quite unnatural. The natural course of things over the millennia was that older people are more experienced and can give direction and advice to the young ones. Sure, this is still true in some "soft" topics, but the generational gap in understanding how the modern world works has never been so large.
This very much feels like justification for victim blaming.
Here's my crack at it for fun:
Exposure Notification apps are a privacy preserving technology to help prevent the spread of COVID-19.
They don't collect or log any location data which is what makes them private.
Instead, a phone equipped with the app will continuously log and broadcast random tokens that change every 15 minutes.
Nearby phones with the app will take note of the token and the signal strength, while broadcasting a token of their own.
Each day the app downloads a public list of tokens that have been shared by people who have tested positive for COVID-19.
If your phone has been around a number of these tokens, it will notify you to get tested and self-isolate.
If you test positive for COVID-19 yourself, your doctor will give you a key to enter into the app. Entering the key will upload your tokens to the public list.
While exposure notification apps do preserve privacy, they are limited in effectiveness without widespread adoption. Additionally they are not a suitable replacement for traditional contact tracing.
You can't now expect them to be rational and trust us with: "don't worry we know privacy is bad, but THIS privacy breach is okay. Again trust us this is because of covid, we're the good guys."
This is misleading, but it is made so because one could potentially use data harvested through those APIs to infer your location (for example, if an app has a map of wifi networks, knowing which networks are around allows it to infer your position)
Alternatively phrased: “only upon government request does the person’s phone upload…” with the implied promise that such request will only come as a result of a CV-19+ test result.
It is very difficult to explain to people that are not curious about the technology and all they hear is 'tracing = tracking = no privacy'.
I imagine this is why this app has been silently pushed, but in my mind just having it available and active on phones does not help you that much if the same users are also not aware and actively reporting their infections. So you will have a very small group that consciously install it and when they get infected they report; a lot larger group will get a notification that they have been close to an infected individual. I suppose they hope that by showing those notifications then people that subsequently get tested positive will be curious enough to find out how they should report in, etc. It's risky especially seeing this backlash about silent installations...
[1] https://covid19-static.cdn-apple.com/applications/covid19/cu...
But this is literally true. This is an app pushed to people remotely without their consent or even knowledge. People cannot trust the claim that there is no privacy gotcha involved in this, especially when previous attempts seem to have opened the log of this information to all installed apps:
https://themarkup.org/privacy/2021/04/27/google-promised-its...
You cannot trust them when they say that the app respects your privacy.
That's going to be hell to explain though, as you've already mentioned.
What? Many many bad people seem to somehow have my number. Practically daily I get an SMSs saying "I've been transferred $5000 to the please login to confirm your transaction .." or some such. I block but they keep on coming. Now, I think I'd rather the person who was responsible for these SMSs to have my phone number than a freaking app running on my phone, especially an app that was basically snuck on without consent.
HN crowd has fallen pretty far. Used to be WE build the things that make our lives better and now the top comment is calling for some ethemeral they to come up with legislation?
That’s BS. And, antithetical to any builder/havker ethic.
We build the world we want.
Even back in the day when you could convince a public payphone to work for free by whistling the right way, that kind of interference in a public communications channel was enough for the powers that be to get worried. Now? Now phones are effectively universal, and every government can afford to pay developers to insert obfuscated backdoors in open source code, while the richest could do the same with the hardware from the silicon wafer up to the finished product. And they do, because they want to keep their power.
Just as you go to war with the army you have rather than the army you want, if you seek to improve our security and freedom you have to use the political power structures that exist rather than the ones you want to exist.
What can we do? I have no confidence that Congress will act in my best interest. Congress has some "partisan deadlock" but somehow I feel confident Intel's payday will go through without a bumpy ride
> U.S. senators propose 25% tax credit for semiconductor manufacturing (reuters.com)
https://news.ycombinator.com/item?id=27561238
We can't even get a modest broadband Internet infrastructure bill passed.
> Widespread fiber-to-the-home deployment would make a bigger difference for more Internet users than Starlink. President Joe Biden pledged to lower prices and deploy "future-proof" broadband to all Americans, but he's already scaled back his plan in the face of opposition from Republicans and incumbent ISPs. AT&T has been lobbying against nationwide fiber and funding for municipal networks, and AT&T CEO John Stankey expressed confidence last week that Congress will steer legislation in the direction that AT&T favors.
https://arstechnica.com/information-technology/2021/06/starl...
> Biden's pitch to build "future-proof" broadband technology is also facing opposition from broadband providers who don't want to build fiber-to-the-home networks in rural areas. Just before Biden announced his plan, AT&T said it opposes subsidizing fiber-to-the-home deployment across the US, arguing that rural people don't need fiber and should be satisfied with Internet service that provides only 10Mbps upload speeds.
https://arstechnica.com/tech-policy/2021/05/biden-cuts-35b-f...
I have not met a single programmer / computer scientist who seriously defends the CFAA and yet we cannot find the votes in Congress to repeal it.
Shorter version though: campaign finance reform, oppose voter suppression, and ranked-choice voting.
How about applying common sense?
― René Descartes, Discourse on Method
- Albert Einstein [0]
0: https://quoteinvestigator.com/2014/04/29/common-sense/ yes, this CAN be attributed to him
The first group’s common sense says “don’t install”; the second group’s common sense says “install via subterfuge if necessary”.
It's not like Richard Stallman hasn't been warning of this sort of thing happening for decades - the GNU project exists for a reason, and we should use their code for general purpose computing.
This absolutely does not work. Here, the NL gov tried this and almost nobody installed the app, despite it using the privacy-safe google/apple API.
My reason was that I was not convinced by the PR that it is actually privacy safe. Just repeating "it uses a safe API, trust us/Google/Apple" was not enough for me.
The subcontractor that made the app did dump some source code on GitHub saying "see, we have nothing to hide". However it was very obviously not the same code as the app published on the Play store (for start, it had a different version number), it had a cleared out commit log, etc. Questions about that went unanswered as far as I know.
I try my best to prevent COVID spread, wear a mask, got vaccinated as soon as possible, etc. I think it's more likely that the thing with the app was just developers not wanting to bother too much with things they were not paid for than anything nefarious going on. However it raised enough red flags for me that I was not comfortable installing the app on my phone.
https://www.iccl.ie/news/serious-privacy-and-data-harvesting...
An excerpt:
> While Android users can, in theory, opt to turn off Google Play Services, users of the Covid-19 contact-tracing app in Ireland cannot turn the surveillance off if they want the contact-tracing app to work. This means the collection and use of this data is unavoidable for people who wish to use the app.
> The data shared includes long-term, unchangeable identifiers of the phone users, including their phone’s IP address, WiFi MAC address, International Mobile Equipment Identity (IMEI) number, SIM serial number, phone number and Gmail address, as well as fine-grained data from other, potentially sensitive apps, such as banking, dating or health apps. This is data which, when considered together, has the potential to draw a very detailed map of our lives and activities.
This story was posted to HN last year, and received a tiny fraction of the upvotes of the story promoting the Irish / Google / Apple app's privacy features. Which would explain why you are downvoted, despite having been proven correct well over a year ago.
Still, the point I was making is that Google absolutely lied about what their app was sending; and people who distrust them are more than justified to. The privacy virtues of the Irish app in particular were the subject of much lauding - when it was shortly after :proven: to be bullshit, that story got less than 1% of the traction.
It's the rest of Android that's the issue.
The point is that installing the contact tracing apps doesn't track you any more than before, neither on microg+fdroid than on a google stack.
I would find it quite amusing if someone submitted a gdpr complaint saying that unnecessary data collection is not optional.
We’ve never had televisions in the house, but I finally broke down and bought a television so my kids could watch Disney+ on the big TV. The first television I purchased was a Samsung, and it came with these apps that I could not uninstall, did not what, and in fact used storage space that I couldn’t do anything about. I put it back in the box and took it back to the store, and got an LG. Very frustrating experience.
It is not a new technology at all. It is the same old one that looks new and shiny, but is complete shit because the software doesn't behave.
CalyxOS: https://calyxos.org/ Privacy-respecting Android distribution that replaces Google spyware with MicroG, so you can have your cake and eat it too. Most everything will work as you're used to, but it does still talk to Google to make that happen.
GrapheneOS: https://grapheneos.org/ Very much like Calyx, but extra-hardened and with no MicroG. No involvement with Google at all.
LineageOS: https://lineageos.org/ The successor to CyanogenMod, will work with many different phones. More privacy and control than stock Android.
There are also many others: Sailfish, Replicant, e
Hardware-wise: CalyxOS and GrapheneOS run best on Pixel 3, 3a, 3XL, 4, 4a, 4XL, 5. The path of least resistance is to get one of these phones and run CalyxOS (if there is an app you need to use that needs Google services like Firebase Cloud Messaging...note that many that can use FCM will run fine without), otherwise run GrapheneOS.
You can also buy a Librem 5 https://puri.sm/products/librem-5/ If privacy and security and hacking are really important to you.
Or a pinephone: https://www.pine64.org/pinephone/
(Important note: I'm not from US)
(Google's data collection isn't much of a concern for me anyway because I block all ads and analytics — so even if they do collect something, they have no way of showing me ads)
I'd argue you should still be concerned about data collection even if you're successfully blocking ads. It doesn't worry you that some super-powerful faceless corporation tracks your every move in the real world? It's one of those things...it won't be a problem until it is ;-)
> Have you thought about looking in to the problem yourself, or maybe just throwing some coffee money at the devs who are?
The problem with this particular thing — making a free software, non-Google NFC payment app — is that it's a regulatory hell and requires partnering with banks. No way an individual would be able to pull this off. Also probably no way to keep it open, I'd be surprised if there are no NDAs involved.
As an alternative, you may get a Curve card (https://www.curve.com/) to regain some of that convenience -- it can connect to several physical cards just like Google Pay does, but itself is a physical card.
I ordered (and paid for) one in October, 2017. It might ship in October or November of this year.
It's not supported by CalyxOS: https://calyxos.org/get/
It's not supported by GrapheneOS: https://grapheneos.org/faq#supported-devices
It's not supported by LineageOS: https://download.lineageos.org/
It's not supported by Sailfish: https://shop.jolla.com/
It's not supported by Replicant: https://www.replicant.us/supported-devices.php
Librem 5 is 8-9x more expensive than my current device: https://shop.puri.sm/shop/librem-5/
PinePhone seems more promising, but the battery capacity is lower, as well as the other specifications are (slighty) worse: https://pine64.com/product-category/pinephone/?v=0446c16e2e6...
I feel like that perhaps calls for an asterisk to be added to your statement:
Fellow humans, there are alternatives*!
*As long as your device is one of the supported pieces of flagship hardware and/or you get a device specifically for it.
Which is unfortunate, because a lot of those devices won't be as affordable. I bought my phone for just over 100 euros, in part because it has a recent enough OS version and is pretty tough.I feel like this situation won't improve until manufacturers get their crap together and make devices based on more open standards which may or may not ever happen. I still dream about the same level of hardware support that GNU/Linux has (with proprietary drivers), where most distros just run on most hardware.
I'm happy that PinePhone seems viable as a daily driver (as long as certain concessions are made) and to be honest, their SoC offerings also seem extremely affordable even when compared to the likes of Raspberry Pi, for example: https://pine64.com/product/pine-a64-lts/?v=0446c16e2e66
That said, a lot of what was offered (alternative OSes) are not feasible alternatives in many use cases, such as when wanting to escape the dominance of Google with an existing device that has regular consumer hardware, particularly those that are already in the budget segment. Being able to install a new OS on any phone would be awesome, but sadly there hasn't been an effort, legislative or otherwise, to ensure that it's possible - right to repair seems to address some of the hardware aspects, but i've seen nothing like that for software (like mandating the use of open bootloaders and for manufacturers to publish drivers).
> Or, make a sacrifice yourself and develop the missing support for the phone you fancy.
This isn't feasible either, since many people like me simply won't be smart enough to do so, won't have the time to do so due to their current life responsibilities or both. That suggestion is good in spirit, but is not something that can be suggested to the common folk as genuine advice.
> I for one am happy they exist and will be glad to shell out 8-9x as much money for a promise of better privacy.
I am happy that you are able to do that and my hat's off to you, since "voting with your wallet" is indeed a good option. However, short of supporting a few content creators on Patreon, i'm unable to afford to live like that.
Buying expensive hardware like that would mean that i'd have to sacrifice any sorts of savings/investments that i could make that month, and it would cost a significant chunk of my salary (which is around 2000 euros after taxes per month). It's reasonable when you have decent savings or income, but that's not my situation and that's not the situation of many people out there.
> There is no reason for having a load of tracking on your phone, it is there just because its OS was developed by an advertising agency.
Ergo, that reason is the current stranglehold by the dominant powers that be within the industry, lack of interest/motivation for any of them to provide more open solutions and perhaps something to do with the reasons behind why AOSP can't just be a drop in replacement for Google's Android offering that could just be installed in ~15 minutes and would just work (consider migrating PCs from Debian to CentOS, or vice versa, which often works like that).
I applaud the efforts of people like you and others who invest in these technologies, but for the rest of society, we'll just have to wait and see how things play out, perhaps buying the budget devices when they become available. In that regard, ARM architectures overall seem to be promising, maybe some day all of what i'm saying no longer will be relevant in any way.
Btw, I hear FairPhone 3+ with e.foundation OS is a good choice too, if you want to avoid Google but still need Android. No first hand experience though, and it's still a few hundred euros.
(this is US ebay, but I assume prices are similar)
I think Calyx still supports Pixel 2, but you've got to trade off the likely length of continuing support against price, of course.
Ulefone doesn't seem to be that popular -- it's not even listed among phone brands on the XDA forums (https://forum.xda-developers.com/all-forums-by-manufacturer). If you want to have a €100 phone with LineageOS support, you definitely can (and do note that the LineageOS website lists only the "officially" supported models, not the community ports).
Hi [my name],
In order for MassNotify to be available to users in their phone’s settings, an update was made by Google that resulted in some users seeing MassNotify appear in their app list in the Google Play Store. Apologies if this caused any confusion.
The appearance of MassNotify in the app list does not mean that MassNotify is enabled on your phone. The presence of the app merely means that MassNotify has been made available as an option in your phone's settings if you wish to enable it. For more information about this, please see this help center article from Google: https://support.google.com/android/answer/10775533
You can see whether MassNotify is active by going to Settings -> Google -> COVID-19 Exposure Notifications. The “Use Exposure Notifications” toggle at the top of the page will show you whether MassNotify is active or not. From this screen, you can also enable or disable MassNotify at any time.
If you have any further questions about this, or anything else related to MassNotify, please don’t hesitate to reach out and we’ll be happy to help.
Regards,
[name]
MassNotify Help Desk Team
www.mass.gov/massnotify
For information about MA COVID-19 resources visit www.mass.gov/isolate
It's honestly not that far off from the truth. Just because google uses your phone as a personal playground all the time doesn't make this instance any more or less outrageous. If this is what it takes for it to be perceived as outrageous as it is, then fine.
The fact that Google and the government worked hand in glove to do this doesn't make it less disturbing. Arguably it's more disturbing.
that's essentially a remote-code-execution backdoor to all android phones?
For Apple as far as I know the most you can do is buy the app on desktop and, if the device is configured that way, it will receive the new app. This means it’s limited to new purchases and by the device’s settings.
I've since de-googled my phone and sacrificed some apps that require google services, but this whole thing shows (to me) that it was the right decision.
The entire "updates" culture is essentially RCE backdoor (botnet) functionality for "trusted" tech companies.
Consent, where it is actually explicitly obtained, never rises to the level of "informed". That's because even if a user "consents", she still cannot see what is in each update.
In my case the maker of my motherboard installed a persistent “self-repairing” (i.e. difficult to uninstall) from yet another third party. Naturally, I will not buy a product from them (MSI) again.
Another way to put this is: windows update will install malware w/o user approval in the background.
It's a different mechanism from Windows automatically loading drivers and/or the vendor's malware when you plug in a device.
In this case nobody actually installed this app by choice!
You can consider installing microG also as an open-source minimal implementation of Google Play Services if some of it's functionality is absolutely necessary for you to keep.
ISPs mandate certain capabilities of the cellular modem + the simcards (remember java cards? that ran java? they still exist as simcards!)
Government RCE is still 100% on the table regardless of whatever software your phone is running
Generally why privacy roms don't support more than 1 or 2 brands total, I guess.
There are also platforms with strict division between the seperate parts of hardware, la pinephone and the librem5
There is a chasm between "a state actor throws an 0day at you" and "Google remotely installs an app on your phone". The latter is done at scale. The former is expensive, risky, and used relatively rarely.
If you're organizing a protest movement, it's totally reasonable to factor government 0days into your threat model. For more boring people, running GrapheneOS is a great way to reduce the attack surface they expose to the advertising and mass surveillance industrial complex.
And this is like, literally a state actor installing an app in this case?
Modems are often isolated by being connected via USB, or if on your SoC the modem has DMA then it's isolated via IOMMU groups.
SIM cards have to implement the E911 feature which allows 911 operators to toggle a cell phone into "stay online no matter what" mode.
Some SIM cards have additional apps installed on them, which allows attacks like SIMjacker and WIBattack.
1) http://ramtin-amin.fr/#nvmepcie, http://ramtin-amin.fr/#nvmedma (the two articles are separate but the first provides incidental context for the second) the iPhone 6 kinda maybe sorta didn't dot the Is and cross the Ts with the MMU side of things. So, USB is awesome in that the failure state is "probably can't RCE".
2) I read a comment on here, which I should be able to re-find, but hn.algolia is not cooperating, suggesting that the system design of a particular AGPS implementation (a few years ago) interposed the GPS in between the CPU and the cellular radio such that the GPS SoC could do HTTP requests to grab its almanac that all of Android, down to the kernel, had no idea about.
IMHO this level of security paranoia is at the end of the day a micro-optimization. For any given device, you're looking at maybe two or three dozen Things Containing ALUs™ (often buried inside subcomponents buried inside other things); one or two concentrations of several billion transistors; and an unknown proportion of manglement, incompetence, cost-cutting, internal compromise (because guarantee there's none), and Agreements™. Honestly: give up, and declare that whatever makes you feel better is enough.
If Google is asserting non-contractual rights, I'd like to know what they are.
Edit: I edited this comment because it was rude, and that was not my intent.
The governing law that would protect people is a lot of things, and ToS is the least of it. The Wiretap Act applies, for example.
I'm afraid I disagree. Google running code on your phone implies it believes you have consented to that. That consent was not given in the app store, so it must have come from the ToS.
Consent is an exception to virtually every protection that exists: Wiretap Act, state wiretapping laws, the CFAA, and state computer trespass laws. Remember, consent is the difference between a home invasion and a dinner party.
So it seems that Google would have to cook up a pretty implausible stopping principle to argue that whatever allows them to do this does not also enable the hypothetical I described above.
You're making out like code is code and there aren't already existing lines and stopping principles, which just isn't true on its face.
Not the law. Google having root access on 2.5 billion android devices.
The law didn't allow Uber to greyball either. It did though.
This is a risk Google fully recognizes - it's why Google prevents f droid from updating apps one by one without user input. That's a privilege reserved exclusively for google play services.
Of the partners in this, I think that the source of authority waa almost certainly the other one. It’s not Google, but the State of Massachusetts, whose authority is likely involved.
Anything in the name of "improving our services".
One possible way: There is a daily job run in the Play Store called "daily hygiene" that performs various configured tasks based on device state and device targeting. It would not be difficult to add some code to install this app for MA users, then push it with the next Play Store update. I am very unpleasantly surprised that this app was installed from a policy perspective, however.
Uh, yes? That is and always has been core functionality. You can click "install" on the Google Play website on your laptop and the app will magically appear on your phone, if both devices are signed in to Google. I triggered this behavior accidentally a good 10 years ago when I got my first Android phone, and it gave me the shivers - it really drove home the point that Google had root on my phone, not me.
In fact, this entire behavior is so normalized on phones we now have a special word for the process of downloading an app and installing it manually, the way we do on PCs: "sideloading".
Yes, of course, but this isn't a technical issue. Look at the webpage that this hn page references. When people say, "an app was installed on my device without my consent or knowledge," the exact method the device used to listen isn't important.
The first issue is that Google software allows non-authorized software installations. The second issue is that a government forced the installation of the app. The technical specifics are just implementation details.
How does the thing know you're a Massachusetts resident?
People who have the contact tracing setting disabled are reporting they still got the app, so the obvious answer seems not to apply.
Is it just getting installed on any device that enters MA? New England states are pretty small, and there's a lot of crossover, especially with states like Maine and New Hampshire, which wouldn't take this very well.
Or, if you have a layover at Boston's Logan airport, do you now end up with its contact tracing app?
It’s the scarier version of the free U2 album.
The question here is about what mechanism Google used to install an app, can it be disabled, and what other kind of apps Google is capable of installing silently on the devices?
But it also brings up the false sense of security, a floppy drive could just choose to ignore the switch and write anyways, just as the phone could secretly write the firmware.
When you go to your phone's settings with this update, there's an option to enable COVID-19 Exposure Notifications. When you turn it on, it prompts you for your location and will download your region's app that uses your phone's new capabilities to connect to the appropriate health authorities.
Massachusetts just opted into this program in the last couple of weeks. I'm honestly not sure why they did it so late - this would have been helpful earlier. Apple iPhones also have this capability, including interoperability with Android phones, and iPhone users in Massachusetts are also able to turn on this setting.
Now, if someone can actually prove that they didn't opt into the COVID-19 Exposure Notifications, then I'd be concerned. But my guess is they opted in when it came out, but there was no app for their region, so nothing was downloaded and the feature did nothing. Then, Massachusetts rolled out the app now and lots of people who configured their phones earlier in the pandemic got a new app. They granted permission for it, perhaps months ago.
- view network connections
- pair with Bluetooth devices
- full network access
- run at startup
- prevent device from sleeping
Android 6.0 introduced requestable permissions, were critical permissions had to be requested (and could be denied) at runtime.
At the same time it removed all modals for non-critical permissions.
My cynical side believes that the reason for it not being as visible as other permissions is that platforms profit from the ad-driven app model, which itself heavily relies on an apps ability to access the internet.
That could also be why stock roms do not allow users to disable full network access on a per app basis. (...like, for example, the camera permission.)
For example, just trick a user into clicking a hyperlink to another app like a browser which does have full internet access, and you have successfully exfiltrated any data in the URL.
I mean sure, you could do that, but it would be complicated, conspicuous, tiring for the user and you would still only get one-sided occasional transfer. It could exfiltrate data, albeit suspiciously, but it wouldn't work for ads .. which are the likely motivating factor.
Other motivating factor may be tracking, which google and vendors want to do, but I'm not sure what the stance would be on others tracking their users.
So far what I guess is:
- This is likely a government action via telco and not something done via Google* (*Unless they've opted into a program like the one you stated)
- These phones being affected COULD BE all Carrier Locked phones which have specific terms to allow such behavior.
To me, this is pretty clear cut violation of Google's Device update policy and could be considered Malware or stalkerware (by their definition): https://support.google.com/googleplay/android-developer/answ...
https://support.google.com/googleplay/android-developer/answ...
-----
I think we should all slow down on putting Google for full blame here and focus on Government abuse and overstep of powers.
I have no memory of ever opting into the program you describe, and it isn't the type of thing I would normally do. It's possible I guess.
In any case, the way they did this is creepy. There was no icon for the app; I had to look in Settings/Apps & Notifications to find it. And neither the official state press releases nor the few local news stories about it mention that the app was installed without notice. They use vague, lawyerly language about how it can be "enabled".
Then they'll be just like Google, Fecebook, Amazon, etc, etc.
There are two routes here. One way is to deal with it the European way, i.e. to try to fix it by a legal framework. The other one is a technical solution like Purism, which is very far from mainstream still. The sooner people realize they have a problem, the sooner they start organizing to find a solution.
You don't find measles outbreaks in rural Mississippi. You find them in Washington, New York, and California. [1]
So it's pretty rich to label someone as an "anti-vaxxer" for refusing the experimental, emergency-use, mRNA jabs, when that person has never demonstrated even the slightest hesitancy about receiving or administering every other approved vaccine.
1. https://en.wikipedia.org/wiki/Measles_resurgence_in_the_Unit...
quick question: what made you put the labels conservative and racist together?
also, a liberal eating granola bar might be stupid, but their actions do not put anyone else in danger. an anti-vaxxer however is a risk to the society in that they are an active and potential host to a disease in circulation.
This incident and your comment reminded me of a story Bezos mentioned in his interview about the time Amazon deleted 1984 from kindle. The analogy he made makes me wonder how can we compare what happened here to what Amazon did..
“Without any notice or warning just electronically go into everybody’s Kindle, who had downloaded the book and just disappear it…so it would be as if we walked into your bedroom in the middle of the night, found your bookshelf, and just took that book away”
Updated to add: well I'll be, an hour after this comment and seeing the link show me that Mass Notification was installed, I was prompted to opt-in appropos of nothing.
I reverse engineered what this does in practice on pinephone modem (Quectel EG25G), for example, and there are pre-compiled binaries there for tmobile and vodafone that process their particular OMA DM flavors, download some configuration and code from internet and run it under root on the modem's SoC ARM CPU. (that's still isolated over USB from the main pinephone SoC, but obviously not good) It's also thankfully disabled by default, but if you google for oma dm android, you get reports of this protocol being used still.
Whatever it does on regular Android phone depends on how well it is implemented on android. Regular phones don't have two almost-isolated SoCs like pinephone, so oma dm client would probably run on the main SoC, and all depends on how secure that binary blob is or what it does/allows the operator to do.
Quectel software is a bit of a turd, so I woudln't take from this that operators can run random code they make the device download under root user, using this protocol. Most proprietary software like this is pretty shit, so I wouldn't feel warm and fuzzy safe on random Android device either.
I did get a notification when it got installed but I thought it was just a push similar to amber alerts. I didn't realize it installed something at the time.
Still, exposure notification was never turned on.
This app seems to use Bluetooth to track potential violations of 6ft personal space and notify people if someone from that list later gets a covid positive test. Whatever the noble goal is I do not want it on my phone, this is creepy!
I'm curious to know if there's any MA Android users that previously removed Google Play, and if they still have the app or not. My guess is no?
You can only disable it
So I decided to check if I was in fact opted in and I was not opted in. Everything was off and this app was still installed without my consent. I do have automatic UPDATES turned on, but that shouldn't tell Google to just push whatever they want to me. You should probably edit your post saying your speculation is wrong.
I don't know what kind of proof you want, but I 100% never opted in.
This is very rampant in India. Operators keep pushing crapware like Linkedin app, clash of kings, etc for money from app vendors.
Personally, I run Android. It is an OS. It is ok. Not great not bad. I don't really care what other people run, I just hope it doesn't treat them to poorly.
Are you using Mi phone?
I've reset it to factory settings and put in a Vodafone SIM. The next time I looked though the installed apps I saw some Vodafone Services app that I didn't install. It couldn't be removed either.
So clearly, either Google with play services or the carrier over the baseband modem can install apps without user consent.
Is there any way this can be avoided? Do open ROMs like carbonROM or LineageOS protect against this?
Other comments mention embedded Java in SIM cards, that's possible, but I'm not sure.
Are you sure that's an actual Android App and not just the SIM Application Toolkit[0]? On iOS these show up under the Carrier menu in Settings but on Android it shows them as if they were an app, even though it's something running on your SIM card (they are backwards compatible and show up way back on old feature phones).
At the end of the day, there likely wasn't actually anything more than a package ID installed on user devices. It didn't opt anyone into exposure notifications, and it most likely didn't include any executable code.
Logcat also shows that this isn't a Google Play misconfiguration where it would show details about an application as if it were installed. Executable code was installed and run on my phone.
06-19 10:55:21.977 1192 1609 I ActivityManager: Start proc 10474:gov.ma.covid19.exposurenotifications.v3/u0a418 for service {gov.ma.covid19.exposurenotifications.v3/androidx.work.impl.background.systemjob.SystemJobService}
06-19 10:55:22.032 10474 10474 D LoadedApk: LoadedApk::makeApplication() appContext=android.app.ContextImpl@bfaf057 appContext.mOpPackageName=gov.ma.covid19.exposurenotifications.v3 appContext.mBasePackageName=gov.ma.covid19.exposurenotifications.v3 appContext.mPackageInfo=android.app.LoadedApk@1f755d6https://www.mass.gov/info-details/enable-massnotify-on-your-...
1. this is not active unless activated.
2. Apple too.
3. Not communicated to the users, especially, that a os level update is served as an app install.
Isn't that what this whole Massachusetts thing a step towards? But my point is that the public health program can't really do something when there's thousands of cases, but the lower case count means this can be effective once more.
Because it took time to develop, and now they just shipped it?
Maybe if the US had had a functional federal government prior to January then a national exposure notification app might have been developed, rather than relying on the states to do their own thing. Or not. But it's too late now.
I'm not a USAian so I don't know what the take-up of a federal government app would have been. Probably insufficient given what seems to be the ambient level of distrust and misinformation.
I've been running the UK/English NHS tracing app since the start of the second wave here, and I have no complaints. I'm happy with its approach to privacy, and that I've never had an alert from it despite living in a region with high covid incidence has been reassuring.
Hm. Mandatory XKCD: https://imgs.xkcd.com/comics/tornadoguard.png
A great example is the lack of any kind of proper federal identification service or registry, something that has been brought up several times over the past century and been met with mass public outcry. So instead we rely on social security numbers, which were literally designed to be bad at identification.
In general the status quo is that the states handle this stuff instead. Whether it be drivers licenses, school circiculums, road maintenance, and emergency responses to natural disasters. Pandemic response is no exception to this. Sure the Federal Goverment often provides funding and guidance but it's largely up to state governments to actually examine and enforce these guidelines.
The point I'm trying to get at here is a federal contact tracing app was never in the cards, regardless of who the President is. The Presidents powers are largely limited to transient international policy (diplomacy, tarrifs, war, border control) and various congress approved Federal agencies.
They do these things because they can.
where is the actual evidence for this? Both Taiwan and South Korea deployed massive, digital tracking efforts to respond to covid often at the cell-provider/ infrastructure level so the entire population was covered whether they wanted to or not.
Nothing about this was despotic or paranoid, it was simply the correct, swift, and strong response to the situation at hand. Until half of Americans have voluntarily installed a tracing app on their phone, if they even know how to do it, we're five years into the pandemic.
Defaults matter. There's a nice example from organ donations in a study conducted by Johnson & Goldstein[1]. When you ask people to opt-in, even if you send everyone a letter personally, only 30% do. When you switch to opt-out, 90% stay in without any resources expended. I would like to think the first obligation of a healthy democracy is to the health of her people. What gives rise to despots is governments failing exactly at that, providng essential functions, being harmstrung by excessive checks and mistrust.
In the USA, nothing is more permanent than a temporary government program, keep that in mind.
>"...was beaten by a prison guard and left with permanent eye damage."
https://www.washingtonpost.com/nation/2021/05/13/capitol-rio...
https://www.politico.com/news/2021/04/19/capitol-riot-defend...
That's the current climate surrounding a single politically charged incident. There's a long history of abuse, from the COINTEL program, extraordinary rendition, torture and current events. Yes, we should absolutely be concerned - regardless of the partisan takes.
>"...Arar protested that he only had a casual relationship with Almalki, having once worked with Almalki's brother at an Ottawa high-tech firm..."
In fact if anyone is paranoid then it is the public every time the issue of governance and technology converge, because in particular in the US there exists a phobia both to technology as well as government.
The existence of a problem does not imply that any measures taken to address it are reasonable. Child pornography is real. Should the government secretly install an app that scans your photos and reports you if it finds anything suspicious?
because in particular in the US there exists a phobia both to technology as well as government
Surreptitiously installing tracking apps is not going to help with that.
Over in reality, though, the only permissions it has are to use the internet and bluetooth: https://hastebin.com/yexoyuluzu.xml
I think that in this context, this previous issue is relevant.
You can get location in a ton of ways, but I doubt the OS will let you without the proper permission.
Your calculator app has more tracking than this.
The "Don't be evil" days are far gone.
https://github.com/google/exposure-notifications-android
And here is the code for the two services it talks to:
https://github.com/google/exposure-notifications-verificatio...
If I had any ability to execute ideas I would have made the app using raffle / cloakroom tickets as the metaphor.
Every time your phone sees another phone, they get one of your tickets and you get one of theirs.
Then whenever someone gets symptoms, if their ticket book was pink then the government announces “anyone with a pink ticket, stay inside for a week”.
(With real ticket books, there aren’t enough unique colours for everyone but the tickets do have unique serial numbers.)
https://www.feteandpartygameshire.co.uk/wp-content/uploads/2...
This is exactly how the German app works. It broadcasts anonymous Bluetooth beacons, and logs whatever beacons it saw.
If you are infected, your app sends to the server "I saw these beacons then found out I'm infected", and the server updates its live infection list.
The one in Play Store uses Google Exposure Notification Framework of course, but a de-Googled version is on F-Droid: https://f-droid.org/packages/de.corona.tracing/
Especially if it traced back to likely exposure events.
> Exposure notifications cannot be enabled without user consent, so if you have not turned MassNotify on, then it is not active on your phone. However, a recent Google update, which makes MassNotify available as an option in your phone's settings, is causing some users to see MassNotify in their app list. Apologies if this caused any confusion.
>
> The appearance of MassNotify in the app list does not mean that MassNotify is enabled on your phone. The presence of the app merely means that MassNotify has been made available as an option in your phone's settings if you wish to enable it. For more information about this, please see this help center article from Google: https://support.google.com/android/answer/10775533
>
> You can see whether MassNotify is active by going to Settings -> Google -> COVID-19 Exposure Notifications. The “Use Exposure Notifications” toggle at the top of the page will show you whether MassNotify is active or not. From this screen, you can also enable or disable MassNotify at any time.
Now I don't know how to uninstall the app... I can disable exposure notifications, but it appears to be a built-in app I can only see in settings, not on the home screen. Am I missing something? The language is confusing too: "Your iPhone is not collecting or sharing exposure notification data with anyone." It is not collecting data with anyone? Or it's not collecting data at all? Either way you parse that sentence makes no sense to me. This app is also not listed under the Location Services app list, which seems strange... How else would this app work other than by tracking your location?
Anybody know how to uninstall this easily?
For example, depending on your cell phone plan, data transfer may incur high costs, especially when roaming etc. Therefore, owners of cell phones may be interested in limiting it to the absolute minimum.
As I see it, this consideration by itself already should have prevented this automatic installation.
Ex: In 2019, Microsoft added a shortcut Win+Ctrl+Alt+Shift that when pressed, brings up an advertisement to buy MS Office, which I have no use for, and you need to edit the registry to disable the shortcut. I already gave MS thousands of dollars for the laptop, you'd think they could leave me alone if they want me to buy another one.
Although at least with Windows, you can remove most of the damage yourself, which is more than can be said for Android. Quite honestly why does the Computer Fraud and Abuse Act exist if manufacturers remain free to abuse your machines at will?
Ooh, its good to reinforce the idea that users need freedom.
OTOH, "consent" isn't really an informed consent. It's pages of TCs, UI antipatterns and take-it-or-leave-it choices. In practice, I don't think consent is genuinely increasing user sovereignty. It's more about disclosure than consent, currently. Human centIpad stuff.
And somehow installing app without asking is surprising and a problem. You have been already trough far worse in the last year.
The app will NOT show up on your App drawer.
Posting the link for its relevancy only.
Some have speculated that this may only be happening to people who mistakenly (or purposefully) turned on the COVID-19 Exposure Notifications in the Google Settings. But I confirmed that that setting is turned off on my phone and the app still installed silently on my device anyway.
This kind of stuff is out of control and consumers need to seriously stand up to this in court.
If you think this is bad, the commercial apps that have been auto-installing for years, without notifying the user, should have you throwing a conniption.
pub:MA Department of Public Health
No results found.
Is that right?
- view network connections
- pair with Bluetooth devices
- full network access
- run at startup
- prevent device from sleeping
[0]https://play.google.com/store/apps/details?id=gov.ma.covid19...
[1] https://www.9news.com.au/national/wa-police-stand-by-decisio...
Honestly, pushing the app to users isn’t anything to worry about – and in fact something I’d have loved to see other countries do as well.
________
[1] https://www.coronawarn.app/en/ [2] https://github.com/corona-warn-app
This app can actually save lives without sacrificing any privacy, pushing it to users is something that has no drawbacks.
The largest trouble for the German version of the app was that not enough people installed it. Choosing to install it automatically isn’t something nefarious under these circumstances.
That is different. They are pre-installed and I can list them and disable them. They do not install suddenly by themselves months after buying the device. If they did so, there would be an outrage.
> This app can actually save lives without sacrificing any privacy, pushing it to users is something that has no drawbacks.
Yeah, "for our own good". Next time it would be an app that sends an alarm when an excon is near you. And next time it would be an app that sends an alarm when someone who shows dangerous opinions (ie. against government) is near you. No thanks, please unsubscribe me of this Chinese dystopia.
They absolute can do that, and do that. For example, if you switch SIM cards, the phone can (and in some situations will) install whatever crap the ISP chooses.
In my case, inserting a SIM card from ALDI’s carrier used to auto-install some weather, news, and similar stuff. Luckily that stopped recently.
This can happen at any time, actually.
> Yeah, "for our own good".
Sometimes it is actually for your own good. I agree that it can be a slippery slope, but using the available means to save lives is sometimes necessary.
The only risk is governments not returning the power they got during this pandemic, but that’s more of a worry in 3rd-world-dictatorships.
Surely there is a prompt. I never had apps silently auto-install in my phone. If that is true, one more reason to go with the custom rom way.
> The only risk is governments not returning the power they got during this pandemic, but that’s more of a worry in 3rd-world-dictatorships.
In my life I've seen a lot of just-for-emergency-temporary-only laws that become permanent once the outrage subsides. In supposedly first world countries
Nope, Google Play Services does this all in the background. The same happens if Google thinks you’ve reinstalled your device (e.g. by wiping the Play Services data) and it starts installing some of Google’s default apps again, without prompts
So you are putting this app in the same category as spam, at least that's good.
> This app can actually save lives without sacrificing any privacy, pushing it to users is something that has no drawbacks.
I have an app that can save your life, trust me. And give me your email so I can send it to you ;)
Great, send me the source code, I’ll get it released on f-droid and then I’ll install the f-droid version of it, just like I’ve got the f-droid and microG version of the Corona Warn App installed :)
This app might have absolutely no privacy leaks; honestly, it’s too early to know that yet. The code is not published; there’s been no public auditing of the backend data handling practices.
Given that, I see drawbacks.
I did not opt-in to the MA one when prompted on iOS (and it did not install [as far as I can tell]).
Even the freedom-loving large news outlets published their opinions that they would have wished to see some sacrifice of those high morals for at least SOME level of effectiveness.
I have the app and it is a big piece of junk since day 1. My brother is a doctor and is using this app. He has regular direct contact with Covid patients. Do you know how many "high risk contact" notifications he has received since Summer 2020? Yes, you guessed it: 0.
That’s because not enough users use it. About 10% of Germans have the app installed.
Massachusetts deciding to auto-install the app on every device is the logical conclusion if you consider those statistics.
And the TV ad was shown as preroll ad for youtube videos for months, and on TV during every ad break on every channel: https://www.youtube.com/watch?v=Z4fCbuZqo6M
Just the ad budget for this app dwarfed the budgets of some hollywood blockbusters, and yet it still didn’t reach more than 10% of the population
[1] article in German about it https://www.heise.de/news/RKI-Schaetzung-Warn-App-hat-mehr-a...
See here (german): https://netzpolitik.org/2021/robert-koch-institut-widersprue...
I'm surprised your brother has not received any notifications. My partner is a doctor at a major university hospital and has been warned repeatedly to say the least. During the second wave, the Corona Warn App showed low or high risk warnings pretty much every week.
[1] https://www.heise.de/news/RKI-Schaetzung-Warn-App-hat-mehr-a... (German)
The government didn't install it in every phone, but they made it mandatory for business-owners to check that you have the app enabled if you want to enter their premises. Everyone needs to eat/shop, so most people were forced to install the app.
Every grocery store has a greeter at the door to check you have the app running, check your temperature, and squirt sanitiser on your hands.
Having said that, I totally agree that German government should have done more to push the Corona Warn App - but only in public relation terms. I totally think Corona Warn App does not live to its full potential in Germany because it is not installed widely enough. But you just cannot do this by force.
Why are you wishing harm on people ?