64 karma · joined April 16, 2020
Just be aware, the data is supposed to be in USD, but some people may still be reporting CAD.
This is an example off the top of my head, as other comments in this thread have explained, violence against people who have the virus is happening around the world and is something that must be accounted for in these protocols.
Edit: a link to a story from another comment (https://www.washingtonpost.com/world/the_americas/coronaviru...). I hope you can see that this technology can worsen this.
I guess my original comment is a bit vague. When I look at these protocols I am interested in how large scale adversaries (Nation State) would use this technology, but also small scale adversaries (day-to-day person you are not friendly with). I think its also important to note as others have, that being outed as having the virus does put people at risk of violence in some places.
I would like to note that a v1.1 has recently been released, my information is about v1.0.
This technology is currently being used to track people today. The use of Bluetooth address randomization does not do a sufficient job to prevent this, the only option is to not use Bluetooth.
It is important that people are aware of these risks. I am fortunate to live in a place where I can live my life without scrutiny from the government, but not all are afforded such a luxury.
DP-3T also explains how records are uploaded to a central server and the interactions with health-care providers. Apple-Google omit this part and focus on proximity data collection.
Edit: Formatting + I wrote a survey paper on a few of the distributed protocols and how they defend against linkage attacks (de-anonymization): https://github.com/robertTheHub/ContactTracingSurvey/blob/ma...
One thing I do wonders is if the mortality rate is higher as they counted the number of patients requiring intubation, not those who received it [2].
[1] https://www.epicentro.iss.it/en/coronavirus/bollettino/Repor... [2] https://jamanetwork.com/journals/jama/fullarticle/2765184?gu...
Again, not sure if this is applicable, but the comments made me think of this.
[0] https://www.blackhat.com/us-19/briefings/schedule/index.html... [1] https://i.blackhat.com/USA-19/Wednesday/us-19-Robert-Messagi...
In terms of privacy, small-scale adversaries can deanonymize infected users that have uploaded their [keys by keeping logs] of and limiting who they have come in close contact with.
On a large-scale, adversaries in control of large Bluetooth receiver networks (such as cities performing traffic analysis) can now track the movements of individual infected users over the course of a day. One could argue that this is already being done to track anyone with bluetooth enabled.
In addition, the process of uploading to the backend server could alert adversaries monitoring your network that you (the device using your IP address, uploading to the server IP address) have tested positive for the virus.
I recommend that you look at other contact tracing protocols that circumvent some of these issues by decrease or eliminating the linkability of identifiers, allowing users to censor records uploaded, and encourge the use of network-anonymization.
*Edit Spelling - Source: https://covid19-static.cdn-apple.com/applications/covid19/cu...