6 ms·
It should be noted that your privacy is not preserved if you test positive and need to upload your Daily Tracing Keys to a server. Your broadcast IDs for an ent
by 0xBeefFed 6y ago
It should be noted that your privacy is not preserved if you test positive and need to upload your Daily Tracing Keys to a server. Your broadcast IDs for an entire day can be linked together, making it easier to de-anonymize you. I understand that they use Daily Tracing Keys to reduce the demand of the backend server, but I think it would be better for user privacy if they either reduced the linkable period from a day to say an hour, or used an unlinkable design.
- pintxo 6y agoIn case you test positive, and we actually have the resources to trace your contacts, your privacy will be gone in todays system for sure. As you'll have to provide information about your recent contacts to the authorities performing the contact tracing. At least that's how I understand our local law (Germany). So I don't think its necessarily worse doing it with an App than doing it the old fashioned way. Sure digital traces are always easier to abuse, but then on the other hand, because things get automated, actually less people might get access to your data. Which would be a privacy win. I believe what's even more important than how we design the app, is how we design the legal framework around it. We do need rock solid laws, having enforceable data retention periods, and that limit access to the pare minimum needed. Unfortunately, our track record for the design of such laws has not been too good over the last years.
- 0xBeefFed 6y agoThe difference is that the old system relied on human memory which is fallible, not to mention you can omit details which would lead to further trouble (infidelities for one). In this system the only control a user has is to turn off bluetooth, or leave their phone at home if Apple/Google override the users ability to turn this off.
- skybrian 6y agoI think it's up to you to upload the data? It seems like it depends how the app is designed. The protocol doesn't specify it.
- 0xBeefFed 6y agoThe protocol states that it will upload the Diagnosis Keys, a set of Daily Tracing Keys relevant to your exposure. So in short, if this is the case it forces the user to either upload all their keys or none. I would like to note that a v1.1 has recently been released, my information is about v1.0.
- Reelin 6y agoThe specification (at least v1.1) contains nothing about uploading keys. The API appears to provide only the minimum required for protocol implementation. The ENSelfExposureInfoRequest class can be used by an app to obtain diagnosis keys for the previous 14 days. What an app does with those keys is up to whoever implements it. https://covid19-static.cdn-apple.com/applications/covid19/current/static/contact-tracing/pdf/ExposureNotification-FrameworkDocumentationv1.1.pdf https://covid19-static.cdn-apple.com/applications/covid19/cu...
- 0xBeefFed 6y agoThat does not seem to line up with their cryptography specification, which is where I am getting my information from. Thank you for mentioning this
- gruez 6y agoI thought only the DTKs are uploaded? That is, you can censor your activity on a day-to-day basis but not on an hourly basis.
- closeparen 6y agoUnder what circumstances do you think it would be okay for an infected person to hide their contacts? Surely you’re not valuing your marriage over the lives that will be lost in the resulting spread?
- 0xBeefFed 6y agoIf a user is in close confinement with someone they fear will lash out at them if they test positive, for one. Off the top of my head, lets say you take an Uber home and the driver now has your home address, you don't know if they will try and attack you. This is an example off the top of my head, as other comments in this thread have explained, violence against people who have the virus is happening around the world and is something that must be accounted for in these protocols. Edit: a link to a story from another comment (https://www.washingtonpost.com/world/the_americas/coronavirus-doctors-nurses-attack-mexico-ivory-coast/2020/04/08/545896a0-7835-11ea-a311-adb1344719a9_story.html https://www.washingtonpost.com/world/the_americas/coronaviru...). I hope you can see that this technology can worsen this.
- closeparen 6y agoThe system doesn’t say who your affected contact is, only that you have one. The driver has no way of knowing it was you.
- 0xBeefFed 6y agoIf you have a Bluetooth receiver logging the different IDs you've come in proximity with and when, its easy to deduce who the positive user is by who you were in proximity of at that time.
- closeparen 6y agoAt what time? It could be any user you’ve been in contact with for two weeks.
- burke 6y ago
- TechBro8615 6y agoI can assure you that most people, if they were buying drugs or cheating on their spouse, will omit certain contacts from any “manual” tracing effort.
- Reelin 6y agoI'm not sure if you intended that to be positive (ie tracing might be more complete in some cases) or negative (ie concerns about not wanting to reveal certain data). I'm going to go ahead and respond to the negative interpretation in case any future readers interpret it that way. This is true, but I think a DP-3T like protocol (ex the Apple-Google spec) doesn't actually pose much risk here. The hypothetical drug dealer or other illicit contact can receive a notification that they were potentially exposed to someone that was infected, but in general no one else (a police officer, a spouse, etc) will be able to determine who was in contact with who. In order to link someone to a particular location, you would need to observe their broadcast identifier while they were there and also link their diagnosis key back to them (this is likely to be quite difficult for most actors to accomplish). In order to reveal a contact between two people, you would either need to do the above for both of them or to observe at least one of them at that location and time in some other manner.
- TechBro8615 6y agoI’m sure the protocol is fully privacy preserving, now. But if we give an inch, the government will take a mile. This is about normalizing self-surveillance and isolating ourselves in response to notifications on our phone. Sure, the tech is privacy-preserving now. But who’s to say an emphasis will remain on privacy in future iterations of the technology? Personally, I will not opt-in to this technology, and if forced to use it, I will leave my phone at home. It’s a small act of civil disobedience but it’s a necessary one IMO. It’s alarming to me how so many in tech seem welcoming of, even excited for, this technology. I say this as someone who wrote my senior thesis on a subject related to privacy enhancing technology, so I’m familiar with the ideas.
- Reelin 6y ago
- xfitm3 6y agoIf I keep my phone in a RF blocking bag and remove it only when needed I will have some semblance of privacy. I don't care about push notifications.
- cm2187 6y agoWell, let's keep in mind it is decentralised, so only people who have been in contact with you can correlate it with your location at a given time in the past. Not the whole world nor a central authority. And even is someone goes to that extent to track your identity down, I am not sure that local de-anonymisation is a problem. This is not something like HIV. I don't think there is any social stigma to catching the coronavirus. If you catch it you should self-isolate, and it will be obvious to the people around you that you got it. And if you don't want to self-isolate and want to hide it, what is the point to self declare that you got contaminated on the app in the first place?
- jstarfish 6y ago> I don't think there is any social stigma to catching the coronavirus. "In Mexico, Colombia, India, the Philippines, Australia and other countries, people terrified by the highly infectious virus are lashing out at medical professionals — kicking them off buses, evicting them from apartments, even dousing them with water mixed with chlorine." https://www.washingtonpost.com/world/the_americas/coronavirus-doctors-nurses-attack-mexico-ivory-coast/2020/04/08/545896a0-7835-11ea-a311-adb1344719a9_story.html https://www.washingtonpost.com/world/the_americas/coronaviru... ...and these are cases where the victims don't even have the virus. Disease has always carried stigma. We tend to lash out at things we don't understand. History has seen everything from leper colonies to menstruating women herded into tents. You or I may be able to rationalize it and say "well, shit, the test was positive-- time to self-isolate" but plenty of plebes will use it as cause to incite a witch hunt, especially if a loved one dies from it and transmission is attributable to you.
- cm2187 6y agoOK, that's a fair point, but it would take someone uneducated that believes in the stigma to also be a tech wiz to collect and correlate the data. Presumably the app won't tell you when and where the contact happened (and if so, no implementation of contact tracing is anonymous since the app won't know that you were in a busy bus full of strangers or in a small office with a single colleague).
- red0point 6y agoValid point. DP3T (in one configuration) adresses this and lets you filter out certain parts that you do not wish to disclose. Thus, this then requires you to upload all broadcast identities used in the relevant timeframe, but because of space-related issues is then „compressed“ using a Cuckoo-Filter. This, however, yields false-positives. To eliminate those to a managable amount, it further requires more space. So, this has a tradeoff. Personally I don‘t think that linking multiple IDs in a day is a big intrusion of your privacy (and remember, it‘s only disclosed to anyone for the timeframe that is epidemologically relevant) - full de-anonymization still requires some second channel, such as cameras or the like - which can be linked together without those Broadcast IDs anyways.
- 0xBeefFed 6y agoThe unlinked DP-3T is one extreme, there is a happy medium if developers don't want to use Cuckoo Filters or Bloom Filters due to false positives, which is to decrease the linkable period. If the period was an hour, people could freely share legitimate tokens for their commute, but hide the ones where they had an hour long 1-1 with their manager.
- radicalbyte 6y agoThe thing with Bloom/Cuckoo filters is that you can play around with the parameters and, for example, provide a set of filters for a day in such a way that the app users can do a binary search. It never provides a false negative so all positives can download their set-up filters until they're satisfied. The filter that DP3T are describing isn't that much bigger than the DTK set anyway.
- user5994461 6y agoIt's hard to test positive given the extremely limited supply of tests and all the effort you'd have to go through to get tested. I really can't imagine anybody willingly testing -more so with new invasive tracking- unless they are really ill and in need of medical attention.
- 0xBeefFed 6y agoThe issue is, if your putting the risk on infected users, what is the benefit to them to release their tokens? They are already at risk, this just makes them bigger targets.
- azinman2 6y agoThis is almost never actually the case. Your daily keys are random, so the only way to know it's you is for someone to monitor bluetooth devices near by, and associate those keys with a physical identity... which becomes very difficult unless there's only one other person you come into contact with. In practice, it provides about the best anonymity you could ask for.
- marblar 6y agoThe recorded broadcast IDs can be linked together, but only if they are somehow gathered from all of the devices that have been near you. As far as I can tell, the spec doesn't include recorded broadcast IDs ever leaving the device.