News: 1586861087

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Wanted: An exit strategy from the overt surveillance of smartphone contact tracing

(2020/04/14)


Comment The world seems set to adopt smartphone-driven contact tracing to help detect COVID-19 carriers but regulators need to plot an exit strategy from this new form of deeply personal and intensive surveillance.

The need for that exit strategy is plain because whenever businesses or governments get us all to sign up for data collection, the assumption is that it's for the greater good and giving up a little privacy is worth it in the end. Then, whether sooner or later, that data is always criminally and cynically abused, usually in utterly predictable ways.

Abuse of contact-tracing data is intolerable, because it is designed to be a verbose description of our movements and encounters. That may be acceptable in this moment of crisis, but it cannot endure.

What should we do? Well, one of the big debates in governments the world over right now is how to exit societies from coronavirus lockdown, a tricky decision because reducing social distancing in the name of boosting economic activity has the potential to worsen the health crisis.

So while we're thinking about exit strategies, let's develop one for contact-tracing, too, so that we can plan how to exit the temporary benefits of enhanced surveillance for a more balanced future.

First, I believe Google and Apple could usefully kick things off by making conditions under which they'll deprecate their [1]schemes as part of their plans. That deprecation scheme should explain how, once coronavirus is behind us, the two firms will expunge contact-tracing from devices they power and ensure similar functions never make it into their app stores. Their operating systems will need to alert users whenever any activity that looks remotely like contact-tracing is in operation.

A foundation will be needed to tend contact-tracing code. Any nation that has built a contact-tracing app could then lodge its code there. The foundation will need to be endowed to fund bug bounties and academic research on all contact-tracing tools.

Carriers may have a part to play detecting and reporting activity that looks like contact-tracing.

Governments that deploy these apps must also be explicit about when they'll be used and when they'll be turned off again.

Above all, we'll need to agree that designate contact-tracing is an "In case of emergency, break glass" tool rather than a tool for routine use. And let's make sure this gets done, because if we don't, the consequences are utterly predictable.

As a comment on our story about [2]Singapore open-sourcing its contact-tracer observed: "We'll soon see similar products being offered by shady security outfits but with slightly different use cases." And if the world holds true to form, we'll also see:

Bad advice given to users who are therefore effectively coerced into releasing their location data;

Authorities neglecting the fine print about exactly what contact-tracing data they can use, and when they're allowed to access contact-tracing data, followed by misuse and insincere promises to do better;

Large-scale leakage of contact-tracing data, followed by insincere apologies and slow reform of the practices that led to the leakage;

Cynical misuse of the data by a social network;

A taboo-busting startup that, like [3]Clearview AI did with mass facial recognition databases, goes where others won't in order to make a buck; and

Ridiculous conspiracies about contact-tracing, possibly accelerated by populist politicians.

It might not be possible to avoid these wholly predictable and utterly undesirable outcomes. But at a moment when it seems our societies are about to be remade in part by government adoption of uniquely powerful surveillance tools, we owe it to ourselves to remake the attitude that has seen us sleepwalk into constant casual privacy abuse. And by doing so, we'll have a good shot at making sure this new form of digital surveillance does more good than harm long after this novel coronavirus's rampage passes. ®

Sponsored: [4]Choosing A Low-Code Vendor



[1] https://www.theregister.co.uk/2020/04/14/coronavirus_phone_app/

[2] https://www.theregister.co.uk/2020/03/26/singapore_tracetogether_coronavirus_encounter_tracing_app_lessons/

[3] https://www.theregister.co.uk/2020/03/09/ai_roundup_march6/

[4] https://go.theregister.co.uk/tl/1936/-8579/choosing-a-low-code-vendor?td=wptl1936

Yebbut...

2+2=5

On the plus side, the wearing of surgical masks by people with colds will become the new norm so that's one in the eye for facial recognition.

What about Google?

Anonymous Coward

Firstly, the article suggests that Google and Apple should be the ones who control when this gets switched on or off. I disagree. Like it or not, decisions over this should be made by national governments (in my case, a democratically-elected national government), not private companies. The article appears to my eyes to suggest that corporations should take decisions over governments, and that has the potential to lead to a very dark future.

Secondly, the article notes that "cynical misuse of the data by a social network" is a risk, but fails to include cynical misuse of the data by the world's largest ad broker, who are also responsible for the software running on 80% of the world's smartphones. And have been known to still collect data even when the "pretty please, I don't want to" switches have been set in the maze of twisty little config settings.

Google are not some collective whose only concern is for the public good. They are a corporation whose only concern is maximising revenue. Any public statements of "Don't be evil" stopped long ago.

Re: What about Google?

Chris G

Not only does it need government input, it needs governments to specifically ban commercial use across the board.

While governments are at it they should also be limiting themselves and their agencies from being able to abuse this technology.

Simon can add to his list Social Services and Local government abuse, as happened before with the RIPA.

Scary and Scarier

Yet Another Hierachial Anonynmous Coward

Whilst Covid-19 is undoubtedly scary, the prospect of users willingly signing up to contact tracing in order to get their life back on track and the abuse consequences of it are even scarier.

It also needs to factor in.....

Not everybody has a mobile phone.

Not everybody with a mobile phone runs google or iphone OS.

Not everybody with a phone has it with them 24/7 - I frequently leave my phone at home when going out, just to get away from it. This particularly the case when going into some public events, like concerts, or maybe restaurants.

Whilst these ideas could do some good, there is a lot of potential for a lot of harm that we will never recover from.

Cynic_999

There is absolutely no doubt in my mind that no real effort will be made to remove or disable any application that is so useful to state surveillance and "analytics" companies. On the contrary, we will likely be urged to adopt it permanently. For our own safety, of course.

Governments need to be explicit...

Ordinary Donkey

UK.gov will inevitably include "... or to protect the economic stability of the UK" into the conditions where they may use this technology.

Or in plain English, if it's worth selling they'll slurp it.

Business opportunity

Pat Att

I foresee a business opportunity a bit like dog walking. I offer to collect people's phones, and take them on a journey, to simulate any desired trip. Be somewhere your phone isn't, and fool The Man.

Anonymous Coward

I will say to both Apple's and Google's credit, they have baked a decent kill switch into their designs. Users hold a unique and private key that is used to generate daily identification tokens. This means two things:

- Without access to the individual's unique key you cannot do pattern-of-life analysis across multiple days. This makes de-anonymisation _very_ difficult. I won't say impossible, but without the ability to spot common patterns across days, in turn allowing you to derive the day, venue, participants etc, it is at least very difficult.

- Without access to everyone's keys (or at least a significant percentage of them), you can't tell which day is which - this means you can't hijack the contact tracing data for "other" research. Answering possibly benign but possibly not benign questions like "which day are people most social on?" becomes impossible.

Assuming that private key is suitably protected and only used during contact tracing activity, the design is sound. Given both Apple and Google have effective root access to our devices and have unlimited capacity to store and analyse information about us, the design could have been a lot, lot more invasive.

My worry here in the UK is that the government's approach is being informed by bullshit merchant powerpoint jockeys like "Faculty AI" and the absolute scumlords at Palantir. They'll be falling over themselves to smash the genie's bottle of privacy into as many pieces as they can so they can hoover up all the post-covid contracts, and I don't think there's any professional or technical body here with enough clout to fight them as they do it.

Tom Chiverton 1

Changing id daily doesn't help, the government knows where the phone was at the end of the day (carrier and local government data) and so has deanonymised not only you, but your whole social graph.

Do you really think they'll give this power up once they have it?

Leave the phone at home

Flak

... and contact who you will...

obviously after we have all stayed at home, protected the NHS and saved lives!

gurmlish, n.:
The red warning flag at the top of a club sandwich which
prevents the person from biting into it and puncturing the roof
of his mouth.
-- Rich Hall, "Sniglets"