News: 1587105190

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Europe publishes draft rules for coronavirus contact-tracing app development, on a relaxed schedule

(2020/04/17)


The European Commission (EC) has published a document describing how it thinks member nations can best built a contact-tracing smartphone app to fight the COVID-19 pandemic.

Such apps have been adopted by Singapore and India. The UK, USA and Australia have all suggested they’ll soon follow suit. Apple and Google have weighed in, saying they’ll tune their mobile operating systems to help the apps operate, a crucial step as current apps use Bluetooth yet smartphones don’t allow the wireless protocol to operate constantly.

The apps are [1]controversial as their explicit purpose is collecting data about users and then sharing it. But they’re also seen as a tool that will make it possible to loosen lockdowns because, by tracing encounters that lead to infections, they have the potential to make it possible to understand who needs to be in isolation and who can roam more freely.

Wanted: An exit strategy from the overt surveillance of smartphone contact tracing [2]READ MORE

Enter the EC with a 44-page guide to what such apps should do, how they should do it and when they might be deployed.

The document thinks such apps can do their job without recording users’ phone numbers. Instead, it suggests that apps broadcast “a temporary anonymous ID that permits establishing contact with other app users in proximity.” Apps will record that anonymous ID and, if any user that has been in proximity tests positive to coronavirus and consents to having their data shared, other devices that have hoovered up the anonymous ID will receive a notification. The document suggests users could optionally enter other contact data if they’d like more than a notification in case they receive worrying news.

The EC is not in a screaming rush. It suggested timeframe is to stage bi-weekly meetings that some time in May deliver a security recommendation and in June deliver data-sharing standards that help authorities to plan exit strategies.

There’s also a list of safeguards the EC believes the apps must include, namely:

App should be deactivated automatically and all remaining personal data and proximity data should be erased, as soon as the crisis is over.

App should be consent-based with full information of intended processing of data

Location data is not necessary nor recommended for the purpose of contact tracing apps, as their goal is not to follow the movements of individuals or to enforce prescriptions. Collecting an individual’s movements in the context of contact tracing apps would violate the principle of data minimisation and would create major security and privacy issues.

The app should ensure that no user knows the identity of any infected persons or of close contacts of infected persons

In order to enhance privacy and security, proximity data (close contacts) should be stored only on the device, and be deleted after the epidemiologically relevant period as recommended by ECDC (14-16 days). Only after a user has been confirmed infected, the proximity data of that user may be uploaded to the central server and/or the competent health authorities, depending on the system chosen by the Member State.

The ephemeral IDs transmitted between devices via BLE should be generated pseudorandomly and changed periodically. They should neither allow any user to identify the user of the specific device nor to associate multiple signals to the same device.

Pseudonyms should have no relation to long-lived personally identifiable information (PII).

The app should encrypt data as much as possible in order to enhance security and privacy

There’s also a call for independent review of the apps by technical experts, open-sourcing the apps, and a fair bit of commentary about such software being a complement to manual contact-tracing. The document also cites an [3]Oxford study that suggests 60 percent of a national population will need to adopt the app for it to be effective.

El Reg is tracking two European efforts at developing contact-tracing apps: the [4]DP-3T project from Switzerland and [5]PEPP-PT . If there are more we should consider, [6]let us know !

The document is sufficiently prolix and careful to be almost a cliché of the European approach to administration! However it is also as comprehensive a statement of the potential pitfalls and requirements that your humble hack has yet seen on the subject. I suspect it will be more than influential in coming weeks.

One last thing: the document suggests that while Apple and Google have made a splash with their announcement of plans to assist contact-tracing apps, it appears that the precise details of what they’ll offer are hard to divine. The Register suggests this as the first item on the EC’s to-do list is “seek clarifications on the solution proposed by Google and Apple with regard to contact tracing functionality on Android and iOS in order to ensure that their initiative is compatible with the EU common approach.” ®

Sponsored: [7]Choosing A Low-Code Vendor



[1] https://www.theregister.co.uk/2020/04/14/contact_tracing_exit_strategy/

[2] https://www.theregister.co.uk/2020/04/14/contact_tracing_exit_strategy/

[3] https://science.sciencemag.org/content/early/2020/04/09/science.abb6936.full

[4] https://github.com/DP-3T/documents

[5] https://www.theregister.co.uk/2020/04/06/pan_european_privacy_preserving_proximity_tracing_plan/

[6] mailto:news@theregister.co.uk

[7] https://go.theregister.co.uk/tl/1936/-8579/choosing-a-low-code-vendor?td=wptl1936

Meanwhile in the UK...

Dan 55

[1]NHS in standoff with Apple and Google over coronavirus tracing

The NHS is in a standoff with Apple and Google after the two tech firms refused to support the UK’s plans to build an app that alerts users when they have been in contact with someone with coronavirus.

Apple and Google are encouraging health services worldwide to build contact-tracing apps that operate in a decentralised way, allowing individuals to know when they’ve been in contact with an infected person but preventing governments from using that data to build a picture of population movements in aggregate.

But the policies, unveiled last week, apply only to apps that don’t result in the creation of a centralised database of contacts. That means that if the NHS goes ahead with its original plans, its app would face severe limitations on its operation.

[...]

But the new tools, which come in the form of an API that lets developers code apps with special access to Bluetooth, strictly limit the information that public health authorities can gather. Most importantly, a public health authority cannot ask a phone to gather a list of every other phone it has been in contact with.

[...]

The limits will prevent the NHS from obtaining useful information about population flows in the aggregate, tracking “near misses” or receiving information about contacts from people who have opted into the system but not recently checked their phones.

This seems to me to be a tenuous excuse at best. If the government wants population flows, it can already get them from the telecos (cell location data). If the government wants to get people to check their phones, it can push a notification to the NHS app or set a notification to appear at some time in the future.

[1] https://www.theguardian.com/technology/2020/apr/16/nhs-in-standoff-with-apple-and-google-over-coronavirus-tracing

Re: Meanwhile in the UK...

Tinslave_the_Barelegged

> That means that if the NHS goes ahead with its original plans,

> its app would face severe limitations on its operation.

It's rather moot anyway. Such a system's effectiveness must depend on an accompanying testing regime that is rigorous enough to be identifying the majority of COVID-19 infections in a quick enough time. The UK seems to think that unless you're dead in a hospital or a VIP (assuming Johnson and Prince Charles can be so described) tests aren't being done at any useful rate, never mind at the scale required.

And if the system relies on self-certifying COVID-19 symptoms, imagine how the system will be gamed. Certify yourself, then hold your mobile on a selfie-stick closer to others while shopping, out for a walk etc, maybe?

No matter how sensible the EC proposals, and the corresponding support by Apple and Google, this looks to end up as just another NHSX data collecting techgasm.

Re: Meanwhile in the UK...

Anonymous Coward

Now what was all that fuss about in the election about control of what the NHS does being handed over to large US corporations!

We know what you did ...

Anonymous Coward

... last coronavirus peak (and on all of the rest of them as well).

The Oxford paper doesn't say 60% is really enough

LDS

Near the end of the paper, they say something different:

"If this is an accurate picture of viral spread in Europe and not an artefact of early growth, epidemic control with only case isolation and quarantining of traced contacts appears implausible in this case, requiring near-universal App usage and near-perfect compliance ." [Bold mine] It looks far more than 60%.

Moreover without a way to quickly test possible cases, how long it would take to lockdown again a large number of people? How many "contacts" there could be before a case is identified as a real covid one, as long as hospitals can't test enough people? And how many people these have had contacts with meanwhile?

There's evidences asymptomatic and per-symptomatic people are infectious. Without testing them you'd need to quarantine them all. Can they avoid the avalanche effect? Or they would just recommend to watch out for symptoms, which may be ineffective?

JohnG

It is probably worth mentioning that Singapore open sourced a substantial part of their efforts in this area:

https://bluetrace.io/

https://github.com/OpenTrace-community

Gomez Adams

I look forward to installing the Windows Mobile 81 version of the app on my phone.

I look forward to ...

Anonymous Coward

The phone's os hijacking the anonymized data, sending it back to central servers, and de-anonymizing it by cross referencing the various datasets. I presume the intent is that this should be impossible, but no doubt just one small slip in the implementation...

.. also, I'm worried about the orbital mind control lasers. :-)

Titanic thinking

TheProf

Whatever happened to the idea of planning for disasters?

It's not like global pandemics are a new thing. They've been threatening us for as long as there's been life on this planet.

Books, movies and TV have shown all sorts of contagious diseases ravaging the world's population and what has been the result of all this red flag waving? A rather dubious mobile phone app knocked up over the last weekend that relies on people volunteering to use it.

Don't worry. By the next pandemic we'll have sorted out the problems with the app and everyone will be really keen to install on their phone.

In the meantime here are some DIY PPE patterns for you to cut-out and colour with felt tip pens.

Re: Whatever happened to the idea of planning for disasters?

Anonymous Coward

More like, "Whatever happened to the idea of planning?" But here the answer is always the same, short, sweet, to the point: "Fine idea"

I mean, there were, apparently, some lessons learnt post previous (sars) outbreak. At least this is what the politicos in a few EU countries tried to peddle as an excuse to keep the plebs from panic stocking toilet paper.

Re: Whatever happened to the idea of planning for disasters?

Anonymous Coward

> More like, "Whatever happened to the idea of planning?" But here the answer is always the same, short, sweet, to the point: "Fine idea"

Yet another know it all with no fucking clue. Where do you think the 4000 beds and cubicles for the Nightingale Hospitals came from? Do you think they were made to order in 9 days?

Have you tried storing anything in a warehouse for 10-15 years awaiting the next pandemic, let alone face masks and gowns that will be damp and unusable after 3 months? What's that Skippy, he's fallen down the mineshaft trying to retrieve his emergency stock of rectal thermometers?

Re: Titanic thinking

Graham Dawson

There were plans, as a matter of fact. The UK government developed detailed plans for dealing with a pandemic. The only problem is that they planned for a flu pandemic, which would have behaved rather differently to this one, so much of the early response - once the pandemic was known - has been inadequate to the problem at hand.

One big problem with the bluetooth approach

wibblethribble

There is one problem with the BT solution - it only records contacts that are in the same place at the same time. The virus is viable outside the body for a period of time (varies according substrate, temperature, etc.) so the app doesn't cover the use case of an infectious carrier contaminating a surface, which shortly afterwards is touched by another person. At that point the original carrier is well outside BT range so won't be recorded by the app.

Admittedly this is less likely to result in transmission than close proximity, but is a good reminder to wash your hands and avoid touching your face.

iOS update would be a blocker on the Apple–Google scheme

coconuthead

From a quick look around the Apple–Google scheme, it appears it will require an iOS update on the iPhone.

There are probably a lot of people whose phones can run iOS 13, but have been avoiding it because of reports of serious bugs: in the Wifi hotspot, speakerphone, Safari and other important functions. Having a reliable phone is more important than privacy issues at the moment. If I do end up in hospital my smartphone will be pretty important to me!

Apple are quite capable of blocking, and do block, security updates to iOS 12 for any phone which can run iOS 13. There is no reason to think they will do things any differently here.

The Singapore app, on the other hand, just runs on what is there.

I like what I read in this article

Pascal Monett

It seems to me that the EU has once again responded to a situation with the proper attitude and the respect of privacy is visibly paramount in the documentation.

I very much appreciate that the first item in the article is the fact that the app will shut down automatically and the data will be erased at the end of the crisis. It means that the EU very much intends this tool to do one thing and one thing only : help pinpoint actual case contacts, and nothing more.

I have but one question : it took China less than four months to flatten the curve. This app will not be available before June, apparently, and we're already on our second month of containment. It seems to me that, by the time we get the app, we won't be needing it any more.

At least I hope not.

Re: I like what I read in this article

Mark #255

It will be very useful for the second wave following the relaxation of lockdown, and for Covid-20, Covid-21, Covid-22...

Anonymous Coward

They way I see it is for this to work it maybe has to be carrier side and not anonymous. Not everyone will install or be able to install the app and those gaps will allow it to continue to spread. If the app said I had contact with 10 people but I had contact with 20 that's another 10 people who can then go on to infect others if I had it.

The privacy implications of this while it appears they are being considered will most likely fall at the way side as we go along. Like we found out with Prism this will be a put laws in place to cover what we already do scenario. The bluetooth side of this just adds accuracy to what they already have.

Down not across

They way I see it is for this to work it maybe has to be carrier side and not anonymous.

Good thing I still have drawer full of old Nokia Symbian phones. Good luck pushing any crap onto those.

Problem with carriers and governments is that they cant, in general, be trusted.

another nanny state idiocy

Anonymous Coward

First off, my Android phone is so old and knackered that having Bluetooth permanently enabled will flatten the battery in an hour or so, and good luck getting anything new on it (storage full warnings even though it's got two photos for use as wallpaper and that's it...) - it won't even play nice with the latest version of Play Store but I only use it to phone or text 'Er Indoors and those functions still work perfectly well thank you - and she has the Facebook app on hers, so I really don't need to worry about *my* phone being a security risk!

Secondly, " But they’re also seen as a tool that will make it possible to loosen lockdowns because, by tracing encounters that lead to infections, they have the potential to make it possible to understand who needs to be in isolation and who can roam more freely." I assume "understand who needs to be in isolation" means targeted lockdowns of anyone/everyone in a particular area at a particular time as against "a 29-year-old female in this locale has it therefore any other 29-y-o female in the area must be locked up while everyone else goes about their business" - but what happens if the "victim" was in a car at the time and not in face-to-face contact with anyone else? What if some of those people have had it and recovered and can't get it again - they can still carry & transmit it so do they need to be locked down too?

Thank $deity the EU are here to look after us, I feel so much safer. But what's that, the UK was supposed to have left the EU six months after the Referendum - several years ago? Might be waiting for that app for a while then.

Whereof one cannot speak, thereof one must be silent.
-- Wittgenstein