News: 1587945686

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Australia’s contact-tracing app regulation avoids ‘woolly' principles in comparable cyber-laws, say lawyers

(2020/04/27)


Australia has released its promised COVID-19 contact-tracing app.

Dubbed [1]COVIDSafe , the smartphone app follows the now-established practice of asking people to register their name, age range, phone number, and postcode, and create a unique identifier. That identifier is shared with other users of the app when they come into close contact with each other.

If a user subsequently tests positive to COVID-19, they have the option to notify health authorities. Other users who have had close contact with an infected person are then contacted by health authorities. Close contact data is stored, encrypted, on devices for 21 days, but some data is stored off-device for health authorities to access.

Only health workers can access the off-device data and even then only after initial opt-in and a second request for permission after a positive test.

The app, available for Android and iOS, uses some code from [2]Singapore’s TraceTogther app and uses Amazon Web Services to store registration information, encrypted user IDs, and contact data.

While source code of the app has not been released, a [3]privacy impact assessment [PDF] drawn up by lawyers recommends it be made available. The Department of Health’s [4]response [PDF] concurs, saying it “will be released subject to consultation with the Australian Signals Directorate’s Australian Cyber Security Centre.”

No timeframe for that consultation is offered, nor is there a guarantee the Cyber Security Centre will agree to the release of the source code.

Privacy

The app’s use of AWS has quickly raised eyebrows given the cloud giant is subject to the United States’ Patriot Act and could be compelled to surrender COVIDSafe data despite it being stored on Australian soil. The app’s legal underpinnings, however, appear reasonably sound.

A [5]newsletter from law firm Gilbert & Tobin analysed the legal instrument that underpins the app – a new [6]ministerial determination made under section 477 (1) the Bioescurity Act – and offered the following commentary:

"To the Government’s credit, it avoids the formula of broad discretions and ‘woolly’ principles which have characterised much of the telco data security legislation of the last few years."

"You cannot – to use medieval plague language – be treated as a ‘leper’ because you have decided not to download the app." Not using the app therefore cannot be grounds to refuse a contract, refuse entry to premises, or refusal to provide or receive goods or services

The determination includes what the firm calls a “keep out Home Affairs signpost” that means any investigation into the app’s use can only concern the determination, not possible breaches of other laws.

Security

Without the source code, it’s impossible to make a full assessment of the software. However the app’s Android .APK file, as is the case with all such files, can be just-about-decompiled.

The Register is yet to find an authoritative post-de-compilation analysis, but some efforts have been made and offer cautiously optimistic assessments of the app.

Data is stored locally in a SQLite database using the RoomDatabase API.

This places collected data inside the apps internal storage, a secure part of your phone strictly private to [7]#covidsafe . [8]pic.twitter.com/u8y8mo8WUu — Matthew Robbins (@matthewrdev) [9]April 26, 2020

The data upload is authenticated by a One Time Pin request that is sent your mobile phone.

This is important as all data upload is through user consent only. — Matthew Robbins (@matthewrdev) [10]April 26, 2020

So I'm generally fine with the app. The two minor things that concern me are:

- device-id is sent to API

- the API could give you the same "temp" id over and over again which might allow tracking; a better solution would be for the client to generate the ID — xssfox (@xssfox) [11]April 26, 2020

Bad Apples

Another criticism leveled at the app is that it must be in active use to perform usefully on Apple devices. As Australia’s national mobile phone fleet is dominated by the iPhone – with over 50 percent market share – the app may not collect a lot of useful data.

That’s not stopped a million registrations for the app, according to health minister Greg Hunt.

As at 10:30 PM 1 million Australians have now downloaded and registered for the [12]#CovidSafeapp - please join us and help protect ourselves, our families, each other but above all else our nurses and doctors — Greg Hunt (@GregHuntMP) [13]April 26, 2020

At the time of writing, the [14]COVIDSafe Google Play page counts 100,000+ installs. The next milestone that Google reports is 500,000 and Apple’s app store doesn’t enumerate usage, making an assessment of actual installs hard to determine.

However the app is well-regarded: Android users give it 4.6/5, and iOS users [15]rate it a 4.3. ®

Sponsored: [16]Legacy Modernization: Finding Your Way With Low-Code



[1] https://www.covidsafe.gov.au/

[2] https://www.theregister.co.uk/2020/03/26/singapore_tracetogether_coronavirus_encounter_tracing_app_lessons/

[3] https://www.health.gov.au/sites/default/files/documents/2020/04/covidsafe-application-privacy-impact-assessment-covidsafe-application-privacy-impact-assessment.pdf

[4] https://www.health.gov.au/sites/default/files/documents/2020/04/covidsafe-application-privacy-impact-assessment-agency-response.pdf

[5] https://sites-gtlaw.vuture.net/22/1719/april-2020/client-alert--covid-app-legal-framework---26.04.20.asp

[6] https://www.legislation.gov.au/Details/F2020L00480

[7] https://twitter.com/hashtag/covidsafe?src=hash&ref_src=twsrc%5Etfw

[8] https://t.co/u8y8mo8WUu

[9] https://twitter.com/matthewrdev/status/1254336112371224577?ref_src=twsrc%5Etfw

[10] https://twitter.com/matthewrdev/status/1254336122714337280?ref_src=twsrc%5Etfw

[11] https://twitter.com/xssfox/status/1254342853053968389?ref_src=twsrc%5Etfw

[12] https://twitter.com/hashtag/CovidSafeapp?src=hash&ref_src=twsrc%5Etfw

[13] https://twitter.com/GregHuntMP/status/1254390626453352449?ref_src=twsrc%5Etfw

[14] https://play.google.com/store/apps/details?id=au.gov.health.covidsafe

[15] https://apps.apple.com/au/app/covidsafe/id1509242894

[16] https://go.theregister.co.uk/tl/1936/-8553/legacy-modernization-finding-your-way-with-low-code?td=wptl1936

Cool app, could be very important

PatuTessa

Personally, I support the COVIDSafe idea. We don't have a vaccination yet, so contact tracing is important. The app is very easy to install and innocuous to use. Since it could save lives, great, though I would prefer for it not to use AWS. This puts our data under the control of a third party and possibly a foreign government. Really hard to understand why this is necessary except as a short-term expedient, as there is open source software and locally owned hardware that could be readily used for the data storage required, which doesn't appear huge.

REally?

Mark 65

Only health workers can access the off-device data and even then only after initial opt-in and a second request for permission after a positive test.

Only health workers? Bullshit. How does the system know that? Once the data is off-device anyone with the right skills can access it. FFS.

Given you will only ever get to see the client-side code I'd wager the server side looks more like a junior school kid's my first web-service project.

Re: REally?

Yet Another Anonymous coward

You'll cooperate with the police/immigration/local council dog walking inspector - if you know what's good for you. Therefore they are health workers

Assuming that were not the case. And what happes to people who don't own phones?

RobHib

"You cannot – to use medieval plague language – be treated as a ‘leper’ because you have decided not to download the app. Not using the app therefore cannot be grounds to refuse a contract, refuse entry to premises or refusal to provide or receive goods or services".

Assuming that were not the case. The fact is that not everyone in Australia owns a mobile phone and a significant percentage of the population still do not possess their own internet account either. So what does that mean for countrywide tracking and surveillance? I'm tech-savvy and I rarely bother to carry a mobile outside the home (I don't need to be interrupted with bothersome calls that I do not originate—and also I'm not addicted to social media, in fact I never use it). Does that mean that I could be pulled up and fined by the police for not having a mobile in my possession whilst I'm on the move (in the same way a licensed driver must have a driver licence to drive)?

I'm not alone either: whether it's still a fact or not I'm not sure, but for years and years the presenter of the Australian Broadcasting Corporation's long-running Science Program , Robin Williams, never owned a mobile telephone and what's more he never used a computer but instead he used his trusty manual typewriter. Right, one doesn’t necessarily need to use a technology to be able to understand it—and just because some people deliberately choose not to use some aspects of technology doesn't mean they're Luddites either. (Unfortunately, this is a fact that far too many techies and regulators fail to comprehend.)

Mandating the use of a particular technology throughout the length and breadth of a country not only poses serious moral and ethical dilemmas but also if a government insisted upon implementing it for everyone then I'd suggest it would cost it a minor fortune. Moreover, can you ever imagine even the dumbest of terrorists planning a 'job' knowing full well that government was tracking every move they made—not in the 'anonymous' sense as in the recent past with disposable phones but rather tracking them as identifiable individuals? No way, they'd just not use mobile phones and revert to better planning and timing as did bank robbers of old in the days before mobile phones. It's also likely that operatives without mobile phones of any kind would—for all the obvious reasons—be more difficult for the law to catch.

Re: Assuming that were not the case. And what happes to people who don't own phones?

The Aussie Paradox

Please point to the bit that says it is mandatory and you MUST go out and buy a smartphone/internet/computer?

Pretty sure it doesn't say that, but I may be wrong. I can wait.

Q: how long is long enough?

aaaa

So I'm tempted to wait 2 weeks to see if someone quickly manages to hack the cloud storage.

Or is 2 weeks not long enough?

I'm curious as to everyone's opinions.

Thanks El Reg for the article - genuinely helpful.

The limitations (no watch app, have to keep app in foreground, only works if other people also have their phone and app in foreground, etc.) are so many, that I find it difficult to feel like there is much imperative to load this app. I thought I'd feel some sense of pressure to comply and perform my civic duty - but I completly don't - and aside from a couple of friends who use android and are talking up how important it is to use the app - no peer pressure at all.

"experts" should be ashamed

john.jones.name

Honestly this goes to show how clueless or double standards people like cannon brookes are...

First of all No DNS security... what does that mean ?

DNSSEC would be part of the way to prevent middle box's at schools/gov depts etc from intercepting traffic CovidSafe app has No protection.

(you can host your domain on a DNSSEC aware Name server and still use AWS)

Secondly No TLS cert declaration... what does that mean ?

Things like HSTS mean that putting a TLS proxy would be harder to intercept, Manipulate and account for CovidSafe. The app has NO protection.

(this is basic webserver security that high school students are capable of)

Thirdly it does not work in the background for at least 40% of the Australian population.... what does that mean?

iPhone etc do not allow the gov or anyone for that matter to broadcast in the background so you have to use the Apple API to broadcast continuously, there are several privacy preserving app's that do that however they are not deployed yet as Apple/Google is not active yet... Australian Gov pushed ahead anyway while the German gov went with a private approach... https://github.com/DP-3T/documents

Honestly I want them to do this right so I hope they fix the errors in server infrastructure deployment and change the app to use matching on the client rather than server. The App can still request data from users but it should not be the default or required for the app to work.

Glossing over errors is not helpful, maybe, just maybe Australians deserve better and our leaders will deliver in the future because the "tech billionaires" are not helpful.

Regards

John Jones

Re: "experts" should be ashamed

Yet Another Anonymous coward

Can't they just use the laws of Australia to override what mathematical rules are in the device?

"Here I Go, Again On My Own..." - DLR

Sanctimonious Prick

So. The CovidSafe app stores some data in the USA...

The US cops are hunting an Aussie who apparently stole a bar of chocolate from the NASA coffee shop.

For some reason, the US cops suspect this Aussie installed the CovidSafe app.

The US cops get a warrant to rifle through the CovidSafe app data stored by Amazon.

Then, as a gesture of good will, the US cops give all that data to AU cops, coz, reasons (and they have done that before (can't find a link right now)) - and, that's LEGAL!

No. I will not be installing that app.

Re: "Here I Go, Again On My Own..." - DLR

Anonymous Coward

The CovidSafe app stores some data in the USA. No, it stores it on AWS. Possibly a moot point given the CLOUD act but that has yet to be legally tested,

The US cops get a warrant to rifle through the CovidSafe app data stored by Amazon. Feel free to elaborate how any of the data stored centrally by default would be in anyway useful in this lame example. There is no location data, the identifier you choose can be fictional, and unless you have tested positive and agree to upload it, there is no contact info either.

Re: "Here I Go, Again On My Own..." - DLR

Yet Another Anonymous coward

In this version. Remember how all those new security laws were temporary after 9/11 and were only going to be used against terrorists?

This phone shows you drove past Mr' known to police' so you are now also a suspect, subject to being the right (ie wrong) skin color.

I'll wait

julian.smith

Call me when you get to 50% - you know the number

Real Time, adj.:
Here and now, as opposed to fake time, which only occurs there and then.