News: 1588054747

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

UK snubs Apple-Google coronavirus app API, insists on British control of data, promises to protect privacy

(2020/04/28)


Analysis The UK has decided to break with growing international consensus and insist its upcoming coronavirus contact-tracing app is run through centralised British servers – rather than follow the decentralized Apple-Google [1]approach .

In a [2]blog post just before the weekend, the CEO of the National Health Service’s tech unit NHSX Matthew Gould, and the app’s main overseer Dr Geraint Lewis, said their new smartphone application will launch “in the coming weeks,” and stressed it “could be important in helping the country return to normality and beating coronavirus.”

But within the details over how it would work, the memo revealed the NHS and UK government reckon the contact-tracing protocols built by Apple and Google protect user privacy under advisement only. Thus, the British health service is in favor of a system that sends data on who may have the virus to a centralised server, and puts the NHS in charge of who is contacted and when.

Both techniques, Apple-Google and NHS, rely on Bluetooth: simply put, your phone wirelessly emits an electronic ID that other phones will pick up when they are in close proximity. If someone tests positive for COVID-19, their ID will be used to alert others who have been near them: an ID will be flagged as infected, and if you've been near that ID, then you may have caught the novel coronavirus, too, and will be warned as such.

Apple and Google, specifically, [3]created an opt-in pro-privacy API for iOS and Android that allows your phone to periodically change its ID as well as store the IDs of other phones it comes close to. Then, if someone is found to have COVID-19, they can authorise the release of their phone’s IDs to a decentralized set of databases managed by healthcare providers, and if another user’s phone recognizes those IDs in the databases – ie: they were close to them recently – they are alerted to the fact by apps that plug into the API.

This particular approach is designed to ensure no one can use it to track individuals: Apple and Google reckon their cryptography-based protocol will make it difficult for governments and miscreants to monitor people – certainly Apple and Google will be none the wiser. Data stays on people's phones, and is [4]only released to providers' databases when the user wants to. And they stay anonymous. To declare yourself infected, you need to enter a special code from a healthcare provider after testing positive – otherwise trolls could derail the system by falsely announcing themselves infected en masse.

An [5]analysis by Brit developer David Llewellyn-Jones, [6]among others , shows this is a decent enough solution, though a point of failure is the apps themselves that plug into the API: they cannot be allowed to siphon off sensitive information gleaned from the contact-tracing protocol.

As an alternative to all of this, the NHS proposes using a centralized approach, in which everyone's whereabouts and any other information is simply uploaded to a government-owned database and analyzed there.

Uptake

Experts say that for a contact-tracing app to be effective, about 60 per cent or more of the population will need to download it on their phones and opt-in. As a result, privacy concerns are critical to the app’s success: if people don’t trust it, they won’t install it.

While there are some advantages and disadvantages to a centralised NHS and decentralised Apple-Google model, the fact that high adoption is critical has led a slew of countries including Switzerland, Estonia, and Austria plumping for the decentralised privacy-protecting approach.

In addition, Germany has backtracked on its plans to run a centralised service, saying on Sunday it will switch to a "strongly decentralised approach," and France – which insisted on a centralised approach – is facing growing backlash from security experts, many of whom have signed a letter opposing its plans.

Apple and Google tweak key bits of contact-tracing privacy plan [7]READ MORE

Despite this, however, the NHS has rejected the decentralised approach in favor of putting itself in control. The NHS app will grab all the IDs of all phones running the app, and store and process it all on its own servers. Then, if someone finds they have the virus and tells the app, whoever is in charge of the NHS database will decide how, when, and if, to alert other phones.

The NHS has been keen to stress that it will protect people’s privacy despite effectively granting itself real-time location tracking. “The data will only ever be used for NHS care, management, evaluation and research,” the blog post stated.

“You will always be able to delete the app and all associated data whenever you want. We will always comply with the law around the use of your data, including the Data Protection Act and will explain how we intend to use it.

“We will be totally open and transparent about your choices in the app and what they mean. If we make any changes to how the app works over time, we will explain in plain English why those changes were made and what they mean for you. Your privacy is crucial to the NHS, and so while these are unusual times, we are acutely aware of our obligations to you.”

Yes, but why?

The obvious question however is: why? Why take this approach at all, especially when the rest of the world is moving toward a decentralised approach?

The answer appears to be that those in charge think it will work better. “The app will advise you what action to take if you have been close to someone who has become symptomatic – including advising you to self-isolate if necessary,” the blog post stated. “The exact advice on what you should do will depend on the evolving context and approach.”

In other words, rather than simply receive an alert that will, presumably, be hard-coded into the app itself, the centralised server approach would, in theory, allow the NHS to send more personalised messages. It goes on: “Scientists and doctors will continuously support us to fine-tune the app to ensure it is as helpful as possible both to individuals and to the NHS in managing the pandemic.”

Whether that is a theoretical advantage or a pragmatic one is hard to know. If the NHS was swamped with hundreds of thousands or even millions of alerts, it would likely have to resort to automated default responses regardless.

Another reason put forward by the NHS is that it wants the ability to build a more extensive database, through app updates, in which additional data is provided by individual users but can then be attached to existing profiles in the centralized database and so help health professionals deal more effectively with the virus.

“In future releases of the app, people will be able to choose to provide the NHS with extra information about themselves to help us identify hotspots and trends. Those of us who agree to provide this extra information will be playing a key role in providing additional information about the spread of COVID-19 that will contribute towards protecting the health of others and getting the country back to normal in a controlled way, as restrictions ease.”

Lower risk

One of the epidemiologists working on the project, Professor Christophe Fraser, [8]told the BBC on Monday: "One of the advantages is that it's easier to audit the system and adapt it more quickly as scientific evidence accumulates… The principal aim is to give notifications to people who are most at risk of having got infected, and not to people who are much lower risk. It's probably easier to do that with a centralised system."

But the end result is that the NHS plans to do exactly what people are concerned about: build a highly specific database of people, their movements and the health status, and have it populated by automated data uploads from anyone who has installed the app.

It will be a major test of how much people trust the NHS with their personal information, and how much they trust the UK government not to copy or exploit that data in future for different purposes. ®

PS: This was a fear the NHS app would burn through people's batteries by using Bluetooth – whereas the Apple-Google interface runs minimally in the background. However, it appears Apple, at least, is [9]willing to let the centralized NHSX app run Bluetooth scanning in the background, avoiding completely draining handhelds' batteries.

Sponsored: [10]How to Build Your Digital Experience Portfolio



[1] https://www.theregister.co.uk/2020/04/14/coronavirus_phone_app/

[2] https://healthtech.blog.gov.uk/2020/04/24/digital-contact-tracing-protecting-the-nhs-and-saving-lives/

[3] https://blog.google/inside-google/company-announcements/apple-and-google-partner-covid-19-contact-tracing-technology/

[4] https://www.theregister.co.uk/2020/04/27/decentralised_contact_tracing_wins_europe/

[5] https://www.flypig.co.uk/list?&list_id=688&list=blog

[6] https://twitter.com/benadida/status/1249067484679794688

[7] https://www.theregister.co.uk/2020/04/27/decentralised_contact_tracing_wins_europe/

[8] https://www.bbc.com/news/technology-52441428

[9] https://twitter.com/jamestitcomb/status/1254841432726069249

[10] https://go.theregister.co.uk/tl/1936/-8578/how-to-build-your-digital-experience-portfolio?td=wptl1936

Oh, Grandma what big eyes you have.

Anonymous Coward

All the better to see you with, my dear!

Re: Oh, Grandma what big eyes you have.

Martin Gregorie

Apart from anything else, why should we ever trust sensitive data to the people who authorized the Care-Data clusterf*ck?

This centralized approach smells very much like another attempt at the same thing. Once they have tracking data, what are the chances that they WON'T come up with some lame excuse to link in our medical records and then let some third party process the data "because our systems are overloaded with all this tracking" and monetize it "because that pays for a better NHS" or similar lame excuse.

Re: Oh, Grandma what big eyes you have.

Barrie Shepherd

"..............what are the chances that they WON'T come up with some lame excuse to link in our medical records and then let some third party process the data "because our systems are overloaded with all this tracking" ......"

I bet Crapita are already writing the Tender documents (together with their pricing response)

Dinanziame

UK government thinks it's not a problem to spy on its citizens. I'm shocked, shocked! Well, not that shocked...

Anonymous Coward

[1]The Lives of Others.

[1] https://pbs.twimg.com/media/EWrJdY3WkAAQt5I.jpg

Three steps to avoid this

Anonymous Coward

Any of those listed below will make this a roaring success (not)

1) set BT to 'disable'.

2) Do not install app.

3) Leave phone at home when going for your daily walk or weekly shop.

Goverments (not just in the UK) seem to assume that ALL of us have a phone glued to an appendage morning noon and night. This is clearly not the case if you are say over 50 years old which puts you into the age group that seems to get the plague more than others. Has anyone told BoJo (and other PM's/Presidents) about that?

Re: Three steps to avoid this

Anonymous Coward

From my understanding they've developed a method with GCHQ that awesomely allows them to enable bluetooth -and anything else- on your device when they see fit. This was mentioned on the BBC article.

They are literally, hacking your phone with this app :-D.

Thus, the app can force itself to run in the background without being hindered by battery saving techniques or users disabling things, ensuring we are all carefully monito... eh, ensuring our safety.

I'm going to get a lot of hate for saying this, but I for one will not be installing this NHS app. I would rather get corona and die at last... even if they make it mandatory by law, still not installing it.

Re: Three steps to avoid this

Anonymous Coward

Issues such as being able to run in the background are already well known as it's a similar problem for things like fitness apps, you don't need GCHQ to work around that. Any battery management settings would still apply unless the user changes the settings for this particular app.

The BBC article also doesn't say anything at all about them being able to enable 'enable bluetooth -and anything else- on your device when they see fit'. GCHQ no doubt have the technology for that but they aren't going to waste it on an app which will be installed by millions of people and undoubtedly disassembled and analysed closely.

Re: Three steps to avoid this

Headley_Grange

"I would rather get corona and die"

This is not just about you and your personal choices. You might rather get corona and die but your choice affects other people who might be much more susceptible to dying from it and would prefer to live a bit longer. If a significant proportion of the population take your approach then susceptible folk are going to be confined to their homes for months or we'll all be locked down for a lot longer.

Re: Three steps to avoid this

Anonymous Coward

It is my choice not to carry a smart phone - I've just bought spare batteries for my old Blackberry should HMG decide that they wish to do such a thing.

I need privacy, not because my actions are questionable, but because the government's judgement and intentions are.

Re: Three steps to avoid this

Ben Tasker

"I would rather get corona and die"

This is not just about you and your personal choices. You might rather get corona and die but your choice affects other people who might be much more susceptible to dying from it and would prefer to live a bit longer

Agreed, but there's a more privacy sensitive option available and they've chosen to disregard it for no tangible benefit (as the article notes, their claimed benefits are going to fall flat once there's sufficient demand, and they'll end up automating anyway).

Other countries have realised that the outcome of going the more privacy invasive way is reduced uptake. Why does our government (with it's fondness for data experts) think this will be any different - hell as "experts" they should probably realise that their very presence (and proven attitude to data protection) will make people more way not less.

Sorry, but I'll not be installing it either.

Re: Three steps to avoid this

Doctor Syntax

"This is not just about you and your personal choices."

No, it's about HMG's choices. Several European govts have opted for a choice that respects privacy. Germany even abandoned its first choice to do this. One then has to ask HMG why it made this particular choice.

It might be simply the ruling ERG's xenophobia leading it to wish to do the opposite of Europeans. It might be an unthinking data-fetish.

But from our PoV it's simply UK govt., having a long history of not being trustworthy in terms of privacy, doing yet another thing which is not trustable in terms of privacy and asking us to trust them. There's nothing to stop them reconsidering like the German govt. did but my expectations are low.

Re: Three steps to avoid this

Anonymous Coward

" I would rather get corona and die at last... "

No you wouldn't. Trust me.

Re: Three steps to avoid this

Anonymous Coward

Well you'd better keep the fuck away from my family then. I don't care if *you* die from Corona either, but if you come near me or mine with that attitude you won't need to worry about that.

Oh, and keep your tinfoil hat nailed on matey, longer nails are available.

Anonymous Coward

Oh no, the government isn’t filled with the Vote Leave criminals and this system has no ties to the companies involved in that. Palantir are just a very helpful society oriented organisation. The same with Faculty. How dare anyone question the motives here.

Anonymous Coward

Demonic Cummings' ectoplasm is all over this one.

"[...] Vote Leave criminals [...]"

Anonymous Coward

Are you for real? You think voting to leave the EU makes someone a criminal? Wow. I was concerned that the EU's desire to centralise everything under their direct control MIGHT lead to a LESS oppressive version of "One Land, One People, One Leader" but obviously I was underestimating the situation.

What's next, Re-education Camps to show the Leave voters the errors of our ways? Prison sentences if we don't confess the error of our ways and bow our heads to our Brussels-dwelling lords and masters?

Re: "[...] Vote Leave criminals [...]"

Anonymous Coward

Learn to read. Vote Leave is the organisation that broke electoral law during the referendum. I did not say voting leave makes someone a criminal, it does make them thick, thick enough to lack basic comprehension of what I wrote.

Re: "[...] Vote Leave criminals [...]"

Anonymous Coward

>>What's next, Re-education Camps to show the Leave voters the errors of our ways?

I bet Priti dreams about something similar for anyone who goes against her ideology.

That and the death penalty for innocent people as a deterrent. All three hundred thousand, thirty four, nine hundred and seventy four thousand of them.

Paranoid Android

nojobhopes

Of course "Pushing out updates to Android is notoriously challenging" (https://www.cnet.com/news/how-youll-get-apple-and-googles-contact-tracing-update-for-your-phone/). In reality lots of Android phones don't have the latest security fixes. So how are Google getting this tracking update onto all Android phones? Via Google Play services. Which doesn't work for vendors who produce Google-free AOSP Android phones (like cheap knock-offs and Amazon Fire devices). This proves the Android OS update approach is a bit broken.

Re: Paranoid Android

Saruman the White

It also does not work if you simply don't download and install the app.

I suspect that trying to force it on to everyone's phone without explicit permission (which is effectively granted by someone actively installing the application) is going to result in HMG being taken to court for breach of privacy.

Re: Paranoid Android

werdsmith

Or make them unpopular (for a change) like U2.

Anonymous Coward

Surely they can already track you by the RFID chips that Bill Gates has installed into people via 5G.

Difficult choice

Anonymous Coward

Trust Google, or trust Government IT?

Neither, I think.

Re: Difficult choice

fwthinks

^ This is the crux of the issue - what does amaze me is the number of people who just automatically trust the statements from google/apple - especially given the history of them deceiving people and covertly collecting data. To me the supposed additional privacy of their solution is dependent on them being and remaining honest. It only takes a few people to start seeing dollar signs at the prospect of using all that personal data, for the privacy to disappear.

I am very uneasy about the whole solution, irrespective of who manages the solution. However maybe us sensitive types are irrelevant in this discussion. Billions of people happily give personal data out on the internet every day. So maybe the critical mass requirements will be met by all the Facebook fans.

However there are dire consequences both economically and personally if this pandemic continues to control our way of life for the next few months even years - so my view is that I would install the app if this goes some way to allowing us to return to normal sooner. The privacy consequences could become irrelevant if things turned bad.

Re: Difficult choice

not.known@this.address

And don't forget the Patriot Act. Whilst I don't have any particular reason to fear the US Government snooping on everything I do and everywhere I go, it doesn't mean I want to give the information to American companies who could be "forced" to hand the data over because US.Gov says so, any more than I want to give the information to our own mob.

Re: Difficult choice

FrogsAndChips

Privacy matters aside, at least I trust Google/Apple to bring an app to the market soon enough. Given gov.uk's track record in terms of delivering IT projects, if this app is a prerequisite to lifting the lockdown we'll still be in our homes by Christmas.

Re: Difficult choice

JohnMurray

Which Christmas?

Re: Difficult choice

TheSirFin

Worth having a listen to this podcast ........ really interesting to hear how both approaches work .... and not a surprise that the Gov have gone on the Slurping route ....

https://www.bbc.co.uk/programmes/m000hgj3

Felonmarmer

So like every other aspect of the pandemic, the UK want's to do this differently from everyone else. How's that worked out so far?

But also, studies suggest that coronaviruses (including preliminary information on the COVID-19 virus) may persist on surfaces for a few hours or up to several days. Doesn't this make the whole concept a bit dodgy? If this is being used to open up the lockdown, and a person going to work is confirmed to have an infection, there may be a trail of infected surfaces going back hours. They would need to track not only proximity at any point but a trail of movement corelated with time for each phone and match those trails with every other to see if you moved throught that trail within hours of the infected trail. Surely this would quickly escalate to flag a huge number of suspected cases quite quickly (every bus passenger on a bus for hours after an infected trail has travelled by that bus for example, and then track everyone of those passengers throughout a city?)

Drat

It is not about picking up everybody who may have been infected, it is about picking up enough people who may have been infected to reduce the R0 below 1

Felonmarmer

Aren't you going to have too many false positives though? If the idea is to uise to relax lockdown, then we could end up with as many at home on 14 day exclusion waiting for symptoms as currently off with the current lockdown measures?

ibmalone

By the time this is actually available hopefully they will have better testing. I've also seen tiers of exposure proposed, again playing on the average rates and the principle that people who've been in each other's company for an hour are more likely to have transmitted it than people who passed in the street.

That said, if they're proposing to massively increase the number of people self-isolating (as this would extend to those who were asymptomatic), are instructed to self-isolate rather than do so voluntarily (some powers in the coronavirus 2020 act * depend on being instructed to isolate or believing the person to be infectious) and have a central system where conceivably this information could then be shared to the police to enforce isolation, then it really is essential that there is a plan for supporting people isolating.

And of course promising a gradual scope creep may not help public trust when public trust is what you really need.

* as distinct from the The Health Protection (Coronavirus, Restrictions) (England) Regulations 2020 which are the ones about not gathering in groups, only being out for certain reasons etc.

Doctor Syntax

This is the crux of any tracing system. It must have an effective testing regime to confirm putative contacts. In fact, to be useful, it would be nothing more than the front-end to a testing system and the current target, assuming it's ever actually met, is probably an order of magnitude short unless the infection rate is got down to manageable size before introducing such a system.

Anonymous Coward

Stupid people can't understand this, there's something broken with their brain that makes them incapable of understanding that sometimes, it's ok for an enforcement measure to be <100% effective if it brings other social benefits. Doesn't compute for them. "But if just one life was saved, it would all be worth it!" makes perfect sense to them. They'll probably be found, shouting at someone on a moor miles away from anyone, for 'putting lives at risk' by 'flouting the restrictions' and sunbathing.

Maximal possible transparency

Anonymous Coward

You don't mean you actually touch surfaces outside your home do you? And when you have to, you do wear gloves and wash your hands afterwards, yes? And you never touch your face outside the house? So as long as you're following basic hygiene practices and don't actually work in a covid ward, you're not very likely to catch the virus off a surface.

Yesterday, Boris (all-hail) said plans must be set out with 'maximum possible transparency'. So I'd like to see as much as possible of the source published, not just of the app but also the server-side code. I'd like to see detailed design documents. I'd like to see server logs published. And I'd like a really clear detailed explanation of why a centralised solution is seen as 'better'.

And then I'll read all the reviews by Ross Anderson and by all the DP3T designers to see whether they support the NHSX design. And then I'll decide whether to install the app or turn my phone off for the duration. Always assuming it is made available of f-droid, of course :) I don't have the google store installed.

Automation

scrubber

Can I give it access to my banking app so it can just automatically withdraw the fine whenever I'm out too long or near too many people or not moving fast enough to count as exercise or whatever else they have decided that was not against the law is now against the law.

Re: Automation

Phil O'Sophical

Maybe there's scope for a micropayment solution here, everyone who is detected as breaking lockdown rules is fined an amount per day, which is then shared-out between all the people who stay at home? Might encourage people to install it, greed always trumps privacy!

Re: Automation

Persona

Sounds good to me. My phone stays at home when I go out so I don't see how I can lose with your scheme.

Re: Automation

Anonymous Coward

Another incentive would be to put people who install it to the front of the queue for vaccinations, when they become available for the great unwashed...

Stupid Decisions

Drat

The most important thing is to get enough people to use the app such that the contact tracking works. Farting around with additional functionality that might subsequently reduce the number of installs is idiotic

Re: Stupid Decisions

monty75

It’s got scope creep baked right in!

Re: Stupid Decisions

TheMeerkat

Well, I have no plans to install it.

Correction

KitD

> As an alternative to all of this, the NHS proposes using a centralized approach, in which everyone's whereabouts and any other information is simply uploaded to a government-owned database and analyzed there.

The NHS system doesn't upload your "whereabouts". They were going to use GPS but that was discounted pretty quickly. It uses a very similar system to the Apple/Google (actually D3PT) system, and, in its basic operation, it uploads only the random tokens to the central servers when you get ill. The difference is that searches by other handsets for matching tokens happens on the central servers, not on the handsets. The advanced operation, which is opt-in, also uploads other medical & PII data & (AIUI) location, when you get ill, which is where the privacy worries are.

But the basic operation is really no less safe than normal smartphone operation.

Re: Correction

Richard 12

If you have a list of timestamps of when a large number of handsets were near each other and a rough distance between them, you only need a tiny number of GPS position fixes on a handful of phones to determine the exact location (within a few metres) of everyone else.

It's completely stupid, and exactly what I expected from the current crop of Big Brother control freaks in power.

Re: Correction

KitD

Firstly, no one mentioned timestamps. You don't need them. Only the last 14 days worth of encountered tokens.

Secondly, location & cell data is already happily donated free-of-charge to Google/Apple anyway. If the spooks were that minded, there are much easier ways of gathering it.

Re: Correction

ChipsforBreakfast

Location and cell data alone is too coarse, especially indoors. It needs to be combined with a more fine-grained dataset to accurately identify gatherings & contacts.. hence Bluetooth.

Add the two and you have a near-perfect surveillance system that can tell you who met who, where and for how long...a dictator's wet dream!

Re: Correction

Ben Tasker

> Secondly, location & cell data is already happily donated free-of-charge to Google/Apple anyway.

That's pure whatabouterry.

It's quite possible someone's willing to make the trade-off and let Google/Apple have this data because they trust them not to fuck up. It's just as possible that they don't trust the state not to fuck up.

It's not just about deliberate mis-use, it's about competence and perceived motivations. Govt historically doesn't do too well in either of those categories.

> If the spooks were that minded, there are much easier ways of gathering it.

There are, but if you're involving a 3rd party (i.e. Google/Apple) there's a much higher chance of someone disclosing that you've been accessing it. That risk is greatly reduced if you own the database and the system feeding into it, particularly when people are expecting that system to feed back the information you need

Re: Correction

matt 83

How can you keep "14 days worth of encountered tokens" without having timestamps associated with the tokens?

How else would you know when the "token encounter" is more than 14 days old?

Re: Correction

Richard 12

"Last 14 days" requires timestamps, or you couldn't work out which were 15 days ago.

Yes, in theory they could be cropped to 1-day precision.

Prove that the timestamps are no tighter than 1 day precision, then prove that there is no way of creating more precision from the metadata, eg when data was sent to the server.

Then prove that Priti Patel would never, ever decide to use the data for unexpected purposes, and further prove that she would be executed if anyone in her dept did so. Repeat for every minister.

(She's on record as being in favour of capital punishment, so she should be ok with that.)

Sorry, but this type of thing is simply unacceptable. It is very quickly near-real-time tracking of everyone.

She was good at playing abstract confusion in the same way a midget is
good at being short.
-- Clive James, on Marilyn Monroe