News: 1588171688

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Academics demand answers from NHS over potential data timebomb ticking inside new UK contact-tracing app

(2020/04/29)


A group of nearly 175 UK academics has criticised the NHS's planned COVID-19 contact-tracing app for a design choice they say could endanger users by creating a centralised store of sensitive health and travel data about them.

In the [1]open letter published this afternoon, the 173 scholars called on [2]NHSX , the state-run health service's app-developing and digital policy quango, to "publicly commit that there will not be a database or databases, regardless of what controls are put in place, that would allow de-anonymization of users of its system."

Due for release in the coming weeks, NHSX's contact-tracing app will be the official way that everyone's contacts with COVID-19-positive people will be tracked. The app will emit an electronic ID from your phone and receive the IDs of other phones with the app installed. If someone develops the coronavirus, everyone who came into contact with that person (i.e. their app came close enough for their ID to be logged by others) will receive an alert.

Controversially, the NHSX app will beam that contact data back to government-controlled servers. The academics who signed today's open letter fear that this data stockpile will become "a tool that enables data collection on the population, or on targeted sections of society, for surveillance."

As we reported yesterday, Britain has [3]abandoned the international consensus on how much data should be collected to fight the COVID-19 pandemic.

The letter said:

We hold that the usual data protection principles should apply: collect the minimum data necessary to achieve the objective of the application. We hold it is vital that if you are to build the necessary trust in the application the level of data being collected is justified publicly by the public health teams demonstrating why this is truly necessary rather than simply the easiest way, or a "nice to have", given the dangers involved and invasive nature of the technology.

So far little is publicly known about the all-important details of the NHSX contact-tracing app. Once its creators publish more information about its architecture and implementation, the public will be able to scrutinise it.

Academics: We hate to ask, but could governments kindly refrain from building giant data-slurping, contact-tracing coronavirus monsters? [4]READ MORE

Apple and Google previously [5]published specifications for the creation of decentralised contact-tracking apps.

Critically, adopting a centralised model may risk losing public trust. In turn, people may simply not install the app for fear that their identities and sensitive health data, as well details of exactly who they met, where and when, might be stolen by thieves or otherwise sold or misused for new purposes by government agencies.

The NHS has been asked for comment.

Separately, the Privacy International campaign group, along with most of Britain's leading privacy campaigners, [6]sent 10 questions to [7]shadowy US data analytics company Palantir about what it would be doing with data gathered from the NHS during the pandemic. ®

Sponsored: [8]Forrester Build a Digital Experience Portfolio



[1] https://drive.google.com/file/d/1uB4LcQHMVP-oLzIIHA9SjKj1uMd3erGu/view

[2] https://www.theregister.co.uk/2019/02/20/nhsx_digital_data_tech_health_service/

[3] https://www.theregister.co.uk/2020/04/28/uk_coronavirus_google_apple_api/

[4] https://www.theregister.co.uk/2020/04/20/coronavirus_contact_tracing_academics_social_graph/

[5] https://www.theregister.co.uk/2020/04/27/decentralised_contact_tracing_wins_europe/

[6] https://privacyinternational.org/press-release/3732/press-release-10-questions-palantir-privacy-organisations

[7] https://www.theregister.co.uk/2017/01/17/techs_protest_possible_muslim_db/

[8] https://go.theregister.co.uk/tl/1936/-8554/forrester-build-a-digital-experience-portfolio?td=wptl1936

What can possibly go wrong?

Jay 2

An app developed by and for (I believe) the UK government, which will quite happily slurp lots of data and send it back to a central database. Plus it's yet to be confirmed if it'll run your mobile battery into the ground, I think we'll have to wait and see on that one.

IHateWearingATie

This is typical public sector thinking - great being the enemy of good.

The extra information they are after will be very very useful in lots of situations, but they have missed the glaring issue of privacy. It could cause far fewer people to sign up, meaning that it misses what it is meant to do in the first place (apparently you need at least 60% of the population to use it for it to be effective), and we can pretty much guarantee some kind of snafu to allow access to the data for people we don't want to access it.

Most frustrating.

Andy Non

I'll be looking closely at the details when they emerge and will (or not) sign up depending on the data they require.

Just Say No

Dan 55

I'll be looking closely at the details when they emerge and will (or not) sign up depending on the data they require.

Make your choice now unless you are under the misapprehension that anything good can come of Palantir.

nematoad

"... a centralised model may risk losing public trust."

No, I don't think it will with the majority of the population. You might, I most certainly would, be wary of such a data slurping feature but the readers of El reg are not in the majority here. Most people are not even aware of what the consequences of such a data grab could mean.

So good that the government is thinking about trying to control the spread of this disease, but bad that their instincts are to grab everything that they can and hope that no-one notices

Saruman the White

I'll be looking closely at the details when they emerge and will (or not) sign up depending on the data they require.

I'll be looking very closely at the details, and will raise a GDPR complaint with the ICO if they are slurping anything apart from the information they must have. Even HMG has to obey the law!

HMG reply.

Doctor Syntax

We only like experts who we agree with. We don't agree with them.

Slurp everyone's details

Persona

Well not "everyone's"

Sunset?

Pen-y-gors

The whole thing smells to high heaven, but let's assume they're just not too bright, rather than maliciously planning something.

It's an emergency, Okay. Some normal rules may need to be relaxed. Okay.

But the situation has some very clear time limitations. We know how long COVID takes to incubate or become obvious, three weeks tops. So is there any justification for NOT automatically deleting all records each day once they are past 3 weeks old? They are of no use to trace contacts of infected people who might themselves have become infected.

And once the emergency is over, or daily infections are down to x, then the app stops collecting data. It could be re-enabled is there was a new peak, but say 6 months after that then the apps are instructed to uninstall themselves.

Having a 'die on' date built into the app (12 months time?) wouldn't be unreasonable either.

Re: Sunset?

Doctor Syntax

"let's assume they're just not too bright, rather than maliciously planning something."

The two are not mutually exclusive given that there's more than one body involved here, the NHS and those who get the job of implementing it.

Ybslik

I hear and read what everyone says they are going to do, but no one yet knows...so armchair theorists come up with what they think is going to happen.

When will those that scaremonger come up with what they will do in its place. We need to have an efficient way of tracking this virus, we need data, vast amounts of it.

Please explain how you would help in this COVID19 era instead of picking holes and being judgemental.

Yes I appreciate the --- they are going to use all this data to spy on us -- they will know what i an doing -- i do not need big brother watching me --

So come up with a way of collecting this data which is so important at this moment in time.

deive

There is an alternative literally in the article.

edit... ah - one post, joined today...

Andy Non

I guess the bare minimum way of tackling this would require people to disclose their phone number so they can be contacted by SMS or via the app. If the proximity with other people is done purely using bluetooth then location would not be needed, only a log of whose phone you were near, when and for how long (i.e. did you stand chatting to them for twenty minutes or race past them on a bicycle). Recording location data would be a grey area in my opinion as it could be legitimately useful but also is a significant intrusion into privacy.

I'll balk at installing the app though if I need to enter name, address, date of birth, ethnicity, NHS number, inside leg measurement etc.

Graham 32

> So come up with a way of collecting this data which is so important at this moment in time.

Apple and Google have already come up with a way that doesn't required it to be collected.

re: Apple and Google have...

Anonymous Coward

Yeah but the bit of the NHS drveloping this app have been told that 'NIH' is the rule of the day here. Followed by 'we don't want any foreign code in our app' (or words to that effect)

That said, I would not want to be on the wrong end of a future select committee grilling over why the solution that is being used by so many countries was not selected.

Doctor Syntax

"we need data, vast amounts of it."

Who's this "we" of whom you write? NHS? The Home Office? Sheffield Council? Local dog warden? The parking vultures who operate my local B & Q car park?

That letter was written by people who know you don't get to put toothpaste back n the tube.

Smartphones

Yet Another Hierachial Anonynmous Coward

Presumably this will download and operate on all flavours of smartphone, upto, say 10 years old, not just those of a recent apple or google variety?

Re: Presumably this will download and operate on all flavours of smartphone...

Jimmy2Cows

Given UK gov's technical mastery and ability to deliver workable, working IT projects, that seems incredibly unlikely.

Frankly I'll be amazed if it actually works at all. Expectations are low. Looking forward to buggy, power-hungry, privacy-leaking surveillance-enabling steaming piles and massive server under-provisioning.

Re: Presumably this will download and operate on all flavours of smartphone...

Doctor Syntax

"massive server under-provisioning"

Given that it's only useful as a front end to a virus testing service the server under-provision might possibly hide some of the testing under-provision.

Fraudsters will likely clone the app

Andy Non

with one or two modifications and require you to enter your credit card number - for age verification purposes of course.

(Sorry, I'm just a cynic, always looking for the worst)

Re: Fraudsters will likely clone the app

Saruman the White

And seldom disappointed I suspect.

How to stop people from having "fun"

ColinPa

What protection is there to stop some joker having fun and broadcasting "Ive got it" to every one, and leaving phones hidden outside a hospital.

It would be good to read the plans to prevent this sort of thing.

Stinginess with privileges is kindness in disguise.
-- Guide to VAX/VMS Security, Sep. 1984