News: 1588608964

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

UK COVID-19 contact tracing app data may be kept for 'research' after crisis ends, MPs told

(2020/05/04)


Britons will not be able to ask NHS admins to delete their COVID-19 tracking data from government servers, digital arm NHSX's chief exec Matthew Gould admitted to MPs this afternoon.

Gould also told Parliament's Human Rights Committee that data harvested from Britons through NHSX's COVID-19 contact tracing app would be "pseudonymised" - and appeared to leave the door open for that data to be sold on for "research".

The government's contact-tracing app will be rolled out in Britain this week. A demo seen by The Register showed its basic consumer-facing functions. Key to those is a big green button that the user presses to send 28 days' worth of contact data to the NHS.

[1]

Screenshot of the NHSX COVID-19 contact tracing app ... Click to enlarge

Written by tech arm NHSX, Britain's contact-tracing app breaks with international convention by [2]opting for a centralised model of data collection , rather than keeping data on users' phones and only storing it locally.

In response to questions from Scottish Nationalist MP Joanna Cherry this afternoon, Gould told MPs: "The data can be deleted for as long as it's on your own device. Once uploaded all the data will be deleted or fully anonymised with the law, so it can be used for research purposes."

De-anonymising such data was successfully demonstrated in 2015, [3]as we reported at the time .

Although Gould said the NHSX app would auto-delete contact data that isn't uploaded to government servers, he did explain:

If data has been shared by choice with the NHS, then it can be retained for research in the public interest or by the NHS for planning and delivering services, obviously in line with the law and on the basis of the necessary approvals by law.

The Register understands the app has been completed and function tested, with the previously announced Isle of Wight trial to begin in the latter part of this week.

Addressing the same committee, Information Commissioner Elizabeth Denham repeated to MPs that her office "was not signing off on an app." Despite being closely questioned on her reverse-ferret from [4]earlier declarations that "the starting point for contact tracing should be decentralised systems", she said this afternoon that she wanted the ICO to be a "critical friend" to NHSX.

Denham added that if enough members of the public complained about the app, NHSX had given the Information Commissioner's Office its permission to "perform a voluntary audit on the app and systems – when appropriate to do so." She shrugged: "The functionality of the app is up to government to decide… it's not for me to decide, it's for me to advise on how to mitigate some of these potential risks."

It looks alright to us, says GCHQ offshoot

The National Cyber Security Centre was also wheeled out to defend NHSX, with top techie Ian Levy telling the world in a blog post late this afternoon that there's nothing to worry about because smart folk have put the hours in to ensure it's reasonably secure.

He went into a full description of how the pseudonymisation in the app works, starting with the 128-bit unique user ID generated after installation:

Every day, your device generates a random elliptic curve key pair and encrypts your installation ID (and some other administrative stuff like time periods) with it in a way that only the NHS server can recover, giving you a daily, random-looking, encrypted 'blob'. Now, your phone advertises a contact service over Bluetooth Low Energy (BLE) – the same mechanism that your phone uses to talk to your step tracker or smart watch. When another app user comes close enough to be seen over BLE, the devices connect to each other's contact service and exchange a package containing their current encrypted blobs, the time and the transmission power used for the BLE connection, all signed using the device authentication key.

Whenever your phone comes near another app user's phone, "date and time, package received over BLE, sampled signal strength, total duration of encounter" are "securely stored" on your own mobile device. You then donk the big green button to send all that data to the NHS for research.

Should you fall victim to COVID-19, and tell the app you're ill, "the app will upload the anonymous record of your proximity events to the NHS server. From each of the encrypted blobs recorded, the server can recover the fixed but anonymous installation ID for each device you were near."

Thanks to the large output variations between different Bluetooth Low Energy chipsets in different handsets, that data is used – along with the phone model identifier collected by the app – to work out a rough proxy for distance.

Levy ended his very readable blog post (available on the NCSC website) by exhorting Britons to "please install the app, and use it". El Reg suspects, quite aside from the public health questions, that its go-live date will be a key moment for seeing just how much trust the public has in the government and civil service of the day. ®

Sponsored: [5]Choosing A Low-Code Vendor



[1] https://regmedia.co.uk/2020/05/04/nhsx_covid_app_screenshot.jpg

[2] https://www.theregister.co.uk/2020/04/28/uk_coronavirus_google_apple_api/

[3] https://www.theregister.co.uk/2015/10/02/s_korean_anonymised_health_data_sharing_a_breach_in_waiting/

[4] https://ico.org.uk/global/data-protection-and-coronavirus-information-hub/blog-combatting-covid-19-through-data-some-considerations-for-privacy/

[5] https://go.theregister.co.uk/tl/1936/-8579/choosing-a-low-code-vendor?td=wptl1936

Dreaming up barriers to adoption...

Cynical Observer

It's almost as if they want the uptake with the contact tracing app to fall short of the 60% needed for efficacy.

Almost as if they are baking in a reason for failure from the beginning.

Making choices and announcements that work against adoption of the solution....

Well that's great confidence from GCHQ

IGotOut

'folk have put the hours in to ensure it's reasonably secure."

Not totally secure, not even very secure, just reasonably secure.

I.e. so long a no one has a determined effort, it's probably ok.

Re: Well that's great confidence from GCHQ

Ryan 7

Anybody who tells you that any security is better than 'reasonable' is stupid and/or lying.

No chance

FordPrefect

Not a snowballs chance in hell I'm installing this government sanctioned spyware. I dont trust central government databases just look at the misuse of the police PNC. Look at the misuse of personal data from projects connected to vote leave and Cummings and I believe him and his cohorts have some fingers in this pie as well. You can only trust the security of your data if you trust the people that have access to it. I dont therefore I wont be going anywhere near this.

Re: No chance

JakeMS

Yup, I'm still not installing this by choice - and there's nothing they can do to change my mind.

I would still rather die by COVID-19 than install. Absolutely nothing will change my mind on that.

- Although, I did get a COVID-19 test on Wednesday - My results were "un clear" apparently, that means "I don't know" and come back in 7 days for another test (I called 111 to verify). Yup, that test was helpful.. thanks guv!

It can go

LeahroyNake

On my work phone, if I leave the house I will turn on Bluetooth, need it for the car. No way this is touching my personal devices though.

The biggest problem I see with this app is that younger school children are sensibly not allowed phones in school. My youngsters are all up for wearing PPE but they are still the highest risk of catching it when they go back to school. My partner has been working from home since it hit Spain and I followed a week later. No real reason for either of us to go back to an office environment apart from me visiting customer sites for hardware issues.

The app may be well done...

Adair

Here's hoping. It's what happens to the data afterwards, especially after the crisis is over, that matters.

Will the app be 'repurposed'? Will the data be repurposed?

To be honest, at this stage I expect the people involved are doing their best, with goodwill. But, history tells us that the govt. and its various agencies will struggle to resist temptation to dip in and find 'necessary' reasons why they should have access, and ongoing access.

Arrogance and paternalism have a long history in UK govt., and there's little evidence that those habits have died.

mrtickleuk

Thankyou, Reg, for your continued reporting on this.

Hm. An incomplete description

TRT

I mean you upload all the blobs to central servers but THEN what happens? No description of the important bit. They what? Decode the installation ids then send a push notification? Or do they send a daily amber and red list of blob signatures that my device might have seen and then the local blobs I have stored are compared to that list?

So until a FULL description of how it works is published they can go whistle.

"please install the app, and use it"

Anonymous Coward

or else we're gonna make you do it. But we'd rather pretend you have a choice, hence this farce.

Re: "please install the app, and use it"

JakeMS

Oh damn! Would you look at that, my phone keeps powering off!

data may be kept for 'research' after crisis ends

Anonymous Coward

Dear Gods, they just can't stop themselves, can they. A bunch of inbred data-fetishists.

Matt_payne666

Can be sold for 'research' market research?

Pseudo anonymised?

No right to delete?

Reasonably secure?

The value of movement data for 60-80% of the population? Someone will be making money there!

I had reservations, now I'm pretty sure I'm not installing, but other than the paranoid and reg-readers (I wonder how big the Venn diagram overlap is on these two demographics?!)

I can see pretty much Everyone else will be installing it...

The best laid plans of mice and men are usually about equal.
-- Blair