News: 1588663691

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

UK finds itself almost alone with centralized virus contact-tracing app that probably won't work well, asks for your location, may be illegal

(2020/05/05)


Comment Britain is sleepwalking into another coronavirus disaster by failing to listen to global consensus and expert analysis with the release of the NHS COVID-19 contact-tracking app.

On Monday, the UK government explained in depth and in [1]clearly written language how its iOS and Android smartphone application – undergoing trials in the Isle of Wight – will work, and why it is a better solution to the [2]one by Apple and Google that other nations have decided to adopt. It has also released a [3]more technical explanation .

Unfortunately for folks in UK, while the explanation is coherent, calm, well-reasoned and plausible, it is likely to be a repeat of the disastrous “herd immunity” policy that the government initially backed as a way to explain why it didn’t need to go into a national lockdown. That policy was also well-reasoned and well-explained by a small number of very competent doctors and scientists who just happened to be wrong.

Here’s what happening: there are broadly two types of coronavirus contact-tracing apps; those that are centralized and those that are decentralized. The first takes data from people’s phones and saves it on a central system where experts are trusted to make the best possible use of the data, including providing advice to people as and when necessary.

The second, decentralized approach, as set out by Apple and Google, puts users in more control of their information, and alerts them automatically with no intervention from a third party. Apple and Google have also [4]banned apps that use their decentralized and anonymized [5]API from accessing location services to track and identify people, despite pressure to do so. And they have said they will only allow one app per country, or state in the US.

Both types use Bluetooth to detect other nearby phones also running the software. Thus, when someone catches the coronavirus, people can be warned if their phone was within 6ft of that patient's phone for more than a few minutes.

Leave it to us

In his post, the technical director of the National Cyber Security Centre (NCSC), Dr Ian Levy, explained in persuasive terms why allowing health service experts to have access to all the data is a good idea for beating back the virus.

“The health authority can use risk modelling to decide which contacts are most at risk, and then notify them to take some action,” he noted, adding: “Importantly, the public health authority has anonymous data to help it understand how the disease appears to be spreading, and has the anonymous contact graphs to carry out some analysis.

"So the health authority could discover that a particular anonymous person seems to infect people really well. While the system wouldn’t know who they are, encounters with them could be scored as more risky, and adjust the risk of someone being infected by a particular encounter appropriately.”

UK COVID-19 contact-tracing app data may be kept for 'research' after crisis ends, MPs told [6]READ MORE

He used two famous epidemiological stories to prove the point: Typhoid Mary and John Snow. Mary Mallon was a cook in New York in the early 1900s who had typhoid fever but showed no signs of it, and ended up infecting a number of households who were otherwise separated from the wider population. No one could figure out why they were falling sick until someone figured out Mary was the link.

Likewise John Snow tracked down the source of a cholera outbreak in London in the 1850s down to a water pump in Broadwick Street in Soho and put a stop to it by removing the handle, although later research suggests the outbreak was already dying out by that time. There is, incidentally, a plaque and a pump on the same spot, and the John Snow pub opposite where this reporter whiled away many happy hours.

The argument is that while the Apple-Google decentralized model protects people’s privacy, it leaves the authorities blind. It puts a public health disaster outside the reach of those who can help most through analysis of the population. Meanwhile, the undertone of the centralized NHS method, where people's data is collected and analyzed together, is almost explicit: we all know how important privacy is but let’s leave this to the experts, shall we? Give up a little bit of data and save lives. Let’s not go too European on this.

So, um, a problem...

But there is a problem with the NHS's approach: it probably won't that well work on your phone, and probably won't be terribly accurate at measuring the spread of the virus.

That's because the proposed system will only work in the way the UK government claims it will if everyone does what it says: a classic failing of the Whitehall mindset that stretches back to the World War One trenches and further back still to the days of Great Houses and Men Who Knew Better.

Despite what the NCSC has continued to imply, the app will not, as it stands, work all the time on iOS nor Android since version 8. The operating systems won't allow the tracing application to broadcast its ID via Bluetooth to surrounding devices when it's running in the background and not in active use. Apple's iOS [7]forbids it, and newer Google Android versions [8]limit it to a few minutes after the app falls into the background.

That means that unless people have the NHS app running in the foreground and their phones awake most of the time, the fundamental principle underpinning the entire system – that phones detect each other – won’t work.

It will work if people open the app and leave it open and the phone unlocked. But if you close it and forget to reopen it, or the phone falls asleep, the app will not broadcast its ID and no other phones around you will register that you've been close by. There is even a [9]handy video of someone in Australia showing this (Australia has gone for a similar system with its COVIDSafe app.)

Because people seem interested here's some video of the COVIDSafe app failing on iPhone. It is literally impossible to broadcast the UUID needed for the app to work without the screen on and the app in the foreground. [10]pic.twitter.com/X5lpyeKL1A — Joshua Byrd (@phocks) [11]May 1, 2020

We cannot state it plainer: on iPhones, apps [12]cannot send out their IDs via Bluetooth when the software is in the background, and on newer Android builds, IDs cannot be transmitted after a few minutes in the background. And Apple and Google have [13]refused to allow the tracing app to send out IDs in the background.

The NHS has insisted its engineers have worked around this problem " [14]sufficiently well " by waking the app after it detects itself running on a nearby phone emitting an ID: the software is blocked from sending out its ID when in the background but it can passively listen for IDs of apps still allowed to broadcast. However, this assumes there are a sufficient number of phones running the tracing app nearby still broadcasting to keep enough people's apps awake: there needs to be a critical mass of users while we're all supposed to be socially distancing. If two or more people pass each other and their apps have stopped broadcasting, the software will never know they came in contact.

And it could be a battery hog, which may make people leave the app off, preventing the app on other phones from waking up.

Little choice

What Levy doesn’t say is that he – and NCSC and the UK government – are assuming that when people are moving around, and so are close to one another, they are likely to be on their phones or have recently opened the app. It’s an assumption they have no choice to make because otherwise they don’t get the data. By contrast, the Apple-Google solution that Germany, Austria, Switzerland and Ireland, among others, are following will allow the IDs of phones to be recorded in the background all the time, due to being built into the operating system, so it will be more accurate and kinder to battery life.

The other big problem with the UK approach is that while it insists it will keep data private, and location data will not be stored nor attached to individuals, the truth is that it will only work as promised if that data is not kept private and location data is stored and attached to individuals.

Levy repeatedly tried to square this circle, leading to some ludicrous assertions. He stated boldly in bullet points that the app “doesn’t have any personal information about you, it doesn't collect your location and the design works hard to ensure that you can’t work out who has become symptomatic,” and that “it holds only anonymous data and communicates out to other NHS systems through privacy preserving gateways.”

But what is literally the first thing the app does when you install and open it? It asks for your postcode, and logs the exact make of your phone.

Levy explained “a big random number” is also generated, which is tied to the copy of the contact-tracing app on your phone. This 128-bit ID is what the app on one phone exchanges via Bluetooth with itself on a nearby phone when they come in range. This exchange includes when exactly the IDs were encountered, how long the phones were near each other, and the signal strength, allowing the distance apart to be calculated. This is the data that is ultimately shared with the NHS, when you choose to.

The exchanged data is also encrypted in such a way that the NHS can decrypt it but not other users. We understand these ID numbers are generated server-side, and are people's unique fingerprints in the centralized system.

Levy also noted that "currently" only “the first part of your postcode” is taken and stored “for NHS resource planning, mainly.” He goes on: “Nothing identifying and no personal data are taken from the device or the user.”

Does it matter?

Presumably the goal with this kind of explanation is to comfort the vast majority of UK folk who don’t understand how the entire internet economy works by connecting vast databases together.

So long as you can rely on one piece of per-user data – like a “big random number” – everything else can be connected. And if you also have a postcode, that becomes 100 times easier. Ever heard of Facebook? It’s worth billions solely because it is able to connect the dots between datasets.

Indeed, it may be possible to work out [15]who is associating with whom from the app's ID numbers. Bear in mind, the Apple-Google decentralized approach produces new ID numbers for each user each day, thwarting identification, especially with the ban on location tracking.

Levy also glossed over the fact that as soon as someone agrees to share their information with UK government – by claiming to feel unwell and hitting a big green button – 28 days of data from the app is given to a central server from where it can never be recovered. That data, featuring all the unique IDs you've encountered in that period and when and how far apart you were, becomes the property of NCSC – as its chief exec Matthew Gould was [16]forced to admit to MPs on Monday. Gould also admitted that the data will not be deleted, UK citizens will not have the right to demand it is deleted, and it can or will be used for “research” in future.

And then there’s the not insignificant issue that the entire approach may break privacy and human-rights laws, anyway, as one legal firm has [17]advised :

A de-centralised smartphone contact tracing system – the type contemplated ... by governments across Europe and also Apple and Google – would be likely to comply with both human rights and data protection laws. In contrast, a centralised smartphone system – which is the current UK Government proposal – is a greater interference with fundamental rights and would require significantly greater justification to be lawful. That justification has not yet been forthcoming.

Oh yes, and “the UK Government’s announcements for sharing health data between the private and public sector appear to be flawed. This means such data sharing is potentially not in compliance with legal requirements.”

Just get it out

What Gould and Levy are not admitting is that they expect the vast majority of UK citizens to opt in, download the app, and share their data anyway, no matter any of these concerns, out of a sense of civic duty.

So long as they can get through the objections and push past the criticisms and get the app launched, they will get what they no doubt honestly believe will be a better end result for the country because the data will be in the hands of the experts. And they might – might – be right. But they might also be completely wrong.

At the heart of this decision by the UK to fall back on the belief that a central authority is going to be a better solution, no matter what compromises have to be made, is that central planning will work better when it comes to COVID-19.

But will it? So far the clear evidence is that greater control of populations has worked better at stopping the coronavirus spread than a more relaxed attitude, The US and UK have notably refused to put limits on their citizens until forced to, and are almost certainly going to end up the worst affected countries on the globe as a result.

But does population control work beyond lockdown? When the economy is opened up, will a centralized approach where hotspots can be identified and dealt with from a command post be more effective than a decentralized approach where individuals are left to decide for themselves?

We may be about to find out. Although if people can’t be persuaded to download the app in the first place because they don’t want their data to be floating around the government’s servers for the next 100 years, then the whole question is moot anyway. The government is continuing to play a giant game of chicken with our lives. ®

Sponsored: [18]Legacy Modernization: Finding Your Way With Low-Code



[1] https://www.ncsc.gov.uk/blog-post/security-behind-nhs-contact-tracing-app

[2] https://www.theregister.co.uk/2020/04/28/uk_coronavirus_google_apple_api/

[3] https://www.ncsc.gov.uk/report/nhs-covid-19-app-privacy-security-report

[4] https://www.theregister.co.uk/2020/05/05/apple_googles_exposurenotification_api_update/

[5] https://developer.apple.com/documentation/exposurenotification

[6] https://www.theregister.co.uk/2020/05/04/uk_covid_app_human_rights_parliament/

[7] https://medium.com/@cbartel/ios-scan-and-connect-to-a-ble-peripheral-in-the-background-731f960d520d

[8] https://developer.android.com/about/versions/oreo/background

[9] https://twitter.com/phocks/status/1256354615051730944

[10] https://t.co/X5lpyeKL1A

[11] https://twitter.com/phocks/status/1256354615051730944?ref_src=twsrc%5Etfw

[12] https://stackoverflow.com/questions/39624045/corebluetooth-advertising-in-background-on-ios-10/39624845#39624845

[13] https://www.reuters.com/article/us-health-coronavirus-usa-apps-idUSKBN22G28W

[14] https://www.bbc.com/news/technology-52441428

[15] https://www.theguardian.com/world/2020/apr/13/nhs-coronavirus-app-memo-discussed-giving-ministers-power-to-de-anonymise-users

[16] https://www.theregister.co.uk/2020/05/04/uk_covid_app_human_rights_parliament/

[17] https://www.matrixlaw.co.uk/news/legal-advice-on-smartphone-contact-tracing-published/

[18] https://go.theregister.co.uk/tl/1936/-8553/legacy-modernization-finding-your-way-with-low-code?td=wptl1936

Of course, being centrally controlled

Anonymous Coward

It could be centrally configured to neglect to alert those who the Government considered to be Troublemakers.

Re: Of course, being centrally controlled

Anonymous Coward

It "could" a lot of things but this is paranoia pure and simple.

Mind you, there's paranoid and there's properly paranoid...

Re: Of course, being centrally controlled

jospanner

You give the state an inch, it will take a mile.

Re: Of course, being centrally controlled

Kane

"You give the state an inch, it will take a mile everything."

Re: Of course, being centrally controlled

Anonymous Coward

The people behind this app (Marc and Ben Warner) were involved in the illegal Cambridge Analytica operations in 2016. They have shown to be law breakers with nefarious intentions funded by foreign far right groups. What makes you think they've suddenly bettered their lives and won't do it again?

It's telling that even Google's approach is more privacy conscious than what these people are planning.

Re: Of course, being centrally controlled

Tilda Rice

Your post is more insightful than the article. Which said "long number, first part of postcode" oh noooz its Facebook again.

Hanlon's razor

Oddlegs

"Never attribute to malice that which is adequately explained by stupidity"

It's far more likely that the decision being taken to go with a centralised approach was simply down to the chosen developers being familiar with that model (it is how almost all software is designed) as opposed to an unfamiliar decentralised model.

Re: Hanlon's razor

Rameses Niblick the Third Kerplunk Kerplunk Whoops Where's My Thribble?

"Never attribute to malice that which is adequately explained by stupidity"

Why do people always leave off "...but don't rule out malice" when quoting this? It's important!

Re: Hanlon's razor

MattWPBS

I prefer "cock up is more likely than conspiracy".

Re: Hanlon's razor

ridley

Presumably the gov had several proposals that they could have chosen the best from or were they just given Dom's mates one?

Re: Hanlon's razor

Adair

Or, in the case of the British Government (and governments the world over): never attribute to malice what can adequately be explained by arrogance and paternalism.

In general, treating responsible adults like responsible adults will produce positive and constructive results. As for the small number of irresponsible adults: a. they have to be lived with; and b. their selfish stupidity should not be allowed to hold everyone else hostage.

With something like C19 the mitigation only has to be 'good enough', so there is a good chance that a well implemented decentralised system will be more than 'good enough' for the job.

Re: Hanlon's razor

The Central Scrutinizer

You want paternalism, come to Australia, where Scotty from marketing says it's the equivalent of national service to download our app.

Re: Hanlon's razor

gnasher729

Much more likely is that there's not much money to be made from Apple/Google's code. As an iOS developer, you can download a working app right now and just have to add a few bits say to make it NHS specific.

Paul Crawford

It is down to stupidity or Machiavellian plans?

Sadly it could be both :(

Hmm ...

Blofeld's Cat

require_once('sarcasm'); // Just in case

I can't imagine that anyone in authority would misuse this data. I mean knowing where people were and who they met has no possible other use to anyone.

You might as well suggest that the Parks Department would use anti-terrorist legislation to check on dog-walkers.

I also wonder what will happen when the first person who uses the app gets Covid-19 from a contact, without the app alerting them ?

My guess is "lawyers".

Mr Humbug

> I also wonder what will happen when the first person who uses the app gets Covid-19 from a contact, without the app alerting them ?

Nothing. It's not NHSX's fault if the contact who gave you the virus didn't use the app, didn't activate the app properly or used the app but didn't report their symptoms. The app is perfect, it's the users (or lack of them) that are the problem.

Re: Hmm ...

Warm Braw

My guess is "lawyers"

Part of the emergency coronavirus [1]legislation is designed to:

provide indemnity for clinical negligence liabilities arising from NHS activities carried out for the purposes of dealing with, or because of, the coronavirus outbreak, where there is no existing indemnity arrangement in place

Could be expensive.

[1] https://www.gov.uk/government/publications/coronavirus-bill-what-it-will-do/what-the-coronavirus-bill-will-do

And what about the people ...

jake

... who don't have a cell phone addiction, and so don't really see a need to carry one everywhere? And what about those of us who have phones that don't run "apps"? I don't think even the current British nanny state has made carrying a so-called "smart" phone mandatory ... or did I miss that bit?

Re: And what about the people ...

Anonymous Coward

Or the people that have a mobile phone that is just a phone.

A good example would be my father who sticks with his Nokia 6310 for it's 2 week battery life and ability to use an external aerial.

The external aerial bit is important as he spends a lot of time living on canal boats (and mobiles don't work too well in steel boxes).

Being boat based also brings up another problem with the proposed app, He has no postcode or address (when I ask him where he is I usually get the name of the canal he is on and the bridge / lock numbers that he is between)

Re: And what about the people ...

jake

My Dad doesn't own a cell phone at all. Never has. Never will. Mom has one, on a bare-bones plan, for "emergencys". It has only been powered up a couple times in the eight or so years she's had it. Nobody knows it's number, in her eyes it's dial-out only. There are zero apps installed on it. In fact, there is at least one voice mail message on it, but she doesn't know how to retrieve it. Doesn't care, either. "If it's important, they have the house number" is their general attitude.

This is very common in the over-70 set here in Northern California. Dunno about blighty.

Re: And what about the people ...

matthewdjb

I think we must have the same dad.

Re: And what about the people ...

Binraider666

I think it’s safe to say most of the working population have a smartphone - and as such this can be considered the arrival of the long talked and balked at National ID card scheme via other means.

Of course NHS procurement is once again showing its expertise in getting an app out that both doesn’t work, is likely illegal, and likely earning crapita (or similar) a fat wad of cash.

For those that don’t comply, our already very thinly staffed police force will have one more job to do.

People keep voting for more of the same though, for some reason. Socialism is the enemy, says the state forced to adopt widespread socialist measures to stop society collapsing the way it appears to be in the US...

Re: And what about the people ...

Shades

"likely earning crapita (or similar) a fat wad of cash."

For once its not Crapita, but a company called Faculty.

Faculty, formerly ASI Data Science and Advanced Skills Initiative Ltd, was hired to work with Cummings on the Vote Leave campaign and has since, quelle surprise, been awarded at least 7 government contracts in the last 18 months. Want to guess what political party one of its shareholders is associated with?

Further still, Ben Warner, former principle of Faculty and brother of the founder, was hired by Cummings to work at Downing Street, after running the Conservatives private election model and (are you sitting down?) worked closely with Cummings on the Vote Leave campaign.

I'm going to go out on a limb here and guess the work done for Vote Leave and the Conservatives was pro bono.

Re: And what about the people ...

Shades

"8 thumbs up & 1 thumb down"

Hi Dom.

Re: And what about the people ...

BebopWeBop

Actually Dave has just arrived as well. (down 2)

Re: And what about the people ...

Laura Kerr

And Matt has joined us too (down 3). Hi Matt.

Re: And what about the people ...

Anonymous Coward

Crapita has (finally) fallen out of favour with the government. They've not been included on the recent approved contractor lists and a lot of their old contracts are now being picked up on renewal by the other large consultancy firms (IBM, Accenture, Deloitte, CGI etc) or these new 'weirdo' firms (Cummings phrase not mine).

Re: And what about the people ...

j.bourne

"I think it’s safe to say most of the working population have a smartphone "

Not sure why you would think that (no supporting evidence provided)- you could of course be right.... by accident.

Just having a smartphone doesn't neccesarily mean 'an up to date, working, regularly used' smartphone.

Re: And what about the people ...

Anonymous Coward

A small sample from my immediate workplace. 25 people. 4 don't have a smartphone. From the much larger wider organisation I think that's about average. Of the 21 with smartphones i would class another 3 as 'have one but hardly use'. We know this stuff because we had to sort out 2FA for all staff...

Re: And what about the people ...

jake

"I think it’s safe to say most of the working population have a smartphone"

I think it's safe to say that isn't an answer to my questions. I was obviously referring to people who do not have such a phone. Incomplete data in this case could easily be far, far worse than having no data at all.

Re: And what about the people ...

TonyHoyle

The government is setting up a separate system for those without smartphones - NHS 119 - although how calling a number is going to manage contact tracing I've no idea.. but I guess calling it if you have symptoms allows them to track the spread.

Re: And what about the people ...

jake

And who would call that number, anyway? Me, I'm calling my doctor if I get sick. I'm certainly not calling the government! When did they ever do anything to help me?

Re: And what about the people ...

Oddlegs

What about them? Those that do have a smartphone and run apps can run this one. Those that don't, won't. Just because this app won't reach 100% of the population doesn't mean we shouldn't bother with it at all (privacy issues aside)

Re: And what about the people ...

gnasher729

"... people who don't have a cell phone addiction, and so don't really see a need to carry one everywhere ..."

You are talking about people with a cell phone addiction, who have to use it everywhere. Many people just want to be reachable wherever they are, and have a mobile phone in their pocket. I carry mine around with me all the time, but not using it. Most people have a phone with them all the time.

Now of course after reading the article it seems that with Apple/Google's solution this will work if two people with their phones in their pockets walk past each other, while the NHS solution only works if both have _active_ phones and both have no other app in the foreground. So if one of the two reads theregister, or one of the two is on Netflix or iPlayer, or one of the two just has the phone in his pocket doing nothing, then the NHS app doesn't work,

sleepwalking?

Pen-y-gors

" Britain is sleepwalking into another coronavirus "

No, don't think so. UK Government is wide awake and knows exactly what it's doing.

Re: sleepwalking?

Evil Auditor

Good I work from home! Otherwise colleagues might have wondered why I had this hysteric fit of laughter.

Pity I can't up-vote you more than once

Almost?

Phil O'Sophical

UK finds itself almost alone

Well, that "almost" covers a pretty wide range!

"that other nations have decided to adopt." is also an interestingly vague phrase. The article seems to make out that Britain is alone in choosing a centralized tracking app that the government can abuse, while all other right-thinking nations have stood up for personal liberty.

It isn't that simple. France, for example, is also sticking with the EU-recommended centralized PEPP-PT model (and privacy organizations like the CNIL are complaining). Norway has a centralized model, while Germany Austria, Estonia and Switzerland have chosen the decentralized DP-3T one. Other nations have chosen other approaches. [1]Privacy International has some figures and articles which are a little less shouty.

[1] https://privacyinternational.org/examples/apps-and-covid-19

Congratulations, Kieren

Pascal Monett

Once again, an outstanding piece of journalism which sets the record straight.

Well done.

Re: Congratulations, Kieren

John Sager

That sounds like sarcasm, which I endorse. Nothing like a bit of snark towards Brexit while he was at it.

I'll suspend judgement on the app until I see some independent analysis of its operation. It might be a technical failure, in which case it'll be useless and all the paranoid ranting will have been for nothing. If it does work reasonably like it's supposed to then the key to acceptance is going to be the political & legal constraints on its use. Personally I would like to see a solid legal control excluding mission-creep with infractors, including ministers, going to jail. But sadly I can't see that happening, and a lot of commenters here wouldn't trust it anyway.

Covid jail "prank"

Smooth Newt

If you have the app on your phone, and you report that you have fallen ill with something like Covid, then all the fleeting contacts that the app has harvested will be given "NHS advice" - an injunction by their android overlord, doubtless soon to be enforced punitively, to lock themselves away for a week. They won't be given tests for them to see if they have actually caught Covid, because we're British and can't do that sort of thing.

So, what is to stop some joker putting the app on a burner phone, adding in a junk postcode, and collecting as many contacts as they can? They can do this, for example, by leaving the phone in some busy area in their employer's khazi or canteen. I am sure with imagination and industry someone could easily harvest 100 contacts a day. Or they can target it very specifically at people they don't like. Then, after a week of this fun, they can collect their reward by pressing the big red nuclear lockdown button. It's a burner phone, so it won't affect them personally of course.

Re: Covid jail "prank"

John Jennings

100? - think thousands - if you leave the phone in a factory canteen. Nice to have a couple of weeks quarentine as the weather gets better.

You dont have to even use a burner. You self report so you, could claim to have a sniffle and a temperature, and it appears that would be enough. Sit the phone by the door or the till of the canteen for half an hour and everyone going through is wiped out.

Or put a burner beside a rivals office/home or whatever and they get a call after the button has been pressed

It wouldnt even be illegal, currently, as far as I can see.

Testing?

Anonymous Coward

Wasn't malicious use of "I'm infected" going to be stopped by requiring a test with the alert phase only being activated (by a code, or similar) if it comes back as positive?

Re: Testing?

Anonymous Coward

Immediately after they're infected, people can be wandering around, with no symptoms yet, highly infectious, spreading COVID-19 everywhere.

To stop that, you need to tell potentially-infected contacts to self isolate immediately. You can't wait a couple of days for a test to be performed and the result to come back.

And we're British, so normal people don't get COVID-19 tests anyway, unless you get so sick that you get sent to hospital. And we certainly can't do rapid testing. Sigh.

Re: Covid jail "prank"

Mr Humbug

Ross Anderson pointed that out some weeks ago:

https://www.lightbluetouchpaper.org/2020/04/12/contact-tracing-in-the-real-world/

"The performance art people will tie a phone to a dog and let it run around the park; the Russians will use the app to run service-denial attacks and spread panic; and little Johnny will self-report symptoms to get the whole school sent home."

Re: Covid jail "prank"

Laura Kerr

So, what is to stop some joker putting the app on a burner phone, adding in a junk postcode

It might do a postcode lookup - even the likes of Crapita can usually get that right - so you need to use a real one:

SW1A 1AA

John Jennings

I actually listened to the select committee hearing last night, so you dont have to ;) It was truly disgraceful.

The only cogent people speaking were the lawyer and professor in infomatics.

I cant say anything about the keepawake option - they may have agreements (or get agreements) from Apple/Google to keep awake in the background for this - NHSX claim to be working with them.

What shocked me was the extent that Elisabeth Denham - the counties Information Commissioner - rolled over and rolled back on the ICO previous statement that decentralised was the way to go. It was almost like she had a vested interest in pushing it. She was also fighting for her quango to be the responsible organisation for its oversite - while also working with the developers to ensure privacy - both ends of the accountability side. She claimed to be a 'critical friend' to the developers - too much invested means her organisation cannot be responsible for system oversight. The ICO site has no mechanism to complain about the app and its privacy - or its mis-application.

On another note

One of the speakers brought up an interesting point - abuse of the system. Anyone can press 'the 'green button - its self reporting - an any phone they get their hands on - so, law enforcement could get contacts (they take phones on some assault accusations, for example, but also the public could potentially send some rival into 2 weeks quarentine for giggles or gain.

It was interesting watching Trimble (a lord from Northern Ireland, who lives not far from me) drop off the calls when he tried to speak.. Broadband hasnt reached Lambeg yet, it seams!

chuBb.

they may have agreements (or get agreements) from Apple/Google to keep awake in the background for this - NHSX claim to be working with them.

Just means they have applied to put it into the app store, apple and google wont push out an OS tweak just for the NHS, as big a UK institution that is, its a fraction of a fraction of there global userbase, best they can hope for is that they get API access to the Google/iOS platform and then balls up the integration

The elephant in the room (or should I say home?).

Anonymous Coward

The elephant in the room is that under lockdown, your location is known static constant in this, you're at home. It doesn't need your location, it's already known by default under lockdown.

The App can pretty much take that for granted and Governments can use an array of other information, cell tower triangulation, nearby Wifi hotspots, Council tax databases, HMRC, Credit Reference files to remove the anonymity of the data. Importantly, always linking the future use of any mobile device (say for criminal purposes), through it's IMEI to a home address, for as long as it's active.

i.e. Lockdown provides a very nice opportunity to build a massive GCHQ database linking every active mobile device through it's IMEI number, to an actual address and its occupants.

And the likelihood of this been done right now, seems pretty high (a certainty), because the Investigative Powers Act/Coronavirus Bill has provided the necessary carte blanche legality to do so.

Re: The elephant in the room (or should I say home?).

IGotOut

To be fair, they already have that info, and so do Google and Apple

Re: The elephant in the room (or should I say home?).

Anonymous Coward

But never with the certainty that lockdown has provided, you're missing the point.

"If John Madden steps outside on February 2, looks down, and doesn't see his
feet, we'll have 6 more weeks of Pro football."
-- Chuck Newcombe